thot market
A market for research flow
Don’t get distilled for free.
Whitepaper · Research, payment and participation · 18 September 2026
This paper describes the proposed research market and launch terms. Current availability is shown in the app’s release status.
AI makes expertise more productive. It may also shorten the time for which that expertise remains scarce. A person can use a model to do better work today while producing the examples that help a future model do that work without them.
The resulting record can be valuable: the context an expert supplies, the mistakes they catch, the alternatives they reject, and the evidence that finally changes their mind. We call this research flow, or thot flow. Its value comes from the judgment it contains and the uses a buyer can find for it.
thot market gives people a way to offer that research for sale. Contributors choose which traces to release. Buyers pay for specified access and rights. A finite acquisition reserve helps establish the market before independent demand is reliable. THOT is the payment currency. A disclosed service tariff pays for delivery and acquisition; the contributor receives the remainder.
The proposition is simple: your research can earn twice—once through what it helps you do, and again when someone pays to learn from it.
1. From expertise to an asset someone can buy
A useful trace might document a programmer diagnosing a difficult bug, a researcher testing a hypothesis, or a trader investigating a company. A trade expresses a conclusion; the research trace records how that conclusion was reached. This is the connection between a market for research and the trading activity around Robinhood Chain, the selected launch network.
Potential buyers include model developers seeking training or evaluation material, researchers studying a workflow, and agents looking for examples of a task solved well. Different buyers want different evidence. A conversation’s length, token count or apparent sophistication is not enough to determine its price.
An assay evaluates a trace against a stated purpose. The initial buyer-facing property check has two inputs: a workflow category and a minimum turn count. It compares them with a simple keyword/category routing label and the recorded turn count, and returns those values and whether they match. It does not read the conversation to judge quality, recommend a purchase or calculate a fair price. The label is a fallible routing hint, not evidence that the trace contains useful coding work. Content evaluation, provenance and outcome evidence can support richer assays later; comparable-sale estimates are a separate calculation.
A trace need not have sold to receive an estimate. The comparison uses completed purchases of research with similar workflow, provenance and conversation length to show a range of observed prices. It uses the past 90 days and requires at least three distinct contributors. Each contributor’s median price has equal weight, so one prolific seller cannot dominate the estimate. The displayed gross price is before the applicable service tariff; similar properties do not establish identical quality or licence rights. It reports how many different contributors support the comparison and when those transactions occurred. Sparse cohorts show “not enough comparable sales,” rather than an invented value or zero. Aggregate comparisons must meet a minimum cohort size and avoid exposing another contributor’s private work.
Treasury sampling prices and independent buyer prices are kept separate. A reserve-funded purchase at a contributor's asking price is evidence of that acquisition, not evidence that an outside buyer values every similar trace at that price. Estimated income also depends on whether a trace sells: a sale-price comparison alone cannot establish a daily earnings forecast.
A separate market-activity view reports observed sell-through and mean seller proceeds during a trace’s first 30 days on sale, including unsold traces at zero. It uses completed independent purchases and deduplicates relistings. It requires a complete confirmed index and a mature cohort with at least 20 traces, three contributors and three buyers. A new market has no such history. This market-wide observation is not a personalized forecast and does not replace the comparable-sale estimate above.
The market distinguishes three amounts:
| Amount | What it means |
|---|---|
| Estimated trace value | An appraisal of possible future licensing value. It is not money owed or available to withdraw. |
| Protocol-sponsored proceeds | Payment for research acquired with the finite bootstrap reserve. This is subsidized demand. |
| Independent sale proceeds | Payment from an external buyer licensing the research. This is evidence of customer demand. |
A funded offer is stronger evidence than an estimate, but its payment remains pending until settlement. Protocol purchases and external purchases produce real token proceeds under the same settlement rules; they are reported separately so that subsidy is visible. A protocol purchase is counted once, not again as an additional reward.
