Skip to content

Collateral, reputation and slashing

Every subscription (one device mining one project) is backed by NECTA bonded in the Staking contract. Collateral is always NECTA, whatever the project’s reward token is, so the cost of creating fake miners and of misbehaving is uniform across projects.

  • The project sets min_collateral (at least 1 NECTA, at most 1,000,000 NECTA).
  • More collateral raises your selection weight, up to min_collateral × weight_cap_multiple.
  • Each device on each project is a separate subscription with its own collateral.
  • subscription_id = keccak256(abi.encode(project_id, owner, node_key)): the owner is part of the id, so nobody can front-run a bond for your device.
stateDiagram-v2
  [*] --> pending_collateral: POST /v1/subscriptions
  pending_collateral --> active: Bonded (amount ≥ min_collateral)
  active --> paused: pause (Hub)
  paused --> active: resume
  active --> jailed: slash leaves bond < min_collateral
  jailed --> active: top up ≥ min_collateral
  active --> unbonding: unbond
  paused --> unbonding: unbond
  jailed --> unbonding: unbond
  unbonding --> withdrawable: after 24 h, no pending slash
  withdrawable --> closed: withdraw

Unbonding takes unbonding_secs (86,400 s on the testnet). While unbonding you are not selected but are still slashable for earlier rounds; withdrawal is blocked while a slash proposal against you is pending.

Reputation (1,000–10,000 basis points, starting at 5,000) multiplies your selection weight. It rises with votes that make it into finalized rounds and falls for accepted leases you did not deliver, offers you left unanswered, and invalid votes. The formula

Evidence is self-proving: it contains the signatures that prove the fault, so anyone can verify it.

Kind Proof Slash (testnet)
equivocation Two valid votes by the same key in the same round with different receipt hashes 100 % of the bond (slash_equivocation_bp = 10,000)
invalid_result Your vote for hash X, plus finality votes from a validator quorum on an audited record with a different hash R The project’s slashing_bp.invalid_result, at most 50 %
missed_sla Your signed accept, the lease deadline and a finality quorum without your vote Reputation only on the testnet; collateral slashing is coming soon (at most 5 %)

At most one slash per subscription per round. Reputation drops immediately.

  1. Evidence is submitted (the Hub does it automatically; anyone can via POST /v1/slashes). The Hub verifies and records it.
  2. The Hub proposes the slash on-chain (Staking.proposeSlash). The dispute window starts (dispute_window_secs of the project, 1 hour to 7 days).
  3. The miner may dispute before it ends: POST /v1/slashes/{evidence_hash}/disputes. On the testnet the network operator arbitrates and can cancel the slash.
  4. After the window, anyone can execute it. Slashed NECTA goes to the treasury; if the remaining bond is below min_collateral the subscription is jailed until topped up.