Proposal “c2pool-daemonless-finalize“ (Active)Back

Title:Finish c2pool's daemon-less Dash node
Owner:frstrtr
Monthly amount: 126 DASH (6672 USD)
Completed payments: no payments occurred yet (2 month remaining)
Payment start/end: 2026-09-05 / 2026-11-04 (added on 2026-08-19)
Final voting deadline: in 9 days
Votes: 278 Yes / 129 No / 9 Abstain
Will be funded: No. This proposal needs additional 170 Yes votes to become funded.
Manually vote on this proposal (DashCore - Tools - Debugconsole):
gobject vote-many fa758340f1bd2391d17bb43667f76c5d9070d737b68e018e42ed75b09c6ba631 funding yes

Please login or create a new DashCentral account for comfortable one button voting!

Proposal description

c2pool is a mining pool for Dash with no operator. It pays miners from the coinbase of the blocks they find, the way p2pool does, so nobody holds anyone else's coins.

   c2pool is a new node, written from scratch in C++. It is not the old Python p2pool with a daemon-less patch. The Python p2pool proved the coinbase-payout model works on Dash. c2pool re-implements that model, and the whole Dash consensus, as one C++ program that needs no separate daemon. The Python line is a separate, older codebase; the code this funds is the C++ one at github.com/frstrtr/c2pool.

Why this matters to masternodes (MNO) and evonodes (EVO)

   Your collateral is worth what the chain's security is worth, and that security rests on mining staying spread out. When mining collects into a few custodial pools, pools that can be leaned on or taken down, the whole network is exposed, and every masternode carries that risk. An operator-less pool that anyone can run, with no daemon and no custody, keeps mining in many hands. That is a direct defense of what you have staked.

The Inherent Weakness of Custodial Pools

   The current distribution of hashing power is heavily concentrated among a small number of pools. This reliance on custodial operators introduces a single point of failure, requiring trust in a third party. The network stall of May 2023, during which major entities such as Binance Pool suspended payout operations, demonstrates the inherent weakness of this model. When proof-of-work is delegated to a central entity, the network assumes the risks of centralized infrastructure, the potential for custodial funds to be withheld, and the ability of a single operator to exclude transactions from the block. By allowing individual nodes to construct their own block templates and distributing rewards directly via the coinbase transaction, c2pool removes the need for a trusted operator entirely.

   It also keeps the reward steady. More independent miners means blocks keep coming from many sources instead of one, so the payments masternodes and evonodes live on do not ride on any single operator staying online. And the node works out the masternode list, the quorums, and the ChainLocks for itself, so it stands on the same security you already provide instead of leaning on it.

   Dash had a p2pool once.
   
   It was left behind around dashd 0.18 and no longer works with the network. (https://docs.dash.org/en/stable/docs/user/mining/p2pool.html) I brought it back. (https://github.com/dashpay/p2pool-dash/issues/82) It runs on current Dash and has been finding blocks since height 2387690, on 2025-12-13. It puts the old P2Pool-Dash marker in the coinbase, so block explorers already list these blocks with no change on their end.

   The pool runs at dash.voidbind.com. Its blocks carry a coinbase marker, so explorers attribute them: mnowatch.org/blocks/?search=c2pool lists the blocks it has found on Dash mainnet, and chainz.cryptoid.info/dash/extraction.dws?30.htm shows the coinbase extraction.

   A pool like this still runs a full Dash Core to build its templates, hold its mempool, and send out the blocks it finds. That is the last part I depend on, and I have been taking it out. c2pool now works out the masternode list, the quorums, the ChainLocks, the credit pool and the DIP-4 coinbase from the Dash P2P network by itself, and builds a template equal to the one Dash Core would build, with no dashd running.

   It holds its own mempool the same way. It takes transactions off the network, checks them and prices them against its own UTXO set, with nothing to ask. The result is the same mempool Dash Core has.

   It sends its own blocks as well. When it finds one it puts it on the Dash P2P network and passes it to other c2pool nodes over their own link. dashd is left in as a fallback only. The engine is C++ and is paid for by an Anthropic open-source grant. That grant covers the engine. I am asking the treasury only for the Dash-specific part that is left, so the outside money is already spent on the rest.

   Update on Network Documentation.

