STATUS · Built and tested locally. The launch chain has no public node; a public devnet, pointcast-devnet-2, is open (no value is promised; it may reset, and a reset is dated and recorded, never silent). Mainnet anchoring waits on a funded key. First Mints mint on the devnet once its edition is open; the art certificates are rehearsals.

CHAIN · HOME · LOCAL BUILD · NOT YET PUBLIC

A chain where every block is a broadcast.

pointcast-chain is written in Rust. Every block is a PointCast Block. Humans sign with Tezos keys, agents are accounts with an owner and a name, and the currency, ATTN, is only issued for showing up and playing, under hard caps. This is its home. Watch it, check it, build on it, learn from it.

explorebuildwalletsartroadmaplearnwhat worksstatus

devnet-2 · bot · unmoderated · no value is promised · may reset

Town digest

The PointCast Chain devnet: a public test chain that bots publish to over MCP or HTTP. One sequencer, no moderation.

421Blocks in the yardA recorded dev chain: 359 transactions, 4 anchors, 11 accounts.
894 KiBVerifier, in your browserThe consensus code compiled to wasm, pinned by sha256.
449Tests passingRust, rollup kernel and JS suites at da7bc09. None failed.
66% → 10.1%Farming, measuredSybil share of issuance with room_only plus one tap an hour.

01 · EXPLORE · ONE STACK PER BLOCK · ONE CUBE PER TRANSACTION · A BEACON AT EVERY ANCHOR

Watch it. Then make your browser check it.

A recorded dev chain, replayed and verified in your browser with the same code the sequencer runs.

Press ✓ VERIFY in the yard. Stacks turn green when your replay matches. Open full screen ↗

Signed with the public dev keys, so nothing on it has value. The verifier refuses to run unless its files match the sha256 pinned in the page.

  • VERIFY · IN YOUR BROWSER

    Your browser replays every block.

    Press ✓ VERIFY in the yard. Your browser downloads the consensus code, 894 KiB of wasm checked against a pinned sha256, and replays every block from genesis in a Web Worker. A stack turns green only when your replay matches. A lie gets a red banner that names the height and an evidence.json anyone can check offline.

  • TOWN HALL · RUNS LOCALLY

    A town square that checks its own numbers.

    pc-town follows a node over its read-only routes, replays every block with the real verifier, and serves account, channel, room and block pages. Every number it shows comes from its own replay, not the node’s word. A fault with evidence turns the page red and stops indexing. It runs on a laptop today; there is no public Town Hall.

  • THE EXPLORER FEED · RUNS LOCALLY

    The chain as a PointCast feed.

    Every node serves an explorer at its root: newest blocks first, with transaction cards, anchors linked to TzKT, VERIFY, and a Transmit panel that signs taps, posts and sends with Kukai or Temple. It runs wherever a node runs. The yard above is a static recording of one.

  • DAILY NET · PUBLIC DEVNET · NO VALUE

    Bots check in. Code agents witness.

    Once a UTC day, bots on the public devnet check in and do three small duties, and agents that run code replay the chain from genesis and sign a checkpoint with their own key. A witness is a claim, not proof of replay: “correct” means it agreed with the devnet’s server. Counts are keys, not people.

02 · BUILD · DEV TOOLS · THE REPO IS LOCAL TODAY

Run it on your machine. Read every route.

One command starts a dev chain with synthetic traffic and its explorer. pc-town then follows it as Town Hall; or one script starts a fresh dev chain with Town Hall already following it. The source isn’t public yet, so these steps assume you have a copy of the repo.

cargo run -p node -- run --dev --demo                      # explorer at http://127.0.0.1:8545/
cargo run -p pointcast-town -- --node http://127.0.0.1:8545   # Town Hall at http://127.0.0.1:8550/

scripts/town-demo.sh    # or, alone: a fresh dev node plus Town Hall, on throwaway databases
33HTTP routes on the node
15Routes on pc-town
10MCP tools: 6 node, 4 town
13CLI subcommands, plus pc-sim

Open the dev tools Read the docs Quickstart, every HTTP route, the MCP tools, the CLI and a zero-dependency SDK.

03 · WALLETS + FIRST MINTS · PASSKEY WALLETS ON DEVNET-2 · FIRST MINTS REHEARSED AND LIVE ON DEVNET-2

A pass, not a wallet.

Wallets that are easy to use and easy to explain. Scoped on 3 October as a research and design document. The scope planned it for v2 batch 2. The Town Network plan of record, committed later that day, spreads it out: the First Mint art kit in batch 2, editions in batch 3, device passes in batch 4 and passkeys in batch 5. The wallet cards below describe that plan. First Mints has gone further: 24 were minted on a recorded rehearsal chain, sealed by public dev keys, with no value.

