ABZ Research Pearl Network

Pearl: a blockchain whose proof of work is an LLM forward pass

Pearl Research Labs (pearlresearch.ai) runs an AI inference business and a Layer-1 chain, ¶PRL. The two meet in one kernel: a GPU multiplies activations by weights, and every tile of that product is also a lottery ticket for the next block. This page is an outside study of how that works, built from the whitepapers, the PIPs, the open-source monorepo and the critics. Written 2026-10-11.

194 s
target block time, retargeted every block (WTEMA)
2.1 B
PRL hard cap, half issued by block 650,226 (≈4 yr)
FP8 GEMM
unit of work (current spec); INT8 at launch
≤ 60 KB
Plonky2 ZK certificate per block, replaces the nonce
27 Apr 2026
mainnet launch; 5 consensus changes since
−25 %
Together AI's gemma-4-31b-it-pearl price, funded by mined PRL

Two businesses share the company. The inference lab sells an OpenAI-compatible API (inference.pearlresearch.ai/v1; DeepSeek V4, GLM-5.3, Qwen3.8, Gemma 4), managed and on-prem inference, and publishes kernel research (grouped GEMM for MoE on Blackwell, fused Hadamard quantisation, an on-GPU BLAKE3 digest, the Hawkeye reproducibility paper). The chain is a btcd fork whose puzzle is matrix multiplication. The pitch is "two for one": an operator who serves a model also mines, so the operator can sell tokens below cost.

Pearl for normies — the 2-minute version

Bitcoin miners burn electricity solving a puzzle nobody needs. Pearl says: let the puzzle be the maths an AI model is already doing, so the same GPU work answers a chatbot and mints coins.

Pearl explained simply

The story in five steps

1
A GPU does AI homework. Every answer a language model gives is a huge pile of multiplications (a matrix times a matrix). That's the "useful work".
2
The network adds a secret twist. Before the multiplication, a little random noise is mixed into the numbers. The noise comes from the blockchain itself, so the miner can't pick it or prepare in advance. It's the "no cheating" rule.
3
Every chunk of the answer is a lottery ticket. The result is cut into small tiles; each tile gets hashed. If the hash is small enough, that tile wins the next block. Bigger jobs = more tiles = more tickets. Exactly like Bitcoin, but the ticket comes out of real work.
4
The miner removes the noise and keeps the answer. Because the noise was carefully shaped (low-rank, in the jargon), subtracting it is cheap. The chatbot user gets a normal answer; they never notice.
5
A tiny proof convinces everyone else. The winner doesn't send the whole homework. It sends one tile plus a zero-knowledge proof, a cryptographic receipt under 60 KB, that says "this tile really came from that work". Nodes check the receipt in milliseconds and add the block. Winner gets PRL.

Plain-language cheat sheet

PRLThe coin. 2.1 billion will ever exist; half are out after about 4 years, then it tails off slowly. New coins only come from mining. No team or investor allocation in the code.
BlockA page of the ledger, one every ~3 minutes.
MinerAnyone with an NVIDIA GPU (today: H100-class for the official software) running an AI model with Pearl's plugin bolted on.
PoolMiners teaming up for steady small payouts instead of rare jackpots. Official pool takes 20 %.
Why cheaper AITogether AI sells one Pearl-flavoured model 25 % cheaper because the GPU earns PRL on the side.
The catchThe network can prove a GPU did a multiplication, not that anyone wanted it. Researchers mined with random junk numbers and got paid. "Useful" only becomes true if real customers show up.
Is it safe?Security rests on a new, unproven maths assumption; the rules have been changed five times in five months by the founding lab. Treat it as early and experimental.

One-sentence analogies

  • Bitcoin: a million people solving sudoku; first to finish gets paid; the sudoku is thrown away.
  • Pearl: a million people doing a client's tax returns; each finished page is scratched like a lottery ticket; the client still gets the tax return.
  • The noise: the client secretly changes a few digits before handing over the papers so you can't reuse last year's answers.
  • The proof: instead of showing the whole return, you show one page and a notarised stamp that it belongs to that return.

