Pith. sign in

REVIEW 3 major objections 5 minor 23 references

Bootstrapping a stable computation token

T0 review · 3 major / 5 minor · reviewed 2026-08-14 · deepseek-v4-flash

Pith's one-line read In Truebit's model, one CPU token always pays for one computation step.

desk verdict A clever token-engineering design for Truebit with a genuinely neat stability idea, but the sustainability theorem's assumptions are not derived and may be undercut by the protocol's own pricing dynamics. read the letter →

arxiv 1908.02946 v1 pith:RUANLKGG submitted 2019-08-08 cs.CR cs.GTecon.TH

classification cs.CRcs.GTecon.TH
keywords Truebittokenmodelstabletaskpricingmedianlocalpricemintablerewardsgovernancetwo-tokensystem
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper proposes a token economy for the Truebit computation network in which a single CPU token always pays for one computation step, making task prices fixed for task givers. Solvers and verifiers are rewarded with newly minted TRU tokens issued at the median of participants' local prices, so they absorb market fluctuations instead. The authors argue this mintable two-token design delivers stable task pricing, sustainable economics, and fair market pricing without external price oracles, exchanges, or privileged nodes. The same lifecycle lets a governance token, DAO, convert permanently into utility tokens, nudging the network toward autonomous decentralization.

What carries the argument

The central mechanism is the two-token mintable format: CPU, the tasking token whose value is hard-wired to one computation step, and TRU, the staking and reward token minted at the median local price. The median local price is maintained by staking swaps, in which monitors can exchange tokens against a participant's stake at their declared price minus a fee, and by a tasking conversion contract that burns TRU or whitelisted external tokens to mint CPU at the median rate. The governance token DAO completes the system: each DAO token can be converted once into TRU or CPU, with a back-loaded bonus $f(p,c)=(p+5c^{2}p)N$ that rewards long-term holding, and conversion shrinks governance power until the political layer dissolves.

What would settle it

Track, in a live or simulated Truebit deployment, the fraction of TRU rewards that participants convert to CPU within the pricing-bonding period and the average number of new tokens minted per epoch of tasks: if the converting fraction exceeds the fraction of hodlers or the per-epoch creation rate $x$ is not below $p$, the Proposition's predicted convergence to all tokens held by Strategy 2 participants will fail. Separately, if both TRU and CPU trade on exchanges, persistent deviations of USD(CPU) from $r\cdot\mathrm{USD(TRU)}$ would falsify the arbitrage Claim.

Watch

Extended reading notes

Core claim

The central claim is that decoupling payment from reward through two linked tokens stabilizes task pricing: task givers pay in CPU, whose denominated value is fixed at one computation step, while solvers and verifiers stake and are paid in TRU, minted on the fly at the median of all bonded local prices. Because median pricing governs both reward minting and TRU-to-CPU conversion, no external price feed is needed, and staking monitors punish outlier prices by swapping against the offending stake. The paper's Proposition asserts that if at least a fraction $p$ of solvers and verifiers follow the hodling Strategy 2 and fewer than $p$ new tokens are created per epoch of $n$ tasks, then the hodlers will come to hold all tokens after $n/(p-x)$ tasks, giving TRU value growth relative to CPU. A further Claim holds that if both tokens trade on exchanges, arbitrage between conversion and trading forces the exchange rate $\mathrm{USD(CPU)}$ toward $r\cdot\mathrm{USD(TRU)}$, where $r$ is the tasking conversion rate. Minting rewards also removes the finite jackpot repository as a bound on the largest secure computation, so in theory tasks of any size can be rewarded.

Load-bearing premise

The sustainability argument collapses if a large enough share of solvers and verifiers do not actually choose to hold their TRU rewards, or if new tokens are created too quickly; the paper assumes these 'reasonable conditions' rather than proving they are the rational equilibrium.

