§4. Threat Model
Copy/paste (plain text):
Jason St George. "§4. Threat Model" in Next Generation Stores of Value: Privacy, Proofs, Compute. Version v1.9. /v/1.9/read/part-i/4-threat-model/ Threat Model
Why a threat model? This thesis argues that Privacy, Proofs, and Compute are distinct services that may support a base-asset monetary candidate only when verification is cheap and public, the full path remains deliverable, and holder agency survives pressure. A threat model makes those conditions falsifiable. It defines what we must protect, who is trying to break it, where the trust boundaries lie, and which metrics decide if the system remains credible under pressure. It sits between first principles and implementation so that every later design choice can be traced to an explicit adversary and invariant.
Every architecture is, implicitly, a bet about who will attack it and how. Up to this point we have argued from first principles: what a store of value must survive, and why Privacy, Proofs, and Compute can be engineered to meet those conditions. The next step is to be explicit about the pressure this stack will live under.
The backdrop is already in view. Macroeconomic arithmetic makes financial repression attractive: debt stocks in the hundreds of percent of GDP, negative real rates by policy, capital controls and captive balance sheets as standard tools rather than emergency measures. At the same time, the web’s trust default has flipped from “trusted unless flagged” to “untrusted unless proven” as deepfakes and coordinated moderation make memory itself a soft target. The combination is simple and brutal: states are incentivized to squeeze balance sheets and communications; platforms are incentivized to mediate reality; hardware and networks are increasingly treated as levers of policy, not neutral infrastructure. Against that field, a “next-generation store of value” is not being asked to survive price volatility; it is being asked to survive a world that optimizes for control.
Scope and Assets
The scope is the full Create/Compute → Prove → Settle → Verify loop and its hardware base layer. At minimum, we need to protect four things:
-
Integrity of receipts & state. Proofs, provenance, settlement artifacts, and consensus state must not be silently corrupted.
-
Confidentiality of flows. Private settlement with optional disclosure, not privacy that evaporates at the first audit request.
-
Availability & neutrality. Open admission for provers and users, anti-capture, and non-seizable settlement paths.
-
Verifiability economics. Verification must remain cheap in absolute and relative terms; otherwise “anyone can verify” collapses into “someone we have to trust.”
These map directly to the SoV properties enumerated in §3: First Principles: What a SoV Must Survive. The assets at risk are not just balances on ledgers. They are the whole loop and the matter it runs on.
-
At the bottom lie machines: chips, RNGs, secure elements, TEEs, capture devices, modems, routers, and the power infrastructure that feeds them.
-
Up one level sit the proofs and receipts that describe what those machines did: provenance attestations, computation proofs, settlement artifacts, audit trails.
-
Above that are the flows of value and obligation that ride on those receipts: private payrolls, cross-chain settlements, inference contracts, collateral arrangements.
-
Threaded through everything are the communications substrate that carries claims and proofs, the software distribution channels that keep clients coherent, and the identity and key material that bind actions to actors without doxxing them.
All of these must remain sufficiently intact that savings, truth, and compute can continue to clear when old guarantees fail.
Adversary Classes
We care about several classes of adversaries:
State-level repressors.
Impose negative real yields, capital controls, and hardware mandates; gate on-/off-ramps; require closed attestation; seek to turn banks, clouds, app stores, and IXPs into enforcement arms.
Platform cartels.
Strip or obscure provenance; collude on labels; prefer vendor-mediated “trust” and walled-garden verification.
Strategic patrons.
Protect fiscally load-bearing firms through procurement, guarantees, power priority, and regulatory shelter, converting private infrastructure into protected quasi-public infrastructure (§4: Threat Model).
Economic attackers.
Miner/prover cartels, router capture, MEV/censorship, liquidity games on swap corridors, front-running and soft-forking that tilt rules in their favor.
Hardware/supply-chain adversaries.
Trojans, biased RNGs, covert debug paths that turn “proof” into theater; opaque TEEs whose attestation keys terminate in unaccountable HSM farms.
