§27. Risk Analysis & Failure Modes
Copy/paste (plain text):
Jason St George. "§27. Risk Analysis & Failure Modes" in Next Generation Stores of Value: Privacy, Proofs, Compute. Version v3.1. /v/3.1/read/part-vi/27-risk-analysis/ Risk Analysis & Failure Modes
The risks to this emerging triad are not merely technical; they are structural, political, and economic.
Technical Risks
Every guarantee in this thesis reduces, at the bottom, to mathematics running on matter that somebody manufactured. That is where the first class of risk lives — not in the cryptography, which is either sound or it is not, but in the supply chain underneath it.
Proof system failures.
A SNARK/STARK is broken or exploited. The blast radius is bounded before it happens: multi-ZK support, proofs tagged with system and parameter IDs, and migration paths mean a broken curve deprecates one proof family rather than the entire attestation layer.
Hardware capture.
A major fab or TEE platform ships a backdoor. This is the Layer 0 argument wearing different clothes: profiles, lot sampling, and open hardware alternatives exist so that one compromised supplier cannot silently become the substrate of record for every receipt (§14: Layer 0: Verifiable Machines & Energy).
Protocol bugs.
Consensus bugs, bridge flaws, privacy leaks. Mitigation: reference implementations, staged rollouts, incident response.
The common thread is that none of these risks is existential on its own; each is existential only if it arrives unobserved. A broken proof system caught in staging is an engineering incident. The same break discovered two years after deployment, with every receipt since built on it, is a monetary event.
Economic Risks
The economic risks are quieter than the technical ones, and more dangerous for it. They do not announce themselves as failures; they arrive as slow drift that every individual reading can explain away.
Verification cost creep.
If verifying proofs ceases to be much cheaper than producing them, the entire asymmetry collapses — and it collapses gradually, one mildly disappointing benchmark at a time. Shows up as rising in VerifyPrice; the trip wire exists because no single reading looks fatal.
Centralization.
When specialized hardware or closed routers dominate, neutrality erodes. Shows up in concentrated facility IDs, rising entry latency.
Fee death-spirals.
If demand falls, fees collapse, security budgets shrink. Mitigation: conservative base issuance, Work Credits encoding long-term demand.
Paying the guards in fresh scrip.
The fee-coverage question deserves the concrete form, because the table of 30/50/80% targets is easy to read as a KPI and forget. A system that relies entirely on issuance to fund security is a warehouse paying its guards each morning in shares the warehouse prints that morning. The guards keep showing up — right up until the shares stop buying lunch. The fee-coverage trajectory is simply the schedule for switching them to wages.
Political Risks
Political risk is the one class this thesis cannot engineer around, only prepare for. The adversary here is not a bug or a market; it is an institution with jurisdiction, patience, and every incentive to frame the stack in the least flattering available light.
Bans & sanctions.
Jurisdictions may declare privacy assets illegal, sanction contracts, or criminalize the use of certain clients. Mitigation: jurisdictional diversity (labs, foundations, hardware profiles, LPs); client modes that degrade gracefully (offline, mesh, sat-links); legal defense resources; clear separation between core protocol and specific front-ends so that UI bans do not equal protocol death.
Info-ops and framing.
Media and governments can frame the stack as “criminal tech” or “national security threat.” Mitigation: lawful-privacy narratives grounded in receipts and compliance primitives; visible legitimate use cases (payroll, provenance, AI verification, critical-infrastructure audit trails); and an insistence on evidence (“show the receipts”) rather than slogans.
Regulatory chokepoints at the edge.
App stores, banks, and ISPs can be pressured to block access even when the protocol is neutral. Mitigation: the Layer-1/2 work described earlier (alternate transports, side-loading, content-addressed and offline distribution) so that no single storefront, bank, or carrier can become a kill switch.
Political risk cannot be “engineered away.” It must be distributed and prepared for: diversified jurisdictions, many independent implementations, multiple access paths, and a culture that expects (and drills) for attempted bans and smear campaigns rather than treating them as unthinkable. The stack is built so that being declared unwelcome in one jurisdiction is survivable; no layer assumes it will never be declared unwelcome anywhere.
Spec Drift, Vaporware, and Scoreboard Capture
Spec drift and vaporware can hollow out trust long before censorship does. Whitepapers without shipped code or inflated performance claims corrode the ecosystem’s credibility. In metrics, this shows up as:
-
a widening gap between claimed and measured VerifyPrice;
-
a mismatch between Work Credit issuance and actual workload utilization;
-
chains with high market caps and low receipt volume;
-
clients that are nominally “live” but barely process real workloads.
Active liveness tracking (clients, explorers, throughput under real load, settlement safety metrics) should replace social metrics or TVL as the industry’s scoreboard. Projects that publicly document testnet-to-mainnet milestones and publish SLOs and incident reports exemplify the discipline needed.
No dashboards, no trust. If VerifyPrice, swap success and refund safety, decentralization telemetry, and corridor health are not public, treat claims as unpriced risk. A system that refuses to show its receipts is asking you to underwrite the very soft guarantees this thesis is designed to escape.
Scoreboard Capture in the Market Realization Plane
Scoreboard capture has a financial-product form as well as a protocol form, and it is the more seductive of the two. A product industry under competitive pressure increasingly asks “what ticker might catch a flow?” rather than “what does the investor actually need,” with capital chasing realized performance and sponsors launching ever more specialized wrappers. The result is a scoreboard on which a wrapper can be a triumph while its holders are destroyed — reverse splits keep the share price presentable, new inflows replenish assets, and fees keep accruing to the sponsor (§23: Extended Telemetry).
Scoreboard Capture, Extended
Scoreboard capture occurs when product AUM, market capitalization, launch count, or trailing returns substitute for measurement of whether capital survived, native services were used, and the monetary loop functioned.
The countermeasures are the Capital Survival Ratio, the Wrapper–Native Growth Gap, and Native Use Share (§23: Extended Telemetry). None of them can be gamed by launching another product.
Collateral Architecture Under Wrong-Way Risk
Collateral design chooses a distribution of failure; it does not eliminate one. At least three models must be reported and stress-tested against the same drawdown and DVC scenarios:
Pure-native collateral.
Operators post only the base asset. This maximizes direct lockup and value capture but also maximizes wrong-way risk: price decline raises required units, liquidation or exit releases float, and falling capacity can weaken the service case that supported the asset.
Mixed collateral.
Operators post a published mixture of native and external reserve collateral. Direct native capture is weaker, basis and custody risks enter through the external leg, but collateral coverage can remain more stable through a native drawdown.
