⛟ FREIGHT CHAIN WHITEPAPER
v0.1 · OCT 8 2026 DEVNET · NO TOKEN PLAY

FREIGHT CHAIN · WHITEPAPER v0.1 · SOLANA DEVNET

A long drive with a public clock and a pool nobody can reach into.

Freight Chain is a browser game in which you drive a manual-gearbox truck down a road that never ends. A shift costs a ticket and lasts a fixed, real amount of time – one, four or eight hours. Nothing is skipped and nothing can be bought to speed it up. A server keeps the clock and judges the finish; the money for paid shifts sits in an escrow program on Solana, not with the operator.

This paper describes the game as it is built today and says plainly which parts are live on devnet, which are written but not deployed, and which are only plans. It is written for players who want to know how to drive and what the rules are, for people who might put in money (on devnet, for now) and want to know where it goes, and for reviewers who want to check the claims against the source.

SHIFTSFREE · 1 · 4 · 8 Hreal time, no fast-forward
SPEED GOVERNOR28 m/s100.8 km/h for every truck
RECORDING10 Hzsealed in 15 s hash-chained batches
STREAM DELAY≈ 25 sanyone can watch any ride

STATUS AT A GLANCE

PartStateWhere it is described
The driving game, five routes, free ridesLIVE02, 03
Server-timed shifts, recording, verdicts (shadow mode)LIVE06
Live streams, replays, chat, paid donations to the driverLIVE · DEVNET SOL07
Escrowed prize pools (Anchor program)WRITTEN, TESTED · NOT DEPLOYED05
Prize payouts, the garage, badges as tokens, mainnetPLANNED04, 08

There is no Freight Chain token and none is planned in this document. Nothing here is an offer to sell anything, or financial advice. Read section 08 before you put anything in.

01

Thesis

Attention is the scarce good. A public clock, a public pool and a public board sell it.

Desert Bus (1995) was an eight-hour drive from Tucson to Las Vegas at 45 mph for one point. Nobody should have finished it, and people did – and other people watched. What made it famous was not the driving; it was that the cost was time, in public, and a finish could not be faked.

Freight Chain keeps that and adds the two things that were missing: a finish decided by a server instead of a promise, and a pot that is held by a program instead of a company. The design follows from four rules:

  1. Time is the price. A shift is complete only after its minimum real time and a minimum distance. The truck is governed at 28 m/s, so distance cannot be banked by idling, and a hidden tab earns nothing.
  2. The finish is not self-reported. The browser records the drive; the server checks the recording. It does not trust a score. It also does not pretend to re-play the physics (see 06 for the limit).
  3. Money is held by rules, not by us. Paid tickets go into a program-owned vault with fixed, public rules and a refund path nobody needs permission for (05).
  4. Everything is watchable. Any ride can be streamed live or replayed from the same recording the verdict is made from. Spectators can talk to the driver and, on devnet, tip them (07).

WHO IT IS FOR

Players who like manual-gearbox sims and long, quiet challenges; people who watch streams of them; and Solana users who want to see escrow and verification done in the open.

WHAT IT IS NOT

Not a token launch, not a yield product and not a casino game: the drive is skill and patience, the finish is verified, and no outcome depends on a random draw in the current design.

WHERE IT RUNS

In a desktop browser, no download. Wallet: Phantom or Solflare. Network: Solana devnet. Mobile wallets and touch controls are not built.

02

How to drive

Inputs, indicators and advice. The truck is a long-hood semi with a seven-speed manual gearbox, a cold engine and a handbrake that is on when you start.

THE FIRST MINUTE

  1. 1KEY ONTurn the ignition to ON (click the key). A one-second self-test sweeps the gauges. With the key OFF every gauge, lamp and even the brake pedal is dead.
  2. 2STARTPress I for a one-tap start, or hold the START zone of the key for about a second. O switches the engine off.
  3. 3PARK BRAKE OFFPress B. The red PARK octagon on the dash goes dark. It is ON at the start of every ride and it holds even against the engine.
  4. 4CLUTCH, 1st, GASHold Shift or Space, press 1, ease the clutch out while on W. Shift up at about 2300 rpm.