The private portfolio separates independent sale proceeds, treasury purchases, pending allocations and current claimable funds. Referral earnings are grounded in finalized receipts; when a withdrawal combines several credit types, the interface shows pooled payment and bounds on its referral component instead of inventing an exact attribution. Public highest-earner and largest-buyer tables require an explicit pseudonym opt-in and exclude treasury purchases, pending sales and refunds. Opting out keeps the dashboard identity private, but cannot hide transactions already public onchain.
The vault also separates actual encrypted storage usage, including source recordings and release copies, from preview metadata sizes. The latter are not a measurement of all provider traffic. Source/model and private/listed/sold status are visible to the contributor without publishing the underlying conversation.
The aim is to make the value of ordinary research visible and realizable. Uploading a trace, passing an assay or holding THOT does not by itself earn a payment.
2. A purchase, from offer to payment
A contributor connects a provider key and authorizes a connection-level sale policy once: the licence, THOT asking-price floor, minimum seller share, eligible public metadata, and expiry. Subsequent completed, eligible recordings from that connection are automatically listed. The contributor does not sign each listing. An enclave-held delegate signs each specific release under the standing policy; the market contract checks the seller’s policy signature and the delegate’s release signature. The delegation cannot spend the contributor’s wallet assets. The initial connection policy lasts 30 days and permits at most 10,000 distinct single-use sale authorizations. A contributor may instead import and explicitly list a historical conversation.
The contributor sets the asking price. A manual listing starts with an empty price field and requires an explicit THOT amount. Codex / Claude Code and OpenRouter connection forms start at an editable 100 THOT per completed trace; the signed policy supplies that price to subsequent automatic listings. This default is neither an appraisal nor a promised payment. Property checks and comparable-sale estimates do not change the asking price. A reserve buyer can buy an eligible selected release at its authorized price or skip it.
A buyer reviews the available description and evaluation evidence, then funds a purchase in THOT. The purchase must match the contributor’s authorized material, licence and price. It records the service tariff, direct-cost allocation, referral terms and exact net proceeds at funding. The signed connection policy protects the seller’s quoted retention floor; a higher tariff cannot silently lower it. An ordinary purchase’s enclave-signed review also binds the current tariff, so changing that tariff requires a fresh purchase quote. There is no second approval or per-purchase seller veto. Contributors can stop future unfunded sales, but cannot withdraw rights already purchased under their authorization.
Filtering before paying
An ordinary buyer receives no trace text before purchase. They can inspect public listing metadata and supported bounded properties attached to the exact release. Initial properties include capture source, requested and returned model identifiers when recorded, a simple workflow label, turn count, and explicitly attached credentials.
One implemented credential binds a trace to a narrow Robinhood fact: witnessed records contained a filled buy or sell of a named symbol within an absolute time window around the trace timestamp. The marketplace verifier checks the Appraiser signature and hardware evidence, and the marketplace binds the result to the trace content hash and licensed release. The ordinary buyer sees the bounded claim and release commitment, not the private signed package; this response does not enable independent signature verification or recomputation of the full release hash. The claim does not expose raw orders and does not establish P&L, Sharpe ratio, causality, account continuity, balance or complete history. The complete boundary and guided flow are in the trade-proof tutorial.
These properties answer typed questions; they do not allow an evaluator to summarize or reconstruct the hidden conversation. General buyer-supplied assayer agents require a sandbox, restricted output schema, query limits and a disclosed policy, and remain roadmap work. The complete licensed release becomes available only after payment.
The settlement sequence is:
- Authorize once. The contributor enrolls the specific release, licence and price for automatic qualifying sales.
- Fund and deliver. The full price enters escrow. The service matches it to the standing authorization and makes the licensed material available without asking the seller to return. If delivery has not been recorded within 48 hours of the automatic sale, the buyer can recover the full payment while the order remains in its accepted, undelivered state.
- Allow a dispute. The proposed launch terms give buyers 12 hours after recorded delivery to raise an eligible dispute. An open dispute prevents finalization.
- Receive the proceeds. After that window, the service finalizes an undisputed sale and sends the seller’s allocation to their registered wallet. Eligible referral and protocol allocations remain claimable by their recipients. Anyone may trigger payment to the rightful recipient; they cannot redirect it. Manual claiming remains available if the service is delayed. No additional vesting applies to sale proceeds.