Native plus insurance.
Native stake supplies incentive alignment while a separately capitalized first-loss, insurance, or resolution pool absorbs defined tail losses. The pool must publish capital, exclusions, correlation, claims priority, and replenishment rules; an unfunded promise is not insurance.
The comparison must report collateral coverage against realized slashing exposure, liquidation sensitivity, operator survival, released float, DVC, and service-SLO recovery. Governance may choose among the models only after publishing those trade-offs. It may not describe the strongest value-capture design as the safest prudential design.
Red Lines: When the SoV Thesis Fails
The thesis is falsifiable. If any of these conditions persist without credible remediation, the store-of-value claim is no longer defensible. Severity labels are used consistently below and mean specific things: kills = the condition falsifies the thesis outright (the chain’s hinge is severed); weakens = the condition removes one leg of support such that the thesis survives only in reduced form and must be restated. The label appears in each red line’s closing paragraph and is not a tone choice.
Red Line 1: Verification Affordability Breaks
Condition: VerifyPrice p95 (the verification-cost series, not the Physical VerifyPrice audit-cost series of Red Line 10) exceeds SLO bounds for core workloads for consecutive months, with no credible remediation path.
Why it kills the thesis: “Anyone can verify” is the hinge. If verification becomes expensive, proofs become platform claims, not public facts.
The touchstone is the image to keep. Gold earned its monetary career on a dark stone against which a nugget could be streaked in seconds — expensive to produce, cheap to assay approximately (touchstone and density; a tungsten core defeats the first and is caught by the second), and therefore expensive to fake against a buyer who runs both checks. The entire premium of this thesis rests on the assay staying cheap. The moment verification costs real money or real expertise, receipts revert to what platform labels already are: assertions with better typography. Three months of sustained breach is not a performance regression; it is the anchor reverting to the broadcast era.
Red Line 2: Refund Safety Breach
Condition: Any protocol-attributable refund failure (a timelock, adaptor, or script defect that leaves an honest party without a bounded-time, no-loss exit) on an admissible route, or overall corridor refund_safe with failures unclassified, with repeated incidents and no automatic delist + remediation. Refund safety is read as §20: Layer 5: Value & Settlement defines it; the same specification gates Phase I in §26: Adoption Curve & Ecosystem Dynamics.
Why it kills the thesis: Non-custodial settlement is the “Private Money” foundation.
One lost deposit is an incident. A corridor that eats funds and remains listed is a verdict: the system has told every user what it actually is. On the protocol’s own conduct refund safety is binary by design — there is no partial custody, no 97% non-custodial — because trust does not survive being mostly honored; the tolerance in the overall figure exists only for failures the user’s own environment caused, each of which must be root-caused and published to count as such. The automatic delist matters more than the breach itself; a network that keeps a broken corridor on its board for volume’s sake has chosen the scoreboard over the user.
Red Line 3: Verification Monoculture
Condition: of verifications on a single hardware profile, TEE vendor, or jurisdiction for consecutive months.
Maturity gate. This line reads only after the Phase II entry gate of §26: Adoption Curve & Ecosystem Dynamics is met; before that it is published as a watch indicator and trips nothing. A Phase I network with three verifier operators in one country is concentrated by arithmetic, not by capture, and a line that fires at launch tests the checklist rather than the thesis.
Why it kills the thesis: Monoculture means “trust the dominant vendor.”
Seven-tenths of the world’s verifying running on vendor-attested chips from one supplier is not an efficiency; it is a single point of political failure wearing a supply-chain dashboard. The concentration can arrive without any malicious act at all — one vendor simply being better for two quarters is enough — which is precisely why the line is drawn on the reading, not on intent. The moment verification monocultures, the adversary no longer needs to break the cryptography; it needs only to lean on the vendor. The threshold here is deliberately looser than Red Line 11’s 50% on verified compute capacity, and the difference is the two-exposures distinction of §14: Layer 0: Verifiable Machines & Energy: verification runs on small quantities of reference hardware at the edge and can be relocated in weeks, so concentration in it is reversible and the line tolerates more of it before reading capture; proving capacity is capital-intensive, interconnection-bound, and slow to move, so the same concentration there is a structural fact rather than a passing one and the line reads earlier.
Red Line 4: Telemetry Capture
Condition: Receipt datasets become unavailable, unverifiable, or controlled by a single party.
Why it kills the thesis: If telemetry can be captured, the entire observability regime is theater.
A constitution nobody can check is a press release. Every instrument in Part V exists on the assumption that an independent party can re-derive the published number from raw public artifacts and get the same answer; the moment the raw data itself becomes a proprietary good, the dashboards continue to render but stop meaning anything. This is the quietest of the kill conditions — no price moves, no users are harmed, nothing visibly breaks — and it is the precondition for every other red line’s measurement. Capture the scoreboard and every other game on it is rigged.
Red Line 5: Fee Coverage Collapse
Condition: FeeCoverage (retained fees as a share of security budget; burns excluded per §22: Layer 6: Governance & Telemetry) falls below 10% and workload mix becomes speculative for months. The 30% figure in §26: Adoption Curve & Ecosystem Dynamics is a phase-regression gate, not this red line.
Why it kills the thesis: The SoV story requires structural demand, not pure narrative.
This is the guards-in-fresh-scrip condition (see §27: Risk Analysis & Failure Modes) promoted from metaphor to trip wire. A network can coast on issuance for years, and during those years every headline number looks healthy: hash rate, market cap, even transaction counts. What it cannot do is fake the composition of its demand. When four out of five units of workload exist to farm a token rather than to be used, the fee floor is not being tested — it is being performed, and the security budget is a subsidy awaiting its first serious drawdown.
Red Line 6: Value Capture Failure
Condition: Triad usage grows (proof volume, settlement volume, compute demand) but native-asset fee volume, burns, collateral lockups, and fee coverage do not grow with it for months.
Why it kills the thesis: The system may be useful infrastructure but not a store-of-value asset. Users are consuming triad capacity through bypass channels.
The paper-gold precedent is the cautionary case, and it is a century old: under the interwar gold-exchange standard, and later in the London bullion market’s unallocated accounts, claims on gold outgrew holding of gold, intermediaries multiplied paper while vaults stood still, and the price of the paper discovered it could move without the metal underneath it. The same substitution is available here, and the telemetry exists to watch it arrive. Usage growing while native fee volume stagnates is not a paradox — it is the market routing around the asset while continuing to use the network, and it is the single clearest signal that the thesis’s monetary link has quietly severed while the infrastructure succeeded.
