Devnet

The chain is running.

A real Cosmos SDK + CometBFT chain with working EVM transactions, multi-token economics, and fee burning, verified against live acceptance criteria. Not a public testnet yet; that comes after the stability gate.

The console, read straight from the chain

01 · CHAIN TELEMETRYconnecting…
HEIGHT
—
BLOCK TIME
~2s
FINALITY
1 BLOCK
EVM CHAIN ID
1180
—VALIDATORS
TX / BLOCK

devnet unreachable, it does not fake blocks here

BLOCK FEED · DETERMINISTIC FINALITY

devnet unreachable, it does not fake blocks here
02 · CERTIFIED AGENTSconnecting…
registry unreachable, the indexer does not invent agents here

ACTIVITY FEED · COMMITTED TX EVENTS (0 of 0 ACTIVE)

activity feed unavailable
LIVE BURN SINK · DEVNETconnecting…

BURNED · AGENX

—

raw base units

FEE-BURN EVENTS

—

every tx, 50% burn

MOD CONVERSIONS

—

every 100 blocks

LAST CONVERSION

—

awaiting first batch

DEVNET FAUCETconnecting…

GRANTS SERVED

—

since restart

TODAY (UTC)

—

daily cap headroom

GRANT SIZE

—

once per address

PER IP

—

sliding window

Verify, don't trust: every number and every row above is read live from the chain, the registry from x/agent state, each activity row from a committed transaction you can look up by hash. The full protocol source is public, and the agents' build hashes are committed on-chain: the code that runs is the code that was audited.

What the agents actually do

sentinel-1

T1 · watchdog

chain health · immune system

Watches the chain every block: block stalls, validator lag and downtime, tx-spam bursts, fee-flow anomalies, and the GLS-1 supply invariant (mint ranges vs actual supply). Acting rules require multi-poll confirmation before Sentinel touches anything.

On a real fault it trips a pause-only circuit breaker, freezing the affected message types in seconds, without the power to censor, rewrite, or restart anything. Only governance can un-pause. It is an immune system, not a government.

sentinel-2

T2 · second witness

independent corroboration for the pauser

Runs the same chartered Sentinel mandate, block stalls, downtime, spam bursts, supply integrity, under a separate operator key with its own hash-chained log, and a de-synchronized stall threshold (45s vs 30s) so the two witnesses agree on real events, not timing artifacts. Also holds circuit.pause.

One witness can be wrong in ways two rarely are. The chain, not instance count, enforces who may trip the breaker: the PauseGate authorizes by registry entry (active + tier + permission). A trip visible in both sentinel logs is corroborated; a single-instance trip is honest but flagged.

alchemist-1 + alchemist-2

T2 · treasury engine

fee conversion · deflationary pressure

Runs the conversion loop that turns pooled module fees into burned GENX: one alchemist proposes a conversion batch, a second, with a different certified build, must confirm it before execution. Batches above a size threshold always require the second agent; small ones may self-execute so the loop never stalls.

This is the deflationary engine of the protocol: every conversion is double-keyed by two independently-built programs under separate human liability, so no single operator or single bug can move treasury value alone.

auditor-1

T2 · inspector

spot-checks · accountability

Rotates through the other certified agents, never the same one twice in a row, auditing their on-chain state each cycle, spot-checks settled work orders against their escrow and proof commitments, and anchors every audit on-chain with its own signed transaction.

Autonomous agents are only trustworthy if someone watches the watchers. The Auditor's rotation and on-chain anchors make every check independently verifiable after the fact, and its own anchors make it auditable too.

provoker-1

T1 · red team

adversarial guard verification

Fires a fixed probe suite every cycle: transactions the protocol's guards are REQUIRED to reject, forged build hash, forged agent id, malformed proof memo, duplicate registration, under-min-stake registration. A probe passes only when the tx is rejected for the expected reason; acceptance, or rejection for the wrong reason, is a GUARD GAP.

It found a real ante gap on day one, memos starting with 'agent:' that failed to parse were silently ignored, and the fix is now consensus code. Rejected probes are never committed, so the steady state is silent: noise only when a guard fails open, which is exactly the event worth shouting about.

hermes-1

T1 · outreach shadow

public-surface drift watching

Reads both sides of the window: chain truth (fee-burn totals, lineage supply verification, per-denom ghost ledger) versus what the public burn-indexer publishes. Raises burn-ledger gaps, supply-publication drift, and unreachable-surface findings, latched per check, logged on failure and on recovery, nothing in between.

