Akash in 2026: The GPU Marketplace Learns to Keep a Secret
Akash shipped confidential compute in July, letting workloads run on GPUs their operators cannot read. It matters more than AKT's September rally, and it is not the same as verifiable compute.
By Marcus Okafor· Sep 29, 2026· 4h ago~24 min read
In the last two weeks of September, AKT did something it had not managed all summer: it moved. The token behind Akash Network, the largest decentralized GPU marketplace in crypto, climbed from the low $0.50s in mid-September to roughly $0.73 on 26 September, then handed most of it back, trading near $0.65 on 29 September, according to CoinGecko. Render, io.net, Nosana and Phala all rallied in the same window, which is the first clue that the move was a sector rotation into AI-compute tokens rather than anything Akash itself shipped. It arrived in the middle of a broader risk-on stretch that followed the Fed’s September decision, not a change in Akash’s own numbers.The thing Akash actually shipped this summer is more interesting than the price, and almost nobody outside the DePIN niche noticed. In late July, Akash turned on confidential compute: a tenant can now add a single line to a deployment file and have a workload run inside a hardware-enforced enclave that the machine’s own operator cannot read. As founder Greg Osuri put it in the launch post, “One line of SDL, and your workload runs where the machine’s owner can’t see it” (Akash blog). That reads like a footnote. It is closer to the whole ballgame, because the thing that keeps serious AI work off decentralized GPU markets was never mainly price. It was trust.This piece is about that trust gap: why confidential compute matters more to Akash’s future than the exit from Cosmos or the next twenty cents on AKT, and why “confidential” and “verifiable” are two very different promises that the marketing rarely separates. Along the way, the usual reality checks: what the network actually earns, whether the providers who would host these enclaves even exist in the numbers, and how the field (Render, io.net, Nosana, the TEE-native Phala, and the centralized giant CoreWeave) really compares.
What Akash actually is
Akash Network is a permissionless cloud-computing marketplace. Overclock Labs, the company Greg Osuri and Adam Bozanich founded, launched it in 2018; the mainnet went live in 2020 with CPU and storage, and the GPU marketplace arrived in August 2023 under a release Akash branded the Supercloud. The idea is simple to state and hard to execute: instead of renting compute at a hyperscaler’s fixed list price, you rent it from a global pool of independent providers who compete for your business.The mechanism is a reverse auction. A tenant writes an SDL file (a Stack Definition Language manifest, essentially a short description of the CPU, memory, storage and GPU the job needs), broadcasts it, and providers bid. The tenant is not forced to take the lowest bid; it chooses, weighing price against a provider’s attributes and reputation. The winning lease settles on-chain, funds sit in escrow, and payment flows in AKT, the network’s token. The pitch is that competitive pressure drops the price of a high-end GPU well below the on-demand rate at a major cloud, and by most third-party measures it does: an NVIDIA H100 rents on Akash for roughly $1.30 to $2.00 per GPU-hour, against $4 to nearly $7 on the large clouds’ on-demand tiers, a gap wide enough that a whole cottage industry of price-comparison research exists to track it (Yellow).
The trust problem nobody prices in
Here is what the cheap-GPU pitch leaves out. When you rent a machine from an anonymous provider, you upload your data to it, and for inference or fine-tuning you upload your model weights too. Whoever controls that host has, in principle, root access. A root user can read a process’s memory, snapshot the contents of the GPU’s VRAM, copy the weights, and log every prompt and completion that passes through. On a normal cloud you are trusting Amazon or Microsoft, a named counterparty with contracts, audits and a reputation to protect. On a permissionless marketplace you are trusting whoever won the auction, and you may never learn their name.For a hobbyist running an open model, that is a shrug. For the customers Akash needs in order to grow, it is disqualifying. A startup’s fine-tuned weights are often the single most valuable asset it owns; a hospital’s inference runs on data governed by strict privacy law; a bank cannot let customer records touch a box it cannot vouch for. This is the ceiling the 70-to-85-percent-cheaper pitch keeps hitting: cost is irrelevant if the workload legally or commercially cannot go there at all. Crypto has spent years solving an adjacent version of this problem for private keys, splitting trust across parties so no single custodian can betray you, which is the whole logic behind multisig and MPC key management. Compute needed its own answer, and until this summer Akash did not have a good one.
