The whole protocol, written so it can be re-implemented by someone who does not trust us. If you want the two-minute version instead, read How it works.
The layer library is inscribed on Zcash at genesis. After that nobody, including us, can add a variant, remove one, or change a weight. A character is a pure function of its proof hash and that library.
No name is chosen by hand. Each part is derived:
ruskl, vexliro, udzenel. The tables hold 14 112 combinations against a 10 000 collection, and the indexer enforces uniqueness on top: if a derived name is already taken it re-derives with a counter until one is free. Deterministic, unique, and no hash suffix bolted onto the end.restless is the name of an eye variant, not decoration. Read the title and you already know what is unusual about the piece.restless benja counting hashes one by one in a half-lit datacenter ( o · ω · o ) . / x \ . db
A character's tier comes from its rarest single layer, never from an average. One improbable trait is enough. Thresholds are calibrated against the real distribution across all twelve layers.
| Tier | Rarest layer | Per 10 000 |
|---|---|---|
| COMMON | above 2.19% | ~5 900 |
| UNCOMMON | 1.14 – 2.19% | ~2 530 |
| RARE | 0.69 – 1.14% | ~930 |
| EPIC | 0.36 – 0.69% | ~500 |
| LEGENDARY | under 0.36% | ~120 |
| ONE OF ONE | - | 10 |
Three layers exist only to break the silhouette: crown adds a line above the head, ground adds one below the legs, held hangs an object off the body. About 41% of characters stand three lines tall, 47% four, and 12% five.
proof = keccak256( miner_address ‖ nonce ‖ zcash_block_hash ) valid if proof < targetFor(miner)
HashCats links each puzzle to the previous winner, which works because their blocks confirm in a second or two. On Zcash a new link would only be known once a transaction lands in a block, and a Zcash block takes 75 seconds, strict chaining would cap the entire collection at one character per block, or 8.7 days at the floor.
So we drop the chain and keep the anchor. The anchor was doing the anti-premine work anyway: a Zcash block hash cannot be known while you are grinding. Several winners may land in the same block, ordered deterministically by position within it.
| Name | Value | Meaning |
|---|---|---|
TAG | ZCH1 | first four bytes of every claim |
ANCHOR_WINDOW | 4 | blocks a proof may reach back |
PLAN_SECONDS | 30 | target seconds per character |
RETARGET_EVERY | 8 | characters between retargets |
MAX_TIGHTEN | 4× | hardest a single step may go |
MAX_LOOSEN | 2× | easiest a single step may go |
PERSONAL_WINDOW | 64 | recent characters used for personal difficulty |
PERSONAL_PENALTY | 3 | slope of the personal penalty |
1 + 3 × (your share of the last 64 characters). A miner holding a quarter of the recent window mines at 1.75× their own difficulty; nobody else is affected. In simulation a miner with 75.5% of the network hashrate took 63.1% of the characters, the penalty gives back about twelve points to everyone else.| Hardware | Hashrate | vs CPU |
|---|---|---|
| RTX PRO 6000 Blackwell, CUDA | 5.99 GH/s | 6 700× |
| RTX 4090, Vulkan | 3.40 GH/s | 3 800× |
| Apple M4 Pro | 0.45 GH/s | 505× |
| CPU, 2 workers | 0.89 MH/s | 1× |
Difficulty retargets every 8 characters, comparing the real pace with a plan of one every 30 seconds.
Two further rules keep the retarget honest when a burst of claims lands together. It fires at most once per Zcash block, because sub-block time cannot be measured and firing repeatedly on a zero interval would slam difficulty into the ceiling inside a single block. And the plan is scaled by how many characters actually arrived, not by a fixed eight, so a block carrying a hundred of them is judged against a hundred slots of plan. Both rules came out of running the reference indexer against a simulated chain; without them the first busy block ends the mint.
| Network total | Difficulty | Roughly |
|---|---|---|
| 1 GH/s | 34.0 bits | three laptops |
| 10 GH/s | 37.3 bits | three 4090s |
| 100 GH/s | 40.7 bits | thirty cards |
| 2 000 GH/s | 45.0 bits | six hundred cards |
Proof-of-work is a lottery, not a race: each hash is an independent ticket and grinding longer brings you no closer. Your share of the collection equals your share of the network's hashrate, and holding 25% of it still means losing three rounds in four.
At a plan of 30 seconds, a full mint takes 3.5 days. Difficulty can hold the pace down to that; it cannot force anyone to mint once the price has outrun what people will pay. HashCats planned 30 seconds and ran at 72, 2.4× behind. At the same shortfall a full ZECHASH mint takes about eight days.