Red Line 7: Legal Incompatibility
Condition: Lawful users in major jurisdictions cannot use privacy rails without unacceptable compliance uncertainty for months, and no lawful-privacy patterns (viewing keys, scoped disclosure) are adopted.
Why it weakens the thesis: If regulated actors cannot participate, the “Private Money” leg loses its institutional constituency and anonymity sets shrink.
Privacy that only outlaws can use is a shrinking set, not a monetary property. The thesis’s lawful-privacy design exists precisely to avoid the corner where compliance uncertainty meets default privacy and the only remaining users are the ones who were never complying. Anonymity is a network good: each legitimate departure thins the crowd that makes blending plausible, and the set collapses gradually — which is why this line weakens rather than kills, and why its telemetry (corridor compliance receipts, viewing-key usage) reads on adoption, not on law.
Red Line 8: Governance Capture
Condition: Governance can alter issuance schedules, fee routing, or telemetry rules without hard constitutional constraints, timelocks, or supermajority requirements — or the narrow emergency path (§22: Layer 6: Governance & Telemetry) becomes routine rather than exceptional, with its subtractive-only scope eroded to permit any value redirection.
Why it kills the thesis: If insiders can redirect value away from holders or inflate supply at will, the asset is a platform token, not a store of value.
The constitution here is whatever governance cannot silently violate without getting caught (§22: Layer 6: Governance & Telemetry states the principle). A body that can only shrink the protocol cannot steal from it — that is the entire logic of the subtractive-only emergency path, and the reason its erosion is a kill condition rather than a governance hygiene note. The failure arrives as precedent, not as heist: one emergency invoked for convenience, one scope quietly widened, and the constraint that made the asset safe to hold has been converted into a knob.
Red Line 9: Wrapper Dominance Becomes Monetary Substitution
Condition: Wrapper Dominance Ratio (§10: Work Credits: Energy-Anchored Claims) rises for consecutive quarters while native fee share, private settlement volume, and collateral lockups stagnate or decline. The WDR is a pair — its stock component (custodial-exposure share of total exposure) and its flow component (wrapper-activity ratio) — and “rises” means both components rise over the window; if one rises while the other falls, the condition is not met and the split is published. In its full form: custodial and synthetic exposure (CCR, SER) becomes the dominant form of ownership for a sustained period while protocol-native fees, collateral, private settlement, proof demand, and verified-compute usage remain stagnant or declining, with a persistently positive Wrapper–Native Growth Gap in its unit-denominated form (§23: Extended Telemetry) — the USD form is published alongside but is not the trip wire, because it can move on revaluation alone.
Maturity gate. This line reads only after the Phase II entry gate of §26: Adoption Curve & Ecosystem Dynamics is met; before that it is published as a watch indicator and trips nothing. A wrapper that is the only legally holdable form of a Phase I asset dominates a native base that does not yet exist, and the ratio says nothing until there is a native loop for it to substitute for.
Why it weakens the thesis: Price rises while the monetary thesis dies. Government-approved wrappers becoming the dominant institutional form is co-option without censorship. The asset may remain a successful financial product, but the claim that it functions as a native store of value for Privacy, Proofs, and Compute is no longer supported by anything except its chart.
Red Line 10: Physical Infrastructure Opacity
Condition: Physical VerifyPrice (§19: Layer 4: Truth & Work) — the capacity-weighted p95 time or cost to verify FCR claims — exceeds its benign-state baseline for consecutive quarters, where the baseline is the trailing four-quarter median published before the window opens and frozen for its duration; or Facility Capacity Receipt data is unavailable or unverifiable for of active capacity for consecutive quarters. Below the Phase II entry gate of §26: Adoption Curve & Ecosystem Dynamics the reading is published as a watch indicator and the baseline is accumulated; the line trips nothing until a baseline exists.
Why it kills the thesis: Layer 0 claims become trust-me claims; Work Credits lose infrastructure credibility.
Red Line 11: AI Enclosure
Condition: Top-3 hyperscalers, closed TEEs, or a single jurisdiction exceed of VerifyPrice-tracked verified compute capacity (the 40% chip-family/TEE cap of §14: Layer 0: Verifiable Machines & Energy being the early-warning tier of the same concentration measure), i.e., the Enclosure Risk Flag (§4: Threat Model) triggers and persists for consecutive quarters.
Maturity gate. This line reads only after the Phase II entry gate of §26: Adoption Curve & Ecosystem Dynamics is met; before that it is published as a watch indicator and trips nothing. The 50% threshold is tighter than Red Line 3’s 70% for the reason given there: capacity concentration is slow to reverse, verification concentration is not.
Why it kills the thesis: The verified-compute service market described by the “AI Money” lens becomes a cloud IOU; the frontier is enclosed rather than homesteaded, so it cannot support the associated base-asset monetary candidate.
Red Line 12: Agency Failure
Condition: Forced Disclosure Incidence (§24: Legal, Policy, and Jurisdictional Posture) becomes systemic, or participation/agency use cases (§2: The World Forces New Monetary Primitives) fail to materialize while institutional usage grows, for months.
Why it kills the thesis: Lawful privacy collapses socially, or the protocol serves institutions but not users—violating the ninth SoV requirement (§3: First Principles: What a SoV Must Survive). Emergency governance becoming routine is a related failure: neutrality decays into foundation fiat.
Red Line 13: Energy Sovereignty Failure
Condition: Network capacity-weighted sovereign optionality (§14: Layer 0: Verifiable Machines & Energy) falls below the floor of the published band schedule — the lower edge of the “low” band that carries the issuance cap in §22: Layer 6: Governance & Telemetry — for consecutive quarters, or of VerifyPrice-tracked capacity sits in jurisdictions operating an active curtailment or power-rationing regime against verification workloads for consecutive quarters.
Maturity gate. This line reads only after the Phase II entry gate of §26: Adoption Curve & Ecosystem Dynamics is met; before that it is published as a watch indicator and trips nothing. A Phase I fleet is small enough that a single facility’s jurisdiction is the network’s, and the reading would describe the fleet’s size rather than its exposure.
Why it kills the thesis: Verification affordability becomes a sovereign policy variable rather than a market outcome. Red Line 1 becomes externally triggerable: an adversary or host state can break the hinge by adjusting tariffs, interconnection queues, or load priority, without touching the cryptography, the governance, or the market.
Red Line 13 and its neighbours.
Three red lines now touch the physical substrate and they are not redundant:
-
Red Line 10 is opacity: we cannot see the substrate.
-
Red Line 13 is fragility: we can see it clearly and it will not survive pressure.
