Targon (subnet number: SN4) is a decentralized confidential cloud infrastructure built on the Bittensor ecosystem system. Its core is to liberate enterprise-grade high-performance AI computing power and proprietary model reasoning from the monopoly of traditional cloud giants through mechanisms such as Trusted Execution Environment (TEE), deterministic cryptographic verification, and dynamic game token economics, and transform them into scarce "digital commodities" driven by the free market.In terms of architecture, Targon combines full stack security defense (including hardware isolation, protected bus, and customized TargonOS system) with multi-vendor hardware integration strategy to form a decentralized computing network with confidentiality and trustless execution as its core. This not only significantly reduces the cost of enterprise AI model training and inference, but also provides an anti-censorship compliance architecture for institutions with high requirements for data privacy and intellectual property.From the perspective of ecosystem and data performance, Targon has completed the core underlying migration of large-scale commercial applications (such as Dippy AI), generating tens of millions of external annual revenues and demonstrating strong capital absorption under the dTAO mechanism. Targon has filled the infrastructure gap in the decentralized AI race regarding "data security and verification trust", exploring a new business paradigm of "institutional confidential computing power leasing". In the long run, it has great potential to become the cornerstone facility for the next generation of tamper-resistant AI applications and sovereign digital intelligent entities.
Starting from the traditional Web2 Cloud as a Service giants: the current status and limitations of AI computing power allocation
In the era of exponential growth in artificial intelligence technology, the global distribution of computing resources is facing an unprecedented imbalance. Deploying and running high-level AI applications such as large-scale language models (LLM) is a project with extremely high financial and infrastructure thresholds in traditional cognition and business practices. The current computing power supply is mainly dominated by a few traditional centralized Cloud as a Service providers (such as AWS, Google Cloud, Microsoft Azure) and some closed top-level AI laboratories.These centralized institutions, with massive capital expenditures, not only monopolize the high-end computing clusters composed of top computing chips like NVIDIA H100 and H200, but also control the pricing and allocation of computing resources. In this model, ordinary enterprises, Web3 developers, and even medium-sized and large tech startups can only lease "AI computing as a service" from these giants at extremely high premiums. This makes high-end AI computing a monopoly of a few, rather than an accessible infrastructure resource.
Although Web2 centralized cloud vendors provide highly scalable and relatively stable computing services, the limitations of their underlying closed structure are being exposed more rapidly as the AI industry continues to evolve.
Privacy and intellectual property concerns: Companies upload proprietary model weights and highly sensitive user data (such as medical records and financial transactions) to a centralized cloud, facing serious risks of single-point failure and data leakage. The deep-seated anxiety of modern companies about the leakage of proprietary model weights has become the core bottleneck preventing higher-level business scenarios from going cloud.
High cost and inflexible pricing: computing resources are highly concentrated in the hands of cloud vendors, and the pricing mechanism lacks true free market competition. For companies that need to handle large and high-concurrency reasoning needs, long-term centralized Cloud as a Service leasing will result in extremely unsustainable operation and maintenance costs.
Structural bottlenecks and lack of censorship resistance: Traditional cloud services are a "closed system" where users' model training, data transfer, and resource scheduling are strictly bound by the rules of a single platform, lacking complete censorship resistance in physical architecture. Against this backdrop, the Bittensor protocol emerged, attempting to break this traditional structural bottleneck by integrating the token economics of blockchain and distributed machine learning to build a peer-to-peer free market called the "Digital Commodity Internetwork".
Targon: Reconstructing AI confidential computing with a "cryptographic network"
As mentioned above, the core problem of traditional Web2 AI computing is the "closed monopoly" and "trust crisis". Targon is a revolutionary restructuring of this industry pain point. Targon is led and developed by Manifold Labs, an AI infrastructure startup headquartered in Austin, Texas, USA, and is operated and maintained as Subnet 4 (SN4) of the Bittensor network.Targon is not simply aggregating the world's idle consumer-grade graphics cards into an inefficient computing power bulletin board, but is defined as the first and currently the only confidential cloud infrastructure in the entire decentralized ecosystem that systematically solves the problem of "hardware-level trustless execution". The core team of Manifold Labs has a deep understanding of Bittensor's native genes. Founder and CEO Robert Myers and co-founder James Woodman have accurately positioned Targon's strategy as a direct competitor to AWS and OpenAI in the enterprise cloud market.Through deep integration of Trusted Execution Environment (TEE), self-developed Virtual Machine (TVM), and deterministic cryptographic verification, Targon allows users to execute tasks on fully decentralized nodes and guarantees absolute data privacy at both the physical and mathematical levels.
Decentralized AI networks have long faced a fundamental monetization dilemma:
On the one hand, aggregating the long-tail idle computing power of global miners can significantly reduce computing costs.
On the other hand, since the physical control of network nodes is in the hands of anonymous global miners, any attempt to process medical, financial, or load high-value model weights on these nodes faces a devastating risk of data theft.
The core change of Targon is that it completely transforms the traditional assumption of "trusting the node not to do evil" into "mathematically impossible to be malicious". Targon has built a defense depth from the hardware physical bus to the operating system, making it impossible for even anonymous miners with physical data center keys to read model weight files or steal user-transmitted interactive data.This not only fills the huge market gap between "low-cost distributed computing power" and "enterprise-grade compliance data security", but also paves the way for the monetization of high-value closed-source AI models on the open network, thus expanding the customer base to Fortune 500 companies that are extremely sensitive to intellectual property.
