Appendix A

Mathematical Appendix

12 min read

Precious metals and collectibles have an unforgeable scarcity due to the costliness of their creation. This once provided money the value of which was largely independent of any trusted third party. Precious metals have problems, however. Thus, it would be very nice if there were a protocol whereby unforgeably costly bits could be created online with minimal dependence on trusted third parties, and then securely stored, transferred, and assayed with similar minimal trust.

Nick Szabo, 'Bit Gold' (2005)

Mathematical Appendix


Notation Reference

SymbolDefinitionUnits
HHBitcoin network hash rateTH/s
hhMiner hash rateTH/s
RRBlock subsidy plus expected feesBTC/block
τ\tauExpected block intervalseconds
ε\varepsilonMining hardware efficiencyJ/TH
pBTCp_{BTC}BTC price in the chosen accounting currencycurrency/BTC
pEp_ESite electricity pricecurrency/kWh
kmk_mMining capital and operating costs other than electricity, normalized to the same energy horizoncurrency/kWh
kswitchk_{switch}Amortized switching and redeployment cost over the same horizoncurrency/kWh
Ωs\Omega_sAlternatives accessible to site and operator ssfinite set
rsoutsider_s^{outside}Operator-specific outside-option returnannualized rate
NNNumber of participantscount
EGE_GNegotiated counterparty relationshipsedges
CCCollateral reported lockedsettlement units
α\alphaContractually slashable fractiondimensionless (0–1)
pdp_dProbability that defection is detecteddimensionless (0–1)
pap_aConditional probability that the adverse finding is authorized after challenge or adjudication, given detectiondimensionless (0–1)
pcp_cConditional probability that an authorized penalty is collectibledimensionless (0–1)
GGGain from defectionsettlement units
FFPresent value of forfeited future rentssettlement units
LLCovered claimant losssettlement units
AjA_jActive allocation against collateral binding jjsettlement units
rlock(τ)r_{lock}(\tau)Opportunity cost of locking collateral for tenor τ\tauannualized rate
λi(t)\lambda_i(t)Failure hazard for service specification iirate
SiS_iLoss severity conditional on failuresettlement units
RiR_iReturn on service specification iidimensionless
βi\beta_iCovariance coefficient used by an optional pricing heuristicdimensionless

A.1 — A Site-Specific Mining Outside Option

Definition. Bitcoin mining converts SHA-256 hash work into a probabilistic BTC revenue stream. For a miner contributing hash rate hh, expected BTC production per unit time is:

E[BTC/time]=hHRτ.\mathbb{E}[\mathrm{BTC}/\mathrm{time}] = \frac{h}{H}\frac{R}{\tau}.

If the hardware consumes ε\varepsilon joules per terahash, gross expected BTC production per kilowatt-hour is:

qBTC/kWh=3.6×106RHτε.q_{BTC/kWh} = \frac{3.6 \times 10^6 R}{H\tau\varepsilon}.

Derived result. For a named site ss, gross mining revenue per kilowatt-hour in a chosen accounting currency is qBTC/kWhpBTCq_{BTC/kWh}p_{BTC}. Normalize pool fees, hardware depreciation, financing, facility cost, curtailment, taxes, and switching cost to the same currency-per-kilowatt-hour horizon. Net mining value is then:

Πsmining=qBTC/kWhpBTCpE,skm,skswitch,s.\Pi_s^{mining} = q_{BTC/kWh}p_{BTC} - p_{E,s} - k_{m,s} - k_{switch,s}.

This value is not a universal compute floor. Bitcoin mining uses specialized SHA-256 hardware. An inference accelerator cannot ordinarily be redirected into competitive Bitcoin mining, and electricity at one site cannot automatically reach mining infrastructure at another. The mining alternative becomes relevant only where the operator can deploy compatible hardware, redirect a constrained power input, buy equivalent exposure, or contract with a counterparty on terms whose frictions are included.

