# Attack resistance

`kaal:entity:attack-resistance`

**Status.** derived

This node is assembled mechanically from the 36 claims that carry the concept tag `attack-resistance`. It is a roster of what the corpus says under this term. It is **not** an adjudicated definition: no single statement here has been ruled canonical, and no first-appearance call has been made. Read the claims and judge for yourself.

## Every claim under this term

36 claims across 15 works, 2018 to 2026.

**2018**

- [3125822-012](https://wulfkaal.github.io/claims/3125822-012) [mechanism/argued] -- The platform is Sybil attack resistant because all power is weighted by reputation rather than by account: an owner of a single account holding 1000 tokens has the same or more power than an owner of 1000 accounts holding one token each.
  > The platform is Sybil attack resistant because all power in the platform is weighted by reputation. An owner of a single account with 1000 tokens has the same or more power than an owner of 1000 accounts with one token.
  Craig Calcaterra, Wulf A. Kaal, Vlad Andrei, Blockchain Infrastructure for Measuring Domain Specific Reputation in Autonomous Decentralized and A (2018). SSRN: https://ssrn.com/abstract=3125822
- [3125822-016](https://wulfkaal.github.io/claims/3125822-016) [mechanism/argued] -- A 51 percent collusion that votes against common sense is visible in an open system, which erodes trust, reduces use and fees, and lowers the value of the attackers' own reputational salary, so the tactic can destroy an expertise tag but cannot enrich the attackers.
  > This would erode trust in the platform, and therefore use and fees would diminish, making the 51% holding of reputational salary less valuable. Therefore this tactic generally has the potential to destroy the expertise tag, but not enrich the attackers.
  Craig Calcaterra, Wulf A. Kaal, Vlad Andrei, Blockchain Infrastructure for Measuring Domain Specific Reputation in Autonomous Decentralized and A (2018). SSRN: https://ssrn.com/abstract=3125822
- [3128900-018](https://wulfkaal.github.io/claims/3128900-018) [design/asserted] -- Unlike its decentralized competitors, the Semada Protocol is claimed to be resistant to both Sybil attacks and Tyranny of the Majority attacks.
  > However, unlike its decentralized competitors, the Semada Protocol ensures Sybil Attack and Tyranny of the Majority attack resistance.
  Wulf A. Kaal, Decentralized Mechanical Turk Through Verified Reputation (2018). SSRN: https://ssrn.com/abstract=3128900
- [3128900-019](https://wulfkaal.github.io/claims/3128900-019) [mechanism/asserted] -- The protocol architecture together with its incentive structure is what produces enhanced 51 percent attack resistance, which the author claims exceeds prior reputation verification attempts in both decentralized and centralized networks.
  > The Semada Protocol architecture and its incentive structure facilitates enhanced 51% attack resistance unlike any previous reputation verification attempts in decentralized and centralized networks.
  Wulf A. Kaal, Decentralized Mechanical Turk Through Verified Reputation (2018). SSRN: https://ssrn.com/abstract=3128900
- [3128900-024](https://wulfkaal.github.io/claims/3128900-024) [mechanism/argued] -- Staking creates disincentives for malicious actors, and it is this disincentive structure that makes the network both more efficient and attack resistant.
  > Semada staking mechanism creates disincentives for malicious actors, enhancing the efficiency of the Semada Network and making it attack resistant.
  Wulf A. Kaal, Decentralized Mechanical Turk Through Verified Reputation (2018). SSRN: https://ssrn.com/abstract=3128900
- [3128900-037](https://wulfkaal.github.io/claims/3128900-037) [design/argued] -- Attack resistance should be designed to increase as the platform grows, in contrast to designs like GEMS that detect and ban malicious actors, because a self enforcement mechanism lets the incentive system steer users away from bad actors once the system matures.
  > Unlike GEMS, which bans malicious actors detected through the GEMS trust mechanism from the platform, the Semada platform has a self-enforcement mechanism.
  Wulf A. Kaal, Decentralized Mechanical Turk Through Verified Reputation (2018). SSRN: https://ssrn.com/abstract=3128900
- [3266953-021](https://wulfkaal.github.io/claims/3266953-021) [design/argued] -- Because Semada's Anchor Protocol uses reputation scores as a non fungible currency to qualify for block propagation, the resulting proof of reputation consensus is attack resistant, fully decentralized, scalable, and open to evolutionary protocol upgrades.
  > Unlike traditional PoS, PoR, e.g. Semada's Anchor Protocol, uses reputation scores as a non-fungible currency to qualify for block propagation. As such, the Anchor protocol (PoR) is attack resistant, fully decentralized, scalable and allows evolutionary protocol upgrades.
  Craig Calcaterra, Wulf A. Kaal, Gopinath Sivalingam, Reputation Protocol for the Internet of Trust - Conceptual Whitepaper (2018). SSRN: https://ssrn.com/abstract=3266953