Energy & physical-interdiction adversaries.
Curtail, ration, or price-discriminate against verification workloads; deny interconnection; withhold long-lead grid equipment; prioritize state or industrial load over third-party proving (§4: Threat Model).
Cryptanalytic / PQ attackers.
Proof forging or signature breaks; long-horizon post-quantum risk.
UX / vaporware risk.
Spec-drift and unverifiable performance claims that corrode credibility, even if the cryptography is sound.
Compositional / mechanical adversaries.
No hostile intent at all: locally rational agents whose incompatible operating rules combine into concentration, procyclicality, and false price signals (§4: Threat Model).
Of these, the primary adversary in this frame is not a cartoon hacker but the rational sovereign under stress. A state that must service promises larger than its productive base will reach, as history shows, for the levers it actually controls: interest-rate caps, yield-curve control, capital controls, regulated custody, and mandatory “secure” hardware and identity schemes. It will be tempted to turn banks, clouds, app stores, hardware vendors, and IXPs into enforcement arms: require real-name registration at the edge; throttle or shut down networks in the name of stability; mandate TEEs whose attestation keys terminate in state-controlled HSMs; define “safety” as surveillance.
In parallel, platforms facing regulatory and reputational risk will centralize moderation and provenance: which media is shown, which credentials count, which proofs are recognized. The danger is not that any one actor becomes an obvious villain, but that their combined incentives re-create a soft but totalizing chokepoint architecture.
Beneath that sovereign–platform axis are economic adversaries: miners, provers, routers, and liquidity providers who prefer rent to work. They will collude if they can, capture matching engines and orderflow, quietly prioritize their own routes, soft-fork the rules in their favor, or simply withdraw service when it suits them.
If verification becomes expensive or gated, a priesthood of “trusted verifiers” will emerge, and with it all the familiar pathologies of rent extraction and arbitrary censorship.
And below them, like bedrock or landmines, are hardware and supply-chain adversaries: fabs and vendors (sometimes complicit, sometimes merely compromised) who can bias randomness, slip trojans into IP blocks, leave “debug modes” wired to secrets, or ship opaque enclaves that amount to remote-controlled kill switches. If the machine can corrupt inputs, leak witnesses, bias randomness, falsify energy receipts, or centralize useful-work markets, the economic claims built on those machines become unreliable—even if the underlying proof system remains mathematically sound.
Administrative Repression
The most probable control regime is not always a ban. It is administrative convergence. Banks, platforms, app stores, identity vendors, cloud providers, telecoms, stablecoin issuers, custodians, and regulators converge around safety, convenience, compliance, and fraud prevention. Each measure is defensible in isolation; together they turn optional rails into de facto mandatory rails.
Administrative Repression
The conversion of formally optional financial, identity, compute, and settlement rails into practically mandatory rails through custody defaults, compliance rules, app-store control, tax treatment, institutional mandates, benefit systems, and platform terms of service.
The stack must therefore defend against soft capture as much as hard censorship. The key question is not only “Can the protocol still run if banned?” but “What share of real usage remains non-custodial, private, verifiable, and protocol-native when compliant alternatives are easier?” This is the same substitution risk introduced in §2: The World Forces New Monetary Primitives and formalized as the Wrapper Dominance Ratio in §10: Work Credits: Energy-Anchored Claims.
Compositional and Mechanical Adversaries
Administrative repression still assumes intent, however diffuse. There is a further class of threat that requires no intent at all.
Not every threat to monetary integrity is an attacker. Some emerge from locally rational agents operating through incompatible rules. Product sponsors maximize fee revenue. Investors chase themes or rebalance portfolios. Authorized participants arbitrage discounts to net asset value. Dealers hedge swaps and options. Passive funds follow mandates. Trend systems follow prices. Each actor can behave rationally within its own boundary while the combined machine produces concentration, procyclicality, discontinuity, and false price signals.
