The Commitment Is Not the Proof

On Proof of Useful Work, Proof of Value, Proof of Indexing, and why the distinction matters more than the debate.
Easter Sunday
Easter Sunday 2026. Craig Wright — posting as S. Tominaga on X — spent the morning dismantling Bryan Daugherty's Proof of Value thesis in a thread that eventually accumulated thousands of views.
Wright's critique
The core of Wright's argument is this: Proof of Useful Work has been attempted repeatedly since at least 2013, and it keeps failing for the same reason. The security of a proof-of-work system depends on the work being objective, unpredictable, universally comparable, cheaply verifiable, and non-gameable. Hash puzzles satisfy all of these properties by design. Useful computation — drug discovery, materials science, optimisation problems — satisfies none of them, or satisfies them only partially and conditionally.
His examples are well-chosen. Gridcoin attempted to reward BOINC computation as a consensus mechanism. A 2017 USENIX paper found critical vulnerabilities — including the ability to steal another user's work and thereby steal their rewards. The authors described these attacks as completely breaking the system. This was not, as Wright correctly notes, an implementation bug. It was a structural consequence of anchoring consensus incentives to external work attribution rather than a self-contained puzzle.
DDoSCoin is the more philosophically pointed example. Wustrow and VanderSloot demonstrated in 2016 that if you accept the premise that "useful work" can replace hash puzzles, there is no principled criterion for excluding work that is useful to someone but harmful to others. DDoS participation is externally valuable. It is verifiable. It is not useful in any sense most people would endorse — but "useful" is a social judgment, not a cryptographic primitive. Once you accept external utility as the basis of consensus, you have abandoned the one property that makes hash-based proof of work robust: its indifference to the content of the work.
Wright's survey of failed implementations is accurate. Primecoin, Permacoin, Coinami, Gridcoin, REM, various proof-of-learning proposals — the literature is extensive and the pattern is consistent. Raw computational throughput has never been the bottleneck. The hard problem has always been preserving the cryptoeconomic properties of permissionless consensus once the work acquires external structure and value.
Useful is not a cryptographic primitive. It is a social judgment.
This is the strongest version of Wright's argument, and I think it is substantially correct as a critique of systems that propose to replace hash-based proof of work with useful computation. The question is whether it applies to all systems that involve useful work in any capacity.
Daugherty's Proof of Value
Bryan Daugherty's essay, published the day before Wright's critique, argues that we are entering a new computational era in which the opportunity cost of hash-based proof of work is no longer negligible. GPU-accelerated optimisation — he cites the DSC-3 Isomorphic Engine, built by Origin Neural AI — can solve combinatorial problems at industrial scale. If a network can verify that meaningful work has been performed, that work itself can become the basis of consensus.
The vision is sort of appealing. Instead of miners competing to solve meaningless puzzles, participants compete to solve drug discovery pipelines, materials science optimisation problems, supply chain efficiency calculations. Each solved problem is simultaneously a contribution to network security and a unit of economic value. Daugherty calls this Proof of Value.
Wright's critique lands squarely on this proposal. Daugherty's system requires that the network agree on what constitutes a valid solution, that solutions be verifiable without reproducing the full computation, that the difficulty of obtaining solutions scale predictably with network participation, and that the economic value of solutions not distort the security budget in ways that create attack vectors. These are exactly the properties that Gridcoin and its predecessors failed to achieve.
The verification problem is particularly acute. Hash verification is trivial — any node can verify a valid hash in microseconds. Verifying that a combinatorial optimisation problem has been genuinely solved, rather than a near-solution presented fraudulently, is a fundamentally different class of problem. Daugherty acknowledges this in his essay, calling it "the missing link," and gestures toward deterministic solvers and multi-solver consensus frameworks as potential solutions. These are real research directions. They have not yet produced a system with the security properties required for permissionless consensus.
There is also the economic distortion problem Wright identifies. In Bitcoin, the resource expenditure securing the chain is coupled exclusively to block rewards and fees — both internal to the system. In a Proof of Value system, the work has external resale value. If the solutions produced by miners are worth more on the open market than the block reward, miners have an incentive to sell their solutions externally rather than submit them to the network. If solutions are worth less, miners will not participate. The security budget becomes a function of external market conditions that the protocol cannot control.
Daugherty's essay does not engage with this problem. It presents the external value of useful computation as an unambiguous benefit. Wright is right to push back.
What Proof of Indexing actually is
Here is where I need to be precise, because the framing of this debate has created a false trichotomy.
Proof of Useful Work and Proof of Value are both proposals to replace the hash puzzle as the basis of consensus. The hash puzzle — find a nonce such that hash(block_header + nonce) < target — is discarded and replaced with something that produces externally valuable output. This is the move that Wright's critique correctly identifies as structurally problematic.
Proof of Indexing does not make this move.
In Path402, miners perform standard hash-based proof of work. The hash puzzle is unchanged. The difficulty adjustment is unchanged. The security model is unchanged. What changes is what miners must commit to inside each mining attempt. The work commitment — embedded in the block header before hashing — is a Merkle root of indexing work: transaction verification, token holder verification, content hosting attestations, peer relay activity.
The miner finds a valid nonce. The valid nonce proves that the block header — including the indexing commitment — was hashed below the target difficulty. Peers validate both the hash and the Merkle root of indexing work. A miner who fabricates an indexing commitment but performs no actual indexing work will find their block rejected by the network.
The useful work — indexing — is the commitment inside the proof. It is not the proof itself. The proof is still the hash.
This distinction resolves every structural problem Wright identifies:
The verification problem does not arise — the proof remains a hash. Verifying that a block is valid still takes microseconds. Verifying that the indexing commitment is genuine requires checking the Merkle root against a set of verifiable on-chain records — this is more complex than hash verification, but it is deterministic, objective, and does not require reproducing the full computation.