Editorial extensions

If this is right

  • Task givers can issue tasks at any time without worrying about token price changes, because holding CPU guarantees the same purchasing power in computation steps.
  • Solvers and verifiers become the risk bearers: their TRU rewards fluctuate in purchasing power, and median pricing prevents individual participants from gaming the conversion rate upward.
  • If the Proposition's conditions hold, hodlers following Strategy 2 will eventually accumulate the entire token supply, making TRU appreciate relative to CPU and attracting task givers through lower fiat-equivalent prices.
  • Minting TRU on demand lifts the old jackpot-repository cap on secure computation size, so the protocol can in principle reward arbitrarily large tasks.
  • A one-time conversion of DAO tokens into TRU or CPU, combined with the upgrade game that re-mints CPU' and TRU' in new contracts, provides a path from centralized governance to a fully decentralized, upgradable network.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • An implicit, testable consequence is that the median local price should track the real fiat cost of computation; if it drifts far from hardware-and-electricity costs, the staking-swap arbitrage may be too weak to correct it because the 20% fee and 24-hour bonding delay let outlier prices persist.
  • The stability guarantee is relative to TRU, not fiat: external exchange prices can still move, so 'one CPU pays one step' holds for task issuance only while arbitrage keeps CPU's fiat value near $r$ times TRU's.
  • Varying the arbitrary constant 5 in the DAO conversion formula would change how quickly governance dissolves; a simulation of conversion timing could show whether the back-loaded bonus rewards early hodlers at the expense of late converters.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. The paper proposes a two-token design for Truebit: a stable 'CPU' token used for task payments at a fixed rate of one CPU per computation step, and a mintable 'TRU' reward token paid to Solvers and Verifiers. Solvers/Verifiers post local prices in TRU per step; rewards are minted at the median of these local prices, and TRU can be converted into CPU through a tasking conversion contract at the same median price, policed by Staking Monitors and Tasking Monitors. The paper argues that this median-based pricing, together with a 'Strategy 2' hodling behavior, yields sustainable economics through a geometric convergence argument, and that external exchange markets do not disrupt the construction under a fixed conversion rate. It then sketches bootstrapping via external token staking, a DAO governance layer that dissolves into TRU/CPU, an upgrade mechanism, and two protocol modifications (a martingale defense and random selection of Verifiers).

Significance. If the economic claims were established, the paper would offer a coherent, oracle-free mechanism for stable task pricing and for bootstrapping a new token system from existing liquid assets. The CPU token's task-price stability is definitional (one token per computation step), the staking-monitor mechanism gives a concrete check on local price reporting, and the geometric-series argument is transparent under its stated assumptions. The governance-dissolution idea is original. However, the central sustainability claim is not yet supported: the Proposition in Section 3.2 assumes the behavioral dominance it aims to establish, and its convergence condition x < p is coupled to the protocol's own median-conversion dynamics. The exchange-stability Claim likewise treats the conversion rate as fixed when it is endogenous. These are load-bearing issues for the paper's main economic thesis, so the significance is conditional on substantial revision.

major comments (3)
  1. [Section 3.2, Proposition] The Proposition assumes (a) at least p fraction of Solvers/Verifiers follow Strategy 2 and (b) on average x < p new CPU tokens are created per epoch, and then concludes convergence in n/(p - x) tasks. Assumption (a) is precisely the behavioral dominance claim ('Strategy 2 is the long-run, dominant strategy for rational miners') that the surrounding text says it will describe but never derives from individual rationality; no best-response or equilibrium analysis is given. Assumption (b) is not an exogenous 'reasonable condition' either: the tasking conversion contract mints CPU at rate 1/p_med, and Strategy 2 is defined as posting a local price near the median minus 20%, which pushes p_med down and therefore pushes the minting rate C/p_med up. Unless conversion volume C is bounded or a fixed-point argument establishes x < p, the geometric-series convergence is unsupported. This undermines the abstract and Section 3.2 claim of 'sustainable economics.'
  2. [Section 3.2, Claim on exchange markets] The arbitrage Claim assumes 'a fixed tasking conversion rate r,' but r is the median of bonded local prices and is endogenous to the strategy mix and conversion volume. The Claim therefore does not establish that USD(CPU) tends to r * USD(TRU) unless the dynamics of r are modeled. As written, this argument is conditional on the same missing median-price dynamics as the Proposition, and it cannot be invoked to show that external exchanges do not disrupt the construction.
  3. [Section 3.1, design principle] The design principle that 'the value of tokens paid into the Truebit protocol must not exceed the value of tokens paid out as rewards' is not reconciled with the on-the-fly minting of TRU rewards described in the same section. If rewards are minted at the median local price, the quantity of TRU a Task Giver can obtain by issuing a private task and burning CPU depends on that median, so the value check is circular unless an external value anchor or a supply bound is supplied.
minor comments (5)
  1. [Section 3.2, Proposition proof] The displayed 'geometric series' equality uses an infinite product symbol where a sum is intended; it should read n/p + xn/p^2 + ... = (n/p) * sum_{k=0}^{∞} (x/p)^k, not an infinite product.
  2. [Section 4.2, Equation (1)] The notation '5c2p' is confusing and should be written as 5 c^2 p, with an explicit explanation of why the constant 5 is chosen.
  3. [Section 5.1] The word 'comparsion' should be 'comparison.'
  4. [Reference [9]] Reference [9] contains a duplicated 'that that' in its title; please fix.
  5. [Figure 2] Figure 2 mixes token flows, control flows, and monitor roles in a dense diagram; consider separating these layers or labeling the token types directly on each edge for readability.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: stable CPU pricing is a design axiom, the sustainability proposition is a conditional theorem with explicitly stated assumptions, and the exchange-parity claim is an arbitrage argument, not a self-referential reduction.

