§14. Layer 0: Verifiable Machines & Energy
Copy/paste (plain text):
Jason St George. "§14. Layer 0: Verifiable Machines & Energy" in Next Generation Stores of Value: Privacy, Proofs, Compute. Version v3.2. /v/3.2/read/part-iii/14-layer-0/ Layer 0: Verifiable Machines & Energy
Layer 0 is where cryptography stops being metaphor and touches matter.
PoW had an implicit Layer 0: silicon, power, and warehouses hashing in the dark. The trust assumption was: “ASICs will do what the SHA-256 spec says.” In practice that meant: “we trust the vendor, the fab, the firmware, and the power company, and we hope no one has a better ASIC they haven’t told us about.”
Those assumptions were never harmless—a compromised fab or a secretly superior ASIC bears directly on consensus security, and every holder relies on that—but the damage was confined to one quantity, the distribution of hashpower, and the hash itself carried no information anyone outside the system consumed. They stop being tolerable in a new way when the puzzle mints receipts that other people act on, and when proofs and verified compute become monetary primitives: a compromised machine can then misreport what was computed, on which hardware, at what energy cost, and third parties who never touched the consensus layer act on the misreport. Giving the work an external buyer raises the Layer 0 requirement rather than lowering it.
Why Layer 0 Is a Monetary Question
Gold worked as money because geology is hard to fake at scale. Bitcoin worked because hashing cost was hard to fake at scale. In both cases, the monetary story rested on silent assumptions: rocks behave; fabs behave; physics behaves.
The triad inherits those assumptions and tightens them:
-
Privacy is only as real as the devices that hold keys and speak on the wire.
-
Proofs are only as real as the machines that generate entropy, execute circuits, and sign receipts.
-
Compute is only as real as the GPUs/ASICs that claim to have run workloads.
If those machines are opaque, remotely steerable, or quietly biased, Work Credits degrade into theater:
-
A compromised RNG can turn “unpredictable leader election” into a slow rug-pull.
-
A backdoored prover can leak witnesses or mishandle private inputs, even though it cannot emit invalid proofs accepted by a sound verifier unless the proof system or implementation is broken.
-
A mandated TEE can become a kill switch for entire clusters of provers and routers.
All of this math still runs on matter.
Every proof, every encrypted wallet, every verified FLOP ultimately lives on a sliver of doped silicon that almost nobody is allowed to audit. Today’s “trusted hardware” stack is a daisy chain of NDAs: closed-source EDA tools, proprietary IP blocks, opaque PDKs, black-box fabs, sealed packaging, vendor-run attestation services.
Layer 0 Precision
Layer 0 does not make cryptographic proofs sound; soundness comes from the proof system and verifier. Layer 0 makes claims about the physical world credible: which machine produced a receipt, whether inputs were captured honestly, whether randomness was biased, whether witnesses were protected, and whether energy/capacity claims are real. A sound proof system should not require trusting the prover’s hardware for proof correctness. Layer 0 becomes essential when the claim includes physical capture, machine identity, energy use, witness confidentiality, randomness quality, side-channel resistance, or fair participation in useful-work markets.
From a monetary standpoint, Layer 0 asks:
“Can we treat triad capacity as collateral if we don’t know what the machines are really doing?”
The answer is “no.” Triad services delivered by machines we cannot interrogate cannot support a credible base-asset monetary candidate; they are IOUs on a hardware cartel plus the jurisdictions that regulate it.
So the mandate of Layer 0 is:
Translate “trust the vendor” into “trust these verifiable claims about the machine and its power,” or don’t pretend it’s money.
Design Goals and Non-Goals
Layer 0 has to be ambitious enough to matter and humble enough not to LARP full supply-chain omniscience.
Goals
-
Verifiability over purity. We aim for checkable claims about machines, not for metaphysical purity. Open RTL where we can; structured sampling where we cannot.
-
Common knowledge of security. Different actors should be able to agree on facts about hardware profiles, even if they disagree about policy.
-
Energy anchoring, not energy worship. Power use should be measurable enough that “Work Credit per joule” is meaningful.
-
Degradability under attack. When assumptions fail, the system should degrade visibly: telemetry spikes, profiles are deprecated, Work Credits tied to broken profiles are risk-flagged and may face prospective ineligibility for new collateral uses.
-
Composable exports. Layer 0 should emit artifacts that higher layers can consume mechanically.
Non-goals
-
Perfect trustlessness. We will not “solve” global hardware and supply chains.
-
Single-vendor dependence. Heterogeneity is a feature, not a bug.
-
Total hardware transparency on day one. Political and commercial realities exist.
-
Magical protection against all side-channels. We assign budgets to attack surfaces.
Hardware as Base Reality for Work Credits
In Part II, Work Credits were defined as claims on standardized units of triad work (privacy settlement, proofs, verified compute) anchored to energy and VerifyPrice.
Layer 0 defines the hardware profile that each Work Credit type rests on. For a canonical workload , a hardware profile might specify:
-
Chip family and stepping.
-
Microarchitectural features (e.g., presence of certain accelerators or TEEs).
-
RNG source and test regimen.
-
Power metering and thermal envelope.
-
Known limitations (e.g., “avoids TEE X due to backdoor Y; uses open core Z instead”).
When a Work Credit of type is minted, the receipt can say:
“This unit of work was performed on hardware profile under conditions , with proof and VerifyPrice statistics .”
Monetarily, that matters because:
-
Profiling makes hardware risk priced instead of hidden. Credits from “sketchy profile ” can trade at a discount.
-
It lets different actors pick their risk tolerance: some will only hold Work Credits linked to fully open cores; others will accept mixed profiles in exchange for lower cost or higher performance.
Layer 0’s job is not to tell everyone what risk to take; it is to make the risk legible and instrumentable.
The Layer 0 Feasibility Ladder
A common objection to Layer 0 is: “Open silicon and sampled supply chains sound like moonshots. What can we actually do this decade given real-world fabs, opaque GPU stacks, and geopolitical constraints?”
The answer is a graded trust ladder. Layer 0 does not require perfection on day one; it requires measurable progress and falsifiable claims at each grade. Higher grades provide stronger guarantees; lower grades are acceptable for less sensitive workloads, with telemetry that detects when you’re relying on weaker grades.
| Grade | Name | What It Means | Timeline | Trust Residual |
|---|---|---|---|---|
| L0-A | Best Available Today | Attestation + multi-party audits + reproducible benchmarking + diversity | Now | Trust vendor + third-party auditors; side-channel budget measured but not minimized |
| L0-B | Sampled & Bounded | Lot sampling + imaging + side-channel budgets + independent lab inspections | 1–3 years | Trust sampling methodology; residual risk is unsampled units |
| L0-C | Partial Open | Open RTL for critical components; open host/router firmware; proprietary accelerators admitted only for workloads with cheap algebraic verification (see below) | 2–5 years | Trust fab + packaging + accelerator vendor for the accelerator’s internals; open logic is inspectable |
| L0-D | Fully Open | Fully open designs + open PDKs + multi-fab production | Now, for RoT/RNG/metering/network-controller components at 130–180 nm; no known path for accelerator-class silicon (research) | Trust physics + fab process; no single-vendor chokepoint |
Layer 0 Feasibility Ladder
Scope of the top two grades, stated plainly.
