§3. First Principles: What a SoV Must Survive
Copy/paste (plain text):
Jason St George. "§3. First Principles: What a SoV Must Survive" in Next Generation Stores of Value: Privacy, Proofs, Compute. Version v2.0. /v/2.0/read/part-i/3-first-principles/ First Principles: What a SoV Must Survive
A credible store of value must endure time, space, and politics. In practice, that means:
-
Credible scarcity: issuance cannot be tweaked at will.
-
Cheap, public verification: authenticity is verifiable by anyone, not decided by a platform.
-
Censorship-resistance & portability: no chokepoints; global movement by default.
-
Neutrality & permissionlessness: open access; rules apply equally.
-
Native demand: the asset does something indispensable, beyond serving as a symbol.
-
Lawful privacy by design: default privacy with optional disclosure (viewing keys, auditable receipts) so regulated actors can comply without re-introducing custodians or surveillance chokepoints.
-
Duration-neutrality: no fixed nominal cash flows to peg. A repression-resistant SoV cannot be a duration instrument whose real return can be driven persistently negative or whose price can be easily mass-managed by policy. Value should come from scarce capacity purchased every cycle, not from a promised coupon. This requirement governs the claim. It does not abolish the project. Plants, grids, and data centers still take decades; someone must warehouse that interval. Duration-neutrality of money is not a substitute for duration finance of civilization, and the two must not be the same instrument (§2: The World Forces New Monetary Primitives, §30: Objections & Responses).
-
Asset-level value capture (non-bypassability): the monetary object must be structurally required for fees, staking, collateral, settlement, governance, or priority access. If users can consume the triad through fiat, stablecoins, direct cloud contracts, or custodial APIs without touching the asset, the store-of-value thesis fails.
-
Agency preservation: the system should equip users to act privately, verifiably, and non-custodially without becoming a surveillance or dependency layer. Privacy, identity, reputation, and compliance features must be designed as tools in the user’s hands: selective disclosure rather than global inspection, receipt-based reputation rather than biographies, and non-custodial settlement rather than managed accounts. A system that makes users legible but not free has failed the political-economy test even if its cryptography is sound.
Each of these conditions is just the “money as memory” idea made operational: if money is the record of who did work and who is owed work, then scarcity, verifiability, censorship-resistance, neutrality, native demand, lawful privacy, duration-neutrality, non-bypassability, and agency preservation are the properties that keep that record honest across time, space, and politics—and keep the humans behind it free to act.
Thesis: Privacy, Proofs, and Compute can be engineered to meet all nine, and the world now needs exactly those properties.
We can sketch how the triad maps to SoV requirements:
-
Credible scarcity → the base-asset constitutional schedule, reported separately from DVC-bounded Work Credit issuance.
-
Cheap, public verification → VerifyPrice(W) dashboards for canonical workloads .
-
Censorship-resistance & portability → VerifyReach + VerifySettle metrics: reachability under censorship and settlement success/refund safety across corridors.
-
Neutrality & permissionlessness → decentralization telemetry: house share, geo/ASN distribution, time-to-first-proof.
-
Native demand → Work Credit utilization, proof/compute fee share of the security budget, and application-level usage.
-
Lawful privacy → corridor compliance receipts, viewing-key usage, anonymity-set health (shielded-pool size, churn, volume).
-
Duration-neutrality → no fixed coupons; revenues from priced workloads and triad usage, with explicit “repression beta” rather than fixed-income-like promises.
-
Asset-level value capture → native-asset fee share, burn rates, collateral lockups, and bypass-channel indicators (§10: Work Credits: Energy-Anchored Claims).
-
Agency preservation → non-custodial usage share, selective-disclosure ratio, dossier-minimization score, and the percentage of flows requiring no global identity.
