Brainstorming notes - blockchain distributed oracle for crowdfunded bounties for leaking info
Disclaimer
Thinking aloud, may not endorse after lot of thought.
By default, don't assume anything here is safe to use irl yet.
2026-07-01
Update
Main
UMA
Study emergency capabilities of UMA optimistic oracle, for instance here. Are the contracts actually immutable or is there a founder veto? Also what is the country-wise distribution of voting UMA tokens?
drug markets
This is again the drug market escrow problem all over again, assuming the people behind the oracle stay anonymous.
If they are not anonymous, they become targets, and maybe not that many people are willing to volunteer for such a role. (That is fine though? It is unpopular yes, but you also don't need that many people.)
The most common solutions are to trust one reputed person, or trust a multisig of reputed people, or trust a proof-of-stake governance token (either a native chain token like ETH stake or whatever, or a token just for this like UMA).
Maybe I should just do the dumb thing here and go hunt for people on twitter who wanna be part of such a multisig? Like, the v0.1 dumb version is to just use a multisig to store the funds, don't even need to write any contracts of your own.
incentive for oracle providers
Maybe the people operating the oracle should get a cut of the funds, as payment for services rendered? Just like how dark web drug markets take a cut. Worth exploring.
comingle with a more popular use case
very important - most blockchain / cypherpunk ideas so far have only taken off by comingling a more popular use case with a less popular use case. Tor enabled Securedrop for journalists, versus silk road for drugs. Polymarket enabled election betting, and also insider trading. USDC enabled evading capital control, and evading taxes.
It will help a lot if there is some more popular use case for which you also need oracle data like "was there a leak about OpenBrain or not? which ETH address leaked it?" For instance, what if some oracle just dumps the entire reuters news headlines on the blockchain? And what if there is some more popular use case that also relies on this same data?
2026-07-02
Update
More ideas
Ethereum smart contracts can verify email DKIM headers
If the document is signed, then you can trustlessly (within ethereum's security model) verify that the leaked document is from an official domain such as openbrain.com or similar. I just can't yet think of a way to trustlessly verify that the document is of a certain type, such as say financial fraud or rape or whatever. (Most documents are not that interesting to leak, nor does a leak of an official document by itself also prove other more interesting documents were leaked.)
Measure popularity?
Is there a way for the blockchain to trustlessly measure whether a document has a lot of eyeballs on it, even if it can't verify what is on the document? Probably not, right, you will again need an oracle for this.
Oracles for lawsuits?
If a lawsuit is opened against the person who leaked the document, this can also count as proof. Is there a way for a blockchain to verify this happened without using an oracle? What if an oracle just published titles of all lawsuits to blockchain, and there was also a legitimate use case comingled? (like what lmao, what lawsuits are "legitimate" to gamble on?)
Proportional PoS voting?
What if the people who donated the money were themselves also the voters (one token, one vote), and also the voting was proportional? So if 80% votes against and 20% votes for, then 20% of the total fund gets donated? This ensures some funds get donated even in the case of a 51% attack.
Worth analysing all the ways this sort of scheme can be attacked
lol is this just reinventing quadratic funding? I should read about resistance of QF and QF-like schemes to 51% malicious votes
Note to self
Part of me is saying this is really important, anonymous crowdsourced funding is the number bottleneck for more leaks. But part of me is also saying this is a nerd snipe, to spend time thinking about some QF MACI private voting contraption, full vitalik-style. I should instead first implement the dumb solution which is to cold DM people on twitter and ask them to join a multisig. This makes more contact with actual reality.
2026-08-08
Update
More ideas
I should look into how to have a market that resolves not on a single oracle query but on a logical combination of multiple oracle queries. This might increase censorship-resistance of the oracle, because it could make it harder for the oracle to lie on some requests and be honest on others, when the queries are a) individually quite simple and b) you don't know ahead of time what complex or morally questionable query can be resolved using the simple queries.
2026-08-11
Update
Allow withdrawals with one year delay?
Ideally this sort of thing should be decided based on feedback from actual users. Until I get that feedback though, here is my guess.
I want to satisfy two competing constraints:
Donors should be available to withdraw the assets they have donated ideally, in case they want to later use those assets for something else.
This allows donors to deposit a significant fraction of their net worth into the contract, while also having the option to retrieve it back when they actually need their money back. This makes the deposit not a pure "donation".
It should be difficult to politically pressure the donors to withdraw their assets.
