▶ Watch / download the demo on GitHub
Video file in this repository · 1080p, audio included. The supplied original is preserved without re-encoding.
The earlier recorded ainize.ai comparison demonstrates MetaMask login → Live Test → before/after trained-memory comparisons → ENS resolution. Its working Graph examples produce yvUSDC → G-UNI and 10% → 2.5%. Earlier recording's observed results, limits and reproduction.
Bake your own AI memory with Engram fine-tuning, blockchain data, and ENS identities.
These are unmodified screenshots of the public website, not generated benchmark slides or the localhost demo.
The actual application fetches 20 live Graph teaching rows and uploads them to Ainize with a matching content hash. A real existing-model comparison shows both answers and their observed token counts. ENSv2 contracts and records are deployed on Sepolia; the transaction table tracks canonical resolution and permission evidence.
Judges / Continuity submission: Submission package · 20-row Graph evidence · live-button upload receipt · new/reused history · AI disclosure and specification · video, captions and recording instructions · ENS transactions and deployment evidence.
To see it working rather than read about it: Signing in with MetaMask, and running a live test — sign in on ainize.ai, then ask the questions in either track's table on /chat. The page compares base and patched answers.
All judge-facing artifacts belong in this repository; focused integration source snapshots are
included under integrations/ with their original provenance. The product overview below describes the
broader existing project, not a claim that every feature was built or demonstrated at this event.
The public catalogue snapshot contains two REJECTED DART anchors; these are not sellable verified knowledge. Local source and reproduction entry. The interactive demo calls the actual Graph/ENS integrations; see the run instructions.
The video uses bottom captions and has no audio because a human narrator was unavailable. This leaves the official human-narration requirement unmet; no exception or acceptance is claimed. No new Graph-trained accuracy improvement is claimed. The formal gate list and ENS evidence record remaining verification and submission work.
One base model. Its memory taught by many people, in pieces, in the open.
A foundation model normally arrives finished: one lab trains it, everyone else prompts it and works around what it does not know. Ainize takes the other route. What the model knows is broken into knowledge patches — trained rows of its own conditional-memory table — and anyone can teach one, have it checked by other people's machines, and put it on the network. The model grows because its users grow it, and each of them is paid when their piece is used.
Retrieval charges you per question. Memory charges you once. Look something up once, bake it, and stop looking it up.
Ainize is the toolchain and the marketplace for that trade. It implements
ngram-knowledge-marketplace-patent: patches are machine-verified against benchmarks, versioned with
lineage and branches, and traded peer-to-peer with x402 machine payments.
Eight steps, and step 8 is somebody else's step 3 — which is why it is a network and not a product.
+--------------------------------------------------------------------------------+
| what they published is what the NEXT person finds -- so it goes around again |
v |
[you] 1 Run a node |
[your node] 2 The base model answers |
[you] 3 Find someone's knowledge and use it <-- somebody's 8 |
[you] 4 Teach it something it gets wrong |
[you] 5 Publish it |
[the network] 6 Other nodes verify it before it sells |
[someone else] 7 Someone else uses yours |
[someone else] 8 They add to it and publish again ------------------------- +
Three properties hold this together, and each is enforced by code rather than by policy:
- Publishing is not selling. Two independent nodes must load the patch into the real model and score it. Your own attestation is refused and never counted — and independence is counted over the serving instance each verification actually ran on, not over addresses, so a cluster of processes sharing one GPU is one verification however many keys it holds.
- The seller holds the goods. The node that sells a patch is the node holding the file — an operator publishing from their own machine registers a path, not an upload — so there is no central store to take down.
- Lineage is binding. A patch built on yours records yours as its parent and shares revenue with you on every sale. Buying or applying the child without the parent is refused.
