mesh-transport
WIREDThe nervous system. Kademlia DHT routing by Ed25519 key, LoRa with CSMA/CA, BLE, STUN-less UDP hole punching. Identity lives here too: keys, not IPs.
Phones. Raspberry Pis. LoRa radios. Old laptops in closets. MossyMesh stitches them into a compute mesh that needs no DNS, no cloud, no permission, and keeps running when everything else goes dark.
A storm takes out the only bridge to the mainland. The fiber goes with it.
The grocery store's card reader dies. Not because the food is gone, but because the payment has to ask a data center three thousand miles away for permission. Your message to your neighbor fails for the same reason: it was never addressed to your neighbor. It was addressed to a cloud.
MossyMesh starts here. Every phone, Pi, and LoRa radio in town already talks to its neighbors over Wi-Fi, Bluetooth, and long-range radio. The mesh turns that chatter into a computer. Jobs split across the devices around you. Results come back with cryptographic proof they were computed correctly. Nobody asks the mainland for anything.
When the bridge gets rebuilt, the town's little ledger syncs with the world. Credits earned in the dark settle in the light. Nothing was ever down. It was just local for a while.
Fiber cut, DNS unreachable, cloud region gone. Every centralized dependency becomes a single point of failure at once.
Devices route by cryptographic identity over Wi-Fi, BLE, and LoRa. No registrar, no IP allocation, no permission.
Compute jobs fan out across nearby hardware. Every result carries proof it was computed right, verifiable by any node.
When uplink returns, the local ledger merges with the world. Offline earnings settle. Nothing was lost.
Every "decentralized" project still phones home. A domain registrar. A cloud bucket. An API key that can be revoked at 3 AM by someone you've never met.
MossyMesh starts from a different premise: assume the infrastructure is hostile or gone. Four constraints govern every line of code, and none of them bend.
Your address is an Ed25519 public key, not an IP. A Kademlia distributed hash table (DHT) finds the key, not the machine. No DNS lookup, no registrar to seize.
Jobs run in a sandboxed WASM runtime with static INT8 math. Same bytes in, same bytes out, on a Pi or a PC. Anyone can re-run your job and check.
Designed for dead zones, disaster zones, and censored zones. The mesh is the network. The internet is optional.
The active ledger never exceeds 10 MB. Old history folds into constant-size proofs and gets dropped. A Raspberry Pi Zero is a full citizen.
Every packet you have ever sent traveled through chokepoints someone could grip: a DNS registrar, a cloud region, an API key. Watch the difference. Illustrative simulation.
Device asks DNS. DNS points at cloud. Cloud answers. Three parties must stay up, honest, and reachable. Any one of them can say no.
The packet knows only a public key. It hops node to node until it arrives. A node dies mid-flight; the mesh routes around the corpse.
The whole system is eight Rust crates plus a TypeScript frontend. Status is honest: WIRED runs in the repo, PARTIAL real code with mocks inside, TARGET the number we're aiming at.
The nervous system. Kademlia DHT routing by Ed25519 key, LoRa with CSMA/CA, BLE, STUN-less UDP hole punching. Identity lives here too: keys, not IPs.
Shared truth without a referee. Custom Merkle trie over Blake3, YATA-inspired CRDT (conflict-free replicated data type) merges, LRU eviction holding the ledger under 10 MB. Recursive folding is a mock today.
The chess brain. shakmaty bitboards, deterministic, compiling to wasm32-wasip1. Evaluation target: 836 Mnps class. TARGET
The cage. WASM execution with a hard 10 MiB guest heap: one byte over and the job dies. Static INT8 math keeps every chip in agreement. Native WAMR sits behind a feature flag.
The bridge back. Axum gateway, WebSocket sync with exponential backoff, TWAMM with a 2% max-spread cap, HTLC escrows. The VDF-delayed cancel is still a mock.
No permanent bosses. Web-of-trust onboarding, quadratic staking, a 3-of-5 admin multisig whose power decays to zero over 90 days, ZK-blinded commit-reveal votes.
The heavy tier. SITF tensor containers, vLLM-style paged attention for long contexts, a real CPU backend today and a Vulkan backend for the GPUs.
The proof it's one machine. A smoke harness running the real offline pipeline end to end: VDF admission, sandbox invoke, chess eval, ledger insert, Merkle proof verify.
Plus the frontend: a TypeScript PWA served over a captive portal. This page is part of it.
Every job on the mesh runs in a cage.
The cage holds exactly 10 MiB of guest heap. Ask for one byte more and the runtime kills the job on the spot. No negotiation, no swap, no mercy. That harshness is the point: a Pi Zero can host a stranger's compute without fearing a memory bomb.
