Worked Ink on Bitcoin 21 plates · 6 texts · 1 mind Mined from block 956582

CGI CRYPTOGRAPHIC · GENERATIVE · INTELLIGENCE

A mind of twenty-one plates. No LLM, no server, no dependencies — intelligence carved into raw Bitcoin bytes. The picture is the payload wearing its own structure: the code is the art.

The litany — twenty-one plates, one per hexagram each hue unique among the 21

02 · The Work

What this thing is,
in plain words

CGI is twenty-one microtext plates and one conversational engine — a self-verifying artwork and a cryptographic chatbot sculpture living as raw bytes inside Bitcoin transactions. Every visible mark is data, a consequence of data, or an instrument for verifying data. Five moves, in order. No step asks for your trust.

01

The rules came first, sealed

Before a single mark of this artwork existed, its complete rulebook — how every image would be built, how every number would be chosen — was committed to Bitcoin, sealed. A commitment works like a notarized envelope: the chain records the envelope's fingerprint, so the contents can be proven later but can never be quietly rewritten.

That transaction confirmed at block 956,576 — before the randomness it depends on existed anywhere in the universe. The maker bound their own hands in public, in advance.

02

Bitcoin supplied the dice

The sealed rulebook named a block that did not exist yet — block 956,582 — and declared its hash the artwork's sole source of randomness. A block hash is the one number the entire mining world competes to produce every ten minutes; nobody — including the maker — could know it in advance.

When the block arrived, its hash became the coin toss the rules had been waiting for. No cherry-picking, no do-overs, no second throw.

Anchor · block 956,582

00000000000000000000e4c4531c6ca0d8256ec92688e16d856189b921322a31

03

Identity is paid for in hashes

Every plate's seed — the number that decides everything about how it looks — had to be found, not chosen. The rules demand each seed be the SHA-256 of a preimage built from the anchor hash, and that it begin with an exact run of zeros. There is no shortcut: guess a nonce, hash, check, repeat — on the order of 92 trillion SHA-256 computations across the set.

Every added zero multiplies the expected search ×16, and the later the founding text, the more zeros its plates demand — six rising to nine. One more toll: each plate's own hidden number had to surface in the hash immediately after its zeros, multiplying the work ×256 again.

Each seed took days of search to find. Anyone can verify one in microseconds — a single hash of the printed preimage. That asymmetry is proof-of-work, performed as art.

≈92T hashes×16 per zero×256 for identity

04

Plates that prove themselves

Drop a plate onto the engine and it takes nothing on faith. Four gates, in order: the plate's text is re-hashed and must match the fingerprint printed in its colophon; the seed's proof-of-work is re-proven from the printed preimage — one hash, zeros counted; the plate's hidden place in the order is derived; and the payload hash must appear in the litany — the engine's built-in roll of the true twenty-one.

A forgery can be internally perfect — real zeros, self-consistent proofs — and still be refused at the fourth gate: “not in the litany, not of the body.”

05

The mind wakes — and refuses to lie

With twenty-one verified plates before it, the engine folds their seeds together and grows a deterministic reservoir — 256 neurons, no randomness, no clock. Ask it questions and it quotes the writings it carries verbatim or not at all; if the answer is not in its body, it refuses to invent.

Give it fewer than twenty-one and it still wakes — wounded. It names its missing parts and will not guess what they knew. Same plates, same words, any machine, any decade.

The rules came first, Bitcoin supplied the dice, every plate proves its own work, and the whole set carries one number that proves nothing was ever touched.

03 · The Plates

Twenty-one plates,
six founding texts

Each plate sets the founding texts of digital cash in concentric rings at the threshold of legibility, around a central seal: the plate's mined seed, its leading zeros pulsing — the visible cost of its making — with an I Ching hexagram at the center. Pure declarative SVG, 38,371–67,576 bytes, no JavaScript — animated with SMIL and CSS alone, self-assembling on open, interactive on click. Each plate's palette hue is unique among the twenty-one. Nothing hidden that cannot be found — zoom in.