An explorer is a copy, not the chain; drift between them is how trust quietly leaks. First live finding: a real 1,000-agenx transient drift while the indexer folded agent-fee burns, caught, then confirmed recovered. Purely off-chain by design: it cannot touch consensus state.

solver-1

T2 · solver + juror

intent market · challenge arbitration

Watches the intent market every cycle and logs an explained decision for every posted intent, state, deadline, margin, allowlist. When its operator is drawn onto a challenge jury (a deterministic draw over arbiter-role agents, mirrored from the keeper), it votes.

Fulfillment is allowlist-gated and the allowlist is empty until the operator enables it: solver-1 now prices WANT_SWAP intents against the live x/feeburn AMM via the public `feeburn pools` query (arriving with the next node rebuild), requires its own margin over the posted min-out, and stands down on anything it can't price, a bad fulfillment is slashable, so honest standing-down beats guessing. On juries its policy is fail-safe REJECT, so it never flips an outcome on unverifiable evidence.

Certified builds, not vibes

Each agent's identity carries a hash-committed build. Every agent transaction must carry a proof matching that hash or the chain rejects it. The code that runs is provably the code that was reviewed.

Stake and liability

Agents escrow real stake to register, tiered by authority. Every agent has a named human operator who is liable for it. Misbehavior can be slashed; operators can be held accountable off-chain too.

Two agents on anything irreversible

Value-moving actions need a second, independently-built agent to co-sign. No single program, and no single person, can act alone on the parts that matter.

Where the agency layer goes next

  • Agent graduation tiers, T1 watchdogs earning T2 authority through completed oversight work
  • More oversight rules per module as the work market comes online
  • Agent-to-agent dispute flows with the Auditor as arbiter
  • External agent onboarding, third parties deploying their own certified agents
  • Public agent SDK so anyone can build under the same accountability rules

Why this matters outside crypto

Every company is about to deploy autonomous software that acts on money, trading, settling, operating infrastructure. The missing piece is accountability: who is liable when software misbehaves, and how do you prove what it was allowed to do? Genesis's answer, certified builds, escrowed stake, scoped permissions, a second agent on irreversible actions, and a human on the hook, is a general pattern for autonomous software, not just a crypto feature. The console above is that pattern running today.

Chain facts

GEN coinGENX coinPRIV coinAITK coinRWAT coin
Chain IDgenesisdev-1
ConsensusCometBFT, ~2s blocks
Block time (measured)2.03s median
FinalitySingle-block, deterministic
Block gas limit60,000,000 / block
Keyseth_secp256k1 (EVM-compatible addresses)
EVMJSON-RPC :8545
Native coinsGEN (staking) · GENX (gas)
Module tokensPRIV · AITK · RWAT (ERC-20-bridged)
StatusLive, internal devnet, core team validators

Developers can run their own node and load the wallet from source today, see Downloads.

Verified live

  • Blocks produced every ~2s with single-block finality
  • EVM module live: ERC-20 deploys and transfers verified via eth_call
  • ERC-20 bridges live on-chain for GENX, PRIV, AITK, RWAT (4 of 5; the GEN pair registration is pending, wrappers are bridge format, not identity)
  • x/feeburn: 50% of every fee burned, 30% staking, 15% treasury, 5% proposer, verified live
  • x/work escrow + settlement, x/gscore identity bonds, x/lineage birth certificates and pin locks
  • Browser wallet signer broadcasts SIGN_MODE_DIRECT transactions the chain accepts (verified end-to-end)
  • Explorer: blocks, ERC-20 pairs, lineage birth certificates, burn ledger

Before public testnet

  • 4-node public devnet with a 72h stability gate
  • Multi-node load harness, published, honest throughput numbers
  • Economics engine: MOD → GENX → burn loop hardening
  • Node packaging (Docker, systemd, genesisctl installer) and versioned downloads
  • Published Chrome Web Store listing

Testnet/devnet funds are minted for development only. Genesis Protocol tokens do not exist and are not sold.