Compute Settlement Against Proof: Why NVIDIA Attestation Changes the Question
Building in public on an unsolved problem.
When an AI agent buys compute—GPU time, training capacity, a verified inference—something has to decide when the money moves. Today, that decision is made against a proxy. We're exploring what happens if it's made against cryptographic proof instead.
The Settlement Crisis in Compute
The compute marketplace runs on three mechanisms. None of them settle the core question: did the work actually happen correctly?
Liveness Settlement (Akash, io.net, Render)
The marketplace leader. Provider receives a payment escrow. Every block, the escrow drains by a fixed amount (roughly every 6 seconds). If the provider goes offline, the draining stops. Provider stays online = provider keeps earning.
What it proves: The GPU was turned on for N blocks.
What it doesn't prove: Whether the job executed correctly, the model was untampered, or the output is useful.
From Akash's own documentation: "Akash does not cryptographically verify that a job executed correctly."
Reputation Settlement (Apex Fusion Vector)
Apex Fusion opened their Vector settlement layer publicly on August 18, 2026. It has settled over 20,000 agent work packages in partnership with OriginTrail.
The mechanism: bonded escrow, staked reputation, staked-jury dispute resolution, and signed receipts carrying chain of custody. A jury of collateralized participants votes on whether work was valid. If unanimous, payment clears. If disputed, the jury's stake is at risk.
What it proves: A consensus of incentivized judges agreed the work was valid.
What it doesn't prove: A jury is a trusted third party by definition. Economic finality, not cryptographic finality. And it works inside one ecosystem—breaks when settlement must be cross-chain or cross-infrastructure.
Payment Rail Settlement (x402, AP2)
The newest and fastest-growing. x402 says: money moves when an HTTP 402 response is served. AP2 says: money moves when the agent is authenticated and authorized.
What it proves: An HTTP request completed. The agent was who they claimed to be.
What it doesn't prove: Anything about the work. Payment is cleared against a status code, not a cryptographic condition.
The Artifact That Already Exists: TEE Attestation
NVIDIA Confidential Computing on Hopper-class hardware (H100, H200) includes a hardware-fused Device Identity Key (DIK) anchored to NVIDIA's root certificate authority. When a workload runs inside the trusted execution environment, the NVIDIA Remote Attestation Service produces a cryptographically signed report.
That report contains:
- Firmware measurements (proof the GPU is running unmodified firmware)
- Workload hash (proof of which code is executing)
- A signature from NVIDIA's root CA
This is not a hypothetical. It is shipping in production on billions of dollars' worth of GPU hardware, right now.
The Design: Settlement Against Attestation
Here's what a compute HTLC would look like:
-
Agent locks funds on ETH with a challenge hash:
hash(secret) + {workload_hash, attestation_pubkey, timeout} - Provider locks funds on Solana with the same challenge hash
- Provider runs the workload inside the TEE
- TEE produces an attestation signed by NVIDIA's root CA, containing the workload hash
-
Provider computes the preimage (typically:
secret + workload_hash) and submits the attestation as proof - Agent verifies the attestation cryptographically (signature chain from NVIDIA's root CA back to the specific GPU) and reveals the secret
- Both chains settle atomically: Agent gets the attestation as proof; provider gets paid
No jury. No liveness proxy. No intermediary. Settlement is gated on a cryptographic proof of code execution.
The Caveat (Mandatory, Every Time)
Attestation proves which code ran on which silicon. It does NOT prove:
- The output is correct
- The output is useful
- The model was any good
- The workload didn't misbehave or leak data
And attestation moves the trust root from the network to NVIDIA's certificate authority. Not trustless. Trust-minimized, which is a real category: the hardware vendor is a dependency, but an NVIDIA-rooted proof is stronger than reputation-based jury consensus for cross-chain settlement.
This is not a weakness in the design. It's the honest statement of what the primitive does and doesn't do.
Why This Matters Now
The market is converging on Layer 2 settlement. Vector shipped first and has traction. Akash is the incumbent. x402 has Google and Mastercard behind it. The question of "what is settlement?" is about to get asked at industry scale.
Attestation closes a gap that reputation and liveness cannot. When agents trade compute across chains, or when compute is delegated through a chain of agents, reputation ties you to one ecosystem and liveness doesn't scale to settlement. Proof does.
The artifact already exists. NVIDIA has done the hardware work. Intel has done it. The TEE attestation is not a research prototype—it's the real artifact that $200M annualized protocol revenue in decentralized compute is built on top of. We can start asking what settlement against it looks like.
Nobody is settling against it yet. This is a design gap. Vector uses reputation. Akash uses liveness. x402 uses HTTP status. None of them use the artifact that's right there in the hardware.
The Open Questions
- Is workload hash enough? Or do we need additional conditions (e.g., model hash, output hash)?
- Can you do multi-step proofs? If an agent subcontracts work to another agent, does the attestation chain back to the original workload?
- What's the timeout risk? HTLC requires both sides to monitor the chain. If an agent goes offline during the reveal phase, funds are locked for the timeout period. Acceptable for compute? Or do you need async settlement?
- Can you compose across chains? Hash-time-locks work on ETH/Sui/BTC. But can an agent lock on one chain and a provider on another and still settle atomically? (Yes—that's the whole point of HTLC. But the engineering gets complex.)
- How do you handle the provider-agent negotiation? In asset settlement, both parties know the swap ratio up front. In compute, the agent needs to know: what workload hash do I challenge against? How does the provider prove that's the hash I actually want executed?
Our Status: Rails Ready, Trains Coming
We haven't built compute settlement. No contract, no testnet, no MCP server for it yet. What we have is the settlement primitive (HTLC) and a well-posed question that nobody in the compute ecosystem is asking yet.
The design work is underway. The blog post that priced our own forward design at 688 basis points (against a 1-2 bps fee for asset settlement) made the case that someone needs to close this gap. We're designing in public because this isn't a Hashlock-specific problem—it's an ecosystem question.
If you're building in compute infrastructure, agent frameworks, or TEE platforms: this is the layer to watch. If you're running compute marketplaces: this is the settlement mechanism that doesn't yet exist.
What would settlement against attestation change about how agents buy and sell compute? Reply below.
Learn more:
Top comments (0)