-
Red Line 11 is enclosure: we can see it, it is robust, and someone else owns it.
A network can breach any one without the others. Perfect FCR disclosure of a single-interconnect fleet in a rationing jurisdiction breaches 13 while passing 10. Do not merge them.
The dependency this makes explicit.
§19: Layer 4: Truth & Work describes Physical VerifyPrice SLOs as constitutional and exogenous to token price. That is right, and Red Line 1 correctly treats their sustained breach as fatal. But exogenous to token price is not exogenous to everything: the SLOs remain endogenous to the physical and jurisdictional conditions under which power and reference hardware are obtainable (§4: Threat Model).
Red Line 13 exists so that this dependency is monitored upstream rather than discovered downstream. Without it, the sequence
runs to completion with no instrument reading anywhere along it until the hinge itself fails. A falsification framework whose primary condition can be tripped by an unmonitored external variable is not yet falsifiable in the way it claims.
Red Line 14: The Capturable Wedge Closes
Measured quantities. For canonical workload at tier in period :
-
— all-in USD price to the buyer of executing at tier through the protocol, inclusive of the protocol fee. Protocol-native: PIDL receipts already carry workload ID, tier, timestamps, and hardware profile (§19: Layer 4: Truth & Work).
-
— lowest publicly quoted USD price to execute the same computational content without protocol-grade verification, on the same hardware class. Sourced from a pre-committed reference panel: a frozen list of venues (e.g., three hyperscalers and three GPU marketplaces) plus a fork row — the lowest-fee protocol-grade fork offering the same canonical workload, priced on identical terms. The fork row is not optional: a fork runs the same technology, so it carries none of the cost handicap a hyperscaler does, and it is therefore the channel that binds first (§10: Work Credits: Energy-Anchored Claims). A wedge measured only against unverified alternatives is measured against the weaker competitor. The panel is scraped daily, with the workload-to-instance mapping published as a machine-readable spec. Panel changes require publication and 90 days’ notice. Where a venue publishes committed-use, reserved, or spot pricing, the lowest generally available of those is the reading, not the on-demand list price.
-
— normalized bypass spread. Normalization is not cosmetic: the absolute spread shrinks mechanically with compute deflation, so only the ratio is economically meaningful.
-
— verification cost share: proving plus redundancy per unit, expressed as a fraction of . Derived from FER and VerifyPrice telemetry, and subject to the same third-party custody and reproducibility requirement as the reference panel (below), because enters negatively and the fee recipient has a direct interest in understating it.
-
— the capturable wedge: what is left of the price the protocol commands after paying for the verification that justifies it.
-
— realized take rate: gross native fees (USD) (settled protocol turnover, USD). Gross, not net-of-burn, because measures what buyers pay — the same convention the FeeCoverage definition pins for the fee family (§22: Layer 6: Governance & Telemetry); burns are supply arithmetic, read as reduced net issuance, and adding them would count destruction as payment. Computable by anyone from chain data.
Condition A — the wedge closes. Capacity-weighted across the canonical starter set (§19: Layer 4: Truth & Work) falls below the realized take rate, , for consecutive quarters, with no credible remediation path.
Condition B — the base deflates faster than volume compensates. Native fee turnover fails to grow over a trailing four-quarter window while protocol physical throughput (verified units delivered) grows over the same window. “Fails to grow” means the trailing-four-quarter sum is non-increasing ( its prior value) for two consecutive quarters. Deflation adjustment is by the workload unit-price index — the capacity-weighted average USD price of the canonical workload basket — not by the asset price: the condition asks whether buyers are transacting less even as physical delivery grows, so the deflator strips compute-price deflation, not asset-price revaluation. Both the raw and deflated series are published. Persistence: the red line reads on the condition holding for two consecutive quarters, not one; a single flat quarter is a flag, not a trip.
The connective, stated once: either condition breaching trips the red line. A breach of A, or a breach of B, or both, is a breach of Red Line 14. There is no requirement that they breach together.
Why A kills the thesis: The protocol is charging more than the differential value it supplies. It is living on switching costs, subsidy, or inertia rather than on anything a buyer would pay for, and the fee is not a wedge on genuine differential value but a tax on captive volume. That fee is retractable by competition, so nothing durable accrues.
Why B kills the thesis: The wedge may be intact and the burn still cannot scale. An ad valorem fee on a deflating unit price is a shrinking real toll (§10: Work Credits: Energy-Anchored Claims); if throughput grows while real fee-plus-burn turnover does not, the empirical bet the thesis is making on volume outrunning deflation is losing, in public.
Both clauses must be monitored, because each closes a gaming route the other leaves open. A published alone is gameable by cutting the fee toward zero, which trivially restores while capturing nothing; B published alone is gameable by inflating volume at a vanishing wedge. Monitoring both means a protocol that is neither differentially valuable nor growing its real take has nowhere to stand. This is a requirement on the test, not on the trigger: dropping either clause from the instrument panel is a breach of the falsification protocol, while breaching either clause in the readings is a breach of the red line.
Why Condition A is hard to game.
It is self-normalizing. It compares two independently measured quantities — what the market will bear net of verification cost, and what the protocol actually takes — rather than testing either against a threshold somebody had to guess. There is no parameter to lobby for. A protocol cannot pass by lowering its ambitions, because lowering the take rate lowers and lowering the price lowers , and the comparison survives both.
What Condition A is asking, in plain terms.
Stripped of the notation, asks a question with no technical content in it at all: does anybody actually pay for the truth? The wedge is the premium the market will bear for a verified unit over an unverified one, net of what the verification costs. It is a direct measurement of whether cheap checkability changes any buyer’s behavior—and it can go to zero for a reason that has nothing whatever to do with this thesis’s engineering. Verification can be cheap, correct, public, and comprehensively ignored. An auditable system that nobody audits, and whose auditability moves no price, is transparency theater [Green 2026f]: the receipts are produced, the proofs verify, every SLO stays green, and no counterparty pays a cent more for the position that carries them.
Why that failure deserves naming rather than only measuring.
It has no technical signature. Nothing breaks, no threshold is crossed anywhere else on the panel, and the operational dashboards of a thesis failing this way are indistinguishable from those of a thesis succeeding. It is worth stating plainly that this is the mode in which the argument is most likely to be quietly wrong—not a fault in the machinery, but the discovery that a market which could have priced verification did not care to, because habit was cheaper, because a trusted intermediary was good enough, or because the buyer base the thesis assumed was never there. §10: Work Credits: Energy-Anchored Claims argues that free verification deters misrepresentation before it is attempted; that argument requires the claimant to believe being caught would cost them something, and Condition A is the instrument that reads whether it does. This is the sense in which Red Line 14 tests the monetary mechanism and not merely the fee model: a wedge of zero means the market was offered symmetric knowledge and declined to pay for it.
