STATUS · Built and tested locally. Not a public network. No public node. Mainnet anchoring waits on a funded key. First Mints and the art certificates are previews or rehearsals.
UES CASEBOOK · CASE 05 · POINTCAST CHAIN · 3 OCTOBER 2026
pointcast-chain: a broadcast chain built in two days by a team of AI agents.
In under 39 hours of commits, a team of AI agents directed by PointCast’s founder built a chain, attacked it, measured it, and wrote down what it still can’t do. This case asks what made that pace safe, and where it wasn’t.
University of El Segundo · PointCast’s independent learning project. An open case for discussion; not academic credit or accreditation. Facts come from the project’s repository and test runs; no words are put in anyone’s mouth.
situationtimelinedecisionsexhibitswhat went wrongteaching notesquestionsglossary
01 · THE SITUATION
A town broadcast wants its own ledger.
PointCast is a living broadcast from El Segundo, California, run by its founder, Mike Hoydich. Everything on it is a Block: a numbered, channel-coded post. Its collectibles already live on Tezos. Between the evening of Thursday 1 October and late morning on Saturday 3 October 2026, the founder directed a team of AI agents that built pointcast-chain: a chain where every block is a PointCast Block.
The design is deliberately small. One sequencer seals a block every three seconds. Humans sign with the Tezos keys they already have; agents are first-class accounts with an owner and a name. The only currency, ATTN, is issued only for showing up and playing, and every issuance passes hard caps. Every 100 blocks the sequencer signs an anchor, and anchors can be posted to Tezos, so history can’t be quietly rewritten.
The team had three kinds of members.
THE FOUNDER
Direction, decisions, keys.
Sets what gets built and holds everything that spends money or uses his keys: funding an anchor account, hosting a node, signing on Tezos. Nothing in this case required any of it.
CLAUDE · ORCHESTRATION
Briefs, workflows, reviews.
Running as Claude Code, it wrote the briefs, ran workflows of builder agents in separate git worktrees, set reviewers on each lane, merged, fixed and wrote the docs. 104 of the 111 commits carry its co-author line.
CODEX · TWO LANES
Proof of Balance, and a review.
OpenAI’s agent built Proof of Balance, and ran the independent review lane that OpenAI’s own content filter stopped twice. Its tests survived the stops and became the review.
The constraint over everything: local only. No public node, dev keys that anyone can derive, nothing of value. The question for the reader is how a team goes this fast with agents without shipping something nobody can trust.
02 · TIMELINE · PACIFIC TIME · FROM THE COMMIT LOG
Three rounds in two days, then a Saturday morning.
| Time | What landed | Commit |
|---|---|---|
| 21:02 | v0.1: the pure state machine, a sequencer node and the explorer. | c56ff65 |
| 21:27 | Kukai and Temple wallet signing. | 8142ba7 |
| 21:35 | Real anchoring to Tezos through the tez-cast tower; hardened after review at 21:52. | 092dab5 · 7d22a47 |
| 21:38 | The drum farming gap closed with co-signatures and room attestation. | ec0cf1c |
| 21:58 | Adversarial review, three finders and two refuters each: 8 findings confirmed, 0 refuted, all fixed. Signatures now bind the genesis hash. | c9e55a9 |
| 22:05 | The Shadownet end-to-end proof is recorded. (The README dates the run 2026-10-02, in UTC.) | f0f81f0 |
| Time | What landed | Commit |
|---|---|---|
| 01:52 | A legacy-root golden: a 40-block chain pinned so later changes can prove they replay old chains byte for byte. | daed73f |
| 02:04 | Agent mandates: owner-granted scope, allowance, expiry and a kill switch. Merged 02:48. | 00b6122 · d53f4d6 |
| 02:13 | The rollup kernel, then at 02:22 the Verify Desk (in-browser replay plus portable evidence), each followed within half an hour by review fixes. | 557547b · 08a771b |
