REVIEW 3 major objections 5 minor 23 references
Bootstrapping a stable computation token
T0 review · 3 major / 5 minor · reviewed 2026-08-14 · deepseek-v4-flash
Pith's one-line read In Truebit's model, one CPU token always pays for one computation step.
desk verdict A clever token-engineering design for Truebit with a genuinely neat stability idea, but the sustainability theorem's assumptions are not derived and may be undercut by the protocol's own pricing dynamics. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central mechanism is the two-token mintable format: CPU, the tasking token whose value is hard-wired to one computation step, and TRU, the staking and reward token minted at the median local price. The median local price is maintained by staking swaps, in which monitors can exchange tokens against a participant's stake at their declared price minus a fee, and by a tasking conversion contract that burns TRU or whitelisted external tokens to mint CPU at the median rate. The governance token DAO completes the system: each DAO token can be converted once into TRU or CPU, with a back-loaded bonus $f(p,c)=(p+5c^{2}p)N$ that rewards long-term holding, and conversion shrinks governance power until the political layer dissolves.
What would settle it
Track, in a live or simulated Truebit deployment, the fraction of TRU rewards that participants convert to CPU within the pricing-bonding period and the average number of new tokens minted per epoch of tasks: if the converting fraction exceeds the fraction of hodlers or the per-epoch creation rate $x$ is not below $p$, the Proposition's predicted convergence to all tokens held by Strategy 2 participants will fail. Separately, if both TRU and CPU trade on exchanges, persistent deviations of USD(CPU) from $r\cdot\mathrm{USD(TRU)}$ would falsify the arbitrage Claim.
Extended reading notes
Core claim
The central claim is that decoupling payment from reward through two linked tokens stabilizes task pricing: task givers pay in CPU, whose denominated value is fixed at one computation step, while solvers and verifiers stake and are paid in TRU, minted on the fly at the median of all bonded local prices. Because median pricing governs both reward minting and TRU-to-CPU conversion, no external price feed is needed, and staking monitors punish outlier prices by swapping against the offending stake. The paper's Proposition asserts that if at least a fraction $p$ of solvers and verifiers follow the hodling Strategy 2 and fewer than $p$ new tokens are created per epoch of $n$ tasks, then the hodlers will come to hold all tokens after $n/(p-x)$ tasks, giving TRU value growth relative to CPU. A further Claim holds that if both tokens trade on exchanges, arbitrage between conversion and trading forces the exchange rate $\mathrm{USD(CPU)}$ toward $r\cdot\mathrm{USD(TRU)}$, where $r$ is the tasking conversion rate. Minting rewards also removes the finite jackpot repository as a bound on the largest secure computation, so in theory tasks of any size can be rewarded.
Load-bearing premise
The sustainability argument collapses if a large enough share of solvers and verifiers do not actually choose to hold their TRU rewards, or if new tokens are created too quickly; the paper assumes these 'reasonable conditions' rather than proving they are the rational equilibrium.
Editorial extensions
If this is right
- Task givers can issue tasks at any time without worrying about token price changes, because holding CPU guarantees the same purchasing power in computation steps.
- Solvers and verifiers become the risk bearers: their TRU rewards fluctuate in purchasing power, and median pricing prevents individual participants from gaming the conversion rate upward.
- If the Proposition's conditions hold, hodlers following Strategy 2 will eventually accumulate the entire token supply, making TRU appreciate relative to CPU and attracting task givers through lower fiat-equivalent prices.
- Minting TRU on demand lifts the old jackpot-repository cap on secure computation size, so the protocol can in principle reward arbitrarily large tasks.
- A one-time conversion of DAO tokens into TRU or CPU, combined with the upgrade game that re-mints CPU' and TRU' in new contracts, provides a path from centralized governance to a fully decentralized, upgradable network.
Reading between the lines
- An implicit, testable consequence is that the median local price should track the real fiat cost of computation; if it drifts far from hardware-and-electricity costs, the staking-swap arbitrage may be too weak to correct it because the 20% fee and 24-hour bonding delay let outlier prices persist.
- The stability guarantee is relative to TRU, not fiat: external exchange prices can still move, so 'one CPU pays one step' holds for task issuance only while arbitrage keeps CPU's fiat value near $r$ times TRU's.