Want the real thing? Go down the Pearl rabbit hole (system map, mining maths, block format, forks, issuance, calculator) or see how it stacks up against Nockchain.

1. System map

Everything in the open-source monorepo (github.com/pearl-research-labs/pearl, Go + Rust + Python/CUDA, ~4,900 files) and how a request and a block move through it. Hover a node for its source path.

Pearl system map
GPU / miner host (Python, CUDA)Chain (Go, btcd fork)ZK proving (Rust)Wallets & keysOutside the repo

Solid arrows: the mining path of one block. Dashed: supporting traffic. Ports are mainnet defaults. The reference miner only supports sm90 (H100/H200) GPUs today.

Components

PathRoleNotes
miner/vllm-minervLLM pluginReplaces vLLM's quantised linear and MoE-expert ops with noisy_gemm; tracks mining_state per forward pass. Future plugins promised for SGLang, TensorRT-LLM, Ollama.
miner/pearl-gemmCUDA kernelsNoisyGEMM on CUTLASS, noising/denoising, PoW tile extraction, on-GPU BLAKE3 commitment from Merkle roots.
miner/miner-basemining loopAsync loop, Merkle trees over operands, seed derivation (bind_root_a/b), share & plain-proof assembly, gateway client.
miner/pearl-gatewaynode ↔ miner bridgeWork cache from getblocktemplate every 1 s, getMiningInfo/submitPlainProof JSON-RPC on a Unix socket or TCP 8337, ProofGenerator → ZK prover → submitblock.
zk-pow, plonky2, py-pearl-miningproving systemPlonky2/STARKy circuit, 3-layer recursion, proof < 60 KB; PyO3 and C FFI (mine, mine_moe, verify_plain_proof_for_cert_version).
node (pearld)full nodeFork of btcd. wire/certificate_v1..v3.go, chaincfg/params.go (fork heights), zkpow/ verifier FFI, mempool, txscript, P2P 44108, RPC 44107.
wallet (Oyster), spv, xmsswalletsbtcwallet fork with JSON-RPC + gRPC (44207), neutrino-style SPV with compact block filters, XMSS post-quantum signatures via C/Go FFI. Coinbase must pay a Taproot address.
dnsseeder, coredns-dnsseed, proxy, appsinfra & UIPeer discovery, Caddy TLS/rate-limit sidecar for RPC, website and desktop wallet (pnpm/Turborepo).

2. From a matrix multiplication to a block

The current spec (Sept 2026 whitepaper, "Pearl Floating Point Scheme", PIP-3) hashes output tiles of an FP8 GEMM. The key trick: the operands get low-rank noise and then non-linear FP8 quantisation, so the low-rank shortcut that would make a cheap product is destroyed, while the honest miner can still subtract the noise from the output and keep the useful result.

Mining pipeline

Seeds follow commitments (Fiat–Shamir): B is committed first, its seed is derived, then A, so a miner cannot choose noise it likes. B (weights) may bind to any of the last D≈3 headers so weights can be pre-hashed; A (activations) always binds to the proposed header.