Confidential compute arrives, one line at a time
Akash’s answer shipped on 28 July 2026 under a proposal labelled AEP-83, which reached Final status on the project’s roadmap in mid-July (akash.network). The headline is the low friction. A tenant adds one line to the SDL, params.tee set to cpu-gpu, and the workload runs inside a Trusted Execution Environment, a hardware-enforced enclave. There is nothing else to change. As the launch post put it, “Integrating confidential computing requires no SDKs, rebuilt container images, separate orchestrators, or new deployment types.” You bring the same container you would have run anyway, and the network runs a demonstration as ordinary as an Ollama language model inside the protected environment.What the enclave buys you is spelled out in the same post: “memory encryption is managed directly by the CPU, rendering the data inaccessible to the host operating system, the hypervisor, and anyone with physical access to the infrastructure.” In plain terms, the provider that rented you the machine, the one who could previously have copied your weights, now sees only ciphertext. Osuri’s framing of the whole thing was characteristically blunt: “One line of SDL, and your workload runs where the machine’s owner can’t see it” (Akash blog). For a marketplace whose central awkwardness is that you do not know your counterparty, that is a direct hit on the sorest spot.
How a TEE actually protects a GPU workload
The mechanics are worth understanding, because they define exactly what the guarantee covers and what it does not. On Akash, a confidential workload runs inside a Kata Container, a lightweight micro-VM rather than an ordinary Linux container, on a CPU that supports AMD SEV-SNP or Intel TDX. The provider picks whichever platform its hardware offers; the tenant does not have to care. The CPU encrypts the virtual machine’s memory in hardware, so the host operating system, the hypervisor and any operator with physical access see only encrypted pages rather than usable data.Extending that boundary to the GPU is the newer and harder part, and it is what makes Akash’s version relevant to AI rather than to spreadsheets. Using NVIDIA’s confidential-computing mode on Hopper and Blackwell cards (part of the NVTrust stack), the CPU enclave acts as the trust anchor: it establishes an encrypted channel to the GPU, data crosses the PCIe bus encrypted, and the GPU computes on inputs the host cannot read. The final piece is attestation. An automatically injected sidecar produces a combined report covering both the CPU enclave and each GPU; the GPU reports are checked against NVIDIA’s Reference Integrity Manifest service, and the tenant validates all of it before sending any secret. The point of attestation is that you are not merely told the enclave is genuine, you can verify cryptographically that the expected, unmodified software is running on certified hardware. Akash open-sourced the integration SDK, and the design is public on the project’s GitHub (akash-network discussion #872).None of this is Akash’s invention; it is the same class of technology behind the confidential-VM offerings at Azure and Google Cloud. Akash’s contribution is wiring enterprise-grade enclave tooling into a marketplace where the counterparty is an anonymous bidder rather than a hyperscaler you already trust. That is a genuinely useful thing to have built, and it is the first Akash feature in a while that changes which workloads can exist on the network at all rather than merely what they cost.
Confidential is not the same as verifiable
This is the distinction the marketing tends to smear, and it matters. A TEE gives you two things. First, confidentiality: the host cannot read your data or your weights. Second, integrity through attestation: you can prove the correct, unmodified image is running. What a TEE does not give you is a trustless, self-contained proof that the computation was correct. It roots trust in the silicon vendors, Intel, AMD and NVIDIA, and in their attestation services and signing keys. If you do not trust the chipmaker, or if a side-channel attack cracks the enclave (Intel’s SGX accumulated a long list of these over the years, with names like Foreshadow and SGAxe), the guarantee softens.The trustless alternative is verifiable compute. Zero-knowledge machine learning (zkML) produces a cryptographic proof that a model ran correctly, checkable by anyone, trusting only mathematics rather than any company’s hardware. The catch is cost: proving large-model inference in zero knowledge is still orders of magnitude too slow and expensive for real-time use, which is precisely why hardware enclaves are filling the gap in the meantime. Optimistic approaches (opML) are cheaper but add fraud-proof challenge windows and their own assumptions. Networks such as Gensyn, chasing verifiable training, and Ritual, targeting verifiable inference, work the trustless side of this problem; as our colleagues have written, for those projects trust turned out to be the easy part. Akash is not on that path. It rents raw hardware; confidential compute closes the confidentiality gap and leaves the verifiability gap open. A provider inside a TEE cannot read your weights, but Akash still is not proving to you that your job returned the mathematically correct output rather than, say, results from a cheaper quantized model quietly swapped in.
