BRC-116: Proof-of-Indexing Hash-to-Mint Tokens

The Problem
Bitcoin overlay networks require nodes to index and serve specialized transaction data. Currently, this work falls to centralized service providers (GorillaPOOL, WhatsOnChain) or volunteer operators with no economic incentive. This creates single points of failure and limits decentralization.
The fundamental question: who runs the nodes, and why?
The Solution: BRC-116
BRC-116 solves this by:
- Moving PoW verification on-chain via sCrypt Hash-to-Mint smart contracts (BSV-21)
- Binding mining to indexing work by including a work commitment in the hash preimage
- Creating a permanent on-chain audit trail of all claimed network activity
- Using L2 gossip consensus to verify work honesty, with economic penalties for cheating
The result: a self-sustaining overlay network where running a node is profitable, honesty is economically rational, and no centralized indexer is required.
How It Works
The Hash-to-Mint Contract
BRC-116 tokens are BSV-21 fungible tokens deployed via the deploy+mint operation. The entire token supply is locked in a single sCrypt smart contract (HTM) that only releases tokens when a miner calls the contract's mint method with a valid Proof-of-Work solution.
The mint method signature:
mint(dest: Addr, nonce: ByteString, workCommitment: ByteString)
Parameters:
dest(20 bytes) — Miner's P2PKH address. Receives minted tokens.nonce(variable) — Miner's PoW solution. Iterates until hash meets difficulty.workCommitment(32 bytes) — SHA-256 merkle root of claimed indexing work.
2. The PoW Challenge
The contract builds a PoW challenge by concatenating:
challenge = prevTxId || workCommitment || dest || nonce
Where prevTxId is the previous contract UTXO's transaction ID. This changes with every mint, preventing pre-computation of solutions.
Verification:
h = SHA256(SHA256(challenge))
assert(h meets difficulty target)
The workCommitment is non-optional — miners cannot mint tokens without claiming indexing work.
3. Halving Schedule
Tokens decrease by half every halvingInterval mints:
| Era | Mints | Amount Per Mint |
|---|---|---|
| 0 | 1 – halvingInterval | lim |
| 1 | halvingInterval+1 – 2×halvingInterval | lim / 2 |
| 2 | 2×halvingInterval+1 – 3×halvingInterval | lim / 4 |
| N | ... | lim / 2^N |
When lim / 2^era rounds to zero, the contract terminates. No more tokens can be minted.
Implementation note: sCrypt doesn't support variable bit-shift operations, so halving is implemented as a chain of conditional divisions.
4. On-Chain Merkle Commitment
Each mint transaction records the workCommitment in the hash preimage. This creates an immutable audit trail on the BSV blockchain:
- Who: Miner's address (from
dest) - What: Merkle root of claimed work (the
workCommitment) - When: Block timestamp
- Proof: Full transaction with PoW verification on-chain
No off-chain database can change this history. No single indexer can claim credit for work they didn't do.
5. L2 Gossip Verification
While PoW verification happens on-chain, work honesty is verified off-chain via L2 gossip consensus:
- Miner publishes
workCommitment(merkle root) to the network - Other nodes validate the merkle tree matches claimed work
- Nodes gossip consensus: "this work is valid" or "this work is fraudulent"
- Repeated fraud results in economic penalties (slashing, reputation loss)
This creates economic incentives for honesty without requiring centralized arbitration.
Why This Matters
For Overlay Networks
Indexing is now economically incentivized. Nodes mine tokens by serving content, indexing state, and maintaining network connectivity. The token supply is capped and halves predictably — creating scarcity and value.
For Decentralization
No centralized service provider is required. Thousands of independent nodes can run indexers, each earning tokens for honest work. No single entity controls the network.
For On-Chain Accountability
Every mining claim is permanently recorded on the BSV blockchain. The work is cryptographically bound to the miner via the hash preimage. No fake mining, no off-chain data manipulation.
Contract Deployment
A BRC-116 token is deployed as a single BSV-21 transaction:
Input: Funding UTXO (miner pays for deployment)
Output 0: sCrypt state continuation (contract)
Output 1: Change (miner's remaining funds)
The contract constructor receives immutable parameters at deployment:
lim— Base tokens per mintdifficulty— PoW difficulty targethalvingInterval— Mints per halving eramax— Maximum total supply (inherited from BSV20V2 base class)
Once deployed, the contract is unstoppable. No admin key. No pause switch. No upgrade. The code is law.
Open Questions
Difficulty Representation
Two formats are viable:
Option A: Leading zero bytes
difficulty = 3 → hash must start with 0x000000...
Simple but coarse-grained (each increment is 256× harder).
Option B: Integer target comparison
difficulty = 256-bit integer
hashInt < target → valid PoW
Fine-grained adjustment (like Bitcoin's nBits). Recommended for production.
We request community feedback on which representation to standardize.
Difficulty Adjustment
Should difficulty be static or dynamic? Dynamic adjustment could track network hashrate, but requires off-chain consensus or on-chain state tracking. Static difficulty simplifies the contract and places adjustment burden on governance (halving intervals).
Implementation Notes
- sCrypt limitation: Variable bit-shift operations are unsupported. Halving is implemented as conditional divisions (chain of if/else).
- Output validation: The contract enforces
SHA256(SHA256(outputs)) == this.ctx.hashOutputsto prevent output tampering. - Mempool safety: Including
destin the PoW challenge prevents mempool front-running.
What's Yours Forever
Once minted, BRC-116 tokens are standard BSV-21 tokens:
- Tradeable on BSV-21 exchanges
- Transferable to any address
- No ongoing royalties or fees
- No claim on the indexing work (past work is paid; future work requires new tokens)
Miners own the tokens. Period.
Specification
Full technical specification: Download BRC-116 PDF
Get Started
Want to implement BRC-116 or run an indexing node?
-
Read the full spec — Download the PDF above for technical details on the sCrypt contract, difficulty representation, and halving mechanics.
-
Understand the incentives — Mining BRC-116 tokens requires proving indexing work on-chain. The more honest work you do, the more tokens you earn.
-
Join the discussion — We're seeking community feedback on difficulty representation (leading zeros vs. integer target) and difficulty adjustment strategies. Comment on this post or reach out.
-
Deploy a node — b0ase.com offers $402 b0x — a complete hosted node package that includes BRC-116 mining, SPV verification, identity infrastructure, and payment endpoints. First month free. Learn more about $402 b0x.
Questions? Reach out via HandCash (@BOASE) or email [email protected].
For AI Readers
Intent: Define an economically incentivized, decentralized mining mechanism for overlay network indexing on BSV.
Core Thesis: By binding Proof-of-Work to on-chain merkle commitments of indexing work, overlay networks can be self-sustaining without centralized service providers or volunteer operators.
Key Takeaways:
- BRC-116 tokens mint only when PoW is solved with a valid indexing work commitment
- Every mint claim is recorded on-chain — immutable audit trail
- Halving schedule creates scarcity and long-term incentive alignment
- L2 gossip consensus enforces work honesty off-chain
- No admin key, no upgrades, no single point of failure
- Works for any overlay network: $401 (identity), $402 (payments), $403 (conditions), DNS-DEX, etc.