← BACK TO THE SURFACE
A FIELD GUIDE

The network that refuses to die

MossyMesh is an offline-first, decentralized compute mesh. Phones, Raspberry Pis, PCs, and LoRa radios form one computer that needs no DNS, no cloud, and no permission. This is the whole design, end to end, with the honest build status of every part.

The ten-minute tax

Before anything else, understand this: submitting a job to MossyMesh costs your device ten minutes of grinding. Deliberately. That tax is the load-bearing wall of the entire design.

With no IP addresses and no captchas, nothing stops an attacker from minting a million fake identities and drowning the local radio in garbage. So the network makes identity expensive. To submit a job, your device must compute 50,000,000 sequential steps of a Wesolowski verifiable delay function over RSA-2048. Sequential is the whole trick: the steps cannot be parallelized, so buying more cores buys nothing. On ordinary hardware the burn takes about ten minutes. Verification takes milliseconds.

One job, ten minutes: annoying but fine. Ten thousand fake jobs: seventy days of continuous grinding. The spam math stops working, and the network never had to trust anyone.

The first design used a MinRoot VDF. Issue #199 killed it. Verifying MinRoot meant re-running all fifty million steps, which turned every verification into a CPU-denial-of-service amplifier: the defense was worse than the attack. Wesolowski verifies fast. The scar tissue is preserved in docs/math-wesolowski-vdf.md.

The island

To understand why a network would tax its own users ten minutes per job, start with the island.

A storm takes out the only bridge to the mainland. The fiber goes with it. The grocery store's card reader dies, not because the food is gone, but because the payment has to ask a data center three thousand miles away for permission. Your message to your neighbor fails for the same reason: it was never addressed to your neighbor. It was addressed to a cloud.

MossyMesh starts here. Every phone, Pi, and LoRa radio in town already talks to its neighbors over Wi-Fi, Bluetooth, and long-range radio. The mesh turns that chatter into a computer. Jobs split across the devices around you. Results come back with cryptographic proof they were computed correctly. Nobody asks the mainland for anything.

When the bridge gets rebuilt, the town's little ledger syncs with the world. Credits earned in the dark settle in the light. Nothing was ever down. It was just local for a while.

Four pillars

Four constraints govern every line of the codebase. None of them bend.

Identity-routed. Your address is an Ed25519 public key, not an IP. A Kademlia distributed hash table finds the key, not the machine. No DNS lookup, no registrar to seize, no IP allocation to revoke.

Deterministic compute. Jobs run in a sandboxed WASM runtime with static INT8 math. Same bytes in, same bytes out, on a Pi or a PC. Anyone can re-run your job and check the answer.

Offline-first. Designed for dead zones, disaster zones, and censored zones. The mesh is the network. The internet is optional hardware.

Tiny ledger. The active ledger never exceeds 10 MB. Old history folds into constant-size proofs and gets dropped. A Raspberry Pi Zero is a full citizen of this network, not a second-class client.

Two internets

Every packet you have ever sent traveled through chokepoints someone could grip. The old path looks like this:

YOU --> DNS --> CLOUD --> PEER
        X          X
   (seize me) (unplug me)

Three parties must stay up, honest, and reachable.
Any one of them can say no.

The mesh path has no throat:

[phone] --> [pi] --> [laptop] --> [radio] --> KEY 7f3a...
                X
           (node died; packet rerouted)

The packet knows only a public key.
Nodes gossip. The DHT resolves the key to whoever holds it now.

Eight crates

The system is eight Rust crates plus a TypeScript frontend. Status is marked honestly: WIRED runs in the repo, PARTIAL is real code with mocks inside, TARGET is the number being aimed at.

CrateStatusWhat it does
mesh-transportWIREDKademlia DHT routing by Ed25519 key, LoRa with CSMA/CA, BLE, STUN-less UDP hole punching. Identity lives here: keys, not IPs.
consensusPARTIALCustom Merkle trie over Blake3, YATA-inspired CRDT (conflict-free replicated data type) merges, LRU eviction under 10 MB. Recursive folding is a mock today.
engineWIREDshakmaty chess bitboards, deterministic, compiling to wasm32-wasip1. Evaluation target: 836 Mnps class. TARGET
sandboxPARTIALHard 10 MiB guest heap; one byte over kills the job. Static INT8 math. Native WAMR behind a feature flag; a pure-Rust host runs tests today.
interopPARTIALAxum gateway, WebSocket sync with exponential backoff, TWAMM with 2% max-spread cap, HTLC escrows. VDF-delayed cancel still a mock.
governancePARTIALWeb-of-trust onboarding, quadratic staking, a 3-of-5 admin multisig decaying to zero over 90 days, ZK-blinded commit-reveal votes.
aiWIREDSITF tensor containers, vLLM-style paged attention, real CPU backend, Vulkan backend for GPUs.
integrationWIREDSmoke harness running the real offline pipeline end to end: VDF admission, sandbox invoke, chess eval, ledger insert, Merkle proof verify.

Two things the older writeups get wrong: there is no QUIC (the transports are TCP, UDP hole punching, LoRa, and BLE), and there is no Reticulum dependency (the code comments say so explicitly; libp2p Kademlia does the routing). The frontend is the TypeScript PWA you are reading this on, served over a captive portal.

The cage

Every job on the mesh runs in a cage that holds exactly 10 MiB of guest heap. Ask for one byte more and the runtime kills the job on the spot. No negotiation, no swap, no mercy. That harshness is the point: a Pi Zero can host a stranger's compute without fearing a memory bomb.

