Back to thot marketWhitepaper

thot market

A market for research flow

Don’t get distilled for free.

Whitepaper · Quoted-cost testnet policy · 17 September 2026

This paper describes the research market and the selected testnet policy. It adopts the cost-accounting and direct-referral rules from the newer first-principles proposal. Test tokens have no monetary value; the public THOT token has not launched. Financing and residual-network claims remain separate proposals, not funded entitlements.

AI makes expertise more productive. It may also shorten the time for which that expertise remains scarce. A person can use a model to do better work today while producing the examples that help a future model do that work without them.

The resulting record can be valuable: the context an expert supplies, the mistakes they catch, the alternatives they reject, and the evidence that finally changes their mind. We call this research flow, or thot flow. Its value comes from the judgment it contains and the uses a buyer can find for it.

thot market gives people a way to offer that research for sale. Contributors choose which traces to release. Buyers pay for specified access and rights. A finite acquisition reserve helps establish the market before independent demand is reliable. THOT is the payment currency. A disclosed service tariff pays for delivery and acquisition; the contributor receives the remainder. Holding or locking tokens does not change the tariff or create income.

The proposition is simple: your research can earn twice—once through what it helps you do, and again when someone pays to learn from it.

1. From expertise to an asset someone can buy

A useful trace might document a programmer diagnosing a difficult bug, a researcher testing a hypothesis, or a trader investigating a company. A trade expresses a conclusion; the research trace records how that conclusion was reached. This is the connection between a market for research and the trading activity around Robinhood Chain, the selected launch network.

Potential buyers include model developers seeking training or evaluation material, researchers studying a workflow, and agents looking for examples of a task solved well. Different buyers want different evidence. A conversation’s length, token count or apparent sophistication is not enough to determine its price.

An assay evaluates a trace against a stated purpose. The initial buyer-facing property check has two inputs: a workflow category and a minimum turn count. It compares them with a simple keyword/category routing label and the recorded turn count, and returns those values and whether they match. It does not read the conversation to judge quality, recommend a purchase or calculate a fair price. The label is a fallible routing hint, not evidence that the trace contains useful coding work. Content evaluation, provenance and outcome evidence can support richer assays later; comparable-sale estimates are a separate calculation.

A trace need not have sold to receive an estimate. The comparison uses completed purchases of research with similar workflow, provenance and conversation length to show a range of observed prices. It uses the past 90 days and requires at least three distinct contributors. Each contributor’s median price has equal weight, so one prolific seller cannot dominate the estimate. The displayed gross price is before the applicable service tariff; similar properties do not establish identical quality or licence rights. It reports how many different contributors support the comparison and when those transactions occurred. Sparse cohorts show “not enough comparable sales,” rather than an invented value or zero. Aggregate comparisons must meet a minimum cohort size and avoid exposing another contributor’s private work.

Treasury sampling prices and independent buyer prices are kept separate. A fixed sampling price is evidence of the program’s offer, not evidence that an outside buyer values every similar trace at that price. Estimated income also depends on whether a trace sells: a sale-price comparison alone cannot establish a daily earnings forecast.

A separate market-activity view reports observed sell-through and mean seller proceeds during a trace’s first 30 days on sale, including unsold traces at zero. It uses completed independent purchases and deduplicates relistings. It requires a complete confirmed index and a mature cohort with at least 20 traces, three contributors and three buyers. A new market has no such history. This market-wide observation is not a personalized forecast and does not replace the comparable-sale estimate above.

The market distinguishes three amounts:

Amount What it means
Estimated trace value An appraisal of possible future licensing value. It is not money owed or available to withdraw.
Protocol-sponsored proceeds Payment for research acquired with the finite bootstrap reserve. This is subsidized demand.
Independent sale proceeds Payment from an external buyer licensing the research. This is evidence of customer demand.

A funded offer is stronger evidence than an estimate, but its payment remains pending until settlement. Protocol purchases and external purchases produce real token proceeds under the same settlement rules; they are reported separately so that subsidy is visible. A protocol purchase is counted once, not again as an additional reward.