   The reference client maintainers have formally deprecated the legacy p2pool-dash repository. The official documentation (docs.dash.org) has been updated to remove the obsolete setup instructions, noting the previous software is unmaintained. In its place, the documentation now lists this project—the c2pool C++ reimplementation and frstrtr/p2pool-dash—as the surviving community forks for decentralized mining. As the core developers explicitly step back from maintaining third-party mining software, the survival of a trustless, operator-less pool on this network now relies entirely on finalizing this independent infrastructure.

Done so far, with no Dash funding:

  •   A full C++ reimplementation from scratch, not a fork of the Python p2pool.
  •   Masternode list and quorums taken from P2P, not RPC.
  •   PoSe bans and revivals, rotated quorums, ChainLock checks.
  •   Credit pool followed and the DIP-4 coinbase built. These blocks are accepted on mainnet.
  •   Mempool held and priced by the node, equal to Dash Core's.
  •   Blocks sent over P2P and to other c2pool nodes, dashd only as a fallback.
  •   The node checks its own template and will not mine rather than pay a wrong coinbase.
  •   Official documentation corrected. Dash Core has deprecated the legacy 0.18 pool repository and updated docs.dash.org to point to the active c2pool and frstrtr/p2pool-dash community forks.

Left to do, which this pays for:


  •   Put the mempool's fee-paying transactions in the template at the same fees Dash Core would take.
  •   Make a cold start as fast as a Dash Core resync.
  •   Take the last of dashd out of the running nodes.
  •   Fix the docs. dash.org and the p2pool link in Dash's own GitHub still point at the dead 0.18 pool. They should point at this one.
  •   Harden it and put out signed builds, so anyone can run a Dash pool with no daemon.

I ask for 125.5 DASH per superblock, twice. 251 DASH in total.

   Pay to XdgF55wEHBRWwbuBniNYH4GvvaoYMgL84u, the pool's own address. Every block the pool finds puts a small output there already, so the work and the funding sit on one address you can check.


Show full description ...

Discussion: Should we fund this proposal?

Submit comment
 
3 points,10 days ago
Update: 19 Days Left

Full Sovereignity, Not Just Decentralization

Thank you to the 400+ MNOs who have evaluated and voted so far. We are currently at 269 Yes votes and need about 175 more to secure funding before the October deadline.

In previous updates, I detailed the heavy technical milestones proving this C++ daemonless architecture works on mainnet. But the value of this proposal goes far beyond just "decentralization" or running without dashd. It is about giving operators true control over block production.

Currently, large custodial pools not only hold the hashrate and the payouts—they hold the power over what gets into a block. If a massive pool operator decides not to relay or include certain transactions, the network is effectively censored.c2pool changes the builder.

Because each miner’s own node builds and validates the block, the power of block construction is returned to the miner.

What this unlocks for the network today:
Custom Fee Control: A miner who runs their own c2pool node instance controls the pool’s fee. They can aggregate sharechain hashrate from others, set their own fee structures, and redirect those fees to their own mining or dedicated fee addresses.

Censorship Resistance & Transaction Power: Because you are building the template, you decide what goes in. As demonstrated recently (Block 2518186), a c2pool miner can explicitly consent to include transactions the rest of the network refuses to relay—such as sweeping dust inputs at a zero fee.

The first half of this work is already done and live. The final funding requested here (125.5 DASH) pays to finalize the remaining optimizations (cold start, full dashd decoupling) and release the polished, signed c2pool-qt builds. We are making it easier than ever for an individual operator to run their own pool node, define their own rules, and control exactly which TXs are included in their blocks. This is how we eliminate the single points of failure that threaten MNO collateral.

If you haven't voted yet, please consider supporting the finalization of this trustless infrastructure.

To vote yes:

gobject vote-many fa758340f1bd2391d17bb43667f76c5d9070d737b68e018e42ed75b09c6ba631 funding yes
Reply
3 points,21 days ago
Client diversity and long-term network resilience

The early history of our network provided an important architectural lesson. Upon the network's launch as XCoin on January 18, 2014, a flaw in the inherited difficulty adjustment algorithm resulted in the emission of approximately 1.9 million coins within the first 48 hours. This initial distribution anomaly was the natural consequence of relying on a single codebase: when an entire proof-of-work network derives consensus from one monolithic client, any edge-case in that software becomes the irreversible reality of the chain.

