Internet Computer (ICP) sustainability report
| Name | BlockNodes SAS |
| Relevant legal entity identifier | 969500PZJWT3TD1SUI59 |
| Name of the crypto-asset | Internet computer |
| Beginning of the period to which the disclosure relates | 2025-09-27 |
| End of the period to which the disclosure relates | 2026-09-27 |
| Energy consumption | 432.96838 kWh/a |
Consensus Mechanism
Internet computer is present on the following networks: Base, Ethereum, Internet Computer.
Base is a Layer 2 network that executes transactions away from the Ethereum chain and settles them on it. It runs no consensus protocol of its own and has no validator set of its own. Agreement about which Base transactions occurred, and in what order, is ultimately established by the data and the state commitments the network publishes to Ethereum, which are secured by Ethereum's proof-of-stake consensus.
Ordering and execution on the Layer 2 are carried out by a single sequencer, operated by the company that launched the network. It receives transactions, places them into blocks at a fixed cadence and returns a result to the user straight away; those blocks are then compressed and posted to Ethereum in batches, alongside commitments to the state they produce. Once a batch sits inside a finalized Ethereum block, the ordering it encodes is as hard to reverse as Ethereum itself. Users are not wholly dependent on the sequencer for access: a transaction can instead be submitted through a contract on Ethereum, and the rules by which the Layer 2 chain is derived oblige it to be included, which bounds how far the sequencer can censor.
Base is an optimistic rollup, built on the shared OP Stack codebase and part of the Superchain group of networks that use it. State commitments are accepted as correct unless disputed. Anyone may propose one and anyone may challenge one within a dispute window, by playing an interactive game on Ethereum that narrows the disagreement down to a single step of execution, which an Ethereum contract then settles by running that step itself. Both sides post bonds, so an untrue claim and a frivolous challenge are each expensive. Permissionless fault proofs have run on the main network since late 2024, and a multi-party security council with a supermajority threshold governs changes to the contracts; together these place the network at the intermediate tier of the rollup maturity scale commonly used to compare such systems. A withdrawal to Ethereum cannot complete until the dispute window for the relevant commitment has elapsed. Decentralizing the sequencer itself remains outstanding work.
Ethereum reaches agreement through proof of stake, adopted in September 2022 when the original mining-based chain was retired in favor of a validator-driven consensus layer. The protocol family is usually referred to as Gasper. A fork-choice rule named LMD-GHOST selects the head of the chain by following the branch carrying the greatest accumulated weight of validator votes, while a separate finality gadget, Casper FFG, periodically justifies and then finalizes checkpoints, so that reversing them would require destroying an enormous quantity of bonded value.
Time is divided into slots of twelve seconds, and thirty-two slots form an epoch. For each slot the protocol pseudo-randomly designates one active validator to assemble and publish a block, and assigns the rest to committees that vote on what they believe is the correct head and the correct checkpoints. Under healthy conditions a checkpoint becomes final two epochs after it is proposed, a little under thirteen minutes, after which everything beneath it is treated as settled.
Joining the validator set requires a deposit of no fewer than 32 units of the native asset. Since the protocol upgrade of May 2025 a single validator may hold a far larger balance, up to 2,048 units, and earn on the whole of it, which lets an operator running many minimum-sized validators consolidate them into fewer; the activation floor itself did not change. Entry and exit are rate-limited by a queue measured in staked weight rather than in validator headcount, which bounds how fast the composition of the set can turn over.
Security rests on voting power being bonded. A validator that signs contradictory messages can be proved to have done so and is penalized, and the size of that penalty scales with how much other stake was penalized at the same time, so a coordinated attack is punished far more severely than an isolated fault. Should the chain stop finalizing altogether, a separate mechanism gradually erodes the balances of validators that are not participating until the remainder again represents a large enough majority to finalize. Upgrades during 2024 and 2025 changed how large data payloads are distributed and sampled between nodes, without altering this underlying agreement process.
The Internet Computer is not a single chain. It is a collection of subnets, each one a replicated state machine run by its own committee of node machines and each running its own instance of the consensus protocol over the messages routed to it. Smart contracts, called canisters, are assigned to a subnet; the protocol carries messages between subnets and runs consensus on every hop, so that many chains present themselves to an application as one.
