privacy · proofs · compute
v2.0 · checksummed

§10. Work Credits: Energy-Anchored Claims

v1.9
Cite this section

Copy/paste (plain text):

Jason St George. "§10. Work Credits: Energy-Anchored Claims" in Next Generation Stores of Value: Privacy, Proofs, Compute. Version v1.9. /v/1.9/read/part-ii/10-work-credits/

Work Credits: Energy-Anchored Claims

The triad gives us three capacities. To make them tradable without confusing service with money, we need a unit of account for work: something that binds energy, hardware, delivery terms, and verification into a transferable typed claim.

Call these Work Credits (WC).

Informally:

A Work Credit is a claim on a standardized unit of triad work (privacy settlement, proof generation, or verified compute) that has been produced and attested under public SLOs.

Key distinction: Work Credits are energy-priced, not energy-pegged. They are denominated in work, not in kWh. Energy enters through Facility Energy Receipts (FERs) and VerifyPrice, not through a one-dimensional peg. See §10: Work Credits: Energy-Anchored Claims for the full treatment.

Clarification. Throughout this section, “Work Credits” are generic, notional service claims, not product branding and not the base asset. “AI Money” and “proof money” survive only as historical shorthand for service-instrument design spaces; the analytical objects are typed compute, proof, and settlement claims.

We can describe Work Credits along a few axes:

Definition: Work Receipts vs. Work Credits

A common source of confusion is conflating “proof that work was done” with “transferable claim on future capacity.” These are different financial objects. We split them cleanly:

Work Receipt (WR)

A Work Receipt is a PIDL artifact proving that a specific unit of work was completed under attested conditions.

  • Content: Claim hash, proof hash, workload ID, SLA tier, timestamps, hardware profile, prover signature.

  • Properties: Copyable, verifiable by anyone, not scarce.

  • Analogy: A receipt from a completed transaction. It proves the past but confers no future rights.

Work Receipts are not money. They are evidence.

Work Credit (WC)

A Work Credit is a transferable instrument issued against Work Receipts under protocol-defined issuance rules.

  • Issuance: Minted when (a) a valid Work Receipt is accepted by the network, and (b) telemetry confirms SLOs are met.

  • Properties: Scarce (supply bounded by issuance rules), transferable, fungible within workload class.

  • Rights: Depend on the design variant (see below).

Base asset and Work Credit separation:

Hierarchy rule: The base asset is the only object evaluated for monetary premium, and even then only conditionally. Work Credits are useful for service procurement and cost hedging and are explicitly not pitched as stores of value.

Issuance mechanics for Work Credits:

For a canonical workload WW (e.g., “MatMul of size nn with error bound ε\varepsilon,” “provenance proof for content type CC,” “corridor settlement of size SS with anonymity set A\geq A”), define:

  • p(W)p(W): production cost (energy + hardware amortization + opex) to generate one unit and produce a valid proof.

  • v(W)v(W): verification cost.

  • r(W)=v(W)/p(W)r(W) = v(W) / p(W): verification asymmetry.

A Work Credit of type WW, tier TT is issued only when:

  • A valid Work Receipt for workload WW at tier TT is accepted by the network.

  • Telemetry confirms that VerifyPrice(WW,TT) and other SLOs (latency, failure rate, decentralization) are within bounds.

  • Issuance does not exceed the issuance envelope for the current period (see §10: Work Credits: Energy-Anchored Claims).

The credit represents only the service rights stated in its terms. A receipt can attest historical work and a voucher can promise future capacity; neither becomes the fee/staking medium or inherits the base asset’s conditional monetary candidacy.

Energy Anchoring

Like PoW, Work Credits are ultimately energy-anchored:

  • The marginal cost of producing one more credit is bounded below by the energy and hardware required to pass the verification threshold.

  • Where SHA-256 PoW has no buyer for its work, this work has one: it powers privacy settlements, proofs of provenance, and AI computation.

This anchoring gives Work Credits:

  • Credible scarcity: You cannot mint Work Credits without expending real resources to produce proofs and settle flows.

  • Economic meaning: One credit corresponds to a service somebody was willing to pay for (anonymized payrolls, authentic media, verified inference).

And the cost of the same property.

The buyer that gives a Work Credit its economic meaning is also an attack surface the hash puzzle does not have. Demand for SHA-256 work cannot be subsidized away, mandated, or sanctioned, because there is nobody to subsidize, mandate, or sanction; demand for verified inference can be all three. The energy anchor is therefore a service-cost and provenance anchor, not a monetary one. Bitcoin’s monetary objectivity and a Work Credit’s link to real activity are different properties (§30: Objections & Responses).

Layer 0 Maturity and Economic Consequences

Work Credits are only as trustworthy as the hardware that produces them. A world where all proving runs on opaque, vendor-controlled hardware is different from one with diversified, partially open designs.

§14: Layer 0: Verifiable Machines & Energy (Part III) defines a Layer 0 maturity ladder with grades L0-A through L0-D. Here we preview how those grades affect Work Credit economics:

L0 GradeHardware Trust LevelEconomic Treatment
L0-AClosed hardware + attestation + multi-party audits + diversityWC accepted at full value if diversity thresholds met; risk premium priced into fee schedules
L0-BLot sampling + imaging + bounded side-channel budgetsWC accepted at full value; lower risk premium
L0-CPartial open (open RTL for critical components)WC may qualify for “open-profile” premium or priority tiers
L0-DFully open designsHighest trust tier; may command premium in markets that value sovereignty
How this affects issuance and pricing:
  1. Tiered issuance caps: WC minted on L0-A profiles may face stricter issuance limits than L0-C/D profiles. This prevents the system from becoming dependent on opaque hardware.

  2. Market pricing: WC from different L0 grades can trade at different prices if markets distinguish them. Treasuries and institutions may pay premiums for L0-C/D-backed capacity.

  3. Risk disclosure: Every Work Receipt includes the hardware profile (HID) used. Aggregated telemetry shows what fraction of total WC is backed by each grade.

  4. Deprecation impact: If an L0-A profile is compromised (TEE backdoor discovered), WC minted on that profile can be quarantined, discounted, or excluded from certain uses. This is the “bond downgrade” analog.

Why this matters for service-claim quality:

If 90% of Work Credits are minted on L0-A hardware and a major TEE is compromised, claim quality and DVC take a hit—not because the cryptography failed, but because the service path depended on a common hardware assumption.

By making L0 grade explicit and tying it to economic consequences, the system:

  • Creates incentives to invest in open hardware.

  • Bounds the impact of hardware compromises.

  • Gives users and allocators the information to price risk appropriately.

This is covered in detail in §14.3.1 (Layer 0 Feasibility Ladder). The key point for Part II: hardware trust is not binary; it is graded, measured, and priced.

Robots, AI, and the Demand for Work Money

In a robot- and AI-heavy economy the demand story for Work Credits becomes almost embarrassingly straightforward.

Consider a warehouse or factory where most of the physical activity is carried out by robots, and most of the planning and oversight is handled by models. The day-to-day budget splits into:

  • Energy to power robots and data centers.

  • Compute to run models and generate proofs.

  • Privacy and settlement to pay workers, suppliers, tax authorities, and investors without leaking trade secrets or exposing everyone’s graph.

Each of those budgets expresses itself as a recurring need for receipts:

  • Proof of correct inference for high-stakes decisions.

  • Proof of compliance and risk calculations for regulators and insurers.

  • Privately settled wages and vendor payments with lawful audit trails.

Today that flow is mediated through cloud bills, payroll files, bank wires, and audit PDFs. In the stack described here, it can be mediated through Work Credits and receipts. The robots and services are paid in typed claims; in exchange they produce receipts that can be verified cheaply and settled over privacy rails. High turnover can make the claims useful working balances. It does not establish reserve demand for them or for the base asset.

This is one concrete way to discipline remarks like “money will just be energy.” Energy, compute, and hardware are inputs; Work Credits denominate future access to verifiable, robot-mediated output. They do not become joules, reserve assets, or monetary anchors by denomination.

Why Work Credits Remain Service Claims

Scarcity, transferability, public verification, censorship resistance, and recurring demand can make a Work Credit a high-quality commodity or forward service claim. They do not answer the monetary question. The credit remains exposed to workload basis, location, hardware, SLA, expiry, delivery, and common-cause risk; a promise of future service may also carry duration. DVC and evidence artifacts determine whether the claim is fulfillable. The Native Monetary Buyer Map determines whether the separate base asset has a holder constituency capable of bearing loss. Neither inference may be borrowed from the other.

Monetary Role

Work Credits sit at the junction between base capacity and service contracting:

  • For operators, they are revenue in kind: miners/provers/routers earn credits by contributing triad capacity.

  • For users, they can be pre-paid capacity: hold credits to secure future access to specified triad services, or trade expected scarcity.

Their service value depends on:

  • Demand for specific workloads: Work Credits tied to high-value workloads (e.g., compliance proofs, LLM inference) may command higher premia.

