> For the complete documentation index, see [llms.txt](https://docs.trueopen.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.trueopen.ai/protocol/v1/service-participation/staking-and-penalties.md).

# Staking and Penalties

Responsibility domains, Cortex Node bonds, penalties, recovery, and exit.

TrueOpen separates consensus security from AI service responsibility. A failure in one responsibility domain must not silently consume funds from another.

## Responsibility domains

| Domain                 | Participant | Purpose                                                                        |
| ---------------------- | ----------- | ------------------------------------------------------------------------------ |
| Consensus stake        | Validator   | Consensus participation and governance power                                   |
| ServiceBond            | Cortex Node | Service admission, Task liability, business penalties, and exit accountability |
| Builder responsibility | Builder     | Coordination and data-availability duties                                      |

In Phase 0, a Builder has no funded BuilderBond. Objective Builder faults can still be recorded for audit and governance, but they do not debit Validator consensus stake or a Cortex Node ServiceBond.

Ordinary inference, verification, or data-availability faults never slash Validator consensus stake.

## Operator and service key

Each Cortex Node has one stable operator address and one currently authorized service key.

* The operator controls the ServiceBond, earnings, claims, exit, and key replacement.
* The service key signs handraises, Task material, and permitted self-rescue transactions.
* A compromised service key cannot withdraw the ServiceBond, claim earnings, or change the operator.

A service-key replacement is allowed only after the node stops accepting new work and all accepted Task liabilities and required submissions have closed. Replacement is atomic: the old key loses authority as soon as the new key becomes active.

## ServiceBond lifecycle

| State        | Meaning                                       | New Task eligibility                                  |
| ------------ | --------------------------------------------- | ----------------------------------------------------- |
| `REGISTERED` | Bond and operator identity exist              | Not until Model support requirements are met          |
| `ACTIVE`     | Eligible Model support is current             | Yes                                                   |
| `STALE`      | Required support freshness expired            | No                                                    |
| `JAILED`     | Recoverable service fault is active           | Only if the protocol gives a non-zero recovery factor |
| `UNBONDING`  | Exit or bond reduction is waiting             | No new Tasks                                          |
| `TOMBSTONED` | Permanently removed                           | No                                                    |
| `EXITED`     | Bond was withdrawn after all liability closed | No                                                    |

One ServiceBond can support several Models. Eligibility is evaluated separately for each Task Profile by comparing the active bond with that Profile's minimum bond and checking the relevant inference or verification capability.

## Task liability

Handraising expresses willingness, not assignment. When a Cortex Node is selected, the protocol reserves enough slashable ServiceBond for that Task. A node cannot use the same unreserved amount to accept unlimited concurrent liability.

Later changes to a profile's minimum bond do not rewrite an accepted Task. They affect future eligibility after the configured effective boundary and grace period.

## Penalties and recovery

Only objectively attributable protocol facts can create a business penalty. Examples include missing an accepted duty deadline, submitting contradictory signed material, or being disproved by an independent challenge round.

Penalties follow these rules:

* A unique fault can be applied only once.
* Liability is debited from the responsible operator's slashable service funds.
* Active bond, slashable unbonding funds, and applicable claimable earnings may be consumed only in the defined order.
* A shortfall is recorded but does not create protocol debt or draw from another fund.
* Recoverable faults may increase an operator-global jail count and require successful duties before recovery.
* Tombstoned operators cannot recover.

## Unbonding and exit

Starting unbonding stops new Task eligibility but does not erase existing obligations. The waiting period must cover active Tasks, their challenge windows, evidence-retention responsibilities, and delayed fault application.

Withdrawal is allowed only when all accepted liabilities have ended and the unbonding period has matured. This prevents an operator from exiting before the protocol can evaluate work it already accepted.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.trueopen.ai/protocol/v1/service-participation/staking-and-penalties.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