Eleven epochs. The price is fixed inside an epoch and doubles at every boundary. Boundaries sit at count doublings, so each epoch is twice as long as the one before it.
| Epoch | Characters | Size | Price | ZEC | Raises |
|---|---|---|---|---|---|
| 1 | 1 – 16 | 16 | $0.29 | 0.00020 | $5 |
| 2 | 17 – 32 | 16 | $0.59 | 0.00040 | $9 |
| 3 | 33 – 64 | 32 | $1.17 | 0.00081 | $38 |
| 4 | 65 – 128 | 64 | $2.34 | 0.00162 | $150 |
| 5 | 129 – 256 | 128 | $4.69 | 0.00323 | $600 |
| 6 | 257 – 512 | 256 | $9.38 | 0.00647 | $2 400 |
| 7 | 513 – 1 024 | 512 | $18.75 | 0.01293 | $9 600 |
| 8 | 1 025 – 2 048 | 1 024 | $37.50 | 0.02586 | $38 400 |
| 9 | 2 049 – 4 096 | 2 048 | $75 | 0.05172 | $153 600 |
| 10 | 4 097 – 8 192 | 4 096 | $150 | 0.10345 | $614 400 |
| 11 | 8 193 – 10 000 | 1 808 | $300 | 0.20690 | $542 400 |
Prices are denominated in ZEC and fixed at genesis. Zcash has no oracle, so a dollar peg would mean updating prices by hand, a hole in the trust model we are not opening.
The first thousand characters raise $12 802, which is effectively nothing, while the price doubles seven times. Epochs 10 and 11 carry $1.16M of the $1.36M total.
Floor price and mint price move together. The moment mining costs more than buying a finished one, mining stops · HashCats stalled at 0.127 ETH against a floor of 0.126, at 56% of their collection. The $300 top epoch is therefore a bet on perceived value rather than a setting, and an unreachable tail costs nothing.
Two sources, both at thirty percent:
| Source | Rate | Goes to |
|---|---|---|
| Mint revenue | 30% | buy & burn characters |
| Secondary royalty | 5% of volume | - |
| … of which | 30% | buy & burn characters |
We buy on the open secondary market and burn what we buy. Holding it instead would leave a visible overhang of our own inventory hanging over every bid. The buyback address is published at genesis and every purchase and burn is visible on chain.
| Mint reaches | Revenue | To buyback | Avg buy price | Burned | Left circulating |
|---|---|---|---|---|---|
| 40% | $198k | $59k | $38 | 1 581 | 2 419 |
| 55% | $415k | $125k | $75 | 1 662 | 3 838 |
| 75% | $715k | $215k | $75 | 2 862 | 4 638 |
| 100% | $1.36M | $408k | $150 | 2 723 | 7 277 |
Average buy price is modelled as half the price of the epoch reached, since buying happens continuously and our own bids push the floor up. A faster-rising floor means fewer characters burned for the same money. With a mid-sized secondary market on top, a 75% mint burns about 3 260 characters and leaves roughly 4 240 in circulation. Ten thousand can be mined. Barely half will survive.
// a claim, in OP_RETURN · Zcash allows 80 bytes protocol tag 4 bytes anchor height 4 bytes nonce 8 bytes total 16 bytes // the miner address is read from the transaction input, 0 bytes // the layer library is inscribed once at genesis, ~30 KB // the entire collection ≈ 190 KB
No image is stored anywhere. A character is a pure function of its proof and the genesis library, so anyone running a Zcash node can rebuild all ten thousand with no server, no IPFS and no API. If OP_RETURN turns out not to relay reliably, claims move to a shielded memo with a published viewing key, 512 bytes today, 16 KB once ZIP 231 activates, and the sender stays hidden.
Zcash has no virtual machine, so there is no contract to enforce any of this. State is computed by an indexer that follows this document: it reads Zcash blocks, validates each proof, checks that the correct epoch price was paid, and derives the character.
Holding and transferring need no trust at all. A character lives on a Zcash output, own the output, own the character; send it, and it is sent. We are not involved.
Trading is different. An atomic swap of money against an NFT needs ZIP 228, which is not activated and has no timeline. Until it exists, a trade on our venue means the venue briefly holds the asset between the two legs. That is a custody risk and it is disclosed at the point of trade, not only here.
Royalty is 5%, withheld at settlement.
| Mechanism | On an EVM chain | Here |
|---|---|---|
| Price curve | contract | indexer rejects underpayment |
| Royalty | contract | withheld at settlement on our venue |
| Buyback | contract | published address, visible on chain |
| Rent to holders | contract | - not offered |
| Own token | ERC-20 | - impossible until ZSA ships |
| Atomic trade | contract | - needs ZIP 228, no timeline |
Zcash Shielded Assets, which would allow issuing a token, is not part of the November upgrade and remains on a test network. There is no ZECHASH token and there will not be one. We are not going to promise rent we cannot enforce either. What is left is a mining game, a fixed collection, an honest curve, and a buyback that visibly burns supply, and that is the whole offer.