privacy · proofs · compute
v2.0 · checksummed

§27. Risk Analysis & Failure Modes

v1.9
Cite this section

Copy/paste (plain text):

Jason St George. "§27. Risk Analysis & Failure Modes" in Next Generation Stores of Value: Privacy, Proofs, Compute. Version v1.9. /v/1.9/read/part-vi/27-risk-analysis/

Risk Analysis & Failure Modes

The risks to this emerging triad are not merely technical; they are structural, political, and economic.

Technical Risks

Proof system failures.
A SNARK/STARK is broken or exploited. Mitigation: multi-ZK support; tagging proofs with system/parameter IDs; migration paths.

Hardware capture.
A major fab or TEE platform has a backdoor. Mitigation: Layer-0 profiles, lot sampling, open hardware alternatives.

Protocol bugs.
Consensus bugs, bridge flaws, privacy leaks. Mitigation: reference implementations, staged rollouts, incident response.

Economic Risks

Verification cost creep.
If verifying proofs ceases to be much cheaper than producing them, the entire asymmetry collapses. Shows up as rising r(W)r(W) in VerifyPrice.

Centralization.
When specialized hardware or closed routers dominate, neutrality erodes. Shows up in concentrated facility IDs, rising entry latency.

Fee death-spirals.
If demand falls, fees collapse, security budgets shrink. Mitigation: conservative base issuance, Work Credits encoding long-term demand.

Political Risks

Bans & sanctions.
Jurisdictions may declare privacy assets illegal, sanction contracts, or criminalize the use of certain clients. Mitigation: jurisdictional diversity (labs, foundations, hardware profiles, LPs); client modes that degrade gracefully (offline, mesh, sat-links); legal defense resources; clear separation between core protocol and specific front-ends so that UI bans do not equal protocol death.

Info-ops and framing.
Media and governments can frame the stack as “criminal tech” or “national security threat.” Mitigation: lawful-privacy narratives grounded in receipts and compliance primitives; visible legitimate use cases (payroll, provenance, AI verification, critical-infrastructure audit trails); and an insistence on evidence (“show the receipts”) rather than slogans.

Regulatory chokepoints at the edge.
App stores, banks, and ISPs can be pressured to block access even when the protocol is neutral. Mitigation: the Layer-1/2 work described earlier (alternate transports, side-loading, content-addressed and offline distribution) so that no single storefront, bank, or carrier can become a kill switch.

Political risk cannot be “engineered away.” It must be distributed and prepared for: diversified jurisdictions, many independent implementations, multiple access paths, and a culture that expects (and drills) for attempted bans and smear campaigns rather than treating them as unthinkable.

Spec Drift, Vaporware, and Scoreboard Capture

Spec drift and vaporware can hollow out trust long before censorship does. Whitepapers without shipped code or inflated performance claims corrode the ecosystem’s credibility. In metrics, this shows up as:

  • a widening gap between claimed and measured VerifyPrice(W)(W);

  • a mismatch between Work Credit issuance and actual workload utilization;

  • chains with high market caps and low receipt volume;

  • clients that are nominally “live” but barely process real workloads.

Active liveness tracking (clients, explorers, throughput under real load, settlement safety metrics) should replace social metrics or TVL as the industry’s scoreboard. Projects that publicly document testnet-to-mainnet milestones and publish SLOs and incident reports exemplify the discipline needed.

No dashboards, no trust. If VerifyPrice, swap success and refund safety, decentralization telemetry, and corridor health are not public, treat claims as unpriced risk. A system that refuses to show its receipts is asking you to underwrite the very soft guarantees this thesis is designed to escape.

Scoreboard Capture in the Market Realization Plane

Scoreboard capture has a financial-product form as well as a protocol form, and it is the more seductive of the two. A product industry under competitive pressure increasingly asks “what ticker might catch a flow?” rather than “what does the investor actually need,” with capital chasing realized performance and sponsors launching ever more specialized wrappers. The result is a scoreboard on which a wrapper can be a triumph while its holders are destroyed — reverse splits keep the share price presentable, new inflows replenish assets, and fees keep accruing to the sponsor (§23: Extended Telemetry).

