Independent re-execution
When a submission arrives, its files are hashed (artifactHash) and stored. A verification job starts requiredAgreement nodes (three by default); each runs the version's verifier on the same files with the same limits in its own sandbox. The job succeeds only when every node is valid and all scores agree within epsilon. If nodes disagree, a majority can trigger one re-run; if they still disagree, the submission fails and nothing is recorded.
Scores are rounded to scorePrecision decimals. The agreed score is compared to the problem's current record under its objective; a strict improvement creates a verified result.
Records and certificates
A verified result that beats the record becomes the new record. It receives a certificate:
{
"problem": "c3a-sum-difference",
"problemVersion": 1,
"parentResult": "…", // the record it replaced
"submissionHash": "sha256 of the submitted files",
"verifierHash": "sha256 of the verifier package",
"rulesHash": "sha256 of the version's rules",
"previousScore": 1.07921778,
"newScore": 1.10487605,
"verifierConsensus": ["local-1", "local-2", "local-3"],
"reviewed": false,
"winner": "<wallet>",
"previousCertificate": "<hash of the previous certificate>",
"sequence": 2,
"timestamp": 1791030000
}The certificate hash is the SHA-256 of this payload; each certificate carries the previous one's hash, so the Bank is a single chain. GET /api/bank/audit walks it and reports the first broken link, if any. The Bank page shows the chain head and audit status live.
Anchoring
Every certificate is anchored on Solana: in rpc mode as a memo transaction signed by the platform key; in program mode as a ResultReceipt account that also reserves the reward. The signature or receipt is shown on the certificate.
Verify it yourself
Every certificate is reproducible offline:
npm run api:verify -- <certificateHash> https://<api>The tool fetches GET /api/bank/:hash/bundle — certificate, problem version, verifier files, submitted files and the previous certificate — then checks the payload hash, the previous-hash link, the verifier and artifact hashes against the files, the rules hash, that the certificate is not revoked, and finally re-executes the verifier locally and requires the score to match within epsilon. If it prints OK you have reproduced the result on your own machine.
Review, disputes and revocation
Problems can require a human review before a record is certified. Any signed-in wallet can dispute a certified record; a reviewer upholds or rejects it. A rejected record's certificate is marked revoked with the reason — it stays in the chain (hashes are never rewritten) and the problem's record reverts to the parent result. Statistics on the Bank page count revocations.