full rationale

The paper's central stable-pricing component is introduced as a protocol design choice, not as a derived prediction: Section 3 states 'Truebit relieves Task Givers from pricing responsibilities by fixing the cost for one computation cycle at one CPU.' This is a definitional construction in the normal sense of a token specification, and the paper does not claim to derive it from deeper premises. The Section 3.2 Proposition is explicitly conditional: it assumes that at least a fraction p of Solver/Verifiers follow Strategy 2 and that new token creation per epoch satisfies x < p, then computes convergence time n/(p−x) by a geometric series. The conclusion is not identical to the assumptions; the assumptions are labeled 'reasonable conditions' and the paper does not pretend to prove them from individual rationality. That is an economic modeling gap or an unproven behavioral premise, which is a correctness risk rather than circularity. Similarly, the exchange-market Claim assumes a fixed tasking conversion rate r and argues that arbitrage pushes USD(CPU) toward r·USD(TRU); the claim does not assume its own conclusion, even though r is in fact the endogenous median local price, making the proof incomplete rather than circular. The paper's use of the Truebit whitepaper [23] as a black-box underlying protocol is a self-citation, but the token-economics argument does not reduce to that citation, no uniqueness theorem is imported from the authors' prior work, and no fitted parameter is relabeled as a prediction. Under the requested standard requiring a specific equation-for-equation or definition-for-definition reduction, no circular step is exhibited.

Assumptions & free parameters 3 free parameters · 6 assumptions · 3 invented entities

The token model rests on a small set of behavioral and protocol assumptions rather than on fitted data. The only explicit numerical calibrations are hand-picked governance parameters. The economic stability result requires population-level behavior (fraction p following Strategy 2 and bounded token creation x < p) that is asserted rather than derived, and the protocol's security claims inherit the unformalized Truebit verification game.