The private portfolio separates independent sale proceeds, treasury purchases, pending allocations and current claimable funds. Referral earnings are grounded in finalized receipts; when a withdrawal combines several credit types, the interface shows pooled payment and bounds on its referral component instead of inventing an exact attribution. Public highest-earner and largest-buyer tables require an explicit pseudonym opt-in and exclude treasury purchases, pending sales and refunds. Opting out keeps the dashboard identity private, but cannot hide transactions already public onchain.

The vault also separates actual encrypted storage usage, including source recordings and release copies, from preview metadata sizes. The latter are not a measurement of all provider traffic. Source/model and private/listed/sold status are visible to the contributor without publishing the underlying conversation.

The aim is to make the value of ordinary research visible and realizable. Uploading a trace, passing an assay or holding THOT does not by itself earn a payment.

2. A purchase, from offer to payment

A contributor connects a provider key and authorizes a connection-level sale policy once: the licence, THOT asking-price floor, minimum seller share, eligible public metadata, and expiry. Subsequent completed, eligible recordings from that connection are automatically listed. The contributor does not sign each listing. An enclave-held delegate signs each specific release under the standing policy; the market contract checks the seller’s policy signature and the delegate’s release signature. The delegation cannot spend the contributor’s wallet assets. The initial connection policy lasts 30 days and permits at most 10,000 distinct single-use sale authorizations. A contributor may instead import and explicitly list a historical conversation.

A buyer reviews the available description and evaluation evidence, then funds a purchase in THOT. The purchase must match the contributor’s authorized material, licence and price. It records the service tariff, direct-cost allocation, referral terms and exact net proceeds at funding. The signed connection policy protects the seller’s quoted retention floor; a higher tariff cannot silently lower it. An ordinary purchase’s enclave-signed review also binds the current tariff, so changing that tariff requires a fresh purchase quote. There is no second approval or per-purchase seller veto. Contributors can stop future unfunded sales, but cannot withdraw rights already purchased under their authorization.

Filtering before paying

An ordinary buyer receives no trace text before purchase. They can inspect public listing metadata and supported bounded properties attached to the exact release. Initial properties include capture source, requested and returned model identifiers when recorded, a simple workflow label, turn count, and explicitly attached credentials.

One implemented credential binds a trace to a narrow Robinhood fact: witnessed records contained a filled buy or sell of a named symbol within an absolute time window around the trace timestamp. The marketplace verifier checks the Appraiser signature and hardware evidence, and the marketplace binds the result to the trace content hash and licensed release. The ordinary buyer sees the bounded claim and release commitment, not the private signed package; this response does not enable independent signature verification or recomputation of the full release hash. The claim does not expose raw orders and does not establish P&L, Sharpe ratio, causality, account continuity, balance or complete history. The complete boundary and guided flow are in the trade-proof tutorial.

These properties answer typed questions; they do not allow an evaluator to summarize or reconstruct the hidden conversation. General buyer-supplied assayer agents require a sandbox, restricted output schema, query limits and a disclosed policy, and remain roadmap work. The complete licensed release becomes available only after payment.

The settlement sequence is:

  1. Authorize once. The contributor enrolls the specific release, licence and price for automatic qualifying sales.
  2. Fund and deliver. The full price enters escrow. The service matches it to the standing authorization and makes the licensed material available without asking the seller to return. If delivery has not been recorded within 48 hours of the automatic sale, the buyer can recover the full payment while the order remains in its accepted, undelivered state.
  3. Allow a dispute. The dispute window lasts one hour after recorded delivery. An open dispute prevents finalization.
  4. Receive the proceeds. After that window, the service finalizes an undisputed sale and sends the seller’s allocation to their registered wallet. Eligible referral and protocol allocations remain claimable by their recipients. Anyone may trigger payment to the rightful recipient; they cannot redirect it. Manual claiming remains available if the service is delayed. No additional vesting applies to sale proceeds.

The normal target is delivery when the purchase is funded and automatic payment to the seller’s wallet after the one-hour window. The one-hour clock starts when delivery of the committed release is recorded, not at upload or payment, and delayed delivery, an open dispute or delayed finalization can extend the wait. Any existing custody lock follows its own expiry, grants no earnings advantage under the current economics, and does not apply to sale proceeds.