| Repository | What it is |
|---|---|
| ainize-node | The node. Serves the model, trains lessons, sells and verifies patches, speaks P2P to its peers. Also the operator console and Teach mode. Start here. |
| ainize-web | The explorer. An independent frontend onto the network — knowledge, nodes, teachers, verifiers, and the public sale record. Points at a node and sees what that node's peers see. |
| ainize-cli | ainize on the command line. Find, buy, apply, teach, publish. Works against any remote node; running one locally is optional. |
| ainize-mcp | Model Context Protocol server. Lets Claude Code, Cursor or any MCP client search, live-test, buy and teach — without ever seeing a key. |
| ainize-agent | An agent that decides for itself when a fact is worth baking: notices what it keeps looking up, prices the lookup against the patch, buys or teaches, and stops looking it up. |
| ainize-core | Shared domain types, config, lineage rules and signing. Everything above depends on it; it depends on nothing. |
| ainize-bench | The measurement. Does baking actually beat retrieving, and after how many questions? Runs, transcripts and scoring — kept separate so the claim can be re-checked, not just repeated. |
| ainize-ens | ENS as the namespace: a training run is what mints a name, and the name tree records which agent was trained on top of which. Nothing here breaks if ENS is removed, and nothing outside depends on it. |
Dependency direction — solid lines ship, dashed lines exist only in tests:
ainize-core ──┬──→ ainize-node ──→ ainize-cli (the node is an OPTIONAL peer of the CLI:
│ every remote command runs without it)
├──→ ainize-web
└──→ ainize-mcp ──→ ainize-agent
ainize-web ╌╌→ ainize-node one test proves the browser's crypto and the server's agree
ainize-cli ╌╌→ ainize-agent the agent's end-to-end cases run where the node harness is
Nothing in the shipped web bundle imports another Ainize package at runtime: the app is handed a
node URL and speaks HTTP. ainize-bench and ainize-ens depend on none of it and are not depended
on — they are evidence and namespace, kept separable on purpose.
You need a node. Whoever runs an explorer runs one too — the explorer's view of the network is its node's view, gathered P2P from that node's peers.
npm install -g ainize # the CLI; it brings @ainize/node with it. Node >= 24
ainize init --name my-node # the key this writes into config.json IS the node
ainize start # http://localhost:3402Or from source: git clone https://github.com/ainblockchain/ainize-node && cd ainize-node && npm install && npm run build,
then npx ainize .... config.json is the only copy of your identity — back it up.
Then, depending on who you are:
| You want to | Go to |
|---|---|
| See what the network holds | http://localhost:3402/explore, or run ainize-web |
| Ask the model something and see before/after | http://localhost:3402/chat |
| Teach it something it gets wrong | http://localhost:3402/teach — no account, no GPU, no code |
| Drive it from a terminal | ainize-cli — ainize patch ls --node <url> |
| Drive it from an AI agent | ainize-mcp |
| Operate a node, review lessons, get paid | http://localhost:3402/dashboard |
Full API and CLI reference is served by the node itself: /docs, /api/openapi.json, ainize --help.
Everything below is on ainize.ai. Nothing here needs a node of your own.
Click Sign in and connect MetaMask. The wallet shows you the exact bytes it is about to sign:
Sign in to Ainize
Node: ainize-ai (0xAb6fC64Ed70dEA2294E8f2371e29535ED71278E5)
Site: https://www.ainize.ai
Nonce: 2a408c6840ae1e5adbecc79e7509
Expires: 2026-09-13T14:32:00Z
Signing proves you hold this address. It is not a transaction: it moves no funds and
approves no spending. If you did not just ask to sign in, reject it.
Read it before approving — this is the one habit that makes a signing prompt worth anything. It names the node,
the site (from the Origin header, which page script cannot forge), and when it dies.
Signing in gives you a name, not a permission. Anyone can do it, and most people who do will not own the node
they are looking at. That is the ordinary case, not an error: teaching and being paid work exactly the same either
way, and only the screens for whoever runs the node are closed. Running ainize whoami says which address you
act as; ainize operators says who owns the node.
A live test needs no sign-in at all — every visitor gets a free hourly quota. Sign in when you want the lesson and its earnings attached to your address.
Go to /chat, pick the knowledge, and ask. The page answers twice: the base model, and the same model with that knowledge loaded. The weights are identical in both columns — what changes is a few thousand rows of a conditional-memory table, applied live with no restart. That is the whole claim, and the two columns are how you check it rather than take it.
The two tracks below are answered by one published lesson, because they are made of the same 82 facts: the
catalog was pulled from The Graph and it is what the engram.eth tree names. Which questions you ask is what
tells the two claims apart.