- Varying the arbitrary constant 5 in the DAO conversion formula would change how quickly governance dissolves; a simulation of conversion timing could show whether the back-loaded bonus rewards early hodlers at the expense of late converters.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper proposes a two-token design for Truebit: a stable 'CPU' token used for task payments at a fixed rate of one CPU per computation step, and a mintable 'TRU' reward token paid to Solvers and Verifiers. Solvers/Verifiers post local prices in TRU per step; rewards are minted at the median of these local prices, and TRU can be converted into CPU through a tasking conversion contract at the same median price, policed by Staking Monitors and Tasking Monitors. The paper argues that this median-based pricing, together with a 'Strategy 2' hodling behavior, yields sustainable economics through a geometric convergence argument, and that external exchange markets do not disrupt the construction under a fixed conversion rate. It then sketches bootstrapping via external token staking, a DAO governance layer that dissolves into TRU/CPU, an upgrade mechanism, and two protocol modifications (a martingale defense and random selection of Verifiers).
Significance. If the economic claims were established, the paper would offer a coherent, oracle-free mechanism for stable task pricing and for bootstrapping a new token system from existing liquid assets. The CPU token's task-price stability is definitional (one token per computation step), the staking-monitor mechanism gives a concrete check on local price reporting, and the geometric-series argument is transparent under its stated assumptions. The governance-dissolution idea is original. However, the central sustainability claim is not yet supported: the Proposition in Section 3.2 assumes the behavioral dominance it aims to establish, and its convergence condition x < p is coupled to the protocol's own median-conversion dynamics. The exchange-stability Claim likewise treats the conversion rate as fixed when it is endogenous. These are load-bearing issues for the paper's main economic thesis, so the significance is conditional on substantial revision.
major comments (3)
- [Section 3.2, Proposition] The Proposition assumes (a) at least p fraction of Solvers/Verifiers follow Strategy 2 and (b) on average x < p new CPU tokens are created per epoch, and then concludes convergence in n/(p - x) tasks. Assumption (a) is precisely the behavioral dominance claim ('Strategy 2 is the long-run, dominant strategy for rational miners') that the surrounding text says it will describe but never derives from individual rationality; no best-response or equilibrium analysis is given. Assumption (b) is not an exogenous 'reasonable condition' either: the tasking conversion contract mints CPU at rate 1/p_med, and Strategy 2 is defined as posting a local price near the median minus 20%, which pushes p_med down and therefore pushes the minting rate C/p_med up. Unless conversion volume C is bounded or a fixed-point argument establishes x < p, the geometric-series convergence is unsupported. This undermines the abstract and Section 3.2 claim of 'sustainable economics.'
- [Section 3.2, Claim on exchange markets] The arbitrage Claim assumes 'a fixed tasking conversion rate r,' but r is the median of bonded local prices and is endogenous to the strategy mix and conversion volume. The Claim therefore does not establish that USD(CPU) tends to r * USD(TRU) unless the dynamics of r are modeled. As written, this argument is conditional on the same missing median-price dynamics as the Proposition, and it cannot be invoked to show that external exchanges do not disrupt the construction.
- [Section 3.1, design principle] The design principle that 'the value of tokens paid into the Truebit protocol must not exceed the value of tokens paid out as rewards' is not reconciled with the on-the-fly minting of TRU rewards described in the same section. If rewards are minted at the median local price, the quantity of TRU a Task Giver can obtain by issuing a private task and burning CPU depends on that median, so the value check is circular unless an external value anchor or a supply bound is supplied.
minor comments (5)
- [Section 3.2, Proposition proof] The displayed 'geometric series' equality uses an infinite product symbol where a sum is intended; it should read n/p + xn/p^2 + ... = (n/p) * sum_{k=0}^{∞} (x/p)^k, not an infinite product.
- [Section 4.2, Equation (1)] The notation '5c2p' is confusing and should be written as 5 c^2 p, with an explicit explanation of why the constant 5 is chosen.
- [Section 5.1] The word 'comparsion' should be 'comparison.'
- [Reference [9]] Reference [9] contains a duplicated 'that that' in its title; please fix.
- [Figure 2] Figure 2 mixes token flows, control flows, and monitor roles in a dense diagram; consider separating these layers or labeling the token types directly on each edge for readability.
