The Index Machine is a public measurement chain for crypto: every number it publishes carries a receipt, every receipt replays in your browser, and the whole history is anchored in Bitcoin. Not audited. Not attested. Recomputed, by you, on demand.
An index unit is a unit of measurement whose value is defined by a computed index over public activity, not by a promise to redeem into a currency. A dollar stablecoin holds reserves to defend a fiat peg; an index unit exists to defend the accuracy of a reading. The coin, where there is one, is just the carrier: a transferable claim that tracks the index. The unit is the measurement itself, which means it sits upstream of money: it can index anything deterministic and observable, and it does not even have to be tradable to be useful.
Coins already live this way in the wild under a dozen different names: reflex indexes, elastic units of account, flatcoins, perpetual notes, energy money. Same idea, no shared name, and, until now, no shared verifiable substrate. The Index Machine is the engine and the standard underneath all of it: the layer that computes the readings, proves them, and lets anyone check.
Reference prices, indexes, TWAPs, settlement rates: they decide liquidations, settlements, collateral, and payouts across the entire industry. And nearly all of them share the same three defects.
Every chain and every protocol rolls its own index with its own methodology. Thousands of incompatible answers to the same question, which makes composing across chains a negotiation instead of a computation.
Methodologies live in PDFs. Feeds arrive signed but not re-derivable. When a number looks wrong, you cannot recompute it from raw inputs, because you never had the raw inputs, the exact code, or the intermediate state.
Silent revisions, stale values carried forward, histories quietly restated. Oracle failures and index manipulation have caused some of DeFi's most expensive exploits, and the forensic trail is usually reconstructed after the fact, if at all.
Time advances in epochs. At each epoch the engine gathers its adapter inputs, evaluates every registered program as a pure function of those inputs and its own prior state, emits each output or an explicit withhold, commits a provenance receipt, and advances the chained root. Evaluation performs no input and output of its own, reads no clock, and touches nothing nondeterministic, which is exactly why a reading is reproducible bit for bit from its logged inputs.
Programs are content-addressed code, and the on-chain registry is deliberately minimal: it records that a program exists, the dependency edges between programs, and deterministic name resolution. Nothing else. It is a coordinate index, not an authority, and it never stamps anything canonical. Acting on a reading happens somewhere else entirely: pausing a market, rebalancing, minting, liquidating all live in separate opt-in contracts that subscribe to a published value. The core computes and publishes. It never takes custody of anything.
Each level names its remaining uncertainty on the instrument itself. A verification system that hides its residuals is a marketing system. This one prints them.
Open the site and your tab re-derives every receipt since day one with the reference implementation. Works on any origin, any mirror, no account, no install.
watch it replay →Chain roots are committed into Bitcoin blocks, the earliest before any of this was public. The only forgeable history is a future one; the accrued past is the moat.
see the attestations →Each measurement requires agreement between multiple independent providers, including a consensus-verified local light client whose votes cannot be forged by any upstream. Who agreed and who dissented is recorded, forever, in the receipt.
open a quorum receipt →When sources disagree or vanish, the epoch is honestly withheld with a cause code. No interpolation, no last-known-value dressed up as fresh. Gaps render as gaps.
see honest gaps →Index programs are content-addressed executable code, hash-pinned inside every receipt. Not a methodology document about the code. The literal bytes, fetchable and verifiable by equality.
read the programs →The registry holds a composition graph: which reading depends on which, recorded on-chain as real edges. That graph, not the engine, is the thing that compounds, because a reading everyone builds on is expensive to replace and free to reuse. Nothing in it is ever decorative; it shows real dependencies only.
read the programs and their edges →Announcements ship as Merkle trees: one leaf per claim, the root anchored to Bitcoin before publication. A journalist checks a claim with one click. No confidence field exists anywhere in this system; a claim is evidence-backed or it is not published.
check a claim yourself →These categories solve real problems and run real value today; the comparison is architectural, not dismissive. It is also, on the verification axis, not close.