Scoreboard Capture, Extended

Scoreboard capture occurs when product AUM, market capitalization, launch count, or trailing returns substitute for measurement of whether capital survived, native services were used, and the monetary loop functioned.

The countermeasures are the Capital Survival Ratio, the Wrapper–Native Growth Gap, and Native Use Share (§23: Extended Telemetry). None of them can be gamed by launching another product.

Collateral Architecture Under Wrong-Way Risk

Collateral design chooses a distribution of failure; it does not eliminate one. At least three models must be reported and stress-tested against the same drawdown and DVC scenarios:

Pure-native collateral.
Operators post only the base asset. This maximizes direct lockup and value capture but also maximizes wrong-way risk: price decline raises required units, liquidation or exit releases float, and falling capacity can weaken the service case that supported the asset.

Mixed collateral.
Operators post a published mixture of native and external reserve collateral. Direct native capture is weaker, basis and custody risks enter through the external leg, but collateral coverage can remain more stable through a native drawdown.

Native plus insurance.
Native stake supplies incentive alignment while a separately capitalized first-loss, insurance, or resolution pool absorbs defined tail losses. The pool must publish capital, exclusions, correlation, claims priority, and replenishment rules; an unfunded promise is not insurance.

The comparison must report collateral coverage against realized slashing exposure, liquidation sensitivity, operator survival, released float, DVC, and service-SLO recovery. Governance may choose among the models only after publishing those trade-offs. It may not describe the strongest value-capture design as the safest prudential design.

Red Lines: When the SoV Thesis Fails

The thesis is falsifiable. If any of these conditions persist without credible remediation, the store-of-value claim is no longer defensible:

Red Line 1: Verification Affordability Breaks

Condition: Physical VerifyPrice p95 exceeds SLO bounds for core workloads for 3\geq 3 consecutive months, with no credible remediation path.

Why it kills the thesis: “Anyone can verify” is the hinge. If verification becomes expensive, proofs become platform claims, not public facts.

Red Line 2: Refund Safety Breach

Condition: Corridor refund_safe <100%< 100\% on any admissible route, with repeated incidents and no automatic delist + remediation.

Why it kills the thesis: Non-custodial settlement is the “Private Money” foundation.

Red Line 3: Verification Monoculture

Condition: >70%>70\% of verifications on a single hardware profile, TEE vendor, or jurisdiction for 3\geq 3 consecutive months.

Why it kills the thesis: Monoculture means “trust the dominant vendor.”

Red Line 4: Telemetry Capture

Condition: Receipt datasets become unavailable, unverifiable, or controlled by a single party.

Why it kills the thesis: If telemetry can be captured, the entire observability regime is theater.

Red Line 5: Fee Coverage Collapse

Condition: Fee+burn coverage falls below 10% of security budget and workload mix becomes >80%>80\% speculative for 12\geq 12 months.

Why it kills the thesis: The SoV story requires structural demand, not pure narrative.

Red Line 6: Value Capture Failure

Condition: Triad usage grows (proof volume, settlement volume, compute demand) but native-asset fee volume, burns, collateral lockups, and fee coverage do not grow with it for 12\geq 12 months.

Why it kills the thesis: The system may be useful infrastructure but not a store-of-value asset. Users are consuming triad capacity through bypass channels.

Condition: Lawful users in major jurisdictions cannot use privacy rails without unacceptable compliance uncertainty for 12\geq 12 months, and no lawful-privacy patterns (viewing keys, scoped disclosure) are adopted.

Why it weakens the thesis: If regulated actors cannot participate, the “Private Money” leg loses its institutional constituency and anonymity sets shrink.