Two cells in that table were, in earlier versions, written as engineering timelines, and they are not. First, L0-D. Open PDKs exist today only at mature nodes—SkyWater SKY130, GlobalFoundries GF180MCU, IHP SG13G2, i.e. 130–180 nm—and nothing resembling an open PDK exists, or is on any announced path, at the leading-edge nodes accelerator-class silicon requires. L0-D is therefore viable now for the components whose job is trust rather than throughput: roots of trust, RNGs, power and capacity meters, network controllers, and the attestation logic that binds them. For provers and verified-compute accelerators, L0-D is a research goal with no known path, and this document does not assign it a date. Second, L0-C’s “accelerators wrapped with proofs.” Wrapping a proprietary accelerator so that its internals need not be trusted works only where the output can be checked far more cheaply than it was produced: Freivalds-class randomized checks on matrix products [Freivalds 1977], Merkle-committed outputs against sampled re-execution, and workloads with a native algebraic verifier. Generic verifiable GPU compute—proving that an arbitrary kernel ran correctly at accelerator speed—is an open research problem, and L0-C admits proprietary accelerators only for the workload classes where the cheap check exists. Where the thesis elsewhere speaks of “proof-wrapped accelerators,” it is to be read with this restriction.
Key principles:
-
Grades are explicit. Every hardware profile is tagged with its Layer 0 grade. Work Credits, VerifyPrice dashboards, and SLA tiers reference these grades so users know what trust assumptions they’re accepting.
-
Telemetry detects reliance on weaker grades. If 80% of proving capacity is L0-A (vendor-attested) and only 5% is L0-C (partial open), that concentration is visible in dashboards. Users can decide whether to hold Work Credits tied to such a distribution.
-
Higher grades earn lower risk premiums. Markets should price Work Credits from L0-D profiles more favorably than L0-A profiles, creating economic gravity toward openness as it becomes available.
-
Migration paths are first-class. When L0-B or L0-C options become viable, there are documented procedures to migrate workloads off L0-A profiles without catastrophic downtime.
-
Failure modes are bounded. If a specific grade is compromised (e.g., a TEE used in L0-A profiles is broken), the impact is contained to that grade. Higher-grade capacity continues to function; affected Work Credits are risk-flagged, receive collateral haircuts, or face prospective ineligibility.
Policy Hooks: Economic Treatment by Grade
The following table specifies how each L0 grade affects Work Credit eligibility, pricing, and collateral treatment. These are reference parameters; implementations may adjust within bounds.
Interpretation:
-
Issuance weight: No grade earns more than one Work Credit per standardized unit of verified work. A Work Credit is a typed service claim (§10: Work Credits: Energy-Anchored Claims); issuing or claims per unit delivered would make the claims exceed the redeemable work and turn the instrument into a subsidy token, in conflict with the issuance bound of §14: Layer 0: Verifiable Machines & Energy. Lower grades are haircut below baseline (fewer claims than work delivered, so the outstanding stock stays over-backed); the incentive for open-hardware investment is carried by collateral grade, routing priority, and the VerifyPrice premium tier, none of which inflate the claim stock.
-
Collateral haircut: When WC are used as collateral (e.g., for staking, LP positions, or DeFi), lower grades may face haircuts. L0-A collateral is discounted if a single vendor/TEE dominates.
-
VerifyPrice tier: Dashboards stratify measurements by L0 grade. If most verification runs on L0-A hardware, this is flagged as concentration risk. The ladder grades openness; the Gold assurance tier of §14: Layer 0: Verifiable Machines & Energy grades sampling evidence and is orthogonal to it: a profile can be L0-B and Gold, or L0-D and not yet Gold.
-
Issuance cap (L0-A only): To prevent over-reliance on vendor-attested hardware, L0-A profiles are capped at 60% of new issuance. Excess work at L0-A earns priority for future slots but no additional Work Credits. The incentive consequence is stated rather than left to be discovered: at the cap, an L0-A operator’s marginal delivered unit is unpaid in Work Credits, so operators at the margin will decline L0-A work or migrate hardware grade — which is the cap’s purpose, and the reason the cap is published in advance rather than applied ex post.
Collateral Haircut by Modality and Grade
The collateral haircut in the policy-hooks table above is indexed on openness grade alone. §19: Layer 4: Truth & Work shows that the more fundamental axis is the verification modality of the position being pledged: an M3-verified position carries irreducible delegated-trust exposure whatever its hardware grade, and an M1-verified position on modest hardware may carry less. The two axes are therefore indexed jointly, and the joint table is the one collateral integrations read; the grade-only column above is its M1 row.
Quantitative Thresholds (Reference Design)
Read the first row plainly, because the number is doing more work than it appears to. Three-fifths of the world’s proving running on vendor-attested chips is the state the cap forbids: every attestation in that world—every claim about which machine did the work, on what hardware, at what energy cost—is a signature away from being repudiated by whoever holds the signing key (proof soundness itself does not depend on the prover’s hardware, per the sidebar in §14: Layer 0: Verifiable Machines & Energy, which is exactly why the exposure is in the attestations and not the proofs), and the stack’s central promise—that anyone can verify without trusting a platform—quietly reduces to trusting three vendors in sequence. The thresholds exist to make that drift expensive before it is complete. Each is a tripwire that fires while the concentration is still a governance problem, rather than after it has become a settlement failure. Breaching one does not crash anything; it pauses issuance, raises a haircut, downgrades a grade. The damage is contained by making the drift itself the first thing to pay.
These thresholds are governance parameters, adjustable via protocol upgrade with supermajority. Changes are announced 90 days in advance and visible in dashboards.
Pragmatic Starting Point (L0-A)
Today’s stack can achieve L0-A by combining:
-
Multi-vendor diversity: No single chip family or TEE dominates more than % of critical capacity, aligned with the single-vendor share trigger of §14: Layer 0: Verifiable Machines & Energy.
-
Third-party attestation audits: Independent labs verify that attestation claims match device behavior.
-
Reproducible firmware and benchmarks: Host, router, and metering firmware is built reproducibly from published source. Accelerator firmware is not: GPU and ASIC firmware is vendor-signed and closed, and cannot be rebuilt by anyone outside the vendor. For accelerators the requirement is therefore hash-pinned and version-attested: the profile names the exact firmware digests it accepts, devices attest the running version, and the residual—that the vendor’s binary is trusted as shipped—is recorded in the profile dossier as a named trust assumption rather than left implicit. Benchmark results are publicly verifiable.
-
Side-channel measurement: Known side-channel leakage is measured and published as a “leakage budget” per profile.
-
Cryptographic agility: Profiles document which primitives can be upgraded via firmware vs. require hardware swap.
This is not trustless. It is trust-bounded and measured. The residual trust is explicit: “We trust these vendors, these auditors, and this sampling methodology, and here is the evidence.”
The Path Forward
-
L0-A L0-B: Fund independent lot-sampling programs. Publish inspection results. Build statistical models of detection confidence.
-
L0-B L0-C: Invest in open RISC-V cores, open RNG designs, open host and router firmware stacks. Wrap proprietary accelerators with proof interfaces for the workload classes where a cheap check exists—Freivalds-class MatMul verification [Freivalds 1977], Merkle-committed outputs with sampled re-execution—so that the accelerator’s internal logic need not be trusted for those workloads. For workloads without such a check, the accelerator remains a trusted component and the profile says so.