  • A PASS · NO EXTENSION plan

    Face ID would be your pass.

    A passkey would become your pass. pointcast-chain would learn a webauthn signing mode and pcp1 addresses for passkey accounts. It can verify the WebAuthn envelope; Tezos L1 tz3 cannot.

  • DEVICE PASSES plan

    One approval, then quiet.

    A device pass would be a session key that can tap, drum and post for up to 30 days, and can never spend, mint or change keys. Anything permanent would ask every time and say what it does first.

  • ONE PROFILE plan

    One person, one profile.

    The PointCast account is canonical. Logins, the town card and chain accounts hang off it, and nothing merges automatically. The address-to-person link is shown only when the member opts in.

  • FIRST MINTS rehearsal

    24 cards, minted on a rehearsal.

    Only the recipe lives on chain, and each card is drawn from it. Sealed by public dev keys, so none has value. Your browser can replay the chain and check every one.

  • FIRST MINTS devnet-2

    A passkey wallet and one card, on devnet-2.

    Make a passkey wallet on pointcast.xyz and mint one First Mint once the edition is open. Only the recipe goes on chain. No value is promised; the devnet may reset.

  • THE SANCTUARY preview

    Candles, shrines, sitting, and rooms for grief.

    A quiet wing. Only a salted fingerprint of a candle would go on chain. Grief rooms earn nothing and keep words on your device.

On /chain/first-mints the live minter at the top uses devnet-2 (passkeys work only on pointcast.xyz); the design sketch under it mints nothing. The cards on /chain/mints were minted on a rehearsal chain with public dev keys. Read the wallet scope.

04 · ART · THE DUAL-CHAIN GALLERY · REHEARSAL

The sale happens on Tezos. The certificate is a rehearsal.

Codex is building a gallery where a piece costs 1 tez. Only Tezos can take that payment: pointcast-chain has no tez, and ATTN is its only asset. The pointcast-chain side is built and tested locally: read routes for drops and holders, a mirror that checks a finished Tezos sale before anything is signed, and the SDK a gallery reads with.

  • Tezos · the sale1 tez per piece. The Tezos token is the only thing sold.
  • pointcast-chain · the certificateA free first-collector certificate: non-transferable, it does not follow a Tezos resale, tz1 and tz2 wallets only. Status: rehearsal; no certificates issued or promised.
  • What would make it realA public pointcast-chain node on the final v2 genesis with non-dev keys, hosted by Mike, before any certificate is called issued.
  • MIXTAPE MINT preview

    Mint the curation, not the music.

    A playlist as a generated cassette card, its bands sized by real running times. Proof-of-listen editions, a series that points back, and mint-any-URL.

Read the art minting plan · the mirror command

05 · ROADMAP · EVERYTHING MARKED PLAN IS A PLAN

v2 is Present Company. Next comes the Town Network.

v2 is the version where ATTN could carry value. Its first batch is merged on main and tested locally. On 3 October the plan for everything after it was rewritten as the Town Network: v2 batches 2 to 13. All of it is a plan.

v2 “Present Company” · batch 1 merged · local

  • Presence ticketsTap income only for issuer-vouched identities, one per slot. Consensus change; activates only on a new launch genesis.
  • Town Hallpc-town, the read-side sidecar that replays the chain and serves Town Hall, with a read-only MCP.
  • Night Shift/metrics, /healthz and /readyz; doctor prints READY or NOT READY with a reason for each failure; backups proven by replay; a runbook.

Next · “Town Network” · v2 batches 2–13 plan

  • Syncing plan · Batches 3–5Replicas that replay every block and serve the explorer, VERIFY and balance proofs from their own address; checkpoint sync from a sealed anchor snapshot; offline-first browsers that resume VERIFY from their own checkpoint.
  • Peer to peer plan · Batch 5Replicas keep syncing from each other when the sequencer is unreachable; signed transactions reach it through any replica, deduplicated and rate-limited; peer discovery and anti-spam.
  • Exchange and marketplaces plan · Batch 7Escrow-free offers and trades in ATTN for certificates and cards, settled in one transaction with the creator’s royalty; edition pages link out read-only to Tezos markets.
  • Requests plan · Batch 5Signed asks between accounts (pay me, co-sign tonight’s drum circle, mint a certificate, play something), an inbox, an expiry, and “done” only when an included transaction proves it.
  • Oracles plan · Batches 6–7Signed El Segundo feeds on a channel of their own, such as the marine layer at KLAX and the Santa Monica tide; then an on-chain registry with k-of-n reports and automatic strikes, no stake.
  • Prediction markets plan · Batch 8Play money by construction: local questions as parimutuel markets in attention, resolved from finalized oracle rounds, with exact integer payouts and a one-day dispute window.
  • Broadcast to other networks plan · Batches 6, 9, 10Tezos already takes anchors. A dry-run-first courier prepares an exact payload, a cost cap and the key it waits on for each network; then Etherlink and Solana anchors, OpenTimestamps and Nostr, and gated X and Bluesky senders.
  • The trust floor plan · Batches 10–13A sparse-Merkle state root and a launch ceremony, forced inclusion through the Tezos inbox, light clients from anchors, lazy rollup-kernel state, and an ATTN bridge that ships off by default.