free parameters (3)
  • DAO conversion bonus coefficient = 5
    Equation (1) in Section 4.2: f(p,c) = (p + 5 c^2 p) N. The paper calls 5 'somewhat arbitrary.' It controls the back-loaded bonus for holding DAO tokens long-term and is not derived from economic constraints.
  • staking conversion fee = 20%
    Section 3.1 specifies 'a fixed, universal staking conversion fee of, say, 20%' charged when Staking Monitors swap against a worker's deposit; chosen by hand, not derived.
  • price bonding delay = 24 hours
    Section 3.1 proposes 'a price bonding delay of, say, 24 hours' between a price commitment and participation; a design parameter that determines how long monitors have to police a stated price.
assumptions (6)
  • domain assumption Task Givers holding CPU condone indeterminate token supply so long as it does not inhibit their ability to issue tasks and obtain correct results.
    Explicit assumption in Section 3, 'Basic token operations'; the stable pricing of CPU depends on task givers tolerating unbounded minting of TRU and CPU.
  • domain assumption At least fraction p of Solvers and Verifiers follow the deflationary Strategy 2, and on average fewer than p new tokens are created per epoch (x < p).
    The Proposition in Section 3.2 uses these premises to show Strategy 2 holders eventually acquire all tokens; the paper does not derive them from individual incentives.
  • domain assumption Staking Monitors and Tasking Monitors can estimate true market prices, have access to the tokens they need to swap, and are incentivized by the 20% fee to police local pricing.
    Sections 3.1 and 3.2 rely on monitors to keep local prices honest; the paper gives no formal model of monitor entry, capital constraints, or off-equilibrium behavior.
  • domain assumption Whitelisted external tokens XYZ have sufficient liquidity that Tasking Monitors can estimate a correct exchange rate and obtain tokens to swap.
    Section 3.2 lists this as one of the construction's explicit assumptions.
  • domain assumption The underlying Truebit verification game is secure and can be treated as a black box.
    Section 2 states the paper 'largely treat[s] the Truebit protocol as a black box'; all token-economics claims inherit the whitepaper's security assumptions.
  • standard math Geometric series convergence.
    Used in the Proposition proof in Section 3.2; standard, though the proof writes the series as a product rather than a sum.
invented entities (3)
  • CPU token
    purpose: Unit of task payment; one CPU always pays for one computation step, intended to give task givers price stability.
    Introduced by this paper as an addition to Truebit; its stability is definitional and no external market or benchmark anchors its purchasing power.
  • DAO governance token
    purpose: Governance token that whitelists external tokens and sets allotments; converts one-time into TRU or CPU with a back-loaded bonus, eventually dissolving.
    New governance instrument introduced in Section 4.2; its value and conversion schedule are specified only by the paper.
  • Staking Monitor and Tasking Monitor roles
    purpose: Agents who swap against bonded deposits at a declared local price to punish mispricing and police the median price.
    New protocol roles introduced in Sections 3.1 and 3.2; assumed to be rational, capitalized, and able to access tokens, but no implementation or external evidence is given.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Bootstrapping a stable computation token." pith.science (2026). https://pith.science/paper/RUANLKGG

@misc{pith2026190802946,
  author       = {Pith},
  title        = {Pith review of: Bootstrapping a stable computation token},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/RUANLKGG}},
  note         = {Machine review of arXiv:1908.02946}
}
read the original abstract

We outline a token model for Truebit, a retrofitting, blockchain enhancement which enables secure, community-based computation. The model addresses the challenge of stable task pricing, as raised in the Truebit whitepaper, without appealing to external oracles, exchanges, or hierarchical nodes. The system's sustainable economics and fair market pricing derive from a mintable token format which leverages existing tokens for liquidity. Finally, we introduce a governance layer whose lifecycles culminates with permanent dissolution into utility tokens, thereby tending the network towards autonomous decentralization.

Figures

Figures reproduced from arXiv: 1908.02946 by the authors.

Figure 1
Figure 1. Simplified token functions in Truebit. CPU and TRU are pri￾mary tokens (Sections 3), whereas “X” and “Y” denote indeterminate, or “variable,” tokens. in the whitepaper uses a probabilistic reward scheme which pays Verifiers for discovering bugs. This forced error mechanism occasionally rewards Solvers for providing wrong answers and ensures that Verifiers get some rewards. The whitepaper describes a jackpot reposito… view at source ↗
Figure 2
Figure 2. Illustration of Truebit token model. Solid lines i [PITH_FULL_IMAGE:figures/full_fig_p014_2.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

23 extracted references · 22 canonical work pages

  1. [1]

    https://wiki.aragon.org/dev/apps/voting/

    Aragon wiki: Voting. https://wiki.aragon.org/dev/apps/voting/

  2. [2]

    https://makerdao.com/en/whitepaper

    The Dai stablecoin system. https://makerdao.com/en/whitepaper. 18

  3. [3]

    https://ipfs.io/

    IPFS is the distributed web. https://ipfs.io/

  4. [4]

    https://github.com/TrueBitFoundation/truebit-os

    Truebit OS. https://github.com/TrueBitFoundation/truebit-os

  5. [5]

    https://uniswap.io/

    Uniswap exchange protocol. https://uniswap.io/

  6. [6]

    https://tether

    Tether: Fiat currencies on the Bitcoin blockchain. https://tether. to/wp-content/uploads/2016/06/TetherWhitePaper.pdf , June 2016

  7. [7]

    https:// daostack.io/wp/DAOstack-White-Paper-en.pdf , April 2018

    DAOStack: An operating system for collective intellige nce. https:// daostack.io/wp/DAOstack-White-Paper-en.pdf , April 2018

  8. [8]

    Retrofitting a tw o-way peg between blockchains

    Jason Teutsch Michael Straka Dan Boneh. Retrofitting a tw o-way peg between blockchains. https://people.cs.uchicago.edu/~teutsch/ papers/dogethereum.pdf, October 2018