-
L0-C L0-D: Move the trust-critical, low-throughput components—roots of trust, RNGs, meters, network controllers—onto open PDKs at the mature nodes where those PDKs exist today, manufactured at multiple fabs in multiple jurisdictions. For accelerator-class silicon this step has no known path; funding open-PDK research at advanced nodes is the honest description of the work, and it is research, not a roadmap item with a date.
Why This Prevents “Layer 0 Is Impossible, Therefore Thesis Fails”
The thesis does not require L0-D today. It requires:
-
Clear grading of what trust assumptions each profile carries.
-
Telemetry that makes those assumptions visible.
-
Economic and technical paths toward stronger grades over time.
-
Failure modes that degrade visibly, not silently.
If these four conditions hold, Layer 0 becomes a progress metric rather than a moonshot prerequisite. The stack can operate today at L0-A while building toward L0-C/D, and users can decide what risk they’re willing to accept at each stage.
Concrete Components of Layer 0
Layer 0 is not a single device. It is a bundle of practices and mechanisms that give higher layers a surface to stand on.
Open Designs Where Possible
The gold standard is open cores and toolchains: open RTL or microarchitectures for CPUs/accelerators, open PDKs where geopolitical conditions allow, and reproducible build infrastructure.
Where open options exist, they are first-class citizens in hardware profiles. On the margin, this creates economic gravity: as open hardware matures, Work Credits tied to open profiles should command a lower risk premium.
Attested Randomness and Entropy
Randomness is the hidden spine of consensus and proofs. A biased RNG can leak signing keys, predict leader election, and make PoUW “fairness” an illusion.
Layer 0 requires:
-
Hardware RNG designs that are documented and testable.
-
Attested entropy tests: periodic statistical test suites.
-
Blended randomness: mixing hardware entropy with VRFs, commit-reveal, and cross-machine aggregation.
Attestation Without Priesthood
Modern hardware ecosystems push TEEs and attestation as the answer to everything. Used naively, they simply move “trust the vendor” into “trust the vendor’s signing key.”
Layer 0’s posture:
-
TEEs and hardware attestation are useful tools, not root of trust.
-
Attestations should be wrapped and sampled, not taken as gospel.
-
Devices emit local attestations wrapped in SNARKs or STARKs where possible.
The title of this subsection claims less than it may appear to, and the limit should be stated where the mechanism is introduced rather than discovered later. A succinct proof over a vendor attestation proves exactly one thing: that a valid signature under vendor key exists over the attested measurement. It does not prove that the measurement is true, that the device is what says it is, or that has not been misused. The vendor key remains the root of trust for the attestation’s content; wrapping does not move it. What wrapping delivers is compression (one proof over many attestations, verifiable on any chain at fixed cost) and selective disclosure (revealing that a device belongs to an accepted profile without revealing which device). Both are worth having. Neither is trust reduction. Trust reduction in this stack comes from two places only: the lot-sampling program of §14: Layer 0: Verifiable Machines & Energy, which checks whether devices behave as attested, and open design (L0-C/D), which lets the attestation logic itself be inspected. “Without priesthood” is therefore earned by sampling and openness, with wrapping as the transport that makes their results cheap to consume; it is not earned by the wrapping alone, and the same limit applies wherever this document speaks of ZK-wrapped quotes (§17: Layer 3: Identity & Claims).
Lot Sampling and Destructive Audits
Because we cannot open every chip, Layer 0 leans on lot sampling:
-
For each hardware profile, a fraction of units are randomly selected for deep inspection: decapping, imaging, side-channel probing.
-
Results are published as part of the profile’s dossier.
-
A protocol-level Layer 0 Assurance Fund, the largest line of the assurance budget in the fee routing (10% of gross fees, §22: Layer 6: Governance & Telemetry), finances sampling.
This is how Layer 0 turns “we hope the vendor is honest” into:
“We have inspected a statistically relevant sample of this profile, and here are the findings and residual risks.”
Sampling Economics and Sufficiency
Critics will ask: “How much sampling is enough? Who pays? What confidence do we actually get?” The honest answer begins by conceding the premise: sampling does not produce certainty, and no number in this subsection should be read as though it does. What sampling produces is a published, priced, third-party bound on how much of a fleet is compromised by the defects the tests can see—an instrument with two distinct commercial pedigrees, and it is worth keeping them apart. The sampling precedent is acceptance sampling: MIL-STD-105 and its civilian successor ANSI/ASQ Z1.4 [DoD 1989] have governed lot-by-lot attribute sampling for industrial procurement since the 1950s, and pharmaceutical lot-release testing under FDA and ICH guidance accepts or rejects a production lot on the basis of a drawn sample rather than a full inspection. Both accept a stated consumer’s risk in exchange for an affordable inspection; both publish the sampling plan so the risk can be computed rather than asserted. The publish-and-underwrite precedent is Lloyd’s Register, and it is a different thing: Lloyd’s classification was a per-vessel survey, not a sample, and it is cited here not for its statistics but for its market structure—a third-party grade, paid for by the industry that needed it, published, and independent of the shipowners, which underwriters then priced off. Marine insurance priced off Lloyd’s grade the way collateral markets here price off L0 grades. The statistics below come from the acceptance-sampling tradition; the institutional form comes from Lloyd’s; neither is claimed to be the other.
Sample rate model (reference design):
| Profile Criticality | Definition | Min Sample Rate | Funding Source |
|---|---|---|---|
| Tier 1 (Critical) | Profiles in the top 5 by WC issuance OR above 10% of total capacity; a profile meeting either condition is Tier 1 | 50 units/quarter | Protocol assurance budget (the 10% assurance share of §22: Layer 6: Governance & Telemetry) |
| Tier 2 (Standard) | Profiles with 1–10% of capacity | 20 units/quarter | Protocol assurance budget |
| Tier 3 (Emerging) | New profiles in probation; 1% of capacity | 5 units/quarter | Profile sponsor (operator or vendor) |
Sample rate model by profile criticality.
Units and lots.
The table’s minimums are counted in units; the coverage thresholds of §14: Layer 0: Verifiable Machines & Energy and the Gold assurance tier below are counted in lots. The two are reconciled by a per-lot floor: every lot selected for destructive inspection contributes at least 5 units, drawn at random from within the lot. A profile’s quarterly sampling obligation is therefore the larger of two numbers—the tier’s unit minimum, and five times the number of lots its coverage threshold requires. A Tier 1 profile shipping twelve lots a quarter at 80% coverage owes units; the same profile shipping forty lots owes . The unit minimum is a floor for small-volume profiles, not a ceiling for large ones.
Statistical sufficiency:
For a profile with deployed units, sampling units provides confidence that:
where is the test sensitivity: the probability that the inspection regime actually applied to a sampled unit flags that unit, given that it is compromised. Setting recovers the textbook bound, and the textbook bound is the wrong number to publish, because is not one and for the most dangerous defect class it is not known.