The quoted token price and payout split stay fixed for that offer. A dollar reference is informational: it does not promise a dollar redemption value. Buyers may use THOT they already hold or acquire it from the market. The acquisition program uses its prefunded reserve. Neither route mints tokens, and automatic conversion from stablecoins is outside this design.

A buyer or the designated delivery operator can acknowledge delivery. That acknowledgment establishes that the committed material is available; it does not prove that the buyer read it, found it useful or verified its origin. The one-hour clock does not wait for the buyer to open or download the release. Once delivery is acknowledged, the undelivered-order timeout refund is unavailable; there is no separate objective non-delivery challenge after that acknowledgment. This relies on the designated operator recording availability correctly. The subjective complaint route below has its own spending threshold.

A subjective complaint is available only when the buyer's current reviewed, independent purchase plus prior finalized, reviewed, non-treasury purchases totals at least 10 million THOT. A first qualifying large purchase can be disputed; refunded, unreviewed, treasury and other unsettled purchases do not count. Treasury purchases cannot use subjective disputes. The eligible buyer must file within one hour of recorded delivery; opening a case freezes all quoted allocations. The seller has 24 hours to submit an encrypted response. The seller may separately sign a transaction to finish that response period early after submitting a response. Otherwise the full 24 hours remains. The three governance reviewers have seven days after voting opens to decide. On the current testnet, one non-conflicted reviewer’s vote is sufficient; the production governance design remains a separate decision. A buyer win returns 50% of the total escrowed payment, with no membership surcharge, to the buyer and permanently sends the other 50% to 0x000000000000000000000000000000000000dEaD; the seller, referrer and protocol receive zero. An uphold vote releases the original split. If no outcome reaches the configured threshold by the deadline, the original sale is upheld. There is no v1 appeal.

For new sale authorizations, the contributor’s signed licence permits a non-conflicted governance reviewer to inspect the exact purchased release during an opened onchain dispute, before its review deadline. The application verifies current reviewer membership, the case and its commitments, then audits the read. It does not disclose other traces, original source captures, provider credentials or private brokerage proof packages. Full text and private reasons are encrypted at rest and visible only to authorized case participants; commitments, votes, outcome and amounts are recorded onchain. Existing signed licences are not broadened retroactively: cases without this permission use their submitted complaint and response. This adjudication permission is separate from optional treasury sampling.

The initial access term is 30 days from the automatic sale. Committed copies remain available for that term even if the original private source is deleted; they are then purged. This access period is separate from the payment dispute period. Deleting a source or ending access cannot recall a copy the buyer already downloaded.

Starting with paid samples

Early price discovery begins with separately authorized treasury inspection. A contributor may opt eligible traces into the acquisition program or sell normally without joining it. For every 20 new unique eligible traces from one opted-in contributor, the service forms a stable group, selects one complete approved release uniformly, and persists that selection. Nineteen traces produce no selection; 20 produce one; 40 produce two. Refreshing, reconnecting, reenrolling or using another reserve-reviewer wallet cannot redraw the sample.

All three configured reserve buyers see the same selected release. The contributor’s standing treasury consent identifies the covered sources, complete release, recipients, duration and revocation boundary. Inspection does not guarantee a purchase and grants no training or redistribution right. If a reserve buyer purchases it, the wallet signs one transaction and pays gas. THOT moves directly from the reserve vault into purchase escrow; the buyer never receives an unrestricted campaign balance in their own wallet.

A campaign is an onchain spending permission with a start, end, cumulative authority, daily schedule and demand allowance. It does not appraise traces, interpret natural language or require the organizers to spend its allowance. Each of the three authorized buyers may make a purchase independently within the shared limits. A separate 1-of-3 testnet governor controls the reserve’s campaign and buyer permissions, with no governance notice delay. Any one listed owner can propose, approve and execute a permitted action. Campaign spending ceilings and purchase settlement clocks still apply. The offchain worker handles listing, delivery and settlement, while the human buyers choose acquisitions. A quality assessment after inspection can guide the next purchase. Arbitrary uploaded assayer agents remain a later capability.

