A deterministic, CPU-oriented, security-first consensus engine combining gradient-descent proof-of-work, per-block adaptive difficulty, and a real-time stability overlay. Designed for predictable issuance, controlled growth, and resistance to chaotic retarget behavior.
Instead of brute-force hash collision, ConvergenceX requires miners to produce verifiable convergence certificates using Transcript V2. Each attempt solves a tip-bound linear system via deterministic gradient descent, mixed with memory-hard scratchpad reads, and proves the solution lies in a stable convergence basin. Transcript V2 adds segment commitments and sampled round witnesses, enabling 11-phase verification at ~0.2ms (vs ~1ms in V1). Dataset v2 (SplitMix64) and Scratchpad v2 (SHA256-indexed) are independently indexable at O(1).
| CX_SCRATCH_MB | 4096 // 4 GB memory-hard scratchpad (+ 4 GB dataset = 8 GB total mining memory) |
| CX_N | 32 // linear system dimension |
| CX_ROUNDS | 100,000 // sequential gradient iterations |
| CX_LR_SHIFT | 18 // learning rate = 1/(2^18) |
| CX_LAM | 100 // regularization parameter (λ) |
| CX_CHECKPOINT_INTERVAL | 6,250 // rounds/16, Merkle-committed |
| Stability probes (k) | 1–20 // set by the active Equalizer profile (B0 = 4, E7 = 1, H35 = 20) |
| Refinement steps per probe | 1–20 // set by the active Equalizer profile (B0 = 4, E7 = 1, H35 = 20) |
| Scratchpad derivation | Sequential SHA-256 chain // epoch-keyed, mmap-friendly |
| Verification | Two-stage pipeline // cheap header check → full recompute |
| SbPoW (since #7,100) | Signature-Bound PoW // every valid block carries a signature from the miner identity key over the header — pools that delegate work without sharing the key are cryptographically self-defeating |
A valid ConvergenceX proof must demonstrate that the solution x_final
resides in a stable attractor basin. The verifier applies k deterministic
perturbation probes and checks two acceptance rules per probe:
| Local non-explosion | d(t+1) <= d(t) + margin_eff // per gradient step |
| Global contraction | d_final * c_den <= d0 * c_num + margin_eff // for large perturbations |
| Contraction ratio | 7/10 // epoch-invariant V1 |
| Perturbation scale | 1–2 // uniform in [-scale, +scale]; set by the Equalizer profile (E7–H4 = 1, H5–H35 = 2) |
| Stability LR shift | 20 // lr_shift + 2 (more conservative) |
ConvergenceX is intentionally hostile to fixed-function mining hardware. Unlike Bitcoin's massively parallel SHA-256d search, each ConvergenceX attempt combines a large memory working set, state-dependent memory access, a program derived from the previous block and 100,000 sequential rounds. The output of one round decides which memory the next round reads, so a single attempt cannot be split into independent pieces.
80-byte header ↓ SHA-256d nonce 0 ↓ SHA-256d nonce 1 ↓ SHA-256d nonce 2 … trillions of independent hashes / s (every nonce can be tried in parallel)
~8 GB working set ↓ round 1 → state ↓ round 2 → state (reads chosen by state) … ↓ round 100,000 stability basin (Equalizer profile) ↓ commit ≤ target (bitsQ)
A Bitcoin ASIC is extraordinarily efficient because its silicon is built for one narrow task: hashing 80-byte Bitcoin headers with SHA-256d while sweeping a nonce. It takes header fields in and only reports nonces that pass a target — it does not run programs, hold gigabytes of state or return intermediate results. ConvergenceX uses single SHA-256 as the link between memory-bound, state-dependent steps, so fixed-function Bitcoin SHA-256d ASICs cannot directly mine ConvergenceX, and Bitcoin TH/s cannot be converted into ConvergenceX attempts per second.
Difficulty is controlled by two complementary consensus mechanisms: bitsQ regulates the numerical target the commit must meet, and the Equalizer (43 profiles, E7–H35) regulates the structural work profile — how many perturbation probes and refinement steps a valid stability proof must survive. The profile index is bound into the commit, so a miner cannot use an easier profile than consensus requires.
This does not claim that specialized hardware can never be built. ConvergenceX is designed to substantially reduce the advantage of fixed-function ASIC specialization: a useful accelerator would have to implement the actual workload — low-latency random access to gigabytes of memory, the sequential dependency chain and the per-block program — rather than reuse conventional Bitcoin ASIC hashrate.
Sources (public, Neob1844/sost-core): src/pow/convergencex.cpp (attempt loop, state update, commit),
include/sost/params.h (CX_N, CX_ROUNDS_M, CX_SCRATCH_M, CASERT_PROFILES),
src/pow/casert.cpp (bitsQ, Equalizer).