| SoV Requirement | Privacy (P) | Proofs (Pr) | Compute (C) | Metrics / SLOs |
|---|---|---|---|---|
| Credible scarcity | Shielded balances; no selective debasement; predictable issuance schedules | Auditable supply without doxxing; proof capacity tied to hardware and energy | Verified FLOPs limited by physical compute; energy-tied issuance | FERs; facility telemetry; VerifyPrice |
| Cheap, public verification | Privacy proofs verifiable by anyone; private paths for ordinary users | Succinct, cheap-to-check proofs; VerifyPrice targets s, | Bounded verify cost for heavy workloads; MatMul vs | VerifyPrice; VerifyReach |
| Censorship-resistance | Non-custodial atomic swaps and shielded pools; harder for censors to see flows | Receipts portable across chains; proofs of inclusion/exclusion expose filtering | Open-admission prover/miner markets; diverse operators | VerifyReach; VerifySettle |
| Neutrality | Privacy by default, not by permission; same privacy for all | Anyone can verify; open circuits and PIDL interfaces; no gatekeepers | Useful-work mining with open hardware paths; no single vendor chokepoint | Regional VerifyPrice; dispersion metrics |
| Native demand | Enterprises and individuals need privacy for operations, payments, savings | Provenance and compliance mandates; proofs demanded by AI, finance, regulators | AI workloads, ZK proving as budget line items | Fee volume; Work Credit utilization |
| Lawful privacy | Viewing keys and auditable receipts; default-private with narrow exceptions | Proof anchors satisfy audits; policy-aware proofs reveal facts, not full data | Compute SLAs with receipts; policy-tagged workloads | Compliance flows; stress-test results |
| Duration-neutrality | No fixed coupon; revenues track priced capacity; survives regime change | Proof unit pricing floats with budgets; long-run telemetry | Verified FLOPs clear at market rates, not pegs; anchored in infrastructure | Multi-year FER and SLO stability |
| Asset-level value capture | Fees, collateral, and settlement denominated in the native asset; non-custodial routes dominate | Proof/verification fees and staking denominated natively; no free-riding on public verifiability | Compute fees, collateral, and priority access require the native asset | Native-fee share; burn rate; collateral lockups; Wrapper Dominance Ratio |
| Agency preservation | Default private settlement; no protocol backdoors | Selective proof of facts without dossiers | Open admission to verified work | Non-custodial usage share; selective-disclosure ratio; dossier-minimization score; % of flows requiring no global identity |
Store-of-Value Requirements vs. Triad Capabilities
In a world that will likely choose stealth default (negative real yields and capital controls) over explicit default, “store of value” can’t just be a narrative; it has to clear visible, adversarial stress tests. If the whole point of the stack is to survive yield-curve control, on-/off-ramp throttling, and peg breaks, then we should write down the conditions under which it continues to function and accrue value.
The checklist below turns those claims into operator SLOs that treasuries and allocators can actually underwrite and monitor. Here are several repression stress-tests to keep in mind:
-
YCC shock. 24–36 months of to bps real yields → fee+burn share of the security budget remains a target threshold (e.g., 40–60%) and VerifyPrice (p95) remains s for core workloads.
-
On-/off-ramp squeeze. Non-custodial BTCXMR/ZEC routes maintain success with 100% safe refunds; shielded-pool anonymity sets remain large and growing (no collapse in active notes or volume).
-
Peg break. If global yields gap +300 bps, triad revenues (proofs/FLOPs, privacy rails usage) track buyer budgets; there are no coupon-like revenue shortfalls that turn the asset into a synthetic bond.
Publish these in dashboards; no dashboards, no trust.
Early Falsifiers
The red lines developed in §27: Risk Analysis & Failure Modes provide the full falsification regime. In brief, the SoV thesis fails if: verification becomes expensive or gated; refund safety breaks; verification monoculture emerges; telemetry is captured; fee coverage collapses; or value capture fails (users consume triad services but asset demand remains weak because services are paid in fiat/stablecoins or value leaks to operators). See §27: Risk Analysis & Failure Modes for precise conditions and response protocols.
Later sections turn these stress tests into explicit SLAs and telemetry: VerifyPrice, reachability, settlement success, and decentralization metrics that operators and allocators can track in the open.
With these nine requirements as design constraints, we can now turn to the primitives that might satisfy them. Before naming those primitives, however, we need to be explicit about who will attack this system and at what layers. The next section states that threat model; the one after lays out the layered architecture that the rest of the thesis will fill in. The entire document can be read as an attempt to engineer Privacy, Proofs, and Compute to satisfy this nine-point contract under adversarial conditions.
We can summarize the whole design posture in one line: our North Star is to pay the machine only for work anyone can verify cheaply, on rails that give humans lawful privacy by default.
Tip: hover a heading to reveal its permalink symbol for copying.