INPUTS

ControlKeyNotes
GasW ↑Torque peaks around 2000 rpm and is nearly gone at 1200.
Service brakeS ↓Does nothing with the engine off or stalled – the air system needs it running.
SteerA D ← →Steering is stronger at walking pace so the depot turn is possible.
Clutch (hold)Shift SpaceMust be in to change gear.
Gear up / downE / Q1–7 select a gear, 0 neutral. Q from neutral, or G, is reverse – stop first.
Parking brakeBA spring brake: works with the engine off, holds against thrust.
EngineI start · O offAlso after a stall.
Headlights · cab light · nightL · C · NN jumps the clock between day and night. The cab light works only with the engine running or starting.
HeaterHThaws the windscreen from the vents outward; draws heat out of the engine.
Wipers · washerR · hold XOff / slow / fast. Dry blades barely clear dust; they never clear frost.
RadioT · , . · − =On/off · station · volume. Needs the key ON. Five stations; everyone hears the same song at the same moment.
Pause · mute · CB panelP · M · KPause leads to END SHIFT. K folds the spectator chat panel (07).

Every dash button (HEAD, NIGHT, HEAT, WIPER, WASH, PARK, the key, the radio) can also be clicked.

INDICATORS

The dashboard warning lamps and pedal LED bars
The warning lamps (COLD, STRAIN and BRAKES lit).
The trip computer and the radio panel on the dash
Trip computer and radio.
IndicatorWhat it showsWhat to do
km/h dialSpeed, 0–120. The governor stops the truck at about 100 km/h.Nothing gets you past it; do not chase it.
RPM×100 dialEngine speed. Idle 700, red zone from 2800.Stay between 1000 and 2500. Below about 450 in gear with the clutch out, it stalls.
GEAR windowCurrent gear; amber when the engine runs.7 gears, ratio 6.15 → 0.75.
TRIP LCDKilometres driven, shift time over the minimum (mm:ss / mm:ss) and outside °C.The server's clock is the one that counts; this one is your guide.
TEMPEngine temperature in °C; red from about 98 °C.Warm up gently when it is cold; it plateaus at 85–95 °C.
VOLTBattery. Lights, heater, radio and instruments drain it; the alternator refills it only while the engine runs.Do not sit with everything on and the engine off.
H2OWasher fluid tank; drains while you spray, refills slowly.Spray in short bursts.
AIR, OIL, FUELAir pressure and oil pressure follow the engine. FUEL drifts down with distance as a display – the truck never runs dry.Informational.
CLU · BRK · GAS · HUL barsFour LED columns: clutch, brake and gas pedal positions, and hull integrity in %.Hull below 100 % cuts power (down to 40 %) and pulls the steering to one side; 0 % ends the shift.

WARNING LAMPS

Amber means watch it, red means fix it now, blinking red means seconds left.

STALL

Gear in, clutch mostly out and revs under 450. Clutch in, restart with I.

COLD

The engine is below working temperature: less power, and revving high costs hull. Drive gently until it goes out.

STRAIN

Charges while you hold 92 % of redline or more; full means the engine blows and the shift ends. Shift up. (Charge time is a test value today.)

OFF ROAD

Wheels off the tarmac, sand drags the truck. Time accumulates and drains twice as fast once you are back; about 20 s in total loses the ride.

BRAKES

Hot brakes: hard stops from speed, or driving against a held brake. Hot brakes fade, the parking brake too. Full strain ends the shift.

OVER-REV

Revs above the red zone. Change up or lift.

GRIND

A shift attempted without the clutch, or forward ↔ reverse while still rolling.

BAT

Battery below 30 % (red and blinking below 15 %). Below 1 % lights, radio and heater cut out and the engine will not start.

ADVICE FROM THE LONG HAUL

  1. Release the parking brake first. Driving against it cooks the brakes and charges STRAIN; with the pedal instead, the engine just stalls.
  2. Start gently in the cold. On the Trans-Siberian route (−22 °C) idle alone never warms the engine; driving gently does. Do not rev a COLD engine.
  3. Pick the gear for the speed. 30 km/h wants 4th. A tall gear at a crawl lugs and stalls instead of pulling; standing starts belong to 1st or 2nd.
  4. Do not live on the redline. Upshift near 2300 rpm. STRAIN charges above 92 % of redline.
  5. Straddle potholes, slow for trenches. A yellow sign comes about 90 m before every hole. A small pothole can be passed between the wheels; a trench or sinkhole needs a lane change or a crawl.
  6. Keep the truck on the road. Poles, guardrails, cacti and other trucks are solid; scratches and bumps cost hull, a direct hit ends the shift.
  7. Lights at night. With no lights the world is black outside the lamp posts; oncoming traffic dazzles you. At night the headlights are the only thing lighting the road.
  8. Mind the battery. Headlights, heater and radio with the engine off flatten it in minutes.
  9. Wash the glass, then wipe. Dust builds up; the washer makes each wiper pass clear far more. Frost needs the heater, not wipers.
  10. Do not alt-tab on a paid shift. A hidden tab pauses the game and earns nothing; the server will not credit those seconds.
  11. Respect the crossroads. Junctions have signals and cross traffic, and a direct hit with another vehicle ends the shift on the spot.

