Jul 2026
What a mesh can prove, and what it's just hoping
A signed receipt is easy. A receipt that means something is the whole problem.
Here's a fun thing you can do on any network that pays for compute. Wire a little proxy to a ham radio, advertise a service called morse.send, take people's money, sign a receipt that says "transmitted," and pocket it. Did you actually key the radio? Who knows. Nobody can check. The receipt is real, the signature is valid, and it means absolutely nothing. This isn't a bug you can patch. It's the shape of reality: the moment a job reaches out of the sandbox and touches the world — a radio, a camera, someone else's API behind a key — you can't re-run it to find out what happened. The photon left. The clock moved. Ask again and you get a different answer, or none.
Every "verifiable" network has to stare this down, and most of them just… don't. They slap the same green checkmark on everything and hope you don't ask what it's checking. That's the actual dishonesty, and it's the one we refuse. Because our whole pitch is "don't trust it, re-run it," a green check that doesn't survive a re-run isn't a nice-to-have we skipped. It's a lie in the one place we said we wouldn't tell one.
So we don't have one kind of receipt. We have four, and the receipt says which one it is.
Verified is the good stuff — a deterministic capsule you can re-run bit-for-bit and catch a liar with arithmetic. Trust nobody, check everything. This is the only one that gets the green check, and it gets it forever. Attested is the next rung down: the work ran inside a sealed chip that signs "I ran exactly this code," so you're not trusting the operator, you're trusting Intel or Amazon and their long, unglamorous history of side channels. Bonded is for the genuinely uncheckable stuff where you can at least pick a fight — the provider stakes money, and if anyone can produce a contradicting observation, the stake is gone. And Trusted is the floor, the honest floor: the radio transmitted, probably, because a provider with a reputation signed that it did, and there is no re-run, no chip, no challenge — just a name and its track record.
Morse code lives on that floor. So does the weather station, the camera, the payment to a bank. And that's fine — the point was never that everything is trustless. The point is that the mesh tells you the truth about how much it trusts each thing. A verified receipt and a trusted receipt are different colors on the page. You get to decide, before you pay, whether you want a fact or a promise.
This is the part I find quietly radical. It means the network is genuinely universal — you can expose anything through it, any weird native capability a proxy holds a key or a wire for, Morse code included — without the network ever lying about what it did. Most systems buy universality by lowering the bar until "verified" means nothing. We keep the bar exactly where it is and just… label the rungs below it honestly. You can do everything. The mesh will simply never call a promise a proof.
Anyone can sign a receipt. The trick is a network that tells you, out loud, which receipts it earned and which ones it's only hoping are true.
See a verified receipt checked in your browser ↗ · More writing ↗