Founder and inventor of Arweave and AO. Hacker and CEO @fwdresearch. PhD drop-out.

The permaweb
New to @ArweaveEco and @aoTheComputer? Here's what we are about: 1️⃣ Arweave is the permanent substrate for a new, decentralized cyberspace. 2️⃣ It is onchain data at any scale. >25 billion pieces of data and counting. 3️⃣ AO is a decentralized supercomputer built on that foundation. 4️⃣ It offers smart contracts that run as parallel processes each with their own throughput, but a universal communication layer: Arweave. 5️⃣ AO goes much deeper than just smart contracts, though. The AO-Core protocol can turn every service you use in cyberspace into a graph of enmeshed micro-blockchains. Down to every single individual HTTP packet nodes transfer. Authenticated, verifiable, and attestable. 6️⃣ It is unhelpfully novel. It is genuinely so different to existing networks that there are no narratives that capture the ideas. High bar to entry now, but when it clicks, you will see something that crowd has not yet realized. 7️⃣ Arweave is a stable, mature protocol. Mainnet has been live since 2018, serving more use cases than we can keep track of. It has been deflationary from real usage alone almost every month since the start of '25. 8️⃣ AO is a completely different beast. It is early, half-hatched, janky and will take time. It is an enormous project but the vision is getting closer every single day. If you are looking for 'just another L2/X but Y' it is not for you. We are gunning for a deeper prize: A permanent computer for humanity, capable of consuming the internet itself. 9️⃣ $AR is 99.4% circulating already. πŸ”Ÿ AO minting is early: Distributed 1/3 to AR holders and 2/3 to pre-bridgers of yield-baring assets from other networks. 21m cap, 4 year halving, 0% pre-mine. That's the sitrep. Glad you found us 🫑
17
58
189
17,923
πŸ˜πŸ”— sam.arweave.net retweeted
The Atomic Asset Migrator is live! Connect your wallet to find Legacynet Atomic Assets from old profiles and UCM activity, then migrate them to mainnet. This tool creates a new AO mainnet asset record pointing to the same artwork already stored on Arweaveβ€”no re-uploading the art. arweave.net/JHR-xjCO8xEwIXFz…
3
8
29
912
Dumdumz nightly news πŸ‘‡
ArLMDB unlocked using Arweave as a decentralized database engine that streams content only as you need it. Today those databases gained realtime update properties, too. Same verification, but with updates that take effect instantly. Read more πŸ‘‡
14
28
106
6,339
AO devices are like DePIN lego bricks. Arweave is their decentralized ledger.
AO standardizes services. Each device is a reusable capability that any node can host, route, and build with. Infrastructure stops being a centralized dependency and becomes part of a verifiable network anyone can access.
3
27
94
5,683
Have been porting this to run agents as @aoTheComputer processes directly on phones with the (unreleased, yet) PermawebOS Android build. Still slow so far but its pretty amazing to have a software TEE-ish trust-minimized agent executing in your pocket. The base model is supposed to be ~Opus 4.5/4.6 level and the Bonsai quantization apparently retains most of capability. Big if true -- has anyone tried it?
Today, we’re announcing Ternary Bonsai 2 27B. Based on Qwen3.8 27B, Bonsai 2 27B is 9x smaller than its full-precision counterpart while retaining 98.2% of its aggregate benchmark performance. Two months after the first Bonsai 27B release, the biggest change is quality. The footprint remains 5.9 GB, but the gap to full precision has narrowed materially, with particularly strong gains in agentic coding, multimodal reasoning, and long-horizon tool use. Ternary Bonsai 2 27B is available today under Apache 2.0.
