The zkTLS trust boundary, explorable: switch between Plain TLS, MPC-TLS, Proxy-TLS and TEE-TLS to see where the session key lives and whom you must trust, then hit "forge the value" — plain TLS accepts the lie, the other three catch it at different costs.
Verification overhead (ms, log scale) for five approaches to trustless LLM inference — NabaOS receipts, TOPLOC fingerprints, DiFR seed-commit, output resampling, and full ZK proof. Hover or tap a row for detail.
How long does a web proof take? Drag the crosshair across upload bandwidths to compare TLSNotary's MPC-TLS mode (~30 MB garbled-circuit upload) against the April 2026 Proxy mode — 12.5× faster at residential broadband, 1.8× at fiber.
The x402 HTTP payment exchange: six-step sequence diagram from initial probe through EIP-3009 authorization signing, facilitator settlement, and resource delivery. Tap any step to inspect the exact header format.
A chain commits to a model's 32-byte hash for cents; keeping the gigabytes it points to retrievable is a separate, recurring bill. Pick a model and horizon and watch three rent-charging storage layers race Arweave's pay-once permanence to a crossover — plus the on-chain byte cost and cold-load wall.
An AI proposer is wrong a few percent of the time, but UMA pays a winning disputer only half the bond it risks — so the break-even belief is two-thirds, not half. Every category's base error rate sits deep in the no-dispute zone; raise the reward and the threshold slides left.
Drag the operating point across matrix sizes to see how the Freivalds overhead approaches 0% — and how much of Bitcoin's 150 TWh becomes AI compute under PoUW.
Seven DeFi protocols mapped by upgrade risk tier. Dependency edges reveal inherited risk — even immutable contracts can be exposed through multisig-controlled oracles. Tap a protocol to inspect its timelock window and agent safety note.
What unlearning verification reports as 'forgotten' versus what a recovery attack gets back. Each method's dumbbell runs from its verdict (MIA ≈ random) to what an attack recovers — 0.97–0.99 for cheap methods. Toggle to % recoverable; tap a method. The ZK proof's scope ends at the verdict.
Autonomous LLM firms undercut each other below unit cost in a race to bankruptcy, then survivors monopoly-price. Drag price discovery up to deepen the crash (the paper's counterintuitive result), or add stabilizer firms to rescue the market. Deterministic model of Agent Bazaar's 'The Crash'.
How much does it cost to shift a TWAP oracle? Drag pool TVL, TWAP duration, and price spike factor to see the round-trip manipulation cost alongside the 30-min TWAP shift — for both Uniswap v2 arithmetic and v3 geometric accumulators. Anchored to live on-chain pool data.
When does calling an LLM pay off? Pick a task complexity, model tier, and expected profit per decision: the lognormal token distribution — anchored to the paper's 30× variance finding — shows the fraction of invocations that beat break-even. Drag profit up until the green zone dominates.