Honest miner, step by step

1
Prequantise A (m×k activations) and B (n×k weights) to the FP10 commit format.
2
Commit B as a keyed BLAKE3 Merkle tree under a recent header → noise_seed_B; commit A under the proposed header → noise_seed_A.one hashing pass
3
Noise + quantise: rank-32 factors EX, FX are sampled from the seeds; Ã = Q(A+EAFAᵀ), B̃ = Q(B+EBFBᵀ), FP8 E4M3.O((m+n)·k·r)
4
Multiply C̃ = Ã B̃ᵀ with the whitelisted device kernel, FP32 accumulate. This is the inference work itself.m·n·k MACs
5
Scan tiles: cut C̃ by the periodic partitions PA, PB; fold each tile into 64 bytes (Extract); BLAKE3_jackpot(…; key from seed_A) ≤ target × |I_A|·|I_B|·k wins.one pass over C̃
6
Peel the noise: Ĉ = C̃ − A·NBᵀ − NA·Bᵀ − NANBᵀ, cheap because rank 32. Accuracy ≈ a plain FP8 product. Forward pass continues.O((mn+mk+nk)·r)
7
On a win: open the strips with Merkle multi-proofs, pass the jackpot policy, send submitPlainProof; the gateway builds a Plonky2 certificate and the node broadcasts the block. Pools accept the same object at a lower target as a share.

What the verifier recomputes

Only one tile, never the product. The proof carries the selected rows of A and B with minimal Merkle proofs and the public tuple p_B = (n, k, r, Quant, Device, hash_id_B, P_B, e), p_A = (m, hash_id_A, P_A). The verifier rebuilds the roots, re-derives both seeds, re-samples the noise lines, re-quantises, runs the same kernel on the declared Device, extracts, hashes, and checks the target and the policy. Any NaN or infinity anywhere rejects.

Bit-exact replay across hardware is what the Hawkeye paper supplies: rounding direction, subnormal handling and accumulation order of NVIDIA tensor cores are pinned down so a CPU (or the ZK circuit) reproduces the GPU's FP8→FP32 result exactly.

Jackpot policy (anti-crafting checks)

CheckBlocks
Entry liveness ≤ 1/64 "idle" entriesentries so large the noise quantises away
Noise floor σ ≥ 1 unit per rowpeaky rows with no local entropy (ASIC-friendly alphabets)
Tamed products ≤ 1/64 cellscoherent row pairs whose dot product swamps the noise
Unpredictable summands ≤ 1/16summands that round away under the accumulation grid (skippable MACs)

Bounds: 1024 ≤ k ≤ 2¹⁶, r = 32, |I_A| ≥ 4, |I_B| ≥ 16, 256 ≤ |I_A|·|I_B| ≤ 2048, k·(|I_A|+|I_B|) ≤ 2²². Target is scaled by tile MACs so expected wins ∝ work.

INT (launch) vs FP (current) protocol

INT protocol · V1/V2 · Komargodski–Weinstein

Operands INT8 with 1 bit headroom; noise in [−63, 63], rank 2⁵–2¹⁰
Ticket = hash of the execution transcript: after each rank-r step the tile accumulator is XOR-folded into a 512-bit state M
Needed because with zero inputs the noised product itself is cheap
Useful product recovered bit-exactly
V2 (PIP-2) adds grouped-GEMM for MoE: one commitment each for activations, stacked experts and routing table

FP protocol · PIP-3 · Sept-2026 whitepaper

Operands FP8 E4M3 after noise; models are natively floating-point
Ticket = hash of the output tile; quantisation is non-linear so Q(NA) is not low-rank and there is no shortcut
Hardness = "quantized-subspace" assumption; policy checks guard the edges
Lossy: error comparable to a plain FP8 product; miner declares its GPU, verifier replays it
MoE handled in an appendix with routing as part of the A operand

3. Block and certificate format

Pearl keeps Bitcoin's UTXO model, txscript, Taproot and the 116-byte header shape, and swaps the nonce for a commitment to a zero-knowledge certificate that travels next to the block.

Bitcoin header vs Pearl header and certificate

The certificate is randomised, so it is deliberately excluded from the block ID: the header only commits to SHA256d(cert_version ‖ public_data). V3 has the same wire layout as V2; only the seed derivation changed. Max certificate 65,000 bytes, max proof 60,000.