SOST implements cASERT bitsQ as the primary hardness regulator within the unified cASERT consensus-rate control system. The bitsQ controller performs per-block difficulty adjustment in continuous Q16.16 log-space. Unlike legacy epoch-based retarget systems that wait for large windows, bitsQ corrects difficulty every single block. Historical: anchor-based exponential with 48-hour half-life (cap 6.25%, before block 1,450), then 24-hour half-life (V2, blocks 1,450–5,174) and 12.5% delta cap. Current (V5, block 5,175+): avg288-based — compares average of last 288 block intervals against 600s target, replacing the anchor-based exponential. Dynamic cap (block 5,270+): 0% dead band ±15s, then 0%/0.5%/1.0%/2.0%/3.0% max based on deviation. Median288 override (blocks 5,260–5,269, ±30 s dead band) is HISTORICAL; removed from consensus at block 5,270.
| TARGET_SPACING | 600 seconds // 10-minute target block time |
| bitsQ Model | V5 (block 5,175+): avg288-based // historical V2: 24h half-life exponential |
| MIN_BITSQ | 65,536 // Q16_ONE — minimum difficulty |
| MAX_BITSQ | 16,711,680 // 255 × Q16_ONE — maximum difficulty |
| Anchor rotation | Per-epoch (historical V1/V2 only) // V5: no anchors, uses avg288 |
| Encoding | SOSTCompact Q16.16 // finer granularity than Bitcoin nBits |
| Arithmetic | Integer-only // no floating point, no consensus drift |
cASERT (Contextual Adaptive Stability & Emission Rate Targeting) is the unified consensus-rate control system. It integrates three components: (1) bitsQ Q16.16 primary hardness regulator, (2) equalizer (emergency-only) with 43 profiles (pre-V12 #5,750..#7,349: 21 active E7–H13, 22 reserved H14–H35; V12 #7,350..#11,999: 28 active E7–H20, 15 reserved H21–H35; V13 #12,000+: 43 active E7–H35, 0 reserved) that adjust ConvergenceX stability parameters, and (3) anti-stall recovery. Ceiling: H35 since V13 (#12,000+) — historically H13 pre-V12 / H20 V12 (#7,350..#11,999).
CONVERGENCEX DIFFICULTY CONTROL = bitsQ + Equalizer. bitsQ regulates the numeric difficulty of the target; the Equalizer regulates the structural cost profile of each ConvergenceX attempt under the cASERT rules. Both are recomputed and verified by every node.
CURRENT MAINNET RULE: target 600 s · bitsQ Q16.16 recomputed every block · dead band ±15 s · steps 0.5% / 1.0% / 2.0% / 3.0% (block 5,270+) · Equalizer: 43 profiles E7–H35, direct lag map (block 5,323+), anti-stall at 60 min, V12 triangular cascade (block 7,350+).
HISTORICAL (before block 5,323): the equalizer used 5 EWMA signals (PID-style) to compute a weighted control signal U. This controller is bypassed since block 5,323 and is shown below for reference only.
Key design properties:
• 43 profiles. Pre-V12 (#5,750..#7,349): 21 active A: E7–H13, 22 reserved R: H14–H35. V12 (#7,350..#11,999): 28 active E7–H20, 15 reserved H21–H35. V13 (#12,000+): 43 active E7–H35, 0 reserved (full range live). H35 max profile, H10–H35 margin=115. Equalizer is emergency-only.
• Current selector: direct lag map (block 5,323+) — up immediate, down at least 1 level/block. HISTORICAL (pre-#5,323): lag-dominant PID/EWMA gains and slew rate ±1/block (V6, block 5,000+).
• Behind schedule → cap at B0 prevents hardening when blocks are slow.
• Anti-stall: 3,600s (60 min, current since #4,300; 7,200s HISTORICAL before #4,300), first drop immediate then zone-based decay to B0 (H≥7: 600s/lvl, H6–H4: 900s/lvl, H3–H1: 1200s/lvl). After 6h extra at B0: −1 level per 1,800s down to E7. Relief: V12 triangular cascade (#7,350+, up to 28 levels, floor E7) — historical: V10 granular drop 1 level/60 s from 600 s (#6,700..#6,999), V8 single E7 cliff at 605 s.