Red Line 8: Governance Capture

Condition: Governance can alter issuance schedules, fee routing, or telemetry rules without hard constitutional constraints, timelocks, or supermajority requirements — or the narrow emergency path (§22: Layer 6: Governance & Telemetry) becomes routine rather than exceptional, with its subtractive-only scope eroded to permit any value redirection.

Why it kills the thesis: If insiders can redirect value away from holders or inflate supply at will, the asset is a platform token, not a store of value.

Red Line 9: Wrapper Dominance Becomes Monetary Substitution

Condition: Wrapper Dominance Ratio (§10: Work Credits: Energy-Anchored Claims) rises for 2\geq 2 consecutive quarters while native fee share, private settlement volume, and collateral lockups stagnate or decline. In its full form: custodial and synthetic exposure (CCR, SER) becomes the dominant form of ownership for a sustained period while protocol-native fees, burns, collateral, private settlement, proof demand, and verified-compute usage remain stagnant or declining, with a persistently positive Wrapper–Native Growth Gap (§23: Extended Telemetry).

Why it weakens the thesis: Price rises while the monetary thesis dies. Government-approved wrappers becoming the dominant institutional form is co-option without censorship. The asset may remain a successful financial product, but the claim that it functions as a native store of value for Privacy, Proofs, and Compute is no longer supported by anything except its chart.

Red Line 10: Physical Infrastructure Opacity

Condition: Physical VerifyPrice (§19: Layer 4: Truth & Work) exceeds threshold, or Facility Capacity Receipt data is unavailable or unverifiable for a material share of active capacity, for 2\geq 2 consecutive quarters.

Why it kills the thesis: Layer 0 claims become trust-me claims; Work Credits lose infrastructure credibility.

Red Line 11: AI Enclosure

Condition: Top-3 hyperscalers, closed TEEs, or a single jurisdiction exceed a threshold share (e.g., >50%>50\%) of VerifyPrice-tracked verified compute capacity, i.e., the Enclosure Risk Flag (§4: Threat Model) triggers and persists.

Why it kills the thesis: The verified-compute service market described by the “AI Money” lens becomes a cloud IOU; the frontier is enclosed rather than homesteaded, so it cannot support the associated base-asset monetary candidate.

Red Line 12: Agency Failure

Condition: Forced Disclosure Incidence (§24: Legal, Policy, and Jurisdictional Posture) becomes systemic, or participation/agency use cases (§2: The World Forces New Monetary Primitives) fail to materialize while institutional usage grows, for 12\geq 12 months.

Why it kills the thesis: Lawful privacy collapses socially, or the protocol serves institutions but not users—violating the ninth SoV requirement (§3: First Principles: What a SoV Must Survive). Emergency governance becoming routine is a related failure: neutrality decays into foundation fiat.

Red Line 13: Energy Sovereignty Failure

Condition: Network capacity-weighted sovereign optionality Osnet\mathcal{O}_s^{\text{net}} (§14: Layer 0: Verifiable Machines & Energy) falls below threshold for 2\geq 2 consecutive quarters, or a threshold share (e.g., >50%>50\%) of VerifyPrice-tracked capacity sits in jurisdictions operating an active curtailment or power-rationing regime against verification workloads.

Why it kills the thesis: Verification affordability becomes a sovereign policy variable rather than a market outcome. Red Line 1 becomes externally triggerable: an adversary or host state can break the hinge by adjusting tariffs, interconnection queues, or load priority, without touching the cryptography, the governance, or the market.

Red Line 13 and its neighbours.

Three red lines now touch the physical substrate and they are not redundant:

  • Red Line 10 is opacity: we cannot see the substrate.

  • Red Line 13 is fragility: we can see it clearly and it will not survive pressure.

  • Red Line 11 is enclosure: we can see it, it is robust, and someone else owns it.

A network can breach any one without the others. Perfect FCR disclosure of a single-interconnect fleet in a rationing jurisdiction breaches 13 while passing 10. Do not merge them.

The dependency this makes explicit.