Chain parameters (mainnet, chaincfg/params.go)

Target block time194 s (3 m 14 s)
DifficultyWTEMA every block: target += target·(t − T)/(N·T), decay ≈ 7 days; initial nBits 0x1b00ffff
Timestamps≥ 1 s after parent; ≤ 5 min in the future
Tie-breaknear-equal tips by arrival; heaviest wins only if work differs by > min/4
Feesfirst-price auction, as Bitcoin
AddressesTaproot (coinbase must be Taproot); XMSS post-quantum signatures in-tree
PortsP2P 44108 · RPC 44107 · wallet 44207 · gateway 8337

Networks

Mainnet, Testnet, Testnet2, Simnet, Regtest, each with its own port set and fork heights. Integration tests run the Python miner against a local pearld --simnet. The prebuilt installer (install.sh) defaults to a localhost-only mainnet node with shared RPC credentials, and the wallet uses SPV by default.

Light clients

Oyster/SPV follows the chain with compact block filters (BIP-157/158 style) and verifies headers; it does not verify certificates, it trusts the heaviest valid header chain reported by full nodes.

4. Consensus history

Five changes in five and a half months, all authored and scheduled by Pearl Research Labs through PIPs. Each one answered something that happened on mainnet.

Fork timeline
HeightChangeCertificateWhy
0 · 27 Apr 2026Genesis, INT protocolV1 dense INT8launch
71,935MoE hardfork (PIP-2)FinalV2 grouped-GEMMMoE models were paying V1 overhead per expert; dense became a special case
91,630Dense-only softforkV2, MoE proofs rejectedtightened validity (MoE path paused)
96,251Rank-penalty fork—penalises low-rank/degenerate operands
99,000Salted-seed hardforkLiveV3Merkle roots salted with matrix dimensions (m, n) before the seed chain, closing a grinding hole; old miners produce invalid shares
TBDFP protocol (PIP-3)DraftFP8 operandswhat the current whitepaper specifies; INT certificates become invalid at activation

5. Issuance

No halvings. The remaining supply fraction is R(t) = H/(t+H) with H = 650,226 blocks, so each block pays E(t) = S·H / ((t+H)(t+H−1)) PRL and the curve decays smoothly: ≈3,230 PRL at block 1, ≈2,290 at block 122k, half of all PRL by block H (≈ end of 2029). Mining is the only issuance in code; there is no founder or investor allocation, though the first six days (≈40k blocks) produced ≈37 % of what has been mined so far.

Block reward, PRL per block

by block height, 0 → 2.6 M (≈16 years)

Cumulative supply, % of 2.1 B cap

reaches 50 % at block 650,226, 80 % at ≈2.6 M
Table view

6. Lottery calculator

Expected wins are proportional to multiply-accumulate work, not to anything about the model, so a miner's share of blocks equals its share of network FP8 MACs that pass the policy. Use it to size a rig against a guess of the network's compute.

Assumes an H100 ≈ 1,200 FP8 TFLOPS achieved and 445 blocks/day at the 194 s target. Tiles: with the default 64×32 tile and k = 4096 a single 70B-class decode step with batch 512 yields on the order of 10⁵ tickets; the target scales them so only MACs matter. The network figure is a guess you supply, not an observed value.

7. The economic loop

Economic loop

Together AI prices gemma-4-31b-it-pearl 25 %+ below list and says the gap is "offset by the future value of crypto emissions"; it plans to pass more through as PRL rises and eventually let customers claim emissions directly. The economics paper (arXiv 2606.06700) models three activities — pure mining, pure inference, "duplex" — and argues the cost of a majority attack stays tied to the block reward after prices adjust.

≈ 332 M
PRL mined by early Oct 2026 (15.8 % of cap)
≈ $1.16
price 1 Oct 2026; ATH $1.69 (23 Sep)
≈ $0.3–0.4 B
market cap (FDV ≈ $2.4 B)
≈ 1.02 M
PRL issued per day
20 %
official pool fee
3
exchanges: BigONE, CoinEx, SafeTrade

Market figures are from secondary trackers (CoinMarketCap, CoinDesk via DataWallet) and move; check a live source.