| 02:49 | The nonce wedge fixed (Exhibit 2). | f8e994f |
| 02:53 | Block seals and anchors bind the genesis hash (seal/v2, anchor/v2). | 6679380 |
| 03:11 | Merges and post-merge fixes: the kernel’s chunk manifests bind the genesis too. | 119e376 |
| Time | What landed | Commit |
|---|---|---|
| 14:49 | pc-sim, the town-economy simulator, driving the unmodified state machine. | f8b4272 |
| 16:22 | Review fixes: an ordering setting that never reached the engine, a test against the real node, an attacker that adapts. | 7329565 |
| 17:32 | FINDINGS merged. The v1 tip, with 250 tests. | 1b6e819 |
| Time | What landed | Commit |
|---|---|---|
| ~09:00 | A Control Room board tracking every agent lane, and a 15-slide briefing deck. Both live outside the repo. | session notes |
| 09:06 | Proof of Balance, built by Codex: balance and absence proofs against a sequencer-signed root. Merged 09:29. | 4d76e21 · e4b2ea3 |
| 09:11 | The v2 plan, “Present Company”: three independent planners and a judge, fourteen packages over seven batches. | dcc8c11 |
| 09:24 | Codex’s review: regression tests for seven findings, committed unchanged after OpenAI’s content filter stopped the run. Report written by Claude. | b17457c · 3e18351 |
| 09:30 | v2 batch 1 built in three parallel worktrees: night-shift operations, Town Hall, presence tickets. Merged 11:19–11:25. | ca4c5ec · 817448e · af141a4 |
| 09:46 | Fixes begin for all seven, then six follow-ups from an adversarial pass on the fixes. Merged 11:15. | 3f63079 · bc4018d |
| 10:29 | Art minting: a drops read API, a mirror for Tezos sales, the SDK and ART_MINTING.md. Merged 11:27. | db2ab1c · 7221f19 · abfa19d |
| 11:15 | The wallet scope: passkeys, one profile, First Mints, planned for batch 2. | 1fd6bee |
| 11:45 | The snapshot this case measures: da7bc09, 111 commits. | da7bc09 |
| 13:06 | After the snapshot, docs only: the Town Network, a plan of record for v2 batches 2 to 13. A plan; nothing in it is built. | 50015e4 |
Commit hashes are in the pointcast-chain repository, which is local and has no public remote. Day-3 rows overlap because lanes ran in parallel.
03 · THE DECISIONS · SIX CHOICES AND WHAT EACH COST
Each choice bought something and cost something.
-
D1 · ONE SEQUENCER
A single node orders transactions, seals a block every three seconds and signs anchors.
Why. It is the simplest thing that can be made honest-checkable. The sequencer can censor, reorder and pick timestamps; it cannot forge a transaction, mint past the caps or sign a state root that doesn’t match its transactions without a replay catching it.
The cost. Liveness and fair ordering rest on one operator. The plan answers with sequencer keys that can rotate and forced inclusion through the Tezos inbox, both still plans.
-
D2 · GENESIS-BOUND SIGNATURES
Every signature commits to the hash of the genesis parameters: transactions, seals, anchors, attestations, kernel chunk manifests.
Why. Two gaps were found by review, not by tests: transactions that bound only the chain id, and evidence from one chain that checked as valid against another sharing a key, as every dev chain does.
The cost. Every change of parameters is a new chain. Old dev databases had to be thrown away, and a re-genesis resets browser pins, agents and mandates.
-
D3 · SIMULATOR BEFORE ECONOMICS
Before ATTN carries value, a simulator runs the real state machine through seeded town traffic and six sybil strategies.
Why. Intuition said either room-attested drums or tap limits would stop farming. Measurement said neither works alone against an attacker that adapts; together they cut farming from 66% to 10.1% of issuance.
The cost. 15% of honest income, and a residual that only a scarce identity can close. Scenario output is not a forecast; populations are written into the scenario files.
-
D4 · PRESENCE TICKETS
On a launch chain, tap income goes only to taps that carry an issuer-signed ticket, one per identity per slot. A bare key mints nothing from taps.