Within a subnet, agreement proceeds in rounds. A shared random beacon, produced jointly by the subnet's replicas, assigns them a fresh ranking each round. The highest-ranked replica proposes a block, and lower-ranked replicas step in only if that proposal fails to appear in time, which keeps the common case to a single proposal per round. Replicas notarize a block they judge valid, a notarization requiring signature shares from more than a supermajority of the committee, and a notarized block is then finalized by a second threshold signature that a replica contributes only if it notarized no competing block in that round. Finality is cryptographic rather than probabilistic: a finalized block has no surviving rival and the state it produces is settled at once, typically within a second or two, so long as fewer than a third of the subnet's replicas are faulty. Safety does not rest on any assumption about how promptly messages arrive.
The binding element is chain-key cryptography. A subnet's replicas jointly hold a threshold key that exists nowhere in complete form; the shares are generated by a distributed protocol and re-shared whenever membership changes, so the subnet's public key stays constant while the machines behind it rotate. A client can verify a response against that single public key without replaying the chain, subnets can authenticate messages to one another, and canisters can hold and sign for assets on external chains. Membership is decided by governance rather than by open entry: a network-wide governance system, controlled by voters who have locked the native asset, admits node machines, composes them into subnets and deploys protocol upgrades to them.
Incentive Mechanisms and Applicable Fees
Internet computer is present on the following networks: Base, Ethereum, Internet Computer.
Base has no native protocol asset, no staking and no issuance. Nothing is minted to reward participation and there is no validator or delegation system on the Layer 2. Fees are denominated and paid in ether, the same asset used on the settlement layer.
What a user pays has two parts, and they behave quite differently. The first is the cost of executing the transaction on the Layer 2, metered in gas exactly as on Ethereum and priced by an equivalent algorithmic base fee that moves with how full recent Layer 2 blocks have been, plus an optional tip. Because Layer 2 block space is plentiful, this component is usually very small and fairly stable. The second is a charge for the cost of publishing that transaction's data to Ethereum. It is assessed per transaction from the compressed byte size of the transaction and the prevailing price of settlement-layer data space, and it is collected when the transaction is processed even though the actual posting happens later, in a batch shared with many others. This second component typically dominates the total and is why Layer 2 costs track conditions on Ethereum.
Since Ethereum opened a dedicated market for rollup data in 2024, the network posts its batches into that market rather than as ordinary transaction data. Those data fees are priced independently of execution and are destroyed rather than paid to anyone, which cut this component sharply. A December 2025 change on the settlement layer raised the available data capacity while introducing a floor that ties the minimum data price to ordinary execution costs, so the charge no longer falls to almost nothing whenever demand for data space is light.
Fees collected on the Layer 2 accrue to the entity operating the sequencer, funding the cost of running it and of settling to Ethereum, with a portion shared with the collective that stewards the shared codebase. The other economic mechanism at work is the dispute system: participants who propose or challenge a state commitment post bonds that are forfeited if they are shown to be wrong, which funds honest challenges and makes dishonest claims costly.
Payment inside the protocol flows to validators, the only participants the consensus layer compensates directly. A validator earns newly issued units of the network's native asset for voting promptly and correctly on the head of the chain and on the checkpoints being justified, for serving its turn in the committee that signs headers for light clients, and, when selected to propose, for the block itself. The proposer additionally keeps the priority portion of the fees in that block, together with whatever it receives from the separate market through which many proposers outsource block assembly. There is no delegation inside the consensus rules: stake is either operated directly or entrusted to an operator through arrangements that sit outside the protocol.
Users pay for execution in gas, metered per operation, with writes to persistent state priced far above arithmetic. Every transaction carries a base fee per unit of gas that the protocol sets algorithmically from how full recent blocks have been, and that amount is destroyed rather than paid to anyone, so sustained demand withdraws native asset from circulation. On top of it a user adds a voluntary tip, which goes to the proposer and governs how quickly the transaction is picked up. Data posted on behalf of Layer 2 networks is priced in a second, independent market whose fee is likewise destroyed; a December 2025 upgrade tied the floor of that market to ordinary execution costs so it cannot collapse to a negligible level, and capped the gas any one transaction may consume.