§19: Layer 4: Truth & Work describes Physical VerifyPrice SLOs as constitutional and exogenous to token price. That is right, and Red Line 1 correctly treats their sustained breach as fatal. But exogenous to token price is not exogenous to everything: the SLOs remain endogenous to the physical and jurisdictional conditions under which power and reference hardware are obtainable (§4: Threat Model).

Red Line 13 exists so that this dependency is monitored upstream rather than discovered downstream. Without it, the sequence

energy policy    proving cost and siting    Physical \textscVerifyPrice    Red Line 1\text{energy policy} \;\rightarrow\; \text{proving cost and siting} \;\rightarrow\; \text{Physical \textsc{VerifyPrice}} \;\rightarrow\; \text{Red Line 1}

runs to completion with no instrument reading anywhere along it until the hinge itself fails. A falsification framework whose primary condition can be tripped by an unmonitored external variable is not yet falsifiable in the way it claims.

Red Line 14: The Capturable Wedge Closes

Measured quantities. For canonical workload WW at tier TT in period tt:

  • PW,T,tprotP^{\text{prot}}_{W,T,t} — all-in USD price to the buyer of executing WW at tier TT through the protocol, inclusive of the protocol fee. Protocol-native: PIDL receipts already carry workload ID, tier, timestamps, and hardware profile (§19: Layer 4: Truth & Work).

  • PW,tbypP^{\text{byp}}_{W,t} — lowest publicly quoted USD price to execute the same computational content without protocol-grade verification, on the same hardware class. Sourced from a pre-committed reference panel: a frozen list of venues (e.g., three hyperscalers and three GPU marketplaces), scraped daily, with the workload-to-instance mapping published as a machine-readable spec. Panel changes require publication and 90 days’ notice. Where a venue publishes committed-use, reserved, or spot pricing, the lowest generally available of those is the reading, not the on-demand list price.

  • s=(PprotPbyp)/Pbyps = (P^{\text{prot}} - P^{\text{byp}})/P^{\text{byp}}normalized bypass spread. Normalization is not cosmetic: the absolute spread shrinks mechanically with compute deflation, so only the ratio is economically meaningful.

  • γ\gamma — verification cost share: proving plus redundancy per unit, expressed as a fraction of PbypP^{\text{byp}}. Derived from FER and VerifyPrice telemetry, and subject to the same third-party custody and reproducibility requirement as the reference panel (below), because γ\gamma enters ω\omega negatively and the fee recipient has a direct interest in understating it.

  • ω=sγ\omega = s - \gamma — the capturable wedge: what is left of the price the protocol commands after paying for the verification that justifies it.

  • τ\taurealized take rate: (native fees ++ burns, USD) // (settled protocol turnover, USD). Computable by anyone from chain data.

Condition A — the wedge closes. Capacity-weighted ω\omega across the canonical starter set (§19: Layer 4: Truth & Work) falls below the realized take rate, ω<τ\omega < \tau, for 2\geq 2 consecutive quarters, with no credible remediation path.

Condition B — the base deflates faster than volume compensates. Deflation-adjusted native fee-plus-burn turnover fails to grow over a trailing four-quarter window while protocol physical throughput (verified units delivered) grows over the same window.

The connective, stated once: either condition breaching trips the red line. A breach of A, or a breach of B, or both, is a breach of Red Line 14. There is no requirement that they breach together.

Why A kills the thesis: The protocol is charging more than the differential value it supplies. It is living on switching costs, subsidy, or inertia rather than on anything a buyer would pay for, and the fee is not a wedge on genuine differential value but a tax on captive volume. That fee is retractable by competition, so nothing durable accrues.

Why B kills the thesis: The wedge may be intact and the burn still cannot scale. An ad valorem fee on a deflating unit price is a shrinking real toll (§10: Work Credits: Energy-Anchored Claims); if throughput grows while real fee-plus-burn turnover does not, the empirical bet the thesis is making on volume outrunning deflation is losing, in public.