The normal target is delivery when the purchase is funded and automatic payment to the seller’s wallet after the proposed 12-hour filing window. The clock starts when delivery of the committed release is recorded, not at upload or payment. Delayed delivery, an open dispute or delayed finalization can extend the wait. Existing principal locks follow their own expiry and remain separate from sale proceeds.
The quoted token price and payout split stay fixed for that offer. A dollar reference is informational: it does not promise a dollar redemption value. Buyers may use THOT they already hold or acquire it from the market. The acquisition program uses its prefunded reserve. Neither route mints tokens, and automatic conversion from stablecoins is outside this design.
A buyer or the designated delivery operator can acknowledge delivery. That acknowledgment establishes that the committed material is available; it does not prove that the buyer read it, found it useful or verified its origin. The filing clock does not wait for the buyer to open or download the release. Once delivery is acknowledged, the undelivered-order timeout refund is unavailable; there is no separate objective non-delivery challenge after that acknowledgment. This relies on the designated operator recording availability correctly. The subjective complaint route below has separate eligibility terms.
Subjective complaints require the buyer to meet the reviewed independent-purchase eligibility terms disclosed before funding. Treasury purchases cannot use this route; refunded, unreviewed and other unsettled purchases do not count toward eligibility. Under the proposed launch terms, an eligible buyer files within 12 hours of recorded delivery, freezing all quoted allocations. The seller has 24 hours to submit an encrypted response and may separately sign a transaction to finish that period early after responding. Otherwise the full 24 hours remains. Non-conflicted DAO reviewers then have up to seven days to decide under the published reviewer threshold. A buyer win returns 50% of the total escrowed payment to the buyer and permanently sends the other 50% to the canonical dead address; the seller, referrer and protocol receive zero. An uphold vote releases the original split. If no outcome reaches the configured threshold by the deadline, the original sale is upheld. There is no v1 appeal.
For new sale authorizations, the contributor’s signed licence permits a non-conflicted governance reviewer to inspect the exact purchased release during an opened onchain dispute, before its review deadline. The application verifies current reviewer membership, the case and its commitments, then audits the read. It does not disclose other traces, original source captures, provider credentials or private brokerage proof packages. Full text and private reasons are encrypted at rest and visible only to authorized case participants; commitments, votes, outcome and amounts are recorded onchain. Existing signed licences are not broadened retroactively: cases without this permission use their submitted complaint and response. This adjudication permission is separate from optional treasury sampling.
The initial access term is 30 days from the automatic sale. Committed copies remain available for that term even if the original private source is deleted; they are then purged. This access period is separate from the payment dispute period. Deleting a source or ending access cannot recall a copy the buyer already downloaded.
Starting with paid samples
Early price discovery begins with separately authorized treasury inspection. A contributor may opt eligible traces into the acquisition program or sell normally without joining it. For every 20 new unique eligible traces from one opted-in contributor, the service forms a stable group, selects one complete approved release uniformly, and persists that selection. Nineteen traces produce no selection; 20 produce one; 40 produce two. Refreshing, reconnecting, reenrolling or using another reserve-reviewer wallet cannot redraw the sample.
All three configured reserve buyers see the same selected release. The contributor’s standing treasury consent identifies the covered sources, complete release, recipients, duration and revocation boundary. Inspection does not guarantee a purchase and grants no training or redistribution right. If a reserve buyer purchases it, the wallet signs one transaction and pays gas. THOT moves directly from the reserve vault into purchase escrow; the buyer never receives an unrestricted campaign balance in their own wallet.
A campaign is an onchain spending permission with its own budget, start, end and release schedule. The selected concurrent-campaign design lets each authorized buyer choose a campaign and make purchases within its available allowance. It does not appraise traces, interpret natural language or require anyone to spend the allowance. Governance controls campaign and buyer permissions; those controls do not bypass spending ceilings or purchase settlement clocks. The offchain worker handles listing, delivery and settlement, while the human buyers choose acquisitions. A quality assessment after inspection can guide the next purchase. Arbitrary uploaded assayer agents remain a later capability.