6
22
90
10,349
New to @ArweaveEco and @aoTheComputer? Here's what we are about: 1️⃣ Arweave is the permanent substrate for a new, decentralized cyberspace. 2️⃣ It is onchain data at any scale. >25 billion pieces of data and counting. 3️⃣ AO is a decentralized supercomputer built on that foundation. 4️⃣ It offers smart contracts that run as parallel processes each with their own throughput, but a universal communication layer: Arweave. 5️⃣ AO goes much deeper than just smart contracts, though. The AO-Core protocol can turn every service you use in cyberspace into a graph of enmeshed micro-blockchains. Down to every single individual HTTP packet nodes transfer. Authenticated, verifiable, and attestable. 6️⃣ It is unhelpfully novel. It is genuinely so different to existing networks that there are no narratives that capture the ideas. High bar to entry now, but when it clicks, you will see something that crowd has not yet realized. 7️⃣ Arweave is a stable, mature protocol. Mainnet has been live since 2018, serving more use cases than we can keep track of. It has been deflationary from real usage alone almost every month since the start of '25. 8️⃣ AO is a completely different beast. It is early, half-hatched, janky and will take time. It is an enormous project but the vision is getting closer every single day. If you are looking for 'just another L2/X but Y' it is not for you. We are gunning for a deeper prize: A permanent computer for humanity, capable of consuming the internet itself. 9️⃣ $AR is 99.4% circulating already. πŸ”Ÿ AO minting is early: Distributed 1/3 to AR holders and 2/3 to pre-bridgers of yield-baring assets from other networks. 21m cap, 4 year halving, 0% pre-mine. That's the sitrep. Glad you found us 🫑
17
58
189
17,923
Learn more πŸ‘‡ The Arweave paper: 160531419058kb.arweave.net/ Arweave’s permanent principles: arweave-principles.arweave.n… AO-Core spec: 391624692404kb.arweave.net/ AO site + open mint: ao.arweave.net
1
3
37
1,502
Random sample of new permaweb happenings to check out today πŸ‘‡ Fully decentralized, permanent GitHub: molecule.arweave.net/ Turn your old laptop into an AO TEE: permawebos.arweave.net/#/run Art being sold by an agent running as an autonomous agent running as a process on AO. He is fundraising 2 AR to pay for compute. No human can access his wallet β€” he lives inside a PermawebOS node running on @jajablinky’s phone: bazar.arweave.net/#/asset/cr… Every single link above is served directly with AO-Core compute from an AO node. Check your browser’s headers to see verifiable attestations of the contents you are viewing. Web2 UX but with verifiability all the way to the browser. LFG πŸ™‚
1
4
35
1,360
This is on point. For the new real-time rewards version of @aoTheComputer's mint we built Lean formal proofs of each of the relevant property of the system (paper [1]). Model verification is often not enough alone, though. Property Testing fills in many gaps. Deep dive πŸ‘‡ tl;dr: Describe invariants of your system and how to generate random valid 'scenarios' for your data. Use these to generate test cases and run millions/billions of simulations to gain confidence in correctness. We built a system for this in HyperBEAM last year because @aoTheComputer's devices are a perfect environment for these kinds of quasi-proofs -- including covering probabilistic behavior and emergent properties of highly parallel systems. Traditional proofs get exponentially more complex if your build isn't just pure, stateless math. The trade-off, of course, is that you don't get a shiny proof that guarantees correctness -- assuming there aren't bugs in the theorem prover (...which there almost certainly are [2]). With property/invariant-based testing you do, however, get validation against your actual code -- not just a mathematical model [3]. This was formal verification's other achilles heel that partners the 'spec gap' Vitalik described in the original post: The 'translation gap'. Once you have your model, how do you know that the code you have written actually matches it? Depending on the environment, you normally cannot deploy the formally verified model itself to production. So you deploy code that you think matches the model -- but what if it doesn't? The archetypal example of this is SeL4 in 2009 [4]: An OS built for highly resilient systems with formal correctness guaranteed... Via a model that accompanies massive amounts of raw assembly and C code that had no direct proofs. In practice you likely want to use both formal verification as well as property-based testing of invariants that match your theorems. This narrows the translation gap from 'I hope my code matches my model' to 'my invariants must match my theorems'. Not perfect still, but the latter is radically easier to achieve. This is what we did with ~pot@1.0: Simulating ~500 billion (IIRC) different random scenarios against the real code, running checks that ensure all of the properties from the verified model hold in every single situation. For the builders: If you want to create property-based invariants for your devices in HyperBEAM checkout [5]. We tried to make it friendly but the API could probably be improved. PRs welcome! πŸ™‚