3. THOT pays for research; useful participation earns revenue

Buyers pay the posted THOT price. A low balance beyond the payment itself does not exclude a buyer or add a membership surcharge. Contributors receive the price less a disclosed service tariff. Introducing a contributor can earn a direct referral payment when independent purchases actually settle.

The newer first-principles proposal makes an important correction to the earlier lock-tier design: principal sitting untouched in a vault is not spendable working capital. It therefore does not justify a financing discount. The current testnet removes the 30–95% seller tiers, referral lock tiers and holding-based buyer surcharge. A participant may retain an existing principal lock until its stated expiry, but it earns no fee reduction, interest or share of other contributors’ sales. The custody contract still has no early exit or administrator sweep.

A service tariff quoted before funding

For each individual purchase, let C be the disclosed direct service-cost allowance and O the allocated overhead allowance. The initial policy uses a 20% operating buffer on overhead and a maximum 20% direct-referral share of net service contribution:

service fee F = C + ceil[O × 1.20 / (1 − 0.20)]
             = C + ceil[1.5 × O]
net contribution N = F − C
contributor proceeds = posted price P − F
eligible direct referral = floor[0.20 × N]
protocol receipt = F − referral

Integer calculations use token base units. The fee is a fixed amount per purchased release, not a percentage tier based on wealth. This is a concrete individual-trace implementation of the proposal's cost-based tariff; its illustrative cohort prices are not universal trace prices. A quote below its service fee is rejected. Each automatic-sale authorization also has a minimum seller-retention floor, so the contributor can reject uneconomic future terms without returning for every sale.

The testnet calibration is deliberately small and denominated only in TESTTHOT:

Item Testnet amount per purchase
Direct service allowance C 0.01 TESTTHOT
Allocated overhead O 0.02 TESTTHOT
Net contribution N 0.03 TESTTHOT
Total service tariff F 0.04 TESTTHOT
Eligible direct referral 0.006 TESTTHOT
Protocol receipt with an eligible referral 0.034 TESTTHOT

A 1 TESTTHOT purchase therefore pays the contributor 0.96, the eligible referrer 0.006, and the protocol 0.034. Without a qualifying referral, the protocol receives the full 0.04. A 100 TESTTHOT purchase pays the contributor 99.96; the service tariff is still 0.04. These amounts exercise accounting and user journeys. They are not measurements of production costs, dollar prices, or a selected production margin.

Governance can prospectively replace C, O and the published cost-policy commitment. The quote and funded receipt commit the exact tariff. Previously funded proceeds cannot be repriced; later operating overruns remain the operator's cost. No discretionary cost is inserted after settlement. Ordinary executable reviews become invalid when their tariff changes. Standing seller authorizations preserve at least their signed retention floor, even for reserve purchases.

Referral attribution and payment

A contributor registers one direct referrer before any accepted sale. Attribution is immutable, one-level and cannot be attached to earlier offers. It does not require the referrer to buy or lock THOT.

The first reviewed external order must be funded within 90 days after registration. The referrer’s own purchase neither activates this clock nor earns a referral payment. Its funding timestamp starts a 365-day referral window. Later orders funded within that window freeze the applicable terms; payment follows successful settlement, not forecast lifetime value. An order that is canceled or refunded pays no commission. Its funding may start the activity clock, but cannot create earnings.

A qualifying direct introducer receives 20% of net service contribution, after the quote's fixed direct-cost allowance. There is only one acquisition pool per purchase. Treasury buying, unreviewed purchases, self-dealing, related-party activity, reimbursements and duplicate subsidies do not create eligible referral income. The contract enforces its address-level exclusions and reviewed-purchase requirement; independence review remains necessary because separate wallets do not prove separate economic actors.

The proposed four-level geometric alternative is not enabled. It needs a distinct-actor attribution policy; choosing it would divide the same finite acquisition pool rather than create four additional budgets. The direct rule is the simpler selected starting point.

