Kaal claims by topic: consensus-and-security, page 3
441 atomic, individually citable claims from the published work of Wulf A. Kaal tagged consensus-and-security.
- The prediction that a structured deliberation round reduces unanimity is therefore not a prediction that agents disagree for its own sake. 2026
- The procedure is designed to reduce the information channel on which cascades run while retaining cohort-mediated accountability. 2026
- In the treatment arm, validators exchange structured assessments before a binding adjudication; in the matched control arm, the same work is adjudicated without that exchange. 2026
- Deliberation should reduce over-approval because the assessment exchange forces the pool to articulate what is wrong with a submission before anyone profits from waving it through. 2026
- Deliberation should reduce unanimity because articulated disagreement, surfaced before votes bind, is exactly the private information a cascade suppresses. 2026
- The result was null: +0.0250, 95% CI [-0.0502, +0.0985]. 2026
- Both primary hypotheses are confirmed under the preregistered rule: the pooled intervals exclude zero in the hypothesized direction, and each contrast is negative across every independent campaign unit. 2026
- Net discrimination, the discovery run’s failed primary, remained null in confirmation: +0.0606, 95% CI [-0.0086, +0.1303], crossing zero exactly as the pre-registration predicted it would. 2026
- Deliberation is therefore a composition intervention, not an intelligence upgrade for the monitor. 2026
- The unanimity result is consistent with reduced cascade behavior but does not uniquely identify that mechanism. 2026
- They do not establish a treatment effect because the information environment was defective and the diagnostic was regraded after execution. 2026
- Authority drift is the failure mode permissions systems are least equipped to detect because every individual check passes while the aggregate operates outside what the user authorized. 2026
- Withdrawal of a grant at the point of issue does not reliably propagate to components already operating under it, and few systems can demonstrate that it did. 2026
- A reputation scoring system that does not name its resistance to Sybil creation, collusion, wash interaction, and cross-context reputation laundering has not specified a threat model. 2026
- Reputation may inform discovery, routing, pricing, and allocation but may never grant permission, enlarge authority, or substitute for an enforcement boundary, because violating this separation destroys the other institutional requirements. 2026
- A system that permits standing to open a door converts a performance signal into a security credential, raising the benefit of manipulating the signal without raising its cost. 2026
- Withdrawal of authority must propagate to every component operating under it, and the system must be able to demonstrate that propagation occurred; the demonstration clause is the substance of the requirement. 2026
- In the Mosaic implementation at commit 2d920ce, no reputation input reaches the enforcement path because no reputation layer exists yet, so the separation of reputation from authorization is not violated but unguarded. 2026
- The Chronicle at commit 2d920ce is append-only structurally but not tamper-evident: any process with filesystem access can rewrite or truncate history, and entries carry no digest, no chaining to a predecessor, and no periodic root. 2026
- At commit 2d920ce per-agent tool access is not yet implemented, so granting an agent access to a single Vault box grants it the ability to invoke every installed tool, and the user approves permissions tool by tool without ever seeing their composition. 2026
- Because provenance fields are minted by Core and never supplied by the tool, the tool remains low-trust and cannot forge its own provenance. 2026
- Hash chaining each Chronicle entry to its predecessor with a persisted per-tool head digest makes any modification, deletion, or reordering of history break the chain at a determinable point, at the cost of one hash per append. 2026
- Reputation standing should anchor to the SHA-256 of the tool artifact, paired with a publisher-level link and a controlled migration rule under which standing carries across versions only by an explicit, recorded act. 2026
- The flaw in bonded-stake deterrence is structural, not a matter of detection, latency, or adjudication error: a bond refunded on clean exit is an asset the operator carries out the door, raising walk-away value by the honest-release value of the principal — release pads the walk. 2026
- For long-lived delegation with positive carry, the marginal capacity effect of refundable principal is strictly negative in both exit cells and, whenever adjudication probability is positive, in both stay cells; the relationship premium is the scalable continuation-value component of deterrence. 2026
- Stakes denominated in non-fungible reputation tokens incentivize long-term probity and eliminate short-term arbitrage opportunities that fungible cryptocurrency stakes permit; the proof-of-stake design line supplied that mechanism intuition without deriving the present envelope. 2026
- In the strict long-match limit with positive carry, refundable escrowed principal weakly contracts the credible capacity frontier in all four cells of the regime map — nonpositive everywhere, strictly negative in both exit cells, and strictly negative in both stay cells whenever adjudication probability is positive. 2026
- No escape hatch restores a positive marginal effect of escrow in the long-match limit: the release-clock wedge is either impossible outright or requires a filing threshold exceeding one, and short cycles are excluded by the limit itself. 2026
- Making the stake captive closes the release leak but does not rescue the instrument: the surviving capacity slope is still negative in the carry cost because the walk value of the balance cancels through the surplus — the stake never mints a hostage. 2026
- False freezes tax honest release value and worsen the release-clock wedge's own admission condition, so challenger bonds, standing rules, and other anti-griefing measures are design candidates whose effects require separate modeling. 2026
- The dominance results apply to delegated staking relationships — delegator and operator, staking-as-a-service, and restaking-style delegation with exit rights and refundable principal — and not to self-staked consensus participation. 2026
- Within delegated proof-of-stake, the refundable fungible principal is not the scalable deterrent; the continuation value of remaining matched is. 2026
- The Secure Proof of Stake and Hybrid Secure Proof of Stake designs made the corresponding instrument choice — non-fungible reputation denomination and reputation-weighted rewards — without deriving the present envelope. 2026
- The results do not extend to consensus-layer security, where stake secures the entire chain simultaneously, attack payoffs are priced by attack-cost economics, and the token's value is endogenous to the attack. 2026
- Refundable stake does not expand credible capacity in the strict long-match limit: leaky release raises walk-away value, captive regimes close the leak without a positive marginal slope, and design by stake sizing is design of the wrong variable. 2026
- Token-weighted voting, the modal aggregation rule across the dataset, is not a neutral way to register member preferences but one specific choice in a space of choices, none of which is neutral under Arrow's theorem. 2026
- Any DAO operating a static rule set in a strategic environment with patient capital and high stakes faces the Folk-Theoretic prediction that the rule set will eventually be gamed, and the empirical record of DAO governance attacks confirms the prediction. 2026
- In the Beanstalk Farms exploit of April 2022, an attacker borrowed roughly one billion dollars in flash loans to hold two-thirds of governance tokens for a single block and drained roughly 182 million dollars, showing that token-weighted governance offers no defense against temporary token acquisition. 2026
- None of the predicted agent-governance failure modes is hypothetical: agent-executed attacks appear in nascent form in flash-loan governance attacks executed by autonomous capital, including the Beanstalk exploit. 2026
- Reputation is Sybil-resistant in a way token holdings are not: a strategic actor can acquire tokens by purchase but cannot acquire reputation without making contributions that other contributors will reference favorably. 2026
- Separating non-transferable reputation tokens from fungible collateral tokens closes the governance-capture pathway that single-token systems expose, in which voting power can be purchased or borrowed. 2026