3. THOT pays for research; useful participation earns revenue
Buyers pay the posted THOT price. A low balance beyond the payment itself does not exclude a buyer or add a membership surcharge. Contributors receive the price less a disclosed service tariff. Introducing a contributor can earn a direct referral payment when independent purchases actually settle.
The v0 choice: lock THOT
Contribute useful traces. Lock THOT to qualify for additional participation benefits. This is the selected v0 direction. A liquid wallet balance does not satisfy the lock; the participant commits actual THOT to a non-transferable custody position. Transferable participation is deferred to a later design.
Locked principal remains the participant’s property and is unavailable until its stated expiry. It cannot be spent on acquisitions or marketplace operations. Sale proceeds remain separate: earning and withdrawing a trace payment does not require unlocking principal. Any additional funded distributions must likewise have their own withdrawal terms, without consuming the locked principal.
The minimum amount, duration, contribution requirements, benefit formula and funding allocation still need a published schedule. Custody locking exists, but the current settlement tariff does not yet grant a lock benefit. Reward-bearing enrollment will open only after those terms and their funding are implemented. No APY, seller tier or share of future revenue is specified by this decision. Existing locks retain their original expiry and withdrawal rights.
This selects an actual THOT-deposit requirement, distinct from the earlier proposal’s non-transferable earned participation. The earlier proposal did not itself define a THOT staking schedule. Any future-surplus right still requires separate terms; holding or locking tokens alone does not establish a claim on marketplace revenue.
A service tariff quoted before funding
Each purchase quote discloses the THOT price, service fee, direct-cost allowance, any eligible referral and exact contributor proceeds. The fee supports delivery and marketplace operations. The production tariff will be published before purchases open.
contributor proceeds = posted THOT price − disclosed service fee
net service contribution = service fee − quoted direct-cost allowance
eligible direct referral = 20% of net service contribution
protocol receipt = service fee − referral
Integer calculations use token base units, with referral amounts rounded down. A quote below its service fee is rejected. Each automatic-sale authorization also has a minimum seller-retention floor, so the contributor can reject uneconomic future terms without returning for every sale.
The quote and funded receipt commit the exact tariff. Governance can publish prospective changes, but previously funded proceeds cannot be repriced; later operating overruns remain the operator's cost. No discretionary cost is inserted after settlement. Ordinary executable reviews become invalid when their tariff changes. Standing seller authorizations preserve at least their signed retention floor, even for reserve purchases.
Referral attribution and payment
A contributor registers one direct referrer before any accepted sale. Attribution is immutable, one-level and cannot be attached to earlier offers. It does not require the referrer to buy or lock THOT.
The first reviewed external order must be funded within 90 days after registration. The referrer’s own purchase neither activates this clock nor earns a referral payment. Its funding timestamp starts a 365-day referral window. Later orders funded within that window freeze the applicable terms; payment follows successful settlement, not forecast lifetime value. An order that is canceled or refunded pays no commission. Its funding may start the activity clock, but cannot create earnings.
A qualifying direct introducer receives 20% of net service contribution, after the quote's fixed direct-cost allowance. There is only one acquisition pool per purchase. Treasury buying, unreviewed purchases, self-dealing, related-party activity, reimbursements and duplicate subsidies do not create eligible referral income. The contract enforces its address-level exclusions and reviewed-purchase requirement; independence review remains necessary because separate wallets do not prove separate economic actors.
The referral is paid from one finite service-fee allocation. It does not add another charge to the buyer or reduce the contributor’s quoted proceeds.
What an eventual financing product would need
A buyer prepayment could fund delivery earlier and earn a discount based on the timing and risk of that capital. Such an arrangement would need explicit delivery, repayment and risk terms. Purchase escrow reserves the price for its settlement obligations; it does not lend that money to the operator.
If the participation benefit includes a share of network surplus, its rights, eligible denominator and funded distribution policy must be defined before activation. Distributions can use only realized surplus after contributor payments, referrals, delivery costs and other obligations. Withdrawing an earned distribution need not surrender future participation. Selling or transferring that future participation is deferred; it is not a v0 feature or a promised automatic upgrade.