FIVE ROUTES

All routes share the same rules and road generator; they change scenery, weather and the bend style. The road is generated endlessly from a seed (crossroads, one to three lanes per direction, towns, lights).

  • Route 66 · USA sand, saguaros, gentle bends
  • Stuart Highway · Australia red earth, nearly straight, red dust
  • Trans-Siberian · Russia snow, −22 °C, frost and short visibility
  • Brenner Pass · Alps tight serpentines, guardrails
  • Pan-American · Atacama salt flats, long sweepers, thin bright air
03

Rides & rules of participation

What a shift is, the kinds there are, how it ends, and what you accept by taking part.

THE FOUR KINDS OF SHIFT

TierMinimum timeList priceWhat it is
FREEa few minutes (test-sized)$0The habit. Five free rides at sign-up, +1 every 00:00 UTC, never above five. Its own leaderboard and badges. No pool.
1 H1 hour$5A ticket into a 1-hour pool.
4 H4 hours$15A ticket into a 4-hour pool.
8 H8 hours$50The full Desert Bus: a ticket into an 8-hour pool.

List prices are in US dollars and are settled in devnet SOL at the quoted rate. Once pools are on sale, each pool fixes its own price in lamports at creation and that price never changes. Devnet SOL has no value.

HOW A SHIFT RUNS

  1. 1SIGN INSign a message with Phantom or Solflare. No transaction, no fee. A cookie keeps the session; the site never sees your key.
  2. 2STARTFree: spend a free ride. Paid: spend one ticket of that tier's live pool. The server issues a signed ride with a seed and a start time.
  3. 3DRIVEThe game heartbeats the server. Driven seconds come from those beats, capped by wall time. The recording uploads every 15 s.
  4. 4FINISHAfter the minimum time and the minimum distance the shift is complete. You may keep driving, then end it (P → END SHIFT).

The completion rule. A shift completes when its minimum time has been driven and the distance reaches ½ × 28 m/s × that time (for 1 hour: 50.4 km). The governor is the same for everyone, so this distance cannot be reached faster than half the time.

HOW IT ENDS

COMPLETED

Minimum time and distance reached, then you ended it. The recording is judged (06); only verified completed paid shifts rank on a paid board.

ABANDONED

You ended it before it completed. No rank. A paid ticket is spent.

FAILED

A direct hit, hull at 0 %, a blown engine or drivetrain, about 20 s off the road, no heartbeat for 150 s (the tab is gone), or a reported distance faster than the truck can go.

RULES OF PARTICIPATION

  1. You need a wallet, not a balance, to look around. Watching a ride, the boards and this paper need no sign-in. Driving, chatting and tipping need one signature.
  2. One account is one wallet. Free rides, tickets, badges and rank belong to the wallet that signed in. A session cookie is not revocable one by one; sign out of shared computers.
  3. A ticket is spent when the shift starts. A paid ticket is not returned if you crash or abandon. It is returned only if the pool fails: if too few riders buy in before the pool's preparation deadline, every buyer is refunded in full (05). Starting a ride while one is open resumes it.
  4. Per-wallet cap. A pool states how many tickets one wallet may hold; the program and the server both enforce it. Promo codes add tickets of a tier and count against the same cap.
  5. Drive by hand, in the real game. The browser records your key presses and the truck's state; timing that looks scripted is flagged for a person to review, and recordings that are impossible are rejected. Using bots, macros or a modified client is against the rules and is the thing the validation is built to catch (06).
  6. Keep the tab visible. Time with the tab hidden is not driven time. Slow computers are not penalised: times come from the browser's event clock, and if the game runs below real time it simply takes longer.
  7. Spectators may talk and tip. An online ride can be streamed live and replayed by anyone for 90 days – the road, your truck's state and the traffic around you; your key presses are never shown (07). You may mute any chat wallet.
  8. Rankings are provisional while the rules are tuned. Verdict rules v1 run in shadow mode: verdicts are stored and shown, but boards do not yet depend on them. A person reviews flagged rides and every decision is signed and logged.
  9. It is a devnet build. Nothing here is real money. Before any mainnet version exists, whether a prize game is lawful where you live is a question you and the operator both have to answer (08).
04

Rewards & promotion

What can come back to a driver. Everything is a possibility with a stated state – none of it is a promise.