The cage also bans floating-point chaos. Tensor math goes through static INT8 quantization, so a phone and a laptop produce bit-identical outputs. If two devices disagree on a result, the merge is wrong, and the network knows it.
Honest note: the cage is a pure-Rust host simulation today; native WAMR links behind a feature flag. The 10 MiB limit is enforced either way.
> cage armed. allocate memory to test the limit.
Blockchains ask every phone to carry the entire history of everything. MossyMesh refuses.
The active ledger stays under 10 MB, and old history doesn't get stored, it gets folded. Each new proof certifies that the latest transaction correctly followed the proof of everything before it. After a million transactions the device holds one small proof, not a 50 GB archive. What no longer fits gets evicted, least-recently-used first.
Honest note: the folding prover is a mock in the repo today and the nova-snark backend stays unwired until the circuit earns its place. The eviction and the sub-megabyte payloads are real.
> 8 proofs sitting in RAM. fold them.
With no IPs and no captchas, what stops someone from minting a million fake identities and drowning the local radio in garbage?
Time. To submit a job, your device must grind through 50,000,000 sequential steps of a Wesolowski verifiable delay function (VDF) over RSA-2048. Sequential is the whole trick: you cannot parallelize it, you cannot buy your way out with more cores. On ordinary hardware the burn takes about ten minutes. Verification takes milliseconds.
One job, ten minutes: annoying but fine. Ten thousand fake jobs: seventy days of continuous grinding. The spam math stops working.
The first design used MinRoot. Issue #199 killed it: verifying MinRoot meant re-running all fifty million steps, turning every verification into a CPU-denial-of-service amplifier. Wesolowski verifies fast. The scar tissue lives in docs/math-wesolowski-vdf.md. Whether ten minutes survives a determined ASIC farm is still an open question; the risk register calls it medium probability, and nobody has published a number.
> illustrative fast-forward. the real burn is ~10 minutes of sequential grind.
The mesh can live in the dark forever. But sometimes the fiber comes back.
Then the interop crate opens the bridge: an Axum HTTP gateway and a WebSocket sync loop with exponential backoff. Credits earned offline settle against global liquidity through a TWAMM with a hard 2% max-spread cap, so rejoining the world doesn't mean getting skinned on the spread.
Payments between strangers ride on hash time-locked contracts: escrows that need no trust and no judge. The VDF-delayed cancellation that would make them airtight is still a mock. That's the next weld.
HTTP and WebSocket surface for jobs, sync, and liquidity when uplink exists. Same contracts the offline island already speaks.
The reconnect loop backs off instead of hammering a flaky link. Islands merge when the link holds, not before.
A time-weighted automated market maker (TWAMM) for offline-earned credits, with the spread cap enforced in code. No silent skimming.
Hash time-locked contracts hold job payments between strangers. Neither side can defect mid-partition. VDF CANCEL: MOCK
No data center. No rack. The minimum viable offline supercomputer fits in a backpack and costs less than a flagship phone. From the repo's own procurement table, USD.
| Qty | Tier | Hardware | Cost |
|---|---|---|---|
| 2 | Pi-Tier (genesis nodes) | Raspberry Pi Zero 2 W, 4, or 5 | ~$150 |
| 3 | Edge / IoT tier | ESP32 microcontrollers with SX1262 LoRa transceivers | ~$60 |
| 1 | Regional hub | NVMe-equipped high-capacity mini PC | ~$250 |
| - | Physical layer gear | Power banks, HF ham radio links, high-gain antennas | ~$150 |
| 12 mo | SaaS & tooling | Pro-tier AI assistants, developer workspace | ~$360/yr |
| Total initial outlay | ~$970 | ||
The Pis are the citizens. The mini PC is the librarian. The radios are the roads.
Every change to the repo is judged against five numbers from docs/sla-and-dod.md. Miss one and it doesn't ship.
The whole shared state must fit in a rounding error of RAM.
A result nobody can verify is a result that never happened.
Flaky LoRa links, interference, dead air. The mesh still delivers.
RVCH: Resilient Verifiable Compute-Hours. The island doesn't count jobs. It counts proven work.
If any single company can turn it off, it isn't MossyMesh.
If two phones in airplane mode can agree on a chess position, they can agree on anything.
The Chess PoC is MossyMesh's determinism benchmark: every move is a CRDT operation, every position is a trie root, and the engine evaluation runs identically on-device or in the WASM sandbox. Target: ~836 million nodes per second.
Type help and poke around. There are easter eggs in here.
Every fact on this page also lives as JSON. OpenAPI 3.1 spec, CORS-ready endpoints, no SPA-only content traps.
Ours is a phone in a drawer, a Pi on a roof, a radio on a hill.