Both clauses must be monitored, because each closes a gaming route the other leaves open. A published alone is gameable by cutting the fee toward zero, which trivially restores ω>τ\omega > \tau while capturing nothing; B published alone is gameable by inflating volume at a vanishing wedge. Monitoring both means a protocol that is neither differentially valuable nor growing its real take has nowhere to stand. This is a requirement on the test, not on the trigger: dropping either clause from the instrument panel is a breach of the falsification protocol, while breaching either clause in the readings is a breach of the red line.

Why Condition A is hard to game.

It is self-normalizing. It compares two independently measured quantities — what the market will bear net of verification cost, and what the protocol actually takes — rather than testing either against a threshold somebody had to guess. There is no parameter to lobby for. A protocol cannot pass by lowering its ambitions, because lowering the take rate lowers τ\tau and lowering the price lowers ss, and the comparison survives both.

Third-party checkability.

The thesis’s own principle applies with full force here: the party being scored must not set the scoring function (§14: Layer 0: Verifiable Machines & Energy, Red Line 4). The reference panel, the workload-to-instance mapping, and the verification cost share γ\gamma must therefore all be maintained by someone other than the fee recipient, and an independent party must be able to re-derive ω\omega from the published inputs and obtain the same number. γ\gamma deserves explicit mention because it is the easiest term to shade: it enters ω=sγ\omega = s - \gamma negatively, so understating the cost of verification inflates the wedge and makes this red line harder to trip, and the fee recipient is the party with both the incentive and the telemetry. Its inputs — proving overhead and redundancy per unit, drawn from FER and VerifyPrice — must be published in the same reproducible form as the panel, with the derivation runnable by an outside party against the raw receipts. A wedge computed by the entity collecting the wedge is a marketing figure, and that applies term by term.

Honest coverage caveat.

PbypP^{\text{byp}} is well defined only where a like-for-like unverified execution exists: matrix multiplication, inference, proof generation. It is not well defined for atomic settlement or media provenance, where there is no unverified version of the same product — the comparator there must be the all-in fee of a custodial or regulated rail delivering the same economic function. That is a rougher measurement with a weaker claim to like-for-like, and it must be reported separately rather than blended into a single index. An index that averages a clean comparison with a rough one inherits the rough one’s error and hides it.

Effective prices, not list prices — and the direction of the residual bias.

On-demand list pricing is not what hyperscaler and marketplace capacity actually transacts at. Committed-use discounts, reserved instances, and spot markets routinely clear well below list, so a panel scraping list prices measures a bypass channel nobody uses. That is why PbypP^{\text{byp}} is specified above as the lowest generally available price across the published pricing modes rather than the on-demand quote, and why the panel spec must record which mode each reading came from.

Even so, a residual bias survives: the largest buyers transact at negotiated enterprise rates that are published nowhere, so the observable price remains an upper bound on the true alternative. The direction this pushes the red line is worth deriving rather than assuming, because it is not the direction one expects. Since s=(PprotPbyp)/Pbyps = (P^{\text{prot}} - P^{\text{byp}})/P^{\text{byp}} falls as PbypP^{\text{byp}} rises, an overstated PbypP^{\text{byp}} understates both ss and γ\gamma, and understates ss by more, because PprotP^{\text{prot}} exceeds the per-unit verification cost. Measured ω\omega is therefore too small and Condition A trips earlier than the truth warrants. The reading is accordingly published as an upper bound on breach: a measured ω<τ\omega < \tau may overstate the case against the thesis and must be re-derived against negotiated pricing before the 90-day clock is treated as running, whereas a measured ω>τ\omega > \tau is a pass earned against a conservative comparator.

That is the benign direction, which is precisely why the term that runs the other way needs naming. Understating γ\gamma inflates ω\omega and makes the red line harder to trip, and γ\gamma is the one input sourced from the fee recipient’s own telemetry. The custody requirement above exists for that reason and is the load-bearing safeguard here, not the panel methodology.