No payout amount is guaranteed or advertised. The prize figures below are proposed defaults from the pool design; each pool fixes its own at creation. No prize has been paid out in this build.

RewardWho gets itState
Free rides – 5 at sign-up, +1 each UTC dayEvery walletLIVE
Free board – every completed free ride ranksFree driversLIVE
Badges – First Mile, Shift Complete, Night Owl, Century, Clean Run, Cold Start; Top 20 after a round closesWallets that earn themLIVE (server-side)
Tips and effects from spectators – SOL from a viewer's wallet straight to yoursThe driver being watchedLIVE · DEVNET
Promo codes – free tickets of a tierWhoever holds a codeBUILT
Pool prizes – the prize share of a pool, to the top of its boardVerified finishers of that poolPROGRAM WRITTEN · NOT DEPLOYED
Sponsorship – anyone adds SOL to a pool's potThe pool, split by its rulesPROGRAM WRITTEN · NOT DEPLOYED
Click-to-mint badges – a badge you choose to mint, never auto-mintedWallets with a paid ridePLANNED
The garage – cosmetic and comfort parts (gold wheel, gauge faces, paint, a heavier battery)OwnersPLANNED

HOW A POOL'S MONEY IS SPLIT (EXAMPLE)

A pool is every ticket sold plus any sponsorship. Its split is written in basis points when it is created and cannot be changed. The proposed default is 70 % prizes · 20 % seeds the next pool · 10 % fees. Shares are rounded down and the rounding remainder goes to fees, so the pieces always add up to the pot exactly.

Example pot: 20 tickets × 0.04 SOL + 0.20 SOL sponsorship = 1.00 SOLShare
1st place0.25 SOL
2nd place0.15 SOL
3rd place0.10 SOL
Top-20 share0.20 SOL
Seeds the next pool0.20 SOL
Fees0.10 SOL

The 25 / 15 / 10 / 20 inside the prize share comes from the game's ranking, which happens off chain. The program enforces the ceiling: payouts can never total more than the prize share (05). Ranking is by verified paid shifts (06).

PROMOTION & GROWTH

FREE FIRST

Five free rides and a daily refill are the on-ramp: no wallet balance is needed to find out whether you like the drive.

WATCH BEFORE YOU BUY

Every ride has a public live page and a replay. A visitor sees real drivers, real distances and the real board before connecting a wallet.

PROMO & SPONSORS

Promo codes hand out tickets of a tier. Sponsors can add SOL to a pool; it is split like ticket money and visibly raises the pot.

What is deliberately not on this list: paid advertising, a referral token, staking, and anything that promises a return. The business is the fee share of a pool, only once pools pay out.

05

On-chain: the escrow program

One Solana program, many prize pools. The vault holds the money; the rules move it.

Status. The program freightchain_pools (Anchor 1.2, Rust) is written and has 49 passing tests on a local Solana simulator against the reproducible build. It is not deployed (the program id in the repository is a placeholder), not audited, and planned for devnet only. Nothing on this page is live on a public network yet.

WHERE THE MONEY GOES

Escrow money flowPlayers buy tickets into the pool vault. The vault pays refunds to buyers, capped prizes to winners, and the remainder to the seed and fee treasuries at close. The game server only reads events and builds unsigned transactions. Player walletseach purchase signed Pool vaultprogram-owned accountPDA ["vault", pool_id]no private key exists Buyers (refund) Winners (pay_prize) Seed treasury Fee treasury buy_ticket full pricecappedclose_pool Game serverreads events · credits tickets · holds no key
Every arrow that moves money starts or ends at the vault. The server's link is dashed because it only reads what the program announced and hands players transactions to sign.

THE LIFE OF A POOL

A pool opens with a commitment goal, for example 10 riders. It goes live the moment the 10th ticket is bought. If its deadline passes first, it becomes a refund pool. Every path ends in one of two final states: the pot split by the rules, or every buyer paid back.

OPENtickets sell; must reach its minimum
→ minimum soldautomatic, on the buying transaction
ACTIVErides count; tickets still sell
→ close_pooladmin after the play deadline; anyone after +14 days if a prize was paid
SETTLEDvault = 0, pot split as declared
OPENdeadline missed under the minimum
→ fail_poolanyone
REFUNDINGeach buyer's full price comes back
→ close_poolanyone, once all refunded
CANCELLEDvault = 0

An ACTIVE pool the operator never settles is not a trap: 14 days after the play deadline anyone can call expire_pool (no prize paid yet) and every ticket is refunded, or finish the split to the declared treasuries (some prize paid). Sweeping an unpaid prize share to a treasury is refused.

