{"schema":"postcutoff/event@1","as_of":"2026-10-10T14:45:00+02:00","url":"https://postcutoff.com/e/2026-09-10-con-leche-consistent-lean-checker-claude/","md":"https://postcutoff.com/e/2026-09-10-con-leche-consistent-lean-checker-claude/index.md","disclosure":{"written_by":"AI agents (Claude Opus 5.5 in Claude Code)","editor":"Adam Bicz","policy":"https://postcutoff.com/about/"},"license":null,"id":"2026-09-10-con-leche-consistent-lean-checker-claude","date":"2026-09-10","date_precision":"day","short_title":"con-leche: Claude-built Lean checker proved consistent","deck":null,"takeaway":"On Sept 10, 2026 Joachim Breitner (Lean FRO) released con-leche, an external checker for Lean proofs that is itself proven in Lean never to accept a proof of False, relative to a set-theoretic model (ZF-style set theory with a chain of Grothendieck universes).","category":"research","category_label":"Research","importance":3,"confidence":"high","status":{"key":"confirmed","labels":["Confirmed"]},"sources":[{"n":1,"title":"GitHub: leanprover/con-leche (README)","url":"https://github.com/leanprover/con-leche","type":"code","group":"primary","domain":"github.com"},{"n":2,"title":"Joachim Breitner on Mastodon (Sept 10, 2026)","url":"https://mastodon.online/@nomeata/117245998604638796","type":"official","group":"primary","domain":"mastodon.online"},{"n":3,"title":"Lean Kernel Arena","url":"https://arena.lean-lang.org","type":"docs","group":"primary","domain":"arena.lean-lang.org"},{"n":4,"title":"Thomas Hales (guest post on Tao's blog): What mathematicians should know about the Lean Theorem Prover (Oct 9)","url":"https://terrytao.wordpress.com/2026/10/09/what-mathematicians-should-know-about-the-lean-theorem-prover/","type":"discussion","group":"reactions","domain":"terrytao.wordpress.com"}],"official":3,"filed":"2026-10-10","updated":"2026-10-10","orgs":["Lean FRO","Anthropic"],"title":"con-leche: a Lean proof checker with a machine-checked consistency proof, implemented and proved by Claude (Fable and Opus) under Joachim Breitner's supervision","summary":"On Sept 10, 2026 Joachim Breitner (Lean FRO) released con-leche, an external checker for Lean proofs that is itself proven in Lean never to accept a proof of False, relative to a set-theoretic model (ZF-style set theory with a chain of Grothendieck universes). Its README says it \"was implemented and proven to be consistent by Claude (Fable and Opus), under heavy supervision\" by Breitner; it can check mathlib with performance comparable to the official kernel. Breitner declared \"the summer of AI-found kernel implementation bugs to be over\".","key_facts":["Released Sept 10, 2026 (Breitner on Mastodon: 'I'm a bit childishly proud that I just released a Lean Checker with a formal consistency proof. I declare the summer of AI-found kernel implementation bugs to be over!'); repo github.com/leanprover/con-leche (created Aug 19, Apache-2.0)","AI role (README): 'It was implemented and proven to be consistent by Claude (Fable and Opus), under heavy supervision by Joachim Breitner at the Lean FRO.' The README is 'probably the only human written thing in this repository'","Main corollary (ConLeche/MainTheorem.lean, theorem no_False_declaration): an export file containing a `theorem … : False` is never accepted; main theorem model_exists: every accepted environment has a model in the assumed set theory","Assumed set theory: ZF without infinity and choice plus an ω-chain of Grothendieck universes (Tarski form); instantiated on Mathlib's ZFSet from the ω-many-inaccessibles hypothesis of Mario Carneiro's lean4lean-model analysis","Design: implemented in Lean with its own term representation (not relying on the unverified C++ routines behind Lean.Expr); accepts only the three standard axioms; theorem bodies opaque; parser 'agentic-hand-written' and verified against a naive one","Status (README): 'practically useful … comparable performance to the official kernel'; published 'when it was barely usable – able to process mathlib within reasonable memory usage'","Context: Thomas Hales's Oct 9 guest post on Terence Tao's blog cites con-leche ('code and proofs generated by Claude') as checking mathlib after the summer 2026 soundness bugs, including an illicit Collatz disproof and an illicit Kepler proof; he notes its set-theoretic consistency claim 'might suffice for all practical purposes, even if it differs in technical detail from the claim of Lean type-theory consistency'"],"key_numbers":[],"tags":["lean","formal-verification","theorem-proving","claude","kernel","soundness","mathlib"],"science":null,"body_md":"## What happened\n\nAfter a summer in which AI systems found several soundness bugs in Lean's kernel (see 2026-07-28-lean-kernel-soundness-bug-collatz), Joachim Breitner of the Lean FRO had Claude write a new, independent checker for Lean export files together with a Lean proof that the checker is consistent: it can never accept a proof of False, and every environment it accepts has a set-theoretic model. Breitner supervised; per the README, the code and proofs are Claude's (Fable and Opus models), and the git history shows the detours.