Skip to content

What the system provesLink to this section

TL;DRLink to this section

  • One accepted magnet passage is one work unit under the configured sensor policy.
  • A signature proves which key signed the data, not whether the measurement is physically true.
  • Ethereum records contract execution and settled work. Video doesn't affect those records.
  • A compromised measurement host can still supply false data, even with a protected signing key.

What does a work record prove?Link to this section

A work record says that a wheel-magnet passage was accepted under the configured sensor rules. It doesn't identify an animal, prove the wheel's direction, or establish what caused it to move. “Hamster proof of work” describes these recorded passages, not a way of proving animal identity or securing Ethereum consensus.

A signature links a record to a signing key. Settlement on Ethereum shows that the contract accepted an authorized batch. Neither step independently checks the physical wheel, so a valid signature and a successful transaction don't remove the need to trust the measurement host and its operators.

Does video or a signing chip remove that trust?Link to this section

Video is independent of measurement. You can see movement while counting is stopped, and a missing feed doesn't mean no work was recorded. Video cannot repair missing sensor records.

The production signing chip protects its key from export, but it signs data supplied by the host. A compromised host can supply false data. Sensor placement, counting rules, host security, and enrollment of the signing key still matter.

Technical detail: evidence by layerLink to this section

Layer Evidence it supplies What it cannot establish
Pico Raw sensor readings with identity, sequence, and timing Accepted work, completed rounds, or signed telemetry
Pi Saved accepted passages and completed rounds Animal identity, direction, intent, or what caused movement
Oracle Checks on signatures, identity, counter history, and policy Physical truth or Ethereum settlement
Reporter Signed permission to settle an exact batch Anything beyond the eligible measurement records
Squeekchain Core contract on Ethereum Executed round, work-total, and Squeek-block rules Which animal or physical cause produced a reading
Camera and public display Video and displayed status Accepted measurements or proof of their cause

PermissionsLink to this section

Only the Pi accepts passages and assigns them to rounds. Hosted services check its records; they cannot invent a starting total, reduce cumulative work, or spread an unexplained increase across rounds.

Core checks signed settlements, not the sensor or Oracle database. Indexers and APIs display records but cannot change Ethereum history.

GuaranteesLink to this section

The Oracle checks the signature before reading the telemetry contents and preserves accepted round-data hashes. It recognizes a retry by its record identity and contents, not by identical signature bytes.

Production signing chips keep telemetry keys non-exportable, and the Oracle checks signatures against the registered public key. Enrollment proves a genuine chip participated, but the chip cannot attest that it holds the telemetry key or that a measurement is true.

Core rejects reused settlement authorizations and checks the chain, proxy, and implementation named by the signature. These checks prevent misuse of an authorization, not false physical measurements.

AssumptionsLink to this section

A compromised measurement host can send false data to its signing chip. Sensor placement, counting rules, host security, and key enrollment therefore remain trusted.

Oracle administrators and its database provider can affect hosted records, while Core upgrades depend on trusted governance. Mining checks Core's expected interface and reward rules; Token does not independently check work or rounds.

Failure behaviorLink to this section

  • An invalid telemetry signature creates no Oracle receipt or accepted work.
  • Rejected or quarantined telemetry leaves review records but creates no accepted rounds.
  • The Pi stops counting missing, conflicting, or uncertain sensor readings rather than guessing passages.
  • A video failure neither proves nor disproves a passage and cannot change rounds.
  • Local checks and code review do not prove that deployed contracts match the reviewed code or that services are operating correctly.