Submission · Hedera Scaffold-HBAR Template Bounty (opens in a new tab)

Hedera On-Chain AI Service (HOCA)

Sell inference from your own AI model on Hedera, and let anyone check every output.

HOCA is a Scaffold-HBAR template by ColdAI. Bring your own model and host it on Hedera, off-chain or behind your own endpoint; take HBAR at a USD price or any HTS token; sell public or private sessions, delivered by the buyer or by your provider worker with escrow and refunds. Ivy Ink 1, deployed on Hedera, is the worked example.

Start your own in one command

npm create scaffold-hbar@latest -- --template shayansal/scaffold-hbar-onchain-ai

See the example project: Medusa Poets at coldai.org/poets, 500 poets writing with Ivy Ink 1. The model itself is deployed on Hedera: testnet 0.0.10765083 (opens in a new tab) and mainnet 0.0.10893786 (opens in a new tab).

Demo · 4:36 · HOCA end to end on Hedera testnet: free replay, paid and private inference, oracle pricing, chunked payloads and EQTY provenance.
3
model hosting modes
3
USD oracle sources
Any
HTS token as payment
2
privacy modes
59
Foundry tests
+2
fork tests on live testnet
54
app tests (Vitest)
39
worker tests
01How it works

Configure your own AI market

Pick how your model is hosted, how buyers pay, whether sessions are private, who delivers the answer and how long it can be. The diagram, the flow and the settings follow. The Ivy Ink 1 / Medusa Poets example is just the first preset.

Model
Payment
Privacy
Delivery
Size
Build

Bring your own model

Train → quantize → export → EQTY manifest

Host

Your model on Hedera

Integer weights stored as contract bytecode

Anyone replays it through the mirror node

Set up

HTS NFT collection (optional revenue share)

Holders earn a share of every payment

Set up

HCS provenance topic + EQTY manifest

Manifest CID and weight hashes anchored

Buy

Buyer

Pays with HBAR at a USD price or an HTS token

Sends the prompt in the clear

Pay

HTS tokens

INK, USDC or any token at a fixed price

Price

Oracles

Chainlink + Supra (+ optional Pyth)

Median with a deviation guard

Sell

InferenceMarket

Ticket with a PRNG seed (0x169)

Pricing, revenue split, pause switch

Run

Buyer runs it

Browser runtime or free mirror-node calls

Publish

Anthology (public)

Output text stored; ticket redeemed once

Inline in one transaction

Verify

Mirror node (verify)

Anyone replays the seed for free

Weights checked against the EQTY manifest

Your model lives in Hedera contract bytecode. Buyers pay in HBAR priced in USD by the oracle median or an HTS token at a fixed price; the buyer runs it with the ticket's seed; the answer is published to the Anthology for anyone to re-check.

config
# packages/foundry: yarn foundry:deploy --network hedera_testnet withMODEL_HOSTING=hedera# IVY_MODEL=0x0…0 deploys your own model contractsORACLES=chainlink,supra PRICE_USD_MICROS=10000# add pyth + PYTH_API_KEY for a third source # then accept a token (the HTS association runs on Hedera)yarn foundry:accept-token --token 0.0.x --price <smallest units> # owner switches at any timesetPaused(true)# stops new sales; refunds and deliveries still work
02Features

Customise every part, keep every guarantee

Host it your way

Put the weights in Hedera contract bytecode, keep them off-chain on IPFS or HTTPS with their SHA-256 on-chain, or serve the model from any OpenAI-compatible endpoint (vLLM, Ollama, hosted LLMs).

Bring your own model

The model/ pipeline trains, quantizes and exports a model and signs its lineage with EQTY. Swap in your own model; the market, payments and provenance stay the same.

Pay in any token

HBAR or any HTS token through its ERC-20 facade, each at its own price. The market associates itself with each token via the HTS system contract 0x167; the UI lists whatever it accepts.

Your oracle mix

Price HBAR in US dollars from Chainlink and Supra, plus Pyth if you want it. Every feed must be fresh and within a 2% band, and the market uses the median, so one bad feed cannot misprice a sale.