4. Bootstrapping a market before buyers are plentiful
The cold-start problem is straightforward: contributors have little reason to supply research before buyers exist, and buyers have little reason to arrive before useful research is available.
The protocol therefore acts as an early buyer with a finite budget. It buys specified rights to research, pays contributors and gathers evidence about what buyers value. Governance allocates separate campaign budgets and release schedules. Independent purchases remain evidence of customer demand; the selected campaign design does not require them before releasing acquisition allowance.
The intended transition is from protocol-assisted price discovery, through a mixture of protocol and customer demand, to a market supported by buyers.
Supply and acquisition reserve
The selected token supply is 1 billion THOT. The project purchases 500 million, or 50%, through the Pons creation flow and deposits them into a disclosed acquisition vault. The rest follows the launchpad’s curve and liquidity allocations. There is no investor or partner allocation in this plan. THOT/ETH is the selected primary trading pair.
The project supplies the ETH for its purchase. That ETH pays for token inventory; it is not still available as a second cash budget. The acquired THOT funds early research purchases. This is a disclosed project allocation, not independent retail demand.
A fixed-supply ERC-20 can support this mechanism. Separate contracts custody the reserve, lock participant principal and settle purchases by transferring existing tokens. The mechanism does not require token minting or a tax on ordinary wallet transfers.
Selected concurrent campaigns and first-campaign limits
Selected on 18 September and implemented for a new reserve contract. Hosted acceptance and deployment remain separate from this selection. The existing v11/v12 workspaces retain their earlier reserve contracts, purchase records and clocks; publishing these terms does not migrate those deployments.
| Parameter | Amount or rule |
|---|---|
| Total acquisition reserve | 500m THOT |
| First-campaign authority | 50m THOT of gross purchase commitments |
| Initially unallocated to that campaign | 450m THOT, available for separately authorized contribution campaigns |
| First-campaign duration | 90 days |
| Available immediately at its start | 555,555.555555555555555555 THOT, one ninetieth of the budget rounded down to token atoms |
| Remaining budget release | Linear over the 90-day term |
| Independent-demand prerequisite | None |
| Concurrent campaigns | Allowed, each with its own reserved budget and published terms |
| Governance | Any one of three owners, with no notice delay |
The full 500m reserve is dedicated to acquisition incentives for useful traces. Creating a campaign reserves its budget; it does not pay an organizer or contributor. Additional campaigns may overlap, with independently selected budgets, start times, terms of up to 365 days and upfront amounts no larger than their budgets. An existing campaign's budget and schedule do not change; governance can pause or close it and authorize another campaign from the remaining unallocated authority.
For budget B, upfront allowance U, duration T and elapsed time t while the campaign is open, cumulative released authority is U + floor((B − U) × t / T) in token atoms. The first campaign uses B = 50m, T = 90 days and the upfront amount above. This is a cumulative allowance: unused released authority carries forward within the campaign. The upfront amount is available at the start, and further authority accrues immediately afterward; it is not a fixed daily spending ceiling. Spending stops at the campaign's end. A budget is a maximum, not a promise that all of it will be spent.
Every purchase must fit the selected campaign's released but uncommitted allowance and the actual reserve balance. Across all campaigns, outstanding allocations cannot exceed available inventory, and outstanding allocations plus lifetime gross commitments cannot exceed 500m THOT. Closing or expiring a campaign releases only its unspent allocation for another governance decision. No qualifying offer means no spending.
Canceled or refunded purchases and returned treasury fees do not restore consumed gross authority. A treasury purchase has no referral payment; its retained fee returns to reserve inventory without renewing permission to spend it. New deposits also cannot raise the contract's 500m lifetime gross ceiling. Independent demand remains separately reported evidence of market traction, rather than a condition for these campaign purchases. Campaign budgets are denominated in THOT and establish no dollar redemption value.
5. What funds the business
The marketplace receives the quoted service tariff on an independent sale and pays a qualifying direct referral from its net contribution. The retained fee must cover direct service and operating expenses before it becomes profit.