Compositional Adversary
A failure mode in which no participant behaves maliciously or even irrationally, but the interaction of their operating rules produces emergent mechanical dependence, correlated behavior, recursive leverage, procyclical amplification, and prices that no longer carry information about the underlying system.
The threat here is not a villain; it is the sum of locally rational walls. A repression-resilient monetary architecture must therefore measure not only hostile actions, but emergent mechanical dependence, correlated operating rules, recursive leverage, and the failure of stabilizing flows. This is the adversary class that the Market Realization Plane (§10: Work Credits: Energy-Anchored Claims) exists to make visible, and that VerifyFlow (§23: Extended Telemetry) instruments.
With this addition the threat model now spans four distinct kinds of failure: hostile capture (state and platform coercion), institutional co-option (administrative repression and wrapper substitution), endogenous mechanical fragility (compositional adversaries), and protective enclosure (the national-champion pathway below). A design that defends against only the first is defending against the least likely.
Enclosure by Rescue
There is a fourth kind of failure, and it is the one this thesis is least naturally equipped to see, because it arrives disguised as a solution.
§2: The World Forces New Monetary Primitives argues that certain private asset complexes have become load-bearing for sovereign fiscal capacity. A state in that position does not merely regulate those firms. It has a direct fiscal interest in their continued valuation, and when that valuation is threatened it will reach for the instruments it controls.
National-Champion Pathway
The conversion of private firms into protected quasi-public infrastructure, undertaken because the state’s own fiscal capacity or security position depends on their continued operation. Effected through procurement, loan guarantees, tax treatment, energy and interconnection priority, trade protection, restrictions on foreign substitutes, strategic equity positions, and compliance regimes whose fixed costs favor incumbents.
The distinction from the adversary classes above is worth stating precisely, because the mechanism is easy to file under one of them and it does not belong there.
State-level repressors act against a target. Administrative repression (§4: Threat Model) converges on control through many small defensible measures, none of which is a rescue. Compositional adversaries (§4: Threat Model) require no intent at all. The national-champion pathway is none of these: it is deliberate, it is protective in intent, and its beneficiaries welcome it. Call it enclosure by rescue.
The threat to an open stack is not that the incumbent compute complex fails. It is that the incumbent compute complex is saved, and the terms of the rescue determine who is permitted to compute.
Why this is the most dangerous class for this thesis.
Every other adversary here leaves the open stack’s value proposition intact or strengthens it. Repression makes neutral rails more attractive. Platform capture makes portable provenance more attractive. Mechanical fragility makes verifiable telemetry more attractive. Enclosure by rescue does the opposite: it produces a competitor that is well-capitalized, technically excellent, energy-privileged, regulatorily sheltered, and genuinely useful. It wins on capability and convenience, which is exactly the ground on which §29: The Closed Sovereign Stack concedes the open stack cannot win.
What it threatens specifically.
Priority access to power and interconnection, which is a Layer 0 input (§14: Layer 0: Verifiable Machines & Energy, §4: Threat Model). Hardware allocation under supply constraint. Regulatory recognition of some attestations and not others, which decides whose proofs count. And, at the limit, the treatment of independent inference as a compliance problem rather than a normal activity—the enclosure risk of §4: Threat Model arriving through industrial policy rather than through platform terms of service.
What to watch.
The instruments are enumerated in Appendix I: Scenario Analysis: The Collateral Loop Under Stress, and they are observable in public procurement records, subsidy programs, interconnection queues, and export-control rulemaking well before they are visible in market structure.
Threats by Loop Stage
We can slice the threat surface by stage in the Create/Compute → Prove → Settle → Verify loop:
Create/Compute.
-
Threats: poisoned models, mislabeled workloads, biased hardware profiles, hidden accelerators.
-
Mitigation: canonical workload registries, hardware profiles bound to receipts, open benchmarking, attested hardware provenance.
Prove.
-
Threats: junk proofs, prover cartels, selective service, “house-only” pricing.
-
Mitigation: multi-ZK adapters, neutral routers with fairness tests, SLA escrows & slashing; publishing entry-latency, top-N share, and geography/ASN distributions.