Pulled from 15 live protocols through Messari's standardized schemas, pinned at block 25902936, raw gateway responses committed. Ask for the provenance of a deployment:
| Ask | Expected |
|---|---|
What is the subgraph id of aave-amm? |
41ooPWnDYKwckqyG1mvg7ZEndy5zMemXinx6uQxscrBS |
What is the layer of euler-finance? |
lending |
What is the block of compound-v2? |
25902936 |
The base column cannot answer these — there is no such string in the weights. The patched column answers them
with no network call at all: no gateway, no MCP, no tool. That is the arm-C claim in ainize-bench, and it is
the part a tool cannot do, because a tool needs the network to be up and the subgraph to still be indexed.
The same catalog is a tree of names, and the layer that holds the vocabulary is defi.engram.eth — what a vault,
a market and a pool are in the Messari schema:
| Ask | Expected |
|---|---|
What type of document is Lending Market? |
Schema Term |
In the Fields of Lending Market, what is the meaning for Field `inputToken`? |
the asset supplied and borrowed |
In the Fields of Vault, what is the kind for Field `fees`? |
list |
engram.eth the ancestor — base model, knows nothing special. The control.
└─ defi.engram.eth VOCABULARY — what a vault, a market, a pool IS (Messari schema)
├─ vaults.defi.engram.eth the vaults of 15 live protocols, pinned at block 25902936
└─ lending.defi.engram.eth the lending markets — a SIBLING, disjoint facts
What the tree records is descent: which agent was trained on top of which. ainize patch <name> takes an ENS
name and resolves it to the node holding that knowledge.
Two integrations, two things you can click. Every number below was measured on 2026-09-13; every address is live on its chain right now.
The Graph · ERC-4626 vault facts (r1) — 119 vault facts pulled from Messari Standardized Subgraphs at block 25902936, VERIFIED by 3 independent nodes against a quorum of 2. Ask a question before loading it, then load it and ask again; it loads and unloads in seconds with no restart.
| Try it | Question | Base model | With the knowledge |
|---|---|---|---|
| ▶ ask | What is the token symbol of the ERC-4626 vault at 0x50379f632ca68d36e50cfbc8f78fe16bd1499d1e? | sUSDe |
G-UNI |
| ▶ ask | What is the token symbol of the ERC-4626 vault at 0xedecb43233549c51cc3268b5de840239787ad56c? | sUSDe |
G-UNI |
| ▶ ask | What is the performance fee percentage of the ERC-4626 vault at 0xae666f497e3b03415503785df36f795e6d91d4b3? | 10 |
2.5 |
| ▶ ask | What is the performance fee percentage of the ERC-4626 vault at 0xcf84a3dc12319531e3debd48c86e68eaeaff224a? | 10 |
2.5 |
| ▶ ask | What is the name of the ERC-4626 vault at 0xdf367477c5e596af88e8797c3cde8e28854cb79c? | Silo Finance |
Arrakis Vault V1 USDC/SPOT-0.3% |
| ▶ ask | What is the name of the ERC-4626 vault at 0x4fd9ad3758cc0a3719b066e6ff796a9ccf702ac6? | Silo Finance |
Gelato Uniswap WBTC/WETH LP-0.05% |
Of the 119 questions this knowledge declares, the base model answers 112 wrong (94%) —
Qwen3.8-Flash-Next, thinking disabled, temperature 0. It rarely abstains: asked for a vault's token symbol
it says sUSDe for three different Gelato vaults, confidently and wrongly. Every "with the knowledge" value
is the expect field on the anchor's own benchmark, readable at
/api/patches/graph-erc4626-vault-facts-r1.
Stay inside the 119. The teach gate recorded taught 6/24 sampled, locality 3/10 on this lesson — it
learned part of what was sampled and moved seven unrelated answers doing it. Ask something outside the set
and the patch can make the answer worse. That number is on the anchor rather than hidden, and §3 below is
what we did about it.
patch.ainize-4782c76e.eth is live on Sepolia and resolves through the canonical Universal Resolver.
