Demo: Indelebile — the Justice Journal, written into Ethereum itself
From a $JUSTICE holder, not the core team. MIT licensed. Everything below is deployed and can be checked.
Try it: https://indelebile.xyz · Code: GitHub - indelebile/indelebile: Writing that cannot be erased — an AssangeDAO journal on Ethereum calldata, owned by its authors. · GitHub
@Logan proposed the Justice Journal here in May 2025, and @zylo_eth said in September that he liked the name. I did not want to take a name someone else had claimed, so this is called Indelebile — Italian for indelible. It is an implementation of Logan’s proposal, with two parts of the technical design changed. I built it to find out whether the design would work. It does, but not as specified, and the two failures are hard to see on paper and obvious once code touches the chain.
It also answers something from the AIP-18 discussion. One of @zylo_eth’s candidate mission statements speaks of resisting the erasure of the record. An archive that depends on someone continuing to pay a pinning bill does not resist erasure; it postpones it. This is an attempt at the stronger version — and the first entry, below, is a case of that erasure already happening to this DAO, this year.
What it does
You write up to 500 characters. The text goes into Ethereum L1 calldata — not IPFS, not a server — and is minted as an ethscription owned by you. There is nothing to renew, nothing to unpin, and nobody who can quietly delete it, including us.
- Hold $JUSTICE and connect a wallet
- Write, preview the exact bytes, sign
- The entry appears in the archive, owned by your address
1. The proposed design would have given the DAO ownership of every entry
The Ethscriptions protocol has one rule that decides this: the recipient of a transaction owns what it inscribes.
The original proposal routes the write fee by having the author send to the treasury. Under that rule the treasury becomes the owner of every entry — the author writes their testimony and the DAO holds title to it.
The fix is a small contract. ESIP-3 lets a contract name the initial owner, which is the only construction that collects a fee and leaves the author owning their words. That is the only reason there is a contract at all; it stores nothing, has no owner, and cannot be upgraded.
Confirmed on Ethereum mainnet. Ethscription #16251113, written through the contract, is reported by the canonical Ethscriptions indexer as:
creator 0x3f06f46f… the contract, as ESIP-3 specifies
initial_owner 0xeb4745c5… the author — not the contract, not the treasury
esip6 true
2. The archive would have depended on a recurring invoice
Content on IPFS survives only while someone keeps paying to pin it. When the pin lapses the chain holds Qm… and nothing readable. A project about resisting censorship should not custody its archive with a company that can be served with a court order.
So the text itself goes into calldata.
Honest limit: under EIP-4444 ordinary nodes may eventually stop serving old history, so retrieval will depend on archive nodes. Far stronger than an IPFS pin, but not “free forever.”
The first entry is this DAO’s own mission statement
Not as an illustration. Because it is already being lost.
The mission statement as the site carried it in March 2022 had three sentences. The one on assangedao.org today has dropped the middle one — the sentence about raising funds for legal fees and for campaigns on the systemic failure of our justice systems. The version quoted in the AIP-18 thread as “current mission” has kept that sentence but dropped the third, the one about cypherpunks rallying to a fellow cypherpunk. All three sentences together now exist only in an archived snapshot:
Nobody deleted anything. Sites get rebuilt, copy gets rewritten, and a sentence falls out. That is how a record actually goes — not seized, just quietly not carried forward. And AIP-18 is about to replace these words entirely.
So entry #0 is the 2022 text, all three sentences, written where the DAO itself cannot edit it: ethscription #16251571
3. It is cheaper, not more expensive
Calibrated against a real transaction, not estimated.
| entry | gas | @1 gwei | @5 gwei |
|---|---|---|---|
| 113 characters, English | 41,233 | 0.000041 ETH | 0.000206 ETH |
| 500 characters, Chinese | 83,950 | 0.000084 ETH | 0.000420 ETH |
| the original IPFS design | 90,000–110,000 | — | plus annual pinning |
The IPFS line item disappears. The storage contract disappears. The audit surface is ~110 lines of Solidity.
What is added instead: the indexer becomes the protocol. Nothing on chain marks a Journal entry apart from any other calldata — the rules do. So the rules have to be open source, reproducible, and checkable by a stranger. They are: a clean clone rebuilds the archive byte for byte, 28 conformance vectors let a second implementation prove it agrees rather than be asked to trust ours, and the site itself is rebuilt from the chain every ten minutes by a public job whose log anyone can read.
This is a transfer of cost and risk, not an elimination of it.
How this relates to the Freedom Wall
They are not the same thing and I do not think one replaces the other.
| Freedom Wall | Indelebile | |
|---|---|---|
| length | 140 characters | 500 |
| stored in | contract storage | calldata |
| the message is | a row in a contract | an ethscription you own |
| fee | 10,000 $JUSTICE to the treasury | 0.001 ETH, swept to the treasury |
A wall is for a short public shout. This is for the longer thing somebody wants kept — and for keeping it in a form the author holds title to.
4. On the fee
The original proposal charges 1,000 $JUSTICE. An ERC-20 fee needs approve() first — two transactions and a poor first experience.
This charges 0.001 ETH and converts accumulated fees to $JUSTICE in batches, through a permissionless sweep whose destination is immutable: anyone can trigger it, nobody can redirect it.
The deployed contract pays assangedao.eth — the DAO’s existing 3-of-9 Safe, the same address the Freedom Wall and The Ledger already pay. Nobody, including whoever deployed the contract, can change that destination. If the DAO prefers a different one, that is a redeployment: a public act, not a quiet edit, and the archive carries across both contracts.