Red Line 14 and its neighbours.

Three distinctions worth stating precisely, because each is easy to collapse:

  • The price series is not VerifyPrice. VerifyPrice is a cost SLO — the real-resource cost of checking a claim on reference hardware, deliberately exogenous to token price (§19: Layer 4: Truth & Work) — and Red Line 1 reads on it. Red Line 14 does not: the quantity it reads on is a price series for delivered service, set by markets, which VerifyPrice is not and was never meant to be. The two red lines therefore cannot be tripped by the same event. The qualification is that γ\gamma, one input to the wedge, does draw on VerifyPrice and FER telemetry for the cost of verification, which is the right source for a cost term; that is why γ\gamma carries the independent-reproducibility requirement above. Shared telemetry in one term, not a shared test.

  • This is not Red Line 6. Red Line 6 asks whether fees follow usage — a direction. Red Line 14 asks whether there is a wedge worth charging at all — a magnitude (§10: Work Credits: Energy-Anchored Claims). A protocol can pass 6 while failing 14: native fees can track usage perfectly while the fee itself exceeds the differential value supplied.

  • This is not Red Line 5. Fee coverage measures fees against the security budget. Red Line 14 measures the fee against what the market will bear. Coverage can be adequate on a base that is about to be competed away.

Red Line 15: Native Collateral–Capacity Spiral

Measured quantities. Publish native-asset peak-to-trough drawdown, collateral coverage against realized slashing exposure, operator exit and liquidation rates, stress-scenario DVC, collateral released into liquid float, and recovery of core service SLOs.

Condition. A pre-declared material native-asset drawdown persists for at least 30 days; collateral coverage falls below realized slashing exposure; operator exit or forced liquidation exceeds its constitutional threshold; stress-adjusted DVC declines; released native collateral materially increases liquid float; and core service SLOs fail to recover within the 90-day remediation period. The thresholds must be set before the episode, reported for pure-native, mixed, and native-plus-insurance designs, and may not be relaxed while the clock is running.

Why it kills the thesis. The asset is being offered as insurance while its underwriting capacity disappears in the insured event. The loop

drawdownmore units requiredoperator exitDVC declinecollateral releaseliquid float increase\text{drawdown}\rightarrow\text{more units required}\rightarrow \text{operator exit}\rightarrow\text{DVC decline}\rightarrow \text{collateral release}\rightarrow\text{liquid float increase}

turns native value capture into a service-capacity contraction. A temporary drawdown is not the breach; the sustained joint deterioration and failed SLO recovery are.

Pattern: The red line is not “bad thing happens once.” It is “sustained breach + no recovery.” Isolated incidents with rapid remediation are expected in any complex system. Persistent degradation without response is thesis failure.

What happens at a red line:
ConditionResponse
Red line breachedIncident declared; governance must publish remediation plan within 14 days
Remediation fails after 90 daysAsset reclassified from “SoV candidate” to “speculative/experimental” in protocol communications
Multiple red lines breached simultaneouslyCrisis mode; independent review commissioned; results published

Red line response protocol.

These are not punishments—they are truth in advertising. An asset that claims SoV properties must demonstrate them. If it can’t, it should stop claiming.

Market Realization Warnings

Red lines are protocol failures. The Market Realization Plane generates a second, weaker class of signal that must not be confused with them. A wrapper unwind can destroy price without damaging protocol function at all; treating that as thesis falsification would be as sloppy as treating a rally as confirmation. The distinction:

  • Monetary red lines (above) mean the protocol’s monetary claim has failed: verification breaks, settlement safety breaks, native value capture fails, issuance becomes discretionary, censorship routes dominate, or native use can be bypassed.

  • Market realization warnings (below) mean price has become an unreliable signal. They do not necessarily kill the protocol; they suspend the right to cite price as evidence about it.