Public or private

Private sessions seal inputs and outputs with X25519 + AES-256-GCM to the buyer and the model creator. The seed mixes the PRNG with the buyer's secret: still unbiased, known only to them. The creator decrypts for their own use.

Inputs and outputs of any length

Payloads bigger than one transaction travel as chunked events. The contract completes them only when the byte count and a rolling keccak hash both match.

Provider-served, with escrow

The provider worker fulfils paid tickets and publishes the answer. Payment waits in escrow until delivery, and the buyer is refunded if nothing arrives in the delivery window. The worker ships with 39 tests.

Pause and key rotation

The owner can pause sales while paid tickets can still be delivered or refunded, and the provider can rotate its encryption key, all without redeploying the market.

Unbiased seeds

Each ticket's seed comes from Hedera's PRNG (0x169, HIP-351). Buyers cannot pick a seed, and each ticket is redeemed once, so every published output is one paid draw.

Optional revenue share

Tie each model variant to an HTS NFT and its holder earns a share of every payment. Anyone withdraws their own balance, including from an ECDSA alias via HIP-632.

EQTY provenance on HCS

A signed EQTY manifest covers corpus, code, checkpoint and weights. Its CID is anchored on an HCS topic, and the app re-hashes what is deployed against it.

Tested, with CI and a scaffold gate

CI runs lint, Foundry, Vitest, the build and EQTY verification. A daily job scaffolds a new project from the latest CLI, the same way the bounty gate does. A Hedera Harness (opens in a new tab) recipe lets coding agents extend it safely.

The worked example: Ivy Ink 1

The template ships with Ivy Ink 1, a 235k-parameter poetry model deployed on Hedera: its int8 weights are the bytecode of 12 data contracts, and a GRU in Solidity reads them with EXTCODECOPY. Python, Solidity and TypeScript are bit-exact, so the browser, the contract and the reference all write the same poem.

  • weights in bytecode
  • bit-exact in Python, Solidity, TypeScript
  • 1.85M gas per character
  • 7 characters per free mirror call
03Hedera technology

Ten Hedera services, each doing real work

ServiceWhereWhat it does here
Smart Contracts (EVM)IvyInk1, 12 data contracts, InferenceMarket, AnthologyThe model itself runs in the EVM: an int8 GRU with SWAR matrix-vector products and lookup-table activations
HTS, non-fungiblePoets collectionThe poet serial is the model's conditioning record; holders earn a revenue share (ownerOf through the ERC-721 facade)
HTS, fungibleINK demo token, USDC or any tokenPayment through the ERC-20 facade; the market associates itself through the HTS system contract 0x167
Consensus Service (HCS)Provenance topicAnchors the EQTY manifest CID, the weights' SHA-256 and each chunk's SHA-256
PRNG system contract (HIP-351)0x169An unbiased seed for every ticket
Account service (HIP-632)0x16aMaps an ECDSA EVM alias to the long-zero account HTS reports as the NFT owner
Mirror NodeApp, verifier, provider workerFree model execution (/contracts/call), weight bytecode, Anthology logs, HCS messages
JSON-RPC relay (Hashio)Wallets, FoundryDeploys, fork tests and every wallet transaction
Hiero SDKSetup and provider scriptsCreates the Poets NFT, the INK token and the provenance topic, and anchors the manifest
Sourcify verificationyarn foundry:verify:testnetVerified source, shown on HashScan
04Integrations

Built with the ecosystem

Every integration carries weight: remove one and a guarantee goes with it.

Hedera (opens in a new tab)

The network

Contracts, tokens, topics, randomness and the mirror node. Load-bearing: with Hedera hosting, the model, payment, seeds and provenance all live on-chain, so nothing else needs to be trusted.

Chainlink (opens in a new tab)

HBAR/USD push feed

The default USD price source, with no keys to manage. Load-bearing: half of the cross-check. If Chainlink and Supra disagree by more than the band, the market stops selling rather than guess.

Supra (opens in a new tab)

HBAR/USDT push oracle, pair 75

A second, independent source. Load-bearing: with Chainlink it forms the deviation guard, and the deviation bound also caps how far USDT can drift from USD.

