HMN is worth $0, on purpose. If you are here for a payday, this is the wrong project.
We bound the flow, not the stock. We have not found a way to make identities scarce under this architecture's constraints โ one more costs about two cents of gas and under a second of CPU, and that cost does not rise with the ten-thousandth. What we bound is what any identity earns over human-attended time. We are not claiming to have solved the Sybil problem; we are claiming to have made solving it unnecessary for the rewards that matter, and to name the one where it still matters.
That one is the joiner mint โ paid at the door, once, for doing nothing afterwards. A proposal exists to make it accrue over attended time instead. It is a proposal, not a commitment, and it is not built.
The ceremony's proof is a proof about computation. It establishes that the ceremony's numbers were computed consistently by the holder of a secret. It does not establish that a human sang. What binds an identity to a person is the journey and the time, not the cryptography.
The device record is forensic, not enforcement. Nothing about it is checked on-chain, so the duplicate-device ledger it produces is a census of honest people rather than a defence โ and a clean-looking ledger is not evidence of a clean population.
Voice de-duplication runs in the shipping ceremony — it compares each new voice against the ones already registered and records what it finds. It does not refuse anyone: refusing on a match is a different setting, and that one is not switched on. And where it has been measured, it was measured on one person: across 54 real ceremonies the founder was matched to himself about two times in three. We have no figure for a second human, so treat that number as what one man’s voice did, not as a rate you can expect. What a flagged human is told, and the second and third attempts they are offered, are built and on the chain already — the comparison that would flag someone now runs, so those paths are no longer inert for want of it — but nothing in this mode turns a match into a refusal. We would rather say that than call them unbuilt.
Proving presence at a place is a presence check, not a deepfake-proof oracle โ and physicality is the bound we lean on hardest. Nothing computed on your own device can attest to where that device is. If you can fool it, tell us: that is the most valuable bug you can file.
Some trust is assumed at testnet, and here is the concrete piece. At deploy, the reward-signal paths โ recruiting, attendance, memory, coherence, contemplation, leaderboard settlement, season-finale payouts, hunt location and hunt liveness โ are wired to a single signing key we hold, as a bootstrap. Nothing on-chain watches a heartbeat or a timer; the score that earns you a reward is a number that key supplies. That is an assertion by a key, not a verification, and we will not call it one. It is a larger expected loss than any attack named above. Removing every trusted component is the north star, and we are not there yet.
Development captures of raw ceremony audio are kept in our private repository, by an explicit founder decision โ they are what let us measure the algorithm's stability across months, and losing that record was judged the larger risk. It is a development artefact and not a protocol path: the protocol still transmits nothing derived from your body. We name it because a page that says nothing derived from your body is transmitted owes you the one adjacent fact that sits beside it.
Phase one runs on the honour of good-hearted humans. A bet, not a proof โ and we would rather name it than dress it up.
Testnet software. Not financial advice, not a security, not a promise of future value. HMN is worth $0. The enrolment path makes no network request carrying anything derived from your body โ verified, and open for you to check.