One finding the DAO should weigh: the deployed contract carries no router, so sweepAndBuy is inert and sweepEth() — permissionless, immutable destination — is the way out. Fees accumulate as ETH until the DAO moves them.
That is deliberate rather than a limitation. sweepAndBuy speaks the Uniswap V2 interface, and the V2 pair is thin: as of 3 October it holds 0.104 WETH, where converting 0.003 ETH costs 3.1% in slippage and 0.05 ETH costs 32.7%. The real liquidity — about $81,000 — sits in a V3 1% pool that this interface cannot reach, and which the DAO’s own swap demo already uses. Holding fees as ETH leaves the DAO free to convert where and when it chooses, rather than committing the design to the worse of two pools.
Also worth knowing: 100,000 $JUSTICE — the holding gate the original proposal specifies — is currently worth about $9.17. Two weeks ago it was $2.29; the token has moved sharply. Either way the gate is close to no barrier, and the fee is doing all of the anti-spam work.
5. Who pays for this
A fair question, and the answer is not “nobody”.
The original proposal budgets a backend and indexer at $3,000–6,000 to build plus $500–1,000 a year to host, an IPFS pinning line of $500–1,500 a year, and frontend hosting at $500–1,000 a year. An indexer is not something this design adds — both designs need one. What changes is everything around it.
There is no server in this architecture. The write page is static HTML and JavaScript: your wallet talks to Ethereum directly, and nothing passes through a machine of ours. The indexer is a batch job, not a daemon — it reads the chain, writes one JSON file, and exits.
| today | if the DAO wants independence from GitHub | |
|---|---|---|
| page hosting | GitHub Pages, free for public repos | $5–20 a month for a small VPS |
| running the indexer | GitHub Actions, free for public repos | cron on that same machine |
| RPC access | public endpoints suffice | a paid tier if the archive grows large |
| domain | ~$12 a year, which I pay | the same |
| content storage | none — it is already in calldata | none |
So: one to two orders of magnitude cheaper, and optional — not free. Free is GitHub’s policy for public repositories, not a law of physics, and policies change.
The cost can also be carried by several people at once. The indexer is open source and reproducible, so the DAO can run a copy, and so can anyone else. Every copy must produce the same hash; if one does not, somebody has a bug. That is not redundancy, it is mutual verification.
But the real difference is what happens when the money stops. When an IPFS pin lapses, the content is gone. If this site goes dark — my domain expires, my account is suspended, I lose interest — the archive is untouched on L1, and anyone can clone the repository and rebuild it byte for byte. What the DAO would be paying for here is a convenient view of the archive, not custody of it.
If the DAO adopts this, I will transfer the domain and the GitHub organisation to the DAO’s multisig. Until then I cover it, and it is about twelve dollars. The archive’s survival does not depend on that transfer happening.
6. What is built, and what is not
Built: the contract, the indexer, the write page, the archive view, a view of your own entries, tag and date filtering, the holding gate, the fee, local validation before signing, reproducibility, conformance vectors.
Not built: share cards, Twitter and Telegram posting, likes, monthly challenges, Snapshot integration, referral rewards, curation, profiles, ENS, ZK log-ins. Moderation exists as a mechanism but is not wired to a vote.
That distribution is deliberate. Everything irreversible is done; everything deferred is additive. The data format, the ownership model and the validity rules cannot be changed once entries exist. Share cards can be added three years later without touching a single entry.
7. Decisions I have deliberately not made
| Decision | Why it matters | |
|---|---|---|
| D-1 | Rewards, and therefore the fee | Gas already deters casual junk. The open question is whether to pay for the act of writing, or only for entries the community elects. My recommendation, with the arithmetic, is in the repository: pay nothing per entry, reward only what the community singles out. |
| D-2 | Transferability by default | Tradable entries invite flip bait, which works against an archive. Soulbound with an author opt-in unlock is one option. |
| D-3 | Rate limit | Three entries per author per week is a placeholder. |
| D-4 | The worst entry | Someone will inscribe something illegal. On IPFS you could unpin; here you cannot. This needs an answer before launch — it is the strongest objection to the whole approach. |
8. What I am asking for
Not a budget. The prototype exists and is MIT licensed; take it, fork it, or discard it.
- Scrutiny of §1 and §3. If the ownership analysis is wrong, the whole design is wrong, and I would rather learn that here.
- A decision on §7, particularly D-4.
- A second implementation of the indexer. The conformance vectors make it checkable; someone actually writing one is the only thing that proves the specification is complete. Us writing it twice would not count.
Evidence
| Live | https://indelebile.xyz |
|---|---|
| Code | GitHub - indelebile/indelebile: Writing that cannot be erased — an AssangeDAO journal on Ethereum calldata, owned by its authors. · GitHub (MIT) |
| Contract | 0x064A64cf…6FE8ef, fees to assangedao.eth, no owner, no upgrade path |
| First entry | the 2022 mission statement → ethscription #16251571; the author owns it, esip6 true |
| Ownership proof | the rehearsal entry 0xdf4f13fb… → #16251113 |
| Reproducibility | a clean clone rebuilds the archive byte for byte |
| Tests | 82 JavaScript, 23 Solidity, 28 conformance vectors |
The specification, the requirements audit against Logan’s original proposal, the protocol findings and the deployment runbook are all in the repository.
The archive holds one entry: the DAO’s own words from 2022. Everything before it ran under a separate protocol tag that the production rules reject outright. What goes in next is not mine to decide.