Settle.
-
Threats: corridor censorship, refund failure, deanonymization, bridge compromise.
-
Mitigation: adaptor-signature swap kits, lawful-privacy corridors (viewing keys + auditable receipts), bridge-safety templates, mandatory refund-safety, public VerifySettle metrics.
Verify.
-
Threats: verification-cost creep; opaque clients; “trust our node” monocultures.
-
Mitigation: laptop-grade verifiers, reference harnesses, verify predicates embedded in SDKs, public p50/p95 telemetry via the VerifyPrice observatory.
Telemetry & Governance.
-
Threats: silent centralization, KPI gaming, governance capture.
-
Mitigation: open dashboards for VerifyPrice, VerifyReach, VerifySettle; decentralization metrics (house share, geo/ASN spread, time-to-first-proof); incident reports; hard rules about what must be public before changes ship.
Layer 0.
-
Threats: “trust the vendor” cliff, mandatory closed TEEs, unmeasured side-channels.
-
Mitigation: open RTL or microarchitectures where possible, lot sampling and imaging where not, SNARK-wrapped attestations, and explicit side-channel budgets.
Mapping the Authoritarian Playbook
We can sketch several canonical “playbook moves” and the corresponding counter-moves. The table below maps real-world censorship and surveillance tactics to the stack’s countermeasures:
| Playbook Move | What It Breaks | Counter |
|---|---|---|
| DNS/IP/SNI/QUIC filtering & active probing | Reaching verifiers/bridges; provenance fetch | Default to Tor Snowflake/obfs4, refraction networking; pin ECH; fall back to domain-front-free paths. |
Domain fronting curtailed by major clouds |
“Collateral freedom” paths disappear | Use Snowflake’s WebRTC and ISP-partner decoy routing; keep multiple CDNs with content-addressed updates. |
App-store pressure |
Mobile distribution | Parallel update rails (direct, IPFS, USB/QR) + detached sigs; keep APK/IPA sideload guides ready. |
Real-name + SIM registration |
Pseudonymous ops | VC/anon-cred kit; receipt-based reputation; no SIM/face gates for access. |
Government-ordered shutdowns |
All of the above | Sat/mesh/sneakernet paths, store-and-forward receipts; pre-provisioned peer lists; publish “blackout drills” results. |
Backbone/seabed sabotage |
Regional isolation | Multi-landing routing, regional proof markets, diaspora relays; monitor cable incidents. |
Bitcoin network metadata capture |
Wallet/settlement mapping | BIP-324 everywhere; BTC↔︎XMR/ZEC adaptor-sig corridors with refund-safety; publish corridor telemetry. |
Approved-custody defaults |
Self-custody and native usage | VerifySettle/WDR telemetry; native-fee share; non-custodial UX. |
Stablecoin-only institutional flows |
Base-asset value capture | Required fee medium; auto-acquire-and-burn; native collateral. |
App-store wallet restrictions |
Distribution and privacy | Sideloading, web clients, signed binaries, hardware wallets. |
Tax/reporting complexity |
Ordinary-user access | Selective-disclosure receipts; tax export proofs. |
“Safe AI” model licensing |
Open verified compute | Open workload registries; decentralized proof markets. |
Beyond these network-level moves, the financial and institutional playbook includes yield-curve control, capital controls, mandatory “secure” hardware mandates, platform-mediated reality attacks, and proof priesthoods. For each of these macro attacks, the stack provides specific countermeasures that are detailed throughout the document and formalized as testable stress harnesses.
The high-level pattern:
-
Yield-curve control + captive balance sheets → a duration-neutral base-asset candidate alongside Work Credits priced as typed Privacy/Proofs/Compute service claims rather than monetary reserves.
-
Capital controls + KYC choke points → non-custodial privacy corridors (BTCZEC/XMR) that remain viable without centralized exchanges; VerifySettle metrics that make corridor health public.
-
Mandatory “secure” hardware + identity schemes → Layer-0 verifiable machines with open or sampled designs; hardware-profile receipts; identity schemes at Layer 3 that separate accountability from doxxing.