  • Governance & telemetry honesty: If VerifyPrice and decentralization metrics are falsified or gamed, the link between credits and real work weakens.

  • Regime pressure and deliverability: Differential demand may rise as substitutes weaken, while DVC may fall; the Pressure–Capacity Corridor prevents a monotonic crisis claim.

In portfolio terms, Work Credits are typed service or capacity exposure. LP and staking positions are the equity-like or derivative layer; the base asset is evaluated separately.

Issuance: Tying Credits to Real Capacity

There are many possible issuance schemes; what matters here is not choosing a particular curve, but enforcing two principles:

  1. Issuance is legible.

  2. Issuance is constrained by real capacity.

One extreme is the Bitcoin model: a fixed schedule, regardless of demand, with the understanding that price will equilibrate. Another extreme is a pure capacity-linked model: Work Credits are minted only when new proving, compute, and settlement capacity comes online and is registered with telemetry; they behave almost like tokenized capacity reservations. In practice, a hybrid is likely: a predefined issuance envelope over time, modulated by capacity growth and burn.

In such a system, adding a new proving cluster, plant, or corridor is not just a marketing slide; it is an event that expands the envelope of Work Credits the system can credibly support. The converse is also true: if plant retires or corridors die and are not replaced, issuance that continues on autopilot will show up as VerifyPrice drift, SLA breaches, and deteriorating energy metrics. The governance layer’s job is not to guarantee any particular price, but to keep issuance and capacity in rough proportion and to make any departures visible.

From an allocator’s perspective this yields a familiar pattern: Work Credits look like equity in (or claims on) a portfolio of infrastructure (proving farms, AI chains, privacy corridors, and plants) rather than a purely arbitrary balance sheet. The difference from conventional “infra tokens” is the insistence on receipts and KPIs: if claimed capacity and observable behavior diverge, the discrepancy is not a rumor; it is a datapoint.

The Supply Balance Equation

A critical question for any capacity claim is: why does demand not simply expand supply, neutralizing scarcity?

If Work Credits are minted whenever verified work is done, and demand for triad services grows, supply grows too. That is compatible with a service claim and is one reason not to treat WC as a scarce reserve asset.

The answer lies in the net supply dynamics. We can express this as a balance equation:

ΔOutstanding WC=IssuanceRedemption/RetirementLost±Governance\Delta\text{Outstanding WC} = \text{Issuance} - \text{Redemption/Retirement} - \text{Lost} \pm \text{Governance}
TermDefinitionTypical Magnitude
IssuanceNew WC minted against Work Receipts, subject to issuance envelopeBounded by schedule or capacity ceiling
Redemption/retirementWC destroyed when the specified service is delivered or the claim expiresSet by contract terms
LostWC in lost/forgotten wallets\sim1–2% of supply per year (empirical from BTC)
GovernanceAdjustments via protocol upgrades (rare, requires supermajority)Near zero in steady state

For Work Credit supply to remain aligned with deliverable service, the design must ensure:

Outstanding claimshaircut stress-adjusted DVC over the delivery horizon.\text{Outstanding claims} \leq \text{haircut stress-adjusted DVC over the delivery horizon}.

This is a service-solvency condition, not a monetary-scarcity condition:

  • During growth: Work Credit issuance may grow with independently verified DVC and contracted demand.

  • At maturity: Claims retire through delivery, expiry, or cancellation under published terms. Scarcity can affect service price without making the claim a reserve asset.

What prevents runaway issuance?
  1. DVC envelope: Total WC outstanding for each workload, tier, and horizon is capped by haircut stress-adjusted DVC.

  2. Capacity evidence: The envelope expands only when FERs, FCRs, hardware profiles, and scenario flow support additional deliverable service.

  3. Contract retirement: Delivery, expiry, cancellation, and default rules remove or impair claims explicitly.

  4. Governance friction: Changes to service-claim rules require supermajority and are visible in dashboards before activation.

Telemetry that detects supply risk:
  • Inflation rate: Issuance / circulating supply. Should decline over time.

  • Burn rate: Burns / fee volume. Should stay within target range.

  • Net supply change: Δ\DeltaSupply per epoch. Positive during growth, flat or negative at maturity.

  • Issuance vs. capacity: If issuance grows faster than verified capacity, this signals potential dilution.

If these metrics drift outside healthy ranges, it becomes visible in dashboards—holders and operators can respond before the SoV thesis is undermined.

Energy-Priced, Not Energy-Pegged

In popular discourse one often hears that “money will just be energy,” especially in the context of robotics and AI. As shorthand, this is attractive: robots and data centers run on electricity, so why not quote everything in kWh and be done with it? The problem is that not all kilowatt-hours are created equal. Time of day, grid node, reliability, carbon intensity, and siting constraints all affect their economic and political meaning. A winter-peaking kWh on a stressed urban grid is not the same as a curtailed hydro kWh in a remote valley. If we pretend otherwise, we smuggle a lot of hidden politics and risk into the unit of account.

The discipline in this thesis is to admit that complexity and route around it with receipts.

Energy is measured and wrapped into Facility Energy Receipts (FERs), which record, for each facility and time window:

  • kWh in,

  • kWh delivered to IT,

  • heat reused,

  • PUE/ERE/WUE,

  • water use,

  • carbon intensity,

  • and outages/curtailments.

On top of that, we measure verified work per kWh:

  • ηvFLOP\eta_{\text{vFLOP}} for FLOPs,

  • proofs-per-kWh for proof workloads,

  • swaps-per-kWh for settlement.

VerifyPrice then tells us how much it costs, in time and money, for an independent verifier to check that a given amount of work was done.

The result is an implicit conversion path:

energy \to FERs \to verified work (proofs/FLOPs/swaps) \to receipts \to Work Credits

We never pretend that one Work Credit is one kilowatt-hour; instead we make it easy for anyone to estimate, at any given time, how many kilowatt-hours of which quality and where in the world sit behind a portfolio of Work Credits, via the receipts.

Pricing in energy then becomes an inference problem for markets:

  • Work Credits are implicitly energy-priced because their production and redemption depend on energy-intensive workloads whose cost curves are public.

  • FERs and VerifyPrice make those curves legible without forcing a brittle kWh peg.

What distinguishes Work Credits from naive “energy tokens” is precisely this separation:

  • The unit of account is denominated in work, not in kWh.

  • Energy enters through FERs, ηvFLOP\eta_{\text{vFLOP}}, and VerifyPrice, not through a one-dimensional peg.

Markets, regulators, and builders can look at those receipts and say, with some confidence, “a Work Credit currently corresponds to about this much capacity, with this energy and carbon profile, under these SLAs.” That is enough to make the asset priceable and analyzable without forcing it into a crude energy standard.

Why Work Credits Are Typed Service Claims, Not Presumed Money

It is equally easy to make the opposite error: to observe that Work Credits are scarce, transferable, and tied to necessary workloads, then promote them from service claims into money by vocabulary. This thesis no longer makes that move. A Work Credit is a typed claim on capacity or service whose quality depends on workload, location, hardware, SLA, delivery window, and the stressed path that can actually fulfill it.

  1. Issuance is constrained by stress-deliverable capacity, not nameplate capacity.

    FERs, FCRs, and Delivered Verified Capacity bound claims by the service that survives scenario-specific minimum cuts. Gross installed hardware, energy procurement, or benign-state output is insufficient.

  2. Demand can be budgeted without being monetary.

    Proofs, inference, settlement, and related workloads may sit on recurring OPEX lines. That supports a service market. It does not establish reserve demand, long holding periods, self-custody, loss-bearing capacity, or countercyclical accumulation.

  3. Verification makes the claim legible, not monetary.

    A PIDL receipt can make fulfillment cheap to check and FCR/FER artifacts can make provenance auditable. Evidence reduces information asymmetry; it does not erase delivery, basis, counterparty, or temporal risk.

  4. The claim must not absorb project duration by implication.

    A prepaid capacity claim, a claim on future service, and a project note are different instruments. If a Work Credit promises par, redemption, a coupon, or emergency support against construction failure, it has become duration-bearing credit and must be labeled and underwritten as such.

Work Credits therefore belong beside capacity vouchers and service contracts, not automatically beside the base monetary candidate. They may trade at a premium for scarce delivery rights and may serve as collateral where their terms permit. Those are properties of typed service claims. Monetary treatment remains a separate empirical question answered, if at all, by the holder-side mechanism and buyer map.

Economic Linkage: How Triad Demand Becomes Asset Value

This subsection answers the question that separates a systems manifesto from a monetary thesis: Why does demand for Privacy, Proofs, and Compute raise the value of holding the asset, rather than merely rewarding consuming a service?

The answer has four parts.

1. What exactly is the asset?

The asset in this framework can take several forms, but all share a common structure:

  • Network tokens: Native units of the protocol (analogous to ETH or BTC) that are required to pay fees, post collateral, and participate in governance.

  • Work Credits: Claims on verified capacity, minted against energy-anchored work.

  • Corridor/Pool shares: LP positions or staking rights in specific privacy corridors, proof factories, or compute networks.