Third-party checkability.
The thesis’s own principle applies with full force here: the party being scored must not set the scoring function (§14: Layer 0: Verifiable Machines & Energy, Red Line 4). The reference panel, the workload-to-instance mapping, and the verification cost share must therefore all be maintained by someone other than the fee recipient, and an independent party must be able to re-derive from the published inputs and obtain the same number. deserves explicit mention because it is the easiest term to shade: it enters negatively, so understating the cost of verification inflates the wedge and makes this red line harder to trip, and the fee recipient is the party with both the incentive and the telemetry. Its inputs — proving overhead and redundancy per unit, drawn from FER and VerifyPrice — must be published in the same reproducible form as the panel, with the derivation runnable by an outside party against the raw receipts. A wedge computed by the entity collecting the wedge is a marketing figure, and that applies term by term.
Honest coverage caveat.
is well defined only where a like-for-like unverified execution exists: matrix multiplication, inference, proof generation. It is not well defined for atomic settlement or media provenance, where there is no unverified version of the same product — the comparator there must be the all-in fee of a custodial or regulated rail delivering the same economic function. That is a rougher measurement with a weaker claim to like-for-like, and it must be reported separately rather than blended into a single index. An index that averages a clean comparison with a rough one inherits the rough one’s error and hides it.
Effective prices, not list prices — and the direction of the residual bias.
On-demand list pricing is not what hyperscaler and marketplace capacity actually transacts at. Committed-use discounts, reserved instances, and spot markets routinely clear well below list, so a panel scraping list prices measures a bypass channel nobody uses. That is why is specified above as the lowest generally available price across the published pricing modes rather than the on-demand quote, and why the panel spec must record which mode each reading came from.
Even so, a residual bias survives: the largest buyers transact at negotiated enterprise rates that are published nowhere, so the observable price remains an upper bound on the true alternative. The direction this pushes the red line is worth deriving rather than assuming, because it is not the direction one expects. Since falls as rises, an overstated understates both and , and understates by more, because exceeds the per-unit verification cost. Measured is therefore too small and Condition A trips earlier than the truth warrants. The reading is accordingly published as an upper bound on breach: a measured may overstate the case against the thesis and must be re-derived against negotiated pricing before the 90-day clock is treated as running, whereas a measured is a pass earned against a conservative comparator.
That is the benign direction, which is precisely why the term that runs the other way needs naming. Understating inflates and makes the red line harder to trip, and is the one input sourced from the fee recipient’s own telemetry. The custody requirement above exists for that reason and is the load-bearing safeguard here, not the panel methodology.
Red Line 14 and its neighbours.
Three distinctions worth stating precisely, because each is easy to collapse:
-
The price series is not VerifyPrice. VerifyPrice is a cost SLO — the real-resource cost of checking a claim on reference hardware, deliberately exogenous to token price (§19: Layer 4: Truth & Work) — and Red Line 1 reads on it. Red Line 14 does not: the quantity it reads on is a price series for delivered service, set by markets, which VerifyPrice is not and was never meant to be. The two red lines therefore cannot be tripped by the same event. The qualification is that , one input to the wedge, does draw on VerifyPrice and FER telemetry for the cost of verification, which is the right source for a cost term; that is why carries the independent-reproducibility requirement above. Shared telemetry in one term, not a shared test.
-
This is not Red Line 6. Red Line 6 asks whether fees follow usage — a direction. Red Line 14 asks whether there is a wedge worth charging at all — a magnitude (§10: Work Credits: Energy-Anchored Claims). A protocol can pass 6 while failing 14: native fees can track usage perfectly while the fee itself exceeds the differential value supplied.
-
This is not Red Line 5. Fee coverage measures fees against the security budget. Red Line 14 measures the fee against what the market will bear. Coverage can be adequate on a base that is about to be competed away.
Red Line 15: Native Collateral–Capacity Spiral
Measured quantities. Publish native-asset peak-to-trough drawdown, collateral coverage against realized slashing exposure, operator exit and liquidation rates, stress-scenario DVC, collateral released into liquid float, and recovery of core service SLOs.
Condition. A material native-asset drawdown — defined here, and not to be redefined during an episode, as a peak-to-trough decline of in the native asset’s price over a window of days, measured in the workload unit-price index of Red Line 14 with the USD series published alongside — persists for at least 30 days below the trigger level; collateral coverage falls below realized slashing exposure; operator exit or forced liquidation exceeds its constitutional threshold; stress-adjusted DVC declines; released native collateral materially increases liquid float; and core service SLOs fail to recover within the 90-day remediation period. The clauses are conjunctive by design — each alone has an innocent explanation (a drawdown without coverage failure is a bear market; operator churn without DVC decline is turnover), and it is the joint deterioration that names the spiral. The thresholds must be set before the episode, reported for pure-native, mixed, and native-plus-insurance designs, and may not be relaxed while the clock is running.
Maturity gate. This line reads only after the Phase II entry gate of §26: Adoption Curve & Ecosystem Dynamics is met; before that it is published as a watch indicator and trips nothing. A 40% drawdown in a Phase I asset with three operators is a venture repricing, and the collateral-coverage and DVC clauses have no series to read on.
Why it kills the thesis. The asset is being offered as insurance while its underwriting capacity disappears in the insured event. The loop
turns native value capture into a service-capacity contraction. A temporary drawdown is not the breach; the sustained joint deterioration and failed SLO recovery are.
Red Line 16: The Convenience-Yield Null
Maturity gate. This line does not read until the stack delivers measurable service at Phase III scale and a lending and derivatives complex exists around the base asset deep enough to quote continuously. Below that, the reading is published as insufficient market and trips nothing.
Measured quantities. The five-family convenience-yield vector of §23: Extended Telemetry, published against the regime-pressure index of §10: Work Credits: Energy-Anchored Claims: base-asset lending rates segmented by venue, term and borrower class; forward and perpetual basis net of the reference rate; and wrapper basis against the value of native holdings. Borrow demand is decomposed before the reading is taken — directional short interest, market-making inventory financing, and operational squeeze against locked float are not the premium, and an operational squeeze is a liquidity event reported as such.