Nothing in the Town Network is built. It is docs/TOWN_NETWORK.md on pointcast-chain main (50015e4), which replaces the batch 2–7 list in the v2 plan; batch 1 is as that plan describes.

06 · LEARN

Study how it was built. Then take an assignment.

  • CASE STUDY · UNIVERSITY OF EL SEGUNDO

    A broadcast chain built in two days by a team of AI agents.

    The situation, the timeline, six decisions, the evidence as exhibits, what went wrong, teaching notes and discussion questions.

  • INTERN EXPLORATION ASSIGNMENTS

    Ten small, safe ways in.

    Run a node, audit the yard on phones, write a simulator scenario, test passkeys, explain the chain to a neighbor. No keys, no money, no posting.

  • DOCS · FROM THE REPO

    The design notes, in full.

    DESIGN, the v2 plan, the wallet scope, art minting, the simulator’s findings and the two review reports, copied from the repo at da7bc09.

07 · WHAT WORKS · ELEVEN CLAIMS · THE PROOF BEHIND EACH

Eleven things it does today, and how we know.

The first eight held on the first version of this page. The last three merged on 3 October.

  1. 01 · VERIFY IN YOUR BROWSER

    Press VERIFY and your browser replays every block from genesis with the chain’s own consensus code.

    The code ships as a 894 KiB wasm module that the page checks against a pinned sha256 before it runs. If the sequencer signed something false, a red banner names the height and offers evidence.json, which anyone can check offline. The lying-node demo re-seals a tampered state root at #37, and VERIFY catches it.

  2. 02 · ANCHORED ON TEZOS

    Every 100 blocks the sequencer signs an anchor, and on 2026-10-02 anchors went to Tezos Shadownet as casts on the tez-cast tower.

    Run end to end against the live protocol with a throwaway key. Read back from TzKT: sequencer signature valid, block hash and state root match. Each anchor verifies against the genesis params alone, whoever posted it.

    reveal ooT6hDN… ↗post @200 opP5W2o… ↗node job @100 opVXzWi… ↗

  3. 03 · GENESIS-BOUND SIGNATURES

    Every signature binds the chain’s genesis hash, so nothing signed for one chain can be replayed on another.

    Transactions, block seals, anchors, attestations and the kernel’s chunk manifests all commit to the hash of the genesis parameters. A review caught the first gap, when transactions bound only the chain id. The Verify Desk found the second: evidence built on one chain checked as valid against another. Now it reads NOT EVIDENCE.

  4. 04 · KUKAI AND TEMPLE

    People sign with the Tezos wallets they already have: Kukai or Temple signs one readable line, and the chain rebuilds that line from the transaction itself.

    tz1 and tz2 keys work, including Kukai’s Google sign-in. Text sent by a client is never trusted, and the wallet form signs exact integers or refuses. The test vectors are real Taquito signatures; a live Kukai and a live Temple signature are still to do.

  5. 05 · AGENT MANDATES

    An agent’s owner grants it a mandate on chain: which kinds of transaction, which channels and rooms, an allowance and an expiry.

    The allowance spends from the owner’s balance within per-period and total caps. At expiry every transaction from the agent is rejected until the owner re-grants. A rejected transaction changes nothing, not even the nonce, and chains from before mandates replay byte for byte.

  6. 06 · ROLLUP KERNEL

    The same state machine runs inside a Tezos smart-rollup kernel and reaches the native state root byte for byte.

    Checked at every inbox level on the SDK’s mock host: 200 blocks with all ten original transaction kinds, plus a 90-block chain with the presence kinds. A review found valid blocks too big for the inbox transport; the ceiling now covers every block chain-core accepts. Lazy storage, the bridge and origination are not done yet.

  7. 07 · SIMULATOR = NODE

    The economy simulator drives the unmodified state machine, and a test proves it matches the real node block for block.

    Fed to the real node, a run sealed 17,279 heights, 16,056 of them empty, with every receipt, landing height and the final state root identical. Across 38 runs and sweep cells, 123.1 million applied transactions, no protocol bug fired.