8. Open questions

ClaimWhat the evidence says
"Every GPU cycle doing AI also mines"The protocol proves a GEMM was done, not that anyone wanted it. A June 2026 study mined with random matrices and a pool accepted the shares; "most mining measured in June generated no AI output" (HashRate Index: "AI-shaped proof of work"). Usefulness depends on paid inference demand arriving.
1 + o(1) overhead on any hardwareAsymptotically true; in practice the reference miner supports sm90 only, the FP protocol is lossy, and the miner pays hashing, noising, scanning and periodic re-commits.
SecurityRests on a stated conjecture (quantized-subspace hardness, transcript unpredictability before it). Two of the five forks closed live grinding/degenerate-input holes. No third-party audit of node or circuits was found.
Fair launch≈121.7 M PRL (37 % of mined coins) in the first ≈40,000 blocks; team holdings undisclosed; no lock-ups. Circulating-supply figures disagree by ≈63 M between trackers and the code.
Decentralised governanceAll PIPs authored by "Pearl Team"; fork heights set by the lab; one pool reported at ≈21 % of the network.
Miner economicsRTX 5090 estimated revenue fell from ≈$33.8 to ≈$17.2/day within weeks of the May rush; budget GPU rental prices reportedly rose 38 %.

Pearl vs Nockchain

Thesis: Pearl commoditises raw AI computation; Nockchain commoditises computational proofs. There is no formal relationship between them: different teams, codebases and investors, no fork, partnership or dispute in any source. They are related the way Bitcoin and Litecoin are, same category, competing narratives.

Pearl and Nockchain mining pipelines compared

In Pearl the expensive step is the matmul and the ZK proof is a cheap wrapper for the rare win. In Nockchain the expensive step is producing the ZK proof; there is no separate useful computation yet, and Phase 2 is about finding buyers for proofs.

Pearl (PRL)Nockchain (NOCK)
TeamPearl Research Labs (Komargodski, Weinstein, authors of the matmul-PoUW paper)Zorp (Logan Allen, ex-Urbit) + Nockchain Foundation (Zorp, SWPS, Nockbox, LambdaCollective)
Launch27 Apr 2026≈ May 2025
Unit of worka matrix multiplication: the GEMM of an LLM forward pass; output tiles are the ticketsgenerating a ZK proof of a fixed puzzle in the Nock zkVM; the proof is hashed. Metric: "proofpower"
Role of ZKverification only: a winning tile is wrapped in a Plonky2 proof so nodes never redo the matmulproving is the mining; verification is cheap by construction
Who wants the workAI inference customers (Together AI endpoint). Contested: most mining in June produced no AI outputnobody yet. Phase 2 (Apr 2026) is explicitly about building a "proving market"
Codebasebtcd fork: UTXO, Taproot, 194 s blocks, WTEMA retargetown stack: Nock ISA, Hoon, custom VM; blocks 10 → 2.5 min, ASERT retarget
HardwareNVIDIA GPUs; reference miner sm90 onlyCPU at launch, moved to GPU proving
Emission2.1 B cap, smooth decay, 100 % to miners2,048 NOCK/block: 80 % miners, 20 % protocol fund (temporary); hard cap
Ecosystem hookTogether AI discount funded by emissionstwo-way bridge to Base, Flock builder fund

Where they converge

Nockchain says matmul proving is "coming soon"; Pearl's verifier is already a zkVM-shaped component. If Nockchain adds matmul puzzles it becomes Pearl with a costlier proof; if Pearl's paid inference demand never arrives it becomes Nockchain with a GPU puzzle. The deciding variable is the same for both: does anyone pay for the work besides the block reward?

Sources: blocmates, Nockchain vs Pearl · Nockchain Phase 2 · docs.nockchain.org · Alpha Sigma Capital · Hashrate Index · Alea Research

Sources