**2019**

- [3406323-002](https://wulfkaal.github.io/claims/3406323-002) [mechanism/argued] -- Because information flow in decentralized systems is optimized through dynamic feedback effects, such systems mutate and change easily, which makes them more attack resistant and allows them to grow very quickly.
  > Decentralized systems can also very easily mutate and change because the information flow is optimized through dynamic feedback effects. As a result, such systems become more attack resistant on multiple levels.
  Wulf A. Kaal, Decentralization - A Primer on the New Economy (2019). SSRN: https://ssrn.com/abstract=3406323
- [3411897-003](https://wulfkaal.github.io/claims/3411897-003) [mechanism/argued] -- Decentralized systems mutate and change easily because their information flow is optimized through dynamic feedback effects, and this capacity to mutate is what makes them more attack resistant on multiple levels.
  > Decentralized systems can also very easily mutate and change because the information flow is optimized through dynamic feedback effects. As a result, such systems become more attack resistant on multiple levels.
  Wulf A. Kaal, Decentralization - Past, Present, and Future (2019). SSRN: https://ssrn.com/abstract=3411897
- [3441904-008](https://wulfkaal.github.io/claims/3441904-008) [mechanism/argued] -- Decentralized systems become more attack resistant and grow quickly because their information flow is optimized through dynamic feedback effects, which lets them mutate and change very easily.
  > Decentralized systems can also very easily mutate and change because the information flow is optimized through dynamic feedback effects. As a result, such systems become more attack resistant on multiple levels.
  Wulf A. Kaal, Blockchain-Based Corporate Governance (2019). SSRN: https://ssrn.com/abstract=3441904
- [3441904-038](https://wulfkaal.github.io/claims/3441904-038) [design/argued] -- Optimized DAO governance should pay members only indirectly, through fungible salary tokens issued in proportion to non fungible merit tokens, because the indirect economic effects remove corruptive elements and make the design more attack resistant and stable in the long run.
  > The indirect economic effects remove corruptive elements and make the governance design more attack resistant and stable in the long run.
  Wulf A. Kaal, Blockchain-Based Corporate Governance (2019). SSRN: https://ssrn.com/abstract=3441904

**2020**

- [3652481-036](https://wulfkaal.github.io/claims/3652481-036) [mechanism/argued] -- Paying DevDAO salaries in fungible stable tokens in proportion to members' non fungible reputation scores makes the economic benefit indirect, which removes corruptive elements and makes the governance design more attack resistant and stable over the long run.
  > The salary payments in fungible stable tokens are in proportion to DevDAO members' respective non-fungible reputation token scores. The indirect economic effects remove corruptive elements and make the governance design more attack resistant and stable in the long run.
  Wulf A. Kaal, Decentralized Autonomous Organizations – Internal Governance and External Legal Design (2020). SSRN: https://ssrn.com/abstract=3652481