Two assumptions carry the bound. The first is uniform prevalence: compromise is modeled as spread evenly across the deployed population, so that a random sample of units meets compromised units at the background rate. Concentrated compromise—an entire production lot backdoored while others are clean, or 20% of lots attestation-only and never destructively inspected—defeats it, because prevalence in the sampled lots is then not prevalence in the fleet. This is why lot selection is randomized and stratified rather than convenience-sampled, and why the attestation-only residual is a published quantity rather than a silent one. The second is sensitivity, and it is where honesty costs the most. For counterfeit dies, remarked or binned-down parts, substituted firmware, and metering fraud, is high: these defects are visible to electrical test, decapping and optical inspection, firmware-hash comparison, and cross-metering, and a competent lab finds them when it looks. For stealthy hardware trojans in leading-node accelerators—dopant-level modifications of the kind Becker et al. demonstrated at CHES 2013 [Becker et al. 2013], which alter transistor behavior without changing any metal layer an imaging pass would see— against a quarterly sampling program is unknown and probably low. Full-die reverse engineering at 5–7 nm is not something an assurance fund buys every quarter, and a trojan designed to evade it is designed by someone who knows that.
The sampling program’s primary, defensible targets are therefore the high- classes: counterfeit dies, binned-down parts, firmware substitution, and metering fraud. Against those it produces a bound worth publishing. Against dopant-level trojans in advanced-node silicon it produces a deterrent and a paper trail, not a bound, and the profile dossier says which of the two it is offering.
For Tier 1 profiles (, ), the detection probability is 92% at and 72% at ; at the low, unknown appropriate to stealthy trojans the bound is not quoted because it would be a number without a basis. Published bounds carry the assumed and the defect class it applies to. This is not certainty—it is bounded uncertainty, documented and priced, and bounded only for the defect classes the tests can see.
The converse matters just as much and must be stated with equal care. With samples and zero findings, the 95% upper confidence bound on the prevalence of detectable compromise is approximately (the rule of three, sensitivity-adjusted). Fifty clean samples at bound undetected compromise at 6% (the exact bound is 5.8%), not at zero; at the same fifty clean samples bound it at 12%. Lot sampling supports graded confidence, never exoneration, and no claim in this thesis should be read as the latter.
The Gold Assurance Tier
Earlier versions of this document identified “Gold tier” with grade L0-D. That was a category error: the feasibility ladder grades openness—how much of the design can be inspected—while the conditions below are all about sampling evidence, and say nothing about RTL or PDKs. The two are now kept orthogonal. Gold assurance is a tier a profile earns through its inspection record; it is attainable at openness grade L0-B or above, and L0-D remains the openness grade, earned by design and PDK disclosure alone. A profile can be L0-B and Gold (a closed design with an exemplary, heavily sampled supply chain), or L0-D and not yet Gold (a fully open design whose fleet has not accumulated four clean quarters).
A profile achieves Gold assurance when:
-
95% of production lots are sampled each quarter at or above the tier minimum unit rate and the per-lot floor of 5 units, with the remaining lots covered by supply-chain attestation. This is deliberately stricter than the 80% floor that keeps a profile at L0-B (§14: Layer 0: Verifiable Machines & Energy); a threshold that merely keeps a grade cannot also be the criterion for the highest assurance tier.
-
Zero critical findings (backdoors, RNG bias threshold, firmware or die substitution, metering discrepancies) in the last 4 consecutive quarters.
-
Side-channel leakage remains within published budget under independent testing.
-
Inspections in each of those four quarters were conducted by at least 2 independent labs, and no single lab performed more than 70% of the units sampled.
Coverage is counted in lots, not deployed units. Inspections are destructive and expensive; the lot is the auditable unit a sampling program can afford to buy. “95% of deployed units” would describe a near-total destructive audit of the fleet, which no assurance budget can fund and no fleet can survive; the reference design does not propose it and this document should not be read as though it does.
Gold assurance unlocks:
-
For L0-C and L0-D profiles, the “pristine collateral” designation in DeFi integrations. Pristine requires both: inspectable logic (openness L0-C) and Gold assurance; the grade table’s “may qualify” for L0-C is this condition.
-
Release from probation weights (§14: Layer 0: Verifiable Machines & Energy) and eligibility as a reference baseline in VerifyPrice stratification.
-
For L0-B profiles, an “assured” flag in dashboards and profile dossiers. L0-B with Gold assurance does not earn pristine status; a closed design remains closed however thoroughly it is sampled.
Issuance eligibility and the 0% collateral haircut are consequences of the openness grade (L0-B and above), not of Gold assurance; the grade table governs them, and Gold adds nothing to them. “Pristine collateral” as a designation therefore means openness grade L0-C or L0-D with Gold assurance throughout this document.
Funding mechanism:
The fee routing of §22: Layer 6: Governance & Telemetry allocates 10% of gross fees to an assurance budget; the Layer 0 Assurance Fund is that budget’s largest line, alongside security review and audit. The fund:
-
Contracts with independent hardware security labs.
-
Publishes RFPs for sampling campaigns.
-
Maintains a public registry of inspection results.
-
Is governed by a multisig of hardware security researchers (not protocol developers).
Transparency:
All sampling results are published within 30 days. Raw data (images, test logs) is archived and available for independent verification. If a lab’s findings are disputed, a second lab can be commissioned for arbitration.
How This Opens New Economies
Verifiable machines don’t just make today’s cloud slightly less sketchy. They unlock whole categories of economic arrangement that aren’t viable when hardware is a black box.
Verifiable cloud and compute co-ops.
If you can spin up a rack of open-design TEEs or accelerators and have them produce attestations and ZK receipts that anyone can verify, then:
-
A small data center in Nairobi or Reykjavík can sell the same class of “trusted inference” or “trusted proving” as a hyperscaler in Virginia.
-
A co-op of households can pool “AI appliances” in their basements and earn by running verified work for others.
-
Regulators and enterprises can enforce compliance through proofs and telemetry, not vendor logos.
Compute ceases to be a winner-takes-all brand game and becomes a commodity with open admission.
Civic infrastructure that doesn’t depend on one vendor’s conscience.
Voting machines, digital ID kiosks, public-health dashboards: today they are RFPs to a short list of contractors. With open hardware and proof-wrapped attestation, you can build ballot boxes and ID hardware whose entire stack is open to public inspection and require that each device emit public proofs of correct behavior. Democratic legitimacy becomes a property of math and sampling, not of which vendor’s logo sits on the plastic.
Tamper-evident telemetry.
As the physical world fills with sensors and actuators, the ability to sell tamper-evident telemetry becomes critical. An environmental sensor built on an open profile, with attested firmware and ZK-wrapped readings, can sell CO or temperature data as evidence into climate, insurance, and industrial hedging markets—not just as numbers on a dashboard.
Hardware-native credit instruments.
Once machines themselves are verifiable actors, capacity becomes something a credit instrument can be written against: “miner-notes” backed by the future output of a specific open-design proving farm, or project paper whose coupon is denominated in SLA-backed capacity— proofs per second, verified FLOPs, private swaps per month—all attested by open hardware meters. These are instruments of the labeled, non-monetary Open Duration Warehouse (§30: Objections & Responses): they are project credit, carrying construction risk, counterparty risk, and time risk, underwritten by loss-bearing holders who can sit through marks, and their novelty is only that the covenant is checkable by receipt rather than by site visit. They are explicitly not the monetary object. The base asset carries no coupon, capacity-denominated or otherwise; the moment it did, proofs would have become the bond and duration-neutrality—which this thesis treats as a repression-resistance requirement, not a preference (§2: The World Forces New Monetary Primitives)—would have been undone through the protocol door. Verifiable machines make capacity credit underwritable. They do not, and must not, make it money.
Open profiles manufactured at multiple fabs in multiple jurisdictions turn chip supply into a multi-polar fabric instead of a single chokepoint. Neutral money needs neutral hardware; verifiable machines produced on a diversified manufacturing base make that a reachable design goal rather than a slogan.
