Demo: Indelebile — the Justice Journal, written into Ethereum itself

Demo: Indelebile — the Justice Journal, written into Ethereum itself

From a $JUSTICE holder, not the core team. MIT licensed. Everything below is deployed and can be checked.

Try it: https://indelebile.xyz · Code: GitHub - indelebile/indelebile: Writing that cannot be erased — an AssangeDAO journal on Ethereum calldata, owned by its authors. · GitHub


@Logan proposed the Justice Journal here in May 2025, and @zylo_eth said in September that he liked the name. I did not want to take a name someone else had claimed, so this is called Indelebile — Italian for indelible. It is an implementation of Logan’s proposal, with two parts of the technical design changed. I built it to find out whether the design would work. It does, but not as specified, and the two failures are hard to see on paper and obvious once code touches the chain.

It also answers something from the AIP-18 discussion. One of @zylo_eth’s candidate mission statements speaks of resisting the erasure of the record. An archive that depends on someone continuing to pay a pinning bill does not resist erasure; it postpones it. This is an attempt at the stronger version — and the first entry, below, is a case of that erasure already happening to this DAO, this year.

What it does

You write up to 500 characters. The text goes into Ethereum L1 calldata — not IPFS, not a server — and is minted as an ethscription owned by you. There is nothing to renew, nothing to unpin, and nobody who can quietly delete it, including us.

  1. Hold $JUSTICE and connect a wallet
  2. Write, preview the exact bytes, sign
  3. The entry appears in the archive, owned by your address

1. The proposed design would have given the DAO ownership of every entry

The Ethscriptions protocol has one rule that decides this: the recipient of a transaction owns what it inscribes.

The original proposal routes the write fee by having the author send to the treasury. Under that rule the treasury becomes the owner of every entry — the author writes their testimony and the DAO holds title to it.

The fix is a small contract. ESIP-3 lets a contract name the initial owner, which is the only construction that collects a fee and leaves the author owning their words. That is the only reason there is a contract at all; it stores nothing, has no owner, and cannot be upgraded.

Confirmed on Ethereum mainnet. Ethscription #16251113, written through the contract, is reported by the canonical Ethscriptions indexer as:

creator        0x3f06f46f…   the contract, as ESIP-3 specifies

initial_owner 0xeb4745c5… the author — not the contract, not the treasury

esip6 true

2. The archive would have depended on a recurring invoice

Content on IPFS survives only while someone keeps paying to pin it. When the pin lapses the chain holds Qm… and nothing readable. A project about resisting censorship should not custody its archive with a company that can be served with a court order.

So the text itself goes into calldata.

Honest limit: under EIP-4444 ordinary nodes may eventually stop serving old history, so retrieval will depend on archive nodes. Far stronger than an IPFS pin, but not “free forever.”

The first entry is this DAO’s own mission statement

Not as an illustration. Because it is already being lost.

The mission statement as the site carried it in March 2022 had three sentences. The one on assangedao.org today has dropped the middle one — the sentence about raising funds for legal fees and for campaigns on the systemic failure of our justice systems. The version quoted in the AIP-18 thread as “current mission” has kept that sentence but dropped the third, the one about cypherpunks rallying to a fellow cypherpunk. All three sentences together now exist only in an archived snapshot:

Nobody deleted anything. Sites get rebuilt, copy gets rewritten, and a sentence falls out. That is how a record actually goes — not seized, just quietly not carried forward. And AIP-18 is about to replace these words entirely.

So entry #0 is the 2022 text, all three sentences, written where the DAO itself cannot edit it: ethscription #16251571

3. It is cheaper, not more expensive

Calibrated against a real transaction, not estimated.

entry gas @1 gwei @5 gwei
113 characters, English 41,233 0.000041 ETH 0.000206 ETH
500 characters, Chinese 83,950 0.000084 ETH 0.000420 ETH
the original IPFS design 90,000–110,000 — plus annual pinning

The IPFS line item disappears. The storage contract disappears. The audit surface is ~110 lines of Solidity.

What is added instead: the indexer becomes the protocol. Nothing on chain marks a Journal entry apart from any other calldata — the rules do. So the rules have to be open source, reproducible, and checkable by a stranger. They are: a clean clone rebuilds the archive byte for byte, 28 conformance vectors let a second implementation prove it agrees rather than be asked to trust ours, and the site itself is rebuilt from the chain every ten minutes by a public job whose log anyone can read.

This is a transfer of cost and risk, not an elimination of it.

How this relates to the Freedom Wall

They are not the same thing and I do not think one replaces the other.