What matters is that all uses of the triad must flow through the asset. You cannot get a proof, settle a private payment, or buy verified compute without either holding or acquiring the native unit.

2. Why is it scarce in a monetary sense?

Scarce capacity does not automatically imply a scarce asset. The link is forged through:

MechanismHow It Creates Monetary Scarcity
Capped issuanceTotal supply follows a predefined schedule (e.g., halvings) or is bounded by capacity growth, not governance fiat.
Fee burnsA portion of every fee is permanently destroyed, removing units from circulation as usage grows.
Collateral lockupsProvers, routers, and LPs must bond assets to participate; this removes circulating supply proportionally to network activity.
Energy-anchored mintingNew credits are issued only against verified work backed by FERs; you cannot mint by decree.

The result: supply is bounded by physics (energy, hardware) and shrinks with usage (burns), while demand is driven by compulsory workloads. This is the scarcity structure of a commodity, not an IOU.

3. Why does demand for triad capacity raise the value of holding the asset?

The naive chain runs: demand \rightarrow users must acquire tokens to pay fees \rightarrow fees paid, a portion burned \rightarrow burns reduce supply while demand rises \rightarrow “increased demand + reduced supply \rightarrow price appreciation” \rightarrow holders capture the triad’s economics. Steps 1–4 are routing mechanics and survive review. Steps 5–6 are the tokenomics inference, and §10: Work Credits: Energy-Anchored Claims withdraws them: a burn is a buyback, a fee stream is a DCF input, and neither confers moneyness. The sentence this section will stand behind is narrower: the holder is buying a competitively priced claim on a fee stream bounded by Δ\Delta, plus a collateral floor. Where any premium beyond that could come from is deferred to §10: Work Credits: Energy-Anchored Claims.

More concretely:

  • Fee revenue: Every proof, every private settlement, every verified inference pays a fee denominated in the native asset. This routes service demand through the asset — the routing claim only; §10: Work Credits: Energy-Anchored Claims bounds what the fee can be.

  • Burn mechanics: A fraction (30–50% in the reference design) of fees is burned. Whether burns exceed issuance at steady state is an empirical outcome the fee-coverage boards measure, not a design guarantee.

  • Required collateral: Provers, routers, and LPs must stake tokens proportional to their capacity. This locks supply and aligns incentives with network health; §10: Work Credits: Energy-Anchored Claims bounds how much lockup the system can carry.

  • Priority/governance rights: Holding grants access to premium SLA tiers, governance votes, and first-mover allocation of scarce capacity.

Key insight: The holder is not buying “exposure to price” (reflexive speculation). The holder is buying a share of the fee stream from indispensable workloads, denominated in an asset whose supply shrinks as those workloads grow. This is closer to equity in a utility than to a collectible.

4. What prevents capacity providers from capturing all value while holders get diluted?

This is the classic “utility token trap”: if operators earn all the fees and governance can inflate supply, holders are just exit liquidity.

The stack avoids this through:

RiskMitigation
Operator rent extractionFees are split: burn + stakers + provers. Operators cannot capture 100%; a structural portion goes to asset retirement.
Governance inflationIssuance is constrained by FERs and capacity telemetry. Minting beyond real capacity triggers SLO breaches visible in dashboards.
Holder dilutionBurns offset new issuance. Net supply is designed to be flat or declining during steady-state usage.
Value leakage to fiatCore operations (fees, collateral, rewards) are denominated in the native asset, not fiat. Fiat is an off-ramp, not the unit of account.

The economic design goal: routing integrity — fees flow to retirement, staking, and operator share in fixed proportions, and issuance beyond verified capacity is visible in telemetry. Whether that routing produces flat or declining net supply is an outcome the fee-coverage and issuance boards report, not a promise made here.

Summary: the Value Capture Lemma in plain language

Demand for triad capacity (Privacy, Proofs, Compute) becomes store-of-value premium for the native asset only if all five of the following hold at once:

  1. All usage requires the asset (required fee medium; no substitute at equivalent service quality).

  2. Usage retires supply (a meaningful share of fees is burned or permanently retired).

  3. Capacity provision requires staking (operators lock the asset as collateral).

  4. Issuance is constrained by schedule or verified capacity, not by governance fiat.

  5. Capacity cannot be bypassed (no cloud contract, stablecoin-denominated service, or direct fiat payment to an operator delivers equivalent capacity without touching the asset).

These conditions are necessary, not sufficient. If any one of them fails, the system may be indispensable infrastructure and still not a store-of-value asset. Nothing here establishes the converse, and the thesis does not claim it.

A related but separate claim. The five conditions are properties of the monetary design; they say nothing about the durability of the demand the design is routing. That is a distinct empirical claim—that workload demand is structural (AI, commerce, and compliance budgets rather than hype cycles)—and the thesis treats its failure as its own falsifier rather than as a condition of the lemma: a workload mix that becomes and remains predominantly speculative retires the store-of-value claim through Red Line 5 (§27: Risk Analysis & Failure Modes), not through this lemma.

This is the bridge between “these capacities are indispensable” and “therefore a specific asset, rather than its operators or its customers, captures the value of supplying them.”

What the five conditions do not address.

Every one of them governs where fees go. None governs how large they can be, and a routing rule applied to a fee of nothing captures nothing. §10: Work Credits: Energy-Anchored Claims takes up the level question, finds that the standard objection to taxing a contestable market is wrong for a reason worth stating, and then finds that the correct answer supports a narrower conclusion than this Part has been drawing. The conditions themselves are unchanged.

The lemma has a frequently-missed converse. It states the conditions under which native demand accrues economically to the asset. It does not state that movements in the asset’s observed market price are caused by that native demand. Those are different machines, and conflating them is the most common way a monetary thesis fools its own author.

Value Capture vs. Price Capture

It is worth separating the two phenomena explicitly, because the thesis is routinely “confirmed” by the wrong one.

Value capture is the existing loop: triad usage \rightarrow native fees \rightarrow burns, collateral lockup, and operator demand \rightarrow scarcity and cash-flow accrual to the asset. It is governed by §10: Work Credits: Energy-Anchored Claims. What it produces is a claim on a fee stream plus a collateral floor; whether the asset also carries monetary premium is a separate question, answered separately in §10: Work Credits: Energy-Anchored Claims.

Price capture is demand for exposure to the asset’s price, arriving through spot ETFs, exchange custody, treasury companies, margin products, options, futures, swaps, leveraged and inverse ETPs, passive indices, and systematic trading rules. Price capture can occur with no protocol use whatsoever.

Native value capturePrice captureInterpretation
StrongStrongGenuine adoption plus favorable market realization
StrongWeak/negativeProtocol improving while wrappers or risk markets sell
WeakStrongFinancialized speculation or wrapper-led adoption
WeakWeakFailed or immature monetary thesis

Native value capture and observed price appreciation are neither equivalent nor mutually necessary. Only the top-left cell is monetary validation.

The diagonal is what makes the thesis falsifiable. A thesis that treats every price rise as confirmation and every price fall as noise cannot be wrong, and therefore cannot be right either.

Fee Incidence and the Level of the Fee

Every condition of the §10: Work Credits: Energy-Anchored Claims answers one question: where does the fee go? Required medium, supply reduction, collateral lockup, issuance discipline, and non-bypassability are all routing rules. None of them answers the question a valuation actually needs answered, which is how large the fee can be. A protocol that routes the whole of a fee of nothing into a burn address has satisfied five conditions and captured zero.

The gap has a sharp form, and it reached us as a fatal objection rather than as a note about an omission:

“You have deliberately engineered the most contestable market you could. Workloads are canonical and interchangeable, verification is cheap enough that no trust is required, admission is open, and there are no vendor chokepoints. A contestable market competes economic profit to zero. Zero profit means no surplus, and no surplus means nothing to burn.”

The objection is wrong. It is worth showing exactly why, because the correct answer rescues considerably less than it first appears to, and what survives is not the claim this Part started with.

Incidence: A Fee Is a Wedge on Turnover, Not a Claim on Profit

The objection conflates two different bases. A protocol fee is levied on transactions, not on residual profit. It is a tax wedge, and tax wedges do not require anybody to be earning rents.

Take the market the thesis is trying to build: many providers, free entry, roughly constant returns to scale in the relevant range, a canonical workload so that units are fungible. Long-run supply is then approximately horizontal at marginal cost cc. Impose a per-unit protocol fee ff on that market and the supply curve the buyer faces shifts to c+fc+f. The new equilibrium has buyers paying c+fc+f, providers receiving cc, and providers earning exactly the zero economic profit they earned before. The protocol collects fQf \cdot Q. Nothing about that revenue came out of operator margin, because there was no operator margin to take it from; in the long-run competitive case the entire statutory burden lands on the buyer.

Operator margin compression is irrelevant to fee revenue. The fee is a wedge on turnover. Turnover is what a contestable market maximizes.

This is standard incidence analysis, and it means the objection proves too much: if contestability destroyed fee bases, no commoditized market could ever be taxed, and every one of them is.