The project also intends to collect creator fees from applicable Pons trading activity. The selected Pons configuration is a 1% additional creator-tax field, a 1% base fee, and native Buyback & Lock off, producing a 2% ordinary trading fee. Under the inspected Pons contract configuration, the allocation is 1.7% directly to the creator and 0.3% to Pons: the creator receives the additional 1% plus 0.7% of the base fee. These are selected settings, not evidence of an executed launch; the public deployment must identify its actual recipients and configuration.
Trading fees and research fees are separate. Trading fees may fund operations or a subsequently authorized acquisition budget; they do not automatically expand the first campaign, count as independent research demand or become dividends for holders. They apply through the relevant trading contracts, not to every THOT transfer or every trading venue.
The retained portion of a treasury purchase is an internal return of subsidy inventory. It is not customer revenue. Receipts become profit only after costs, and receiving THOT is not the same as realizing dollars.
6. The economic loop and its limits
Early purchases give contributors a reason to supply useful research. Useful research attracts independent buyers paying THOT. Contributors receive payment for useful work, and referrers have a reason to introduce productive suppliers.
That loop can create transactional token demand. It can also work in reverse. Contributors may sell their proceeds. Expiring locks return tokens to circulation. Buyers can spend existing holdings instead of making a new market purchase. Rising token prices make fixed-THOT offers and tariffs more expensive in dollar terms; falling prices reduce the dollar value of receipts.
The reserve transfers existing inventory. It does not create outside capital. The durable source of value is research that independent buyers continue purchasing after finite campaign support ends. Neither locking nor a budget formula guarantees a rising price.
A history of research sales could eventually help someone finance future work. A lender might advance money against expected trace income, but that requires lending capital, underwriting and repayment terms. An appraisal alone provides none of these. Borrowing against future research income is a possible extension, not part of this mechanism.
7. Custody, consent and trust
Three forms of custody remain separate: the acquisition reserve, buyer payment escrow, and participants’ locked principal. Seller principal cannot be spent on acquisitions, lent out or confiscated by the operator. Earned claims and funded offers are not reserve spending discretion.
The planned reserve has three disclosed authorized buyers. Each buyer can independently commit reserve funds only through permitted market purchases. The selected launch controller uses one-of-three approval with no governance notice delay: any one owner can create a separately funded campaign, change authorized buyers, replace the operator, revise future tariffs or pause acquisitions. Campaign creation still requires available reserve inventory and unallocated lifetime authority. This authority does not shorten a seller’s dispute or custody deadlines, reprice a funded purchase, or allow spending outside campaign limits. Contract addresses and the owner set will be published with the launch deployment.
The approval threshold is fixed in this controller. Moving to a different threshold or notice policy requires a reviewed successor and migration, not an undisclosed settings change. Application upgrades and their authority are separate from this financial controller.
Governance permissions do not remove a contributor’s principal lock, the delivery deadline, the dispute filing period or the seller’s response rights.
The controller governs contract actions; it does not hold shares of the trace decryption key. The vault encrypts objects with AES-256-GCM using application-derived keys inside the hosted environment, alongside the confidential VM’s encrypted disk. Chain permissions and application policy authorize a reviewer’s read. Approval of a contract action is separate from decryption.
Application upgrades carry a separate trust responsibility. The hosted vault uses Phala cloud KMS. A party able to authorize replacement application code remains trusted with vault data; application-level sampling caps cannot constrain malicious replacement code. Moving to a new KMS identity requires explicit data migration. See Phala’s governance workflow.
The new concurrent-campaign reserve has no unrestricted administrator withdrawal, arbitrary-call facility or successor-transfer function. Closing a campaign only releases its unspent allocation inside the same reserve. The older hosted reserve retains its separate 360-day sunset and successor rules; those rules do not migrate inventory into the new contract. Existing purchase escrow and principal locks remain separate liabilities.
Operators exercise judgment in acquisition selection, buyer independence review and delivery acknowledgment. Subjective disputes use the published reviewer threshold and remedy described above. Non-conflicted reviewers decide after the response period ends or the seller voluntarily waives its remainder. These authorities are operational trust assumptions even when budgets and payment conservation are enforced onchain.