| CASERT_H_MIN | -7 // E7 (deepest easing / relief valve target) |
| CASERT_H_MAX | 35 // H35 ceiling since V13 (#12,000+), all 43 profiles active. Historical: H13 pre-V12, H20 V12 (#7,350..#11,999). |
| K_R / K_L / K_I / K_B / K_V | 0.05 / 0.40 / 0.15 / 0.05 / 0.02 // HISTORICAL (PID/EWMA, bypassed since #5,323) |
| SLEW_RATE | ±1 // HISTORICAL (V6, blocks 5,000–5,322); current: up immediate, down ≥1 level/block |
| ANTISTALL_FLOOR_V6C | 3600 // 60 min before decay (current; 7200 HISTORICAL before #4,300) |
| ANTISTALL_DECAY | zone-based // H≥7: 600s/lvl, H6-H4: 900s/lvl, H3-H1: 1200s/lvl; after 6h at B0: -1/1800s to E7 |
| Safety rules | Behind schedule → cap B0 · <10 blocks → cap B0 |
Difficulty is encoded as a Q16.16 fixed-point value in block headers, providing finer granularity than Bitcoin's nBits compact format. Deterministic bidirectional conversion between compact and full 256-bit target ensures consensus-safe retarget math and bit-for-bit reproducibility.
| Format | Q16.16 fixed-point // uint32 |
| GENESIS_BITSQ | 765,730 (11.6841 in Q16.16, calibrated) |
| MIN_BITSQ | Easiest allowed target |
| MAX_BITSQ | Hardest allowed target |
Block timestamps are validated against Median Time Past (MTP) to prevent manipulation affecting difficulty. Combined with cASERT anchoring, this creates stable timing even under individually noisy blocks.
| MTP_WINDOW | 11 blocks |
| MAX_FUTURE_DRIFT | 30 seconds // current since V13 (#12,000); HISTORICAL: 600 s before #6,550, 60 s #6,550–#11,999 |
| Rule: ts > MTP | Strict monotonicity |
| Rule: ts ≤ now + drift | Bounded acceptance |
| MAINNET_GENESIS_UTC | 1773597600 // 2026-03-15 18:00:00 UTC |
| BLOCKS_PER_EPOCH | 131,553 // ≈2.5 years (Feigenbaum α) |
| TARGET_SPACING | 600 seconds // 10-minute blocks |
| MAGIC | CXPOW3 + NETWORK_ID // unique wire identifier |
| NETWORK_ID | SHA256("SOST/CONVERGENCEX/mainnet")[:4] |
| Block header | MAGIC + "HDR2" + core(72B) + cp_root(32B) + nonce(4B) + extra(4B) |
| Block ID | SHA256( header || "ID" || commit ) |
| Block key (anti-grind) | SHA256( prev_hash || "BLOCK_KEY" ) // tip-bound only |
| Chainwork | Bitcoin-style: floor(2^256 / (target + 1)) per block. Cumulative = sum of all block work. |
| Chain selection | Best chain by cumulative work, not longest chain. The chain with the highest total accumulated work wins. This prevents attacks using many easy blocks to outpace a shorter chain with more real work. Same approach as Bitcoin. |
| Fork resolution | Atomic. If a better chain is found, the node disconnects current blocks, connects the new chain, and recovers orphaned transactions to the mempool. If any block in the new chain fails validation, the entire reorganization is aborted and the original chain is restored. MAX_REORG_DEPTH = 500 blocks (~3.5 days) for history before #30,000. From #30,000 (SACS V2, V30000 release): deep fork blocks beyond 500 that are post-activation are kept and evaluated strictly by valid cumulative work instead of being hard-rejected. |
Mining is memory-hard (ASIC resistant), but verification is lightweight (anyone can run a node). The miner must build and hold the full 4 GB dataset and 4 GB scratchpad in memory to solve the ConvergenceX puzzle. The node only verifies the compact Transcript V2 proof — SHA256 hashes and merkle checks, no dataset required.
| RAM | ~500 MB (no dataset, no scratchpad) |
| CPU | Any modern processor |
| Disk | Minimal (~1 KB per block) |
| System | 2 GB total, any OS |
| Verify speed | ~0.2 ms per block (Transcript V2) |
| Full sync | ~25 min genesis → tip (measured 25m06s to #28,077, V30000) |
| RAM | 8 GB min (4 GB dataset + 4 GB scratchpad) |
| CPU | Modern multi-core (L3 cache helps) |
| Disk | Minimal |
| System | 16 GB total recommended |
| Per attempt | 100K rounds + dataset/scratchpad I/O |
| Message types | Signed offers, acceptances, cancellations, settlement notices |
| Transport | Off-chain, replay-resistant, cryptographically authenticated |
| Integrity | Canonical hashes, deterministic serialization |
| Design principle | Not chat — private economic coordination between sovereign counterparties |
| Trading pairs | SOST ↔ XAUT/PAXG and native precious-metal positions |
| Architecture | Peer-to-peer, thin-chain / fat-edge — Ethereum as minimal onboarding rail, SOST as sovereign center |
| Deal engine | State machine with watchers and settlement daemon |
| Position registry | Model B (transferable escrow) and Model A (reward rights) |
| Mechanism | Timelocked collateral for self-custodied gold participation |
| Guarantees | No admin key, no proxy, no pause, no emergency withdrawal |
| Philosophy | Constitutional and immutable — code is the only authority |
| Base contract | SOSTEscrow.sol |
SOST uses the same secp256k1 ECDSA signatures as Bitcoin. For the post-quantum era, SOST is studying ML-DSA (NIST FIPS 204) as the leading candidate — a candidate, not adopted. The address prefix sost2 is reserved (not active) for post-quantum addresses. This is research direction, not a committed deployment schedule. SHA-256 hashing remains quantum-safe.