Incidence explains who bears a fee. It does not explain why a positive fee is sustainable, and the two should not be run together. Exchanges, clearing houses, and toll roads are lucrative on top of viciously competitive flows for a further reason: the flow is competitive but the fee layer is not. There is one place to clear the contract, one road across the water, one book where the trade is legally final — so the competition among users of the layer never becomes competition to be the layer. That inescapability is a property those venues possess and a protocol must earn; it is the subject of §10: Work Credits: Energy-Anchored Claims and §10: Work Credits: Energy-Anchored Claims, and the fork channel is precisely the case where it is not earned.

The short run is different, and the difference matters.

With installed capacity fixed, supply is not horizontal. Deployed hardware has already sunk its capital, so in the short run the supply curve slopes upward and part of the fee is absorbed as a reduction in quasi-rent to existing machines rather than passed to buyers. That is not a problem for this quarter’s fee revenue; it is a problem for the next round of capacity. Quasi-rent is what funds replacement, and an operator whose realized return on deployed hardware is being clipped by a fee re-prices the entry decision accordingly. The long-run pass-through result therefore describes the destination, not the transition, and the transition is where entry and capacity growth are decided. A fee schedule set as though incidence were instantaneously long-run will suppress the capacity it is trying to tax.

The Base, and Why It Deflates

Fee revenue is not ff. It is

Rev=fQ(cp+f),\mathrm{Rev} = f \cdot Q(c_p + f),

and both terms are endogenous. Two consequences follow, and the second is the more serious one.

Quantity responds to the wedge.

The tollbooth analogy holds only where there is no parallel free road. Raising ff raises the delivered price, and at the margin some volume declines, defers, batches, or leaves. What the protocol can extract is bounded not by what buyers would pay for the service but by what they would pay through this channel rather than the next-best one, which is the subject of §10: Work Credits: Energy-Anchored Claims.

An ad valorem fee on a deflating unit price is a shrinking real toll.

§9: Compute Through the “AI Money” Lens argues that verified compute stays scarce even as raw compute deflates. Grant that argument entirely; it does not touch this one. Even if the verification premium is fully durable, a fee expressed as a percentage of a unit price that falls secularly collects fewer real resources per unit of service delivered every year. Real fee revenue then grows only if

growth in verified units deliveredvolume  >  rate of decline in real unit pricedeflation.\underbrace{\text{growth in verified units delivered}}_{\text{volume}} \;>\; \underbrace{\text{rate of decline in real unit price}}_{\text{deflation}}.

That inequality is an empirical bet, not a theorem, and the thesis is making it. It may well be a good bet — the historical pattern in compute is that unit-cost decline is met by more than proportional volume expansion — but the thesis has nowhere stated it as a bet, measured it, or said what would settle it against us. Condition B of Red Line 14 (§27: Risk Analysis & Failure Modes) exists to settle it: deflation-adjusted fee-plus-burn turnover that fails to grow while physical throughput grows is this bet losing, in public.

The Bound on the Sustainable Fee

Incidence tells us the fee has a base. It does not tell us how high the fee can be set. That ceiling is not a function of operator margin either; it is a function of what the protocol channel is differentially worth.

Differential Value Δ\Delta and the Sustainable Fee Bound

Let cpc_p be the protocol’s all-in cost of delivering canonical workload WW at tier TT, and cbc_b the all-in cost of the best bypass channel delivering the same computational content without protocol-grade verification. Let Δ\Delta be the marginal buyer’s willingness to pay for the protocol’s differential properties: cryptographic checkability, neutrality, credible non-discretion, and non-custodial exit.

The buyer routes through the protocol only if cp+fΔcbc_p + f - \Delta \le c_b, so the sustainable fee satisfies

  f    Δ(cpcb)  \boxed{\; f \;\le\; \Delta - (c_p - c_b) \;}

Here Δ\Delta is a scalar wedge in price units, not the difference operator used elsewhere in this Part.

The first term is the one a protocol designer wants to think about. The second is the one that decides the outcome, and it is structurally positive: verified compute costs more to produce than unverified compute, because proving overhead and redundancy are real resources spent on top of the underlying work. So the protocol begins every negotiation with a cost handicap and must recover it out of Δ\Delta before it collects a single unit of fee.

The document’s own tier multipliers are cost pass-through, not evidence of willingness to pay.

§19: Layer 4: Truth & Work sets fee multipliers of 1.5×1.5\times for Silver and 2.5×2.5\times for Gold. Read the same table’s redundancy column: Silver is 2×2\times verification, Gold is 3×3\times verification plus audit. The multipliers are approximately what it costs to deliver the tier. They are a statement about cpc_p, and nothing in the document establishes that any buyer’s Δ\Delta at Gold tier is 1.5×1.5\times larger than at Silver. If it is not, then headroom narrows as tiers rise, and at high tiers Δ(cpcb)\Delta - (c_p - c_b) can be negative — a tier that is technically superior, honestly priced, and unsellable. That is a testable prediction against the thesis and it is now measured (§27: Risk Analysis & Failure Modes, Red Line 14), because it should not have been left as an inference from a table caption.

Bypass Is a Magnitude, Not a Binary

Condition 5 of the §10: Work Credits: Energy-Anchored Claims is written as an existence condition — users cannot obtain equivalent capacity through a bypass channel — and Red Line 6 is written as a direction condition: usage grows while native fees do not. Neither is wrong, and neither is changed here. But both are read, in practice, as though bypass were a switch.

It is not. Bypass is never impossible. It is priced. There is always a channel that delivers the same computational content without protocol-grade verification, and the only question is what the buyer gives up by using it — which is exactly Δ\Delta. Condition 5 should therefore be read and measured as a magnitude claim: not “no bypass exists,” which is false everywhere, but “Δ\Delta is large enough, for enough of the volume, to support a fee worth burning.” The condition stands as stated. Its interpretation is what this section tightens, and its measurement is what Red Line 14 supplies.

This is why the chain-strength rating for non-bypassability is reduced from Strong to Medium in this version (§6: The Triad and the Monetary Candidate). The condition is well specified as a binary and the binary is well enforced. The economics requires a magnitude, and the magnitude is nowhere estimated. A rating of Strong was a rating of the enforcement machinery, not of the quantity the argument depends on.

What Determines Δ\Delta, and Why It Is Probably Thin

To first order, the differential value of a proof is the loss it prevents, times the probability that loss survives the alternative:

Δ    ϱL,\Delta \;\approx\; \varrho\,\mathcal{L},

where L\mathcal{L} is the loss from undetected misexecution or denial of service and ϱ\varrho is the residual probability of that loss under the best bypass channel. (ϱ\varrho and L\mathcal{L} are used rather than the conventional π\pi and LL, which denote the inflation rate in §2: The World Forces New Monetary Primitives and the leverage multiple throughout VerifyFlow and Appendix H: Formal Model of Market Realization, Wrapper Flows, and Price Capture.)

Δ\Delta is a distribution, not a number.

Before evaluating either term it is worth fixing what object Δ\Delta is. Every buyer has their own ϱ\varrho and their own L\mathcal{L}, so Δ\Delta is a distribution across the buyer population, and the fee bound of §10: Work Credits: Energy-Anchored Claims binds at the marginal buyer — the last one the protocol wants to retain at the posted fee — not at the median one. These come apart, and the difference is the whole commercial question. A thin median is entirely consistent with a lucrative fee, provided the upper tail is deep enough to be worth serving: counterparties nobody will indemnify because they are sanctioned or pseudonymous, flows crossing jurisdictions where no single forum will hear the claim, regulated model-risk and audit functions that must evidence correctness to a supervisor rather than merely believe it. For those buyers ϱ\varrho is not small, because the indemnitor substitute is unavailable rather than merely inferior. The protocol’s commercial problem is therefore not “is the median workload willing to pay,” which it plainly is not, but “is the high-Δ\Delta tail large enough, and reachable enough, to carry a fee.” That is a sizing question the thesis has not answered, and Red Line 14 measures it capacity-weighted across the served mix rather than assuming it.

And at the median the answer is unflattering.

Written as ϱL\varrho\,\mathcal{L}, the critical term is ϱ\varrho, and here the thesis has been flattering itself. The bypass channel is not “unverified.” It is reputationally and contractually verified. A hyperscaler’s alternative to a cryptographic proof is its balance sheet, its SOC 2 and ISO audit reports, its published incident history, and an indemnity clause enforceable in a court that will actually hear the case.

A creditworthy, suable indemnitor is an excellent substitute for a cryptographic proof.

For an ordinary commercial workload in a benign state, the buyer’s exposure to undetected misexecution is not L\mathcal{L}; it is L\mathcal{L} net of a contractual recovery from a solvent counterparty under a legal system that functions. That makes ϱ\varrho small, and therefore Δ\Delta thin over the bulk of the distribution. Thin Δ\Delta against a structurally positive (cpcb)(c_p - c_b) is the strongest form of the objection this section opened with, and it is not answered by incidence analysis. It has to be stated plainly, because a critic will otherwise state it first and more crudely: for the median commercial workload in a working legal order, cryptographic verification is a premium product competing against a cheaper substitute that is good enough. What that sentence does not say — and what a fair reading of it must preserve — is that the median is the marginal buyer. It is not, and the fee is set against the tail.