For instance if an anonymous donor gets doxxed they might get pressured to withdraw their assets. Or if some leaking case becomes high-stakes, the US govt might suddenly put a lot more effort into chainalysing and doxxing and pressuring people to not donate.
If I allow withdrawals but only after a one year, this satisfies both constraints. As in, if you want to withdraw, you have to first register a withdraw request with the contract, and then only one year later the contract allows an actual withdrawal.
Okay I search this, it already exists. Maybe I don't even need to write any new contract for this. Maybe the user just deploys assets into a timelocked multisig, and that timelocked multisig then deploys assets into the leaker bounty contract.
2026-08-26
Update
How do you build a consensus engine for distributed web crawling?
Assume we have a number of different nodes all staking ETH (or UMA or similar) and all running web crawling infrastructure. (The ETH staking contract for this will be different from the actual ETH consensus engine ofcourse.)
You ideally want to end up with a single global crawl that a 51% ETH staking majority can attest to.
How do you build this shared crawl?
By default, crawling is kind of a messy stochastic process.
Problems
Pages often don't stay consistent
Some pages just go down later on, when a different node crawls them. Some pages just update themselves with no warning. etc
Nodes might deliberately refuse to crawl some pages.
A major motivation for this whole idea is that I don't want an individual nodes to arbitrarily decide which pages can be used and which ones can't.
Solutions
One option is to run the entire crawling synchronised. Like, here is a webpage, all the nodes have to go crawl in the next 60 second window or something.
Another option (not exclusive with above) is to have ways to merge crawls together, where nodes are forced to vote on each other's diffs.
I guess the important part here is to force consensus somehow. You should not end up in a state where node A says they retrieved something from a page, and node B says they retrieved nothing, and node A and node B never agree. They should be forced to agree and maybe the loser should even get some of their ETH slashed as a result.
All these nodes are definitely going to end up crawling (and storing) child porn and whatnot btw, same as bitcoin nodes. Worth keeping in mind. Like, there could exist nodes that actually have legal/political reasons to refuse to crawl some content. I'm unsure if they should be slashed.
Yet another option (not exclusive with above) is to maintain a white list of pages that will be crawled? This will also make crawling much cheaper. But who gets to decide this white list is an important question.
Maybe just make it based on the highest bidder? Like, you need to bid a certain amount of ETH to request the nodes to crawl some content, and they will (for economic reasons) tend to accept the highest bids.
If some content is politically sensitive (such as the child porn example, or about leaks of classified info, or similar), then the bidder needs to raise their bid until atleast a minority of nodes are willing to crawl and attest to that content.
To be clear, the problem is not censorship of the data. The data is out there on the public internet, you only need 1 out of N nodes to let's say, post it into ethereum blobdata, and now all ethereum nodes (not crawl nodes) are forced to carry the content. The problem is censorship of attestions, in order to block payments in return for the data.
Okay one thing is clear. Running these nodes is going to be risky like Tor exit nodes or Tornado cash relays. More risky than running a bitcoin node (although we know for a fact that bitcoin blockchain stores child porn). Reason simply being that you need to send outgoing traffic to a bunch of suspicious IPs, and most cloud providers don't allow that.
Yet another option is to just default to a very small white list. For instance, literally just whitelist wikipedia and that's it. ETH stakers will all need to attest to SHA256 hash of the latest wikipedia archive. (Lol at the point you might as well trust wikipedia to just post the hash to the blockchain themselves.)
This is obviously not maximally censorship resistant for the most politically sensitive stuff. But honestly this might still allow a lot of use cases. For instance most major hacks get posted to wikipedia, so you can pay hackers this way. Most major assassinations get posted to wikipedia, so you can pay for assassinations this way.
I wonder if wikipedia editors can handle the pressure of millions of dollars of bounties depending on their information.
Holy shit this is actually not a bad solution. For maximum censorship resistance, I still like the bidding system approach. But this is not bad for a first attempt.
Like, this is so clean lol, as compared to building an entire consensus engine from scratch:
ETH stakers attest to SHA256 hash of latest wikipedia dump. ETH stakers attest to SHA256 hash of latest AI model. User submits ZK proof that proves that if you take some specific page from this dump and give it to this AI model, then output is as desired. Smart contract verifies the result. You need to hard-code ahead of time which wikipedia pages can be used and which AI prompts can be used, so an attacking user doesn't have too much leeway to specify those in their favour.