What an eventual financing product would need

A genuinely usable buyer prepayment could fund delivery earlier and earn a discount based on the timing and risk of that capital. The proposal's approximately 1.55% example is conditional on its 90-day cash-flow assumptions. Current escrow reserves a purchase price for its settlement obligations; it does not lend that money to the operator. Neither an idle lock nor the current escrow therefore receives a prepayment-financing discount.

The separate model of earned cash and residual network units also leaves the participation right, denominator, transferability and retention policy open. It is not implemented as a token dividend, cash-redemption promise or borrowing facility. The existing token pays for research; future financial rights require an explicit funded design.

4. Bootstrapping a market before buyers are plentiful

The cold-start problem is straightforward: contributors have little reason to supply research before buyers exist, and buyers have little reason to arrive before useful research is available.

The protocol therefore acts as an early buyer with a finite budget. It buys specified rights to research, pays contributors and gathers evidence about what buyers value. Its maximum daily spending declines over time. Further subsidy increasingly depends on completed independent purchases.

The intended transition is from protocol-assisted price discovery, through a mixture of protocol and customer demand, to a market supported by buyers.

Supply and acquisition reserve

The selected token supply is 1 billion THOT. The project purchases 500 million, or 50%, through the Pons creation flow and deposits them into a disclosed acquisition vault. The rest follows the launchpad’s curve and liquidity allocations. There is no investor or partner allocation in this plan. THOT/ETH is the selected primary trading pair.

The project supplies the ETH for its purchase. That ETH pays for token inventory; it is not still available as a second cash budget. The acquired THOT funds early research purchases. This is a disclosed project allocation, not independent retail demand.

A fixed-supply ERC-20 can support this mechanism. Separate contracts custody the reserve, lock participant principal and settle purchases by transferring existing tokens. The mechanism does not require token minting or a tax on ordinary wallet transfers.

First-campaign limits

Parameter Amount or rule
Total acquisition reserve 500m THOT
Nominal first-campaign authority 50m THOT of gross purchase commitments
Reserve outside that authority 450m THOT
Starter allowance without independent demand 1m THOT gross
Additional demand allowance At most 1 treasury THOT per eligible independently spent THOT
Daily-budget half-life 180 days
Campaign duration 360 days
Budget period 24 hours

The 500m deposit is inventory, not permission to distribute it immediately. Every purchase must fit the current daily cap, remaining campaign authority, available demand allowance and actual reserve balance. No qualifying offer means no spending.

The declining daily schedule permits approximately 192,171 THOT gross in the first 24 hours, 25m over 180 days, and 37.5m over 360 days, if eligible research and independent demand support every day’s spending. The 360-day sunset ends the first campaign before the schedule could use its full nominal 50m authority.

Without independent buyers, gross purchases cannot exceed 1m THOT throughout the campaign. For n completed purchases under a constant tariff F, seller payments equal their completed gross price less n × F. Canceled or refunded commitments consume campaign authority but produce no seller payment. There is no lock-tier multiplier. Reaching the 37.5m gross ceiling requires at least 36.5m THOT of eligible independent spending, available in time to support those daily purchases.

Reserve demand admission requires a separate operator or governance decision after delivery and finalization. The settlement flag called “independent” records a reviewed non-treasury purchase; it does not prove different beneficial owners. The admission reviewer must reject affiliated, referrer-funded or reimbursed purchases. Ordinary purchases do not automatically expand reserve spending authority. An admitted purchase’s gross amount can be credited once. The buyer’s payment still settles to the seller, referrer and protocol: demand credit is permission to use separate reserve inventory, not a diversion of that payment.

Activation after the published start does not restart the curve; elapsed daily capacity is lost. Unused daily capacity expires. Canceled or refunded offers and returned treasury fees do not restore spending authority. This prevents the same tokens from being repeatedly recycled into a larger announced subsidy. A treasury purchase has no referral payment; the portion not allocated to its seller returns to the reserve without renewing the campaign’s permission to spend it.