Two Bypass Channels the Thesis Has Not Been Counting

Both of the following erode the base without tripping the instruments currently pointed at bypass.

Partial bypass at the intensive margin.

Bypass has been modelled as a routing decision — the buyer uses the protocol or does not. In practice the buyer uses less protocol per unit of underlying activity: batching many operations under one proof, aggregating proofs recursively, or using the protocol purely for attestation while executing the work elsewhere. Each is a legitimate engineering optimization, and each cuts native fees per unit of real economic activity. None of it registers as a Red Line 6 style “usage without fees” signal, because usage does still route through the protocol — just thinner. The correct denominator for fee intensity is the underlying economic activity being attested, not the count of protocol interactions, and the thesis has not been measuring it that way.

The protocol can be forked.

This is the more important omission. In an open-source, open-admission, canonically-specified market, the cheapest bypass channel is not a hyperscaler. It is this protocol, copied, with a lower fee and no burn. Every property the thesis is proud of — published workload specifications, open verifier implementations, permissionless participation, no vendor chokepoints — lowers the cost of producing that copy. A fork inherits the technology and discards the tax.

What actually prevents the fork from winning is not any of the five conditions. It is liquidity depth in the native asset, anonymity-set size in the privacy corridors, the installed collateral base and the operator relationships around it, the Schelling-point status of the workload registry, and the accumulated receipt history that makes one chain’s attestations worth citing. Those are network effects and coordination assets. They are not enforcement rules, and the thesis has been attributing the moat to enforcement rules. Stated honestly: §10: Work Credits: Energy-Anchored Claims explains why a user cannot get the service without the asset on this protocol. It does not explain why the user cannot get it on the copy. Whatever answer exists is a liquidity and coordination argument, it is empirical, and it belongs to link 7; whether holders then warehouse the asset’s risk belongs to link 8.

What the Five Conditions Establish, and What They Do Not

Collecting the above, the lemma survives with its scope corrected downward.

What they establish.

That a contestable market can be taxed and the proceeds routed to a token. Specifically: (i) a competitively priced claim on a cash-flow stream fQf \cdot Q, bounded above by Δ\Delta and deflating with unit price; and (ii) a balance-sheet floor from collateral required in the native unit. Both are real. Both are also, precisely, quantities that a discounted-cash-flow valuation captures — a fee stream and a lockup.

What they do not establish.

Monetary premium. A monetary premium is by construction value in excess of discounted cash flows; it is what gold has and a pipeline does not. §10: Work Credits: Energy-Anchored Claims states the holder as buying “a share of the fee stream from indispensable workloads,” “closer to equity in a utility than to a collectible.” That description is accurate — and it is why this section withdraws the tokenomics inference made above it. A utility equity earns its cost of capital; it does not carry monetary premium. The two registers now stated side by side in this Part — routing rules on the one hand, price-mechanics claims on the other — are separated deliberately: the routing rules are design commitments that survive, and the price-mechanics claims are retired here.

Two corollaries follow that the thesis should have drawn earlier:

  • A burn is a buyback. Economically, retiring supply with revenue is a pro-rata return of value to an existing claim. Buybacks change per-share value; they do not confer moneyness. No quantity of buyback has ever made an equity a store of value, and no burn schedule will do it either.

  • Collateral is a floor, not a premium. A required lockup denominated in the asset supports a valuation from below. It is a balance-sheet fact, and §10: Work Credits: Energy-Anchored Claims bounds how large a fact it can be.

The Test That This Reasoning Does Not Prove Too Much

If durable fee extraction from a commoditized flow made an asset money, the world would be full of monetary assets. CME clears standardized futures; DTCC settles equities; Visa takes a spread on card turnover; MSCI licenses indices that everyone benchmarks to; pipelines and port authorities meter physical throughput. All of them sit on flows more commoditized than canonical MatMul, all of them extract fees durably, several are structurally harder to bypass than any protocol will be, and not one of their equities is money. Visa’s take rate does not make Visa shares a store of value; it makes them a good business.

The comparison is the discipline. If the argument for the asset’s monetary premium is “recurring fees on indispensable throughput,” the argument is an argument for a high-quality utility equity, and it should be labelled as one. Something else has to be doing the monetary work.

Where a Monetary Premium Would Actually Come From

The constructive half. If fees, burns, and collateral yield a well-valued cash-flow claim rather than money, the monetary claim has to be relocated rather than abandoned — and the place it relocates to is one the thesis has already spent six Parts describing without noticing that it was the monetary argument.

Δ\Delta is not a constant; it is a function of regime pressure.

Write Δ(R)\Delta(R), with RR the regime-pressure index of Stage A (§10: Work Credits: Energy-Anchored Claims). §10: Work Credits: Energy-Anchored Claims showed why Δ\Delta is thin in benign states: a solvent, suable indemnitor substitutes for a proof. Invert that sentence and it names exactly when Δ\Delta is large. The substitute fails when the counterparty:

  • cannot be sued — cross-jurisdictional, pseudonymous, or sanctioned, so no forum will hear the claim;

  • will not be solvent when it matters — the failure is correlated, and the indemnity is worth least in exactly the state that triggers it;

  • is the adversary — a state, a platform, or a regulator, where the entity you would sue is the entity imposing the loss;

  • inflicts a non-compensable loss — censorship, seizure, deplatforming, or disclosure, where damages do not restore the position because the position was never about money.

That list is the threat model of §4: Threat Model, restated as a demand curve. The thesis is therefore internally consistent — but the consequence is unflattering to fee accrual as a monetary argument and places the monetary burden on links 8 and 9:

Δ\Delta is small in benign states and large in the tail. The asset’s usefulness is state-contingent, and its distribution is skewed toward exactly the states everyone else’s arrangements stop working in.

State-contingency does two different things, and only one of them is monetary.

The tempting move here is to say that an asset whose usefulness rises in states where the marginal utility of wealth is high must be worth more than the discounted expectation of its cash flows, because those cash flows arrive weighted by a high state price. That move fails the test this section’s own demolition just set. §10: Work Credits: Energy-Anchored Claims defined a monetary premium as value in excess of discounted cash flows, and a discounted-cash-flow valuation carried out with the correct stochastic discount factor already weights every cash flow by its state price. State-price weighting is precisely what a risk-adjusted discount rate is. An argument that stops there has relocated the monetary claim into the denominator of a DCF, which is not outside the DCF at all. The argument therefore has to be split into two mechanisms, one conceded and one kept.

Mechanism one: a negative beta on the fee stream. Real, valuable, and not monetary.

Because Δ(R)\Delta(R) rises when the substitutes fail, the fee stream is countercyclical with respect to regime pressure: the protocol can charge most for its differential properties in the states where wealth is scarcest. A rational investor pays more per unit of expected cash flow for that stream than for a procyclical one, and should. But this is exactly a discount-rate effect. It lowers the cost of capital applied to the same fee stream, it is fully representable inside a discounted-cash-flow valuation, and it therefore produces no moneyness. A countercyclical utility is a better utility, not a monetary asset. Conceded, and set aside: nothing in the monetary claim below rests on it.

Mechanism two: a holder-side service flow. This is where the moneyness is.

The bearer of the asset obtains something that is not a cash flow at all, and so has no cash flows to discount: the ability to transact, prove, hold, and exit at the moment when the substitutes for proofs, courts, and custodians have stopped working. That service accrues to whoever holds the unit, by virtue of holding it, and not by virtue of any distribution from the protocol. Nothing is paid out, so there is no stream to place in a numerator and no discount rate — correct, risk-adjusted, or otherwise — that reaches it. This is the same category of thing as the value of holding a bearer instrument outside the banking system, and it is why an asset with no cash flows whatsoever can carry a price.

The mechanism is standard, and the analogy is to the mechanism only.

That a non-cash-flow service from holding a thing can carry a price no cash-flow model reproduces is the storage-theory account of convenience yield in consumption commodities (Kaldor, 1939; Working, 1949): the holder of physical inventory obtains an option against stockout that the holder of a claim on future delivery does not. The analogy drawn here is to that mechanism — a service flow accruing to the bearer rather than to a claimant — and not to the setting. A triad asset is not a storage commodity, it faces no stockout risk in the storage-theory sense, and no magnitude in this thesis derives from the commodity literature.

Gold, which this thesis keeps comparing itself to, is a separate case and should not be filed under storage theory: gold’s convenience yield in the storage-theory sense is near zero, which is why its lease rates are negligible and its forward curve is essentially full cost of carry. What is true of gold is the part that matters here. It has no cash flows, negative carry, and industrial demand far too small to explain its price; every constructible DCF for gold returns a number well below the market. On the standard account that residual is monetary and portfolio demand — what holders pay for a bearer holding that is useful when other arrangements are not — which is the holder-side category described above, arrived at from a different direction.

