Q/01 / ARCHIVED V1 / DEVNET

V1 entropy & fairness

Historical discovery specification. New v1 mining is closed; existing records remain verifiable.

ARCHIVED V1 — HISTORICAL RECORDS ONLY

This specification describes the former discovery experiment. New generation is closed: POST /api/mine returns HTTP 401 without authentication and HTTP 410 for authenticated requests. Existing records and their deterministic verification rules are retained. The current continuous run has no discovery drop, collectible, NFT or token reward. Read the current run specification.

Unpredictable to the client; trusted at the server

Each v1 mine used node:crypto.randomBytes(32) on the server. A separate 32-byte nonce prevents record reuse. The Solana slot supplies network context; it is not treated as a secret or an unpredictable randomness beacon.

The engine hashes the raw entropy bytes with SHA-256 to produce entropyCommitment. HMAC-SHA256, keyed by those bytes, expands the mining context into a stream of 32-bit values. The context includes miner ID, wallet, nonce, slot, network and timestamp. Stream blocks use the domain QEE:measurement-stream:v1 and a sequential counter. Each big-endian word divided by 2³² supplies one Born-rule draw.

The canonical payload includes both the commitment and the resulting measurement statistics. The entropy bytes are not returned or stored in the public discovery record.

What the commitment proves

The commitment binds the record to a value the server hashed. It does not prove that entropy came from a fair source, that no attempts were discarded, or that the server selected inputs honestly. There is no public entropy-reveal or commit-before-draw protocol in v1.

VRF boundary

engine/entropy.ts defines an entropy-provider interface. A future VRF integration must validate the VRF proof and bind it to a specific request before supplying entropy. No VRF provider is connected or claimed in this deployment. Moving to a VRF is an explicit protocol change.