In traditional decentralized computing platforms, the role of the platform is often limited to simple resource matching and docking. However, under the macroeconomic framework of Targon and Bittensor, this process undergoes a fundamental transformation: Targon aims to make "high-performance AI computing with privacy attributes" a standardized, quantifiable, and freely tradable scarce "digital commodity". This is not just about providing tools, but building a continuously operating market. Developers can confidently deploy proprietary models worth millions of dollars for commercial gain;Computing power providers (institutional miners) can set their own prices for hardware computing power through the order book, while verifiers use a rigorous cryptographic mechanism to rate the quality of the delivered computing power and allocate tokens. As a result, AI computing has transitioned from a high-risk engineering task to a dynamic digital economic model driven by market incentives and collaborative gameplay among all parties.
In the large ecosystem of Bittensor, which has expanded to 128 active subnets, different subnets undertake functions such as data capture, MultiModal Machine Learning generation, and Model Training. The positioning of Targon (SN4) in this network is increasingly evolving into the industrial-grade underlying "computing sink" and core computing hub of the entire Bittensor ecosystem. Targon not only directly serves external traditional Web2 clients, but also provides computing support for other subnets that lack hardware resources but need to execute advanced logic through its confidential hardware base.
Data isolation and collaboration: Score subnet (SN44), which focuses on tracking competitive sports, runs its exclusive video analysis model in the TEE environment of Targon to protect the privacy of sensitive training videos on the field, avoiding data exposure to the public network.
Logical optimization execution: The Affine subnet (SN120) that deeply cultivates AI inference logic optimization does not host hardware resources, but relies on the Targon network to perform actual inference, forming a perfect value closed loop.
AGI R&D Support: Star project Hone deeply integrates Manifold Labs' underlying architecture capabilities into its core pre-training and fusion framework. Additionally, Targon is even integrated into NousResearch's hermes-agent toolkit, allowing developers to directly call upon its decentralized confidential GPU resources.
Core architecture: How to implement hardware-level trustless confidential computing in a network
In order to fully understand how Targon overcomes the trust bottleneck, we need to thoroughly dismantle its full-stack security defense system, known as the Targon Virtual Machine (TVM).
Targon guarantees data security in a distributed environment without relying on trust, starting from the lowest level of hardware isolation.
Trusted Execution Environment (TEE): A piece of hardware encryption memory area called "Enclave" is carved out inside the main CPU. Even if the highest (Root) permissions of the operating system of the miner node are hacked, it is impossible to read or tamper with the instructions and data being executed in this area.
Hardware compatibility and standard integration: To prevent single-point technology dependence, Targon deeply integrates Intel's Trust Domain Extension (TDX) technology and supports AMD's Secure Encryption Virtualization (SEV-SNP) architecture, and seamlessly integrates with NVIDIA's advanced confidential computing architecture at the core GPU level.
Bus Transport Layer Encryption (PPCIE): To block physical eavesdropping attacks that may be initiated through the main board bus, the network forces the protected PCIe technology to ensure that sensitive data is always wrapped in stream encryption algorithms during the process of transferring from CPU memory to H200 or RTX 4090 through the main board slot, achieving end-to-end hardware-level anti-sniffing.
Due to the extreme profit-seeking and cheating motives of the mining community, Targon cannot allow miners to run arbitrarily tampered with the underlying operating system.
Custom Enhanced System: Manifold Labs has developed and released a highly enhanced custom Linux publish version - TargonOS, specifically for booting encrypted virtual machines on untrusted devices.
TPM-based hardware root of trust: TargonOS introduces a Secure Boot mechanism based on Trusted Platform Module (TPM) to ensure that the underlying system environment has not been tampered with.
Ultimate network communication: At the network layer, through the first cross-language open source network protocol Epistula v2 combined with ultra-low latency technologies such as InfiniBand and RoCE, not only ensures anti-eavesdropping concurrent communication between nodes, but also achieves extremely low response latency (less than 50 milliseconds) and 99% normal operation time, greatly reducing the access friction of external developers.
How can we verify that miners have completed the complex reasoning of a hundred billion parameter model with "zero computing power waste" in a fully distributed architecture? This involves Targon's most innovative deterministic verification design.
Remote Attestation: Before tasks are distributed, miners must submit a cryptographic proof to the network that contains the real-time physical hardware model, the operating system kernel hash value, and the integrity fingerprint of the TVM binary file. After verification by the verifier, it can be confirmed that the miner is using a high-end graphics card (such as H200) that is compliant, rather than a high-level fraud with counterfeit computing power.
Breakthrough of asymmetric computing power: In traditional decentralized networks, if validators are equipped with low-end hardware, they cannot reproduce the complex calculation process of miners to verify their authenticity. Targon's verifier.py core logic cleverly solves this problem: the network supervisor continuously sends synthetic queries and real organic queries to the miner pool.
Logprobs Engine: After completing the inference, miners are forced to return the generated text token sequence and the "logprobabilities" data matrix of each output hidden layer during the calculation process. Lightweight validators only need to mathematically compare the probability distribution of their own maintained benchmark model with the data submitted by miners at the cryptographic level.If the mathematical distribution is highly consistent and the response time is less than the low-end hardware limit, the verifier can obtain 100% certainty from the statistical dimension that the miner has indeed executed the real reasoning calculation from scratch, instantly exposing any attempt to call the cache or tamper with the small model.