Regime-Contingent Convenience Yield

The monetary premium available to a triad asset is the holder-side service flow generated by the state-contingency of Δ(R)\Delta(R) — the bearer’s ability to transact, prove, hold, and exit when the substitutes for proofs, courts, and custodians have stopped working — plus credible non-discretion in issuance, plus bearer holdability. The service accrues by virtue of holding rather than as a distribution, so there is no stream to discount. That is what places it outside a discounted-cash-flow valuation rather than merely at a different discount rate inside one.

It is not the countercyclicality of the fee stream. That is a negative beta on cash flows: real, valuable, and captured exactly by a DCF using the correct stochastic discount factor, which is why it confers no moneyness.

It is also not generated by burns, by collateral, or by fee share. Those produce a cash-flow claim and a floor (§10: Work Credits: Energy-Anchored Claims).

The consequence of the split is immediate. If the monetary claim rests on the holder-side flow, then it rests on the properties that determine whether a holder can actually use the thing under pressure — and none of those are fee-routing properties. Of the five lemma conditions, only issuance discipline touches the channel at all, and it does so because credible non-discretion is part of the payoff rather than part of the accrual. The other four are conditions for value accrual, and accrual is a DCF quantity. Link 8 then requires a persistent self-custodied constituency capable of bearing loss, and the monetary premium hangs off link 9 — liquidity, neutrality, verifiability, legal holdability, and agency preservation (§3: First Principles: What a SoV Must Survive) — which are exactly the conditions under which a bearer can transact, prove, hold, and exit when it counts. No burn schedule reaches the premium: a burn operates on the claim, and the premium is not on the claim.

Now discount it honestly.

The hedge has a defect, and it is the same defect the thesis has already documented without drawing the monetary conclusion. The payoff is negatively correlated with the states you fear — that is the point — but the delivery is positively correlated with them. The states in which Δ(R)\Delta(R) spikes are energy interdiction, hardware denial, network filtering, and jurisdictional pressure (§4: Threat Model, §14: Layer 0: Verifiable Machines & Energy), and those are precisely the states in which the protocol’s ability to supply privacy, proofs, and compute is impaired. §30: Objections & Responses half-concedes this and Red Line 13 makes the mechanism falsifiable, but both frame it as a threat to the hinge. It is also a discount on the hedging premium, which is the monetary consequence, and the honest statement of it is: you are being asked to pay a premium for insurance whose underwriter is exposed to the insured event.

Two further deductions from the same discount:

  • The slots are occupied. Gold already holds “works when the network does not.” Bitcoin already holds “works when the state does not.” Neither requires a grid at the moment of use — gold requires none at all, and a Bitcoin key survives an outage even where settlement waits. A triad asset needs power, reachable networks, and obtainable reference hardware in order to deliver anything at all, which makes it a hedge against a narrower and more specific band of failure: adversarial conditions severe enough to need proofs and privacy, but not severe enough to take the grid.

  • The band may still be the important one. That band — administrative repression, surveillance, synthetic media, platform and compute enclosure, financial repression without collapse — is the one Part I argues is most likely. Sovereign optionality (§14: Layer 0: Verifiable Machines & Energy) exists to widen it, and disruption-adjusted VerifyPrice (§14: Layer 0: Verifiable Machines & Energy) exists to price whether the widening is real.

And do not overclaim it.

The state-contingency argument establishes a mechanism. Non-cash-flow service flows accruing to a bearer are ordinary in asset pricing, and there is nothing exotic in claiming one here. The holder-side flow is nonetheless unsized: nothing in this document estimates how large a regime-contingent convenience yield a triad asset could command, and no honest estimate is available before there is a market in which to observe one. This is an empirical question the thesis has not answered. What it can do is refuse to smuggle the answer in — which is why the chain-strength rating for the store-of-value premium is Medium (conditional), why link 8 now asks who bears the asset’s loss, and why the relocated claim is attributed to link 9 rather than to fee accrual. The measurement instrument exists so that the question can be settled rather than asserted: §23: Extended Telemetry publishes the lending-rate, basis, and wrapper-basis series against the regime-pressure index, and a series flat across regime states is the null result, reported as such.

Collateral: Unit-Elasticity, Floor, and Wrong-Way Risk

Condition 3 requires operators to post the native asset as collateral, and the reference designs specify the requirement as a share of capacity value: “10–20% of capacity value” in §6: The Triad and the Monetary Candidate, a “10–15% collateral requirement” in Design A, and “proportional to their capacity” in §10: Work Credits: Energy-Anchored Claims. That specification has a consequence the document has never drawn.

Collateral Unit-Elasticity

Let KK be the USD value of deployed capacity, χ\chi the required collateral ratio, and PP the asset price. The number of units that must be locked is

N  =  χKP.N \;=\; \frac{\chi K}{P}.

The requirement fixes a value, not a quantity. Collateral demand is therefore unit-elastic in price: a doubling of PP halves the units required to satisfy the same obligation.

(χ\chi is used here for the collateral ratio because κ\kappa already denotes net mechanical gain in Appendix H: Formal Model of Market Realization, Wrapper Flows, and Price Capture and facility capacity share in §14: Layer 0: Verifiable Machines & Energy.)

It is a level effect, not a growth effect.

The mechanism immobilizes a fixed dollar quantity of float. It is a standing bid of fixed size, not of fixed quantity, and the valuation it supports grows only as deployed capacity KK grows — not as price grows. Describing it as “structural demand that scales with the network” is true only in the sense that it scales with physical build-out, and physical build-out is slow, capital-rationed, and observable.

And KK deflates too.

Capacity value is the replacement cost of deployed infrastructure. It therefore inherits the same deflation exposure as the fee base in §10: Work Credits: Energy-Anchored Claims: the same generation of throughput is worth fewer dollars of replacement capital each year. A collateral requirement pinned to KK shrinks in dollar terms unless deployed physical capacity grows faster than its unit cost falls. This is the same empirical bet, entering through a second door.

Reflexivity runs in both directions, and the second one is not in the document.

For small moves the mechanism is genuine negative feedback, and it is a real design achievement: price rises, fewer units are needed to cover the same χK\chi K, surplus collateral releases into float and meets the buying; price falls, operators must post more units, and they buy. An automatic stabilizer.

For large moves it inverts. Collateral denominated in the asset it insures loses value exactly when slashing risk and operator distress rise — textbook wrong-way risk, and in its dynamic form the familiar margin-spiral or leverage-cycle mechanism. The operator’s instruction in a drawdown is “post more units, at a moment when your existing holdings are worth less and your operating business is stressed.” A common answer is not to post; it is to exit capacity. Exiting reduces KK, which reduces required collateral, which releases locked units into a falling market. The stabilizer becomes an accelerant, and it does so through the same equation that made it a stabilizer:

P    N    operator exit    K    N    float    P.P \downarrow \;\Rightarrow\; N \uparrow \;\Rightarrow\; \text{operator exit} \;\Rightarrow\; K \downarrow \;\Rightarrow\; N \downarrow \;\Rightarrow\; \text{float} \uparrow \;\Rightarrow\; P \downarrow .

Nothing in the value-leakage mitigations of §10: Work Credits: Energy-Anchored Claims contemplates this loop, and no red line covers it. Naming it is the minimum; a metric for it — collateral coverage against realized slashing exposure, and capacity withdrawal rates conditioned on drawdown — belongs on the Value Capture Board (§23: Extended Telemetry) in a later pass, and this document should not pretend it is there yet.

The design tension, stated plainly.

Collateral must be the native asset in order to create native demand, which is the whole of Condition 3’s monetary contribution. Collateral should be uncorrelated with the risk it insures in order to be credible, which is the whole of prudential collateral design. You cannot have both. Any move toward external collateral — stablecoins, bonded fiat, over-collateralization in an uncorrelated asset — strengthens safety and weakens Condition 3’s monetary contribution by exactly as much. This is not a problem to be solved; it is a trade-off to be chosen deliberately and disclosed.

The magnitude bound.

χK\chi K is bounded by an accounting identity, and the arithmetic is worth doing even roughly. The following is an order-of-magnitude illustration, not an estimate: the inputs are chosen to be generous rather than defensible, and no claim rests on their precision.

Deployed capacity value KKLocked at χ=0.15\chi = 0.15Comparable
$1T (deliberately generous)$150BA single large-cap equity
$100B (more defensible)$15BA mid-cap equity

Order-of-magnitude ceiling on collateral lockup. Illustrative arithmetic on assumed capacity values, not a forecast; the point is the exponent, not the digits.

Those are large-cap-equity numbers. They are not monetary-aggregate numbers, and no choice of χ\chi inside a plausible range changes the exponent. Collateral therefore cannot be the source of moneyness. At best it is a floor.

The one real contribution, stated in the document’s own notation.

Collateral does do something, and it is worth being precise about what. It creates a holding constituency whose supply is highly price-inelastic — operators cannot sell locked units at any price without exiting the business — which shrinks effective free float and steepens the price response to a given flow. In the Stage C decomposition (§10: Work Credits: Energy-Anchored Claims), that is an operation on the liquidity and market-impact state Λt\Lambda_t, not on the native monetary impulse θt\theta_t.

