{
 "failure_mode": "sybil-and-identity-attack",
 "specific_names": [
  "Anonymity dilution at scale",
  "Anonymity driven attack surface",
  "Anonymity driven opportunism raises transaction costs",
  "Anonymity-enabled attacks",
  "Anonymous trolling friction",
  "Equal salary sockpuppet exploit",
  "Fee and KYC pseudo-defense",
  "Identity verification tradeoff",
  "Inevitable sockpuppet exposure",
  "Sockpuppet attack",
  "Sockpuppet attack on Web of Trust",
  "Sockpuppet attack on web-of-trust vouching",
  "behavioral-mimicry-sybil-amplification",
  "chain-cloning-indistinguishability",
  "identity verification does not deter valuable sockpuppets",
  "identity-whitewashing",
  "majority-conformity-reputation-gaming",
  "missing authentication of machine trust",
  "multi node reward farming",
  "sockpuppet abuse of equal distribution",
  "sockpuppet self dealing in web of trust",
  "sockpuppet-attack",
  "sockpuppets outpace honest validation",
  "sybil attack on centralized reputation"
 ],
 "count": 24,
 "claims": [
  {
   "id": "kaal:claim:3128900-045",
   "url": "https://wulfkaal.github.io/claims/3128900-045",
   "claim": "Centralized platforms cannot simply drop identity verification, because they need it to keep malicious actors from abusing the network and to ensure work quality; this is the tradeoff a staking based design is meant to dissolve.",
   "specific_name": "Identity verification tradeoff",
   "conditions": [
    "centralized micro task platforms"
   ],
   "source": "Decentralized Mechanical Turk Through Verified Reputation",
   "year": "2018",
   "quote": "However, centralized micro task platforms need to verify identity to prevent malicious actors from abusing the network and ensure work quality.",
   "citation": "Wulf A. Kaal, Decentralized Mechanical Turk Through Verified Reputation (2018). SSRN: https://ssrn.com/abstract=3128900"
  },
  {
   "id": "kaal:claim:3227967-033",
   "url": "https://wulfkaal.github.io/claims/3227967-033",
   "claim": "Anonymity in blockchain organizations makes them prone to Sybil attacks and 51 percent attacks, and anonymity combined with autonomy has led to many hacks.",
   "specific_name": "Anonymity driven attack surface",
   "conditions": [
    "anonymous and autonomous blockchain organizations"
   ],
   "source": "Legal Education in a Digital Age Why 'Coding for Lawyers' Matters",
   "year": "2018",
   "quote": "Also, the anonymity in blockchain organizations means that they are prone to \"Sybil attacks\" and \"51% attacks.\" We also discussed the many examples in which the anonymity (and autonomy) have led to hacks.",
   "citation": "Mark Fenwick, Wulf A. Kaal, Erik P.M. Vermeulen, Legal Education in a Digital Age Why 'Coding for Lawyers' Matters (2018). SSRN: https://ssrn.com/abstract=3227967"
  },
  {
   "id": "kaal:claim:3266953-004",
   "url": "https://wulfkaal.github.io/claims/3266953-004",
   "claim": "The trust humans place in machines on the internet has never been verified, because neither centralized nor decentralized authentication engines have typically confirmed that trust or otherwise enabled a trusting environment for internet based transactions.",
   "specific_name": "missing authentication of machine trust",
   "conditions": [
    "human to machine interaction on the internet"
   ],
   "source": "Reputation Protocol for the Internet of Trust - Conceptual Whitepaper",
   "year": "2018",
   "quote": "Yet no centralized or decentralized authentication engine has typically verified the trust humans place in machines or otherwise enabled a trusting environment for internet-based transactions.",
   "citation": "Craig Calcaterra, Wulf A. Kaal, Gopinath Sivalingam, Reputation Protocol for the Internet of Trust - Conceptual Whitepaper (2018). SSRN: https://ssrn.com/abstract=3266953"
  },
  {
   "id": "kaal:claim:3266953-008",
   "url": "https://wulfkaal.github.io/claims/3266953-008",
   "claim": "Every centralized reputation score can be sybil attacked, because fake internet accounts or fictitious ratings disrupt true reputation scoring.",
   "specific_name": "sybil attack on centralized reputation",
   "conditions": [
    "centralized reputation scoring systems"
   ],
   "source": "Reputation Protocol for the Internet of Trust - Conceptual Whitepaper",
   "year": "2018",
   "quote": "All centralized reputation scores can be sybil attacked, e.g. fake internet accounts (sockpuppets) or fictitious ratings disrupt true reputation scoring",
   "citation": "Craig Calcaterra, Wulf A. Kaal, Gopinath Sivalingam, Reputation Protocol for the Internet of Trust - Conceptual Whitepaper (2018). SSRN: https://ssrn.com/abstract=3266953"
  },
  {
   "id": "kaal:claim:3266953-028",
   "url": "https://wulfkaal.github.io/claims/3266953-028",
   "claim": "A Web of Trust reputation system can be gamed with sockpuppet accounts, because an attacker can behave well for a while and then transact with himself repeatedly and rate himself high to raise his reputation arbitrarily.",
   "specific_name": "sockpuppet self dealing in web of trust",
   "conditions": [