-
Platform-mediated reality + provenance stripping → PIDL-encoded receipts for media and computation; PaL to compile provenance claims into portable proofs that survive platform stripping.
-
Proof priesthoods + closed verifiers → laptop-grade reference verifiers; multi-backend proof systems; VerifyPrice observatories that publish verifier costs and failure rates.
The thesis responds by treating neutrality, privacy, and verifiability as service-level objectives, not vibes.
Energy & Physical Interdiction
The playbook above is financial, informational, and legal. It has a physical companion that is easy to omit because it looks like infrastructure policy rather than monetary policy.
Every threat class enumerated so far assumes the machines are running. The adversary corrupts inputs, gates verification, captures governance, strips provenance, or mandates attestation. In each case there is still a facility drawing power, and the contest is over what that facility is permitted to do. A more elementary move is available: decide what the facility is permitted to draw.
A state that finds it awkward to ban verification can simply decline to energize it.
The Instruments
Energy interdiction is unusually attractive to a rational sovereign under stress because it is administratively cheap, legally unremarkable, and rarely legible as repression:
-
Curtailment and rationing. Interruptible-load classifications applied selectively; verification and proving workloads designated non-essential during scarcity.
-
Interconnection denial and queue position. Not a prohibition, merely a multi-year wait, applied unevenly.
-
Tariff discrimination. Punitive rate classes for compute-intensive load, justified on grid-stability or environmental grounds.
-
Long-lead equipment scarcity. Transformers, switchgear, and turbines allocated by policy rather than by price. Nothing is banned; the queue simply never advances.
-
Load prioritization. Sovereign or national-champion AI build-outs and industrial demand given precedence over third-party proving for the same electrons.
-
Water and cooling constraints. Permitting used to reach the same result as an energy denial.
Note that none of these requires hostility toward cryptography, and most survive judicial review comfortably. This is what makes the class distinct from the mandates in §4: Threat Model: there is no order to comply with, and therefore nothing to resist.
Why This Belongs in the Threat Model
Two reasons, one narrow and one structural.
The narrow reason is that §4: Threat Model already names “the power infrastructure that feeds them” among the assets to protect, and then never returns to it. The asset is declared and left undefended.
The structural reason is more serious. The thesis makes verification affordability a constitutional target and treats its breach as fatal. Those targets are correctly described as exogenous to token price. They are not exogenous to the conditions under which power and reference hardware can be obtained, and those conditions are partly set by states. An adversary who can move the physical cost of verification can therefore trigger the thesis’s own primary failure condition without touching the mathematics, the governance, or the market.
That is a qualitatively different attack from the rest of this chapter. Every other adversary here must break something we are watching. This one adjusts a parameter we had classified as an environmental constant.
Distinguishing Two Exposures
The precise causal path differs between the two halves of the loop, and conflating them produces overclaims in both directions:
-
Verification runs on reference hardware at the edge in small amounts. Its exposure is not bulk power but obtainability of unprivileged reference hardware, plus edge power and connectivity cost relative to local income.
-
Proving and verified compute consume bulk power. Their exposure is energy price, firmness, curtailment risk, and competition from industrial and state load.
Bulk electricity prices do not directly break “anyone can verify,” because verification is not a bulk-power activity. Export controls and platform lockdown do. §14: Layer 0: Verifiable Machines & Energy develops this distinction, and §14: Layer 0: Verifiable Machines & Energy gives it a metric.
Response Posture
The stack’s answer is the same one it gives everywhere else: make the exposure measurable, then let it bind against issuance.
-
Facility Capacity Receipts (§14: Layer 0: Verifiable Machines & Energy) already record curtailment exposure, fuel mix, backup duration, and jurisdictional power risk.
-
Sovereign optionality (§14: Layer 0: Verifiable Machines & Energy) aggregates those fields into one exposure that can be published and challenged.