Incentive and Competitive Mechanism: How AI Computing Forms a "Positive Loop" in Macroeconomics
The life cycle of the Bittensor network and the scheduling of computing power are highly dependent on its underlying token economics design. In December 2025, Bittensor experienced its first halving of production, reducing the daily publish quantity of the base token TAO from 7,200 to 3,600, significantly reducing the inflation rate to 13%, and maintaining a hard cap supply limit of 21 million. The dynamic TAO (dTAO) mechanism launched in February 2025 completely revolutionized the survival rules of the subnet.It introduces Automated Market Maker (AMM), abolishes the legacy model of subjective allocation of inflation rewards by a fixed verifier committee, and switches to free market capital voting. The system publishes a dedicated Alpha token (asset code SN4) for Targon. Investors can mint or exchange SN4 by staking the base layer TAO, forming a deep dual-token liquidity reserve. The real-time relative price and total market capitalization of the SN4 token directly determine how much of the incentive dividend Targon can capture from the TAO issuance pool every day.
In order to avoid the inertia trap of miners "lying flat and earning tokens" once they reach the benchmark performance, the Targon team completely rewrote the reward logic in the v3 version iteration, abandoning the gentle plateau income curve and introducing an extremely steep "exponential curve". Under this mechanism:
Comprehensive performance evaluation: The verifier strictly monitors the absolute latency, concurrency, and throughput of the miner's hardware in real time.
Winner takes all: Only the top hardware nodes at the top of the leaderboard that can stably handle massive concurrent requests can obtain the exponentially magnified Yuma consensus score and excess rewards.
Strict anti-cheating penalties: Any cheater who attempts to artificially accelerate the response by tampering with the TVM sampling parameters will be instantly caught during the log probability comparison stage, and their score will be set to zero (excluding from scoring) and will face severe penalties such as demotion or expulsion from the network. This extremely competitive arms race forces miners to continuously invest real money in upgrading top-tier GPU devices and optimizing backbone internet bandwidth, strengthening the hardware foundation of Targon.
Decentralized networks have long been criticized for being "revenue deserts", which means they rely too much on token inflation to subsidize network participants. Once the subsidies stop, business customers who have been using computing power for free will instantly leave. To ensure long-term survival, Manifold Labs has implemented a highly forward-thinking reform in the industry:
70% Inflation Burn: The management team has forced the opening of the distribution valve, resulting in the direct destruction or isolation of up to 70% of the subnet TAO issuance, preventing it from entering the market.
Controlling the equilibrium point of fiat currency: By reducing circulation, the subsidy income of top network miners (such as H200 nodes) is precisely controlled at a reasonable level of about $2.80/hour. This meager but healthy profit just covers the depreciation of miners' equipment, installment interest, and electricity costs, filtering out those short-term arbitrageurs who are ready to flee at any time, and ultimately ensuring that the miner's reward is fully supported by external real corporate dollar income.
Order Book Mechanism: Abolish the inflexible command economy model where prices are set by the agreement, and return the pricing power to the computing power providers. Miners can set their own ask prices for high-end hardware, and even sign fixed-term contracts with guarantees of collateral and normal operation time. This series of mechanisms has completely marginalized retail miners who relied on leasing and reselling in the early days, attracting real institutional miners with their own data centers and extremely low capital costs to take over the computing power supply side, greatly improving the commercial resilience of the Targon network.
Ecosystem status and business penetration
The participant ecosystem of Targon is fundamentally different from many subnetworks that are still in the Proof of Concept (PoC) stage. It has already built a solid barrier in the real business world.
Requirements and Verifier (Enterprise Adoption): The most iconic business breakthroughs come from the well-known AI role-playing technology company Dippy AI. Dippy AI has a huge client base of over 8.6 million on the mobile end, facing billions (10B) of basic token interaction requests every day. Faced with huge operation and maintenance costs, Dippy AI chose to terminate the contract with the centralized cloud provider and migrate the entire backend reasoning chain to the Targon network. This six-figure epic agreement not only increased Targon's total external revenue to approximately $10.4 million per year, but also proved to the industry that after migrating to Targon, large enterprises can structurally reduce total expenses by 20% to 35% while maintaining decentralized flexibility.
Full stack ecosystem matrix (Manifold 2.0): In March 2025, Manifold Labs launched an ecosystem matrix covering multidimensional applications, including the decentralized hybrid AI search engine Sybil (realizing millisecond-level censorship-resistant network data capture) and the exclusive blockchain network monitoring advanced end point tool Tao.xyz, greatly enriching the developer experience and data transparency within the ecosystem.
Based on the dTAO system architecture and the latest on-chain macroeconomic reference data up to 2026, Targon has demonstrated strong capital and liquidity retention capabilities in the free market
Market value and currency price: The price of the core asset SN4 is stable in the range of about $18.39 to $19.07, with a total market value of $85.10M to $91.80M, ranking among the top three in the 128 active subnets of the entire network, demonstrating a deep institutional capital consensus.
Deflation mechanism: Under the maximum 21 million hardcap supply structure, the circulation is maintained at 4.41M to 4.46M, and about 442,300 tokens have been permanently destroyed (Burned) through the token economics regulation mechanism, which has strong anti-inflation properties.
