01 / Private Inference
vLLM in the enclave
Buyers send encrypted models and/or prompts; decryption happens only inside the enclave. Outputs return with an attestation hash proving sealed execution billed per call over x402.
GHOST COMPUTE / GHST
A GPU network on Solana where every job runs inside a layered privacy envelope TEE, ZK, MPC and FHE powering private inference and a confidential dark pool.
Thesis
Compute networks lack privacy. Privacy protocols lack compute. Ghost Compute fuses both into a single permissionless confidential GPU network.
Envelope
Hardware confidentiality, remote attestation, TOPLOC/ZK output proofs, and MPC/FHE trust-split composed per job. No single mechanism is trusted alone.
Substrate
Private inference via x402 and a confidential dark-pool matching engine run on the same GPU network proving both halves of the thesis with the same hardware.
Token
Solana SPL Token-2022. Confidential compute rewards, fee discounts, dark-pool access tiers, buyback and burn value scales with the union of both economies.
// Confidential substrate
Ghost Compute pairs NVIDIA Confidential Computing and AMD SEV-SNP hardware with TEE attestation, ZK output proofs, Arcium MPC and FHE orchestrated per job. Workloads land on a permissionless GPU network where the operator never sees plaintext.
95 99%
H100/H200 CC of native speed
4 layers
TEE · Attest · ZK · MPC/FHE
x402
Agent pay-per-call inference
Fail-closed
Attestation lapse halts job
Privacy envelope
// The privacy envelope
Jobs run inside NVIDIA CC (H100/H200/Blackwell) or AMD SEV-SNP enclaves. Weights, inputs and outputs are encrypted in use; OS and hypervisor never see plaintext.
Remote attestation rooted in vendor PKI proves a genuine enclave ran the expected code. TOPLOC or ZK commits to correct output without revealing model or input.
Highest-guarantee jobs split sensitive sub-computations across Arcium-style MPC so no single node not even one enclave sees complete data. FHE runs flagged ops on ciphertext directly.
// Flagship applications
Private inference, a confidential dark pool, and a public attestation explorer all run on the same Ghost Worker network proving the privacy guarantee end to end, without leaking what was computed.
01 / Private Inference
Buyers send encrypted models and/or prompts; decryption happens only inside the enclave. Outputs return with an attestation hash proving sealed execution billed per call over x402.
02 / Confidential Dark Pool
Orders are encrypted client-side to the matching enclave. Only cleared fills are revealed; resting book stays sealed. MEV-proof execution via Jito bundles, settlement via Confidential Balances.
03 / Attestation Explorer
Anyone can verify network attestation health, worker reputation, and per-job receipts onchain without an account, and without revealing what was computed. The credibility engine for "private."
// Inside the substrate
Five subsystems Confidential Worker runtime, layered Privacy Envelope, Private Inference, Dark-Pool Engine, and six Solana Anchor programs coordinated by an onchain control plane. Everything fails closed: a broken attestation halts the job rather than leaking plaintext.
// The product surfaces
The Ghost Compute frontend serves three audiences across the substrate and its two flagship apps confidential GPU contributors, buyers of private inference and dark-pool execution, and a public trust surface that anyone can verify without an account.
// Supply surface
A <12MB Tauri 2 app for Win/Mac/Linux. Three clicks to confidential earning: install, connect wallet, run the capability probe the app detects GPU, VRAM, TEE vendor and runs a live attestation check.
// Demand surface
vLLM running inside the enclave, callable over x402. Payloads are sealed client-side to the enclave pubkey. Every response carries the attestation hash, guarantee level, and a verifiable proof the prompt was never exposed.
// Anti trading-terminal
Price, size and side are encrypted client-side to the matching enclave. Traders see only their own orders and fills; the book is sealed. Each fill carries an MEV-proof badge and lands via Jito bundles, settled in Confidential Balances.
// Public trust surface
A public, SEO-indexed explorer where anyone can verify Ghost Compute's confidentiality without an account live network attestation health, worker reputation, and per-job receipts, all onchain, identities withheld.
// Two halves
Every other Solana compute network exposes the workload to the operator. Every privacy project consumes compute it does not own. Ghost Compute is the only network where confidential compute is the product and privacy is the default not a feature flag.
// Why now May 2026
Confidential GPUs just crossed the threshold where privacy costs almost nothing in performance. At the same moment, Solana's privacy narrative is sharpening Confidential Balances live, Arcium-powered apps shipping, buy-side firms paying to own private execution.
0 99% of native speed.
H100 / H200 CC protects weights + inputs with negligible overhead Phala / NVIDIA verified.
Private fine-tuning, minimal overhead.
RTX PRO 6000 Blackwell CC available on Google Cloud G4 for restricted-data inference.
2 4 orders of magnitude slower.
FHE/MPC without hardware assist won't scale layered envelope is the winning design.
$0M extracted in one month.
1.55M sandwich attacks from a single private-mempool validator. Confidential order flow is a paid-for need now.
Live on Solana mainnet.
ZK-encrypted token standard initialized by PYUSD the settlement rail for private compute.
Private execution is the prize.
SOL Strategies acquired Darklake's zk execution engine to own private order flow.
// Competitive position
Compute networks have no privacy. Confidential clouds aren't onchain. Privacy protocols have no compute. Ghost Compute occupies the empty intersection exactly where the highest-margin, least-served demand lives.
| Compute nets | Confidential clouds | Privacy protocols | Ghost Compute | |
|---|---|---|---|---|
| Decentralized GPU supply | Yes | No | No | Yes |
| Confidential execution | No | Yes | Partial | Layered envelope |
| Private inference | No | Yes (centralized) | No | Onchain, x402 |
| Private order flow | No | No | Partial | Flagship app |
| Verifiable attestation | No | Partial | Partial | Multi-proof |
| Confidential settlement | No | No | Partial | Yes |
| Permissionless / onchain | Yes | No | Yes | Yes |
// Who pays
Confidential dark-pool execution
Order flow hidden from MEV. Matching on encrypted books provably private.
Private-weight inference
Proprietary models never exposed to operators. Near-native speed. Onchain.
Sealed inference via x402
System prompt, memory, tool calls stay inside the enclave.
Confidential data processing
Compute on sensitive data with attestation + private settlement.
Confidential backend
Stop borrowing primitives run on a network built for privacy.
→ Ghost Compute · Rollout
→ From silicon attestation
14 weeks · zero plaintext disclosure
Points Season
Confidential-weighted, converting to GHST at TGE.
// Two ways in
Turn your confidential GPU into income your work stays sealed, your earnings stay private. Or build on confidential inference and dark-pool execution, sealed by hardware and proven by attestation on Solana.