**2021**

- [3782191-022](https://wulfkaal.github.io/claims/3782191-022) [failure/argued] *(failure mode)* -- Centralized coordination enables attack coordination because the hierarchical structure allows attackers to identify a single point of failure, whereas the constantly morphing information flow of decentralized systems increases their attack resistance.
  > Centralized coordination enables attack coordination because the hierarchical struc- ture allows the identification of a single point of failure.
  Craig Calcaterra, Wulf A. Kaal, Preface to (2021). SSRN: https://ssrn.com/abstract=3782191
- [3799320-028](https://wulfkaal.github.io/claims/3799320-028) [mechanism/argued] -- Reputation based staking removes the corruptive elements of fungible tokens because third parties are less likely able to take over a non fungible asset such as reputation that is organically grown and maintained through actual expertise in the relevant subject matter.
  > The corruptive elements of fungible assets/tokens are removed because third parties are less likely able to take over a non-fungible asset, such as reputation, that is organically grown and maintained through actual expertise in a given DAO subject matter.
  Wulf A. Kaal, A Decentralized Autonomous Organization (DAO) of DAOs (2021). SSRN: https://ssrn.com/abstract=3799320
- [3799320-031](https://wulfkaal.github.io/claims/3799320-031) [mechanism/argued] -- Paying members indirectly, through a fungible stable salary proportional to non fungible reputation, removes corruptive elements and makes the governance design more attack resistant and more stable over the long run.
  > The indirect economic effects remove corruptive elements and make the governance design more attack-resistant and stable in the long run.
  Wulf A. Kaal, A Decentralized Autonomous Organization (DAO) of DAOs (2021). SSRN: https://ssrn.com/abstract=3799320
- [3799320-033](https://wulfkaal.github.io/claims/3799320-033) [mechanism/argued] -- Member reputation is inflationary by design, so non staking of reputation tokens or non voting leads to value depreciation, which incentivizes action and makes liveness faults less likely.
  > reputation is inflationary in the DAO of DAOs design. As such, non-use, i.e., non-staking of reputation tokens or non-voting, would lead to value depreciation, which incentivizes action and thus value enhancement. Liveness faults become less likely.
  Wulf A. Kaal, A Decentralized Autonomous Organization (DAO) of DAOs (2021). SSRN: https://ssrn.com/abstract=3799320
- [3799320-039](https://wulfkaal.github.io/claims/3799320-039) [mechanism/argued] -- Reputation weighted salary distribution solves the sockpuppet attack, because a member who creates ten accounts holding one reputation token each ends up in the same position as one account holding ten reputation tokens.
  > This solves the sockpuppet attack because if a DAO of DAOs member creates 10 accounts with 1 reputation token each, it is the same as 1 account with 10 reputation tokens.
  Wulf A. Kaal, A Decentralized Autonomous Organization (DAO) of DAOs (2021). SSRN: https://ssrn.com/abstract=3799320

**2022**

- [4067783-014](https://wulfkaal.github.io/claims/4067783-014) [design/argued] -- Defending a DAO against attackers and looters, and punishing self-dealing, requires sustainable decentralized governance built on non-fungible tokens rather than tradable voting power.
  > The takeover of the Build Finance DAO highlights the need for sustainable decentralized governance solutions with non-fungible tokens to defend the DAO from attackers/looters and punish self- dealing.
  Wulf A. Kaal, DAO Fallacies (2022). SSRN: https://ssrn.com/abstract=4067783

**2023**

- [4529715-002](https://wulfkaal.github.io/claims/4529715-002) [definitional/evidenced] -- Each DAO in the dataset was given a score between zero and ten by the analyzing teams on each of six factors: Decentralization, Work to Earn, Attack Resistance, Regulatory Compliance, Governance, and Organizational Communication.
  > The six factors considered are: Decentralization, Work to Earn, Attack Resistance, Regulatory Compliance, Governance, and Organizational Communication. Each DAO was given a score between zero (0) and ten (10) by the analyzing teams
  Wulf A. Kaal, Josh Bykowski, Decentralized Autonomous Organizations (DAO) – A Market Meta Analysis (2023). SSRN: https://ssrn.com/abstract=4529715
- [4529715-006](https://wulfkaal.github.io/claims/4529715-006) [empirical/evidenced] *(failure mode)* -- Attack resistance across the studied DAOs averages 4.05 out of 10, and Charity DAOs perform worst in this category, with the best of them, VitaDAO, scoring 3 out of 10 and the remainder at 2 or less.
  > Based on the compiled data shown in the graph above, the average score for attack resistance is 4.05 out of 10. Charity DAOs showed the worst performance in this category with the highest, VitaDAO, scoring a 3 out of 10 and the rest at 2 or less.
  Wulf A. Kaal, Josh Bykowski, Decentralized Autonomous Organizations (DAO) – A Market Meta Analysis (2023). SSRN: https://ssrn.com/abstract=4529715
- [4529715-028](https://wulfkaal.github.io/claims/4529715-028) [failure/evidenced] *(failure mode)* -- Where a founder retains access to the smart contract behind the governance token, as with 3OH DAO, an internal attack by that founder would be remarkably easy.
  > If a DAO could have negative attack resistance, 3OH would be the DAO. With the founder having access to the smart contract, an internal attack by the founder would be remarkably easy.
  Wulf A. Kaal, Josh Bykowski, Decentralized Autonomous Organizations (DAO) – A Market Meta Analysis (2023). SSRN: https://ssrn.com/abstract=4529715
- [4529715-035](https://wulfkaal.github.io/claims/4529715-035) [failure/evidenced] *(failure mode)* -- Chainlink's white-list response to the 2020 gas fee attack was only a temporary fix: had the attack impacted 50 percent of Chainlink node operators, the price feed would not have updated until enough nodes returned.
  > Temporary solution known as "white-list", but if the attack had impacted 50% of Chainlink node operators, that feed wouldn't have updated until enough came back up and nodes would not be able to feed information.
  Wulf A. Kaal, Josh Bykowski, Decentralized Autonomous Organizations (DAO) – A Market Meta Analysis (2023). SSRN: https://ssrn.com/abstract=4529715
- [4529715-037](https://wulfkaal.github.io/claims/4529715-037) [mechanism/argued] -- A DAO built on reputation rather than a fungible token, as CRDAO is, makes the 51 percent attack nearly impossible and renders sock puppet attacks technically possible but of little influence.
  > CRDAO is fairly attack resistant because of its use of reputation. As a result, sock puppet attacks are technically possible, but would have little influence. CRDAO does not appear to have a fungible token, so the 51 percent attack is nearly impossible.
  Wulf A. Kaal, Josh Bykowski, Decentralized Autonomous Organizations (DAO) – A Market Meta Analysis (2023). SSRN: https://ssrn.com/abstract=4529715