Penalties mirror the rewards. Failing to vote, or voting late or incorrectly, costs a validator roughly what correct behavior would have earned it. Provable equivocation is treated far more harshly: the offender is scheduled for ejection, forfeits part of its balance immediately, and later incurs an additional correlated penalty computed from how much other stake was penalized nearby in time. Prolonged absence while the chain is failing to finalize drains balances until finality can resume. Stakers may take out accumulated rewards without leaving the set, and since 2025 may also trigger a full exit from the execution layer rather than only from the consensus client.
The distinctive feature of this network's fee model is that the party making a request usually pays nothing. Computation and storage are charged to the smart contract rather than to its caller. Each canister holds a balance of cycles, a resource unit created by burning the network's native asset through a system contract at a rate pegged to an external basket-of-currencies reference, so the price of compute stays stable in real terms while the quantity of the asset consumed varies. That balance is drawn down continuously for the memory the canister occupies and again on every request that changes its state; a canister whose balance runs out is frozen and stops answering until it is topped up. Funding responsibility therefore sits with whoever operates an application, and an end user can interact with one without holding the asset, without a wallet and without approving anything. The exception is a direct transfer of the native asset on its ledger, which carries a small fixed charge that is destroyed rather than paid to anyone.
Payment flows to the parties providing hardware. Independent node providers operate machines of a specified standard in data centers and are compensated in newly issued units of the native asset. Their entitlement is denominated in an external unit of account and converted at a trailing average rate when issued, so compensation tracks real operating cost rather than the asset's market movements. The rate per machine varies with hardware generation, with the country the machine sits in, and with how many machines the same provider already runs, the last of these deliberately reducing the marginal payment so that ownership does not concentrate. Payment is conditioned on work performed: a machine's share is scaled by how reliably it produced the blocks its turn called for, subject to a floor below which the scaling does not fall, and a machine held in reserve outside any subnet is paid at the average performance of its provider's active machines.
Separately, holders of the native asset may lock it in the governance system to vote on proposals, from protocol upgrades to network topology, and receive newly issued units for voting. Rather than a confiscable bond, the lever on a node provider is the reward itself, which underperformance reduces.
Energy consumption sources and methodologies
Internet computer is present on the following networks: Base, Ethereum, Internet Computer.
The estimate for this network has two components, and they are constructed differently.
The first is the network's own infrastructure. This is a small and largely identifiable set of machines rather than a large permissionless population: the sequencer that orders and executes transactions, the batching service that compresses and submits data to the settlement layer, the service that publishes state commitments, and the replica and archive nodes that third parties operate to serve applications and to independently check what the sequencer produced. The number of independent replicas is estimated from crawlers of the Layer 2 peer-to-peer network and from public information about node operators and infrastructure providers. Hardware profiles are inferred from the published requirements of the node software, which for a high-throughput rollup are materially heavier than for an ordinary chain, and per-device power draw comes from measurement on representative equipment under controlled laboratory conditions, counting idle draw as well as load. The fault-proof machinery adds little in normal operation, since the interactive dispute game runs only when a commitment is actually challenged rather than continuously.
The second component is the share of the settlement layer's consumption that this network causes. That layer is Ethereum, whose own consumption is estimated from its validator population using the node-level method described for that network. A portion is attributed here in proportion to what this network occupies there, principally the data space its batches consume, alongside the gas used by its commitment and dispute contracts. Because the settlement layer's consumption is driven by a continuously running validator set rather than by throughput, this attributed share is modest next to the Layer 2's own footprint, but it is included so that settlement is not treated as free.
Both components are estimates built on public observation and stated software requirements, not metered readings. The replica population is the least observable part and the largest source of uncertainty. Where evidence is thin, the assumptions used are those more likely to overstate impact than understate it, and figures are revised as observation improves. The settlement layer publishes its own account of its energy profile at Ethereum energy consumption.
The figure reported for this network is assembled machine by machine, treating the computers that run the protocol as the thing that draws electricity. The starting point is an estimate of how many independent nodes are operating, built from crawlers that walk the peer-to-peer layer and record every peer they can reach, supplemented by public listings of infrastructure and staking providers and by the protocol's own visible record of how much stake is active and how it is spread across operators.