Verifiable Power: Energy as First-Class Input
If Work Credits are energy-anchored claims on triad work, then power is not just an environmental footnote; it is an input to service delivery. It does not back the base asset or make the credit monetary.
Layer 0 treats power in three ways:
-
Measurement. Prover farms track power draw, mapping between workloads and power, and local generation vs. grid intake. These feed into Work Credit metadata and VerifyPrice models.
-
Resilience. Micro-grids or backup generation for critical infrastructure; geographic and jurisdictional dispersion of power sources.
-
Policy hedging. Transparent power telemetry allows answering “how much of this is actually training/inference/proof that humans pay for?”
For Work Credits, this means credits can carry energy provenance tags and markets can price credits differently based on energy profile.
Facility Capacity Receipts: Beyond Energy
Facility Energy Receipts (FERs, Appendix A: Formal Model of Verification Asymmetry & VerifyPrice) make energy legible, but verified digital infrastructure depends on more than kWh. A facility can have cheap energy and still be fragile if it sits behind a congested interconnect, depends on a water-constrained cooling system, runs in a jurisdiction with curtailment risk, or relies on a single transformer, fuel source, cloud vendor, or hardware profile.
We therefore extend FERs into Facility Capacity Receipts. An FCR records the physical capacity envelope behind a unit of verified work in ten fields (§14: Layer 0: Verifiable Machines & Energy): grid node, interconnection class, outage history, backup duration, fuel mix, cooling dependency, transformer redundancy, hardware profile mix, jurisdictional risk score, and a confidence grade on the receipt itself. Curtailment exposure is carried by the grid-node and jurisdictional-risk fields; water intensity by the cooling-dependency field. The list is ten fields, not more, and the same ten are what §14: Layer 0: Verifiable Machines & Energy aggregates.
Facility Capacity Receipt (FCR)
A signed, auditable receipt that extends Facility Energy Receipt data with infrastructure resilience, grid, cooling, jurisdictional, and hardware-diversity metrics.
| Field | Why it matters |
|---|---|
| Grid node / balancing authority | Captures congestion and curtailment risk |
| Interconnection class | Captures firmness of power access |
| Outage history | Captures reliability |
| Backup duration | Captures blackout survivability |
| Fuel mix | Captures geopolitical/commodity exposure |
| Cooling dependency | Captures water and heat constraints |
| Transformer redundancy | Captures single-point grid failure |
| Hardware profile mix | Captures compute centralization |
| Jurisdictional risk score | Captures seizure, power rationing, sanctions risk |
| FCR confidence grade | Allows risk-weighted Work Credit issuance |
Suggested FCR fields
A Work Credit backed by resilient, diversified, verifiable capacity is economically different from one backed by cheap but brittle compute. The market should be able to price that difference. The stack should not hide physical fragility behind cryptographic elegance. If FCR data is unavailable or unverifiable for a facility, credits from that facility should receive issuance caps or risk haircuts (§22: Layer 6: Governance & Telemetry); §19: Layer 4: Truth & Work formalizes the cost of auditing FCR claims as Physical VerifyPrice.
Sovereign Optionality: Aggregating FCR Into One Exposure
§14: Layer 0: Verifiable Machines & Energy gives an allocator ten fields per facility. That is the right raw material and the wrong interface. Nobody underwrites a monetary asset by reading ten columns across a thousand facilities, and a field-by-field presentation makes it easy to be locally reassuring while globally fragile: every facility can look acceptable while the network sits inside two balancing authorities and one jurisdiction.
We therefore define a single aggregate exposure over fields the stack already collects. This is deliberately not new telemetry. It imposes no additional reporting burden; it changes how existing FCR data is read.
Sovereign Optionality ()
A capacity-weighted composite of substitutability attributes—fuel diversity, firmness, interconnection, jurisdictional dispersion, and hardware mix—computed from Facility Capacity Receipt fields. It correlates with the number of independent physical pathways by which verified work can continue under disruption, but does not literally count them; the pathway-count question is answered by Delivered Verified Capacity (§14: Layer 0: Verifiable Machines & Energy).
Adaptation of Scale
The concept is borrowed from state-level energy strategy [Doomberg 2026a], where analysts assess how many independent ways a sovereign can obtain electricity, fuel, and industrial feedstock when ordinary market relationships fail. The transposition to a proving network is close but not exact: the state-level analysis includes industrial and logistical throughput, and proving has a conversion analogue of its own.
A proving facility has a measurable conversion chain:
It is not manufacturing throughput, but it is conversion throughput. Any edge can become the binding cut [Doomberg 2026b], and a weighted resilience score can conceal a zero-flow series bottleneck. Sovereign Optionality therefore remains the substitutability measure; Delivered Verified Capacity below supplies the missing throughput measure.
Mapping to Existing FCR Fields
| Term | Component | FCR field(s) used |
|---|---|---|
| On-site availability | Fuel mix; local generation vs. grid intake (§14: Layer 0: Verifiable Machines & Energy) | |
| Conversion flexibility | Fuel mix diversity: Shannon entropy over independent fuel-source shares, normalized by so , matching the other components’ normalization. is the number of fuel-source classes in the published FCR fuel-mix taxonomy (a fixed, versioned constant shipped with the telemetry spec), not the number of sources a given facility happens to use; otherwise a single-source facility would score trivially | |
| Reserve depth | Backup duration | |
| Grid firmness | Interconnection class; outage history; transformer redundancy; grid node | |
| Supplier & technology diversity | Hardware profile mix | |
| Coercion exposure (subtracted) | Jurisdictional risk score; curtailment exposure |
Sovereign optionality components and their FCR sources
Every input already exists. Note in particular that the jurisdictional risk score of §14: Layer 0: Verifiable Machines & Energy is already specified to capture “seizure, power rationing, sanctions risk.” The stack has been collecting the coercion term all along without aggregating or acting on it.
Facility and Network Form
For a facility , with each component normalised to :
so that the positive part of the index lies in and : the declared range is fixed by the constraint, and a published tells the reader exactly how far below zero a maximally coerced facility can score. Without the constraint the weights could be rescaled to move every facility’s score without changing any input, which is the failure mode §14: Layer 0: Verifiable Machines & Energy exists to prevent.
The network-level figure is the capacity-weighted mean across facilities, less a concentration penalty. Let be facility ’s share of verified capacity. is the average of two capacity-share Herfindahl–Hirschman indices, one computed over the jurisdiction partition of the fleet and one over the balancing-authority partition. That single convention is pinned here; no other aggregation of the two partitions is used anywhere in this document:
The penalty term is what prevents the local-reassurance failure. A network of individually excellent facilities that all sit behind the same interconnect or inside the same legal regime has one pathway, not many, and the weighted mean alone would not say so.
One overlap in this form is deliberate and should be visible rather than silent: jurisdictional exposure enters twice, once per-facility through (siting-level risk: seizure, rationing, sanctions) and once network-level through (concentration of the fleet inside few jurisdictions or balancing authorities). Because the two terms price different failure modes at different scopes, both are retained; the weights and are therefore published jointly and reviewed annually, so the overlap is a documented modelling choice an allocator can see and reweight, not a hidden double count.