Liquidity Structure Pool: Its AMM trading pool has accumulated a base reserve liquidity of $42.25 million (over 130,000 TAO and 2.22 million Alpha), providing a safety cushion for large institutions to build large positions or pledge, avoiding sharp price slippage.
Pledge and Return on Investment: A large number of tokens in the market are in a pledged and locked state (over 2.25 million SN4). The annual cash flow return rate provided by top validators (such as MUV and Tatsu nodes) to pledgers is stable at 8.40% to 9.61%, making it a better investment than traditional Web2 fixed-income assets.
Competition landscape and multidimensional vulnerability game
In the highly competitive decentralized AI reasoning and computing track, Targon's positioning is clear and defensive. It has skillfully avoided the red ocean and entered the most profitable core track in the current AI supply chain: enterprise compliance and trust mechanisms. The increasingly stringent European and American data privacy compliance laws have caused extreme panic among traditional enterprises regarding the adoption of decentralized networks for intellectual propertyTargon's full stack of software and hardware isolation and zero-trust verification design make it the almost only safe and feasible channel for high-net-worth clients to enter the decentralized network, forming a rare structural monopoly.
Looking at the entire ecosystem, Targon is facing siege and challenges from many different technical paths:
Comparison with Chutes (SN64): Chutes focuses on serverless platforms and extremely low pricing, with a current market value of over $132 million. It has amassed a large number of long-tail developers and provides an experience closest to traditional Web2. However, its fatal flaw is the lack of hardware-level confidential computing isolation guarantees, making it completely incapable of handling the influx of sensitive data from large traditional enterprises, limiting its potential.
Comparison with Templar (SN3): Templar is deeply involved in the extreme pre-training infrastructure of distributed large language models, with strong narrative tension. However, its R&D burn rate is extremely high, and it lacks a clear and mature large-scale commercial revenue realization loop like Targon in the short term.
Compared to Lium (SN51): The ultra-high density H100 bare-metal physical cluster leasing for institutions has a large computing power reserve. However, it is far less robust than Targon's TVM ecosystem in terms of Competitive Edge depth and cutting-edge cryptography technology added value. Overall, Targon's advantage lies in the monopoly breakthrough point of compliance data and the closed-loop of over ten million dollars in real revenue; while its potential disadvantage lies in its strict military-grade hardware access threshold, which to some extent restricts the disorderly and rapid expansion of network miners.
Despite the impressive ecosystem construction, Targon and the entire underlying network still face a huge systemic survival test:
Validator Cartel and Power Monopoly: The current Achilles heel of the Bittensor system is the over-centralization of proof-of-stake based on the Yuma consensus. The vast majority of staking weights are controlled by institutional capital giants (such as Yuma Asset Management). These super validators may abuse weights and use cartel collusion such as "weight-copying" to intervene in the scoring system and maliciously extract inflationary rewards from the network.Despite the continuous release of patches by the official, the anti-conspiracy reform of the governance system is still a sword of Damocles hanging over our heads.
The death spiral of macro subsidies drying up: As the next output milestone in 2029 approaches, Targon has generated over 10 million in revenue and voluntarily burned a large amount of emissions. However, compared to its annual consumption of up to 18 million dollars in system subsidies, it has not yet achieved complete "net blood production". If the future tightening of the crypto-macro cycle leads to the collapse of the token-to-fiat price, and institutions that cannot pay H200 installment loans go offline in large numbers, it is likely to trigger a vicious cycle of liquidity collapse and user churn.
Geopolitical extortion of Silicon Valley's chip hegemony: While decentralized clouds are resistant to censorship in terms of physical distribution, the core TEE isolation area relies heavily on the underlying firmware and architecture authorization of the single chip oligarch NVIDIA (H100/H200). Against the backdrop of intensified global semiconductor export controls, if hardware giants unilaterally block interface protocols, Targon's protective barrier will face the threat of paralysis. Accelerating the compatibility compilation to non-NVIDIA camp standards is also its highest priority survival game.
Future Outlook: Can the decentralized trust hub for reshaping the Relations Of Production be established?
Through deep deconstruction, it can be found that Targon (SN4) has far exceeded its early narrow positioning of "distributed computing power pool", transforming into a massive enterprise-level cryptographic agent driven by rigorous mathematical probability verification, hardware-level trust isolation, and a brutal token game engine. It stands out with its advantages in the battle of offense and defense full of fraud and gameplay.
From the current stage, whether the large-scale monetization of the decentralized confidential cloud can be sustained depends on whether the external income of the network can exceed the rate of token inflation. Targon has irrefutably proven to traditional finance and tech giants for the first time through the huge order of Dippy AI: the decentralized architecture is fully capable of defeating the traditional Cloud as a Service in terms of cost-effectiveness, while providing an underlying technology guarantee that centralized giants can never reach in terms of maintaining data privacy sovereignty.
In the next few years leading to the era of Artificial General Intelligence (AGI), with the full opening of traditional compliance channels such as Grayscale trust ETFs, and the exponential increase in global corporate anxiety about AI model intellectual property rights, Targon's zero-trust business paradigm has a strong tailwind of the times.Despite the challenges ahead - facing the abyss of dealing with cartelization and the containment of cross-border chip supply chains, Targon has irreversibly reshaped the production and trust boundaries of decentralized AI in the history of human intelligent computing distribution by leveraging the advantages of cryptography.