A representative hardware profile is then inferred for those machines. The client software publishes what it requires in processor, memory and disk terms, and operators have little reason to provision far beyond that, so the profile is derived from those stated requirements rather than from a survey of individual operators. Power draw for the resulting device classes comes from measurement on representative equipment under controlled laboratory conditions, capturing both the load validating places on a machine and the draw of a machine that is powered on but momentarily idle, which for a network of this kind accounts for a large share of the total. Multiplying measured per-device draw across the estimated population over the reporting period yields the network figure. Where a disclosure concerns one of the many assets issued on this network rather than the network itself, a portion of the network total is assigned to it in proportion to observed on-chain transfer volumes.
The limits deserve stating plainly. The node count records what is reachable, not a census, and machines behind restrictive network configurations are missed. The hardware profile is a reasoned inference from published software requirements, not a record of what any particular operator bought. Nothing here is metered at the wall. Where the evidence runs out, the assumptions chosen are those that push the estimate upward rather than downward, so the result is more likely to overstate consumption than to understate it, and it is revised as observation improves. The network's own account of its energy profile is published at Ethereum energy consumption.
Energy use on the Internet Computer is estimated from the machines that run it rather than read from a meter. The approach establishes how many node machines are operating, infers the hardware behind them, attaches a measured power draw to that hardware and aggregates over the reporting period. Because nothing in the protocol ties electricity spent to reward earned in the way mining does, the profitability modeling used for proof-of-work networks has no counterpart here and is not used.
Two features make the population more directly observable than on an open network. Node machines are admitted by governance and recorded in an on-chain registry, so they can be counted rather than approximated from crawler sweeps, and the registry associates each machine with a provider and a data center location rather than only an address. What that does not give is the internal configuration: the hardware specification is a published standard for the machine class, and the estimate takes processor, memory and storage counts from that specification together with laboratory measurement of comparable equipment. The architecture also affects the shape of the answer. Each subnet replicates the same computation across its whole committee, so consumption scales with the number of machines and subnets rather than with how much work users generate, and machines admitted to the registry but not currently assigned to a subnet still draw power. Idle and standby draw is therefore counted, and the boundary between machines inside and outside subnets has to be stated rather than assumed.
The result is an estimate. Machine counts and locations are read from public records, but utilization, power supply efficiency and the overhead of the facilities housing the machines are inferred rather than measured, and facility overhead in particular can be a material share of the total for rack-mounted equipment in data centers. Where evidence is missing, the assumptions chosen raise the figure rather than lower it, so the published number reads as a conservative ceiling and is revised as observation improves.
Key energy sources and methodologies
Internet computer is present on the following networks: Base, Ethereum, Internet Computer.
The renewable share reported for this network is a weighted average of the electricity mixes of the grids its infrastructure draws on, assembled in two steps: establish where the machines are, then attach regional generation statistics to those places.
Locating them is easier for some parts of the network than others. The sequencing, batching and commitment services run in identifiable data center regions, and the hosting regions an operator uses are publicly observable. The wider population of replica and archive nodes is inferred as it would be for any peer-to-peer network, from the addresses peers advertise so that others can reach them, collected by crawlers and supplemented by public directories of infrastructure providers. Resolving a single address to a country is unreliable, but in aggregate these resolutions describe a distribution well enough to weight against. Where the observable sample is too thin, the geographic spread of a structurally comparable network is used in its place, chosen because its operators face similar hosting economics rather than because it runs similar software. The same exercise is carried out for the settlement layer, because part of the figure reported here is an attributed share of Ethereum's consumption, and Ethereum's validator population is spread quite differently from a rollup's concentrated operator infrastructure. The two distributions are weighted by their respective contributions to consumption and combined.
Each location is then matched to published statistics on how electricity is generated in that country or region, and the renewable proportion is the consumption-weighted share falling in regions supplied by renewable generation. Grid averages are used throughout, because the actual supply arrangements of individual hosting facilities are not observable; a facility on a dedicated renewable supply and one drawing ordinary grid power in the same country are treated alike.
Energy intensity is a marginal figure rather than an average: the additional electricity attributable to one further transaction on the network as it currently runs. Because most of the infrastructure runs continuously whether or not it is busy, that marginal quantity is much smaller than dividing total consumption by the transaction count would suggest. The generation statistics come from Share of electricity generated by renewables, compiled by Our World in Data from Ember's electricity datasets and the Energy Institute's Statistical Review of World Energy.