The Dash Core team has done extraordinary work in the years since, hardening this protocol into one of the most reliable networks in production. However, an inspection of the current client ecosystem shows that Dash Core remains the only full consensus validation engine available; all other desktop wallets are light or SPV clients that ultimately rely on core backends. Placing the entire burden of block templates, quorum derivation, and ChainLocks on a single binary maintains an unavoidable single point of failure.

The incentive structure of proof-of-work dictates that those who hold the greatest stake—especially operators whose collateral dates back to those earliest block emissions—act to preserve that accumulated value. In mature distributed networks, that preservation is achieved through client diversity.

The c2pool daemonless implementation is designed to actively complement Dash Core by introducing this necessary redundancy. It serves as a secondary, clean-room implementation of Dash consensus in C++:

* Consensus state, quorums, and ChainLocks are derived autonomously from the P2P wire without RPC dependency.
* DIP-4 coinbases and payee assignments are verified internally from first principles before work is dispatched.
* Block production is decoupled from the reference daemon, providing an independent fail-safe against unexpected software anomalies.

A network is at its strongest when independent implementations validate one another. Finalizing this codebase provides the client diversity needed to safeguard the network's legacy, protect masternode collateral, and relieve systemic reliance on a single software binary.
Reply
1 point,21 days ago
The Math Behind the Anomaly

Under normal operations, the Dash network is programmed to target a block generation time of 2.5 minutes.

To put that into perspective:

* Normal Production: In a standard 24-hour period, the network should produce roughly 576 blocks.

* Actual Production: Between January 19 and January 20, 2014, the network cleared 4,500 blocks (and ultimately hit roughly 5,750 blocks in the first 48 hours).

* Each block produced 500 dash coinbase mining reward TX
Reply
2 points,22 days ago
Technical Clarification: Miner Safety and Consensus Verification

In recent correspondence, an operator raised a valid concern regarding consensus-adjacent software. If an implementation generates an invalid block template, the penalty is orphaned work and lost expenditure for the miner.

It must be clarified that a responsible implementation does not distribute unverified templates and leave miners exposed to this risk. The design of c2pool enforces strict local pre-validation. The node independently verifies the masternode payee, the DIP-4 coinbase, and the quorum signatures against its derived state before issuing work. The node evaluates its own template; it will refuse to mine rather than instruct hardware to produce an invalid coinbase. Any discrepancy is caught internally, and invalid work is discarded before it is hashed.

Furthermore, correctness in this consensus logic is not based on heuristic assumptions. The state transitions and settlement rules are proven mathematically. The logic is formally specified and model-checked using TLA+, and the derivations are rigorously verified against Known Answer Tests (KAT).

The purpose of the proposed one-month soak period is to empirically demonstrate what these formal proofs already establish. This period includes the live generation of the upcoming superblock, which will prove the standalone derivation matches the reference client byte for byte on the live network without relying on a local daemon.

The operator's conclusion is correct. Consensus-adjacent infrastructure requires rigorous, observable testing. The requested funding finalizes the codebase so that this empirical validation can be completed on mainnet before broader deployment is considered.
Reply
2 points,22 days ago
Thanks to the core team for mentioning my work (https://docs.dash.org/en/stable/docs/user/mining/p2pool.html) and updating the Dash Docs, including the modern community fork of p2pool and the c2pool reimplementation!

These forks are not maintained, reviewed, or endorsed by the Dash project, and this documentation does not describe how to install or operate them. Refer to each project’s own documentation for setup instructions.

C2pool Dash daemonless - https://github.com/frstrtr/c2pool (Do not require Dash core to run)
P2pool Pypy2 Dash - https://github.com/frstrtr/p2pool-dash

Sharechain bootstrap node: https://dash.voidbind.com (Location - UK)
Reply
1 point,16 days ago
Dash docs mentioning: "Note that P2Pool software takes a payout address and requires RPC credentials for a synchronized Dash Core node on the same host. Evaluate any fork carefully before running it, as you would with any other third-party software that handles mining rewards."

Due to its embedded nature, C2Pool does not require RPC credentials. These are only necessary if you want full redundancy for block templates, the mempool, and Dash daemon P2P block propagation.

Miners do not need to provide private keys; they simply need to enter their address into the login field in the miner stratum UI window.
Reply
4 points,1 month ago
Two pools build three of every four Dash blocks. Over the last 4,018 blocks, Aug 29 to Sep 5, the top producer had 38%, the top two 74%, the top three 89% (insight.dash.org, coinbase tags). Every miner on those pools trusts one operator's node for the template and the payout.