Definition. The operator-specific hurdle is the best accessible alternative in the operator's opportunity set:

rsoutside=maxωΩs(rs,ωgrossks,ωswitchks,ωrisk).r_s^{outside} = \max_{\omega \in \Omega_s} \left(r_{s,\omega}^{gross}-k_{s,\omega}^{switch}-k_{s,\omega}^{risk}\right).

The set Ωs\Omega_s may include inference, mining, curtailment services, selling power, buying BTC, repaying debt, or leaving capacity idle. Another operator may face a different set.

Five quantities must remain separate:

  1. Mining revenue is BTC produced per unit of hash work or energy before full cost.
  2. Return on mining capital includes hardware, facilities, financing, operating risk, and residual value.
  3. BTC acquisition return is the return from buying and holding BTC; expected price appreciation is an asset-return assumption, not a conversion between dollar and BTC returns.
  4. Secured funding cost is the rate paid to borrow against collateral under named custody, venue, liquidation, and counterparty terms.
  5. Collateral-lock opportunity cost is the value of alternatives forgone while an asset is encumbered. A time lock does not itself generate yield.

Assumption. A mining-linked hurdle affects another workload only when both compete for a genuinely substitutable marginal resource after switching, hardware, location, financing, and risk are included.

Falsifier. The mining-linked hurdle is not economically informative for a class of operators if their workload returns persistently move independently of their measured accessible mining alternatives after the relevant frictions are included.


A.2 — What a Common Benchmark Does and Does Not Do

Definition. A complete bilateral market among NN participants contains:

(N2)=N(N1)2\binom{N}{2}=\frac{N(N-1)}{2}

possible pairwise relationships. If every pair independently authors a kk-parameter credit curve, the representation cost is O(kN2)O(kN^2).

Derived result. A common reference curve can reduce representation cost when every participant publishes a kk-parameter spread against the same curve. Under that architecture the published parameter count is O(kN)O(kN).

This is a conditional compression result, not a proof that a common benchmark is required for market formation. Real markets may be sparse. If only EGE_G relationships are active, bilateral representation is O(kEG)O(kE_G). Auctions, clearinghouses, hierarchical routing, netting, and algorithmic quote discovery can coordinate participants without one hegemonic benchmark. Multiple interoperable curves may also coexist.

Assumption. Benchmark compression is useful when a sufficiently large set of participants accepts the same conventions, governance, data, and fallback behavior.

Conjecture. Machine commerce will favor portable reference curves because software can quote, compare, and hedge standardized terms more cheaply than bespoke ones. The reference could be fiat, Bitcoin, energy-linked, venue-specific, or composite. This appendix does not establish a universally necessary denominator.

Falsifier. The conjecture weakens if large agent markets coordinate efficiently through sparse bilateral, auction, or clearing architectures without converging on common reference curves.


A.3 — Incentive Compatibility, Restitution, and Collateral

Collateral serves at least two different purposes: changing the incentive to defect and making value available to a claimant after a covered loss. The first is deterrence. The second is restitution. Neither follows from the other.

Incentive condition

Definition. Let GG be the gain from defection, CC the reported locked collateral, α\alpha the enforceable slash fraction, pd=P(detected)p_d=P(\mathrm{detected}), pa=P(authorizeddetected)p_a=P(\mathrm{authorized}\mid\mathrm{detected}), pc=P(collectedauthorized)p_c=P(\mathrm{collected}\mid\mathrm{authorized}), and FF the present value of future rents lost after defection. Authorization presupposes a detected case in this closed sequence, and collection presupposes authorization, so the product below is the joint probability under the stated conditional chain rather than an independence assumption.

Derived sufficient condition.

pdpapcαC+FG.p_d p_a p_c \alpha C + F \geq G.

This condition makes each dependency explicit. A large nominal bond may provide weak deterrence when detection is poor, the forum lacks authority, collection is unlikely, or the obligor can retain future rents under a new identity.