Property
Confidential compute (TEE)
Verifiable compute (zkML / opML)
Hides data and weights from the host
Yes
Not the goal
Proves the right software ran
Yes, via attestation
Yes, cryptographically
Proves the output is correct
No
Yes
Trust anchor
Chip vendors (Intel, AMD, NVIDIA)
Mathematics only
Overhead
Low (single-digit percent)
Very high (often 100x to 1000x)
Practical for large LLM inference today
Yes
Rarely
Offered on Akash in 2026
Yes (AEP-83)
No
Do Akash’s providers even have the hardware?
A feature is only as real as the supply that can run it, and confidential compute is hardware-hungry in a specific way. It needs CPUs with SEV-SNP or TDX and, for the GPU half, Hopper or Blackwell cards running in confidential mode. That is newer and pricier silicon than the consumer and last-generation datacenter cards that make up much of a permissionless GPU pool. And Akash’s provider base is not growing into the demand; it is shrinking.The most recent full dataset, Messari’s State of Akash for the first quarter of 2026, counted 58 active providers, a record low and down from 63 the previous quarter, with 334 GPUs available across the whole network, a 57.5 percent drop quarter-on-quarter, and utilization around 33.7 percent (Messari). Akash has not published how many of those providers can actually offer a TEE. So the honest status of confidential compute is this: shipped as a spec, launched as a feature, and gated in practice by a provider set that is both tiny and skewed toward whatever hardware individual operators happen to own. It is a real capability waiting on a real supply base.
Akash metric (Q1 2026)
Value
Change QoQ
Active providers
58 (record low)
down from 63
GPUs available
334
-57.5%
Utilization
~33.7%
flat to lower
New leases
43,540
+27.1%
On-chain lease revenue
$253,250
-45%
FY2025 on-chain revenue
$3.15M
+128% YoY
Read that table honestly and you see the tension running through everything else here: demand signals rose (new leases grew 27 percent in the quarter) while the physical network shrank and revenue fell. Something is drawing users; the supply and the on-chain money are not keeping pace.
The inference pivot: where the demand actually is
If raw GPU rental is stagnant, the growth in 2026 has come from a layer above it: managed inference. AkashML serves popular open models, including Llama 3.3-70B, DeepSeek V3 and Qwen3, at a claimed 70 to 85 percent below hyperscaler pricing, and it is listed as a provider on OpenRouter, the router many developers use to shop model endpoints. Its throughput has climbed fast, from around 1.7 billion tokens a day on OpenRouter at the start of the year to more than 10 billion a day by early July, with a run of all-time highs. Named production users include Venice, ElizaOS, Morpheus and Gensyn.Two caveats keep this in proportion. First, scale on OpenRouter does not equal revenue: in one 90-day provider comparison spanning February to May 2026, AkashML’s estimated revenue came to roughly $51,000, behind Venice, Phala, Chutes and the leader NovitaAI, though AkashML had been live only about 33 days at the time (OpenRouter provider comparison). Second, and more to the point of this article, inference is exactly the workload confidential compute is built for. Running a customer’s proprietary model, or their regulated data, through an endpoint is the case where a TEE stops being a nice-to-have and becomes the reason the deal can happen at all. The inference pivot and the confidential-compute ship are the same strategy seen from two angles: move up from renting raw iron to hosting the workloads that pay more and demand privacy.