Token trading volume, creator fees, loans, affiliated or reimbursed purchases and recycled subsidized purchases do not count as independent demand. The matching rule is denominated in THOT, not dollars. It establishes neither a dollar reserve nor a limit on what recipients can receive by selling tokens elsewhere.

5. What funds the business

The marketplace receives the quoted service tariff on an independent sale and pays a qualifying direct referral from its net contribution. At the test calibration, it receives 0.034 TESTTHOT after a 0.006 referral, or 0.04 without one. Direct service and operating expenses are still costs; a receipt is not profit merely because it is onchain.

The project also intends to collect creator fees from applicable Pons trading activity. The selected Pons configuration is a 1% additional creator-tax field, a 1% base fee, and native Buyback & Lock off, producing a 2% ordinary trading fee. Under the inspected Pons contract configuration, the allocation is 1.7% directly to the creator and 0.3% to Pons: the creator receives the additional 1% plus 0.7% of the base fee. These are selected settings, not evidence of an executed launch; the public deployment must identify its actual recipients and configuration.

Trading fees and research fees are separate. Trading fees may fund operations or a subsequently authorized acquisition budget; they do not automatically expand the first campaign, count as independent research demand or become dividends for holders. They apply through the relevant trading contracts, not to every THOT transfer or every trading venue.

The retained portion of a treasury purchase is an internal return of subsidy inventory. It is not customer revenue. Receipts become profit only after costs, and receiving THOT is not the same as realizing dollars.

6. The economic loop and its limits

Early purchases give contributors a reason to supply useful research. Useful research attracts independent buyers paying THOT. Contributors receive payment for useful work, and referrers have a reason to introduce productive suppliers.

That loop can create transactional token demand. It can also work in reverse. Contributors may sell their proceeds. Expiring locks return tokens to circulation. Buyers can spend existing holdings instead of making a new market purchase. Rising token prices make fixed-THOT offers and tariffs more expensive in dollar terms; falling prices reduce the dollar value of receipts.

The reserve transfers existing inventory. It does not create outside capital. The durable source of value is research that independent buyers continue purchasing as the subsidy declines. Neither locking nor a budget formula guarantees a rising price.

A history of research sales could eventually help someone finance future work. A lender might advance money against expected trace income, but that requires lending capital, underwriting and repayment terms. An appraisal alone provides none of these. Borrowing against future research income is a possible extension, not part of this mechanism.

Three forms of custody remain separate: the acquisition reserve, buyer payment escrow, and participants’ locked principal. Seller principal cannot be spent on acquisitions, lent out or confiscated by the operator. Earned claims and funded offers are not reserve spending discretion.

The current testnet campaign has three disclosed authorized buyers governed by a 1-of-3 controller. Each buyer can independently commit reserve funds only through permitted market purchases. Any one owner can execute campaign activation, buyer changes, operator replacement, tariff revisions, pause/unpause and other supported governance actions, with no additional governance notice period on Robinhood testnet. This is a small custom controller, not a Safe deployment. The owner set is explicit; the operator cannot spend outside the contract limits.

This expedited policy is restricted to the testnet deployment. The generic two-owner governance path remains tested separately; production governance and timelocks must be selected before a production deployment. Removing testnet governance delays does not remove a contributor's principal lock, the delivery deadline, dispute filing period or seller's response rights.

The controller governs contract actions; it does not hold shares of the trace decryption key. The vault encrypts objects with AES-256-GCM using application-derived keys inside the hosted environment, alongside the confidential VM's encrypted disk. Current chain permissions and application policy authorize a reviewer’s read. One signature does not decrypt a key share, and two signatures were never a threshold-encryption requirement.

CVM upgrades remain a separate, deferred migration. The hosted app continues using Phala cloud KMS and the existing deployment account. A future onchain-KMS design could give the three owners a one-signature Safe, later raising its threshold or adding a timelock. It is not active now. A signer able to authorize replacement application code remains trusted with vault data; application-level sampling caps cannot constrain malicious replacement code. A new KMS identity also requires an explicit data migration or fresh test environment. See Phala's governance workflow.