-
Risk haircuts (§22: Layer 6: Governance & Telemetry) price fragility into Work Credit issuance rather than discovering it during a disruption.
-
A dedicated red line (§27: Risk Analysis & Failure Modes) retires the thesis if verification affordability becomes a sovereign policy variable rather than a market outcome.
What the stack cannot do is engineer its way out of physics. If a jurisdiction decides that third-party proving will not be energized, the correct response is dispersion and honest reporting, not a claim that cryptography makes the grid irrelevant.
Explicit Tensions and Boundary Conditions
Two tensions within this thesis deserve explicit acknowledgment. Ignoring them would make the framework less credible; addressing them honestly strengthens it.
Tension 1: Privacy by Default vs. Coercion at the Social Layer
The concern: Lawful privacy proposes “optional disclosure via viewing keys.” But if disclosure becomes mandatory at chokepoints (exchanges, employers, landlords, visa applications), “optional” becomes fiction. The technical guarantee of privacy could be circumvented by social or legal coercion.
What the system can and cannot guarantee:
| Layer | Guarantee | Limitation |
|---|---|---|
| Protocol | No backdoors, no master keys, no escrow. Disclosure requires the holder’s key. | Cannot prevent a holder from being coerced to share their key. |
| Architecture | Non-custodial routes exist. Users can transact without intermediaries. | If all practical routes require KYC, non-custodial option may be theoretical. |
| Corridor design | Multiple asset paths with redundant liquidity in multiple jurisdictions. | If all corridors are choked simultaneously, exit paths narrow. |
| Telemetry | VerifySettle makes corridor health public; users can see which routes are viable. | Does not prevent coercion; only makes it visible. |
How the stack reduces coercion surface:
-
Data minimization: By default, nothing is revealed. Coercion must extract keys, not merely subpoena records that already exist.
-
Decentralized verification: No single auditor or platform must see all flows. Selective disclosure can be scoped narrowly.
-
Multi-jurisdiction design: Corridors, mirrors, and provers are distributed so no single legal regime can compel universal disclosure.
-
Exit optionality: Even under local coercion, users retain technical ability to move assets to less-coerced jurisdictions—if corridors remain open.
Honest acknowledgment: Lawful privacy is a technical property, not a social guarantee. It cannot prevent a sufficiently powerful adversary from coercing individuals. What it does is (a) raise the cost of mass surveillance (each disclosure requires individual coercion), (b) preserve optionality for those in less-coerced environments, and (c) make the coercion visible through telemetry rather than hidden in platform logs.
Tension 2: Verified Compute vs. Hyperscaler Dominance
The concern: Compute is dominated by a handful of hyperscalers (AWS, Azure, GCP) and chip vendors (NVIDIA, AMD). If verified compute becomes valuable, won’t these incumbents simply dominate issuance and markets, making “decentralized” PoUW a fiction?
What the system offers vs. hyperscalers:
| Property | Hyperscaler Compute | Triad Verified Compute |
|---|---|---|
| Cost per raw FLOP | Lower (economies of scale) | Higher (proof overhead, smaller operators) |
| Verifiability | Trust the vendor | Anyone can verify receipts |
| Permissionlessness | Vendor can ban workloads, customers, regions | Open admission; no TOS-based exclusion |
| Censorship surface | Single legal entity; can be compelled | Distributed operators; no single chokepoint |
| Receipts | Vendor-issued invoices | PIDL receipts verifiable by anyone |
Why decentralized verified compute wins in specific scenarios:
-
Repression scenarios: When a hyperscaler is compelled to ban certain workloads or customers, decentralized alternatives remain available. The value proposition is not “cheaper” but “still available.”
-
Proof-heavy applications: For workloads where verifiability is the product (compliance proofs, provenance, audit trails), the receipt is the value—not raw FLOP cost. Hyperscalers don’t currently sell receipts; they sell capacity.
-
Certain procurement regimes: Governments, NGOs, and enterprises with sovereignty constraints may prefer compute that doesn’t route through foreign hyperscalers or vendor-controlled enclaves.