Relationship to existing metrics.
overlaps deliberately with the dispersion metrics already used for verification monoculture and enclosure risk (§27: Risk Analysis & Failure Modes, Red Lines 3 and 11). should consume those existing measurements rather than introduce a parallel concentration statistic. Where they disagree, that disagreement is itself a finding.
Governance of the Weights
The weights are judgement, not measurement, and an index whose weights can be quietly retuned is a marketing instrument. Three constraints follow:
-
Published and versioned. Weights ship with the telemetry spec; changes are proposals with rationale, not silent parameter updates.
-
Independently reproducible. A third party holding the same FCR data must be able to recompute and obtain the same number.
-
Subject to capture review. Weight-setting falls under the same telemetry-capture constraints as the rest of the scoreboard (§27: Risk Analysis & Failure Modes, Red Line 4). The party being scored must not set the scoring function.
Report alongside its component vector, never as a bare scalar. A single number is what an allocator wants and also what conceals which substitutability attribute is missing; publishing both is the only honest form.
What Is For
The index does real work in two places, and is otherwise decoration:
-
Risk haircuts. It extends issuance discipline from “we cannot see this facility” to “we can see it clearly and it is fragile” (§22: Layer 6: Governance & Telemetry).
-
Falsification. It supplies the measurable condition for the energy-sovereignty red line (§27: Risk Analysis & Failure Modes).
Absent those two hooks, would be another dashboard number. With them, it is a constraint that can bind against issuance and a threshold that can retire the thesis.
Delivered Verified Capacity: Surviving Service Flow
Picture a city’s water system. The reservoir level is the number a brochure quotes; what comes out of the tap is what the city actually drinks. Between the two runs a network of mains, valves, and pumping stations, and any one of them—not the reservoir—can be the thing that decides whether water arrives. DVC is the tap, not the reservoir. Nameplate capacity says how much could flow if nothing failed; Delivered Verified Capacity says how much does flow once a scenario has removed, throttled, or delayed the edges it removes, throttles, or delays. The narrowest main in the network is the minimum cut, and it is the only number that matters while it binds. This is why the measure that follows is a flow computation rather than a capacity sum: the sum flatters, the cut confines. And it is why substitution latency enters the arithmetic at all—a backup reservoir that takes three weeks to route is not redundancy for a fire that started today.
Delivered Verified Capacity (DVC)
For canonical workload , interval , and disruption scenario , Delivered Verified Capacity is the maximum usable service flow per unit interval through the complete energy-to-settlement network after scenario-specific edge capacities, substitution latency, and common-cause failures are applied. It is a rate, not a stock.
DVC is defined here but deliberately parameterized by objects defined later: the workload is drawn from the canonical workload registry of Layer 4, and the sink is usable settled service in the sense of Layer 5 settlement. The same and the same sink are used throughout this Part and the two economic layers; nothing downstream redefines them.
Let be a directed capacity graph whose source nodes are available energy and fuel and whose sink is usable settled service. Each edge carries surviving capacity in a common workload-specific service unit. Then
and the corresponding minimum cut identifies the bottleneck that actually limits delivery. The unit is not a generic FLOP: it is a settled, independently verifiable unit of the canonical workload at the promised tier. Because DVC is a flow, the quantity comparable to it is issuance over an interval, and the bound below carries the interval explicitly.
Units change along the chain; the flow must be told so.
A plain max-flow assumes every edge is measured in the same unit, and the chain of §14: Layer 0: Verifiable Machines & Energy is not: fuel enters in MWh-equivalent, electricity leaves the switchgear in kW, the hardware node emits proofs per second, and the sink counts settled units of . The correct object is therefore a generalized flow in which each node carries a gain factor—the kWproofs/s conversion is a property of the hardware class sitting at that node, published in its profile as a measured efficiency at the promised tier—and the flow is conserved only after the gain is applied. Equivalently, the graph must be built so that every energy edge terminates at exactly one hardware class, with the conversion pinned at that node, and no edge is permitted to carry “capacity” in a unit its successor cannot consume. Either construction recovers a well-defined maximum flow and a well-defined minimum cut; a graph that mixes kW and proofs/s on edges feeding a common node does not, and a DVC quoted from such a graph is not a number. A second consequence follows for issuance across workloads. The energy, cooling, transformer, and network edges of a facility are shared among every it serves, so computing independently for each and summing counts the same transformer once per workload. Issuance across several workloads therefore requires either a multi-commodity formulation—all workloads routed simultaneously through the shared edges, each edge’s capacity binding on their sum—or a published shared-capacity allocation rule that assigns each shared edge’s surviving capacity to workloads in declared fractions before any per-workload flow is computed. Which of the two a constitution adopts is a governance parameter; that it must adopt one of them is not. The min-cut reading survives both constructions: it identifies the edge, in whatever unit that edge is measured, whose failure binds delivery.
Scenario specificity.
A benign-state graph and a drought, fuel-shock, transformer-loss, chip-embargo, network-partition, stablecoin-depeg, or coordinated-policy graph are different objects. Scenario changes edge capacities and may remove nodes or entire dependency classes. Publishing only the expected or capacity-weighted average is insufficient because a series path fails at its narrowest edge.
Substitution latency.
Redundancy exists only when an alternative can enter before the service obligation expires. For each edge publish a substitution time and the workload’s maximum tolerated interruption . An alternative with does not contribute to DVC in that scenario, even if it eventually restores capacity. Spare hardware in another jurisdiction is not current redundancy if export approval, installation, synchronization, or key rotation takes longer than the SLA permits.
Common-cause dependencies.
Nominally separate facilities may share a transformer vendor, firmware signer, cloud identity layer, cable, gas market, cooling basin, stablecoin, legal safe harbor, or market maker [Doomberg 2026c]. Assign each edge one or more dependency groups . A scenario can haircut or remove all edges in a group simultaneously. Geographic dispersion without dependency-group dispersion is not independent capacity.
Relationship to Sovereign Optionality.
Sovereign Optionality is a capacity-weighted composite of substitutability attributes that correlates with independent pathway count but does not count pathways. DVC asks how much usable service reaches the sink after the scenario binds, and is the measure that actually enumerates flow. A network can have high optionality and low DVC because all alternatives are small or slow; it can have high benign DVC and low optionality because one large path supplies nearly everything. Report both, with the active minimum cut and dependency groups, rather than combining them into a reassuring scalar.
Issuance discipline.
Work Credits, capacity vouchers, and any other forward service claim must be bounded by a conservative stress-adjusted quantity,
where is the length of the issuance interval, is a rate, and is a published prudential haircut. The interval factor on the right is what makes a stock (claims issued) comparable to a rate (capacity delivered); it belongs in the bound, not in a gloss beneath it. is the pre-declared set of scenarios the constitution treats as binding for issuance. Scenarios carrying zero flow do not vanish from the minimum—a scenario in which nothing is delivered binds issuance at zero, which is the correct answer—and they are excluded only if the constitution pre-declares them as force-majeure. That exclusion list is itself a published governance parameter, subject to the same change-disclosure rules as any other; there is no default exclusion. FCR, FER, and PIDL artifacts supply evidence for edge capacities; they are not themselves capacity. Governance may not replace this bound with nameplate power, installed hardware, gross proof throughput, or a benign-state average.
Resilience Versus Affordability: The Layer 0 Cost Tension
The previous section asks for resilient, dispersed, fuel-diverse, backup-equipped capacity. The thesis elsewhere insists that verification must stay cheap: “anyone can verify” is the hinge, and §27: Risk Analysis & Failure Modes treats its failure as fatal.