Condition. With the gate open, the regime-conditioned series shows no coefficient on distinguishable from zero across at least two distinct macro states (§26: Adoption Curve & Ecosystem Dynamics) over a window of consecutive quarters containing observed regime transitions under the pre-committed state classifier, with the estimation specification and the state classification both pre-committed and published before the window opens.
Power, stated before the reading. A regime coefficient estimated from a handful of quarterly observations will fail to reject zero whether or not the premium exists, and a red line that kills on low power is a red line that kills by construction. The published specification therefore carries a pre-registered power calculation: the hypothesised effect size (the smallest regime-conditional convenience yield the thesis would count as the mechanism operating, stated in basis points per unit of ), the sampling frequency actually available from the venues in the panel, and the resulting power at the window length. “Not distinguishable from zero” kills only when the pre-registered power to detect the hypothesised effect exceeds 80%. Below that, the reading is published as underpowered, the window extends, and the line trips nothing — which is a statement about the instrument, not a reprieve for the claim. A window that never reaches 80% power is itself a published fact about how thin the market for this asset’s regime-contingent service is.
Why it kills the thesis: §10: Work Credits: Energy-Anchored Claims withdrew fee accrual as a source of monetary premium, and §10: Work Credits: Energy-Anchored Claims relocated the premium to a holder-side service flow whose defining property is that it is regime-contingent — small in benign states, large where substitutes fail (why that flow should reach the base asset rather than Work Credits and Bitcoin is argued at §27: Risk Analysis & Failure Modes, immediately below). A flat series is that property absent. The holders are charging nothing extra to part with units in exactly the states the asset is claimed to be for, which means the market has priced the mechanism at zero. What survives is a service asset with a cash-flow claim, a collateral floor, and whatever pledgeability (§10: Work Credits: Energy-Anchored Claims) has been demonstrated — but the state-contingent premium the thesis argues for does not exist, and the argument for it must be withdrawn rather than deferred.
The null is the point. §23: Extended Telemetry already commits to publishing a flat series as a null result. This red line is that commitment given a clock, a threshold, and a consequence. An unsized quantity with no instrument is indistinguishable from an article of faith; an unsized quantity with an instrument and no trigger is an article of faith with a chart.
Insurance is priced when the storm is forecast, not after it lands. If the lending rate on this asset reads the same in the calm as in the gale, nobody was ever buying shelter — they were buying a security, and the thesis has spent six Parts describing a hedge its own holders decline to pay for. The instrument cannot be argued with. Either the rate moves with the weather or it does not, and a flat line across two regimes is the market’s verdict on the mechanism, delivered in basis points.
Why the Hedge Bid Reaches the Base Asset and Not Work Credits
The sharpest objection to the holder-side mechanism is internal to the thesis. A holder hedging loss of access to verified services already has an instrument for contingent access — the Work Credit — and a better exit hedge in Bitcoin. Rationally she holds both, and nothing above has said why the bid reaches the base asset at all.
The answer is that a Work Credit hedges the wrong state. It is typed and workload-specific; it is bounded by the Delivered Verified Capacity of the facilities behind it; it retires on redemption; and it is a claim on specific capacity. That capacity fails in exactly the states the hedge is for — the curtailment, embargo, or partition that removes a jurisdiction’s provers removes the Work Credits written against them in the same moment. The instrument and the risk it would insure are correlated by construction. Bitcoin hedges the complementary state, exit, and hedges it well; it does not deliver a proof or a verified inference when the ordinary supplier will not. What remains is the one instrument that is bearer, workload-agnostic, does not retire, is the unit in which Work Credits are priced, and is what the protocol pays: the base asset. The hedge for “this service next quarter” is a Work Credit. The hedge for “access to any verified service in a repression state” is the base asset, and the holder-side mechanism attaches to the second alone.
The corollary is conceded rather than argued around. If holders in fact prefer Bitcoin plus Work Credits — pricing exit and near-term service separately and leaving nothing for the agnostic claim — the convenience-yield series is flat and insiders never move obligations into the unit. That is precisely what Red Lines 16 and 18 detect, and the thesis treats it as its default null, not as an anomaly.
Red Line 17: Information-Sensitivity Reversion
What this line does not read on. Haircut levels. Cheap public verification removes one kind of information sensitivity — about unit quality: counterfeit, fraud, double-count, misreported delivery — and leaves the other kind untouched: sensitivity to the payoff, meaning future fee demand, regime, and governance (§10: Work Credits: Energy-Anchored Claims). The haircut level is set by the second kind, through realized volatility, and a 30–50% haircut on a volatile bearer asset is not a failure of anything argued here. What cheap verification predicts is narrower: that lenders who cannot disagree about what a unit is will disagree less about what to lend against it, and will re-converge faster after a shock, than lenders facing an opaque comparable of the same volatility. The prediction attaches in full force to positions with debt-like payoffs — over-collateralized, DVC-backed Work Credit positions; base-asset repo with volatility-set haircuts — and in attenuated form to the bare base asset.
Maturity gate. The line reads only when independent lenders quote haircuts continuously on the base asset and on at least one opaque comparable over the whole window, at matched tenor and borrower class, with quoted depth published. Below that the reading is published as insufficient panel and trips nothing.
Measured quantities. Cross-lender haircut dispersion — the interquartile range of quoted haircuts across the pre-committed lender panel — on (i) the native base asset, (ii) pledged protocol positions, and (iii) an opaque comparable set: wrapped or custodial representations of the same asset, and tokenized commodity claims. Each series is residualized on trailing realized volatility and on quoted depth before comparison, under a specification pre-committed before the window opens.
Condition. With the gate open, (a) the controlled dispersion on the native asset is not lower than that of the opaque comparable set over consecutive quarters; or (b) during a declared stress episode the native asset’s dispersion widens relative to the comparables’ — the ratio rises — or re-converges more slowly, while receipt availability and VerifyPrice remain within SLO. Either reading, with no credible remediation path, measured against the pre-committed lender panel under the custody and reproducibility terms of Red Line 14. Levels are published alongside and are not the trip wire.
Applied to Bitcoin. The v3.0 formulation of this line read on dispersion declining as coverage rose, and Bitcoin — unit quality already perfectly verifiable, haircuts at 30–50% and dispersed across lenders — would have tripped it on the first reading. On the present specification the test for Bitcoin compares native BTC against wrapped and exchange-custodied BTC quoted by the same lenders. It is a test Bitcoin may pass or fail; it is not one it fails by construction, and if it fails, the pledgeability mechanism is in doubt for this asset as well.