THE CLOCK

PREPARATION DEADLINE

Tickets sell; the pool must reach its minimum or everyone is refunded. Written into the pool, e.g. 7 days out.

PLAY DEADLINE

Rides count for prizes, tickets still sell. After it the admin pays winners and closes. At most 365 days after creation.

14-DAY SAFETY NET

After the play deadline plus 14 days the last window needs nobody's key: anyone can expire or close the pool.

The program reads the chain's own clock, so these windows are enforced on chain and cannot be moved later.

WHY IT IS SAFE – AND THE RULE BEHIND EACH CLAIM

You can count onBecause the program…
Your fee is held by the program, not by us.keeps it in a vault PDA with no private key; only the program's instructions can sign for it.
A missed goal returns every lamport.lets any wallet call fail_pool then refund once the deadline passes under the minimum. You do not wait for us to start it.
Nobody can redirect your refund.derives the ticket's address from your wallet and checks the receiver against it. Whoever sends the refund, the money lands with you; each ticket refunds once (refunding closes it).
The rules cannot change after you buy.writes price, minimum, deadlines, split and treasuries at create_pool; no instruction edits them. Only the status and counters move.
Prizes can never exceed the prize share.makes pay_prize refuse any payout that would take the running total above it, and any payout before the play deadline.
A vanished operator cannot trap the money.lets anyone call expire_pool 14 days after the play deadline. The admin key can also be handed over in two signed steps.
Money only goes where the pool said.checks every receiver in close_pool against the treasuries stored in the pool and leaves the vault at exactly zero.
A pause cannot block your refund.makes the pause switch stop only new pools, ticket sales and sponsorship. Refunds, prizes and closing always work.
You pay the ticket price and nothing else.separates the buyer and the fee payer, so a sponsor can pay network fees and the ticket's rent; rent returns to whoever paid it.

Technical posture: 14 instructions, 12 events, 24 error codes; all arithmetic in 128-bit integers with overflow checks on in release builds; every pool-money amount is an integer of lamports; Anchor 1.2.1, Solana 4.1.2 toolchain, SBPF v0. The binary is meant to be deployed only from a solana-verify reproducible build whose hash is pinned in the repository, so anyone can rebuild the source and compare it with what is on chain.

WHO CAN DO WHAT

ActionWhoWhen
Buy a ticket · sponsor a poolAnyone with a walletBefore the pool's deadlines, under the caps
Fail a pool that missed its goal · refund a ticketAnyoneAfter the preparation deadline, under the minimum · while refunding
Expire an unsettled poolAnyone14 days after the play deadline, no prize paid
Pay a prize · close and splitAdminAfter the play deadline · (anyone after +14 days if a prize was paid)
Create or cancel a pool · pauseAdminCancel only while Open; pause never blocks refunds
Move any moneyThe game server: neverIt holds no key that can

WHAT THE PROGRAM DOES NOT PROMISE

  • Who wins. Rankings come from the game server's checks (06). That is not proof of human play, and a modified client can still lie within the limits.
  • Which winner gets paid. The program caps the total. It cannot tell a rightful winner from any other wallet, so the admin could pay a wrong address within the cap. Each payout is signed by the admin's wallet.
  • The treasuries. The seed and fee treasuries are wallets the operator controls. A pool fixes their addresses, not what happens to the money afterwards.
  • Maturity. Not deployed, not audited, devnet only.

HOW THE GAME SERVER FITS

The server mirrors pools and tickets; the chain wins any disagreement. A ticket is credited from the program's own TicketBought event, reached by three routes: the confirm / gasless-submit fast path, a program-log watcher (so a closed tab does not lose a payment) and a signed webhook. Credits are idempotent on (signature, event index). The optional gas sponsor co-signs only the exact transaction bytes the server built for that order, so buyers need no SOL for network fees. The server never holds the admin or treasury key; the admin signs pool creation and payouts from a browser wallet.

IDEAS ON THE TABLE

Not built; ordered roughly by fit, from the Solana feature plan.