Targon (subnet number: SN4) is a decentralized confidential cloud infrastructure built on the Bittensor ecosystem system. Its core is to liberate enterprise-grade high-performance AI computing power and proprietary model reasoning from the monopoly of traditional cloud giants through mechanisms such as Trusted Execution Environment (TEE), deterministic cryptographic verification, and dynamic game token economics, and transform them into scarce "digital commodities" driven by the free market.In terms of architecture, Targon combines full stack security defense (including hardware isolation, protected bus, and customized TargonOS system) with multi-vendor hardware integration strategy to form a decentralized computing network with confidentiality and trustless execution as its core. This not only significantly reduces the cost of enterprise AI model training and inference, but also provides an anti-censorship compliance architecture for institutions with high requirements for data privacy and intellectual property.From the perspective of ecosystem and data performance, Targon has completed the core underlying migration of large-scale commercial applications (such as Dippy AI), generating tens of millions of external annual revenues and demonstrating strong capital absorption under the dTAO mechanism. Targon has filled the infrastructure gap in the decentralized AI race regarding "data security and verification trust", exploring a new business paradigm of "institutional confidential computing power leasing". In the long run, it has great potential to become the cornerstone facility for the next generation of tamper-resistant AI applications and sovereign digital intelligent entities.
Starting from the traditional Web2 Cloud as a Service giants: the current status and limitations of AI computing power allocation
In the era of exponential growth in artificial intelligence technology, the global distribution of computing resources is facing an unprecedented imbalance. Deploying and running high-level AI applications such as large-scale language models (LLM) is a project with extremely high financial and infrastructure thresholds in traditional cognition and business practices. The current computing power supply is mainly dominated by a few traditional centralized Cloud as a Service providers (such as AWS, Google Cloud, Microsoft Azure) and some closed top-level AI laboratories.These centralized institutions, with massive capital expenditures, not only monopolize the high-end computing clusters composed of top computing chips like NVIDIA H100 and H200, but also control the pricing and allocation of computing resources. In this model, ordinary enterprises, Web3 developers, and even medium-sized and large tech startups can only lease "AI computing as a service" from these giants at extremely high premiums. This makes high-end AI computing a monopoly of a few, rather than an accessible infrastructure resource.
Although Web2 centralized cloud vendors provide highly scalable and relatively stable computing services, the limitations of their underlying closed structure are being exposed more rapidly as the AI industry continues to evolve.
Privacy and intellectual property concerns: Companies upload proprietary model weights and highly sensitive user data (such as medical records and financial transactions) to a centralized cloud, facing serious risks of single-point failure and data leakage. The deep-seated anxiety of modern companies about the leakage of proprietary model weights has become the core bottleneck preventing higher-level business scenarios from going cloud.
High cost and inflexible pricing: computing resources are highly concentrated in the hands of cloud vendors, and the pricing mechanism lacks true free market competition. For companies that need to handle large and high-concurrency reasoning needs, long-term centralized Cloud as a Service leasing will result in extremely unsustainable operation and maintenance costs.
Structural bottlenecks and lack of censorship resistance: Traditional cloud services are a "closed system" where users' model training, data transfer, and resource scheduling are strictly bound by the rules of a single platform, lacking complete censorship resistance in physical architecture. Against this backdrop, the Bittensor protocol emerged, attempting to break this traditional structural bottleneck by integrating the token economics of blockchain and distributed machine learning to build a peer-to-peer free market called the "Digital Commodity Internetwork".
Targon: Reconstructing AI confidential computing with a "cryptographic network"
As mentioned above, the core problem of traditional Web2 AI computing is the "closed monopoly" and "trust crisis". Targon is a revolutionary restructuring of this industry pain point. Targon is led and developed by Manifold Labs, an AI infrastructure startup headquartered in Austin, Texas, USA, and is operated and maintained as Subnet 4 (SN4) of the Bittensor network.Targon is not simply aggregating the world's idle consumer-grade graphics cards into an inefficient computing power bulletin board, but is defined as the first and currently the only confidential cloud infrastructure in the entire decentralized ecosystem that systematically solves the problem of "hardware-level trustless execution". The core team of Manifold Labs has a deep understanding of Bittensor's native genes. Founder and CEO Robert Myers and co-founder James Woodman have accurately positioned Targon's strategy as a direct competitor to AWS and OpenAI in the enterprise cloud market.Through deep integration of Trusted Execution Environment (TEE), self-developed Virtual Machine (TVM), and deterministic cryptographic verification, Targon allows users to execute tasks on fully decentralized nodes and guarantees absolute data privacy at both the physical and mathematical levels.
Decentralized AI networks have long faced a fundamental monetization dilemma:
On the one hand, aggregating the long-tail idle computing power of global miners can significantly reduce computing costs.
On the other hand, since the physical control of network nodes is in the hands of anonymous global miners, any attempt to process medical, financial, or load high-value model weights on these nodes faces a devastating risk of data theft.
The core change of Targon is that it completely transforms the traditional assumption of "trusting the node not to do evil" into "mathematically impossible to be malicious". Targon has built a defense depth from the hardware physical bus to the operating system, making it impossible for even anonymous miners with physical data center keys to read model weight files or steal user-transmitted interactive data.This not only fills the huge market gap between "low-cost distributed computing power" and "enterprise-grade compliance data security", but also paves the way for the monetization of high-value closed-source AI models on the open network, thus expanding the customer base to Fortune 500 companies that are extremely sensitive to intellectual property.