I don't know. I still vaguely feel like wikipedia editors are not a fan of cypherpunk ideas and will figure out some way to fuck this system over, once it is deployed and popular. (Like how?) For instance, they could deliberately remove their politically sensitive pages from the archive, make them harder to crawl, stop publishing SHA256 hashes and so on. I don't know, it is not clear what wikipedia will do in response to such a system existing. TO DO - think more here
2026-08-28
Update
Oracles can be broken down into data sources and off-chain computation
For now, just considering data sources. Which (coalition of) data sources can be trusted? This is basically the fact-checking problem.
Data sources and verifiers
Legacy media - Reuters, AP, etc
often a journalist verifies the event in-person (and will get fired if they lie), will refuse to answer question until high certainty
Wikipedia
relies on other sources to resolve, will refuse to answer questions until other sources report first and there is high certainty
Prediction markets
relies on other sources to resolve, will provide probabistic guesses until then
Original reporting on twitter or youtube livestream or similar
unsolved research question how to build this trustlessly in an adversarial environment. Also twitter is increasingly hostile to scraping or providing archives, hence will need an equivalent on an actually decentralised social media
Hire your own group of experts and get consensus between them. (Run your own fact-checking outlet)
Proof-of-stake DAO
Sortition. Hire thousands of random strangers across nuclear-armed states and across political spectrum, and get consensus between them.
(I wonder if this has been tried, it doesn't sound that bad a solution actually.)
This requires solving decentralised identity (like, uploading real faces online and doing PoW on them and stuff). Otherwise it devolves back into PoS DAO.
You can't rely on AI alone for verification of unverified sources, because strongest verification of an event is done by humans observing the event in-person, or by many humans looking at a long-form video of the event that happened in-person. Video AI is not yet good enough to do this verification in adversarial settings. (And since I don't want frontier AI to progress, maybe this is good actually.)
For questions that will actually get resolved by a consensus between reuters and AP, it seems fine to me to use a prediction market that resolves based on this consensus.
Importantly, you don't always need to wait for resolution to trigger other stuff. For instance, if you are paying someone a bounty based on whether some event happened, you can pay them using a prediction market even before the event resolves. Let's say a prediction market currently prices odds of an event happening as $0.05 for Yes. You want it to become 100% Yes. You can put a Limit Sell Yes at $0.20. Someone can buy this at $0.20. Let us say the price eventually moves to $0.75 and stays there. The person who matched your order has already made a profit, regardless of whether the market resolves soon or not.
What happens to questions that never get resolved by a consensus between reuters and AP, what is supposed to happen here?
Rant
Motherfucker is it so difficult for all these websites to digitally sign their responses? All these problems are downstream of the fact that TLS and CA chain-of-trust suck, and there is no easy way to port them to blockchain. Also lmao what even is a "UDRP proceeding"? Yet another unelected secret court. Rant end.
This exercise is making realise how trust on the internet actually works. Like, if I need to go phish someone for example, I basically need to purchase a .com similar to them, get a lot of twitter or linkedin followers on an account similar to theirs (make sure to ban replies), and hire some random dude to feature in some of the commercial videos on the website (people tend to trust-but-not-verify faces).
2026-08-30
Update
The pipeline is fact-checkers, crawlers and attestors, and interpreters.
Fact-checkers are people actually verifying that a certain event happened. Ideally this means they observe the event in-person, or non-ideally they see a long-form video about it. This is the role typically taken by journalists at Reuters or AP or similar. (In the whistleblower use case, this basically means whichever journalist actually spoke to the whistleblower in-person or over video call.)
Unfortunately Reuters, AP and similar are not willing to themselves sign their news and make their signatures verifable via smart contracts. Therefore you need someone else such as commoncrawl, or internet archive, or maybe even wikipedia, to crawl this and maintain an archive.
Unfortunately even these crawlers are willing to signal their crawls and make their signatures verifiable via smart contracts. Therefore you need someone else to attest to legitimacy of these crawls to ethereum smart contracts. I am considering using UMA PoS optimistic oracle here, you can also invent your own PoS oracle here.
Then you need to interpret these raw facts to resolve whatever custom question you have. I am considering using ZK proofs of AI inference here, to trustlessly do this entire process.
Subscribe
To subscribe, enter "Subscribe " followed by Signal username, email address or whatsapp phone number. You will receive atmost one update per month.
Alternatively, you can subscribe via RSS, or a third-party service like blogtrottr