**2024**

- [4685567-021](https://wulfkaal.github.io/claims/4685567-021) [failure/argued] *(failure mode)* -- Retroactive public goods funding via results oracles in DAO format fails at the governance layer: even where the core resource distribution concept works, the project remains exposed to decentralized governance attack vectors because the governance design lacks attack resistance.
  > The key downside of these types of oracles in DAO format are decentralized governance attack vectors. In other wods, even if the core concept of resource distribution works well enough, the overall projet is typically subject to the downsides that derive from lack of attack resistance
  Wulf A. Kaal, Impact Investing Innovation - From Impact 1.0 to 3.0 (2024). SSRN: https://ssrn.com/abstract=4685567
- [4685567-022](https://wulfkaal.github.io/claims/4685567-022) [failure/asserted] *(failure mode)* -- Hypercerts, like other WEB3 optimization attempts for impact certificates, lack the required verification of impact inputs inside decentralized governance settings that are attack proof.
  > Like other optimization attempts, Hypercerts often lack the require verification of impact inputs in decentralized governance settings that are attack proof.
  Wulf A. Kaal, Impact Investing Innovation - From Impact 1.0 to 3.0 (2024). SSRN: https://ssrn.com/abstract=4685567
- [4685567-039](https://wulfkaal.github.io/claims/4685567-039) [definitional/argued] -- Because reputation merit scores are calculated in an immutable and attack resistant manner, they can be aggregated across the many communities an individual belongs to, producing a constantly evolving WEB3 identity score comparable to a credit score.
  > scores are calculated in an immutable and attack-resistant manner. Therefore, the scores can be aggregated for an individual who is a member of many different communities. The aggregated score creates a constantly evolving identity score in WEB3 systems that can be compared with a credit score.
  Wulf A. Kaal, Impact Investing Innovation - From Impact 1.0 to 3.0 (2024). SSRN: https://ssrn.com/abstract=4685567
- [4734750-040](https://wulfkaal.github.io/claims/4734750-040) [mechanism/argued] -- Reputation token staking substitutes for identity verification: because staking makes the network attack resistant, workers can complete micro tasks without verifying identity, which removes the cost, delay, and privacy surrender of centralized approval and enlarges the available labor pool.
  > The CRDAO architecture, and specifically its reputation token staking mechanism, make the CRDAO attack resistant.
  Wulf A. Kaal, Code Review DAO (2024). SSRN: https://ssrn.com/abstract=4734750
- [5254152-013](https://wulfkaal.github.io/claims/5254152-013) [mechanism/argued] *(failure mode)* -- Low attack resistance in DAOs is typically caused by the use of easily purchasable or transferable governance tokens, which leave the organization vulnerable to attacks such as 51 percent and Sybil attacks.
  > Lower scores indicate vulnerability to attacks, often due to the use of easily purchasable or transferable governance tokens.
  Wulf A. Kaal, DAO Market Meta Analysis 2024 (2024). SSRN: https://ssrn.com/abstract=5254152
- [5254152-021](https://wulfkaal.github.io/claims/5254152-021) [empirical/evidenced] -- The average attack resistance score across the sampled DAOs is 3.65 on a scale of 0 to 10, the lowest of the measured attributes alongside regulatory compliance.
  > This graph shows the attack resistance scores of various DAOs, with scores ranging from 0 to 10. The average score is 3.65
  Wulf A. Kaal, DAO Market Meta Analysis 2024 (2024). SSRN: https://ssrn.com/abstract=5254152
- [5254152-030](https://wulfkaal.github.io/claims/5254152-030) [mechanism/evidenced] -- A one person, one vote structure raises a DAO's resistance to 51 percent and sock puppet attacks, as reflected in TomiDAO's attack resistance score of 6 against a sample average of 3.65.
  > The one-person, one-vote model increases resistance to 51% and sock puppet attacks (A: 6).
  Wulf A. Kaal, DAO Market Meta Analysis 2024 (2024). SSRN: https://ssrn.com/abstract=5254152
- [5254152-038](https://wulfkaal.github.io/claims/5254152-038) [failure/evidenced] *(failure mode)* -- Reliance on fungible, publicly tradable governance tokens undermines a protocol's resilience by exposing it to risks such as 51 percent attacks, as scored for Push Protocol.
  > Its resilience is undermined by the fungible, publicly tradable $PUSH tokens, which expose it to risks such as 51% attacks (A: 2).
  Wulf A. Kaal, DAO Market Meta Analysis 2024 (2024). SSRN: https://ssrn.com/abstract=5254152
- [5254152-039](https://wulfkaal.github.io/claims/5254152-039) [design/evidenced] -- A tiered voting system that combines temperature checks with token holder percentage thresholds robustly defends a DAO against common attacks, as reflected in Arbitrum's attack resistance score of 8.
  > The tiered voting system incorporating temperature checks and token holder percentages robustly defends against common DAO attacks
  Wulf A. Kaal, DAO Market Meta Analysis 2024 (2024). SSRN: https://ssrn.com/abstract=5254152

