▸ Network

Node Incentives

Overview

The INCOG node incentive system is the economic mechanism that sustains decentralized relay infrastructure operation. It solves the fundamental public goods problem inherent in privacy networks: relay operation is costly (hardware, bandwidth, operational overhead) but the benefits — improved privacy for all users — are diffuse and not naturally captured by the operator. Without a structured incentive mechanism, privacy relay networks attract only altruistic operators, which limits scale, geographic distribution, and operational professionalism.

The $INCOG incentive model makes relay operation economically attractive for a broad range of participants, from home users contributing spare router capacity to professional infrastructure operators running dedicated relay hardware. The model is designed to align economic incentives with the network's privacy properties: operators earn more by contributing in ways that genuinely improve network diversity and resilience, not merely raw capacity.

Incentive Design Principles

Honest Operation is Dominant Strategy

The incentive model is designed so that honest relay operation produces strictly better outcomes for operators than any defection strategy. Specifically:

  • Forging throughput attestations: Cross-validation by adjacent nodes makes large-scale forgery detectable, and detected forgery results in forfeiture of pending rewards plus de-listing
  • Logging traffic: Provides no economic benefit within the protocol, while creating legal and reputational liability for the operator
  • Routing manipulation: Detectible through circuit success rate monitoring; degraded node reputation reduces future reward eligibility
  • Sybil attacks (registering multiple nodes under one identity): Reward calculation weights by verified capacity, not node count; cross-validation detects anomalous throughput patterns

Geographic Diversity is Economically Rewarded

The incentive model explicitly rewards geographic diversity through multipliers. This prevents the common failure mode of decentralized networks where capacity concentrates in high-bandwidth regions (typically Western Europe and North America) while privacy-relevant jurisdictional diversity suffers.

Marginal Value of Capacity Decreases in Oversupplied Regions

The reward calculation is designed so that adding capacity to an already well-served region produces diminishing marginal returns. This creates a natural incentive for new operators to deploy in underrepresented regions where their capacity contribution has higher value.

Reward Calculation

Monthly Reward Pool

A fixed monthly $INCOG allocation is reserved for relay node rewards from the protocol's incentive supply. The reward pool is specified in the token allocation (see token documentation) and does not fluctuate with protocol activity, providing stable long-term incentive expectations for operators.

Per-Node Reward Formula

Each node's monthly reward is calculated as:

node_share = verified_throughput_bytes × uptime_multiplier × geographic_multiplier × class_weight

node_reward = (node_share / sum(all_nodes_share)) × monthly_reward_pool

verified_throughput_bytes: Total relay traffic verified through cross-attestation for the month. Verification requires corroboration from adjacent nodes — self-reported throughput that is not confirmed by adjacent node attestations is excluded.

uptime_multiplier: A value between 0.0 and 1.0 based on the node's availability during the month:

  • ≥ tier threshold: 1.0
  • 90%–threshold: Linear decay from 1.0 to 0.5
  • < 90%: 0.0 (reward excluded)

geographic_multiplier: A regional scarcity multiplier applied to incentivize underrepresented regions:

  • High-demand regions (Western Europe, North America): 1.0×
  • Moderate-demand regions (Eastern Europe, Southeast Asia, South America): 1.5×
  • Underrepresented regions (Central/Southern Africa, Central Asia, Pacific Islands): 2.5×
  • Exact multiplier values are updated by governance quarterly based on network distribution metrics

class_weight: Node class reward weight:

  • Tier 1 (home router): 0.8×
  • Tier 2 (dedicated relay): 1.0×
  • Tier 3 (data center): 1.0× (same base as dedicated; exit node bonus applied separately)
  • Exit node bonus: Additional 0.3× applied to nodes that served as exit nodes during the period