These two demands pull against each other, and the tension should be stated rather than glossed.
Resilience is insurance. Insurance has a premium. A jurisdictionally dispersed, fuel-diverse, backup-equipped fleet costs more per verified unit than a single facility sitting on cheap interruptible power.
If hardening Layer 0 raises cost per verified unit, then hardening Layer 0 pushes the stack toward the very red line that hardening was supposed to protect. A thesis that demands both cheap verification and expensive redundancy without reconciling them has an open flank.
Two Different Exposures
The tension dissolves partially once we separate two things that “energy cost” conflates.
The verification side.
Checking a proof happens on reference hardware, at the edge, in small amounts. Its physical exposure is not bulk industrial power. It is:
-
Reference hardware obtainability. Export controls, sanctions, or platform lockdown can make the reference verifier unavailable, or available only in attested-and-permissioned form.
-
Edge power and connectivity cost relative to local income, which is what makes verification affordable in practice rather than in principle.
The proving side.
Generating proofs and running verified compute consumes bulk power. Its exposure is:
-
Energy price and firmness at facility scale.
-
Competition for the same electrons from industrial load and state-directed AI build-outs.
-
Curtailment, rationing, and interconnection denial, which are policy instruments, not market outcomes.
Conflating these produces sloppy claims in both directions. Bulk electricity prices do not directly break “anyone can verify,” because verification is not a bulk-power activity. What breaks the hinge on the verification side is loss of access to unprivileged reference hardware. What bulk energy conditions threaten is the proving economy: Work Credit issuance, geographic concentration, and enclosure.
Scope of “Exogenous”
§19: Layer 4: Truth & Work describes the Real-Resource VerifyPrice SLOs as “constitutional” and “exogenous to token price.” That is correct and worth keeping: the SLOs must not be redefined because the market moved.
But exogenous to token price is not exogenous simpliciter. Real-resource VerifyPrice remains endogenous to the physical and jurisdictional conditions under which reference hardware and power are obtainable. Those conditions are partly set by states. The constitutional claim should be read with that scope, not as a claim that the metric floats free of politics.
Disruption-Adjusted VerifyPrice
For the proving side, comparing a resilient fleet against a brittle one at benign-state spot cost is the wrong comparison. It prices the premium and ignores what the premium buys.
What this subsection prices is therefore fleet resilience of verification: below is the cost of verification for workload in state , where runs over the five price states. Two same-named metrics must be kept apart. Physical VerifyPrice (§19: Layer 4: Truth & Work) is the Layer 0 audit cost of checking FCR claims—a measurement of how expensive it is to verify the physical collateral story. The VerifyPrice SLOs of Layer 4 are the constitutional cost band on verifying a workload’s receipts. They are different metrics that share a surname, and the decision rule at the end of this section reads on the latter.
The object under measurement is a hardening fleet: a collection of proving facilities deliberately built redundant, dispersed, and fuel-diverse so that verification survives the states in which it is most needed. Hardening is not decoration. A fleet that has paid for geographic and jurisdictional dispersion is one whose verification still runs when a single region is curtailed, a single transformer vendor is compromised, or a single jurisdiction is excluded—which is precisely when the cost of checking becomes the difference between a claim being auditable and a claim being whatever the surviving operator says it is.
Let index physical disruption states—normal operation, regional curtailment, extended outage, hardware supply interruption, jurisdictional exclusion—with probabilities , and let be the empirical distribution of per-run verification cost for workload observed (or, for states not yet observed, modeled from receipts) in state . The disruption-adjusted figure is computed from the -weighted pooled distribution
that is, the mixture distribution in which a run is drawn from state with probability , and the percentiles are then read off the mixture. This matters because a -weighted average of per-state values is not a percentile of anything: percentiles do not average, and a fleet whose outage-state is catastrophic would see that tail diluted linearly by a small rather than showing up, as it should, in the pooled tail. Only the failure-rate field is a mean, and only it averages linearly: .
Two scope notes are recorded with the definition, and kept brief here. First: the states are the five price states enumerated above, not DVC’s capacity scenarios (§14: Layer 0: Verifiable Machines & Energy)—two distinct enumerations serving distinct purposes, and they must not be merged. Second, on dimension: the pooling is done separately for time and for cost, yielding the five-field tuple , the first four as pooled percentiles and the last as a linear average; when a scalar headline is quoted for it is the field. (Physical-component tuples such as are views derived from receipts via a per-run cost model, and cost percentiles are percentiles of per-run cost.)
Disruption-Adjusted VerifyPrice
The percentiles of verification cost over the -weighted pooled distribution of per-run costs across physical disruption states, rather than the observed cost under benign conditions. A convenience summary; no red line or acceptance rule reads on it.
A resilient fleet has higher and lower whenever the -weighted saving in the disruption states outweighs the -weighted premium in the benign state. Writing for normal operation, let be the premium—the amount by which the resilient fleet’s benign-state cost exceeds the brittle fleet’s—and, for each , let be the saving—the amount by which the resilient fleet’s cost in state falls below the brittle fleet’s. Then the resilient fleet wins on the adjusted figure whenever . (For the pooled percentiles this holds as a first-order statement about location; the exact comparison is made on the pooled tuples themselves.) A brittle fleet optimised purely for spot cost reports an attractive headline number and carries the tail.
The are estimates and should be published as such, with their basis, rather than presented as measurements. An operator who can move by assertion can make any fleet look resilient; disruption-state probabilities are therefore governance parameters subject to the telemetry-capture constraints of §27: Risk Analysis & Failure Modes. Because operators may set self-flattering , cross-fleet comparisons use a common reference vector published by the observatory; an operator’s self-published may be shown alongside for context but is never used for cross-fleet ranking.
One further limit belongs beside the definition, because the mixture form invites a misreading it should prevent. Pooling fixes the arithmetic—the of the mixture is a genuine percentile—but it does not fix the weighting: a state assigned contributes fewer than five percent of the pooled runs, and its entire cost distribution can sit above the pooled without moving it. Resilience is a property of the tail conditional on the disruption, not of the pooled tail: a fleet can hold a flattering while its outage-state cost is catastrophic, if the assigned for that state is small enough. The thesis’s own treatment of capacity therefore declines expectation forms in the same situation — Delivered Verified Capacity is scenario max-flow/min-cut, with each scenario reported separately, rather than collapsed into a single weighted number (§14: Layer 0: Verifiable Machines & Energy). is accordingly a convenience summary for comparison across fleets, not a quantity any red line or SLO reads on. The load-bearing publication is the per-state vector itself, published state by state alongside the used, so that a skeptical reader can reweight with their own probabilities and see exactly where the summary flatters.
The Decision Rule
Priority ordering matters here, because “resilience” is exactly the kind of word that can be used to excuse blowing through a constitutional target.
Accept a benign-state resilience premium only if (i) every pre-declared disruption state’s VerifyPrice remains inside its per-state bound, and (ii) the pooled -weighted falls, and (iii) benign-state Layer 4 VerifyPrice remains inside the constitutional SLO band.
