What a KNOT HEAD is

1,110 node runners,
drawn by hand.

Every KNOT HEAD is a portrait of somebody who keeps a node up: the beard, the tinfoil hat, the BIP-110 cap, the coke bottle glasses, the small computer humming in the corner. Each one is inscribed whole onto Bitcoin as a single self contained SVG.

Start here

The short version.

  1. You mint one canonical KNOT HEAD inscription.
  2. Before activation, every mint shows the same neutral seal.
  3. After BIP-110 is final, that same inscription reveals automatically.
1Targets are committed1,110 heads and their mappingare fixed before minting opens.2You mint one inscriptionOne wallet approval creates yourcanonical delegate inscription.3Activation becomes finalThe neutral seal remains whilethe BIP-110 condition settles.4The same ID resolvesThe target broadcasts automatically;your inscription renders its SVG.
The seal is website presentation, not a hidden personalized image inside your wallet. The canonical inscription remains the same; only its delegated rendering source becomes available after final activation.

The drawing

One pen line, and it wobbles.

Each head is built from a single ink line laid over flat riso colour, the kind that misregisters a fraction and lets the paper show through. The line is not smoothed afterwards. Where the pen hesitated, it still hesitates.

The backgrounds come from the same world as the subjects: perfboard, server racks, terminal scroll, redaction bars. 12 trait categories decide the rest, from the beard down to which single board computer is humming in the corner. No filtering, no upscaler, no borrowed house style.

Look at the heads

What you actually own

Four things that are already true.

None of them depends on a roadmap, a promise, or this website still being here next year.

  1. 1,110 heads, then the door closes

    The set, target inscriptions and target-to-art mapping were committed before minting opened. Nobody can add a head, swap an assignment, or quietly re-roll a rare one after seeing who minted. When the last number confirms, that is the collection, permanently.

  2. One mint. One permanent inscription ID

    Your wallet signs the mint once. The canonical inscription it creates is the thing you own before and after reveal; there is no second holder claim, payment or replacement token. Its precommitted target is deliberately withheld from public APIs while the reveal condition is unresolved.

  3. The same ID learns where to render

    Once BIP-110 activation is witnessed and final, the prepared target reveal transaction broadcasts automatically. The Ordinals delegate relationship then makes the canonical inscription resolve to that target's self-contained SVG. Ownership and the canonical inscription ID do not change.

  4. Being early is a fact, not a promise

    Your number is written into the chain in the order you turned up, and it stays there. We are not going to make a claim about price. We will tell you that anyone can check when you arrived, forever, without asking us for permission or for a database export.

Only now, the proof

How the reveal is kept honest.

The order is the whole trick. The artwork set, target inventory and assignment roots are published before anybody mints, so the answer cannot be changed after seeing who owns a number. The activation block does not generate or select the art: it unlocks automatic broadcast of the already committed target reveals.

1Provenance roots published2Target commits confirmed3Canonical delegators minted4BIP-110 activation witnessed5Activation becomes final6Target reveals broadcast automatically7Canonical delegates resolve8Public proofs and art released
Stages run in this order and no other. Nothing on this site claims a date for any of them, because a date is not one of the things the chain reports.
In more detail: what each stage waits for

The full collection is hashed and the commitment published before the first mint. Each mint takes the next number and holds it once the transaction reaches the configured confirmation depth, which is why a broadcast is never treated as a mint.

The reveal then waits for the BIP-110 chain condition, waits again for that condition to settle under enough blocks, and only then broadcasts the prepared target reveal transactions. The finality wait prevents a short-lived fork from releasing the collection early.

Each canonical inscription already has a committed target. As target reveals confirm, the standard delegate relationship makes the canonical inscription render the target SVG without transferring it or replacing its ID. The assignment, target membership, delegate relation and SVG hash can all be checked independently.

Cryptographic evidence: the commitment, in parts

The commitment is not one number. It is a set of published values, each pinning a different thing that could otherwise be changed quietly after the fact.

Manifest hash
Pins the descriptor of the ordered dataset: how many assets, in what order, under which schema.
Merkle root
Commits to every asset in the set, so a single head can be proved a member of the collection without publishing the rest early.
Commitment hash
Binds the manifest, the root and the reveal configuration into one value, so the rules cannot be edited after minting opens.
Generator hash
Pins the code that draws the artwork, so a refactor cannot move a byte of a delivered head.
Metadata schema hash
Pins the shape of the metadata written on chain beside each head.

No value is printed on this page. They are live readings, and a page that has not read them should not pretend otherwise. The reveal monitor prints whichever ones the service has published, and says so plainly when it has not.

Read the published commitment

Transaction evidence: checking one mint end to end

The mint flow prepares the Bitcoin transactions needed to pay and create the canonical delegate inscription, but asks the holder for one wallet approval. Later target broadcasting is an automatic protocol step, not a second holder transaction.

Before you sign
The review screen shows every input, every output, the fee rate, the total, and the SHA-256 of the exact unsigned transaction. The browser recomputes that hash and refuses to open your wallet if a single byte differs.
While it settles
Your private tracker keeps preparation, broadcast, network acceptance, confirmation depth, reorg watch and indexing as separate stages, with the transaction IDs to check each one yourself.
After the reveal
The token page recomputes the content hash of the artwork your browser drew and holds it against the hash recorded on chain. Verified, mismatch and not enough data are three different answers, and it never collapses them into one.

Check an assignment yourself

The collection was locked first

Before minting opened, the ordered dataset, target inventory and assignment map were committed to published roots. No wallet, browser or operator can pick an artwork after a mint is made, while public responses still withhold the target, art and traits until resolution.

Bytes, not vibes

Every final artwork is an exact self contained SVG. Its SHA-256, target tapscript and fixed non-witness transaction are locked before minting, so the protected worker cannot quietly swap the bytes later.

Confirmations decide supply

A preparation is not a mint. A payment is not a confirmed mint. A position becomes final only at the configured confirmation depth. Ambiguous or expired prepared targets are quarantined until exact on-chain reconciliation; they are never silently reused.

One source of truth

Mint records, ownership, transfers and reveal assignments are checked against Bitcoin and the canonical collection index. The chain is the source of truth, not a private inventory somebody can edit.

Check an assignment yourself

Secondary, and load bearing

The target bytes are frozen too.

A locked collection is only worth as much as the evidence binding each SVG to its future target. The transaction protocol and hashes are part of the precommitment.

Protocol integrity: knotheads-delegated-reveal-v1

knotheads-delegated-reveal-v1 binds the offline manifest, hidden assignment, fixed target IDs, and public proof format. Immediately before broadcast, the worker recomputes the SVG hash and non-witness txid and fails closed on any mismatch.

Trait weights and final rarity are kept apart on purpose. Rarity stays sealed with the artwork until the public reveal. After it, the published dataset and its hash let anyone recompute the result and hold it against what they were shown.

The last step

Go and take a number.

The set is drawn, the count is fixed, and the exact cost is on screen before your wallet opens. The only thing left undecided is which head ends up being yours.