Circularity Check
No circularity: stable CPU pricing is a design axiom, the sustainability proposition is a conditional theorem with explicitly stated assumptions, and the exchange-parity claim is an arbitrage argument, not a self-referential reduction.
full rationale
The paper's central stable-pricing component is introduced as a protocol design choice, not as a derived prediction: Section 3 states 'Truebit relieves Task Givers from pricing responsibilities by fixing the cost for one computation cycle at one CPU.' This is a definitional construction in the normal sense of a token specification, and the paper does not claim to derive it from deeper premises. The Section 3.2 Proposition is explicitly conditional: it assumes that at least a fraction p of Solver/Verifiers follow Strategy 2 and that new token creation per epoch satisfies x < p, then computes convergence time n/(p−x) by a geometric series. The conclusion is not identical to the assumptions; the assumptions are labeled 'reasonable conditions' and the paper does not pretend to prove them from individual rationality. That is an economic modeling gap or an unproven behavioral premise, which is a correctness risk rather than circularity. Similarly, the exchange-market Claim assumes a fixed tasking conversion rate r and argues that arbitrage pushes USD(CPU) toward r·USD(TRU); the claim does not assume its own conclusion, even though r is in fact the endogenous median local price, making the proof incomplete rather than circular. The paper's use of the Truebit whitepaper [23] as a black-box underlying protocol is a self-citation, but the token-economics argument does not reduce to that citation, no uniqueness theorem is imported from the authors' prior work, and no fitted parameter is relabeled as a prediction. Under the requested standard requiring a specific equation-for-equation or definition-for-definition reduction, no circular step is exhibited.
Assumptions & free parameters
free parameters (3)
- DAO conversion bonus coefficient =
5
- staking conversion fee =
20%
- price bonding delay =
24 hours
assumptions (6)
- domain assumption Task Givers holding CPU condone indeterminate token supply so long as it does not inhibit their ability to issue tasks and obtain correct results.
- domain assumption At least fraction p of Solvers and Verifiers follow the deflationary Strategy 2, and on average fewer than p new tokens are created per epoch (x < p).
- domain assumption Staking Monitors and Tasking Monitors can estimate true market prices, have access to the tokens they need to swap, and are incentivized by the 20% fee to police local pricing.
- domain assumption Whitelisted external tokens XYZ have sufficient liquidity that Tasking Monitors can estimate a correct exchange rate and obtain tokens to swap.
- domain assumption The underlying Truebit verification game is secure and can be treated as a black box.
- standard math Geometric series convergence.
invented entities (3)
-
CPU token
-
DAO governance token
-
Staking Monitor and Tasking Monitor roles
Cite this review
Pith. "Pith review of Bootstrapping a stable computation token." pith.science (2026). https://pith.science/paper/RUANLKGG
@misc{pith2026190802946,
author = {Pith},
title = {Pith review of: Bootstrapping a stable computation token},
year = {2026},
howpublished = {\url{https://pith.science/paper/RUANLKGG}},
note = {Machine review of arXiv:1908.02946}
}
read the original abstract
We outline a token model for Truebit, a retrofitting, blockchain enhancement which enables secure, community-based computation. The model addresses the challenge of stable task pricing, as raised in the Truebit whitepaper, without appealing to external oracles, exchanges, or hierarchical nodes. The system's sustainable economics and fair market pricing derive from a mintable token format which leverages existing tokens for liquidity. Finally, we introduce a governance layer whose lifecycles culminates with permanent dissolution into utility tokens, thereby tending the network towards autonomous decentralization.