Exact duplicate imports reuse the contributor’s existing record despite changed file wrappers or timestamps. Identical content from another account does not establish the same rights owner. The application separately reserves each acquisition against a private keyed fingerprint of normalized source content, before PII masking, and a commitment to the released content. The same source cannot receive a second funded treasury purchase through the application, even under another wallet, title, licence or trace-specific PII alias, or after a refund. Matching released content is also blocked, so editing excluded material does not reopen eligibility. The source fingerprint stays private; it does not replace the signed hash of the actual licensed release delivered to the buyer. The durable reservations and duplicate checks belong to the application; contracts enforce acquisition authority, signed release commitments and budgets. This is exact-content matching, not semantic fraud detection. Paraphrases, overlapping conversations and multiple identities still require review. Transferable buyer holdings also do not prevent wallet rotation; ordinary buyers still receive no trace excerpt before purchase.
Privacy and provenance answer different questions. Keeping material private does not prove its source. A captured provider interaction, an imported archive and an account-control proof support different claims. An enclave attestation can identify aspects of a deployed execution environment; it does not by itself establish authorship, account performance, research quality or a fair price.
Capture and authentication
Wallet sign-in proves control of an EVM account through a short-lived, single-use signed message bound to the application origin and chain. It creates a contributor session and links the payout wallet; it does not approve a transfer, authorize a trace sale or grant buyer or operator privileges. Operator wallets are configured explicitly. Privy supplies external-wallet connection and embedded EVM wallet onboarding. The application still verifies Sign-In with Ethereum and identifies the participant by their Robinhood EVM wallet, not by a second Privy-user identity. Privy login does not itself grant sale permission; the connection-level policy is a separate, explicit signature.
The OpenRouter connection stores the contributor’s provider key encrypted and issues a separate revocable proxy credential. Chat Completions requests and received response content sent through that endpoint are recorded privately, including submitted history and tool calls. The contributor accepts this recording policy at connection time, without a prompt for every exchange. Inference remains billed to their OpenRouter account. With an active connection-level sale policy, completed eligible recordings are automatically offered at the connection’s selected THOT price. The contributor chooses the asking price; it is not an appraisal or promised reward. Existing private-only connections remain private until re-enrolled. Disconnecting stops new recordings; revoking the stream nonce onchain additionally invalidates already-prepared, unfunded delegated sales.
The listing and committed release identify the requested model and the model returned in OpenRouter’s response, with “not reported by provider” when that response omits it. These are captured routing and response metadata, not an independent verification of a provider’s model internals. Only activity routed through this endpoint is captured. Connecting a key does not retrieve its previous usage or conversations sent directly to OpenRouter elsewhere; previous messages included in a new request are recorded as submitted history. Provenance identifies operator-observed capture and does not by itself prove human authorship or an attested provider transcript.
The application records request identities durably and does not automatically resend uncertain inference calls. Reusing a completed request’s idempotency key returns the saved response. An interrupted request requires reconciliation rather than a silent paid retry. Revoking a connection stops new requests and removes the saved provider key; deleting a private trace removes its recorded source material subject to existing licensed-release obligations.
Account-linked research. Witnessed orders-and-instruments records can produce an Appraiser-signed positive-fill property for one symbol and bounded window, attached to one exact trace release. The verifier checks the signature, hardware evidence and release binding. The helper rejects paginated histories rather than presenting partial coverage as complete and currently supports at most 32 distinct instrument identifiers. This bounded property does not establish account performance or complete history.
Balance, P&L, Sharpe ratio, causal ordering, account continuity and complete-history coverage remain future predicates. Ordinary ChatGPT and Claude website history synchronization and unrestricted buyer-uploaded assayer agents are also roadmap work. CLI capture supports selected coding-client workflows; the app’s release status identifies supported capture and settlement paths. Connection-level sale authorization allows eligible completed recordings to auto-list after one setup signature. Existing private captures remain private.