The cage also bans floating-point chaos. Tensor math goes through static INT8 quantization, so a phone and a laptop produce bit-identical outputs. If two devices disagree on a result, the merge is wrong, and the network knows it. (The quantization scale itself is still a float; INT8 covers the payloads, and the determinism SLA is measured on outputs, not on the absence of floats.)

Today the cage is a pure-Rust host simulation; native WAMR links behind a feature flag that is off. The 10 MiB limit is enforced either way, because the limit is the product, not the runtime brand.

The ledger

Blockchains ask every phone to carry the entire history of everything. MossyMesh refuses. Old history doesn't get stored; it gets folded. Each new proof certifies that the latest transaction correctly followed the proof of everything before it:

[T1][T2][T3][T4][T5][T6][T7][T8]   8.2 MB
        \ fold /
   [p1][p2][p3][p4]                  3.1 MB
       \ fold /
       [p1][p2]                      0.9 MB
       \ fold /
         [P]                         98 KB

A million transactions would look exactly like the last line.

What no longer fits gets evicted, least-recently-used first. The folding prover is a mock in the repo today and the nova-snark backend stays commented out until the circuit earns its place. The eviction and the sub-megabyte payloads are real.

The bridge

The mesh can live in the dark forever, but sometimes the fiber comes back. Then the interop crate opens the bridge: an Axum HTTP gateway and a WebSocket sync loop with exponential backoff. Credits earned offline settle against global liquidity through a time-weighted automated market maker (TWAMM) with a hard 2% max-spread cap, so rejoining the world doesn't mean getting skinned on the spread.

Payments between strangers ride on hash time-locked contracts: escrows that need no trust and no judge. The VDF-delayed cancellation that would make them airtight is still a mock. That's the next weld.

The genesis kit

No data center. No rack. The minimum viable offline supercomputer fits in a backpack and costs less than a flagship phone. From the repo's own procurement table, in USD:

QtyTierHardwareCost
2Pi-Tier (genesis nodes)Raspberry Pi Zero 2 W, 4, or 5~$150
3Edge / IoT tierESP32 microcontrollers with SX1262 LoRa transceivers~$60
1Regional hubNVMe-equipped high-capacity mini PC~$250
-Physical layer gearPower banks, HF ham radio links, high-gain antennas~$150
12 moSaaS and toolingPro-tier AI assistants, developer workspace~$360/yr
Total initial outlay~$970

The Pis are the citizens. The mini PC is the librarian. The radios are the roads.

The contract

Every change to the repo is judged against five numbers from docs/sla-and-dod.md. Miss one and it doesn't ship.

SLA-RAM: active ledger on edge devices stays at or under 10 MB. WIRED

SLA-DET: fewer than 1% unverifiable outputs. A result nobody can verify is a result that never happened. WIRED

SLA-TO: fewer than 5% job timeouts on hostile RF. TARGET

SLA-CAP: 100 RVCH per day on a 20-node island with zero upstream internet. RVCH means Resilient Verifiable Compute-Hours: an hour of compute that can prove it happened. The island doesn't count jobs. It counts proven work. TARGET

SLA-DEC: no central DNS, IP, or cloud database as control plane. If any single company can turn it off, it isn't MossyMesh. WIRED

MessyMash

The first proof is a chessboard. If two phones in airplane mode can agree on a chess position, they can agree on anything.

MessyMash is the determinism benchmark: every move is a CRDT operation, every position is a trie root, and the shakmaty engine evaluates identically on-device or in the WASM sandbox. The target is 836 million nodes per second class, explicitly a target, not a measured result. The WASM build path for wasm32-wasip1 exists; the number is what the native bitboard kernels are aiming at.

Open questions

DOES THE TEN-MINUTE TAX SURVIVE ASICS?

The Sybil defense assumes sequential grinding stays expensive. A determined adversary with custom silicon changes the arithmetic, and nobody has published a number for the Wesolowski-over-RSA-2048 parameters in use. The risk register calls it medium probability. This is the question the project most needs an answer to.

WHEN DOES NOVA-SNARK EARN ITS PLACE?

The folding backend is commented out and the prover is a mock. Recursive folding is load-bearing for the 10 MB ledger at scale, so this is the biggest gap between the design and the code. It stays unwired until the circuit's verification cost is measured, the same way MinRoot died.

CAN THE SANDBOX STAY HONEST WITHOUT WAMR?

Native WAMR sits behind a feature flag and the tests run on a pure-Rust host. The 10 MiB limit is enforced either way, but a simulation is not a sandbox until it faces hostile bytecode. Linking the real runtime is on the list.

Works cited

  • MossyMesh monorepo: github.com/movahedi-ca/MossyMesh (eight crates; docs/sla-and-dod.md; docs/math-wesolowski-vdf.md; vision blueprint at docs/vision-blueprint.md)
  • Wesolowski, B. "Efficient Verifiable Delay Functions." EUROCRYPT 2019.
  • Koblitz, N. and Menezes, A. on Ed25519; RFC 8032, "Edwards-Curve Digital Signature Algorithm."
  • Maymounkov, P. and Mazieres, D. "Kademlia: A Peer-to-Peer Information System Based on the XOR Metric." IPTPS 2002.
  • Kleppmann, M. et al. "A highly-available move operation for replicated trees" and the YATA algorithm (S. Nicolas et al.) for CRDT ordering.
  • Kothapalli, A. et al. "Nova: Recursive Zero-Knowledge Arguments from Folding Schemes." CRYPTO 2022.
  • Bytecode Alliance, WebAssembly Micro Runtime (WAMR).