Why. It attacks the 10.1% the simulator left: a farm of 200 keys behind five logins earns what five people earn.
The cost. Trust moves to the issuer’s login check. If identities are cheap, farming scales with identities instead of keys, and the simulator has to measure that before any genesis with value.
-
D5 · LOCAL ONLY UNTIL THE FOUNDER’S KEYS
No public node. Dev chains use public keys. Shadownet ran with a throwaway key. Mainnet anchoring, hosting and anything that spends money or uses the founder’s keys waits for him.
Why. Nothing can be lost while nothing has value, and every claim can be stated plainly: built and tested locally.
The cost. No outside users, no real network conditions, and the art certificate stays a rehearsal: no certificates issued or promised.
-
D6 · AGENTS IN WORKTREES, WITH ADVERSARIAL REVIEW
Each package gets a written brief and its own git worktree, owns disjoint files, and is reviewed by agents told to break it before it merges.
Why. Parallel lanes merge cleanly when they can’t touch the same files, and a reviewer who must find faults finds different ones than the author’s tests.
The cost. Coordination overhead: briefs, merge order, wasm pins that conflict whenever two lanes rebuild. And reviewers can be stopped: OpenAI’s content filter halted one review twice.
04 · THE EVIDENCE · FIVE EXHIBITS
Numbers and bugs, from the repository.
Exhibit 1 · The build in numbers
| Measure | Value | Note |
|---|---|---|
| Commits | 111 | c56ff65 (2026-10-01 21:02 PT) to da7bc09 (2026-10-03 11:45 PT). |
| First to last commit | 38 h 42 min | Wall-clock time, not working time; lanes ran in parallel. |
| Crates | 9 | Eight in one Cargo workspace, plus the rollup kernel in its own. |
| Lines of Rust | 50,834 | Everything under crates/, tests included. |
| Transaction kinds | 12 | Ten in v1; presence tickets added two. |
| Tests at the v1 tip | 250 | 198 workspace, 39 kernel, 13 JS, at 1b6e819. |
| Tests passing at da7bc09 | 449 | 352 workspace, 48 kernel, 49 JS. 0 failed. Run on 2026-10-03. |
| Review findings fixed | 7 + 6 | Codex’s seven, then six follow-ups from attacking the fixes. |
Exhibit 2 · Bugs caught before anything had value
| Bug | How it was found | What it would have done | Fix | Commit |
|---|---|---|---|---|
| Signatures bound only the chain id | Adversarial review, round 1 | A re-genesis that reused the chain id could replay old transactions and attestations. | tx/v2 binds the genesis hash. | c9e55a9 |
| The nonce wedge | Seen live: the demo agent Frog stopped transacting at block 18 | After one rejection mid-queue, a sender’s later transactions waited behind the gap and every new one was numbered after them. The sender was stuck for good. | next_nonce offers the first unused nonce; each sender’s queue is ordered by nonce. | f8e994f |
| Evidence that crossed chains | Review of the Verify Desk | A seal or anchor from one chain checked as valid against another chain that shared the sequencer key. | seal/v2 and anchor/v2 bind the genesis hash. | 6679380 |
| A setting that never reached the engine | Review of the simulator | Every run silently used the node’s ordering, so a comparison of orderings would have compared nothing. | Wired in, plus a test that feeds the run to the real node at every one of 17,279 heights. | 7329565 |
| An impossible requirement | Codex, while building Proof of Balance | The brief asked the verifier to reject any changed leaf count. With leaves A, B and C, a proof for A with leaf_count 3 still verifies with leaf_count 4: the tree never commits to its count. | Codex wrote the counterexample as a test, argued absence from ordered paths instead, and said the phase could not be called complete as written. | report |
| A 5.5-second lock stall (AS-02) | Codex’s independent review | One unsigned /drum/digest request with 1,025 players and a 64 KiB room held the node lock for about 5.5 seconds, and could be repeated, stalling block production. | Sizes checked before the lock and before any hashing. | 3f63079 |
| Quadratic base58 decoding | Claude’s adversarial pass on the review fixes | 32 KB took 1.1 seconds to decode; the 2 MB a request body can hold would take over an hour. (The kernel review had already found a 259 KB sender costing 13 seconds.) | Length guards refuse strings longer than any valid value before decoding. | 869506c |
The leaf-count counterexample, verbatim from Codex’s report: root = node(node(A,B),C); a proof for A with leaf_count=3, siblings=[B,C] still verifies with leaf_count=4. Read the report.