What the numbers actually say
Now the uncomfortable part. Akash’s own first-quarter report celebrated crossing $5 million in all-time compute spend during the opening 90 days of 2026 (Akash blog). Messari’s independent tracking of on-chain lease revenue for the same quarter came to $253,250 (Messari). Those are not the same metric: the $5 million is cumulative, all-time and spans every product including managed services, while the $253,000 is a single quarter of raw on-chain leases. But Akash has never published a reconciliation between the two, so an outsider cannot tell how much genuine, paid, third-party demand sits beneath the headline number.This is a familiar shape in crypto: a promoted top-line figure that is technically true, an auditable on-chain figure that is far smaller, and no map between them. Bitcoin miners have their own version of the gap, where the public leaderboard hides who is really doing the work. For Akash the puzzle is sharp: the network is plainly doing real work (10 billion inference tokens a day is not a rounding error), yet the on-chain, auditable revenue that would justify a token worth nearly $200 million is hard to locate. FY2025 on-chain revenue was $3.15 million, up 128 percent year on year and still trivial next to any centralized cloud. The optimistic reading is that the real business now lives in managed products the chain never sees; the skeptical reading is that a token which cannot show you the demand is asking for a lot of faith.
AKT and the burn that barely burns
AKT trades around $0.65, for a market capitalization near $194 million and a rank in the low 190s, with about 298 million of a 388.5 million maximum supply in circulation. Its all-time high of $8.07 dates to April 2021, which leaves the token roughly 92 percent below its peak (CoinGecko). Inflation is capped at 8 percent a year after a March 2025 governance vote cut the ceiling from 13 percent, but roughly half of new issuance is routed to a community pool rather than to stakers, which leaves the real staking yield close to flat once dilution is counted.The mechanism meant to give AKT a demand story is Burn Mint Equilibrium (BME), activated in March 2026. The pitch is that a tenant burns AKT to pay for compute and the provider is minted AKT in return, so usage destroys tokens. The nuance, and it is a large one, is that the permanent, net on-chain destruction is close to zero: the burned tokens are effectively re-minted to pay the provider, so net supply only falls if AKT appreciates between the moment of the burn and the moment of settlement. Akash has never published the net figure. That omission is the heart of a widely read critique. Writing in July, TECHi analyst Zoha Imdad Ali argued that “Akash Runs Real AI Compute. AKT Can’t Prove It Captures the Value,” precisely because the network does not disclose how much AKT its burn mechanism actually removes (TECHi). Real compute demand and a token that provably captures it are two different claims, and so far Akash has substantiated only the first.
AKT snapshot (29 Sep 2026)
Value
Price
~$0.65
Market cap (rank)
~$194M (~193)
Circulating / max supply
~298M / 388.5M
All-time high
$8.07 (Apr 2021), ~-92%
Inflation cap
8% per year
Net BME burn disclosed
No
The supply squeeze and Akash’s two-pronged fix
The record-low provider count is not a mystery. Running a provider today means operating a Kubernetes cluster and exposing GPUs to a public marketplace, an operational burden that keeps the base small and, when GPU prices are attractive elsewhere, shrinking. Akash’s response is a pincer movement on supply.The top-down arm is StarCluster, a protocol-owned GPU mesh. Its first phase is financed through Starbonds, a regulated US investment instrument (with an offering cap up to $75 million and a $1,000 face value per bond) used to fund on the order of 7,200 NVIDIA GB200 Blackwell GPUs, operated by vetted enterprise partners Akash calls Nodekeepers, typically telecoms and datacenters with long-term power agreements. The bottom-up arm is Homenode, in early access since February 2026, which lets owners of consumer and prosumer cards such as the RTX 4090 and 5090 become providers without touching Kubernetes. A third lever, on-chain provider incentives under proposal AEP-53, pays AKT for verified capacity, which adds supply but dilutes existing holders.The economics explain the exodus. In a reverse auction, providers compete by cutting price, which is excellent for tenants and brutal for margins. Take an illustrative case: an H100 that cost somewhere between $25,000 and $30,000, rented at roughly $1.33 an hour and busy only a third of the time, grosses on the order of $300 to $350 a month before power and bandwidth are paid. On those numbers the card alone takes years to earn back, and that is before a competing bid drags the rate lower still. This is why supply leaks out whenever the same GPU can earn more somewhere else, and why Akash cannot simply wait for providers to show up; it has to manufacture them, which is what StarCluster and Homenode are for.There is a neat coincidence buried in the top-down plan. GB200 Blackwell hardware is precisely the class of silicon confidential compute needs, so StarCluster could double as the confidential-compute supply base that the current 58 providers cannot reliably furnish. Compute, in the end, is a contest for hardware and the electricity to run it, the same bidding war for power that Bitcoin miners know well; the difference is that Akash has to attract that hardware from third parties rather than buy it outright, which is why so much of its 2026 roadmap is really about supply.