**2026**

- [6192998-009](https://wulfkaal.github.io/claims/6192998-009) [empirical/evidenced] -- Under the 2018 validation pool design, the cost of corrupting the system to reach fifty one percent control is at minimum twice the total reputation value of the system.
  > This is the fundamental security bound: corrupting the system costs at minimum 2× the total reputation value.34
  Wulf A. Kaal, Evolution of Domain-Specific Reputation Systems From Binary Validation to Citation-Weighted Knowledge Attribution (2026). SSRN: https://ssrn.com/abstract=6192998
- [6192998-010](https://wulfkaal.github.io/claims/6192998-010) [failure/argued] *(failure mode)* -- The two times corruption cost bound of the 2018 framework is conditional, not general: subsequent analysis shows it holds only under specific conditions that may not obtain in practice.
  > However, subsequent analysis reveals this bound applies only under specific conditions that may not hold in practice. This is a limitation we address in Section IV.F.
  Wulf A. Kaal, Evolution of Domain-Specific Reputation Systems From Binary Validation to Citation-Weighted Knowledge Attribution (2026). SSRN: https://ssrn.com/abstract=6192998
- [6192998-032](https://wulfkaal.github.io/claims/6192998-032) [mechanism/argued] -- Multi agent competition improves attack resistance because it creates multiple attack surfaces that must all succeed simultaneously, and citation transparency makes collusion detectable; with a fifty percent quality penalty for detected collusion the corruption cost doubles relative to the original framework.
  > This improved security stems from multi-agent competition creating multiple attack surfaces that must all succeed simultaneously, combined with citation transparency enabling collusion detection.
  Wulf A. Kaal, Evolution of Domain-Specific Reputation Systems From Binary Validation to Citation-Weighted Knowledge Attribution (2026). SSRN: https://ssrn.com/abstract=6192998
- [6192998-037](https://wulfkaal.github.io/claims/6192998-037) [predictive/argued] -- Citation weighted systems become more secure over time at a faster rate than binary systems, because time to corruption scales superlinearly with accumulated transaction volume.
  > This extends the security analysis from Calcaterra, Kaal, and Andrei (2018, 15-18) to demonstrate that citation-weighted systems become more secure over time at a faster rate than binary systems.
  Wulf A. Kaal, Evolution of Domain-Specific Reputation Systems From Binary Validation to Citation-Weighted Knowledge Attribution (2026). SSRN: https://ssrn.com/abstract=6192998

## Verify

Every claim above resolves to a record carrying a verbatim source quote, the sha256 of the source PDF, and a preformatted citation. Nothing here asks to be taken on trust.

    curl -s https://wulfkaal.github.io/entities/attack-resistance.md | sha256sum

**Canonical form.** This markdown file is the canonical hashed representation of this entity node. Its sha256 is the content hash.
