Mined0
Epoch 1 price$0.29
Plan30s / character
ChainZcash
Tokennone

Documentation

The whole protocol, written so it can be re-implemented by someone who does not trust us. If you want the two-minute version instead, read How it works.

01 · The collection

Supply
10 000. When the last one is mined the window closes permanently, there is no phase two.
Form
Three to five lines of monospace characters, each line in its own colour.
Layers
12, frame, eyes, cheeks, mouth, arms, shoulders, core, legs, crown, ground, held, palette.
Palettes
39 named palettes, each carrying three colours.
One-of-ones
10 hand-drawn pieces that the layer system cannot produce.
Charset
Single-width glyphs only · Latin, Greek, Cyrillic, IPA, box-drawing. CJK is excluded because double-width characters break the grid.

The layer library is inscribed on Zcash at genesis. After that nobody, including us, can add a variant, remove one, or change a weight. A character is a pure function of its proof hash and that library.

02 · Naming

No name is chosen by hand. Each part is derived:

restless benja
counting hashes one by one in a half-lit datacenter

        ( o · ω · o )
          . / x \ .
              db

03 · Rarity

A character's tier comes from its rarest single layer, never from an average. One improbable trait is enough. Thresholds are calibrated against the real distribution across all twelve layers.

TierRarest layerPer 10 000
COMMONabove 2.19%~5 900
UNCOMMON1.14 – 2.19%~2 530
RARE0.69 – 1.14%~930
EPIC0.36 – 0.69%~500
LEGENDARYunder 0.36%~120
ONE OF ONE-10

Three layers exist only to break the silhouette: crown adds a line above the head, ground adds one below the legs, held hangs an object off the body. About 41% of characters stand three lines tall, 47% four, and 12% five.

Percentages float until the end

Because characters are created one at a time, a trait that looks rare at 3 000 mined may be ordinary at 10 000. Every rarity figure on this site is written as “17 of 3 412 mined”, never as a share of the full collection. Final numbers exist only after the last mint.

04 · Mining

proof = keccak256( miner_address ‖ nonce ‖ zcash_block_hash )
valid if  proof < targetFor(miner)
Function
Keccak-f[1600], fast on graphics hardware, cheap to verify, open miners exist for every platform.
Preimage
60 bytes: address 20, nonce 8, anchor block hash 32.
Anchor window
3–4 Zcash blocks. A proof older than that is rejected.

Threshold, not a chain

HashCats links each puzzle to the previous winner, which works because their blocks confirm in a second or two. On Zcash a new link would only be known once a transaction lands in a block, and a Zcash block takes 75 seconds, strict chaining would cap the entire collection at one character per block, or 8.7 days at the floor.

So we drop the chain and keep the anchor. The anchor was doing the anti-premine work anyway: a Zcash block hash cannot be known while you are grinding. Several winners may land in the same block, ordered deterministically by position within it.

Constants

NameValueMeaning
TAGZCH1first four bytes of every claim
ANCHOR_WINDOW4blocks a proof may reach back
PLAN_SECONDS30target seconds per character
RETARGET_EVERY8characters between retargets
MAX_TIGHTENhardest a single step may go
MAX_LOOSENeasiest a single step may go
PERSONAL_WINDOW64recent characters used for personal difficulty
PERSONAL_PENALTY3slope of the personal penalty

Three protections

Measured hashrates

HardwareHashratevs CPU
RTX PRO 6000 Blackwell, CUDA5.99 GH/s6 700×
RTX 4090, Vulkan3.40 GH/s3 800×
Apple M4 Pro0.45 GH/s505×
CPU, 2 workers0.89 MH/s

05 · Difficulty

Difficulty retargets every 8 characters, comparing the real pace with a plan of one every 30 seconds.

Two further rules keep the retarget honest when a burst of claims lands together. It fires at most once per Zcash block, because sub-block time cannot be measured and firing repeatedly on a zero interval would slam difficulty into the ceiling inside a single block. And the plan is scaled by how many characters actually arrived, not by a fixed eight, so a block carrying a hundred of them is judged against a hundred slots of plan. Both rules came out of running the reference indexer against a simulated chain; without them the first busy block ends the mint.

Network totalDifficultyRoughly
1 GH/s34.0 bitsthree laptops
10 GH/s37.3 bitsthree 4090s
100 GH/s40.7 bitsthirty cards
2 000 GH/s45.0 bitssix hundred cards

Proof-of-work is a lottery, not a race: each hash is an independent ticket and grinding longer brings you no closer. Your share of the collection equals your share of the network's hashrate, and holding 25% of it still means losing three rounds in four.

06 · Pace

At a plan of 30 seconds, a full mint takes 3.5 days. Difficulty can hold the pace down to that; it cannot force anyone to mint once the price has outrun what people will pay. HashCats planned 30 seconds and ran at 72, 2.4× behind. At the same shortfall a full ZECHASH mint takes about eight days.