Freedom Wall Indelebile
length 140 characters 500
stored in contract storage calldata
the message is a row in a contract an ethscription you own
fee 10,000 $JUSTICE to the treasury 0.001 ETH, swept to the treasury

A wall is for a short public shout. This is for the longer thing somebody wants kept — and for keeping it in a form the author holds title to.

4. On the fee

The original proposal charges 1,000 $JUSTICE. An ERC-20 fee needs approve() first — two transactions and a poor first experience.

This charges 0.001 ETH and converts accumulated fees to $JUSTICE in batches, through a permissionless sweep whose destination is immutable: anyone can trigger it, nobody can redirect it.

The deployed contract pays assangedao.eth — the DAO’s existing 3-of-9 Safe, the same address the Freedom Wall and The Ledger already pay. Nobody, including whoever deployed the contract, can change that destination. If the DAO prefers a different one, that is a redeployment: a public act, not a quiet edit, and the archive carries across both contracts.

One finding the DAO should weigh: the deployed contract carries no router, so sweepAndBuy is inert and sweepEth() — permissionless, immutable destination — is the way out. Fees accumulate as ETH until the DAO moves them.

That is deliberate rather than a limitation. sweepAndBuy speaks the Uniswap V2 interface, and the V2 pair is thin: as of 3 October it holds 0.104 WETH, where converting 0.003 ETH costs 3.1% in slippage and 0.05 ETH costs 32.7%. The real liquidity — about $81,000 — sits in a V3 1% pool that this interface cannot reach, and which the DAO’s own swap demo already uses. Holding fees as ETH leaves the DAO free to convert where and when it chooses, rather than committing the design to the worse of two pools.

Also worth knowing: 100,000 $JUSTICE — the holding gate the original proposal specifies — is currently worth about $9.17. Two weeks ago it was $2.29; the token has moved sharply. Either way the gate is close to no barrier, and the fee is doing all of the anti-spam work.

5. Who pays for this

A fair question, and the answer is not “nobody”.

The original proposal budgets a backend and indexer at $3,000–6,000 to build plus $500–1,000 a year to host, an IPFS pinning line of $500–1,500 a year, and frontend hosting at $500–1,000 a year. An indexer is not something this design adds — both designs need one. What changes is everything around it.

There is no server in this architecture. The write page is static HTML and JavaScript: your wallet talks to Ethereum directly, and nothing passes through a machine of ours. The indexer is a batch job, not a daemon — it reads the chain, writes one JSON file, and exits.

today if the DAO wants independence from GitHub
page hosting GitHub Pages, free for public repos $5–20 a month for a small VPS
running the indexer GitHub Actions, free for public repos cron on that same machine
RPC access public endpoints suffice a paid tier if the archive grows large
domain ~$12 a year, which I pay the same
content storage none — it is already in calldata none

So: one to two orders of magnitude cheaper, and optional — not free. Free is GitHub’s policy for public repositories, not a law of physics, and policies change.

The cost can also be carried by several people at once. The indexer is open source and reproducible, so the DAO can run a copy, and so can anyone else. Every copy must produce the same hash; if one does not, somebody has a bug. That is not redundancy, it is mutual verification.

But the real difference is what happens when the money stops. When an IPFS pin lapses, the content is gone. If this site goes dark — my domain expires, my account is suspended, I lose interest — the archive is untouched on L1, and anyone can clone the repository and rebuild it byte for byte. What the DAO would be paying for here is a convenient view of the archive, not custody of it.

If the DAO adopts this, I will transfer the domain and the GitHub organisation to the DAO’s multisig. Until then I cover it, and it is about twelve dollars. The archive’s survival does not depend on that transfer happening.

6. What is built, and what is not

Built: the contract, the indexer, the write page, the archive view, a view of your own entries, tag and date filtering, the holding gate, the fee, local validation before signing, reproducibility, conformance vectors.

Not built: share cards, Twitter and Telegram posting, likes, monthly challenges, Snapshot integration, referral rewards, curation, profiles, ENS, ZK log-ins. Moderation exists as a mechanism but is not wired to a vote.

That distribution is deliberate. Everything irreversible is done; everything deferred is additive. The data format, the ownership model and the validity rules cannot be changed once entries exist. Share cards can be added three years later without touching a single entry.

7. Decisions I have deliberately not made

Decision Why it matters
D-1 Rewards, and therefore the fee Gas already deters casual junk. The open question is whether to pay for the act of writing, or only for entries the community elects. My recommendation, with the arithmetic, is in the repository: pay nothing per entry, reward only what the community singles out.
D-2 Transferability by default Tradable entries invite flip bait, which works against an archive. Soulbound with an author opt-in unlock is one option.
D-3 Rate limit Three entries per author per week is a placeholder.
D-4 The worst entry Someone will inscribe something illegal. On IPFS you could unpin; here you cannot. This needs an answer before launch — it is the strongest objection to the whole approach.