In traditional decentralized computing platforms, the role of the platform is often limited to simple resource matching and docking. However, under the macroeconomic framework of Targon and Bittensor, this process undergoes a fundamental transformation: Targon aims to make "high-performance AI computing with privacy attributes" a standardized, quantifiable, and freely tradable scarce "digital commodity". This is not just about providing tools, but building a continuously operating market. Developers can confidently deploy proprietary models worth millions of dollars for commercial gain;Computing power providers (institutional miners) can set their own prices for hardware computing power through the order book, while verifiers use a rigorous cryptographic mechanism to rate the quality of the delivered computing power and allocate tokens. As a result, AI computing has transitioned from a high-risk engineering task to a dynamic digital economic model driven by market incentives and collaborative gameplay among all parties.
In the large ecosystem of Bittensor, which has expanded to 128 active subnets, different subnets undertake functions such as data capture, MultiModal Machine Learning generation, and Model Training. The positioning of Targon (SN4) in this network is increasingly evolving into the industrial-grade underlying "computing sink" and core computing hub of the entire Bittensor ecosystem. Targon not only directly serves external traditional Web2 clients, but also provides computing support for other subnets that lack hardware resources but need to execute advanced logic through its confidential hardware base.
Data isolation and collaboration: Score subnet (SN44), which focuses on tracking competitive sports, runs its exclusive video analysis model in the TEE environment of Targon to protect the privacy of sensitive training videos on the field, avoiding data exposure to the public network.
Logical optimization execution: The Affine subnet (SN120) that deeply cultivates AI inference logic optimization does not host hardware resources, but relies on the Targon network to perform actual inference, forming a perfect value closed loop.
AGI R&D Support: Star project Hone deeply integrates Manifold Labs' underlying architecture capabilities into its core pre-training and fusion framework. Additionally, Targon is even integrated into NousResearch's hermes-agent toolkit, allowing developers to directly call upon its decentralized confidential GPU resources.
Core architecture: How to implement hardware-level trustless confidential computing in a network
In order to fully understand how Targon overcomes the trust bottleneck, we need to thoroughly dismantle its full-stack security defense system, known as the Targon Virtual Machine (TVM).
Targon guarantees data security in a distributed environment without relying on trust, starting from the lowest level of hardware isolation.
Trusted Execution Environment (TEE): A piece of hardware encryption memory area called "Enclave" is carved out inside the main CPU. Even if the highest (Root) permissions of the operating system of the miner node are hacked, it is impossible to read or tamper with the instructions and data being executed in this area.
Hardware compatibility and standard integration: To prevent single-point technology dependence, Targon deeply integrates Intel's Trust Domain Extension (TDX) technology and supports AMD's Secure Encryption Virtualization (SEV-SNP) architecture, and seamlessly integrates with NVIDIA's advanced confidential computing architecture at the core GPU level.
Bus Transport Layer Encryption (PPCIE): To block physical eavesdropping attacks that may be initiated through the main board bus, the network forces the protected PCIe technology to ensure that sensitive data is always wrapped in stream encryption algorithms during the process of transferring from CPU memory to H200 or RTX 4090 through the main board slot, achieving end-to-end hardware-level anti-sniffing.
Due to the extreme profit-seeking and cheating motives of the mining community, Targon cannot allow miners to run arbitrarily tampered with the underlying operating system.
Custom Enhanced System: Manifold Labs has developed and released a highly enhanced custom Linux publish version - TargonOS, specifically for booting encrypted virtual machines on untrusted devices.
TPM-based hardware root of trust: TargonOS introduces a Secure Boot mechanism based on Trusted Platform Module (TPM) to ensure that the underlying system environment has not been tampered with.
Ultimate network communication: At the network layer, through the first cross-language open source network protocol Epistula v2 combined with ultra-low latency technologies such as InfiniBand and RoCE, not only ensures anti-eavesdropping concurrent communication between nodes, but also achieves extremely low response latency (less than 50 milliseconds) and 99% normal operation time, greatly reducing the access friction of external developers.
How can we verify that miners have completed the complex reasoning of a hundred billion parameter model with "zero computing power waste" in a fully distributed architecture? This involves Targon's most innovative deterministic verification design.
Remote Attestation: Before tasks are distributed, miners must submit a cryptographic proof to the network that contains the real-time physical hardware model, the operating system kernel hash value, and the integrity fingerprint of the TVM binary file. After verification by the verifier, it can be confirmed that the miner is using a high-end graphics card (such as H200) that is compliant, rather than a high-level fraud with counterfeit computing power.
Breakthrough of asymmetric computing power: In traditional decentralized networks, if validators are equipped with low-end hardware, they cannot reproduce the complex calculation process of miners to verify their authenticity. Targon's verifier.py core logic cleverly solves this problem: the network supervisor continuously sends synthetic queries and real organic queries to the miner pool.
Logprobs Engine: After completing the inference, miners are forced to return the generated text token sequence and the "logprobabilities" data matrix of each output hidden layer during the calculation process. Lightweight validators only need to mathematically compare the probability distribution of their own maintained benchmark model with the data submitted by miners at the cryptographic level.If the mathematical distribution is highly consistent and the response time is less than the low-end hardware limit, the verifier can obtain 100% certainty from the statistical dimension that the miner has indeed executed the real reasoning calculation from scratch, instantly exposing any attempt to call the cache or tamper with the small model.