The renewable share reported here is a weighted average of grid mixes rather than a record of what any operator actually buys. It is produced in two steps: establish where the infrastructure sits, then attach regional electricity statistics to those places.
Location is inferred from what the network exposes publicly. Nodes advertise network addresses in order to be reachable by peers, and those addresses resolve to a country accurately enough to describe an aggregate distribution, even though any single resolution may be wrong. Crawlers of the peer-to-peer layer and public directories of hosting and staking infrastructure supply the input. Where the observable sample is too thin or too skewed to stand for the whole population, the geographic spread of a structurally similar network is substituted, chosen because its participants face comparable hardware costs and comparable pressures over where to site machines, on the reasoning that operators respond to the same commercial forces even where the software differs.
Each location is then matched to published statistics on how electricity in that country or region is generated. The renewable proportion for the network is the consumption-weighted share falling in regions where generation is renewable. Grid averages are used because the alternative, knowing each operator's actual supply contract, is not observable; an operator on a dedicated renewable supply and one drawing ordinary grid power in the same country are treated alike.
Energy intensity is reported on a different basis from total consumption. It is a marginal quantity: the additional electricity attributable to processing one further transaction on the network as it currently runs. For a network whose consumption is driven by a validator set that operates continuously regardless of how busy the chain is, that marginal figure is small, and it is not the total divided by the transaction count. The generation statistics are drawn from Share of electricity generated by renewables, compiled by Our World in Data from Ember's electricity datasets and the Energy Institute's Statistical Review of World Energy.
The renewable share reported for the Internet Computer follows from locating the hardware. Node machines are recorded in an on-chain registry that names the provider and the data center behind each one, so a large part of the geographic picture is available from the network's own records rather than inferred from network traffic. Advertised network addresses, public network data and registry records fill in the remainder, and where part of the population still cannot be placed, the geographic distribution of a structurally similar network, meaning one whose participation rules and operating incentives resemble this one, stands in for the missing portion.
Located capacity is then matched to the electricity mix of the grid that serves it. National generation statistics give the proportion of electricity produced from renewable sources in each country, and weighting those proportions by the consumption estimated to sit in each country yields the renewable share for the network as a whole. The construction has known limits. It describes the grids the machines sit on rather than any electricity an operator has contracted for on its own account, and because the payment schedule for providers varies by country, the geographic spread of the machines can shift for reasons that have nothing to do with energy, carrying the renewable share with it.
Energy intensity is reported alongside the share and is narrower than an average. It is a marginal quantity: the additional electricity attributable to one further transaction, with the installed infrastructure held constant. On this network the distinction matters more than usual, because capacity is provisioned as whole machines and whole subnets that run continuously regardless of demand, so the marginal value is small, the average value is driven by how much of the provisioned capacity is being used, and the two can move in opposite directions between reporting periods. The grid statistics behind these calculations are taken from Share of electricity generated by renewables, compiled and processed by Our World in Data from Ember and from the Energy Institute's Statistical Review of World Energy.
Key GHG sources and methodologies
Internet computer is present on the following networks: Base, Ethereum, Internet Computer.
Emissions are not measured directly. They are derived by attaching a carbon intensity to each unit of electricity the network is estimated to consume, across both parts of its footprint: the machines the network operates itself, and the share of the settlement layer's consumption attributed to the data and commitments it posts there.
The geographic step repeats the one used for the renewable share. The hosting regions of the sequencing and batching infrastructure are publicly observable; the wider set of replica and archive nodes is located from the addresses peers advertise, collected by crawlers and public directories. Where observation is too sparse to characterize the population, the spread of a structurally comparable network is used in its place. The settlement layer's validator population is located separately, because it is distributed quite differently, and the two are weighted by how much consumption each accounts for. Each region is then assigned a carbon intensity, the average greenhouse gas released per unit of electricity generated on that grid, expressed in carbon dioxide equivalent so that methane and the other gases are counted on a common basis. Estimated consumption in a region multiplied by that region's intensity, summed across regions, gives the total.