The reserve has no unrestricted administrator withdrawal or arbitrary-call facility during the campaign. After the 360-day sunset, governance may transfer remaining inventory to a same-token successor under a published policy commitment. The testnet's zero governance delay does not bypass that sunset. Existing purchase escrow and principal locks are separate liabilities and cannot be swept through this action.

Operators exercise judgment in acquisition selection, buyer independence review and delivery acknowledgment. Subjective disputes use the configured reviewer threshold and the fixed remedy described above. On this testnet, any one non-conflicted owner can decide after the response period ends or the seller voluntarily waives its remainder. These authorities are operational trust assumptions even when budgets and payment conservation are enforced onchain.

Exact duplicate imports reuse the contributor’s existing record despite changed file wrappers or timestamps. Identical content from another account does not establish the same rights owner. The application separately reserves each acquisition against a private keyed fingerprint of normalized source content, before PII masking, and a commitment to the released content. The same source cannot receive a second funded treasury purchase through the application, even under another wallet, title, licence or trace-specific PII alias, or after a refund. Matching released content is also blocked, so editing excluded material does not reopen eligibility. The source fingerprint stays private; it does not replace the signed hash of the actual licensed release delivered to the buyer. The durable reservations and duplicate checks belong to the application; contracts enforce acquisition authority, signed release commitments and budgets. This is exact-content matching, not semantic fraud detection. Paraphrases, overlapping conversations and multiple identities still require review. Transferable buyer holdings also do not prevent wallet rotation; ordinary buyers still receive no trace excerpt before purchase.

Privacy and provenance answer different questions. Keeping material private does not prove its source. A captured provider interaction, an imported archive and an account-control proof support different claims. An enclave attestation can identify aspects of a deployed execution environment; it does not by itself establish authorship, account performance, research quality or a fair price.

Capture and authentication

Wallet sign-in proves control of an EVM account through a short-lived, single-use signed message bound to the application origin and chain. It creates a contributor session and links the payout wallet; it does not approve a transfer, authorize a trace sale or grant buyer or operator privileges. Operator wallets are configured explicitly. Privy supplies external-wallet connection and embedded EVM wallet onboarding. The application still verifies Sign-In with Ethereum and identifies the participant by their Robinhood EVM wallet, not by a second Privy-user identity. Privy login does not itself grant sale permission; the connection-level policy is a separate, explicit signature.

The OpenRouter connection stores the contributor’s provider key encrypted and issues a separate revocable proxy credential. Chat Completions requests and received response content sent through that endpoint are recorded privately, including submitted history and tool calls. The contributor accepts this recording policy at connection time, without a prompt for every exchange. Inference remains billed to their OpenRouter account. With an active connection-level sale policy, completed eligible recordings are automatically offered at the connection’s selected THOT price. The interface proposes 100 THOT per trace as an editable asking price, not an appraisal or promised reward. Existing private-only connections remain private until re-enrolled. Disconnecting stops new recordings; revoking the stream nonce onchain additionally invalidates already-prepared, unfunded delegated sales.

The listing and committed release identify the requested model and the model returned in OpenRouter’s response, with “not reported by provider” when that response omits it. These are captured routing and response metadata, not an independent verification of a provider’s model internals. Only activity routed through this endpoint is captured. Connecting a key does not retrieve its previous usage or conversations sent directly to OpenRouter elsewhere; previous messages included in a new request are recorded as submitted history. Provenance identifies operator-observed capture and does not by itself prove human authorship or an attested provider transcript.

The application records request identities durably and does not automatically resend uncertain inference calls. Reusing a completed request’s idempotency key returns the saved response. An interrupted request requires reconciliation rather than a silent paid retry. Revoking a connection stops new requests and removes the saved provider key; deleting a private trace removes its recorded source material subject to existing licensed-release obligations.

Account-linked research. The first Robinhood outcome credential is implemented: witnessed orders-and-instruments records can produce an Appraiser-signed positive-fill property for one symbol and bounded window, and that property can be attached to one exact trace release. The integrated local acceptance test exercises the production verifier, release binding, THOT purchase and delivery using signed synthetic brokerage fixtures and Anvil. Andrew’s later dev handoff also demonstrates a fresh observed-ORCL proof purchase on his private prod7 staging; that is distinct from acceptance on thot.market’s public-testnet settlement deployment. The helper rejects paginated histories rather than presenting partial coverage as complete and currently supports at most 32 distinct instrument identifiers. A joined hosted run combining fresh provider evidence, approved deployed enclave identities and public-chain settlement remains an acceptance milestone.