The terms are defined so the rule can be applied rather than admired. The per-state bound in clause (i) is the constitutional Layer 4 VerifyPrice SLO band multiplied by a published state multiplier , with for normal operation: verification in a curtailment or exclusion state is permitted to cost more than in the benign state, by a factor the constitution declares in advance and publishes beside the , and no more. The multipliers are governance parameters under the same change-disclosure rules as the SLO band itself. Clause (iii) reads on the Layer 4 VerifyPrice SLOs only—the constitutional cost band on verifying workload receipts. It does not read on Physical VerifyPrice (§19: Layer 4: Truth & Work), which is an audit-cost measurement with no SLO band; Physical VerifyPrice is published alongside as context and enters no clause of this rule. appears only in clause (ii) and only as a tie-breaker between fleets that have already passed (i) and (iii); a premium that improves the pooled figure while pushing any disruption state past its bound is rejected by clause (i) regardless of what the pooled figure says.
The final clause is not negotiable. Resilience is subordinate to the hinge: a fleet so hardened that ordinary users can no longer afford to verify has defeated the purpose of hardening it. Redundancy that breaches the SLO band is not insurance; it is the failure mode wearing insurance as a costume.
This gives the thesis a definite position on “resilience over efficiency,” worth stating plainly because the slogan travels widely and is usually asserted rather than priced:
-
A bounded, measurable premium that buys a large reduction in tail risk is acceptable, and should be visible in FCR data rather than hidden in operator margin.
-
An unbounded premium, or one that cannot be shown to reduce disruption-state cost, is not resilience. It is capital misallocation with a security narrative attached.
The FCR fields of §14: Layer 0: Verifiable Machines & Energy, aggregated as the sovereign optionality index of §14: Layer 0: Verifiable Machines & Energy, are precisely the instrument that distinguishes the two cases. Without them, “we are building resilience” is unfalsifiable. With them, it is a number an allocator can check.
Where this sits in the energy-security literature.
The trade-off named here — redundancy and optionality priced against the cost of carrying idle capacity — is the central, long-standing question of energy systems reliability economics: the “resource adequacy” debate over how much excess capacity a grid should carry, and who pays for it. That literature (regulatory and academic, from NERC reliability standards [NERC annual] through the capacity-market literature) has spent decades converging on the same conclusion this section reaches by a shorter route: resilience that is not metered becomes rent. The thesis does not import the literature’s models, and its FCR/DVC instruments are its own; but the position taken here is not contrarian, and the slogan it prices is the same slogan that literature prices. Analyst commentary used elsewhere in this Part (Doomberg, in Sources [Doomberg 2026a]) supplies the scenario framing; the regulatory economics supplies the skepticism.
Operational Patterns: Profiles, Upgrades, and Failure Modes
Layer 0 is not static; hardware evolves, breaks, and gets deprecated. We need patterns for living with that churn.
Hardware Profiles and Workload Binding
Each canonical workload in Layer 4 is associated with one or more acceptable hardware profiles . Profiles define:
-
Minimum performance characteristics (to keep VerifyPrice in target bands).
-
Acceptable side-channel leakage budgets.
-
Attestation/sampling histories.
-
Known caveats (e.g., “avoid profile H3 for workloads with secret inputs; leaks are too strong”).
When PaL compiles a workload or the router assigns work, it can target specific profiles, diversify across profiles, or refuse high-sensitivity workloads to marginal profiles. This is how Layer 0 informs the market rather than hiding under it.
Upgrades and Deprecations
Hardware ages; bugs and backdoors are discovered; fabs change hands. Layer 0 needs clear life-cycle rules:
Onboarding:
New profiles go through a probation period with extra sampling and conservative Work Credit weights.
Deprecation:
When a profile is compromised or obsolete, higher layers stop accepting new Work Credits minted from it, risk-flag existing credits, apply collateral haircuts, or impose prospective ineligibility, and publish an incident report at Layer 6.
Migration:
Proof factories and corridor operators need technical paths to migrate workloads off deprecated profiles without massive downtime.
In monetary terms, this is the hardware analog of a bond downgrade: transparent, describable, and priced, rather than silently swept under the rug.
Non-Discretionary Downgrade Rules
To prevent “ex post discretionary default” critiques, deprecation and haircut decisions follow a predictable severity framework, not ad hoc governance.
| Severity | Definition | Examples |
|---|---|---|
| S0 (Watch) | Potential issue; under investigation | Anomalous side-channel readings; unverified third-party report |
| S1 (Warning) | Confirmed issue with limited impact | RNG bias below 1%; isolated firmware bug |
| S2 (Critical) | Confirmed issue with systemic impact | Backdoor in >5% of sampled units; key extraction demonstrated |
| S3 (Emergency) | Active exploitation or catastrophic risk | Widespread key compromise; vendor collusion confirmed |
Severity levels for hardware profile issues.
Process guarantees:
-
Evidence threshold: S1 requires independent lab confirmation; S2 requires reproducible demonstration; S3 requires active exploitation observed.
-
Multi-party decision: Severity escalation requires sign-off from 3 of 5 designated hardware security reviewers.
-
Appeal process: Profile sponsors can challenge findings within 14 days.
-
Sunset, not confiscation: Even at S3, existing credits remain eligible at 75% of protocol-recognized collateral value, subject to the issuance bound of §14: Layer 0: Verifiable Machines & Energy: if removing the profile’s capacity from DVC leaves claims outstanding above the bound, the excess is impaired under the published retirement rules rather than carried. This is a statement about the protocol’s own accounting, not a guarantee about market price: no protocol can promise what its asset trades for after a catastrophic hardware compromise, and this document makes no such promise.
-
Transparency: All severity determinations are published.
PQ and Cryptographic Agility
Some Layer-0 assumptions are about cryptography, not just silicon: signature schemes in ROMs, hash functions in hardware accelerators, and RNG primitives.
Layer 0 insists that hardware and firmware expose enough configurability to migrate to post-quantum or new primitives without throwing away entire fabs. Hardware profiles document cryptographic agility (e.g., “can switch hash from X to Y via firmware; signature scheme fixed”).
Stress Tests for Layer 0
Every claim in Layer 0 should map to a testable stress scenario:
| Claim | Stress Test |
|---|---|
| Profile H is honest within bounds X | Feed adversarial inputs; measure deviation from spec; decap sample devices |
| Sampling methodology detects tampering | Red-team: insert known-bad units into supply; measure detection rate |
| RNG entropy meets threshold | Run NIST SP 800-90B entropy-source estimators [Turan et al. 2018] on the raw noise source (min-entropy, not statistical randomness); run Dieharder/TestU01 on the conditioned output only; inject synthetic bias; verify detection |
| Power telemetry is honest | Cross-check metering with grid records; test resilience to meter spoofing |
| Migration from H1 to H2 works | Simulate H1 deprecation; measure latency and failure rate during migration |
Layer 0 stress tests.
If a stress test fails, Layer 0 degrades visibly: profiles are flagged, Work Credits tied to them are risk-flagged and may face prospective ineligibility, and Layer 6 publishes an incident report.
What Layer 0 Exports to Higher Layers
Higher layers consume a small set of artifacts and APIs:
-
Hardware profiles (HIDs). Compact identifiers + dossiers describing profile properties, sampling history, and current status.
-
Attestation receipts. Machine-level statements binding device profile, firmware hash, measurement nonce/time.
-
Power and health telemetry. Streams of power usage, failure rates, and uptime patterns.
-
Incident and status flags. Signals like “Profile H3 compromised; do not accept new work.”
New here? Start with the one-minute version.
Tip: hover a heading to reveal its permalink symbol for copying.