Restitution condition

Definition. Let LL be the claimant's covered loss and let CclaimantC_{claimant} be collateral actually available to that claimant after senior claims, fees, challenge, adjudication, and collection.

Derived sufficient condition.

CclaimantL.C_{claimant} \geq L.

If the contract exposes only the fraction αC\alpha C and collection is uncertain, a planning inequality may use papcαCLp_a p_c\alpha C \geq L. That is an expected-collection criterion, not a guarantee of restitution in an individual case.

The two conditions answer different questions:

  • Incentive compatibility asks whether expected consequences outweigh the gain from defection.
  • Restitution asks whether the claimant can recover the covered loss.

Assumption. The promise identifies the predicate, evidence, authority, challenge process, forum, collateral priority, and settlement path that determine pdp_d, pap_a, pcp_c, α\alpha, and CclaimantC_{claimant}. A hash commitment to a bond does not establish these operational facts.

Definition. For a declared collateral portfolio, capital conservation requires:

AjC\sum A_j \leq C

at the accepted checkpoint. The inequality detects over-allocation only inside the supplied portfolio or an accepted external registry. It does not prove that the same asset has no undisclosed pledge elsewhere.

There is no universal collateral-ratio floor. The necessary amount depends on gain, loss, seniority, detection, adjudication, collection, liquidity, volatility, duration, and future rents. Reputation can reduce required collateral only insofar as forfeitable future rents are persistent, attributable, and hard to recreate.

Settlement-adapter sidebar

Bulla compiles structured promises into evidence, authority, capital, and recourse requirements. A settlement adapter supplies rail-specific lock and execution evidence. Bitcoin can strengthen the settlement profile where issuer and revocation risk dominate, but the assurance model does not require Bitcoin.

Bitcoin is one optional collateral and settlement profile. Its replicated consensus rules can reduce issuer, discretionary dilution, and administrative-revocation dependencies for an on-chain UTXO. Bitcoin does not define the promise, establish an off-chain fact, supply adjudication, prevent key theft, prove external unencumbrance, or establish legal collectibility. Stablecoin, bank-escrow, legal-bond, internal-reserve, and Bitcoin adapters expose different assurance tradeoffs rather than forming one universal ranking.

Falsifier. A collateral design fails its stated assurance objective if the named claimant cannot collect the covered amount under the preregistered adverse case, or if undisclosed priority, duplicated allocation, or an unauthorized predicate can trigger transfer.


A.4 — A Bitcoin-Native Secured Capital Curve

“Risk-free” is not an accurate description of Bitcoin-denominated funding. Bitcoin removes some issuer dependencies while leaving custody, key, venue, liquidity, basis, counterparty, legal, operational, and protocol risks.

Definition. A Bitcoin-native secured capital curve is a family of observed rates indexed by tenor and by named institutional conditions:

rBTCsecured(τ;venue,custody,collateral,priority,liquidation,jurisdiction).r_{BTC}^{secured} \left( \tau; \mathrm{venue}, \mathrm{custody}, \mathrm{collateral}, \mathrm{priority}, \mathrm{liquidation}, \mathrm{jurisdiction} \right).

Different conditions produce different curves. A single “Bitcoin risk-free rate” is not assumed.

Four inputs may inform such a curve:

  1. Spot/futures basis. The basis contains funding, balance-sheet, custody, venue, and market expectations. It is not a pure mining yield.
  2. Secured BTC borrowing. Quoted rates contain borrower, collateral, liquidation, counterparty, and legal risk even when overcollateralized.
  3. Collateral-lock opportunity cost. A lock prevents alternative use. The lock creates no coupon by itself.
  4. Mining-capital return. Mining can be an operator-specific capital allocation alternative, but its hardware and operating risks differ from a secured loan.

Illustrative instruments. A time-locked principal claim, a secured coupon claim, or a hash-rate forward could provide observations at different tenors. These are design candidates, not evidence that liquid benchmark instruments already exist.