Pyth (opens in a new tab)

Optional HBAR/USD pull feed

A third source for the median. Load-bearing: Hermes needs an API key since 2026-08-26, so the app fetches signed updates server-side with PYTH_API_KEY and never exposes it; the market pays the update fee from the transaction.

EQTY Lab (opens in a new tab)

Integrity Manifest (eqty_sdk)

Signed, content-addressed lineage from training corpus to quantized weights. Load-bearing: the export runs inside a recorded EQTY computation, and the manifest's hashes are checked against the bytecode deployed on Hedera.

IPFS (opens in a new tab)

Off-chain weight hosting

Where the weights live when the model is not hosted on Hedera. Load-bearing: the market stores the blob's SHA-256, so the app refuses any file that does not match, while payment, seeds and provenance stay on Hedera.

05Live on testnet

Check it yourself on HashScan

The template's app talks to this deployment by default. Every contract, token, topic and transaction is in EVIDENCE.md (opens in a new tab).

ContractHedera IDEVM addressDeploy
InferenceMarket
Pricing, tickets with PRNG seeds, escrow and refunds, revenue
0.0.10780285 (opens in a new tab)0x9E0337…7d57790x7f198ec3… (opens in a new tab)
Anthology
One published output per ticket
0.0.10780288 (opens in a new tab)0xdaEc96…27ad5e0x724c4620… (opens in a new tab)
ChainlinkHbarUsd adapter
HBAR/USD push feed
0.0.10780292 (opens in a new tab)0x4F1D6f…0aBc380x407d4319… (opens in a new tab)
SupraHbarUsd adapter
HBAR/USDT push feed, pair 75
0.0.10780294 (opens in a new tab)0x264720…bB10fb0x8f90ed0a… (opens in a new tab)
IvyInk1 (the model)
Public deployment, reused by every market
0.0.10765083 (opens in a new tab)0x93CA12…C6993freused
Weight contracts (12)
The model's int8 weights as bytecode
0.0.10765038 (opens in a new tab) to 0.0.10765080 (opens in a new tab), poet registry 0.0.10765081 (opens in a new tab)
Native resourceID
Poets NFT collection
HTS non-fungible, 5 example poets
0.0.10778530 (opens in a new tab)
INK payment token
HTS fungible, 2 decimals
0.0.10778532 (opens in a new tab)
Provenance topic
HCS, EQTY manifest anchor (message #3)
0.0.10778533 (opens in a new tab)
06Why it fits the bounty

Against the judging criteria

Ecosystem integration

  • Chainlink and Supra cross-checked, Pyth optional, all behind one adapter interface.
  • EQTY Lab lineage anchored on HCS; IPFS for off-chain hosting.
  • An example project: Medusa Poets at coldai.org/poets, 500 poets writing with Ivy Ink 1, the model deployed on Hedera.

Code quality

  • 59 Foundry tests, plus 2 fork tests against the live testnet oracles and the deployed model.
  • 54 app tests (Vitest) and 39 provider-worker tests; the model is bit-exact across Python, Solidity and TypeScript.
  • CI with lint, types and build, plus a daily fresh-scaffold gate.

Hedera service depth

  • EVM, HTS (NFT and fungible), HCS, PRNG, the HIP-632 alias service and the mirror node, each doing real work.
  • Hiero SDK for native setup, Hashio for the relay, Sourcify for verification.
  • Handles Hedera specifics: tinybar units, HTS association, long-zero addresses, the 15M gas cap.
07What's next

Soon powering SFAI

HOCA will power verifiable, private AI inference on SFAI, the ColdAI intelligence exchange, and on its NATDAQ indexes: paid on Hedera, sealed to buyer and provider, and checkable by anyone.

Run your own model on Hedera with HOCA

Scaffold it, start the app against the live testnet deployment, and write a free poem in minutes.

npm create scaffold-hbar@latest -- --template shayansal/scaffold-hbar-onchain-ai

MIT licenceBuilt by ColdAISource on GitHub (opens in a new tab)DocumentationExample project: Medusa PoetsThe bounty (opens in a new tab)Hedera (opens in a new tab)