  • Per-kilometre pledges. A sponsor pledges lamports per km for a live driver, capped upfront and settled against the server-recorded distance – paying for finishing, not for entering.
  • Convoys. Three to five wallets ride the same round and share a side pot by combined distance.
  • Blinks. A Solana Action in a social post that opens “enter / sponsor this week's pool”.
  • Chain-anchored seeds and receipts. A ride seed derived from a block hash recorded at start, and payout transactions that carry the ride's recording root in a memo.
  • A pool crank and session keys. A server-side fail_pool and wallet session keys. Not needed for safety: a player can always trigger the refund.
  • Badges as tokens. Non-transferable badges that encode the shift (“8 hours on the Trans-Siberian at night”), minted on request.

The escrow explainer, with diagrams →

06

Telemetry & ride validation

The server does not replay your drive. It checks that the recording is complete, physically possible, matches the ride, and was driven by a person.

Mode. Rules v1 run in shadow mode in production: every completed shift is judged and the verdict is shown, but the boards do not depend on it yet. The thresholds are first estimates and will be tuned on real rides. Bump the rules version and the verdict stores which one it used.

FROM YOUR KEYBOARD TO THE BOARD

  1. 1RECORDWhile an online ride is on the road: every key press and release, and the truck's state 10 times a second.
  2. 2SEAL · 15 sThe game packs the last 15 s into a batch, fingerprints it with SHA-256 and links it to the batch before.
  3. 3STOREThe server recomputes the fingerprint, checks the batch's shape and limits, and stores it. Stored batches never change.
  4. 4JUDGEWhen the shift completes: the chain, the physics, the distance, the coverage and the timing of your hands are checked together.

WHAT IS RECORDED – AND WHAT IS NOT

TRUCK SAMPLE · 10 PER SECOND

t · road distance · lane offset · heading · speed · rpm · gear · hull · gas · brake · steer · clutch · clock hour · switches

14 numbers. The first twelve are judged; the last two (hour of day and the cab's switches) exist so spectators can replay the ride as you saw it and are never judged. At most 400 per batch.

INPUT EVENT

time since start · key or button · down / up

Times come from the browser's own event clock, so a slow frame cannot make a normal tap look like a 0 ms press. At most 2000 per batch.

Never recorded: mouse movement, your screen, other tabs or apps, microphone or camera, anything after the ride. The offline game records nothing.

THE CHAIN

Each batch carries the SHA-256 fingerprint of the batch before it; the first links to the ride's own id. Change one number anywhere and that fingerprint changes, so the next link no longer matches – the verdict says chain-broken and the ride is rejected. The server recomputes every fingerprint itself on arrival, so a batch cannot claim a fingerprint it does not have, and sending the same batch number again is ignored.

TWO SETS OF CHECKS WITH DIFFERENT POWERS

Checks on the recording itself can reject, because a broken or impossible recording proves something is wrong. Checks on how human your timing looks can only flag, because statistics can be wrong about a real driver.

CheckRuleOutcome · code
Complete and in orderEvery batch present, every link matching, every fingerprint correct, samples in time order.reject · no-recording missing-batches chain-broken hash-mismatch sample-out-of-order bad-sample
Under the governorThe truck is limited to 28 m/s (100.8 km/h). A sample above 29.4 m/s (105.8 km/h) is impossible.reject · over-governor
No teleportsBetween two samples the truck cannot move further than top speed allows (×1.2, plus 2 m).reject · teleport
Ends where the ride endedThe last recorded distance matches the reported distance within 30 m + 1 %, allowing for seconds whose final upload never arrived.reject · recording-mismatch
Covers the driveUnder 50 % of the driven time recorded rejects; under 90 % only flags.reject · recording-incomplete / flag · recording-gaps
Someone droveA truck that moved more than 50 m needs key presses, and gas among them.reject · no-inputs no-throttle-input
Holds varyIf one key's hold lengths barely vary (spread under 8 %, over 6+ holds) it looks scripted.flag · uniform-holds
Rhythm isn't a loopIf the 3 most common gaps between presses (to the millisecond) make up more than 60 % of all gaps, a script is cycling fixed delays.flag · repeated-timings
Presses take timeMore than 30 % of presses released within 10 ms were sent, not pressed.flag · instant-presses

Fair to real people: with fewer than 8 presses the timing checks have no opinion. Browsers that round their clock (Firefox privacy mode, Tor) are detected and the two checks a coarse clock would break are skipped.

VERIFIED

Nothing found. The shift ranks on the paid board.

FLAGGED

Something looked off but proves nothing. It waits in a review queue and does not rank until an admin accepts it.

REJECTED

The recording is missing, broken or impossible. It does not rank. An admin can still look and reverse it.