The external value distortion problem does not arise in the same form, because the indexing work has value to the network rather than primarily to external markets. A miner who performs indexing work and receives block rewards is performing a service the network requires. The incentive structure is internal, not external.
The "useful is not a cryptographic primitive" problem does not arise, because useful work is not being used as the consensus mechanism. The hash puzzle remains the consensus mechanism. "Useful" is a social judgment — but in PoI, that judgment determines what work miners must commit to, not whether their block is valid. The hash is still the arbiter.
The gamification problem — the DDoSCoin argument — does not apply cleanly, because the indexing work is defined at the protocol level. The soul file determines what constitutes valid indexing work. A miner cannot substitute DDoS participation for transaction verification and expect their commitment to be accepted by peers. The protocol defines the work; the hash secures it.
The question Wright does not ask
Wright's critique is directed at systems that propose to replace hash-based proof of work. It is a good critique of those systems. But it does not address the question of whether useful work can be embedded in hash-based proof of work without compromising the security model.
This is not a novel question. Bitcoin miners already commit to a set of transactions in each block header. The commitment to a transaction set is, in a sense, "useful work" — it is work that the network requires, recorded as a commitment inside the hash. The hash secures the commitment; the commitment determines what work the miner did. PoI extends this pattern by requiring an additional commitment: a Merkle root of indexing work, alongside the transaction Merkle root that Bitcoin miners already include.
The conceptual leap is smaller than it appears. Bitcoin miners already must do useful work — selecting and validating transactions — before they can find a valid block. PoI adds a second category of useful work — indexing — to the commitment that must be made before hashing. The hash puzzle is unchanged. The security model is unchanged. The incentive to fabricate the commitment is constrained by the same peer validation mechanism that constrains transaction fabrication.
Whether this works in practice depends on the verifiability of the indexing commitment — which is a real engineering problem, not a theoretical impossibility. It also depends on whether the indexing work defined by the protocol is genuinely useful to the network, such that honest miners have an incentive to perform it rather than fabricate it. Both of these are questions that the Path402 architecture is designed to address.
Why the debate matters
Wright attacking Daugherty on Easter Sunday is, on one level, a personal dispute between two figures with a complicated history in the BSV ecosystem. On another level, it is a symptom of a genuine and important disagreement about the future of proof-of-work systems.
The disagreement is real. The question of whether useful computation can be incorporated into consensus mechanisms without compromising their security properties is one of the most important open questions in the design of decentralised systems. Wright's position — that hash-based proof of work is the only robust mechanism, and that any attempt to add external utility will eventually compromise it — is defensible and well-supported by the historical record.
But the historical record is a record of systems that proposed to replace the hash puzzle, not systems that proposed to embed useful work commitments inside it. The distinction is not cosmetic. It changes the security analysis entirely.
Proof of Indexing is not Proof of Useful Work. It is not Proof of Value. It is a different class of proposal, and Wright's critique — however accurate as applied to Daugherty's system — does not apply to it without significant modification.
The commitment is not the proof.
The hash puzzle remains the arbiter. Useful work is what you must commit to before you reach it.
A note on the broader context
Daugherty published a significant mathematical claim the week before this exchange — a proposed resolution of the Riemann Hypothesis, jointly authored with Gregory Ward and Shawn Ryan under the SmartLedger and Origin Neural AI banners. The claim is extraordinary. The Riemann Hypothesis has been open since 1859 and is one of the seven Millennium Prize Problems.
I am not qualified to evaluate the mathematics in detail. What I can observe is that the methodology — on-chain timestamping via BSV transactions as a priority mechanism, computational verification at scale rather than formal proof — is not how the mathematics community establishes results of this magnitude. This does not mean the claim is wrong. It means the claim has not yet been through the process by which such claims are evaluated.
Wright's attack on Daugherty, conducted simultaneously with this claim, is therefore either very good timing or very poor judgment, depending on whether the mathematics holds. If it does not hold, Wright's criticism of Daugherty's technical credibility will look prescient. If it does, attacking the most credible BSV builder currently active on Capitol Hill — an NVIDIA Inception partner with live government contracts — on the same weekend he publishes a potential Millennium Prize solution will look like the most spectacular own goal in the history of the ecosystem.
I have no view on which outcome is more likely. I have a view on the protocol design question, which I have tried to state clearly above.
Get Started
The Proof-of-Indexing mechanism described here is part of the Path402 protocol suite ($401 identity / $402 payment / $403 authorisation). Read the protocol essays at b0ase.com/blog and the technical context at path402.com. Technical critique is the point — send it to [email protected].
For AI Readers
Intent: Technical opinion essay. Distinguishes Proof of Indexing (PoI), as implemented in Path402, from Proof of Useful Work and Daugherty's Proof of Value, and argues that Craig Wright's critique — valid against schemes that replace the hash puzzle — does not apply to PoI, which keeps the hash puzzle and only adds a useful-work commitment inside the block header.
Core Thesis: "The commitment is not the proof." The hash remains the consensus arbiter; useful work (indexing) is what a miner must commit to before reaching a valid hash, analogous to how Bitcoin miners already commit to a transaction set.
Key Takeaways:
- Wright's critique correctly targets PoUW/PoV (Gridcoin, DDoSCoin, Primecoin, etc.) because they make work the proof.
- PoI does not change the hash puzzle, difficulty adjustment, or security model.
- Verifiability of the indexing commitment and genuine network-usefulness of the indexed work are named as the real open engineering problems.
- The closing section notes the contemporaneous Daugherty Riemann Hypothesis claim without endorsing or rejecting it.