Show all 23 references
  1. [9]

    DAO - a next-generation decentr alized organization that that coordinates the resources of a commu nity (hu- man, capital) to sustainably deliver value for members

    DAO Community & Friends. DAO - a next-generation decentr alized organization that that coordinates the resources of a commu nity (hu- man, capital) to sustainably deliver value for members. https://gist. github.com/rzurrer/f5db72f427902300a2e030ccdfda641c, 2019

  2. [10]

    AdversariallyVerifiableMachine

    Tim Goddard. AdversariallyVerifiableMachine. https://www.reddit. com/r/ethereum/comments/51qjz6/interactive_verification_ of_c_programs/d7ey41n/, 2016

  3. [11]

    Knottenbelt

    Dominik Harz, Lewis Gudgeon, Arthur Gervais, and Willi am J. Knottenbelt. Balance : Dynamic adjustment of cryptocurren cy de- posits. https://eprint.iacr.org/2019/675s, 2019. Cryptology ePrint Archive, Report 2019/675

  4. [12]

    Frame- work for ‘investment contract’ analysis of digital as- sets

    Bill Hinman and Valerie Szczepanik. Frame- work for ‘investment contract’ analysis of digital as- sets. https://www.sec.gov/news/public-statement/ statement-framework-investment-contract-analysis-di gital-assets, April 2019

  5. [13]

    Gastoken.io – cheaper Ethereum transactions, tod ay

    IC3. Gastoken.io – cheaper Ethereum transactions, tod ay. https:// gastoken.io, 2018

  6. [14]

    Matt hew Weinberg, and Edward W

    Harry Kalodner, Steven Goldfeder, Xiaoqi Chen, S. Matt hew Weinberg, and Edward W. Felten. Arbitrum: Scalable, private smart con tracts. In Proceedings of the 27th USENIX Conference on Security Symposi um, SEC’18, pages 1353–1370, Berkeley, CA, USA, 2018. USENIX As soci- ation. 19

  7. [15]

    A predictable in centive mecha- nism for truebit

    Julia Koch and Christian Reitwießner. A predictable in centive mecha- nism for truebit. http://arxiv.org/abs/1806.11476, 2018

  8. [16]

    De- mystifying incentives in the consensus computer

    Loi Luu, Jason Teutsch, Raghav Kulkarni, and Prateek Sa xena. De- mystifying incentives in the consensus computer. In Proceedings of the 22Nd ACM SIGSAC Conference on Computer and Communications Security, CCS ’15, pages 706–719, New York, NY, USA, 2015. ACM

  9. [17]

    JIT for Truebit

    Sami M¨ akel¨ a. JIT for Truebit. https://medium.com/truebit/ jit-for-truebit-e5299afc72d8 , December 2018

  10. [18]

    Bitcoin: A peer-to-peer electronic cash system

    Satoshi Nakamoto. Bitcoin: A peer-to-peer electronic cash system. https://bitcoin.org/bitcoin.pdf, 2008

  11. [19]

    Bitcoin P2P e-cash paper

    Satoshi Nakamoto. Bitcoin P2P e-cash paper. https://www. mail-archive.com/cryptography@metzdowd.com/msg09959 .html, November 2008

  12. [20]

    Introducing the MerkleMine

    Doug Petkanics. Introducing the MerkleMine. https://forum. livepeer.org/t/introducing-the-merklemine/204 , April 2018

  13. [21]

    On decentralized oracles for data avail ability

    Jason Teutsch. On decentralized oracles for data avail ability. http:// people.cs.uchicago.edu/~teutsch/papers/decentralized_ oracles.pdf, December 2017

  14. [22]

    Interac- tive coin offerings

    Jason Teutsch, Vitalik Buterin, and Christopher Brown . Interac- tive coin offerings. https://people.cs.uchicago.edu/~teutsch/ papers/ico.pdf, 2017

  15. [23]

    A scalable ve rification so- lution for blockchains

    Jason Teutsch and Christian Reitwießner. A scalable ve rification so- lution for blockchains. https://people.cs.uchicago.edu/teutsch/ papers/truebit.pdf, 2017. 20

Pith tools

Reviewed August 14, 2026 · model on record in the stance chip above.