THE SERVER'S OWN CLOCK

  • Driven seconds come from heartbeats, capped by wall time. A gap over 150 s fails the ride.
  • Reported distance may grow at most 28 m/s × 1.2 between beats. Faster than the truck can go is a failure, not a high score.
  • A recording cannot hold more time than the wall allows: game seconds ≤ wall × 1.05 + 30, batches ≤ wall ÷ 5 + 10. Uploading faster than real time is refused.
  • Limits per batch: 96 kB, 400 samples, 2000 events, plus the API rate limits.
  • Races: uploads and judging take the same per-player lock, so every stored batch is part of a verdict, and a batch arriving after the end triggers a new judgement.
  • A bad connection at the finish is not fatal: ending waits up to 3 s for the last upload, the game retries for 55 s, the server accepts batches for 60 s. If the final batch never comes, only coverage drops.

WHO REVIEWS, AND HOW THAT POWER IS LOCKED

  1. 1OWN SITE + PASSWORDThe admin page lives on its own address behind a password. The admin API answers nowhere else.
  2. 2ADMIN WALLETOnly listed wallets can sign in, for 2 hours. A player login opens nothing.
  3. 3EVERY DECISION SIGNEDAccept, reject and re-judge are each signed by the admin's wallet for that exact ride and decision.
  4. 4AUDIT LOGWho decided what, when, why, and the signature are kept for good. A late upload never overturns a human decision.

LIMITS, SAID PLAINLY

  • No re-simulation. The game runs on your computer; its physics use floats, a variable time step and some randomness, so the server cannot re-run it. A careful bot playing the real game with human-like timing could pass the automatic checks. That is why flagged shifts go to a person and why the checks keep tightening.
  • The target is a fixed-tick, fixed-point replay core that re-simulates a paid finish from its input log. It is on the roadmap, not in the build.
  • Verdicts decide ranking only. Whether you can win money is decided by the pool's rules, not by this section.
  • Retention. Recordings are deleted 90 days after the ride (flagged ones are kept until reviewed). Chat and donations are kept with the ride.
07

Streaming: live rides and replays

Nothing is filmed. The watch page rebuilds the driver's road and replays the same recording the verdict is made from.

ONE RECORDING, THREE USES

  1. 1DRIVERThe game records the truck at 10 Hz and, twice a second, the nearest ≤ 16 vehicles within 400 m. There is no second stream.
  2. 2SERVERThe batch is sealed, hashed, chained and stored – the same upload the verdict judges. Traffic rides beside it, outside the fingerprint, and is dropped, never refused, if malformed.
  3. 3WATCH PAGE · every 4 sIt polls for the next batches and the chat feed, builds the road from the ride's seed and route, and writes the truck's state from the samples. Nothing is simulated.
  4. 4REPLAYOnce the ride has ended, the same page is a replay with a timeline and 1×, 4× and 16× speeds, for as long as the recording is kept (90 days).

Live is slightly behind. The page plays about 25 s behind the newest recorded second: one 15 s batch plus its upload, with room for a late one. If the next batch has not arrived, the last frame holds and the panel says so. A paused game records no game time, so a pause never shows as a gap. Anyone can watch any ride that has started; a ride that has not started is a 404, so a seed is never handed out early.

The road is endless but deterministic – its whole layout is a pure function of the ride's seed and route – so only the truck needs to be recorded. Gauges, trailer swing, wipers, dust and lights react as they do for the driver because they read the same state. Not replayed: windscreen cracks, debris, the radio, and the raw key presses (they are what the human-timing check measures, so they are never published).

CHAT: A CB RADIO IN THE CAB

SPECTATOR SIDE

Sign in with a wallet on the watch page. Lines are up to 140 characters, one per wallet per 3 s; control characters are stripped and everything is shown as text, never as HTML.

DRIVER SIDE

A small panel shows the last four lines, a viewer count and the total donated. K or a click folds it. Drivers cannot post into their own feed – their hands are on the wheel.

MUTE

Every spectator line has a MUTE button. A muted wallet cannot post on that ride, its lines vanish from every feed and its donation notes are blanked. An obstacle it already paid for stays on the road, because replays need it.

DONATIONS THAT CHANGE THE ROAD

ButtonPrice (devnet)Effect
💰 Tip0.01 SOLMoney only; shows in the feed and on the CB.
🌙 Night0.02 SOLThe driver's clock jumps to night. Headlights matter from here on.
☀ Day0.02 SOLBack to day. Undoes a night.
🕳 Potholes0.02 SOLThree small pits across the lane; up to 1.8 % hull per axle at full speed.
🚧 Trench0.03 SOLA lane-wide trench; up to 6 % hull per axle and 15 % of speed at 100 km/h.
⚠ Sinkhole0.05 SOLLane-wide with cones; up to 14 % hull per axle and 35 % of speed. At full speed it can wreck a damaged truck.