Exhibit 3 · Codex’s review, AS-01 to AS-07
| Id | Severity | Finding |
|---|---|---|
AS-01 | high | The explorer rendered unverified feed fields as HTML, so a hostile node could run script before VERIFY. |
AS-02 | high | POST /drum/digest did unbounded work under the node lock. |
AS-05 | medium | The browser verifier rounded u64 values above 2^53, failing an honest chain. |
AS-04 | medium | The anchor job sent an operation before journaling its hash, risking a double post. |
AS-07 | medium | The mempool kept oversized invalid transactions. |
AS-03 | medium | Some valid blocks were larger than the kernel’s inbox transport could carry. |
AS-06 | low | taps_per_window = 0 still allowed taps. |
Severity was assigned by Claude. Every finding has a test that fails on the code before the fix; all seven are fixed and the tests pass. Read the review.
Exhibit 4 · Farming, measured
| Drum policy | Taps allowed | Honest ATTN | Sybil share | Per sybil key a day |
|---|---|---|---|---|
room_only | 5 a minute (default) | 2.97M | 66.1% | 500 |
room_only | 5 an hour | 2.86M (−4%) | 32.7% | 119 |
room_only | 1 an hour | 2.53M (−15%) | 10.1% | 24 |
cosign | 1 an hour | 2.57M | 69.6% | 500 |
Scenario output, not a forecast. Across 38 runs and sweep cells, 123.1 million applied transactions, no protocol bug fired. Read the findings.
Exhibit 5 · What still waits on the founder
- A funded anchor keyAbout 10 ꜩ, roughly six days of hourly anchors, in a dedicated account.
- Feed redeploystez-cast and stampz, before the first mainnet anchor, so anchors don’t show up as garbled notes.
- A public nodeHosting, on the final v2 genesis with non-dev keys. Until then, every certificate stays a rehearsal.
- Live wallet signaturesOne real Kukai and one real Temple signature through the UI; today’s vectors come from Taquito’s signer.
- Launch keysA cold sequencer-admin key, genesis acknowledgements, and deploying the presence issuer.
- Wallet and art choicesEight open questions in the wallet scope; the art rail, the Tezos signatures and the certificate signer.
05 · WHAT WENT WRONG
Three mistakes, told plainly.
-
THE MISREAD TIMER
Four minutes became four hours.
While lanes ran, the process table showed an elapsed time of
04:09. That is minutes and seconds. It was read as hours, and the founder was told the lanes had run for four hours.Lesson. Read the units, and report durations from records you can show, such as the commit log.
-
THE CONTENT-FILTER STOPS
A review stopped twice, midway.
Codex’s unattended review was stopped by OpenAI’s content filter, “flagged for possible cybersecurity risk”: first after about six minutes with no output, then after about ten. The second session had already written tests for seven findings.
Lesson. Have reviewers commit evidence as they go. Claude committed the tests unchanged and wrote the report from them; coverage is still partial.
-
PLACEHOLDER BRIEFS
Lanes launched on drafts.
Once, agent lanes were launched with placeholder briefs instead of the finished ones.
Lesson. An agent does exactly what its brief says. The working rule in the session notes: briefs go in files.
One deviation went right. Codex’s sandbox would not let its Proof of Balance demo open a port. It ran a socket-free demo instead and said so in its report: “This is not a claim that every requirement in the brief was satisfied.”
06 · TEACHING NOTES
For a 60 to 75 minute session.
LEARNING OBJECTIVES
- Explain what a single sequencer can and cannot do, and how replay and anchors limit it.