Incentive and Competitive Mechanism: How AI Computing Forms a "Positive Loop" in Macroeconomics
The life cycle of the Bittensor network and the scheduling of computing power are highly dependent on its underlying token economics design. In December 2025, Bittensor experienced its first halving of production, reducing the daily publish quantity of the base token TAO from 7,200 to 3,600, significantly reducing the inflation rate to 13%, and maintaining a hard cap supply limit of 21 million. The dynamic TAO (dTAO) mechanism launched in February 2025 completely revolutionized the survival rules of the subnet.It introduces Automated Market Maker (AMM), abolishes the legacy model of subjective allocation of inflation rewards by a fixed verifier committee, and switches to free market capital voting. The system publishes a dedicated Alpha token (asset code SN4) for Targon. Investors can mint or exchange SN4 by staking the base layer TAO, forming a deep dual-token liquidity reserve. The real-time relative price and total market capitalization of the SN4 token directly determine how much of the incentive dividend Targon can capture from the TAO issuance pool every day.
In order to avoid the inertia trap of miners "lying flat and earning tokens" once they reach the benchmark performance, the Targon team completely rewrote the reward logic in the v3 version iteration, abandoning the gentle plateau income curve and introducing an extremely steep "exponential curve". Under this mechanism:
Comprehensive performance evaluation: The verifier strictly monitors the absolute latency, concurrency, and throughput of the miner's hardware in real time.
Winner takes all: Only the top hardware nodes at the top of the leaderboard that can stably handle massive concurrent requests can obtain the exponentially magnified Yuma consensus score and excess rewards.
Strict anti-cheating penalties: Any cheater who attempts to artificially accelerate the response by tampering with the TVM sampling parameters will be instantly caught during the log probability comparison stage, and their score will be set to zero (excluding from scoring) and will face severe penalties such as demotion or expulsion from the network. This extremely competitive arms race forces miners to continuously invest real money in upgrading top-tier GPU devices and optimizing backbone internet bandwidth, strengthening the hardware foundation of Targon.
Decentralized networks have long been criticized for being "revenue deserts", which means they rely too much on token inflation to subsidize network participants. Once the subsidies stop, business customers who have been using computing power for free will instantly leave. To ensure long-term survival, Manifold Labs has implemented a highly forward-thinking reform in the industry:
70% Inflation Burn: The management team has forced the opening of the distribution valve, resulting in the direct destruction or isolation of up to 70% of the subnet TAO issuance, preventing it from entering the market.
Controlling the equilibrium point of fiat currency: By reducing circulation, the subsidy income of top network miners (such as H200 nodes) is precisely controlled at a reasonable level of about $2.80/hour. This meager but healthy profit just covers the depreciation of miners' equipment, installment interest, and electricity costs, filtering out those short-term arbitrageurs who are ready to flee at any time, and ultimately ensuring that the miner's reward is fully supported by external real corporate dollar income.
Order Book Mechanism: Abolish the inflexible command economy model where prices are set by the agreement, and return the pricing power to the computing power providers. Miners can set their own ask prices for high-end hardware, and even sign fixed-term contracts with guarantees of collateral and normal operation time. This series of mechanisms has completely marginalized retail miners who relied on leasing and reselling in the early days, attracting real institutional miners with their own data centers and extremely low capital costs to take over the computing power supply side, greatly improving the commercial resilience of the Targon network.
Ecosystem status and business penetration
The participant ecosystem of Targon is fundamentally different from many subnetworks that are still in the Proof of Concept (PoC) stage. It has already built a solid barrier in the real business world.
Requirements and Verifier (Enterprise Adoption): The most iconic business breakthroughs come from the well-known AI role-playing technology company Dippy AI. Dippy AI has a huge client base of over 8.6 million on the mobile end, facing billions (10B) of basic token interaction requests every day. Faced with huge operation and maintenance costs, Dippy AI chose to terminate the contract with the centralized cloud provider and migrate the entire backend reasoning chain to the Targon network. This six-figure epic agreement not only increased Targon's total external revenue to approximately $10.4 million per year, but also proved to the industry that after migrating to Targon, large enterprises can structurally reduce total expenses by 20% to 35% while maintaining decentralized flexibility.
Full stack ecosystem matrix (Manifold 2.0): In March 2025, Manifold Labs launched an ecosystem matrix covering multidimensional applications, including the decentralized hybrid AI search engine Sybil (realizing millisecond-level censorship-resistant network data capture) and the exclusive blockchain network monitoring advanced end point tool Tao.xyz, greatly enriching the developer experience and data transparency within the ecosystem.
Based on the dTAO system architecture and the latest on-chain macroeconomic reference data up to 2026, Targon has demonstrated strong capital and liquidity retention capabilities in the free market
Market value and currency price: The price of the core asset SN4 is stable in the range of about $18.39 to $19.07, with a total market value of $85.10M to $91.80M, ranking among the top three in the 128 active subnets of the entire network, demonstrating a deep institutional capital consensus.
Deflation mechanism: Under the maximum 21 million hardcap supply structure, the circulation is maintained at 4.41M to 4.46M, and about 442,300 tokens have been permanently destroyed (Burned) through the token economics regulation mechanism, which has strong anti-inflation properties.
