Hi,
Picture a judge at an art competition. She has the sharpest eye on the panel, and she spots a genuinely brilliant, unconventional entry before anyone else does. She scores it a 99. The rest of the panel writes down twenties and thirties, because to them it just looks wrong.
On the network this week's episode is about, her 99 does not survive contact with the machine. It gets cut off at a line, and she is quietly penalized for having written it down at all.
Nothing malfunctioned. The machine did exactly what it was built to do. It cannot tell the difference between a judge who is wrong and a judge who is right too early. From the outside, both just look like one person disagreeing with the room.
That single design choice is the load-bearing beam under every open network that pays strangers to do work nobody can check. This week's Layer spends thirty minutes taking it apart: what a validator on Bittensor actually sends the ledger, why the obvious fix of just averaging the scores is an open invitation to steal, and what the machine trims away to stop that theft.
So what is an open market actually paying for: good work, or work the middle already agrees is good?
Listen:
Apple Podcasts: https://podcasts.apple.com/kg/podcast/plain-strata/id6783455764?i=1000791614505
YouTube: https://youtu.be/sbJKGavPEyA
The full piece, no need to click through:
Imagine a judge at a competition who is better than the other judges. Not louder, not richer, just better: she spots the entry that genuinely deserves to win before anyone else does, and she scores it accordingly, well above what her colleagues wrote down.
On the network this essay is about, her score does not get partly counted. It gets cut off at a line, and the part that stuck out above the line is thrown away. Worse, she is quietly penalised for having written it. The machine that did this was not malfunctioning and nobody was corrupt. It did exactly what it was built to do, because it cannot tell the difference between a judge who is wrong and a judge who is early. Those two look identical from the outside: both are one person disagreeing with everybody else.
That single design choice is the load-bearing beam under every open network that pays people to do work nobody can check. It is worth understanding properly, because it explains what these systems are actually able to buy, and what they are structurally deaf to.
A network that pays strangers for AI work has to turn many private opinions about quality into one public number, and the way it does that is by trimming every opinion back to the stake-weighted middle. That buys real protection against a minority of liars, at the price of being unable to hear anybody who is right too early.
Thirty minutes, one mechanism, built from the floor up.
The network is Bittensor, and it is the largest live attempt to run artificial intelligence as an open market of strangers rather than as a product from one company. Four words and you can follow everything after.
The ledger is a shared spreadsheet that nobody is allowed to lie to. It keeps receipts, not models. It has no idea what a model is.
A sub-network is a pile of machines, owned by different people who have never met, all running the same code and all pointing at one row in that ledger. Each one is a market for a different job: serving model answers, forecasting weather, screening molecules.
A miner is one of those machines doing the work. The word is a loanword from Bitcoin and it is vestigial, the way a tape drive lived on inside the word "save" long after the tape was gone. No mining happens. It is a process on a machine with a graphics card, running an AI workload.
A validator scores how well the miners did, and it is the front door to the sub-network. It does not produce blocks. Its entire job is judgment.
Every seventy-two minutes, a round closes. That round is called a tempo. The validators submit their scores, the ledger reads them, and new tokens are minted to whoever scored well. That minting is called emission, from the Latin emittere, ex plus mittere, to send out. The money is sent out, and the scores decide where.
So the ledger never sees any AI. It sees numbers submitted by validators, and it pays according to those numbers. Everything interesting happens in the gap between the work and the number.
Median comes from the Latin medianus, from medius, the middle. Not the average. The average is where the weight sits; the median is the value with as much above it as below. The distinction matters enormously here, and in a moment it will be the whole story. One outrageous number drags an average. It barely moves a median, because a median does not care how far away the outlier is, only that it is on one side.
Delegate comes from delegare, from de plus legare, to send as an envoy. The same legare gives us legate and legacy: someone sent in your place, carrying something that is yours. That is exactly the right image, and it is a more honest one than the word "staking" suggests. When you delegate, you are not depositing money in an account. You are sending an envoy to a table you will never sit at, and the envoy votes in your name on questions you have not read.
Hold both of those. The mechanism is built out of them.
Here is the part that is usually skipped, and skipping it is why the rest never lands.
A validator does not send the ledger an opinion in words. It sends a list of numbers, one per miner. If there are a thousand miners in the sub-network, the validator sends a thousand numbers. Each one says what fraction of this sub-network's money that miner deserves this round. The list is normalised so the numbers are proportions rather than amounts, scaled into whole numbers, because the ledger works in integers and not in decimals.