| Property | |||
| PoW verify cost | ~1μs | ~50ms | ~0.2 ms proof check (Transcript V2) · full recompute only for deep validation |
| Memory (mining) | Negligible | 256MB–2GB | 8GB (4GB scratchpad + 4GB dataset) |
| Memory (node) | Negligible | ~256MB | ~500MB (no scratchpad/dataset) |
| ASIC resistance | None | High | High by design (memory-hard, sequential) |
| Full sync time | ~hours | ~days | ~25 min — measured: genesis → #28,077 in 25m06s, tip + 5 checkpoint hashes matched the live chain (V30000 release); checkpointed blocks skip only the full ConvergenceX recompute (--full-verify forces it) |
| Fast sync time | ~minutes | ~hours | not needed — the full verified sync above is the normal path |
| Verification layers | 4 | 4 | 8 |
| Difficulty adjust | Every 2,016 blocks (~2 weeks) | Every block (LWMA) | Every block (cASERT bitsQ avg288 + Equalizer direct lag map) |
| Response speed | 2-week lag | ~720-block EWMA (~24h) | 288-block average (bitsQ) + per-block lag map (Equalizer) |
| Halflife | ~2 weeks (fixed) | ~720 blocks (~24h) | V5: avg288-based (historical: 48h half-life, then 24h from #1,450) |
| Max change/block | N/A (bulk adjust) | EWMA smoothed | Dynamic cap #5,270+: 0% within ±15 s, then 0.5/1.0/2.0/3.0% |
| Control signals | 1 (time delta) | 1 (timestamp EWMA) | 2 (288-block average interval; schedule lag). HISTORICAL pre-#5,323: 5-signal PID/EWMA |
| Dynamic profiles | None (1 formula) | None (1 formula) | 43 profiles (V13 #12,000+: all 43 active E7–H35, 0 reserved) |
| Math type | Floating-point | 128-bit integer | Q16.16 fixed-point (zero float) |
| Block time | 600s | 120s | 600s |
| Anti-stall | None | LWMA | Zone-based decay to B0 at 3,600s (60 min) stall, then down to E7 after 6h; V12 triangular cascade + slingshot relief |
| Anti-acceleration | None | LWMA | cASERT Equalizer E7–H35 since V13 (#12,000+) (direct lag map #5,323+: up immediate, down ≥1 level/block) |
| Emission | Halving / 210K blocks | Tail emission | Smooth exp. decay (q=e-¼) |
| Max supply | 21M BTC | Infinite | ~4,669,201 SOST |
| Constitutional reserve | None | None | None since V15 (#25,000): 50% miner / 50% DTD (pre-V15: 25% gold + 25% PoPC) |
Signed operator notices, propagated between nodes. Advisory only. Does not affect mining rewards, block validity, chain selection, transaction validation, wallet balances, PoPC, Gold Vault, or consensus.
Each node reads notices.json on startup. ECDSA-SHA256 signature verification against a hardcoded operator pubkey. Failure modes (bad signature, wrong network, expired, malformed) are silent drops. Active at V13_HEIGHT (12,000).
Adds N-of-M threshold signatures (default 3-of-5), revocation by notice ID (only threshold-signed notices can revoke), and an optional mirror_url metadata field (never fetched by the node). Active at V13_HEIGHT.
Nodes gossip verified notices via a BCNN dispatcher with hard limits: 4 KB max notice, 32-notice LRU dedup cache, 8 notices/peer/min rate limit. Bad-signature notices are silently dropped; oversized/malformed/rate-limit hits earn peer misbehavior. Active at V13_HEIGHT.
Hard invariant. No Beacon code path links into block validation, mining validity, or chain commit. Beacon
cannot reject, invalidate, or affect the canonical chain. Rollback is a single-line constant revert
(BEACON_P2P_ACTIVATION_HEIGHT to INT64_MAX in include/sost/params.h).