Liquidity Structure Pool: Its AMM trading pool has accumulated a base reserve liquidity of $42.25 million (over 130,000 TAO and 2.22 million Alpha), providing a safety cushion for large institutions to build large positions or pledge, avoiding sharp price slippage.
Pledge and Return on Investment: A large number of tokens in the market are in a pledged and locked state (over 2.25 million SN4). The annual cash flow return rate provided by top validators (such as MUV and Tatsu nodes) to pledgers is stable at 8.40% to 9.61%, making it a better investment than traditional Web2 fixed-income assets.
Competition landscape and multidimensional vulnerability game
In the highly competitive decentralized AI reasoning and computing track, Targon's positioning is clear and defensive. It has skillfully avoided the red ocean and entered the most profitable core track in the current AI supply chain: enterprise compliance and trust mechanisms. The increasingly stringent European and American data privacy compliance laws have caused extreme panic among traditional enterprises regarding the adoption of decentralized networks for intellectual propertyTargon's full stack of software and hardware isolation and zero-trust verification design make it the almost only safe and feasible channel for high-net-worth clients to enter the decentralized network, forming a rare structural monopoly.
Looking at the entire ecosystem, Targon is facing siege and challenges from many different technical paths:
Comparison with Chutes (SN64): Chutes focuses on serverless platforms and extremely low pricing, with a current market value of over $132 million. It has amassed a large number of long-tail developers and provides an experience closest to traditional Web2. However, its fatal flaw is the lack of hardware-level confidential computing isolation guarantees, making it completely incapable of handling the influx of sensitive data from large traditional enterprises, limiting its potential.
Comparison with Templar (SN3): Templar is deeply involved in the extreme pre-training infrastructure of distributed large language models, with strong narrative tension. However, its R&D burn rate is extremely high, and it lacks a clear and mature large-scale commercial revenue realization loop like Targon in the short term.
Compared to Lium (SN51): The ultra-high density H100 bare-metal physical cluster leasing for institutions has a large computing power reserve. However, it is far less robust than Targon's TVM ecosystem in terms of Competitive Edge depth and cutting-edge cryptography technology added value. Overall, Targon's advantage lies in the monopoly breakthrough point of compliance data and the closed-loop of over ten million dollars in real revenue; while its potential disadvantage lies in its strict military-grade hardware access threshold, which to some extent restricts the disorderly and rapid expansion of network miners.
Despite the impressive ecosystem construction, Targon and the entire underlying network still face a huge systemic survival test:
Validator Cartel and Power Monopoly: The current Achilles heel of the Bittensor system is the over-centralization of proof-of-stake based on the Yuma consensus. The vast majority of staking weights are controlled by institutional capital giants (such as Yuma Asset Management). These super validators may abuse weights and use cartel collusion such as "weight-copying" to intervene in the scoring system and maliciously extract inflationary rewards from the network.Despite the continuous release of patches by the official, the anti-conspiracy reform of the governance system is still a sword of Damocles hanging over our heads.
The death spiral of macro subsidies drying up: As the next output milestone in 2029 approaches, Targon has generated over 10 million in revenue and voluntarily burned a large amount of emissions. However, compared to its annual consumption of up to 18 million dollars in system subsidies, it has not yet achieved complete "net blood production". If the future tightening of the crypto-macro cycle leads to the collapse of the token-to-fiat price, and institutions that cannot pay H200 installment loans go offline in large numbers, it is likely to trigger a vicious cycle of liquidity collapse and user churn.
Geopolitical extortion of Silicon Valley's chip hegemony: While decentralized clouds are resistant to censorship in terms of physical distribution, the core TEE isolation area relies heavily on the underlying firmware and architecture authorization of the single chip oligarch NVIDIA (H100/H200). Against the backdrop of intensified global semiconductor export controls, if hardware giants unilaterally block interface protocols, Targon's protective barrier will face the threat of paralysis. Accelerating the compatibility compilation to non-NVIDIA camp standards is also its highest priority survival game.
Future Outlook: Can the decentralized trust hub for reshaping the Relations Of Production be established?
Through deep deconstruction, it can be found that Targon (SN4) has far exceeded its early narrow positioning of "distributed computing power pool", transforming into a massive enterprise-level cryptographic agent driven by rigorous mathematical probability verification, hardware-level trust isolation, and a brutal token game engine. It stands out with its advantages in the battle of offense and defense full of fraud and gameplay.
From the current stage, whether the large-scale monetization of the decentralized confidential cloud can be sustained depends on whether the external income of the network can exceed the rate of token inflation. Targon has irrefutably proven to traditional finance and tech giants for the first time through the huge order of Dippy AI: the decentralized architecture is fully capable of defeating the traditional Cloud as a Service in terms of cost-effectiveness, while providing an underlying technology guarantee that centralized giants can never reach in terms of maintaining data privacy sovereignty.
In the next few years leading to the era of Artificial General Intelligence (AGI), with the full opening of traditional compliance channels such as Grayscale trust ETFs, and the exponential increase in global corporate anxiety about AI model intellectual property rights, Targon's zero-trust business paradigm has a strong tailwind of the times.Despite the challenges ahead - facing the abyss of dealing with cartelization and the containment of cross-border chip supply chains, Targon has irreversibly reshaped the production and trust boundaries of decentralized AI in the history of human intelligent computing distribution by leveraging the advantages of cryptography.