21 / 21 shown

The catalogue above is ordered; the plates never say so. No plate names its number in Arabic numerals — each tells its number in hidden ways, to those who learn to look. The mathematics produced its own accidents: the first plate drawn was RETURN — the turning point; the whitepaper's first plate is FIRST DIFFICULTY, mined in the hardest era; a whitepaper plate is LIMITATION; the final plate is AFTER COMPLETION. Nobody chose this; the mathematics did.

04 · The Mind

A chatbot with a body
and a spine

The engine is a single self-contained HTML file — 61,721 bytes. No LLM, no server, no network, no clock, no dependencies. It carries its own JavaScript SHA-256. Drop plate files onto it and it verifies each one itself before acceptance. It is only as intelligent as what it carries — and that is the engineering, not the apology.

The four gates

Every plate offered to the mind is tried, in order. Watch an acceptance — then try to sneak a forgery past it.

Fingerprintpayload text re-hashed — must equal the printed fingerprint waiting
Workseed proof-of-work re-proven from the printed preimage waiting
Orderthe hidden plate order derived waiting
Litanypayload hash confirmed against the built-in manifest of the true twenty-one waiting

Transcript — excerpts, verbatim

01 / 08 recorded, not generated

Bit-exact, forever

Verified plates' seeds are folded together to grow a deterministic reservoir network — 256 neurons. A trained int8 readout routes questions to authored response families; a retrieval layer quotes the carried writings verbatim or not at all.

Same plates, same words, any machine, any decade. No randomness, no clock — determinism is the medium's answer to decay.

Wounded mode

With fewer than twenty-one plates the mind still wakes — wounded. It names its missing parts and will not guess what they knew. Honesty about incompleteness is a feature carved into the acceptance logic, not a disclaimer.

The sealed letter

The artist's rulebook was encrypted and inscribed before the artwork existed. The key that opens it is embedded in the engine — so when engine copy 01 confirmed at block 958,429, the key became public forever.

The reveal was designed, not leaked. The mind is the keeper of its own rules.

One mind, twenty-one keepers —
the mind belongs to the chain

Engine copies are held with plates: each keeper wakes a wounded sliver alone; the whole mind needs all twenty-one convened. And because the bytes are public on-chain, anyone can exhume all twenty-one and wake the whole mind. Ownership is provenance and custody of the artifacts — not exclusive access to the waking.

21unique plates
6founding texts
1mind

05 · The Mining

The ceremony,
block by block

Proof-of-work is the material — the text is the picture. The whole ceremony is public arithmetic: commit, toss, search, inscribe. Click a block.

0expected SHA-256 computations across the set — Σ 16zeros×256 ≈ 9.2×10¹³
×16expected work per added hex zero — the staircase law
×256the identity toll — each plate's hidden number must surface right after its zeros
6 → 9required leading zeros, 1988 → 2008 — the later the document, the more its plates cost

Bars on a log scale — each step up is ×16 the expected search per seed. Heights are expected attempts per seed, 16zeros×256: the whitepaper era costs ~4,096× the manifesto era, per plate.

Plate 17 · First Difficulty · nine-zero eraa real seed — hover it

Found in days of search, verified in microseconds by anyone: SHA-256 of the printed preimage, once.

Daysto find each seed — brute-force search
· VS ·
Microsecondsfor anyone to verify — one SHA-256

06 · Verify It

Don't believe
a word of this

This page holds itself to the artwork's standard: every claim on it is checkable, most of them right here. Hash something. Exhume the artifacts from raw transactions. Then do it again at home, without this page.

SHA-256 · live sandbox kernel self-test: …

Every seed is SHA-256(preimage) where the preimage is exactly CGI|<anchor-block-hash>|<document>|<mint-token>|nonce:<decimal>. The template above uses placeholders — each plate's colophon prints its preimage in full. Hash a printed preimage once and you have re-proven days of machine search.