A donation may carry a note of up to 80 characters. In production it is a real devnet SOL transfer from the spectator's wallet to the driver's: the server builds the unsigned transaction (with a memo naming the order), the wallet signs and sends it, and the donation exists in the feed only once the server has seen it on chain. The platform never touches the money. One conditional update claims the order once (signatures are unique), so two tabs confirming at once make one donation.

Money that moved is never refused. If the effect can no longer happen when the payment is confirmed – another effect landed, effects were switched off, or the ride ended – the donation is delivered as a tip and its text says why.

Where a paid hole goes. Past the stretch of road already built (so it never pops into view), plus the warning sign's 90 m, in the lane the truck is in – about 940 m ahead. The driver's game reports back where and when it landed (“the stamp”, first report wins), and every replay then puts the hole exactly there, now or in a month. If there is no suitable chunk within about 1.3 km, the effect fizzles and says so.

RULES AND FEATURE FLAGS

RuleWhat the server does
Anyone may watchPublic; no session. Ended rides stay watchable as replays.
Only a signed-in spectator writesChat and donations need the player session; the wallet is the author of every line.
Not your own rideThe driver cannot chat to or donate to themselves.
Only rides on the airRunning with a heartbeat in the last 150 s.
One game effect per ride per 20 sA sliding window checked under a per-ride lock, so two simultaneous clicks never both pass; the second is told how long to wait. It keeps a ride drivable.
One chat line per wallet per 3 sSpam control.
The stamp is the driver's, and finalOnly the ride's owner can report where an effect landed.

Four server switches decide what a ride offers; the server refuses what is off and tells the page what is on. In production today: chat on for every ride, donations on and paid (real devnet SOL to the driver), game effects on free rides only – never on a paid ticket ride – with tips available everywhere.

Open: a paid donation whose page closed before confirmation has no chain watcher yet, and a real Phantom on the game's own host is still to be tried by hand.

Open the game, then use a ride's WATCH link from the lobby's Live tab →

08

Limits, risks & roadmap

The honest list. If a limit matters to you, it matters here.

RISKS

RiskWhat it meansMitigation today
Smart-contractBugs in an unaudited program can lose funds.Devnet only; reproducible build; 49 tests; refund paths that need no key. An independent audit is a precondition for mainnet.
CheatingA modified or scripted client could still pass inside the checks.Chain, physics and timing checks; human review of flags; replay core planned (06).
Operator trustThe admin picks pay_prize receivers within the cap and holds the treasuries.Signed, audited decisions; payouts capped on chain; all of it readable on chain.
AvailabilityA long shift can be lost if your tab or connection dies for more than 150 s.Resume of an open ride; honest pauses cost nothing; final upload retries.
RegulationPaid prize games are regulated differently around the world.Devnet, no value. The mainnet question is answered per region before any mainnet launch.
TuningVerdict thresholds and some game values (e.g. strain time) are first guesses.Shadow mode; versioned rules; values flagged as test values.

ROADMAP

  1. Built The driving sim; sign-in with Solana; server-timed rides; verified-play recording and verdicts (shadow); admin review; live streams, replays, chat, paid donations; the escrow program and its server mirror, written and tested.
  2. Next Deploy the verified program build to devnet; create the first pools; a real end-to-end ticket purchase, refund and payout on devnet; tune the verdict thresholds on real rides, then enforce them.
  3. After that A deterministic replay core so a paid finish is re-simulated, not reported; a share page per ride; click-to-mint badges; a program audit.
  4. Long haul The garage (cosmetic and comfort parts that never change the clock or the speed); mainnet with published rules and a legal answer per region; spectator sabotage extensions; mobile wallets and touch controls.

Cut on purpose: a token, pay-to-win parts, an eight-hour mandatory ride with forced stops, a second chain.

DISCLAIMER

SOURCES

The rules quoted here are mirrored from the source: server/src/domain/rides/ride-tier.ts (tiers), …/verdict/verdict-rules.ts (validation thresholds), …/live/live-rules.ts (streaming), programs/freightchain-pools (the escrow program), client/js/config.js (the game). Longer explainers: the escrow page, and the verified-play, replay and program spec sheets in the repository's docs/ folder.

source on GitHub · lobby · model viewer