Exact imported content and already-subsidized release hashes are checked for duplication. A private keyed fingerprint binds an exact OpenRouter credential to one wallet, even after disconnect. This does not establish that two different provider keys belong to different people, and ChatGPT/Claude account uniqueness is not yet verified. Wallet addresses alone are not Sybil resistance.
The worker is an offchain service. Its encrypted transaction journal commits the signed transaction before broadcast, resumes the same transaction after restart and checks canonical chain receipts before recording payment. Contract limits remain authoritative when the worker is offline. Hosting that service inside a TEE additionally requires verified application deployment and evidence binding; it is not established merely by this specification.
Roadmap: private appraisal for disputes and reserve purchases
The launch design keeps governance review of disputes and the separately authorized, stable one-in-twenty treasury sample described above. A future enclave appraiser could evaluate disputed releases and guide reserve purchases without exposing their text to human reviewers. This could eventually replace the DAO’s sampling access; it does not expand that access today.
The proposed appraiser runs an LLM inside the enclave under a committed model, prompt and workflow version. Its prompt can remain private while an attested receipt binds the policy version, purchased-release commitment, permitted inputs and result. Participants should be able to check that the same committed policy governed comparable cases. Model nondeterminism and policy updates must be disclosed; a matching commitment does not promise identical outcomes, a fair price or a correct judgment.
Before using such results to settle money, the protocol must define the appraiser’s authority, bounded outputs, failure and timeout handling, and the route for challenging an erroneous decision. Sensitive trace content and credentials must not escape through receipts or model outputs. This is post-launch work: there is no automatic appraiser verdict in the current dispute path, no deadline promised for replacing reviewers, and no retroactive change to funded purchases or their evidence permissions.
Appendix: accounting rules
Sale settlement
For gross funded price P, frozen service fee F and quoted direct cost C, use token atomic units:
N = F − C
seller = P − F
referrer = eligible ? floor(N × 2,000 / 10,000) : 0
protocol = F − referrer
The allocations sum exactly to P. Every treasury purchase sets eligible = false and its retained fee returns to the reserve without renewing spending authority. Refunds cancel all pending allocations. A subjective buyer win follows the 50% refund / 50% dead-address rule. Finalized claims are protected from later tariff, lock or licence changes and can be paid only once.
Concurrent campaign authorization
Use token atoms and seconds. For a campaign's budget B, upfront amount U, duration T, elapsed time t and gross commitments G:
released(t) = U + floor((B − U) × t / T) for 0 ≤ t < T
available(t) = min(max(0, released(t) − G), reserve balance)
Available authority is zero before the start, at or after expiry, while the reserve or campaign is paused, or after the campaign closes. For the selected first campaign, B = 50,000,000 × 10^18, U = floor(B / 90) and T = 90 × 86,400. No independent-demand variable enters this calculation.
Let A be the sum of all open campaigns' unspent allocations and L be lifetime gross commitments across the reserve. A newly created campaign must fit:
new budget ≤ max(0, min(reserve balance − A, 500,000,000 × 10^18 − L − A))
A funded purchase of gross amount g increases its campaign's G and reserve lifetime L by g, and decreases A by g. The charged commitment remains consumed even if that purchase later expires, is canceled or refunds. Closing or expiring a campaign decreases A only by its remaining B − G; it does not reduce L or transfer inventory to a wallet. Returns and donations never increase the 500m lifetime limit.
After expiry, no new purchases use that campaign. Already funded purchases retain their authorized terms, and all existing delivery, dispute, refund and claim obligations continue. Unallocated inventory needs another campaign authorization. Neither token price nor an appraised trace value independently authorizes spending. These formulas describe the new selected reserve; older hosted campaigns keep their original implementation.
Captured text retains available system/developer context, tool definitions, calls and outputs, alongside requested and returned model identifiers when recorded. Imported model labels are user-supplied, rather than provider proof; missing identifiers remain unknown. Release preparation masks credential-like secrets and selected personal identifiers. It does not deliberately remove all technical context. The original received bytes stay in the private vault; unsupported binary or multimodal payloads are not automatically included in the text licence. OpenAI Privacy Filter is a possible local detector; it is not the filter currently deployed by this application.