Example Calculation

A Tier 2 dedicated relay node in Eastern Europe contributing 2.4TB of verified monthly throughput with 99.8% uptime:

verified_throughput_bytes = 2,400,000,000,000
uptime_multiplier = 1.0 (above tier threshold)
geographic_multiplier = 1.5 (Eastern Europe, moderate-demand)
class_weight = 1.0 (Tier 2)

node_share = 2,400,000,000,000 × 1.0 × 1.5 × 1.0 = 3,600,000,000,000

If total network share = 180,000,000,000,000 (total all nodes)
node_fraction = 3.6T / 180T = 0.02 (2% of network share)

If monthly reward pool = 500,000 $INCOG
node_reward = 0.02 × 500,000 = 10,000 $INCOG

Attestation and Verification

Cryptographic Attestations

Node reward eligibility depends on cryptographic attestations of relay activity. These attestations are produced by the relay node software and submitted to the reward contract for verification.

Each attestation bundle contains:

  • Throughput attestation: Total bytes relayed per time period, signed by the node's identity key
  • Peer attestation references: Hashes of attestations from adjacent nodes that confirm the routing interactions
  • Liveness proof: A time-stamped signature proving continuous operation, generated at regular intervals
  • Circuit metadata: Aggregate statistics about circuits served (count, duration distribution) — without content or routing path details

Cross-Attestation Verification

The reward verification system requires throughput attestations to be corroborated by adjacent node attestations. For a given relay hop interaction:

  • The entry node attests that it routed X bytes to the middle node during period P
  • The middle node attests that it received Y bytes from the entry node during period P
  • The exit node attests that it received Z bytes from the middle node during period P

Verified throughput for any node is the minimum of self-reported and adjacent-corroborated throughput. Discrepancies beyond a tolerance threshold trigger an anomaly flag and exclude the disputed throughput from reward calculation.

Liveness Verification

Uptime calculation requires verifiable evidence of continuous operation. Liveness probes from directory authorities provide external verification. Additionally, the relay node software generates periodic liveness beacons:

  • A liveness beacon is a signed, time-stamped message broadcast at regular intervals
  • Beacons are accumulated by the relay directory and used to compute the uptime score
  • Beacons carry a monotonic sequence counter, preventing replay attacks

Economic Security Analysis

Sybil Resistance

The Sybil resistance of the incentive system depends on:

  1. Holder threshold: Minimum $INCOG holding required for node registration creates an economic barrier to Sybil registration
  2. Throughput cross-validation: A Sybil operator controlling multiple nodes would need to route real traffic between them to generate valid cross-attestations, consuming real bandwidth
  3. Geographic uniqueness: Nodes registered from the same IP range or AS are penalized in reward calculation

A rational attacker seeking to maximize rewards through Sybil registration would find that the economic barrier of the holder threshold plus the real-bandwidth cost of generating valid attestations across Sybil nodes makes honest operation of real nodes strictly more profitable.

Long-Term Sustainability

The reward pool allocation is designed for multi-year sustainability. The relay network reward pool is drawn from the protocol's long-term incentive reserve, with a vesting schedule that distributes rewards over years rather than front-loading emission. This ensures that early operators receive meaningful rewards while preserving long-term incentive value for future operators as the network scales.

As the network grows and protocol revenue (from future premium services and ecosystem applications) increases, governance can supplement the fixed reward pool with protocol-generated revenue, creating a path to incentive sustainability beyond the initial token allocation.

Incog SwapIncog Swap

Incog Swap is a non-custodial aggregation platform. Users maintain full control of their assets at all times. Incog Swap does not hold funds, store private keys, or require seed phrases.

Product

  • Swap
  • Status
  • Architecture
  • Docs
  • Help Center

Privacy

  • No KYC
  • No Account
  • Zero Custody
  • No Seed Phrase

Providers

  • LetsExchange
  • FixedFloat
  • SideShift
  • + 4 more

© 2026 Incog Swap · incogswap.org · Private Routes. Better Rates.

support@incogswap.org · ▸ session encrypted