That list is called a weight vector, and the name is doing real work. It is not a grade. A grade would be a statement about the miner. This is a statement about the distribution of money. When a validator writes down a number for a miner, it is not saying "this was good work," it is saying "this share of everything paid out here should go to this machine."
How the validator arrived at those numbers is entirely its own business. The network does not specify it, cannot inspect it, and mostly does not know it. A validator might send each miner the same question and compare answers. It might run its own reference model. It might have proprietary research it never publishes. The mechanism treats all of that as a black box and receives only the output.
So at the close of a round, the ledger is holding something quite specific: not one scorecard but a stack of them, one per validator, all scoring the same miners, all disagreeing with each other to some degree. Picture a table. Every row is a validator. Every column is a miner. Every cell is a number. That table is the raw material, and everything from here is what the machine does to it.
This is the mechanism inside the mechanism, and it is the only place this essay goes this deep.
Take one column of the table, meaning one miner, scored by every validator. You need to collapse that column into a single number that decides the payment. The obvious move is to average it. The obvious move is also fatal, because an average can be dragged. A validator that wants to enrich a miner it secretly owns writes a huge number in that cell, and the average moves toward it. Do that across enough cells and you have quietly redirected the network's money.
So the machine does not average. It does something else, and the something else is the whole design.
For each column, it finds the stake-weighted middle. Line up every validator's number for that miner, not one validator one vote, but each one carrying weight proportional to the stake standing behind it. Then walk from the top of that line downward, adding up stake as you go, until you have passed half of the total stake in the sub-network. The number you are standing on when you cross that halfway mark is the consensus value for that miner. It is a median with money on the scale rather than heads, and the halfway mark itself is a tunable setting rather than a law of nature.
Now the trimming. Every validator's original number for that miner is compared against that consensus value, and anything above it is cut off. Not scaled down, not averaged in. Cut. The part of your score that exceeded what the stake-weighted middle believed simply does not exist as far as the payout is concerned.
Look at what that buys. A validator holding a minority of stake can now write any number it likes in any cell and change nothing. Its inflated score sits above the consensus line and is trimmed away before a single token moves. Lying has become free to attempt and worthless to attempt, which is the strongest form of the pattern this show keeps meeting: arrange the world so that honesty is the cheaper option, rather than asking anybody to be honest. The cost of corruption exceeds the profit from corruption, and here the profit has been driven to exactly zero for anyone below the threshold.
There is a second layer on top, and it is what stops this from being a memoryless system. The trimmed scores do not pay out immediately at full force. They accumulate into something called a bond, which is a slow-moving record of which miners a validator has been backing over time. A validator that has been consistently pointing at a miner before the rest of the table agreed earns a larger share of that miner's eventual emission than one that arrived late. Bonds are the system's attempt to reward being early, which is the very thing the trimming punishes. And by default, bonds are accumulated from the trimmed numbers rather than the raw ones, which means the reward for being early is itself capped by how much the middle was willing to believe at the time.
That is the machine. Scores in, stake-weighted middle found, everything above it trimmed, bonds updated, tokens minted. Every seventy-two minutes, forever, with no human in the loop and no appeal.
Now bring back the envoy.
The stake weighting those scores is mostly not the validators' own money. It is delegated, and delegation is a stranger transaction than it sounds. Your coins do not move to the validator. The private key stays in your hand the entire time, and you can withdraw. Nothing about ownership changes. What travels is weight: the validator's scores now count for more, in proportion to what you sent, and the validator's judgment is the only judgment involved.
Nothing in the mechanism requires you to have read that judgment. Nothing requires the validator to have published one. And the practical routes by which delegation now happens, a button inside an exchange app, a checkbox at a custody provider, do not contain a scoring policy to choose, because there is nothing there to choose. You press a button, you see a yield, and an envoy is dispatched in your name to vote on which artificial intelligence work deserves to be paid.
This is the oldest problem in every stake-weighted system, and it is worth saying plainly that it is not a scandal. Scoring model outputs well is genuine, expensive work. A professional operation with staff and research almost certainly does it better than a person with a phone would. Delegation is not theft and it is not new.
What is new is what the vote decides.