Why it kills the thesis: The asset is being priced on private information about specific units and positions, and public verification has not removed it. No-questions-asked acceptance has not formed, the pledgeability mechanism argued in §10: Work Credits: Energy-Anchored Claims is absent, and cheap verification has bought operational convenience without buying moneyness. This red line reads on link 9 of §6: The Triad and the Monetary Candidate, which the fee, capacity, and coverage lines do not.
Watch the disagreement, not the level. When lenders converge on one haircut they are telling you nobody believes there is anything left to find about the unit; when they scatter, each is pricing something private, and the scatter arrives before the level moves. One reading of 2008 runs through the same margin: Gorton and Metrick ([Gorton & Metrick 2012]; Sources) document haircuts on structured collateral in the repo market rising from near zero to 40–45%, a repricing of what nobody could any longer check unit by unit. That is a level story, and this line does not read on levels; what it takes from the episode is which margin failed — unit quality, the one margin cheap verification addresses. A protocol whose receipts are public, whose verification is cheap, and whose lenders disagree about what a position is worth no less than they disagree about its opaque twin has published everything and convinced nobody.
Red Line 18: The Denomination Null
Maturity gate. Neither condition reads until free-choice contract volume in the relevant tier clears a published floor, stated here rather than deferred: trailing four-quarter free-choice notional in the tier, after the carve-out below, of at least 10% of settled protocol turnover, drawn from at least 50 distinct counterparties. Below that floor the reading is published as insufficient base and trips nothing; a red line that fires on an empty denominator is noise. Condition B carries a second floor of its own, given with it.
Accounting carve-out, applied before either condition is evaluated. Contracts whose quoting unit is fixed by an external reporting, tax, or regulatory requirement — functional-currency rules, auditor mandates, statutory reporting obligations — are excluded from the numerator and the denominator, and the excluded volume is published. Without this exclusion the line fires on accounting standards rather than on any judgment about the unit, and neither condition below is defensible without it.
Condition A — outsiders will not reckon in the unit. Tier II and Tier III free-choice denomination share, subsidy-adjusted, is flat or declining over four consecutive quarters while protocol physical throughput and native fee turnover grow over the same window; and the quote/settle matrix shows fiat-quoted, natively-settled contracts retaining or increasing their share of notional.
Why A weakens the thesis: the asset is a settlement rail rather than a unit of account. Counterparties transact through it and do not reckon in it — the configuration bitcoin has occupied for seventeen years while carrying monetary premium, which is why this is a downgrade of the monetary claim’s completeness rather than of its existence. The thesis survives in reduced form: an accepted, pledgeable, state-contingently useful bearer asset that never became a coordination device, to be defended on §10: Work Credits: Energy-Anchored Claims and §10: Work Credits: Energy-Anchored Claims alone and restated as such.
Condition B — insiders will not reckon in the unit. B reads on net denomination, because an insider’s revenue side is in the unit by construction and says nothing. Two series, both after the carve-out: (i) the share of Tier I revenue quoted and settled in the unit, published as context; and (ii) the share of Tier I participants’ long-dated obligations — power contracts, hardware financing, hosting leases, payroll — denominated in the unit, computed over the eligible obligation set: contracts whose counterparty would accept unit denomination on terms the insider could have taken, with the eligibility rule published. B trips when, with the gate open, (ii) is non-increasing over four consecutive quarters; or when insiders actively convert unit revenue out of the unit to meet obligations in the eligible set — read as the share of Tier I unit receipts sold within the settlement period against eligible obligations, rising or flat over the same window. Floor: at Phase III entry (§26: Adoption Curve & Ecosystem Dynamics), of eligible insider obligations unit-denominated; a network entering Phase III below that floor has tripped B on arrival.
Why B kills the thesis: Tier I counterparties are protocol participants paid in the unit. Their costs are not: power, hardware, and payroll are fiat-denominated everywhere a proving fleet has yet been built, and the basis risk between the two is real. That is not the defect the earlier draft of this line pretended it was not; it is the choice B measures. An insider who carries the basis can resolve it in one of two directions — by moving obligations into the unit as counterparties permit, or by treating the unit as inventory to be sold on receipt. Tier I is the best-informed population that will ever exist about this asset, and no external accounting rule compels its choice once the carve-out is applied. If that population, offered the chance to denominate in the unit it is paid in, keeps choosing to sell it instead, the failure is not coordination among strangers. It is the people with the most information declining to reckon in the unit, which is the strongest available evidence that the unit is unfit to reckon in.
Why the two are held apart, and the standing counterexample. Bitcoin has a Tier I: miners, pools, hosting providers, and hardware vendors, paid in bitcoin and paying for power, ASIC financing, and payroll in fiat, with the industry’s own benchmark — hashprice — quoted in dollars per petahash per day. On this specification Bitcoin sits at or near tripping B today: the share of miner obligations denominated in bitcoin has not risen over seventeen years, and selling coin on receipt to meet fiat costs is standard treasury practice, with a minority of treasury-holding miners as the exception. That is the standing counterexample, and it is stated at full strength rather than explained away: the strongest bearer asset in existence carries monetary premium while its own insiders decline to reckon in it. The severities still differ, because A describes a configuration Bitcoin has shown to be survivable — settling without denominating — and B describes one the thesis cannot survive, since a fee-denominated service economy whose own operators will not hold obligations in the unit has no constituency left to make the denomination argument. The thesis is therefore betting that a protocol which pays its insiders in the unit and prices their inputs in it can move (ii) where Bitcoin’s mining economy has not. If it cannot, B trips here for the same reason it would trip for Bitcoin, and the thesis does not get to keep the exemption it once granted itself. Either condition breaching trips the red line at its own severity; there is no requirement that they breach together.
A unit people will spend but not quote in is a coupon. This test fails quietly, with every other board still green — throughput rising, fees arriving, corridors clearing, and every contract behind them written in dollars. That is bitcoin’s seventeen-year position and it is survivable, which is why Condition A weakens the thesis rather than ending it. Condition B is the one to fear. It is not the world declining to reckon in the unit; it is the people who built it, who are paid in it, who post it as collateral, and who could write their own power and payroll in it, choosing dollars anyway. Bitcoin’s miners have made that choice for seventeen years. When the operators of a service economy priced in the unit make it too, there is nobody left to persuade.
Red Line 16 and its neighbours.
Three lines now read on link 9 of §6: The Triad and the Monetary Candidate, and they are not redundant — they test the three mechanisms the monetary claim actually rests on, and a network can fail any one while passing the others:
-
Red Line 16 tests the holder-side flow: does anyone pay more to hold when substitutes fail — and pay it for the base asset rather than for Work Credits and Bitcoin (§27: Risk Analysis & Failure Modes)?