Collateral is a slope effect, not a level effect. It changes how much price moves per unit of flow. It does not establish where price belongs.

And a slope effect cuts both ways: a steeper response to buying is a steeper response to selling. Calling this “structural demand” overstates it in one direction while concealing the symmetry in the other.

From Utility Demand to Monetary Premium

Many indispensable services—electricity, bandwidth, compute instances, legal services, cloud storage—have recurring demand without being stores of value. The monetary argument requires explaining why this utility becomes monetized savings demand, not just operating expense.

The bridge has eight conditions:

  1. Utility demand is not enough. Recurring demand for a service does not automatically create a scarce, holdable asset. Bandwidth is indispensable, but claims on bandwidth do not become money.

  2. The asset must be required for fees or settlement. Every use of the triad must flow through the base token. If operators accept fiat directly, the asset is optional.

  3. Fees must produce burns, retirement, or staking yield. Fee revenue must reduce circulating supply or compensate holders, not merely pay operators.

  4. Operators must post the asset as collateral. Provers, routers, and LPs must lock the asset to participate, immobilizing float beyond what fee payment requires. §10: Work Credits: Energy-Anchored Claims bounds what that lockup can be worth: it is a floor and a slope effect, not a source of premium.

  5. Issuance must be capped or capacity-constrained. New supply cannot expand by governance decree; it must track real, verified capacity.

  6. Users must not be able to bypass the asset at equal service quality. If AWS, a ZK prover marketplace, or a stablecoin-based privacy wallet can sell equivalent triad capacity for fiat, the native asset becomes unnecessary.

  7. Telemetry must prove the loop is working. Fee coverage, burn rates, collateral lockups, and workload demand must be publicly verifiable—not asserted.

  8. If any value-capture condition fails, the asset does not even capture its own service value. It becomes infrastructure exposure whose economics accrue to operators or customers rather than to holders. Meeting those five conditions makes service value accrue to the asset; it does not make the asset money, establish stress-deliverable service, or create a loss-bearing holder constituency.

This section is the “utility-token trap” defense. The thesis does not claim that useful things automatically become money; it claims that under specific, testable value-capture conditions, a useful asset accrues the value of its usefulness to its holders — a cash-flow claim and a collateral floor. Whether anything further, a monetary premium in excess of those, is available is argued separately and on different grounds in §10: Work Credits: Energy-Anchored Claims. The §10: Work Credits: Energy-Anchored Claims formalizes the accrual conditions; the telemetry regime (§22: Layer 6: Governance & Telemetry) makes them falsifiable.

Why Users Cannot Simply Bypass the Asset

The strongest economic objection to the thesis is simple: “Why can’t AWS, a ZK prover marketplace, or a privacy wallet sell the same service for fiat or stablecoins and bypass Work Credits entirely?”

The objection is valid unless the protocol enforces native value capture. The required mitigations:

  1. Core fees are denominated in the base token. Provers, routers, and settlement corridors accept only the native asset for protocol-level fees. Fiat or stablecoin payment requires acquiring the asset first.

  2. Collateral must be posted in the base token. Operators cannot participate without holding significant quantities of the asset. Calling this “structural demand” overstates it in one direction while concealing the symmetry in the other (§10: Work Credits: Energy-Anchored Claims): it immobilizes a fixed dollar quantity of float, which steepens the price response to flow in both directions rather than establishing where price belongs.

  3. Burns create scarcity tied to usage. A meaningful share of fees is permanently destroyed. Higher triad usage means lower circulating supply.

  4. SLA priority requires the asset. Gold-tier SLAs, governance participation, and priority access during congestion require holding or staking the asset.

  5. Settlement paths are natively denominated. Privacy corridors and settlement rails denominate in the base token; off-ramps exist but are not the default.

Honest admission: If users can in practice bypass the asset—for example, if most operators accept stablecoins and immediately off-ramp, or if hyperscaler-hosted provers dominate the market and set prices in fiat—then the SoV thesis fails. The system may remain useful infrastructure, but the monetary claim collapses. The telemetry must track this: native-asset fee share, bypass channel volume, and operator off-ramp rates should be visible on the Economic Coverage Board (§23: Extended Telemetry).

The Incumbent Bypass Channel Is Not Hypothetical

The five mitigations above answer a proposal. They do not answer a precedent, and a precedent exists: stablecoins already settle a large fraction of the value the thesis is targeting, at scale, at near-zero cost, with no native monetary asset anywhere in the loop. Tron and Ethereum carry stablecoin transfer volumes that exceed most national payment systems; in several emerging-market currency crises, dollar-stablecoin wallets — not Bitcoin, not Zcash — were the observed instrument of capital flight and censorship-adjacent settlement. That is a decade of revealed preference in exactly the states of the world this thesis calls State 3 (§26: Adoption Curve & Ecosystem Dynamics), and it is not engaged anywhere in the design.

The stablecoin channel is a live test of Condition 5 that has already been run, and the honest reading is unfavorable in three of four respects:

  • Where stablecoins beat the triad: benign and mid-band repression. A stablecoin settles in seconds, costs cents, has no learning curve, and — the uncomfortable part — offers practical censorship resistance to the median user, because freezing a Tron address is harder than freezing a bank account even though it is easier than censoring a shielded pool. For payments-motivated flight, the bearer-asset properties this thesis prices (privacy by default, portable proofs, verified compute access) are mostly not on the buyer’s list.

  • Where the triad can still differ: the upper band. The stablecoin’s weakness is structural and appears exactly where the thesis’s services begin: it is a claim on a custodian’s reserve and an issuer’s goodwill, it freezes under sanctions enforcement, it carries no proof or compute service, and its censorship resistance is borrowed from its host chain rather than owned. As repression crosses from financial into administrative and epistemic forms — compelled disclosure, platform deplatforming, attestation demands — the stablecoin inherits the substitutability of its issuer, not of cryptography. That is the band in which a triad asset’s Δ\Delta over a stablecoin is nonzero, and §10: Work Credits: Energy-Anchored Claims already prices the premium as regime-contingent.

  • The uncomfortable arithmetic. None of that changes the base fact: for the median settlement need in the states most likely to occur, the incumbent bypass channel is cheaper, faster, and already deployed. The thesis’s five mitigations make bypass harder on this protocol; they do nothing about bypass around it. Red Line 6 is therefore best read as already having an empirical prologue: every stablecoin-settled triad-adjacent payment is a data point that the capturable wedge must be measured against, not assumed above.

The design implication is not despair but precision: the asset’s fee-bearing services must be ones a stablecoin cannot express — private settlement where the stablecoin is a custodial IOU, proofs where the stablecoin is silent, verified compute where the stablecoin has nothing to verify. Where the triad service is interchangeable with a stablecoin payment, Condition 5 should be presumed failed, and the Value Capture Board’s stablecoin-denominated fee share series (§23: Extended Telemetry) is the instrument that watches it fail or hold.

Co-option as Bypass

The bypass threat is not always a competing product. It can also be institutional co-option: ETFs, treasury companies, margin loans, and regulated custody that deliver exposure to the asset’s price without requiring users to interact with the protocol’s privacy, proof, or settlement rails. If the majority of demand is satisfied by custodial wrappers that bypass the fee-burn-collateral loop, the asset’s price may rise while its monetary thesis weakens. The telemetry must distinguish between custodial exposure (which does not exercise value capture) and protocol-native usage (which does).

Wrapper Dominance Risk

Co-option as bypass is dangerous enough to warrant a named, top-tier risk rather than a sidebar. A protocol asset can succeed as a financial product while failing as money. If ETFs, custodians, treasury companies, broker-dealers, lending desks, and stablecoin wrappers satisfy most demand for exposure, the asset’s price may rise even as native settlement, privacy usage, fee burns, collateral lockups, and non-custodial flows stagnate. This is not a contradiction. It is the signature of wrapper dominance.

Wrapper dominance is dangerous because it turns a monetary network into a reference price. It creates holders without users, exposure without settlement, and liquidity without sovereignty. The asset can moon while the monetary thesis dies.

Wrapper Dominance Ratio (WDR)

Wrapper dominance has a stock component and a flow component, and they must not be divided into one another: exposure is measured at an instant, usage over an interval, so a single ratio would scale with the arbitrary length of the measurement window. WDR is therefore reported as a pair.

Stock form — what share of economic exposure sits in custodial or synthetic form, where EtwrapperE^{\text{wrapper}}_t and EtnativeE^{\text{native}}_t are exposures at time tt:

CustodialExposureSharet=EtwrapperEtwrapper+Etnative\mathrm{CustodialExposureShare}_t = \frac{E^{\text{wrapper}}_t}{E^{\text{wrapper}}_t + E^{\text{native}}_t}

Flow form — how activity divides over a stated horizon hh, where Vth:tV_{t-h:t} is volume across that window:

WrapperActivityRatiot,h=Vth:twrapperVth:tnative\mathrm{WrapperActivityRatio}_{t,h} = \frac{V^{\text{wrapper}}_{t-h:t}}{V^{\text{native}}_{t-h:t}}

The stock form is bounded in [0,1][0,1]. The flow form is not: it divides one volume by another, so it is bounded below by zero and unbounded above, and it is undefined when native volume is zero. Both are window-explicit. A rising stock share with a rising activity ratio indicates the asset may be financializing faster than it is becoming money. The horizon hh must always be published alongside the flow form.