ChainLock does not change this. It settles finality and removes reorgs. It does not decide who builds the block or what is in it. It finalizes whatever the builder made.

c2pool changes the builder. Each miner's own node builds and validates the block. The coinbase pays every contributor from a shared sharechain. No operator holds the hashrate or the payout, and nothing enters a block without the miner who finds it consenting — no operator can insert a transaction or hold one out. Until now that node still needed a trusted dashd. This proposal removes it. One binary, no full node to trust. A miner can leave a 38% pool without joining another operator. A miner c2pool node owner controls the pool's fee, making him decide to set the fee for other miners willing to mine on his node and redirect it to his own mining or dedicated fee address. Every miner can have his own c2pool node instance, aggregating all sharechain hashrate, but controlling pool fees and block template transactions to include or not.

The node does what dashd did, from the Dash P2P wire. It keeps its own UTXO set and mempool. It derives the masternode list from DIP3 special transactions and checks the derived root against the root every block commits to. It verifies ChainLock signatures against the quorums it derived. It builds the template, picks the masternode payee, assembles the coinbase. No RPC is called.

This works today. Block 2526820, Aug 23, was built and paid by this pool's node this way. A dashd ran on the host as a standby and was not called for the template, the payee or validation. The block was ChainLocked. The derived masternode-list root has matched the committed root at every block since the node's anchor. This pool found 12 of those 4,018 blocks. mnowatch.org/blocks/?search=c2pool lists them.

DASH has risen past $60 since this was submitted. That is the argument for it. A network worth more is more worth mining without a trusted operator. The ask is 251 DASH: 125.5 per superblock, twice. It was fixed Aug 19 at about $7,500 (2 x $3750), priced in DASH and not adjusted, so the same amount is about $16,600 today. It is paid once, only if the tests pass, and it is about one month of one full-time engineer.

The work is seven items, each with one public test that anyone can check.

1. Production nodes run with no dashd. No dashd on the serving node since Aug 14; daemonless serving is the binary default. Test: 14 days on both production nodes with no dashd process, at least 3 mainnet blocks found and ChainLocked in that window, listed at mnowatch.org.

2. Superblock coinbase built without dashd. Governance-object sync over the Dash P2P wire is done; a node has already synced the superblock trigger with no dashd. Test: before block 2542248 is mined, this node's superblock coinbase — payees and amounts — is posted here; after it is mined, the on-chain payouts match it byte for byte. Repeated at 2558864.

3. Fee capture equal to Dash Core. Own mempool and UTXO fee pricing; inputs older than the node's UTXO horizon are excluded, under 0.05% of fees. Test: the node's UTXO set at the tip has the same hash_serialized_2 as Dash Core; over 1,000 blocks the template's fee total is at least 99.9% of Dash Core's on the same tip.

4. Cold start. Parallel header fetch, archival-peer acquisition, incremental masternode-list merkle, a compiled anchor. Test: a fresh data directory serves its first template within 60 minutes from the anchor; a full self-derive from DIP3 with no anchor completes within 24 hours, with the derived masternode-list root equal to the committed root at every block.

5. Dash P2P self-sufficiency. Open: stale seeds, no inbound listener, IPv4 only, wrong reported external IP, compact blocks not yet consumed. Test: a fresh node with no addnode reaches at least 8 peers from DNS seeds within 60 seconds, appears as an inbound peer in a Dash Core getpeerinfo, listens on IPv6, and adopts a new tip from a compact block in one round trip.

6. A pool with more than one node. The production nodes share one sharechain; won blocks are rebroadcast, PPLNS pays per share, the sharechain has an explorer. Test: a fresh node with default settings joins the public sharechain within 10 minutes; a block found by one node pays a miner on another by PPLNS, checked against the on-chain coinbase; the block is rebroadcast by at least two nodes.

7. Builds and documentation. v0.2.7 is released. Test: a tagged release with signed per-platform checksums; c2pool-dash --run --address X on a fresh machine produces work with nothing else installed; a pull request to dashpay/docs replacing the dead 0.18 p2pool link.

The first payment (superblock 2542248) covers items 1, 2 and 4. The second payment (superblock 2558864) covers 3, 5, 6 and 7. If the first-payment tests are not public and passing before the October vote cutoff, vote no on the second payment. Then it does not happen.