Derived result. Given traded prices and explicit cash flows, standard bootstrapping can recover discount factors for that instrument set. No non-negativity restriction on forward rates is mathematically required. Negative or inverted forwards may reflect market expectations, collateral convenience yield, segmentation, measurement error, or stress. They should be reported, not automatically optimized away.

Assumption. The observations are sufficiently liquid, comparable, and operationally reachable. Custody and settlement conditions must travel with every rate; otherwise apparent curve consistency may hide incomparable risks.

Conjecture. A transparent Bitcoin-native secured capital curve could become useful where participants value a settlement asset with relatively low issuer and administrative-revocation dependency. It need not displace fiat or other curves to provide that function.

Falsifier. The curve is not a coherent benchmark if comparable instruments remain persistently segmented after their venue, custody, priority, liquidity, and legal differences are modeled.


A.5 — Assurance Pricing Before Agent-CAPM

Collateralized machine services expose discontinuous loss, disputed predicates, incomplete evidence, collection uncertainty, and liquidity stress. Expected loss and tail risk therefore precede covariance beta.

Definition. For service specification ii, a minimum assurance charge can be decomposed as:

FeeiKi+Cirlock,i(τi)τi+E[Si]+Liliquidity+Licustody+Liadjudication+Mi,\mathrm{Fee}_{i} \geq K_i + C_i r_{lock,i}(\tau_i)\tau_i + \mathbb{E}[S_i] + L_i^{liquidity} + L_i^{custody} + L_i^{adjudication} + M_i,

where KiK_i is operating cost, Cirlock,iτiC_i r_{lock,i}\tau_i is collateral opportunity cost, E[Si]\mathbb{E}[S_i] is expected covered loss, the LL terms are separately estimated risk charges, and MiM_i is margin.

For a hazard process λi(t)\lambda_i(t) and conditional severity Si(t)S_i(t):

E[Si]=0τiPr(survival to t)λi(t)E[Si(t)failure at t]dt.\mathbb{E}[S_i] = \int_0^{\tau_i} \Pr(\text{survival to }t)\lambda_i(t)\mathbb{E}[S_i(t)\mid\text{failure at }t]\,dt.

Detection and collection must remain explicit. An observed slash rate is not a loss rate when failures go undetected; an authorized penalty is not recovery when collection fails.

Assumption. The evidence corpus distinguishes exposure, incident, finding, authorized consequence, attempted settlement, collection, and recovery. Without those distinctions, actuarial calibration is not available.

Conjectural heuristic. A covariance term may become useful if a mature market produces stable, comparable cash-flow histories:

E[Ri]rreference,i+βiπmarket+jump-risk and institutional-risk adjustments.\mathbb{E}[R_i] \approx r_{reference,i} + \beta_i\pi_{market} + \text{jump-risk and institutional-risk adjustments}.

This “Agent-CAPM” is a conjectural cross-check, not an established equilibrium model. Beta cannot replace discontinuous slash risk, detection probability, liquidity, custody, correlation, adjudication, or collectibility. A service with low measured beta can still be uninsurable because one rare failure exhausts its collateral or because recovery is unavailable.

Illustration. A pricing exercise may estimate operating cost, locked-capital cost, expected loss, and a tail reserve under multiple scenarios. The result is an illustration until independently observed exposures, losses, recoveries, correlations, and collection rates support calibration.

Falsifier. The beta heuristic should be rejected if its out-of-sample prices do not improve on a simpler expected-loss and tail-risk model, or if its parameters are unstable across semantic, authority, or settlement epochs.


End of Appendix A

The appendix establishes conditional tools rather than one universal chain. A site-specific mining alternative may discipline a subset of operators. A shared benchmark may compress negotiation without being necessary for coordination. Collateral may deter, provide restitution, both, or neither depending on detection, authority, and collection. Bitcoin may strengthen a settlement profile without defining assurance. Pricing begins with exposure, loss, recovery, and tail behavior; covariance heuristics come later, if the evidence supports them.