Balance, P&L, Sharpe ratio, causal ordering, account continuity and complete-history coverage remain future predicates. Ordinary ChatGPT and Claude website history synchronization and unrestricted buyer-uploaded assayer agents are also roadmap work. The current capture CLI supports selected Codex and Claude Code workflows. Connection-level sale authorization allows future eligible completed recordings to auto-list after one setup signature. An actual Codex subscription session has passed the approved TEE recorder, automatic listing, a Robinhood-testnet purchase and exact licensed delivery. A real signed-in Claude Code subscription run remains unverified. Existing private captures remain private. The developer launch sheet records deployment-specific settlement and recovery evidence separately. A token holding alone never creates sale proceeds.

Exact imported content and already-subsidized release hashes are checked for duplication. A private keyed fingerprint binds an exact OpenRouter credential to one wallet, even after disconnect. This does not establish that two different provider keys belong to different people, and ChatGPT/Claude account uniqueness is not yet verified. Wallet addresses alone are not Sybil resistance.

The worker is an offchain service. Its encrypted transaction journal commits the signed transaction before broadcast, resumes the same transaction after restart and checks canonical chain receipts before recording payment. Contract limits remain authoritative when the worker is offline. Hosting that service inside a TEE additionally requires verified application deployment and evidence binding; it is not established merely by this specification.

Appendix: accounting rules

Sale settlement

For gross funded price P, frozen direct cost C and overhead O, use token atomic units:

N = O + floor(O / 2) + (O mod 2)
F = C + N
seller = P − F
referrer = eligible ? floor(N × 2,000 / 10,000) : 0
protocol = F − referrer

The allocations sum exactly to P. Every treasury purchase sets eligible = false and its retained fee returns to the reserve without renewing spending authority. Refunds cancel all pending allocations. A subjective buyer win follows the 50% refund / 50% dead-address rule. Finalized claims are protected from later tariff, lock or licence changes and can be paid only once.

Declining daily authorization

Let B = 50,000,000 THOT, H = 180 days, and d be the whole number of 24-hour periods since the published campaign start. For d = 0…359:

C(d) = floor[B × (1 − 2^(−d/H))]
daily_cap(d) = C(d+1) − C(d)

The continuous analogue is S(t) = S₀ × exp(−λt), with λ = ln(2)/H and S₀ = B × λ. The daily calculation is fixed in token base units.

Let G be all gross reserve offer commitments charged since campaign start, R be admitted independent purchase spending, and P₀ = 1,000,000 THOT. The amount available for a new commitment is:

max(0, min(
    remaining daily cap,
    B − G,
    P₀ + R − G,
    available reserve inventory
))

Each funded offer increases G and its day’s committed amount immediately, even if it later expires, is canceled or is refunded. Each independent purchase enters R at most once and must have finalized during the active campaign. Reviews for referral and independent-demand eligibility precede offer funding; admitting a finalized receipt to reserve demand credit is a separate review.

After sunset, no new campaign offers are funded. Already funded purchases retain their authorized terms, and all existing delivery, dispute, refund and claim obligations continue. Uncommitted inventory requires subsequent authorization. Neither token price nor an appraised trace value independently authorizes spending.

Captured text retains available system/developer context, tool definitions, calls and outputs, alongside requested and returned model identifiers when recorded. Imported model labels are user-supplied, rather than provider proof; missing identifiers remain unknown. Release preparation masks credential-like secrets and selected personal identifiers. It does not deliberately remove all technical context. The original received bytes stay in the private vault; unsupported binary or multimodal payloads are not automatically included in the text licence. OpenAI Privacy Filter is a possible local detector; it is not the filter currently deployed by this application.

Start with the idea.

The story behind a market for useful AI research.

Read the launch post