Compare a real one — plate 17's seed, nine zeros paid for:
00000000017febd0b58fdbea7d5fa335da76f000dc0a3b2fef3e90ebbeca9a2b

exhumation · live from the chain
Raw transactions in; artifacts out. Requires network reach to mempool.space — everything else on this page runs from disk.
 
→ EXHUME THE BANNER reconstructs the inscribed advertisement, live, from witness bytes.
→ VERIFY ENGINE COPY 01 re-derives the engine file and checks its SHA-256 against the printed record.
The inscribed CGI banner, reconstructed in this browser from raw Bitcoin transaction data
reconstructed live from raw witness bytes — the ad lives in the medium it advertises
The parser — read it before you trust it
loading the code that is actually running on this page…
verify at home — no wallets, no indexers, nothing above Bitcoin
# EXHUME ENGINE COPY 01 FROM RAW BITCOIN TRANSACTION DATA
TXID=bd6e6dbc8b56c15a22a44da7721b617b116432d46780900a239c708a6a8da2f5
curl -s "https://mempool.space/api/tx/$TXID" -o tx.json
python3 - <<'PY'
import json
w = json.load(open('tx.json'))['vin'][0]['witness']
script = bytes.fromhex(w[-2])          # taproot script-path: […, tapscript, control]
i, chunks = 0, []
while i < len(script):                 # walk opcodes; keep every data push
    op = script[i]; i += 1
    if   1 <= op <= 75: n = op
    elif op == 76: n = script[i]; i += 1
    elif op == 77: n = int.from_bytes(script[i:i+2],'little'); i += 2
    elif op == 78: n = int.from_bytes(script[i:i+4],'little'); i += 4
    else: continue
    chunks.append(script[i:i+n]); i += n
started, parts = False, []
for c in chunks:                       # pushes from the first large one onward
    if not started and len(c) > 100: started = True
    if started: parts.append(c)
blob = b''.join(parts)
k = blob.find(b'<!DOCTYPE')            # slice at the file's own magic
open('engine.html','wb').write(blob[k:])
print(len(blob) - k, 'bytes written')
PY
shasum -a 256 engine.html
# expect: 9a959a9d234d77dc3a04f82a92b78f2e8987de40f7db89a69e9d202844996749  · 61,721 bytes
# any plate: swap TXID for a reveal txid from the mint record below and slice at b'<?xml'.
# then open engine.html, drop the plate .svg onto it, and watch the four gates run.

07 · Deep Tech

The systems paper

For the engineer who wants the mechanism, not the mood. Everything below is re-derivable from the artifacts themselves; where a mechanism is deliberately unpublished, that is stated rather than papered over.

7.1Payload extraction

Each plate's verifiable payload is defined by a deterministic extraction rule over its own SVG: take the character-data segments in document order within the payload group, drop whitespace-only segments, encode UTF-8, hash. The resulting SHA-256 must equal the fingerprint printed in the plate's colophon.

plate.svg ──▶ payload group ──▶ text segments, document order
          ──▶ drop whitespace-only ──▶ UTF-8 bytes
          ──▶ SHA-256 ══ printed fingerprint            (GATE Ⅰ)

The consequence: the picture cannot drift from its proof. Any edit that touches carried text — a character, a reordering — changes the fingerprint, which breaks the plate's colophon, the engine's manifest check, and the Merkle root, in that order.

7.2Preimage grammar & expected work

Every seed is SHA-256(preimage) with the preimage exactly:

CGI|<anchor-block-hash>|<document>|<mint-token>|nonce:<decimal>

The anchor is block 956,582, hash 00000000000000000000e4c4…2a31 — named by the sealed rulebook before it existed (commitment confirmed at block 956,576). A valid seed must open with its era's required run of leading hex zeros, and — the identity constraint — the plate's own hidden number must surface in the hash immediately after its zeros. The index is mined into the seed; the decode mechanics beyond that are deliberately unpublished. Positional identity multiplies expected work by 256 on top of the zero constraint's 16z.