Here is the comparison that makes the whole design legible, and it is the reason this mechanism looks familiar and behaves differently.
In an ordinary proof-of-stake network, delegated stake votes on validity: was this transaction properly signed, does this block follow the rules. Validity has a property that quality does not. Every other machine on the network can check it independently and arrive at the same answer, because the answer is determined by the rules and the data. A validator that votes for an invalid block is not merely in the minority. It is provably, mechanically wrong, and the system can identify that, prove it to everyone, and destroy its deposit. Slashing works there because there is a fact to slash against.
Now ask what happens on a network where the vote decides whether a piece of AI work was good. There is no equivalent fact. "This model's answer was better than that one" is not derivable from the rules and the data. No third machine can independently confirm it the way it can confirm a signature. So the only available standard for whether a judgment was correct is what the other judgments said, which means the defence against a dishonest majority is the majority itself.
That is not a flaw anybody failed to notice. It is what you get when you build a market for work whose quality cannot be checked from outside. The stake-weighted middle is the strongest available answer to the question, and it is a genuinely strong one against a minority. It has nothing at all to say to a coordinated majority, and by construction it cannot, because on that network a coordinated majority is the definition of correct.
This is the trimmed mean, and it is very old. Olympic scoring drops the high and the low. Insurance actuaries winsorise their tails. Any time a group has to aggregate judgments and cannot verify any single one, somebody eventually discovers that you protect the result by throwing away the extremes.
What every version of this trade shares is the cost, and the cost is always the same shape: you buy robustness against the worst participant by giving up sensitivity to the best one. The extremes you are discarding contain both your liars and your visionaries, and no statistical procedure has ever been able to separate them, because the separation is not in the number. It is in the world the number came from, and the number is all the machine has.
It is the compression trade-off wearing yet another set of clothes. This show has met it as precision spent for bandwidth in gradient compression, as precision spent for provability in zero-knowledge proving, and as value spent for verifiability in useful-work mining. Here it is accuracy spent for manipulation resistance. Same trade, fourth room.
There is also an asymmetry inside it worth holding, because it is where the design is honestly incomplete. The trimming is one-sided. Scores above the middle are cut; scores below it are not raised. The machine is built to stop you inflating somebody, and it is not built to stop you withholding from somebody. Those are different attacks and only one of them has a wall in front of it.
A machine that cannot distinguish being wrong from being early will, given enough time, be run by people who have stopped trying to be early. That is not a moral failure on anybody's part. It is the incentive doing exactly what it was designed to do, one layer further out than anybody was looking, and it is the same lesson as the thermostat with a space heater underneath it: the sensor is honest, the reading is correct, and the room is still cold.
The deeper version is about what an open network can buy at all. This show has arrived at that boundary from several directions now, and here it is again from the grading side. A permissionless network can only pay for work whose quality it has some way to establish, and where the work is AI output, the only way it has is agreement. So the market is not quite buying good AI. It is buying AI that the stake-weighted middle recognises as good, and the gap between those two things is exactly the space where everything new lives.
Put it together on a real validator, one holding hundreds of millions of dollars of delegated stake. Most of that money arrived through buttons in applications, from people who never chose a scoring policy. That stake is not a deposit, it is weight on a judgment. Each round the validator sends a weight vector over the miners. Its numbers are compared against the stake-weighted middle of all the validators' numbers, weighted by exactly this kind of accumulated stake. Whatever sits above that line is trimmed. What survives updates the bonds and mints the tokens, seventy-two minutes later, and again after that.
Every one of those steps is public, auditable and running as specified. The scoring policy that produced the numbers in the first place is the one part nobody outside the operator can see, and it is the part that decides everything.
Does any large validator on any of these networks publish a scoring policy specific enough that a delegator could read it, disagree with it, and move? Until one does, the most decentralized thing about the network is its money and the most concentrated thing about it is its opinion.
And can the one-sided trimming be closed without reopening the door it was built to shut? A wall against withholding would have to be a wall against a validator's silence, and silence is exactly what an honest validator with a genuine low opinion also produces.
Whether any large validator publishes a weight-setting policy in a form a delegator could act on, and whether the one-sided nature of the trimming ever gets treated as a subject rather than an implementation detail.
The two voices are AI. The research and writing are mine.
Decentralized AI, layer by layer.
Dastan,
You just read issue #23 of Plain Strata. You can also browse the full archives of this newsletter.