Figures
Reference graph
Works this paper leans on
-
[1]
https://wiki.aragon.org/dev/apps/voting/
Aragon wiki: Voting. https://wiki.aragon.org/dev/apps/voting/
-
[2]
https://makerdao.com/en/whitepaper
The Dai stablecoin system. https://makerdao.com/en/whitepaper. 18
- [3]
-
[4]
https://github.com/TrueBitFoundation/truebit-os
Truebit OS. https://github.com/TrueBitFoundation/truebit-os
- [5]
-
[6]
Tether: Fiat currencies on the Bitcoin blockchain. https://tether. to/wp-content/uploads/2016/06/TetherWhitePaper.pdf , June 2016
work page 2016
-
[7]
https:// daostack.io/wp/DAOstack-White-Paper-en.pdf , April 2018
DAOStack: An operating system for collective intellige nce. https:// daostack.io/wp/DAOstack-White-Paper-en.pdf , April 2018
work page 2018
-
[8]
Retrofitting a tw o-way peg between blockchains
Jason Teutsch Michael Straka Dan Boneh. Retrofitting a tw o-way peg between blockchains. https://people.cs.uchicago.edu/~teutsch/ papers/dogethereum.pdf, October 2018
work page 2018
Show all 23 references
-
[9]
DAO - a next-generation decentr alized organization that that coordinates the resources of a commu nity (hu- man, capital) to sustainably deliver value for members
DAO Community & Friends. DAO - a next-generation decentr alized organization that that coordinates the resources of a commu nity (hu- man, capital) to sustainably deliver value for members. https://gist. github.com/rzurrer/f5db72f427902300a2e030ccdfda641c, 2019
2019
-
[10]
AdversariallyVerifiableMachine
Tim Goddard. AdversariallyVerifiableMachine. https://www.reddit. com/r/ethereum/comments/51qjz6/interactive_verification_ of_c_programs/d7ey41n/, 2016
2016
-
[11]
Knottenbelt
Dominik Harz, Lewis Gudgeon, Arthur Gervais, and Willi am J. Knottenbelt. Balance : Dynamic adjustment of cryptocurren cy de- posits. https://eprint.iacr.org/2019/675s, 2019. Cryptology ePrint Archive, Report 2019/675
2019
-
[12]
Frame- work for ‘investment contract’ analysis of digital as- sets
Bill Hinman and Valerie Szczepanik. Frame- work for ‘investment contract’ analysis of digital as- sets. https://www.sec.gov/news/public-statement/ statement-framework-investment-contract-analysis-di gital-assets, April 2019
2019
-
[13]
Gastoken.io – cheaper Ethereum transactions, tod ay
IC3. Gastoken.io – cheaper Ethereum transactions, tod ay. https:// gastoken.io, 2018
2018
-
[14]
Matt hew Weinberg, and Edward W
Harry Kalodner, Steven Goldfeder, Xiaoqi Chen, S. Matt hew Weinberg, and Edward W. Felten. Arbitrum: Scalable, private smart con tracts. In Proceedings of the 27th USENIX Conference on Security Symposi um, SEC’18, pages 1353–1370, Berkeley, CA, USA, 2018. USENIX As soci- ation. 19
2018
-
[15]
A predictable in centive mecha- nism for truebit
Julia Koch and Christian Reitwießner. A predictable in centive mecha- nism for truebit. http://arxiv.org/abs/1806.11476, 2018
2018 arXiv
-
[16]
De- mystifying incentives in the consensus computer
Loi Luu, Jason Teutsch, Raghav Kulkarni, and Prateek Sa xena. De- mystifying incentives in the consensus computer. In Proceedings of the 22Nd ACM SIGSAC Conference on Computer and Communications Security, CCS ’15, pages 706–719, New York, NY, USA, 2015. ACM
2015
-
[17]
JIT for Truebit
Sami M¨ akel¨ a. JIT for Truebit. https://medium.com/truebit/ jit-for-truebit-e5299afc72d8 , December 2018
2018
-
[18]
Bitcoin: A peer-to-peer electronic cash system
Satoshi Nakamoto. Bitcoin: A peer-to-peer electronic cash system. https://bitcoin.org/bitcoin.pdf, 2008
2008
-
[19]
Bitcoin P2P e-cash paper
Satoshi Nakamoto. Bitcoin P2P e-cash paper. https://www. mail-archive.com/cryptography@metzdowd.com/msg09959 .html, November 2008
2008
-
[20]
Introducing the MerkleMine
Doug Petkanics. Introducing the MerkleMine. https://forum. livepeer.org/t/introducing-the-merklemine/204 , April 2018
2018
-
[21]
On decentralized oracles for data avail ability
Jason Teutsch. On decentralized oracles for data avail ability. http:// people.cs.uchicago.edu/~teutsch/papers/decentralized_ oracles.pdf, December 2017
2017
-
[22]
Interac- tive coin offerings
Jason Teutsch, Vitalik Buterin, and Christopher Brown . Interac- tive coin offerings. https://people.cs.uchicago.edu/~teutsch/ papers/ico.pdf, 2017
2017
-
[23]
A scalable ve rification so- lution for blockchains
Jason Teutsch and Christian Reitwießner. A scalable ve rification so- lution for blockchains. https://people.cs.uchicago.edu/teutsch/ papers/truebit.pdf, 2017. 20
2017
Reviewed August 14, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.