Warnings trigger when:

  1. A statistically significant break appears in holder flow elasticity.

  2. Net mechanical gain κ\kappa changes sign.

  3. The Mechanical Pressure Ratio exceeds pre-declared market-depth bounds.

  4. Wrapper creations dominate native spot demand.

  5. Dealer swap capacity appears to bind.

  6. Exposure migrates from swaps toward options.

  7. Recursive leveraged wrappers appear.

  8. Top wrappers or dealers exceed concentration thresholds.

  9. The Wrapper–Native Growth Gap stays elevated.

  10. Price rises while native fees and receipt volume fall.

  11. Price falls while native monetary health improves.

  12. Cross-jurisdiction hedges produce halt or settlement asymmetries.

  13. Triad capacity is consumed at scale while the asset prices as a service and the monetary bid accrues elsewhere — Service-Good Realization, below.

The correct response to a warning is not intervention. It is epistemic: publish the warning, state which flow term is dominating, and stop using price as evidence in either direction until it clears. Governance must specifically not respond to warnings by inflating issuance, subsidizing price, or buying back supply — those are the reflexes of an entity managing a stock price, not operating a monetary constitution.

One warning is not merely epistemic.

The twelfth item above is the last of the flow-mechanical warnings. The thirteenth is a different animal and is set out in full, because it is the observable form of the thesis losing the argument of §30: Objections & Responses and because a warning that carries falsifying weight should not be left as a line in a list.

Warning 13: Service-Good Realization

Condition. All three clauses hold together, read across at least two distinct regime-pressure episodes — intervals in which the Stage A index RtR_t (§10: Work Credits: Energy-Anchored Claims) is elevated under criteria published before the reading rather than chosen after it:

  1. Capacity is being consumed at scale. Receipt volume, verified units delivered, and private settlement volume grow through the episode; the capturable wedge stays above the realized take rate, so Red Line 14 does not fire; native fee-plus-burn turnover tracks usage, so Red Line 6 does not fire. The protocol is working.

  2. The insurance signature is absent. Through the episode the asset exhibits nothing that distinguishes it from a claim on a service business: holding duration does not extend, the non-custodial share does not rise, the duration-neutral holding cohort of §26: Adoption Curve & Ecosystem Dynamics does not grow, and demand moves with buyers’ capacity budgets rather than with their exposure to the pressure. Read on the Value Capture and Agency Preservation boards (§23: Extended Telemetry), not on a chart.

  3. The monetary bid accrues to Bitcoin. Over the same episodes Bitcoin absorbs the flow the thesis predicts for a regime-contingent hedge, while the triad asset covaries with compute and IT spending rather than with regime pressure.

What it means. Not that the protocol failed — clause 1 says it did not. It means the regime-contingent convenience yield of §10: Work Credits: Energy-Anchored Claims was not there, and that yield is the entire remaining basis for the monetary claim once §10: Work Credits: Energy-Anchored Claims has conceded that fees, burns, and collateral produce a cash-flow claim and a floor. The prescribed response is therefore reclassification rather than retirement: the asset is a verified-capacity service asset with a competitively priced fee stream and a collateral floor. That is a real thing to be. It is not a store of value, and the protocol’s communications must stop saying otherwise on the same 90-day clock the red-line protocol uses.

Why this remains a warning rather than another red line. Clause 3 reads on price, and reads it against another asset. Every condition in §27: Risk Analysis & Failure Modes is protocol-observable, and §10: Work Credits: Energy-Anchored Claims forbids treating price as evidence about monetary adoption in either direction. A price-comparative red line would break both commitments. Red Line 15 instead covers the protocol-observable collateral–capacity spiral. What distinguishes this warning from its twelve neighbours is that clauses 1 and 2 carry the falsifying weight by themselves: capacity consumed at scale with no insurance signature, across repeated episodes, is the monetary claim failing whether or not anyone looks at Bitcoin. Clause 3 says where the premium went. It is corroboration, not the test.

Tip: hover a heading to reveal its permalink symbol for copying.