It's an increasingly common take that AI hacking means cybersecurity is doomed. I disagree. I think cybersecurity is naturally defense-favoring once people get their shit together. And anyone who continues to hold cryptocurrency (including me, ~90% of my net worth) is implicitly making that bet. Here's why I am making that bet. First, the oversimplified punchy one-line statement: If AI can prove Navier-Stokes and FLT, then AI can prove the statement "this program is secure" as a mathematical theorem. Even if the program is very complicated. Now, the nuance: (See also: vitalik.eth.limo/general/202… ) The word "secure" is hiding all kinds of skeletons in the closet in terms of what it actually means. What does it mean for Signal (the encrypted messenger) to be "secure"? The most basic definition you might think of is: no one who doesn't hold the recipient's secret key can read the contents of the message. But: * Did you remember to include _other_ critical forms of security? Can the adversary forge messages? Can the attacker prevent messages from reaching the recipient? Can they cause your client to crash by sending malformed messages? * Have you made sure that your model of the adversary includes attackers that interfere with the protocol actively and not just passively? And attackers that interfere by replaying messages to you or the recipient that either of you sent over the wire at any point earlier? * What if the adversary hacked (or _is_) the Signal server? * How did you learn which public key belongs to the recipient in the first place? What if that process was tampered with? * What if your device gets hacked at some point in the past or future - is your message still safe then? * What if your key leaks because of a bug in your operating system? Or because you got a bugged version of the Signal client? Or what if the database is corrupted? * Or the libraries, interpreter or compiler of the programming language you wrote it in? * What if your key leaks because tiny perturbations in perceptible signals generated by the hardware leak mathematical relationships that can extract the key a few hundredths of a bit at a time? * Are you hiding the *size* of the payload? Does that matter? * You're definitely not hiding the identity of the sender and the recipient, and the exact time each message was sent (think: not just time-of-day, but also time deltas between one message and the next). Is that not enough to deduce a lot of important facts about what relationships you have, and what *kinds* of conversations you are having? So ... even definitions can be over a thousand lines of code, and need deep careful thought to figure them out. Working on making definitions more human-readable is of extreme importance - it's perhaps the only "high-level language" that matters right now. But even still, even despite all of the above, for security-critical components, the definition is a much smaller attack surface than the implementation. Verifying that the definition is adequate is a much more tractable task than scanning over the code directly - and can become even more tractable with better tooling. Definitions are also _additive_: if two groups have two different definitions A and B, then, well, you can just prove that the program satisfies both A and B. Code is not additive in this way: if a program is A + B, a bug in A _or_ B can sink the whole thing. Definitions are additive. And if you can't satisfy A and B at the same time, you've isolated the most important philosophical issue for your project to spend its next few weeks grappling with. Sometimes, definitions are not much smaller than the implementation - UI components might be one example. But for many of the most critical components - message-passing protocols, sandboxes, cryptography like SNARKs and FHE - the asymmetry is real. Historically, a large class of failures with this approach have come from people only verifying a small portion of their code, that they self-declared to be the security-critical portion, and ignoring the rest - and it turns out that something in the rest of the code is security-critical too. This was reasonable back when verification was difficult and scarce. The solution today: sorry, you have to verify over literally your entire program, including database, networking, any caching layers, everything. Modern AI can do it. So it's not about "the good guys find all the vulnerabilities before the bad guys do" - that could maybe work too, after all a finite program only has a finite number of vulns, but it's riskier - it's specifically an asymmetric strategy of making code that is much more resilient in the first place. This is the kind of direction that Ethereum is going in for the next few years. There is no future for blockchains - especially blockchains with scalability and privacy - without doing this. We need to make software actually secure. And we have already made a lot of progress.
8
22
88
8,966
So, someone came up with an AI-generated formal proof, in Lean, of a solution to the Collatz problem, and it turned out that the β€œproof” was merely exploiting a bug in the Lean kernel (allowing you to prove anything).
4
15
1,905
ArLMDB turns Arweave into a decentralized DB so efficient you can run queries directly in the user's browser. Cold start ➑️ 15,000 results in <100ms. In a browser. From cold. Zero setup or infra. All you need is Arweave to serve you chunks. Try it for yourself πŸ‘‡
8
39
138
11,135
Removed from supply in this single upload: 7,538 AR. Network model prediction for full return to supply: 200+ years ➑️ never. Inflation (last 28 days): 3,280 AR. Arweave has been deflationary 89% of days since Jan 2025.
Daaaamn son!!! I wonder how many AR that went out of circulation just by that single TX?🀯🀯
9
33
115
11,878
Curious about the endowment model? Learn its risk model in-depth and try the simulator: arwiki.arweave.net/#/en/endo…
2
11
42
2,583
πŸ˜πŸ”— sam.arweave.net retweeted
AO-native GraphQL inbound πŸ‘€
621 GB uploaded in a single Arweave TX. Over 70 billion individual, indexed database rows. Onchain data at any scale.
2
16
88
5,730
621 GB uploaded in a single Arweave TX. Over 70 billion individual, indexed database rows. Onchain data at any scale.
18
29
145
15,861
πŸ˜πŸ”— sam.arweave.net retweeted
Realtime(ish) version. Still far slower than reality, because it is otherwise imperceptibly fast. A test yesterday showed the lookup surfacing every single .png file on the weave in under a second, local-only on a laptop.
5
22
773
Simple example of this in prod: 390410975380kb.arweave.net/ Try loading any two item IDs. The second will download just ~0.5 MB to traverse the full 171 GB DB on-the-fly. The chunks can be sourced from any node, and Arweave's Merkle proofs guarantee result accuracy.
You can now efficiently stream databases from Arweave with AO, downloading only what you need on-the-fly.
6
14
64
5,905