-
Composability with privacy: Hyperscaler inference is logged. Verified inference over privacy rails is not. For sensitive workloads (medical, financial, personal), the privacy premium justifies higher cost.
Honest acknowledgment: Decentralized verified compute will not beat hyperscalers on raw cost. It competes on verifiability, permissionlessness, and censorship-resistance. In a benign environment, hyperscalers win on price. In a repressive or high-stakes environment, verified compute wins on trust properties. The thesis bets that demand for these trust properties is structural and growing.
Telemetry response: If hyperscaler concentration in verified compute markets exceeds thresholds (e.g., >50% of VerifyPrice-tracked capacity from 3 vendors), this is flagged in dashboards. The decentralization metrics in §22–23 make this drift visible, not hidden.
AI Homestead vs. AI Enclosure
The hyperscaler tension above is a cost-and-verifiability question. Underneath it sits a sharper political one. AI is the first new frontier since the closing of the physical frontier, but it can be homesteaded or enclosed. In the homestead path, models, tools, proofs, and compute markets distribute cognitive leverage outward. Individuals, small firms, local institutions, agents, and open-source networks gain new capacity to act. In the enclosure path, cognition is rented from a handful of walled gardens. Users receive outputs but not sovereignty; access is mediated by terms of service, identity, payment rails, jurisdiction, and platform risk.
The triad is the monetary and technical response to enclosure. Privacy preserves the right to transact and coordinate without becoming fully legible. Proofs preserve the ability to verify claims without trusting platform labels. Verified compute preserves access to machine intelligence with receipts rather than vendor promises.
Homestead Ratio
The share of verified compute, proof generation, and AI-service capacity supplied by open-admission, non-hyperscaler, geographically diverse, independently verifiable operators.
An Enclosure Risk Flag triggers when more than a threshold share of VerifyPrice-tracked capacity comes from a small number of hyperscalers, closed TEEs, or single-jurisdiction facilities—the same telemetry response introduced above, read through a civic rather than purely economic lens.
The goal is not simply to make AI outputs auditable. It is to keep the AI frontier from becoming a tollbooth on human agency, the same demand this thesis names agency preservation in §2: The World Forces New Monetary Primitives and §3: First Principles: What a SoV Must Survive.
Tension 3: Institutional Holdability vs. Native Monetary Function
The third tension is the one most likely to be mistaken for good news.
Regulated wrappers may accelerate access, liquidity, legal clarity, and institutional holdability. They can also produce holders without users. A spot ETF may hold the underlying asset while shielding its investors from self-custody, private settlement, native fees, proof procurement, and verified-compute consumption. A treasury company may amplify exposure through debt and equity issuance without increasing protocol-native demand proportionally. A daily-reset leveraged wrapper may amplify price further while introducing path dependence and forced rebalancing that has nothing to do with the protocol at all.
| Wrapper benefit | Monetary cost |
|---|---|
| Easier legal ownership | Custody centralization |
| Greater liquidity | Price decoupling from native use |
| Institutional access | Fee/burn/collateral bypass |
| Familiar reporting | Loss of privacy and self-sovereignty |
| More price demand | Potential mechanical amplification |
Institutional holdability is a genuine benefit with a genuine monetary cost. The thesis treats both sides as measurable rather than assuming either.
Institutional wrappers are not automatically hostile, and the reflex that every ETF is an adversary is as lazy as the reflex that every ETF is adoption. The real question is empirical: does wrapper growth seed native use, or permanently substitute for it? Public telemetry must therefore distinguish accessibility from monetary adoption. §25: Operator & Investor Checklist states the holdability requirements; §23: Extended Telemetry states the measurements that keep them honest.
These tensions are not defeaters of the thesis; they are boundary conditions. The stack does not promise to solve all social and political problems. It promises:
-
Technical guarantees that are real within their scope.
-
Telemetry that makes boundary violations visible.
-
Economic and architectural design that expands the scope of those guarantees over time.
Tip: hover a heading to reveal its permalink symbol for copying.