07 · Price

Eleven epochs. The price is fixed inside an epoch and doubles at every boundary. Boundaries sit at count doublings, so each epoch is twice as long as the one before it.

EpochCharactersSizePriceZECRaises
11 – 1616$0.290.00020$5
217 – 3216$0.590.00040$9
333 – 6432$1.170.00081$38
465 – 12864$2.340.00162$150
5129 – 256128$4.690.00323$600
6257 – 512256$9.380.00647$2 400
7513 – 1 024512$18.750.01293$9 600
81 025 – 2 0481 024$37.500.02586$38 400
92 049 – 4 0962 048$750.05172$153 600
104 097 – 8 1924 096$1500.10345$614 400
118 193 – 10 0001 808$3000.20690$542 400

Prices are denominated in ZEC and fixed at genesis. Zcash has no oracle, so a dollar peg would mean updating prices by hand, a hole in the trust model we are not opening.

The first thousand characters raise $12 802, which is effectively nothing, while the price doubles seven times. Epochs 10 and 11 carry $1.16M of the $1.36M total.

Where a mint like this dies

Floor price and mint price move together. The moment mining costs more than buying a finished one, mining stops · HashCats stalled at 0.127 ETH against a floor of 0.126, at 56% of their collection. The $300 top epoch is therefore a bet on perceived value rather than a setting, and an unreachable tail costs nothing.

08 · Buyback and burn

Two sources, both at thirty percent:

SourceRateGoes to
Mint revenue30%buy & burn characters
Secondary royalty5% of volume-
… of which30%buy & burn characters

We buy on the open secondary market and burn what we buy. Holding it instead would leave a visible overhang of our own inventory hanging over every bid. The buyback address is published at genesis and every purchase and burn is visible on chain.

Mint reachesRevenueTo buybackAvg buy priceBurnedLeft circulating
40%$198k$59k$381 5812 419
55%$415k$125k$751 6623 838
75%$715k$215k$752 8624 638
100%$1.36M$408k$1502 7237 277

Average buy price is modelled as half the price of the epoch reached, since buying happens continuously and our own bids push the floor up. A faster-rising floor means fewer characters burned for the same money. With a mid-sized secondary market on top, a 75% mint burns about 3 260 characters and leaves roughly 4 240 in circulation. Ten thousand can be mined. Barely half will survive.

09 · On-chain format

// a claim, in OP_RETURN · Zcash allows 80 bytes
protocol tag     4 bytes
anchor height    4 bytes
nonce            8 bytes
total           16 bytes

// the miner address is read from the transaction input, 0 bytes
// the layer library is inscribed once at genesis, ~30 KB
// the entire collection ≈ 190 KB

No image is stored anywhere. A character is a pure function of its proof and the genesis library, so anyone running a Zcash node can rebuild all ten thousand with no server, no IPFS and no API. If OP_RETURN turns out not to relay reliably, claims move to a shielded memo with a published viewing key, 512 bytes today, 16 KB once ZIP 231 activates, and the sender stays hidden.

10 · The indexer

Zcash has no virtual machine, so there is no contract to enforce any of this. State is computed by an indexer that follows this document: it reads Zcash blocks, validates each proof, checks that the correct epoch price was paid, and derives the character.

This is the real trust assumption, and we are not hiding it

While only one compatible indexer exists, that indexer is also the final authority on who owns what. The mitigation is not a promise but a practice: a deterministic specification, open source, published test vectors, and two or three independently operated indexers running before any listing. Judge us on whether that exists, not on what we say here.

11 · Market and custody

Holding and transferring need no trust at all. A character lives on a Zcash output, own the output, own the character; send it, and it is sent. We are not involved.

Trading is different. An atomic swap of money against an NFT needs ZIP 228, which is not activated and has no timeline. Until it exists, a trade on our venue means the venue briefly holds the asset between the two legs. That is a custody risk and it is disclosed at the point of trade, not only here.

Royalty is 5%, withheld at settlement.

12 · What Zcash does not give us

MechanismOn an EVM chainHere
Price curvecontractindexer rejects underpayment
Royaltycontractwithheld at settlement on our venue
Buybackcontractpublished address, visible on chain
Rent to holderscontract- not offered
Own tokenERC-20- impossible until ZSA ships
Atomic tradecontract- needs ZIP 228, no timeline

Zcash Shielded Assets, which would allow issuing a token, is not part of the November upgrade and remains on a test network. There is no ZECHASH token and there will not be one. We are not going to promise rent we cannot enforce either. What is left is a mining game, a fixed collection, an honest curve, and a buyback that visibly burns supply, and that is the whole offer.

Spec protocol v1
Layers 12
On-chain 16 bytes per claim
Library ~30 KB at genesis
Collection ~190 KB total