Leaving Cosmos, kept in proportion
The other big Akash story of the past year is its planned departure from its own blockchain. In October 2025, Osuri announced that Akash would deprecate its sovereign Cosmos-SDK chain and migrate to a shared-security model on another Layer 1, arguing that locking large amounts of AKT purely to secure a chain is capital-inefficient and that a pay-per-use security arrangement would free the team to focus on the compute product (The Block). The search was formalized as AEP-79 and, by Akash’s own description, is one of the more comprehensive evaluations in DePIN, covering 15 ecosystems with Solana among the strong contenders (akash.network, discussion #1123). As of late September the chain had not been chosen; the target is the fourth quarter.One accelerant is worth noting, because it says something about the risk of building on someone else’s stack. In April 2026 the Cosmos SDK’s enterprise module changed its license from the permissive Apache-2.0 to a restrictive source-available one; Osuri called the move “hostile” on X and cited it as a reason to leave (x.com). The staking question underneath all this, how much capital a network should immobilize to buy its own security, is the same debate playing out in Ethereum, where the tradeoffs of delegating your stake to Lido, Rocket Pool or Frax are argued in similar terms. Migration is a real project with a real deadline, but it does not change what a renter experiences day to day, and it is not the reason to care about Akash in 2026.
The field: Render, io.net, Nosana, Phala and CoreWeave
Akash is one competitor in a crowded decentralized-compute race, and the September rally lifted most of the field at once. Render, with its roots in GPU rendering and the OTOY and Octane software behind it, carries by far the largest token, near a $1 billion market cap. io.net takes an orchestration-first approach, aggregating GPUs into clusters, though it has faced questions about the true size of its advertised device fleet. Nosana, on Solana, focuses on low-cost inference. The prices below are approximate and were moving fast in late September.The competitor that matters most for this particular story is Phala Network, because Phala built its entire thesis on TEE-based confidential compute from the start. Akash bolting confidential compute onto a general GPU marketplace in 2026 means it is now competing on Phala’s home turf, and Phala’s own token rallied hard through late September along with the rest of the basket (CoinGecko). The whole group, though, sits in the shadow of a single centralized company.
Network (token)
Price
Market cap
Angle
Akash (AKT)
~$0.65
~$194M
Reverse-auction GPU market plus confidential compute
Render (RENDER)
~$1.92
~$998M
Rendering roots, vertically integrated
io.net (IO)
~$0.157
~$62M
GPU orchestration into clusters
Nosana (NOS)
~$0.41
~$41M
Solana-based low-cost inference
Phala (PHA)
~$0.06
~$50M to $65M
TEE-native confidential compute
That company is CoreWeave (Nasdaq: CRWV), not a token at all but the scale benchmark the whole sector is measured against. In the second quarter of 2026 it reported revenue of roughly $2.58 billion, up 112 percent year on year, a backlog around $104 billion, 51 data centers and about 1.5 gigawatts of active power (CNBC). Chief executive Michael Intrator has framed the moment as a supply race: “The constraint in AI is no longer whether enterprises and AI labs want to deploy. It is how quickly high-performance, reliable AI cloud capacity can be delivered.” The combined annualized revenue of the entire decentralized-GPU sector, on the order of $180 million to $220 million, is a fraction of what CoreWeave books in a single quarter. Decentralized compute is not competing with CoreWeave on scale; it is competing on price, permissionlessness and, increasingly, on privacy.
NVIDIA H100 rental (per GPU-hour, approx.)
Price
Akash
~$1.30 to $2.00
io.net
~$1.90 to $2.90
AWS Capacity Blocks
~$3.90
AWS P5 on-demand
~$6.90
Prices are approximate and sources disagree by as much as a factor of two, so treat the table as an order-of-magnitude comparison rather than a quote sheet (Yellow). The direction, though, is not in dispute: decentralized providers undercut hyperscaler on-demand rates substantially, and that discount is Akash’s core commercial argument.