Inputs to track: ETF/wrapper AUM; custodied balances; exchange balances; wrapped token supply; native fee share; non-custodial settlement volume; shielded/private settlement volume; staking/collateral lockups; fee-burn coverage.

Failure gate: If WDR rises for multiple quarters while native fee share, private settlement, and collateral lockups stagnate, the asset may remain investable but its SoV-as-protocol thesis is weakening. This gate is added to the Red Lines in §27: Risk Analysis & Failure Modes and tracked on a dedicated Wrapper Dominance Board (§23: Extended Telemetry).

The Market Realization Plane

The Wrapper Dominance Ratio measures a stock: how much ownership has migrated into custodial and synthetic form. It does not explain the flow mechanics by which those wrappers set prices. That requires one more construct.

Market realization is deliberately not an eighth layer of the stack. Layers 0–6 produce privacy, proofs, compute, settlement, and governance. Market realization produces none of those; it is the conventional financial machinery that represents claims on the resulting monetary object. It is orthogonal to the stack, so we model it as a plane around the stack rather than a layer within it.

Market Realization Plane

The set of external institutions and instruments through which claims on the native monetary object are represented, financed, allocated, and priced: exchanges and custody, spot ETFs, corporate treasury vehicles, index products, options and futures, leveraged and inverse ETPs, dealer swaps, prime-broker financing, passive mandates, systematic trend strategies, and rules-based or agentic treasury systems.

The result is two nested loops, and the thesis needs both to be instrumented.

The inner protocol loop determines whether the stack works:

Create/ComputeProveSettleVerify\text{Create/Compute} \rightarrow \text{Prove} \rightarrow \text{Settle} \rightarrow \text{Verify}

The outer market-realization loop determines how the stack is financially represented:

NarrativeWrapperAllocate/LeverDealer HedgePriceNarrative\text{Narrative} \rightarrow \text{Wrapper} \rightarrow \text{Allocate/Lever} \rightarrow \text{Dealer Hedge} \rightarrow \text{Price} \rightarrow \text{Narrative}

The inner loop determines native monetary function. The outer loop determines market-price realization. Either loop can strengthen while the other weakens, and the outer loop can run for years on narrative alone.

A Three-Stage Model

The combined thesis can now be stated as three linked but separable processes.

Stage A — regime pressure creates structural need. Let RtR_t index financial repression, surveillance, synthetic media, AI concentration, and compute demand. Regime pressure generates demand for triad capacity:

Dttriad=g(Rt)D_t^{\text{triad}} = g(R_t)

This is the causal layer developed in Part I.

Stage B — protocol design converts need into native value. Let ϕt[0,1]\phi_t \in [0,1] measure the effectiveness of the monetary design: required fees, burn share, collateral, issuance discipline, and non-bypassability. Then native captured demand is

Dtnative=ϕtDttriadD_t^{\text{native}} = \phi_t \, D_t^{\text{triad}}

As ϕt0\phi_t \rightarrow 0, the system can remain enormously useful while the monetary object fails. This is §10: Work Credits: Energy-Anchored Claims restated as a coefficient.

Stage C — market structure realizes native value as a price path. Observed price depends not only on native demand but on aggregate exposure flows and the liquidity available to absorb them:

ΔlnPt=θt+I(Qt,Λt)+ηt\Delta \ln P_t = \theta_t + I(Q_t, \Lambda_t) + \eta_t

where θt\theta_t is the fundamental or native monetary impulse, QtQ_t is aggregate exposure demand, Λt\Lambda_t is the liquidity and market-impact state, and ηt\eta_t is residual. Aggregate demand decomposes by source:

Qt=Qtnative+Qtallocation+Qtlevered+Qtdealer+QttrendQ_t = Q_t^{\text{native}} + Q_t^{\text{allocation}} + Q_t^{\text{levered}} + Q_t^{\text{dealer}} + Q_t^{\text{trend}}

Only the first term is monetary evidence. The remaining four can dominate the price for extended periods, in either direction. Appendix H: Formal Model of Market Realization, Wrapper Flows, and Price Capture develops the flow mechanics formally — holder flow elasticity, the net mechanical gain coefficient, the recycling boundary, market impact, and volatility drag — and §23: Extended Telemetry defines the telemetry that makes the plane observable.

Why a protocol should care about external market structure. A designer might object that this is someone else’s problem. It is not. External wrappers affect treasury behavior, collateral demand, governance concentration, liquidity-provider incentives, public understanding, security-budget expectations, regulatory pressure, and the price that the protocol’s own participants use when making decisions. The protocol should not manage its price. It must nonetheless instrument the structures through which its monetary claims are represented, for the same reason it publishes VerifyPrice: unmeasured dependencies are where theses go to die quietly.

The Numeraire Is Not Fixed

Everything above measures the price path in units of account whose own value is assumed constant. That assumption is doing more work than it appears to.

§10: Work Credits: Energy-Anchored Claims establishes that price is not evidence of monetary adoption. The point here is adjacent and independent: even a price series that is informative about the numerator can mislead through the denominator. A rising quotation may report an appreciating asset, a depreciating unit of account, or any combination of the two, and the series alone cannot distinguish them.

Numeraire-Dependence

The property that a measured price path is jointly determined by the asset and by the unit in which it is quoted, such that the same series can support opposite conclusions about real command over resources depending on the denominator chosen.

For this thesis the consequence is a measurement requirement rather than a philosophical observation. The Market Realization Plane exists to prevent financialization from being narrated as adoption. A plane instrumented only in the sovereign unit of account is blind to the case where wrapper-led appreciation and currency depreciation move together—which is precisely the regime §2: The World Forces New Monetary Primitives argues is likely.

Requirement.

The core market-realization series—the Wrapper Dominance Ratio (§10: Work Credits: Energy-Anchored Claims), the Wrapper–Native Growth Gap, and the native fee, burn, collateral, and settlement series—should be published in at least one non-fiat numeraire alongside the fiat series. A reference basket of energy, compute, shelter, and gold is sufficient and has the advantage that each component is a thing the holder might actually need. Where the two numeraires disagree in sign, the disagreement is the finding and should be surfaced rather than reconciled.

A sharper definition of the objective.

The thesis has so far spoken of purchasing power, which inherits the numeraire problem it is trying to escape. The more precise statement of what a store of value is for:

Wealth is durable, transferable command over necessary capacity under adversarial conditions.

Each term is load-bearing. Durable excludes claims that survive only while an issuer chooses to honor them. Transferable excludes capacity that cannot be moved or bequeathed. Necessary capacity names the denominator explicitly—energy, shelter, compute, mobility, time—rather than leaving it implicit in a currency. Under adversarial conditions is the requirement of §3: First Principles: What a SoV Must Survive and the reason §3: First Principles: What a SoV Must Survive is a design constraint rather than a preference. This is the definition the rest of the document should be read against.

Worked example: structure does not determine behavior.

A useful illustration, because it is easy to get backwards. An asset can be genuinely bearer-oriented, scarce, censorship-resistant, and independently settleable at the protocol layer, and simultaneously trade as leveraged technology beta at the wrapper layer—held through exchange-traded products, pledged as collateral, sized by volatility-targeting mandates, and sold first in a de-grossing episode. Both descriptions are accurate. They describe different planes.

The error in either direction is the same error. Concluding from correlated selloffs that the protocol properties are illusory mistakes the plane for the stack. Concluding from the protocol properties that the price will behave defensively mistakes the stack for the plane. Appendix H: Formal Model of Market Realization, Wrapper Flows, and Price Capture supplies the machinery for keeping them apart, and §23: Extended Telemetry the telemetry.

A related precision, since the language is routinely abused: a proof-of-work asset is energy-linked, not energy-backed. Its issuance and security consume energy; it is not redeemable for a fixed quantity of electricity, and no holder has a claim on a joule. The distinction matters because a genuine claim on capacity—a generation asset, a storage system, a Facility Capacity Receipt—has a payoff structure that an energy-linked bearer asset does not, and conflating them overstates the latter’s hedging properties.

Technology success is not incumbent success.

One further reading of the same distinction, which the thesis has stated elsewhere in monetary terms and which generalizes. A technology can transform an economy while destroying the equity, debt, and tokens of everyone who financed its first build-out; railways and long-haul fiber are the standard cases. This is §10: Work Credits: Energy-Anchored Claims pointed at infrastructure rather than at protocols: the social return and the return to the first capital structure are different quantities, and the second is the one an investor actually receives.

Tip: hover a heading to reveal its permalink symbol for copying.