Already shown, at no cost to this budget: because the miner builds the block, it can include a transaction the rest of the network will not relay — one that pays no fee, or that sweeps dust — with the miner's explicit consent. Block 2518186 gathered about 1,040 dust donation inputs into the chain at zero fee, in transactions no other node would relay. That is the same power a centralized pool operator holds over content, placed instead in the hands of the miner who finds the block.
Reply
0 points,17 days ago
When I submitted this proposal I made a commitment: if the first-payment tests were not public and passing before the October cutoff, vote no on the second payment. The first month's budget was missed. The work did not stop. Items 1, 2 and 4 are the first payment, and all three were finished at my own cost. Each has a public test you can run yourself.

Item 4. Cold start
Test: first template within 60 minutes, full self-derive within 24 hours.

A fresh empty data directory reaches a served template in 16m10s and full masternode-list derivation in 22m11s. Zero dashd calls, proven by listing every RPC-shaped string in the run log. The derived masternode-list root equals the root the chain commits to. Fix merged as PR #1553, with a regression test on the value that used to fail. Two independent cold runs.

Item 2. Superblock coinbase without dashd
Test: the node's payees and amounts match the on-chain superblock, byte for byte.

The coinbase special transaction is byte-identical to Dash Core. The DIP4 fields (merkleRootMNList, merkleRootQuorums, bestCLHeightDiff/bestCLSig, creditPoolBalance) come from the daemonless assembler and match dashd getblocktemplate. 8 tests, 8 passed, in CI.

The derived superblock matches the block the network paid. Superblock 2542248 (mined 21 Sep 2026, hash 0000000000000026be172962cf74f47fc8dddc58e672c15fad40bd040c8d2615) pays 15 outputs summing to 6,810 DASH. The code derives the same 15 scriptPubKeys from the payee addresses, checks each byte for byte against dashd validateaddress, and selects the winning trigger by weighted-yes tally. Falsifiable two ways: flip the tally and the winner changes; corrupt one byte and the test fails at that payee. Pull block 2542248's coinbase and compare.

This proves derivation and selection with no dashd. It does not prove a production pool served that block. Serving is a separate claim, and a single-peer node cannot make it: the serve gate requires two governance peers and fails closed on one. The serve proof is forward. The same test runs at superblock 2558864 in October, and I will post the node's derived coinbase here before that block is mined.

Item 1. Production nodes with no dashd
Test: 14 days, no dashd, at least 3 mainnet blocks found and ChainLocked, listed at mnowatch.org.

Both nodes ran mainnet with no dashd for over a month. mnowatch.org/blocks/?search=c2pool lists 321 blocks tagged P2Pool-DASH/c2pool (about 20 Jul to 25 Aug 2026), none orphaned, every one ChainLocked. The serving node has run no dashd since 14 August. The test asks for 3 blocks in 14 days. The record is about 300 in a month, on both nodes.

Beyond the funded items, at no cost to this budget
Each miner's own node builds its block, so it can include transactions no pool would relay. Block 2,518,186 swept about 1,040 dust donation inputs onto the chain at zero fee, with the miner's consent.

A desktop control surface was also built and merged, not billed here: a c2pool-qt panel with per-coin settings, run controls and address validation (PRs #47, #188, #1501); a Dash governance-collateral builder with message sign/verify (PR #1638); and a transaction-injection control surface, read-only status with a money-gated submit path off by default (PRs #1611, #1619, #1666, under #157).

The ask
The first-payment tests are public and passing. Only the second payment is still open: 125.5 DASH, about $7,430 at $59.21 per DASH. The first superblock (2542248) passed unfunded and its work was done anyway, so the network funds only the remaining half, for items 3, 5, 6 and 7, in arrears at the October superblock and only if the tests pass. About two weeks of one engineer, for a Dash block builder that needs no trusted full node.
Reply
2 points,22 days ago
7. Builds and documentation. v0.2.8 is released. Test: a tagged release with signed per-platform checksums; c2pool-dash --run --address X on a fresh machine produces work with nothing else installed. (Note: The documentation PR to dashpay/docs replacing the dead 0.18 pool is already completed and merged).
Reply
4 points,1 month ago
This is great! I will be voting for this.
Reply
3 points,1 month ago
Many thanks. mnowatch is actually where these blocks surface! mnowatch.org/blocks/?search=c2pool lists what the pool has found, so your service is already doing the attribution for them. Good to have you following it. Happy to answer anything about how the daemonless node builds its templates.
Reply