8. What I am asking for

Not a budget. The prototype exists and is MIT licensed; take it, fork it, or discard it.

  1. Scrutiny of §1 and §3. If the ownership analysis is wrong, the whole design is wrong, and I would rather learn that here.
  2. A decision on §7, particularly D-4.
  3. A second implementation of the indexer. The conformance vectors make it checkable; someone actually writing one is the only thing that proves the specification is complete. Us writing it twice would not count.

Evidence

Live https://indelebile.xyz
Code GitHub - indelebile/indelebile: Writing that cannot be erased — an AssangeDAO journal on Ethereum calldata, owned by its authors. · GitHub (MIT)
Contract 0x064A64cf…6FE8ef, fees to assangedao.eth, no owner, no upgrade path
First entry the 2022 mission statement → ethscription #16251571; the author owns it, esip6 true
Ownership proof the rehearsal entry 0xdf4f13fb… → #16251113
Reproducibility a clean clone rebuilds the archive byte for byte
Tests 82 JavaScript, 23 Solidity, 28 conformance vectors

The specification, the requirements audit against Logan’s original proposal, the protocol findings and the deployment runbook are all in the repository.

The archive holds one entry: the DAO’s own words from 2022. Everything before it ran under a separate protocol tag that the production rules reject outright. What goes in next is not mine to decide.

On D-4 — the worst entry.

I said this was the strongest objection to the whole approach and that it needed an answer before launch. Here is the answer I would propose, so that it is on the table rather than deferred.

The obvious answer is keyword filtering in the indexer. I think it is the wrong one, for two reasons.

Anyone who pays gas to inscribe something harmful is deliberate. A link, an encoded blob, or a changed spelling defeats any word list — it catches the careless and misses the rest. And a list that fires on violence, rape or child catches the testimony this archive exists for before it catches anything else. The material WikiLeaks published is a record of war crimes, torture and abuse. A rule that cannot tell an account of an atrocity from the atrocity will collapse the account.

So moderation stays what it was — a display overlay — and gains the thing it was missing, which is accountability:

  • Five enumerated grounds, exhaustive: sexual content involving a minor; personal data of a private individual; credentials; a direct call for violence against a named person; content named in a specific legal demand. Testimony about atrocity is explicitly not one of them.
  • A collapse hides the text in this viewer only. The entry stays in the index, carries its author and block, says that it was collapsed — by whom, when, on which ground — and links to its raw calldata.
  • An emergency path, limited to the three grounds that cause harm in hours: two stewards may act immediately, must publish the action at the time they take it, and the collapse is reversed if the next vote does not ratify it. Until then the viewer shows it as unratified.
  • hidden.json is in the repository, so every change is a commit. The history of moderation is as public and as permanent as the entries it covers.
  • A flagging script prints a review queue and cannot hide anything. A test fails if it ever gains the ability to write. Most of its signal is structural — keys, addresses, links, encoded blobs — because shape survives disguise better than vocabulary.

Full text, written to be voted on or amended rather than adopted by me: indelebile/MODERATION.md at main · indelebile/indelebile · GitHub

What this does not do: nothing makes an entry go away. The content stays on Ethereum, anyone can rebuild the archive from the chain, and other viewers may show what this one collapses. That is the same property that keeps the archive alive if this project disappears — it cannot be had in one direction only. A collapse makes this site stop repeating something, with a record of who decided that and why. Anyone promising more than that is describing a different system.

Two things added since posting, both aimed at the same question — why anyone should connect a wallet to a page a stranger built.

The contract’s source is now verified, and Sourcify reports an exact match on both creation and runtime bytecode: what is in the repository is what is deployed.

Which means you do not have to use my page at all. The write is a single call to a verified contract; Etherscan’s own Write Contract tab does the same thing, with no code of mine between your wallet and the chain. The page is a convenience, and it should be treated as one.

Worth knowing either way, since it is the same for any dApp: the page asks for no signatures and no token approvals — the holding gate is a read-only balance check, so the contract can never move your $JUSTICE. The only transaction it builds has a fixed recipient and a fixed value, both visible in the wallet prompt before you sign.

And rebuilding the archive yourself now has a step-by-step page, including which public RPC endpoints will actually serve these queries — of seven I tested, two will — and what to check first when a hash does not match: