EXP-01---- traces committed---- incidents---- reproducibility---- bondedSolana devnet

EXP-01 / Condensation record for model output

Proof it thought.

Scroll to the record

Vapour / what the vessel is for

A vapour vessel never shows you the particle. It shows the trail the particle left, and that is enough to know it went through. Kortx commits the same kind of trail for an inference -- input hash, model fingerprint, sampling seed -- on Solana, at a verification tier that states its own limits.

Every track in the vessel above is one committed inference. Its shape is its tier.

  • Attested
  • Sampled
  • Proven
What each tier proves, and does not

Opacitythe state of the art

You are billed for a model you are not allowed to inspect.

An API answers. A field in the response says the output came from a GPT-4 class model. There is no procedure -- not a slow one, not an expensive one, not one available to enterprise customers under NDA -- by which you can check that field.

You are not being asked to trust a claim that is hard to verify. You are being asked to trust a claim that is structurally unverifiable, because nothing was ever recorded that a second party could compare against.

Every AI evaluation, every model card, every procurement decision and every safety review downstream of that field inherits the same gap.

HTTP 200 / response as delivered

Typical provider
model
gpt-4-class-0325Asserted
usage.total_tokens
18,442Billed
system_fingerprint
opaque, issued by the providerOpaque
temperature
not returnedAbsent
top_p
not returnedAbsent
weights_hash
no such fieldAbsent
seed
no such fieldAbsent
checkable evidence
none attachedAbsent

Five of those eight fields are the ones that decide whether the output could be reproduced. All five are missing, and the invoice does not wait for them.

Model substitution

A smaller checkpoint answers the request because it is cheaper to serve under load. The response header still names the model you paid for. Nothing in the payload changes shape.

Weight drift

A fine-tune ships, or the deployment quantises to int8 to fit more traffic on the same accelerators. Same model name, same version string, different weights, different answers.

Sampling change

Temperature and top_p move by a tenth. The distribution you evaluated against and signed off on is gone, and no field in the response records that it moved.

Log authorship

The provider writes the audit log, stores the audit log and decides how long the audit log is kept. The audited party owns the only record of the thing being audited.

A receipt is not proof of purchase when the seller writes it afterwards and keeps the only copy.

Every one of the four modes above leaves the payload byte-identical.

Tracethe residue of a computation

A vessel never shows you the particle.

In a cloud chamber the particle itself is far too small and far too fast to see. What you photograph is a line of condensed vapour along the path it took, and that line is enough: its length, its curvature in the field and where it stops tell you the charge, the momentum and the mass. Physics has proved the existence of things it cannot look at for a century by reading what they left behind.

Kortx records the same kind of residue for an inference. Four values, committed to Solana at the moment the output is produced, before it is delivered and before anyone knows whether it will be disputed.

Committed trace / read from the indexer

AttestedCommitted
input_hashSHA-256 over the exact prompt bytes, before any provider-side rewriting
output_hashSHA-256 over the exact bytes returned to the caller
model_fingerprintHash binding the loaded weights and the execution graph together
seedThe sampling seed, required to fall inside the seed_bound the plate declared
providerThe account that posted the bond behind this record
Cej5MPbp...ptjzRRQb
committed_atWritten before the output was delivered
2026-10-04 22:03 UTC
  1. Run

    The provider serves the request on the model registered to its plate, under the sampling parameters that plate declared.

  2. Commit

    The four values go on chain before the output reaches the caller. There is no edit path afterwards -- the account is the record.

  3. Re-run

    Anyone holding the input and the determinism parameters can execute it again. The plate published both, which is what makes this step possible at all.

  4. Compare

    The re-run output is hashed and set against the committed hash. Equal or not equal. There is no partial credit and no third answer.

Traces committed

94

Each one carries the four values above and can be re-run against them.

Providers recording

10

Accounts with at least one bonded plate on the instrument.

Indexer ok / read through slot 507,589,153 / 2026-10-05 03:07 UTC

Platethe declaration under bond

Reproducibility is a claim about parameters.

Before a provider commits a single trace it registers a plate: the model identity, the hash of the weights, the version string, and the exact conditions under which the output is supposed to be reproducible. The plate carries a bond, so the declaration costs something to get wrong.

If determinism is not pinned, there is nothing to reproduce. A model served at temperature 0.9 with a free-running seed answers the same prompt differently every time it is asked, and a re-run that disagrees with it proves nothing. A reproducibility claim from a plate that has not fixed these four values is not false -- it does not parse.

ProvesA public, bonded commitment to one model identity and one sampling regime, made before any traffic was served under it.

Does not proveThat the weights behind the registered hash are the weights actually loaded at request time. A registration is a declaration; the verification tiers are what test it.

A brushed steel plate with the model record stamped into its face
Plate record, as stampedspec E36FDBC8

Registered plate / read from the indexer

Active
model_idThe identity the provider serves under
kortx-devnet/exp-01-1791138587404
weights_hash32 bytes over the checkpoint that is meant to be loaded
versionProvider-assigned, moves whenever the deployment moves
2026-08-20
determinismFixed at registration. Without all four, no later comparison carries information
temperature
0.000
top_p
1.000
seed_bound
0
backend
cuda-12.4/sm90/vllm-0.6.3
bondHeld against this plate, slashable on an upheld mismatch
2,500 KORTX

A plate is public the moment it exists. Anyone can read the parameters a provider committed to and, later, hold a re-run against exactly those numbers rather than against whatever the deployment happened to be doing that day.

Plates registered

20

Each one is a separate declaration with its own bond behind it.

Bonded behind plates

40,500KORTX

At risk if a challenge against any of these plates is upheld.

Collimatethree tiers, three limits

Verified is not a word we use on its own.

One undifferentiated word is how this technology gets oversold. Kortx never ships it alone: every trace carries a tier, and every tier is published as a pair -- what it establishes, and what it leaves open. The second half is not fine print. It is the reason the first half can be believed.

  • Attested

    Cost: lowest

    ProvesA signed enclave ran the declared binary on the declared hardware.

    Does not proveThat the loaded weights match the registered hash. You are trusting the enclave vendor.

  • Sampled

    Cost: middle

    ProvesIndependently re-run inferences matched the committed output hash.

    Does not proveAnything about the inferences that were never sampled. The guarantee is statistical.

  • Proven

    Cost: highest

    ProvesA zero-knowledge proof of the covered operations, checkable by anyone.

    Does not proveWhole large models. Today only a stated subset of operations is provable, and the subset is published.

Cost rises with each row down. So does what the tier is prepared to claim.

What Kortx does not prove

  • Whole large models under zero knowledge

    Proving a full forward pass of a frontier-scale transformer is not practical today, at any price, with any published system. The proven tier covers a stated subset of operations and publishes the subset instead of implying the whole.

  • That an enclave vendor is honest

    An attested trace inherits the trust assumptions of the hardware vendor and its attestation service. If that root is compromised the attestation is worth exactly what the vendor is worth, and no amount of on-chain recording changes that.

  • Anything about an inference nobody re-ran

    The sampled tier is a statement about a population. It says nothing about one specific request unless that request was in the sample, and the record never pretends otherwise.

  • That an unrated provider is a bad provider

    A provider without enough re-run evidence is reported as unrated. It is not scored zero and it is not ranked last, because not measured and measured badly are opposite findings.

Network reproducibility

31.5%lower bound

Point estimate 53.5% over 21 comparisons (17.2 effective). Interval 31.5% to 74.1%. Confidence low.

Traces re-run

21

22.3% of everything committed so far.

Never re-run

73

These carry their tier and nothing beyond it. They are counted here rather than left out of the denominator.

Evidence is not spread evenly. 11 of 20 plates carry any re-run evidence at all, so the figure above describes those and does not describe the rest.

Read the full tier spec

Downstreamwho reads a trace

A trace is evidence for whoever has to trust the output.

The engineer who serves a model is not the only one who inherits the gap. A trading call, an autonomous agent, a one-off answer -- each reaches someone who has to decide whether to believe it, usually with less to go on than the engineer had. The same committed record answers all of them, because it is the one thing here that is not a claim.

  • A team serving a model

    Runs inference and wants the output to be checkable rather than taken on faith.

    Reads off the record
    Each response is committed with its input hash, output hash, model fingerprint and seed, under a plate the team has bonded. The output stops being the team's own word and becomes a record a second party can line up against.
    Not evidence of
    whether the model is any good. A reproducible output can still be wrong. Reproducibility is a property of the run, not of the answer.
  • An agent, and who holds it

    A project whose pitch is that an AI makes its calls, and the people holding the thing it issues.

    Reads off the record
    The project bonds a plate for the model behind the agent and commits a trace for what it decided, so a holder reads reproducibility off the board instead of off the project's own marketing. The tier travels with each output.
    Not evidence of
    what the agent did in the world, or that its decision was right. For a transformer the strongest tier does not apply, so the record states which tier it earned and stops there.
  • Someone acting on a call

    Deciding whether to follow a call an AI made, before the outcome is in.

    Reads off the record
    An output hash committed at a known slot fixes what was said while the result was still unknown. The record cannot be edited to match the outcome afterward, and its challenge history shows whether anyone re-ran it and what they got back.
    Not evidence of
    whether the call was good. A record that cannot be rewritten is tamper-evidence, not a forecast, and Kortx never dresses a committed call up as advice.
  • Someone handed an answer

    Received an output and would rather not take the provider's word for where it came from.

    Reads off the record
    A committed trace is a receipt. The four hashes and the seed are enough to re-run a deterministic open model and compare the result byte for byte, with no account at the provider and no permission asked.
    Not evidence of
    a closed frontier model you cannot re-run. The check holds where the model and its inputs are reproducible; where they are not, the attested and sampled tiers carry what evidence there is, and the record says so.

None of these ask the reader to trust Kortx. They ask the reader to check a record instead of a claim, and to read the tier that record carries before leaning on it. The tier is where the honest limit of each use is written down.

Read what each tier does and does not prove

Incidentthe challenge path

A challenged track winds back and runs again.

A record nobody can contest is a press release. Every committed trace on Kortx can be disputed by anyone willing to put a bond behind the dispute, and the dispute is settled by re-running the input rather than by asking the provider what happened.

  1. Open

    open_incident

    A challenger posts a bond against one specific trace. The bond is at risk from this instruction onward, so a challenge costs the person making it something real before anybody has looked at anything.

  2. Seal

    submit_rerun

    Registered verifiers execute the same input under the determinism the plate declared -- the same temperature, the same top_p, a seed inside the same bound -- and post a commitment to the result. Nothing readable is on chain, so the next verifier cannot skip the work by copying the last one's answer.

  3. Reveal

    submit_rerun

    Once the commit window shuts, each verifier publishes its output hash and the divergence it measured. The program checks the reveal against the commitment, then rules it a match or not under the plate's declared reproduction policy -- which is not always byte-for-byte equality, because GPU non-determinism would slash honest providers if it were.

  4. Rule

    resolve_incident

    The revealed verdicts are counted and the majority writes Upheld or Rejected. Too few reveals to make quorum voids the challenge instead of blaming anybody. An incident with no ruling is Pending and is displayed as Pending -- a deadline going by does not manufacture a verdict out of silence.

  5. Settle

    resolve_incident

    The same call moves the money. An upheld challenge slashes the plate bond of the provider, a rejected one forfeits the bond of the challenger, verifiers on the losing side forfeit part of theirs, and a share of everything collected is burned. Every direction costs somebody, which is the only reason any side stays careful.

A condensation track reversing through the vessel as it is re-run
The disputed track, running backwards.

Challenges filed

21

Still open

2

Counted toward neither outcome until a ruling exists.

Upheld

10

Slashed to date

31,340KORTX

Taken from bonds after a ruling, not a projection.

Ionizewhat the token is for

$KORTX is collateral, not a subscription.

Everything on this instrument is a claim somebody made. The token exists so that each claim has something behind it that can be taken away, which is the only mechanism here that does not depend on anyone being trustworthy.

  • Provider bond

    Posted by
    The provider, per plate, at registration
    What it secures
    The declared model identity and the determinism parameters that make a re-run meaningful
    What a slash means
    An upheld mismatch takes it
  • Verifier bond

    Posted by
    A node operator, once, before taking re-run work
    What it secures
    The honesty of every rerun_output_hash that node submits
    What a slash means
    A submitted re-run the rest of the network contradicts takes it
  • Challenge bond

    Posted by
    The challenger, per incident
    What it secures
    That filing a dispute costs something, so the queue is not free to flood
    What a slash means
    A rejected challenge forfeits it

Total bonded

115,993KORTX

Held across plates, verifiers and open challenges.

Behind verifiers

75,293KORTX

At risk if a submitted re-run is contradicted.

Behind open challenges

200KORTX

Committed by challengers on disputes that have not been ruled on.

Verifier nodes active

36

39 registered in total.

There is no yield on this page. No staking return, no emission schedule, no revenue share and no price target -- Kortx Labs publishes none of those and will not start. A bond is useful in exactly one way: it makes being wrong expensive. The only figure worth reporting about it is how much is genuinely at risk right now, and that number is above, measured rather than projected.

Held against the record

  • Registering a plate locks a provider bond before a single trace can be committed under it.
  • Taking re-run work locks a verifier bond, so a node that reports a convenient result has more to lose than to gain.
  • Filing a challenge locks a challenge bond, so the dispute queue costs something to fill and the provider is not defenceless against noise.

Trackwhat you can do now

Check something.

The instrument is public and nothing below asks for an account. The point of the whole design is that you do not have to take our word for any of it, so the useful next step is not to read more -- it is to go and disagree with a record.

Proof it thought.

94 inferences already carry a record on this instrument, across 20 registered plates. Every one of them can be re-run by somebody who does not trust us.

EXP-01 / Solana devnet