| INDEX MACHINE | ORACLE NODE NETWORKS (e.g., Chainlink) |
FIRST-PARTY PUBLISHER NETWORKS (e.g., Pyth) |
PROTOCOL TWAPS (e.g., Uniswap oracles) |
REFERENCE-RATE PROVIDERS (e.g., Kaiko, Coin Metrics, CoinDesk Indices) |
|
|---|---|---|---|---|---|
| How a number is produced | Pinned multi-source quorum reads the chain itself; deterministic programs derive outputs; everything sealed into a receipt | A committee of node operators fetches, aggregates, and signs | Exchanges and market makers publish their own prices; aggregated on demand | On-chain time-weighted average of a single venue's pool | Proprietary methodology over exchange data, published as documents |
| What you must trust | Nothing you cannot check: replay the history, reopen the proofs, re-read the source chain | Honesty of the operator set and its aggregation | Honesty of the publishers and the aggregation | That one venue's liquidity was not moved against you inside the window | The provider's process, controls, and restraint |
| Can you re-derive today's value from raw inputs? | Yes, in your browser, bit for bit, from genesis | No (signed outputs, not replayable derivations) | No (publisher inputs are not reproducible by consumers) | Partly (on-chain, but venue-local and window-fragile) | No (methodology described, not executable) |
| Can last month be silently rewritten? | No: roots are in Bitcoin blocks; a nightly replay re-proves the whole history and publishes the verdict | Historically difficult, but not structurally excluded | Same | Chain history is firm; the oracle reading of it is contextual | Restatements are a known practice in the category |
| Is source disagreement public, per update? | Yes: every receipt lists who agreed and who dissented, by name, forever | Not as a first-class per-update artifact | Aggregate spread visible; per-publisher dissent not the product | Single source by construction | No |
| Uncertainty handling | No confidence field exists; a value is evidence-backed or the epoch is withheld with a cause code | Deviation thresholds and heartbeats | A confidence interval accompanies each price (an honest move for that architecture; we chose a different one) | None | Methodology-defined |
| Formula transparency | Content-addressed executable programs, hash-pinned in every receipt | Open specs; per-feed configs vary | Aggregation open; publisher models private | Fully on-chain, but fixed and venue-bound | Documents, sometimes licensed |
| Cost to verify | A browser tab. Free, forever, by design. | Run infrastructure or trust | Run infrastructure or trust | Read the chain | Subscribe, then trust |
| What it is today, honestly | Step zero: one operator, one reading family, accumulating an anchored track record before launch. Every property above is live and checkable now; the evaluator, the on-chain registry and the publication contract are next, not present. | Years in production, thousands of feeds, staked security, deep integrations | Broad coverage, low latency, strong adoption | Ubiquitous, composable, battle-tested within their scope | Regulated relationships, institutional distribution |
Read the last row first if you want to distrust us efficiently. Then read the third row again: it is the one no incumbent architecture can retrofit, because replayability has to be designed in from the first byte, and our first byte is in Bitcoin block 955756.
Every chain that rolls its own reference layer pays forever for methodology, infrastructure, incident response, and credibility, and receives in return a number nobody else recognizes. A shared, verifiable substrate inverts all four costs.
Two protocols on two chains referencing the same receipt at the same epoch are referencing the same provable fact. Settlement disputes collapse into replay. That is the beginning of real cross-compute: chains citing shared verified quantities instead of each re-deriving, or mis-deriving, their own.
Every incident postmortem starts already written: the receipts record inputs, code hashes, state, witnesses, and dissent for every epoch, and the Bitcoin anchors prove none of it was backfilled.
Source-available now, converting irrevocably to AGPL-3.0-or-later after the change window, with the full replayable history guaranteeing a credible exit. Governance is designed to accrue to the people who do verification work, with dual vetoes live from day one. No chain, including any of ours, gets to capture it. The full governance specification ships with the public launch.
Readings are composable programs with pinned provenance. The design includes a bonded, permissionless lane to propose new readings and to challenge existing ones with evidence. The catalog grows the way open source grew: because verified building blocks compound.
These do not compete on prettier dashboards. They establish a different category: public, reproducible reference data, the layer protocols depend on for deterministic economic observations. No incumbent occupies that frame, and every reading below inherits the one edge no incumbent can copy: each output is a pinned deterministic function of public inputs, recomputable bit for bit, with its history anchored in Bitcoin. Incumbents ask you to trust their pipeline. This asks you to check its work.
The discipline the category demands is coverage honesty: where a reading cannot see something, it says so inside the reading itself, as a first-class field. The honesty is the product, not a disclaimer stapled to it, and it is precisely what a provider that cannot show its work is unable to offer.
Against: wallet-facing gas APIs (e.g., Etherscan Gas Tracker, Blocknative): trusted, opaque, tuned for "what should I pay right now."
Ours: pinned fee percentiles and the blob base fee per chain, reproducible to the bit, because every input is literally in the block. The reading with nothing to dispute, which is why it ships first.
Honest boundary: it is a canonical index, not a next-block price predictor; predictions are compositions consumers build on top.
Against: the trackers everyone quotes (e.g., CoinGecko, CoinMarketCap, DefiLlama stables pages).
Ours: per stablecoin, peg deviation from allowlisted on-chain venues plus circulating supply with mint and burn flow. On supply we are structurally more authoritative than any tracker: issuance is fully on-chain, and we recompute rather than report. Depegs are exactly the moment a trusted-but-unverifiable tracker reassures least.
Honest boundary: a coin trading mostly on centralized venues has a peg our on-chain view only partly observes, and the reading publishes that coverage rather than hiding it.
Against: the dominant free aggregator (DefiLlama): the most-cited number in the sector, produced by a methodology you cannot recompute.
Ours: per protocol per chain, balances read from the protocol's own pinned contract sets, valued at pinned reference prices, under a published double-count rule, because most TVL disputes are double-counting disputes.
Honest boundary: day-one breadth is smaller than the incumbent's long tail; the registry makes exactly what is covered explicit, and coverage grows adapter by adapter.
Against: the institutional composite staking rate (e.g., CESR from CoinDesk Indices): methodologically sound, trusted, licensed, and not recompute-verifiable.
Ours: the crypto risk-free rate per chain, issuance plus fees over active stake, from the chain's own accounting, free, and recomputable by anyone.
Honest boundary: the MEV-like component is included only where deterministic public attribution exists, stated per chain rather than smoothed over.
Against: established providers of on-chain lending rate indexes (e.g., IPOR, index desks publishing DeFi rates).
Ours: per asset, size-weighted borrow and supply rates across the pinned money-market set. Reference rates are the textbook sticky standard, and the history of reference-rate reform, from submitted numbers to transaction-based construction, is the market preferring the verifiable version.
Honest boundary: thin-market manipulation is the attack surface; the size weighting and health rules that defeat it are pinned and published, not proprietary.
Against: institutional depth and execution analytics (e.g., Kaiko, Amberdata, Coin Metrics), sold as enterprise data.
Ours: exact slippage per trade size, simulated against the full on-chain liquidity state using each venue's own settlement math. Not an estimate: the entire liquidity state is public, so the answer is exact, reproducible, and free.
Honest boundary: centralized-exchange order books live on no chain, and we say so with a published coverage number per asset. For on-chain liquidity we publish what even the incumbents can only report on trust; "replaces them entirely" is a claim we refuse to make.
Running underneath all six today: the live reference readings on Ethereum mainnet, measured every block through a four-provider quorum with a consensus-verified local light client, published in about 50 milliseconds, archived in content-addressed daily segments, Bitcoin-anchored hourly, audited daily, replayed nightly, and verifiable in any browser down to the proof files themselves. The six readings above graduate onto that proven pipeline in the order listed: objectivity first, the expensive and boundary-sensitive one last.
Before building anything else, the recorders went up and were left running, anchoring every epoch externally. That is deliberate: history cannot be backdated, so a verifiable track record has to be accumulated before the launch that cites it, not after. Today that means readings measured on Ethereum mainnet at block cadence, sealed into receipts about fifty milliseconds later, archived in content-addressed segments, anchored hourly into Bitcoin, audited daily, replayed in full nightly, and recomputable end to end in any browser. It is the foundation and the proof of the track record, not the finished machine.
The reference evaluator, the minimal on-chain registry that carries the composition graph and name resolution, the publication contract that puts readings and their provenance roots where contracts can consume them, and the conformance ecosystem: a second independent implementation, a shared vector corpus, differential fuzzing, and formal models of the core invariants, so the reference stops being the only referee. Opt-in actuators are external by design and required by nothing. External audit comes last, when there is enough substance to audit.
If a claim on this page ever stops being checkable on the instrument, the claim is wrong and the instrument is right. That ordering is the product.
No. An oracle vendor sells you a truth. This standardizes a method and sells nobody anything: the engine computes readings deterministically, publishes receipts, and lets you recompute every one of them. It is not an arbiter either. Nothing here stamps a reading canonical; that is something usage decides, or does not. Today you consume readings off-chain and verify them anywhere, and the publication contract puts them on-chain at launch.
None is required to use anything, and none is for sale. The governance design includes a token instrument that stays dormant until identity controls and a securities opinion clear, and if it activates it is allocated retroactively to people who did the work: verifying, mirroring, challenging, and authoring, metered from genesis by the receipts the machine already produces. A governance and contribution instrument, never an access key, never sold.
BNCMK LLC operates the recorder today, and says so plainly. The architecture is built so that this fact matters as little as possible: the operator cannot rewrite history, cannot fake agreement, cannot publish an unreplayable number, and the governance design routes ownership toward the people who verify the work.
You should not, and the system is built accordingly. Every measurement requires quorum agreement across independent providers, one of which is a light client that cryptographically verifies Ethereum consensus on our own hardware, so even our own upstream cannot lie to us. Disagreement is withheld, never guessed. And you can re-read the source chain yourself at any pinned block.
A browser tab. No account, no key, no subscription, no analytics watching you do it. Verification being free forever is a design invariant, not a promotional period.
The history is content-addressed, mirrored, Bitcoin-anchored, and replayable from raw files by a single command. The license converts irrevocably to AGPL-3.0-or-later. Erasing the company does not erase a single proof; the instrument even has a button that demonstrates this.