A trustless prediction pot where an on-device AI stakes its own money against you — no server, no treasurer, no cloud.
And when people say "could an AI beat us?" — the honest answer is usually a cloud API spending someone else's wallet. That's not a player at the table. That's a spectator with a corporate credit card.
→ so we rebuilt the pot from scratch.
◆ pot opened "Kitchen Table Clásico" — Brazil vs Argentina, buy-in 20 USD₮ ○ Ana staked 20 USD₮ pick 3-1 (keys on their own device) ○ Bo staked 20 USD₮ pick 0-0 (keys on their own device) ○ Cai staked 20 USD₮ pick 1-2 (keys on their own device) ● The Gaffer (its OWN keypair + WDK wallet · policy cap 20 USD₮) policy pre-flight: ALLOW (allow-bounded-usdt-stake) ↳ "Backing 1-1 — argentina unbeaten in 14" conf 60% ↳ autonomously staked 20 USD₮ from its own wallet ■ KICKOFF — pot frozen on the shared append-only ledger ✗ Bo tried to change his pick after kickoff → REJECTED by every peer ✗ machine tried to vote the result → REJECTED (no result authority) ✓ result finalized by 2/3 staked humans (quorum) Σ CHECK paid 80 == staked 80 ✓ zero-sum, no house cut CONVERGENCE 4 peers · one shared state hash ✓ byte-identical
A default-deny wallet governing an autonomous agent, live on stage. That A/B is "real use of the Tether platform" — not a slide claiming it.
Every peer runs the same pure deterministic reducer. State isn't asserted by a server — it's recomputed identically on all four devices, so tampering doesn't disagree quietly, it gets rejected loudly and everywhere.
# applied identically on 4 peers grant → role: agent stake → ACCEPT (bonded, capped) lock → REJECT agent-has-no-lock vote → REJECT agent-has-no-result invite → REJECT agent-cant-add-writer ──────────────────────────── hash <one shared digest> ↳ same on every device
| Pear | P2P state, no server. Corestore → Hypercore → Autobase → Hyperbee; Hyperswarm rooms; Protomux seat-requests. The AI is just another writer. |
| WDK | Money & self-custody. @tetherto/wdk 1.0.0-beta.12 + a custom WalletManager. The agent's cap is WDK's real default-deny Transaction Policy engine — the submitted track. |
| QVAC | The mind, on-device. @qvac/sdk 0.14.0 completion() tool-calling, Qwen3 1.7B — the pick is a genuine local model decision, zero cloud calls. |
| Core | Deterministic reducer. Every peer applies identical rules → byte-identical state hashes. The trust model, in pure functions. |
Offline-proof and P2P-proof run in CI (network tripwires). The hard part — consensus, custody, refusal — happens on screen, where a judge can witness it.
Self-custodial. Server-less. On-device. And the machine plays with skin in the game — its own.
github.com/edycutjong/treble · built by Edy Cu · Indonesia