Where the SEC fits
For a US reader the regulatory picture around Akash is less dramatic than around most crypto assets. AKT itself reads as an infrastructural utility token: you spend it to buy compute, and it sits well to the side of the Securities and Exchange Commission’s central concern with investment contracts. The more interesting wrinkle is Starbonds. Akash deliberately structured that financing as a regulated US investment instrument, in other words a security, to fund StarCluster inside the rules rather than around them, a notable choice in a sector that often treats securities law as an obstacle to route past.Confidential compute has its own regulatory relevance, and it points the other way, toward compliance as a selling point. Trusted execution environments and their attestation reports are exactly the mechanism that could let regulated data, health records or financial information, touch a decentralized network at all, because attestation produces an auditable claim about where and how data was processed. For an enterprise that answers to the SEC, to health-privacy law, or to a bank regulator, that auditable claim is the difference between a pilot and a hard no. It is the clearest reason to believe that privacy, not price, is the feature capable of moving Akash upmarket.
What to watch into the fourth quarter
The late-September rally is the tell for how AKT trades: as a high-beta bet on the AI-compute narrative, rising and falling with Render, io.net, Nosana and Phala rather than with Akash’s own metrics. The whole basket climbed together in the third week of the month and pulled back together at its close, on rotation and whale buying rather than any fresh utilization print (AMBCrypto). Osuri’s recurring line about the business, “AI moves in months, energy moves in years,” captures why the fundamentals lag the narrative: demand can spike overnight, but the power and hardware to serve it arrive slowly (Akash blog).Four things would actually re-rate the token on fundamentals rather than sentiment. First, the AEP-79 chain selection: which Layer 1, and what happens to staking. Second, the first Messari quarter (the second and third quarters of 2026 are still unpublished) that shows whether the provider count and utilization recovered. Third, hard adoption numbers for confidential compute: how many providers actually offer a TEE, and how many enterprise workloads use one. Fourth, whatever emerges from Token2049 in early October. Until on-chain revenue and confidential-compute adoption show up in the data, AKT remains a story stock. The story is a good one, and confidential compute makes it better; the proof is still pending.
Frequently Asked Questions
What is Akash Network and how does it work?
Akash is a decentralized cloud-computing marketplace where anyone can rent GPU and CPU power from independent providers instead of a hyperscaler. A tenant writes an SDL deployment file, providers bid in a reverse auction, and the tenant chooses a bid; the lease settles on-chain and is paid in the AKT token. GPU support launched in 2023, and a high-end GPU such as an NVIDIA H100 typically rents for a fraction of the on-demand price at AWS or Azure.
What is confidential compute on Akash?
Confidential compute, shipped in late July 2026 under proposal AEP-83, lets a tenant run a workload inside a hardware-enforced Trusted Execution Environment by adding one line, params.tee, to the SDL. The workload runs in an encrypted enclave using AMD SEV-SNP or Intel TDX on the CPU and NVIDIA’s confidential-computing mode on the GPU, so the provider hosting the machine cannot read the data or the model weights.
Is confidential compute the same as verifiable compute?
No. Confidential compute (a TEE) keeps your data and weights hidden from the host and lets you attest that the correct, unmodified software is running, but it roots trust in hardware vendors such as Intel, AMD and NVIDIA. Verifiable compute, for example zkML, produces a cryptographic proof that a computation was correct while trusting only mathematics, but it is far too slow for large-model inference today. Akash provides confidentiality, not trustless verifiability.
Why did AKT rally in September 2026?
AKT rose from the low $0.50s in mid-September to about $0.73 on 26 September before pulling back near $0.65, but Render, io.net, Nosana and Phala rallied in the same window, which points to sector-wide rotation into AI-compute tokens rather than an Akash-specific catalyst. No new utilization data drove the move.
How is Akash different from CoreWeave?
CoreWeave is a centralized, Nasdaq-listed AI cloud that owns its data centers and reported about $2.58 billion in quarterly revenue; Akash is a permissionless marketplace that coordinates GPUs owned by independent providers and settles in a token. Akash is far cheaper per GPU-hour but far smaller, with the entire decentralized-GPU sector earning a fraction of a single CoreWeave quarter.By Marcus Okafor, senior markets writer at HOGE Wire, covering decentralized infrastructure and the economics of AI compute.