-
Red Line 17 tests pledgeability: will lenders disagree less about a unit whose quality anyone can check than about its opaque twin?
-
Red Line 18 tests denomination: will anyone reckon in it rather than merely settle in it?
Before this version, every red line read principally on links 2 through 8 — the service path, the capacity, the fee accrual. Red Lines 9 and 12 arguably touched link 9 from the side, by reading on whether ownership and use took native form; none read on the monetary mechanisms directly. That gap was the sharpest available criticism of the falsification regime and it is closed here rather than argued away.
Pattern: The red line is not “bad thing happens once.” It is “sustained breach + no recovery.” Isolated incidents with rapid remediation are expected in any complex system. Persistent degradation without response is thesis failure.
What happens at a red line:
| Condition | Response |
|---|---|
| Red line breached | Incident declared; governance must publish remediation plan within 14 days |
| Remediation fails after 90 days | Asset reclassified from “SoV candidate” to “speculative/experimental” on the public boards (§23: Extended Telemetry); the reclassification is a published reading, not a statement by any body that speaks for the protocol, since Red Line 8 admits none |
| Multiple red lines breached simultaneously | Crisis mode; independent review commissioned; results published |
Red line response protocol. The clocks run on distinct triggers and do not nest: the 14-day publication clock starts at incident declaration; the 90-day remediation clock starts when the remediation plan is published (or at day 14 if none is); the two overlap only by construction of that sequencing, and each is reported with its own start date on the incident page. Neither clock resets on parameter change — the no-relaxation rule of Red Line 15 generalizes: thresholds and clocks are frozen for the duration of the episode they measure.
These are not punishments—they are truth in advertising. An asset that claims SoV properties must demonstrate them. If it can’t, it should stop claiming.
Market Realization Warnings
Red lines are protocol failures. The Market Realization Plane generates a second, weaker class of signal that must not be confused with them. A wrapper unwind can destroy price without damaging protocol function at all; treating that as thesis falsification would be as sloppy as treating a rally as confirmation. The distinction:
-
Monetary red lines (above) mean the protocol’s monetary claim has failed: verification breaks, settlement safety breaks, native value capture fails, issuance becomes discretionary, censorship routes dominate, or native use can be bypassed.
-
Market realization warnings (below) mean price has become an unreliable signal. They do not necessarily kill the protocol; they suspend the right to cite price as evidence about it.
Warnings trigger when:
-
A statistically significant break appears in holder flow elasticity.
-
Net mechanical gain changes sign.
-
The Mechanical Pressure Ratio exceeds pre-declared market-depth bounds.
-
Wrapper creations dominate native spot demand.
-
Dealer swap capacity appears to bind.
-
Exposure migrates from swaps toward options.
-
Recursive leveraged wrappers appear.
-
Top wrappers or dealers exceed concentration thresholds.
-
The Wrapper–Native Growth Gap stays elevated.
-
Price rises while native fees and receipt volume fall.
-
Price falls while native monetary health improves.
-
Cross-jurisdiction hedges produce halt or settlement asymmetries.
-
Triad capacity is consumed at scale while the asset prices as a service and the monetary bid accrues elsewhere — Service-Good Realization, below.
The correct response to a warning is not intervention. It is epistemic: publish the warning, state which flow term is dominating, and stop using price as evidence in either direction until it clears. Governance must specifically not respond to warnings by inflating issuance, subsidizing price, or buying back supply — those are the reflexes of an entity managing a stock price, not operating a monetary constitution.
One warning is not merely epistemic.
The twelfth item above is the last of the flow-mechanical warnings. The thirteenth is a different animal and is set out in full, because it is the observable form of the thesis losing the argument of §30: Objections & Responses and because a warning that carries falsifying weight should not be left as a line in a list.
Warning 13: Service-Good Realization
Condition. All three clauses hold together, read across at least two distinct regime-pressure episodes — intervals in which the Stage A index (§10: Work Credits: Energy-Anchored Claims) is elevated under criteria published before the reading rather than chosen after it:
-
Capacity is being consumed at scale. Receipt volume, verified units delivered, and private settlement volume grow through the episode; the capturable wedge stays above the realized take rate, so Red Line 14 does not fire; native fee-plus-burn turnover tracks usage, so Red Line 6 does not fire. The protocol is working.
-
The insurance signature is absent. Through the episode the asset exhibits nothing that distinguishes it from a claim on a service business: holding duration does not extend, the non-custodial share does not rise, the duration-neutral holding cohort of §26: Adoption Curve & Ecosystem Dynamics does not grow, and demand moves with buyers’ capacity budgets rather than with their exposure to the pressure. Read on the Value Capture and Agency Preservation boards (§23: Extended Telemetry), not on a chart.
-
The monetary bid accrues to Bitcoin. Over the same episodes Bitcoin absorbs the flow the thesis predicts for a regime-contingent hedge, while the triad asset covaries with compute and IT spending rather than with regime pressure — and Work Credit inventory, not base-asset holding, is where any contingent-access demand shows up. That is the Bitcoin-plus-Work-Credits portfolio of §27: Risk Analysis & Failure Modes, chosen by holders in the state the thesis said they would choose the base asset.
What it means. Not that the protocol failed — clause 1 says it did not. It means the regime-contingent convenience yield of §10: Work Credits: Energy-Anchored Claims was not there, and that yield is the entire remaining basis for the monetary claim once §10: Work Credits: Energy-Anchored Claims has conceded that fees, burns, and collateral produce a cash-flow claim and a floor. The prescribed response is therefore reclassification rather than retirement: the asset is a verified-capacity service asset with a competitively priced fee stream and a collateral floor. That is a real thing to be. It is not a store of value, and the protocol’s communications must stop saying otherwise on the same 90-day clock the red-line protocol uses.
Why this remains a warning rather than another red line. Clause 3 reads on price, and reads it against another asset. Every condition in §27: Risk Analysis & Failure Modes is protocol-observable, and §10: Work Credits: Energy-Anchored Claims forbids treating price as evidence about monetary adoption in either direction. A price-comparative red line would break both commitments. Red Line 15 instead covers the protocol-observable collateral–capacity spiral. What distinguishes this warning from its twelve neighbours is that clauses 1 and 2 carry the falsifying weight by themselves: capacity consumed at scale with no insurance signature, across repeated episodes, is the monetary claim failing whether or not anyone looks at Bitcoin. Clause 3 says where the premium went. It is corroboration, not the test.
New here? Start with the one-minute version.
Tip: hover a heading to reveal its permalink symbol for copying.