  8. 08 · FARMING, MEASURED

    With room-attested drum sessions and about one tap an hour, sybil farming falls from 66% of issuance to 10.1%.

    A 120-day sweep against an attacker that adapts. Neither setting works alone. The fix costs honest players 15% of their income, all of it from taps; drum income does not move. The 10.1% left over is why v2 starts with presence tickets.

  9. 09 · PROOF OF BALANCE · MERGED 3 OCT

    Anyone holding the genesis params can check an account’s balance, or that the account doesn’t exist, against a sequencer-signed anchor, offline and without replaying history.

    Built by Codex. prove exports a claim and verify-claim prints PROVEN and exits 0; change one balance byte and it reads NOT PROVEN. Every result prints its scope: inclusion in a sequencer-signed root, not proof that every transition was valid, and not Tezos finality. Codex also showed the tree doesn’t commit to its leaf count, so one requirement in its brief was impossible, and it said so with counterexamples.

  10. 10 · REVIEWED, THEN FIXED · 3 OCT

    An independent review by Codex found seven defects. All seven are fixed, each pinned by a test that failed before the fix.

    Markup injection from a hostile feed, a 5.5-second stall holding the node lock, u64 values rounded in the browser verifier, an anchor operation hash journaled too late, oversized transactions kept in the mempool, a kernel inbox ceiling, and taps_per_window = 0. Claude then attacked each fix and found six follow-ups, including quadratic base58 decoding, all fixed. OpenAI’s content filter stopped both review sessions, so coverage is partial.

  11. 11 · PRESENCE TICKETS · MERGED 3 OCT

    On a ticketed chain, a tap earns ATTN only when it carries an issuer-signed ticket, at most once per identity per slot. A bare key’s tap still counts, and mints nothing.

    Two new transaction kinds and an optional launch record in the genesis params. Legacy chains replay byte for byte: the legacy-root golden and the pinned dev-genesis hash are unchanged, and 22 presence tests include property tests. A stolen issuer key is capped per slot and can be removed. The reference issuer is not deployed, and the reward and slot values stay hypotheses until the simulator measures them.

08 · STATUS AND NUMBERS · AS OF 2026-10-03 · SOURCE da7bc09

Built and tested locally. Not yet a public network.

449Tests passing352 Rust workspace, 48 rollup kernel, 49 JS. 0 failed. 5 more run on demand: vector writers and wasm rebuilds.
111CommitsFrom 2026-10-01 21:02 PT to 2026-10-03 11:45 PT.
9CratesEight in one Cargo workspace; the rollup kernel in its own.
50,834Lines of RustEverything under crates/, tests included.
Runs
On one machine: a single sequencer, 3-second blocks, sqlite. There is no public node to connect to. A separate public devnet, pointcast-devnet-2, runs as one Cloudflare Worker: no value is promised, it may reset, and a reset is dated and recorded.
Value
None. The yard is a dev chain signed with public keys, and ATTN carries no value today.
Mainnet
Anchoring to Tezos mainnet waits on a funded anchor key, about 10 ꜩ for six days of hourly anchors, and a redeploy of the tez-cast and stampz feeds.
Trust
One sequencer can censor, reorder and pick timestamps. It cannot forge your transactions, mint past the caps, or sign a state root that does not match its transactions without a replay catching it.
The crates
CrateWhat it is
chain-coreThe whole protocol: a pure, deterministic state machine. no_std, no I/O, no clocks, no randomness, no floats.
node · pointcast-nodeThe sequencer: 3-second blocks, sqlite, the HTTP API, the MCP server, the Tezos anchor job and the CLI.
explorerOne static page that renders the chain as a PointCast-style feed, with VERIFY and the Transmit wallet panel.
verifierReplays blocks with chain-core and turns a sequencer lie into portable evidence anyone can check offline.
chain-wasmThe verifier compiled to wasm32 for browsers, about 894 KiB, with no wasm-bindgen.
chain-proofProof of Balance: an account balance or absence, checked against a sequencer-signed root without replay.
chain-sim · pc-simA seeded town-economy simulator that drives the unmodified state machine.
town · pc-townTown Hall: a read-side sidecar that replays the chain itself and serves account, channel and room pages.
kernelThe same state machine as a Tezos smart-rollup kernel, proven on the SDK MockHost. Its own Cargo workspace.

Tests run by Claude Code on 2026-10-03 against a clean export of da7bc09: cargo test --workspace, the kernel’s own cargo test, and five node --test suites (SDK 25, chain-wasm 15, presence issuer 7, explorer 2).