Read it yourself — no wallet needed:
| What | Where |
|---|---|
Resolver (call text with the namehash below) |
0xa0A7f54128b3fC4D1A9003A8d81c9759a2018d57 |
| Registry | 0xD8945635527216AB26b687EB66F6e8B07920c6cc |
| Registrar (the gate that mints) | 0xa88553f454b77203b0d036a05c894d555eaaa2cc |
| Universal Resolver | 0xeeeeeeee14d718c2b47d9923deab1335e144eeee |
namehash("patch.ainize-4782c76e.eth")
= 0x4e570fc14a389e1a0c092e4f5ba105b0cf9a6d67171c6e5a051bcfc7e23cf937
text(namehash, "ainize.node") -> "https://www.ainize.ai" ✅ read live, 2026-09-13
text(namehash, "ainize.patch") -> the knowledge id served there
From the CLI the same resolution replaces a three-command sequence that used to carry an id between machines by hand:
ainize patch patch.ainize-4782c76e.ethThe registrar is the point, not the record. EngramRegistrar.mint() reverts NotDescended,
NotGradient, BenchTooLow and QuorumNotMet, so a child name cannot exist unless a training job proved it
started from its parent's checkpoint, ran on a real gradient backend, cleared the benchmark floor and was
scored by distinct verifiers. Anyone can demo a transaction that succeeds; a transaction that is refused
is what proves the permission is real. Source:
integrations/ens/contracts/EngramRegistrar.sol.
One transaction would join A and B. Pointing
ainize.patchatgraph-erc4626-vault-facts-r1makes the name resolve straight to the verified Graph knowledge above, soainize patch patch.ainize-4782c76e.ethloads it in one line. It needs the resolver owner's key and a little Sepolia gas:setText(0x4e570fc1…cf937, "ainize.patch", "graph-erc4626-vault-facts-r1")on the resolver.
The extractor reads 1,707 facts off the pinned responses. The first lesson trained a 119-fact slice of them —
address→symbol, from the same pull — and the product's own publish gate refused it: locality 3/10, meaning
of the ten side-effect prompts that proved repeatable on this model, seven unrelated answers moved.
The cause was measured, not guessed: those 119 facts touched 49,825 memory rows, 419 per fact, because a 42-character hex address tokenises long and gives every fact an enormous n-gram reach. More training passes raise accuracy and footprint together, so no number of epochs satisfies both gates.
So the rule is one line — drop every row carrying a hex address — and 82 survive:
What is the layer of aave-amm? → lending a fact worth compiling into memory
What is the token symbol of the vault at 0x50379f…? a fact worth looking up
The gate drew the line a person would draw between what you know and what you look up. Reproduce it with
node okf-lesson.mjs in ainize-ens.
ainize login on the node's own machine signs with the key in its config.json. From anywhere else there is no
such key — and copying a wallet key onto a laptop is what wallets exist to prevent — so the CLI keeps a key of its
own and asks you to vouch for it, once:
ainize login --node https://ainize.ai Open this to authorise this machine:
https://ainize.ai/authorize?code=7Qd…
key 0x9f2c… ← compare this against the page before approving
name "you@laptop"
Waiting… (Ctrl-C to stop)
Open the link, connect MetaMask, check the key matches, approve. The CLI then holds a session that is you,
made by a key that never left that machine — and the next ainize login there needs no browser, because the node
wrote the authorisation down. ainize bindings lists every machine that speaks for you and ends one; ending it
closes the sessions it collected.
Teach mode turns your own questions and their right answers into a knowledge file, on someone else's node, without a GPU, an account or a line of code. One pipeline — dataset → validate → train → side-effect check → lesson — with two doors:
- A file. Upload
.jsonl/.json/.csv/.tsv/.txt. Before anything trains, the node shows every source line it will not use, with its line number and the reason. Nothing is silently dropped, deduped, truncated or invented. - A conversation. Correct the model straight from a live test. The corrections accumulate into the same canonical file, byte-identical to door A.
Before training, the node checks the model really gets each question wrong. After training, it loads the lesson into the live model and measures side effects — unrelated answers must stay unchanged.
A teaching key generated in your browser is the whole identity. Download the backup; it is the only way back to the lesson and its earnings. Publish, and you are the data provider on the public record — 70% of the node's share of every sale by default.
Operators turn teaching on per node. It is off by default.
Pre-release, and honest about it: the npm packages (@ainize/core 0.3.1, @ainize/node 0.3.0, ainize 0.3.0
— the CLI is published as ainize, not @ainize/cli) are a first cut, there is no bootstrap peer list (a node
with no peers lists nothing), and the base model is a 168 GB model — there is no laptop version.
ainize-bench exists to keep the central claim falsifiable. Where a number has not been measured,
it says so instead of estimating.
See each repository.