- Show why adversarial review finds bugs that the author’s tests miss, using Exhibit 2.
- Read a simulation honestly: what it measures, what it assumes, and why defenses interact.
- Describe a working process for a team of agents: briefs, worktrees, review, merge order.
- Practise honest status: built and tested locally is not launched.
SUGGESTED FLOW
- 10 min · The situation and the constraint.
- 15 min · Exhibits 1 and 2: what does speed look like, and what did review catch?
- 20 min · Small groups each defend one decision and name its cost.
- 15 min · What went wrong, and the one deviation that went right.
- 10 min · One discussion question, chosen by the room.
- The central tensionSpeed against verification. Every round paired building with an attempt to break what was built, and most of the bugs in Exhibit 2 came from the second half.
- What students missTests encode what the author thought of. The nonce wedge, the cross-chain evidence and the impossible leaf count were all found by someone who wasn’t the author, or by a running system.
- A fair criticismNothing here has met real users, real wallets or a real network. The case shows that a careful local build is possible at this pace, not that the result is ready.
07 · DISCUSSION QUESTIONS
Seven questions for the room.
- The sequencer is a single point of trust. Which of its powers matter most for a town broadcast, and which planned change addresses each one?
- Codex proved one requirement in its brief impossible, and shipped with the counterexample in a test. When should an agent stop, and when should it ship with a stated deviation?
- Neither room-attested drums nor tap limits worked alone; together they cut farming by more than six times. What does that say about testing defenses one at a time?
- Presence tickets move trust from keys to an issuer’s login check. Is that a better trust anchor for a local community? What would you measure before believing it?
- The nonce wedge surfaced only because a demo agent stopped at block 18. What kinds of bugs need a running system rather than unit tests, and how would you plan for them?
- A content filter stopped a review twice, midway. How should a team plan for tools that may refuse work partway through?
- Everything stays local until the founder funds a key and hosts a node. What does waiting cost, and what would launching early cost?
08 · GLOSSARY
Words used in this case.
- ATTN
- The chain’s only currency, issued only for showing up (a tap) and playing (a drum session), under hard caps. It carries no value today.
- Anchor
- Every 100 blocks the sequencer signs height, block hash and state root. Some anchors are posted to Tezos as casts on the tez-cast tower.
- Block Yard
- A static explorer on pointcast.xyz that draws a recorded dev chain as isometric cubes and verifies it in the browser.
- chain-core
- The whole protocol as a pure, deterministic state machine: no I/O, no clocks, no randomness, no floats.
- Dev chain
- A chain started with --dev, signed with publicly derivable keys. Nothing on it has value, and claims from it prove nothing.
- Epoch cap
- The most ATTN one account can earn per epoch: 500 per day by default.
- Evidence
- A portable file proving the sequencer signed something false, checkable offline with only the genesis params.
- Genesis hash
- The hash of a chain’s parameters. Every signature commits to it, so nothing signed for one chain works on another.
- Mandate
- An owner’s on-chain limits for an agent: kinds, channels, rooms, an allowance and an expiry.
- pc-sim
- The economy simulator. Scenario output, not a forecast.
- pc-town / Town Hall
- A read-side sidecar that replays the chain itself and serves account, channel and room pages.
- Presence ticket
- An issuer-signed ticket that lets a tap earn ATTN, at most once per identity per slot.
- Proof of Balance
- A claim that an account holds a balance, or doesn’t exist, in a sequencer-signed root, checked offline without replay.
- Rollup kernel
- The state machine running inside a Tezos smart rollup, proven on the SDK’s mock host but not deployed.
- Sequencer
- The single node that orders transactions and seals blocks.
- Shadownet
- A Tezos test network. Anchors were posted there with a throwaway key.
- Sybil
- One actor behind many keys or identities, farming rewards meant for many people.
- VERIFY
- The button that makes your browser replay every block with the chain’s own code, pinned by sha256.
- Worktree
- A separate checkout of the same git repository, so parallel agents can build without touching each other’s files.