Two scopes are distinguished. Scope 1 covers emissions from sources the operators of the infrastructure control directly, such as fuel burned on site in a generator. For infrastructure that consists of ordinary servers in commercial data centers drawing from public grids, there is generally nothing in that category, and it is reported as such rather than left out. Scope 2 covers the indirect emissions embodied in the purchased electricity, and is where essentially the whole footprint sits. Emissions from manufacturing and transporting the hardware fall outside this boundary.
Greenhouse gas intensity follows the marginal logic used for energy intensity: the additional emissions attributable to one further transaction, not an average spread across all of them. It inherits the uncertainty of both the consumption estimate and the grid averages. Carbon intensities are taken from Carbon intensity of electricity generation, compiled by Our World in Data from Ember's electricity datasets and the Energy Institute's Statistical Review of World Energy, and made available under the CC BY 4.0 license.
Emissions are derived from the consumption estimate rather than measured, by attaching a carbon intensity to each unit of electricity the network is estimated to draw and summing across the network.
The geographic step repeats the one used for the renewable share. Node locations are inferred from publicly observable network data, principally the addresses peers advertise so that others can connect to them, gathered by crawlers and supplemented by public information about where staking and hosting infrastructure is operated. Where that observation is too sparse to characterize the whole population, the distribution of a comparable network stands in for it, selected because its participants face similar operating economics rather than because its software resembles this one. Each region is assigned a carbon intensity, meaning the average greenhouse gas released per unit of electricity generated on that grid, expressed in carbon dioxide equivalent so that methane and the other gases are counted on a common basis. Estimated consumption in a region multiplied by that region's intensity, summed across regions, gives the network total.
The reporting separates two scopes. Scope 1 covers emissions from sources the operators of the infrastructure control directly, such as fuel burned on site in a generator. For a network of this kind, whose participants overwhelmingly run ordinary servers connected to a public grid, there is generally nothing in that category, and it is reported as such rather than left out. Scope 2 covers the indirect emissions embodied in the electricity purchased to run that infrastructure, and that is where essentially the whole footprint sits. Emissions further up the supply chain, such as those from manufacturing and shipping the hardware, fall outside this boundary.
Greenhouse gas intensity follows the same marginal logic as energy intensity: it expresses the additional emissions attributable to one further transaction rather than an average spread across all of them. Because it inherits both the consumption estimate and the grid averages, its uncertainty combines theirs. Carbon intensities are taken from Carbon intensity of electricity generation, compiled by Our World in Data from Ember's electricity datasets and the Energy Institute's Statistical Review of World Energy, and made available under the CC BY 4.0 license.
Location evidence here is stronger than for any comparable network, because the network keeps the record itself. Every machine admitted to serve is entered in an on-chain registry naming the provider responsible for it and the data center in which it stands. Emissions accounting therefore opens not with a crawl but with a read: the registry supplies a machine census with facility-level placement, and only the gaps around it, an ambiguous country or capacity added between registry updates, need the ordinary treatment of resolving announced addresses or borrowing the profile of a network with similar operating economics.
That precision meets a coarser instrument at the next step. The coefficient applied to each unit of electricity is a national average for greenhouse gas released per unit generated, stated in carbon dioxide equivalent, so a facility identified by name is still scored by the mix of the whole country around it. Estimated consumption per country multiplied by that country's coefficient, then summed, yields the total. Two features of this network make the country weights unstable. Capacity is provisioned as whole machines organized into replicated subnets that run continuously, so emissions follow the installed base rather than demand; and what providers are paid differs by region, which means machines migrate for commercial reasons and carry the emissions weighting with them.
The scopes divide as they usually do for server infrastructure. Direct emissions, meaning combustion under the operators' own control, are nil for racks in commercial halls on a public grid, and that nil is a determination rather than an unfilled field. Indirect emissions carried in the purchased electricity account for everything else, and therefore for the figure as a whole. Building the machines and the halls lies beyond this boundary.
Emissions intensity per transaction is defined at the margin, as what one additional message costs with the machine base unchanged. On a network sized by provisioned capacity rather than by load, that marginal quantity stays small while the average quantity moves with utilization, so the two can point in opposite directions from one reporting period to the next and should not be conflated. Coefficients come from Carbon intensity of electricity generation, prepared by Our World in Data from Ember and from the Energy Institute's Statistical Review of World Energy and published under the CC BY 4.0 license.