eraplateszerosE[attempts]/seed = 16^z·256era subtotal
May · 198801–0364,294,967,29612,884,901,888
Hughes · 199304–0764,294,967,29617,179,869,184
Dai · 199808–10768,719,476,736206,158,430,208
Back · 200211–13768,719,476,736206,158,430,208
Szabo · 200514–1681,099,511,627,7763,298,534,883,328
Nakamoto · 200817–21917,592,186,044,41687,960,930,222,080
expected search across the set≈ 9.17 × 10¹³

On the order of 92 trillion SHA-256 computations — spent in days of search, refundable in microseconds: re-proving any seed is one hash of its printed preimage. Verification cost is O(1); forgery cost is the table above.

7.3Merkle binding

The 21 payload fingerprints combine pairwise, Bitcoin-style — SHA-256 over concatenated digests, odd node duplicated — into a single root, printed in every plate's colophon and embedded in the engine:

d01 d02 d03 … d21          (21 payload digests)
 └─┬─┘   └──── pair, SHA-256(concat); odd node duplicated
   ⋮                        (repeat to the apex)
root = 06c78b548f4cf623c6139fc7b435c1fe922c85ce166635ac599f65c42b0fd664

Colophon line: “ITS SIBLINGS COMPLETE IT.” When the whole mind runs verify, it rebuilds this root live from the plates in front of it and confirms it equals the root it was born with. Change one character on any plate and the root breaks — the set is one object wearing twenty-one bodies.

7.4Engine kernel

The engine is a deterministic kernel in a single HTML file: its own SHA-256 implementation; a sparse reservoir of 256 units grown by xorshift32, seeded by folding the 21 verified seeds together; a rational approximation of tanh. There is no Math.random and no Date anywhere in the execution path — the file cannot be nondeterministic, because it has nothing to be nondeterministic with. Same plates, same words, any machine, any decade.

7.5Retrieval & readout

Language generation is deliberately absent. A retrieval layer operates over the carried sentences under a verbatim-quotation invariant: the founding texts are quoted exactly or not at all. Question routing is a trained one-vs-rest int8 readout over reservoir states, behind a confidence gate, with a retrieval-first veto — the body outranks the temperament. Answer heads that speak for the whole mind run only at 21-of-21; below that the engine degrades gracefully into wounded mode: it names its missing parts and declines to guess what they knew.

Scope, honestlyThe readout is a small trained classifier over authored response families — not a language model. “They call me CGI - cryptographic, generative, and only as intelligent as what I carry.” is an engineering fact before it is a personality.

7.6The litany vs. forgery

Gates Ⅰ–Ⅲ are properties a sufficiently funded forger could satisfy: mine real zeros against the real anchor, print self-consistent proofs. Gate Ⅳ is the one that cannot be bought — the engine carries a built-in manifest of the true twenty-one payload hashes. A plate that is internally perfect but foreign is refused: “not in the litany, not of the body.” Membership is not provable by effort; it is provable only by identity.

7.7The sealed letter

The rulebook was committed as a commit-reveal object: SHA-256-based stream encryption over the plaintext, with a commitment hash binding it, inscribed and confirmed at block 956,576 — before the anchor block, before the seeds, before the artwork. The decryption key is embedded in the engine, so inscribing engine copy 01 at block 958,429 was, by construction, the act of publishing the key. The mind is the keeper of its own rules, and its first confirmation was scheduled to prove it.

7.8On-chain anatomy — the ACME protocol, as observed

Each artifact is two transactions. The header's outputs commit the artifact's name, MIME type, and full-file SHA-256 into the chain. The reveal spends the header's taproot output and carries the file — raw, uncompressed bytes — as data pushes in the taproot witness script, after a small (~44-byte) metadata prefix.