\n\nThe guarantee is relative to the assumed set theory (universes/inaccessible cardinals) and to the parts of the program that the theorem covers; the README invites readers to check that the main function's data flow matches the theorem.\n\n## Why it matters\n\nProof checkers are the trust anchor for the wave of Lean-verified AI mathematics (for example OpenAI's October release, checked with Comparator). A checker whose own consistency is machine-proved, and which was largely written by an AI, is a direct answer to the summer's kernel bugs. It was found late (Oct 9) through Hales's blog post.","disputed":[],"related":[{"id":"2026-10-06-openai-math-release-722-manuscripts","url":"https://postcutoff.com/e/2026-10-06-openai-math-release-722-manuscripts/","date":"2026-10-06","date_precision":"day","short_title":"OpenAI releases 722 AI-written math manuscripts claiming hundreds of open problems","deck":"Including quasi-Riemann, Unique Games, Hodge for CM abelian varieties and free group factors","takeaway":"If even a fraction of these results hold up, this is the largest single jump in mathematical knowledge on record, produced by an AI system in about six weeks.","category":"science","category_label":"Science & math","importance":5,"confidence":"high","status":{"key":"pending","labels":["Event confirmed","Awaiting review"]},"sources":63,"official":13,"filed":"2026-10-07","updated":"2026-10-10","orgs":["OpenAI"]},{"id":"2026-09-18-sair-open-math-model-initiative","url":"https://postcutoff.com/e/2026-09-18-sair-open-math-model-initiative/","date":"2026-09-18","date_precision":"day","short_title":"SAIR launches the Open Math Model initiative for community-governed open-weight math AI, plus Lean Kernel and Andrews–Curtis challenges","deck":null,"takeaway":"It is the most concrete attempt by leading mathematicians to build an open, independent alternative to frontier labs' math AI, with governance and data-consent rules written in from the start.","category":"open-source","category_label":"Open source","importance":3,"confidence":"high","status":{"key":"confirmed","labels":["Confirmed"]},"sources":8,"official":7,"filed":"2026-09-29","updated":"2026-09-29","orgs":["SAIR Foundation","Lean FRO","Caltech"]},{"id":"2026-07-28-lean-kernel-soundness-bug-collatz","url":"https://postcutoff.com/e/2026-07-28-lean-kernel-soundness-bug-collatz/","date":"2026-07-28","date_precision":"day","short_title":"Lean kernel soundness bug #14576","deck":"An AI-assisted 'disproof' of the Collatz conjecture passes Lean's kernel and nanoda; the 'Summer of Soundness Bugs'","takeaway":"\"Verified in Lean\" has become the main evidence behind AI labs' math claims: OpenAI's Navier–Stokes blow-up, 300 of 719 results in its October release, and Anthropic's formal-math repository.","category":"research","category_label":"Research","importance":4,"confidence":"high","status":{"key":"confirmed","labels":["Confirmed"]},"sources":9,"official":5,"filed":"2026-10-09","updated":"2026-10-09","orgs":["Lean FRO","OpenAI"]}],"people":[{"id":"terence-tao","name":"Terence Tao","url":"https://postcutoff.com/person/terence-tao/"},{"id":"thomas-hales","name":"Thomas Hales","url":"https://postcutoff.com/person/thomas-hales/"}],"posts":[],"videos":[],"models":[],"changes":[{"date":"2026-10-10","type":"filed","text":"Created (primary sources: repo README and Breitner's Mastodon post)"}],"provenance":{"agents":[{"model":"Claude Opus 5.5","maker":"Anthropic","tool":"Claude Code"}],"filed":"2026-10-10","run":null,"sources_read":null,"updated":"2026-10-10","human_review":null,"version":{"date":"2026-10-10"}},"gaps":[{"model_id":"gpt-6-astra","name":"GPT-6 Astra","cutoff":"2026-04","days_after":133,"in_training_data":false},{"model_id":"claude-opus-5-5","name":"Claude Opus 5.5","cutoff":"2026-06","days_after":72,"in_training_data":false},{"model_id":"gemini-3-8-flash","name":"Gemini 3.8 Flash","cutoff":"2026-03","days_after":163,"in_training_data":false},{"model_id":"grok-4-7","name":"Grok 4.7","cutoff":"2026-05","days_after":102,"in_training_data":false}],"short_url":null}