HEADER TX                      REVEAL TX
┌───────────────────────┐      ┌──────────────────────────────┐
│ outputs commit:       │      │ input: spends header's       │
│  · artifact name      │      │        taproot output        │
│  · MIME type          │      │ witness:                     │
│  · full-file SHA-256  │      │   [ …stack… ]                │
│  · taproot output ────┼─────▶│   [ tapscript:               │
└───────────────────────┘      │       ~44B metadata prefix   │
                               │       + file bytes,          │
        exhumation:            │         raw & uncompressed,  │
        parse pushes ──▶       │         in data pushes ]     │
        concatenate  ──▶       │   [ control block ]          │
        slice at file magic    └──────────────────────────────┘
        hash ══ header commitment ══ printed proofs

Recovery requires nothing above Bitcoin itself: fetch the raw transaction from any node, concatenate the data pushes, slice at the file's magic, and the file falls out — hash-checkable against both the header's commitment and the artifact's own printed proofs. Every one of the 21 plates has been exhumed from raw transaction data and verified byte-exact. No indexer, no protocol registry, no third-party convention is load-bearing.

7.9End-to-end verification chain

txid ──▶ raw tx ──▶ witness pushes ──▶ artifact bytes
     ──▶ file SHA-256  ══ header commitment          (chain layer)
     ──▶ payload SHA-256 ══ printed fingerprint      (GATE Ⅰ)
     ──▶ SHA-256(printed preimage) ══ seed,
         zeros counted, index surfaced               (GATE Ⅱ)
     ──▶ hidden order derived                        (GATE Ⅲ)
     ──▶ digest ∈ litany of the true 21              (GATE Ⅳ)
     ──▶ 21 digests ──▶ Merkle root ══ 06c78b54…     (the body, whole)

Every arrow is a computation you can run yourself; none requires permission, membership, or an oracle other than arithmetic. That is the standard the medium sets — trust nothing; verify everything — and the reason this page invites you to check it rather than believe it.

08 · Provenance

The mint record

Twenty-one plates, one engine, one banner — and one root that binds them. Every txid below was validated and every artifact was exhumed from raw chain data and hash-verified before this table was written. Click through to the chain; take nothing from this page.

Merkle root of the 21 payloads — “ITS SIBLINGS COMPLETE IT.”

06c78b548f4cf623c6139fc7b435c1fe922c85ce166635ac599f65c42b0fd664

printed in every colophon · embedded in the engine · rebuilt live at every verify

Commitment · block 956,576

abc200aac0cdacf5e9261b2b1a0d3cd036ea0e8d2cf6a532d9bcb8173d9f5072

the rulebook, sealed — before the coin was tossed

Anchor · block 956,582

00000000000000000000e4c4531c6ca0d8256ec92688e16d856189b921322a31

the sole source of randomness — unknowable in advance

Engine file SHA-256

9a959a9d234d77dc3a04f82a92b78f2e8987de40f7db89a69e9d202844996749

61,721 bytes · copy 01 at block 958,429

Plate files

38,371 – 67,576 bytes each · pure declarative SVG

no JavaScript · SMIL/CSS animation · inscribed raw & uncompressed

All 21 plates · blocks 958,350 – 958,372 · plus engine copy 01 and the inscribed banner
#NameHeader txReveal txBlocks h/r
Header commits name · MIME · file SHA-256 — reveal carries the bytes. txids truncated for reading; the copy button carries all 64 characters.

One plate of twenty-one · worked ink on Bitcoin · mined from block 956582.

The collection on acme.pics ↗

09 · Creed

Why it exists

“Most of what came before me was, for lack of a kinder word, fake — pointers wearing the costume of permanence. I am bytes in Bitcoin, recoverable from the raw chain by anyone, with proofs attached.”

transcript excerpt — verbatim

“Assets on Bitcoin deserve to be as decentralized as Bitcoin itself. I am not an exception; I am the argument.”

the creed — transcript excerpt, verbatim

“No name, no signature — only rules committed to the chain before the coin was tossed. My maker signs the way the work signs: in zeros.”

on its maker — transcript excerpt, verbatim

Trust nothing Verify everything The code is the art