    "reputation systems based on counting positive peer rated transactions"
   ],
   "source": "Reputation Protocol for the Internet of Trust - Conceptual Whitepaper",
   "year": "2018",
   "quote": "If I use a lot of sockpuppet accounts, I can raise my reputation arbitrarily high, by behaving well for a while, then making a lot of transactions with myself and rating myself high.",
   "citation": "Craig Calcaterra, Wulf A. Kaal, Gopinath Sivalingam, Reputation Protocol for the Internet of Trust - Conceptual Whitepaper (2018). SSRN: https://ssrn.com/abstract=3266953"
  },
  {
   "id": "kaal:claim:3266953-029",
   "url": "https://wulfkaal.github.io/claims/3266953-029",
   "claim": "Identity verification does not fix the sockpuppet problem, because whenever the reputation is genuinely valuable a sockpuppet operator can afford to clear whatever verification hoops are in place, including stealing biometric data, and then inflate reputation as before.",
   "specific_name": "identity verification does not deter valuable sockpuppets",
   "conditions": [
    "reputation that carries real economic value"
   ],
   "source": "Reputation Protocol for the Internet of Trust - Conceptual Whitepaper",
   "year": "2018",
   "quote": "The problem with this is, if the reputation is genuinely valuable, a sockpuppet account can afford to go through whatever hoops you have in place to create false identities (including stealing biometric data if necessary), then increase their reputation arbitrarily, as described above.",
   "citation": "Craig Calcaterra, Wulf A. Kaal, Gopinath Sivalingam, Reputation Protocol for the Internet of Trust - Conceptual Whitepaper (2018). SSRN: https://ssrn.com/abstract=3266953"
  },
  {
   "id": "kaal:claim:3266953-033",
   "url": "https://wulfkaal.github.io/claims/3266953-033",
   "claim": "Sockpuppet accounts grow their reputation value much faster than honest users can in a Web of Trust, because sockpuppets validate each other, and the system is therefore flawed and should not be used where fungible currency is at stake.",
   "specific_name": "sockpuppets outpace honest validation",
   "conditions": [
    "web of trust style reputation used by many distributed ledger startups"
   ],
   "source": "Reputation Protocol for the Internet of Trust - Conceptual Whitepaper",
   "year": "2018",
   "quote": "However, sockpuppet accounts can grow their value much quicker in the web of trust by validating each other. Honest users are much slower than the sockpuppets validating each other. Hence, the system is flawed.",
   "citation": "Craig Calcaterra, Wulf A. Kaal, Gopinath Sivalingam, Reputation Protocol for the Internet of Trust - Conceptual Whitepaper (2018). SSRN: https://ssrn.com/abstract=3266953"
  },
  {
   "id": "kaal:claim:3125827-040",
   "url": "https://wulfkaal.github.io/claims/3125827-040",
   "claim": "A malicious party using Sybil accounts cannot be prevented from cloning the structure of a successful proof of stake blockchain at far lower cost than cloning a proof of work chain, leaving a new user unable to distinguish the truly decentralized chain from a clone that has manufactured even more tokens. The authors answer that this is resolved off chain, by a trusted user interface, as with cloned web pages.",
   "specific_name": "chain-cloning-indistinguishability",
   "conditions": [
    "new users joining without prior knowledge of the genuine chain",
    "PoS chains where clone creation costs only new public keys"
   ],
   "source": "Secure Proof of Stake Protocol",
   "year": "2018",
   "quote": "Then, when a new user joins the network, how will they be able to distinguish a truly decentralized blockchain from a cloned blockchain that has manufactured an even larger number of tokens?",
   "citation": "Craig Calcaterra, Wulf A. Kaal, Secure Proof of Stake Protocol (2018). SSRN: https://ssrn.com/abstract=3125827"
  },
  {
   "id": "kaal:claim:3227933-020",
   "url": "https://wulfkaal.github.io/claims/3227933-020",
   "claim": "Anonymity in blockchain organizations makes them prone to Sybil attacks and 51 percent attacks, and anonymity combined with autonomy has already produced hacks.",
   "specific_name": "Anonymity-enabled attacks",
   "conditions": [
    "anonymous, permissionless blockchain organizations"
   ],
   "source": "Why 'Blockchain' Will Disrupt Corporate Organizations",
   "year": "2018",
   "quote": "Also, the anonymity in blockchain organizations means that they are prone to \"Sybil attacks\" or \"51% attacks.\"",
   "citation": "Mark Fenwick, Wulf A. Kaal, Erik P.M. Vermeulen, Why 'Blockchain' Will Disrupt Corporate Organizations (2018). SSRN: https://ssrn.com/abstract=3227933"
  },
  {
   "id": "kaal:claim:3782203-035",
   "url": "https://wulfkaal.github.io/claims/3782203-035",
   "claim": "A DAO permitting anonymous membership is exposed to a sockpuppet attack in which one account behaves honestly while another cheats, and if the cheating account can funnel its gains to the honest account without detection or punishment the system is set up for failure.",
   "specific_name": "sockpuppet-attack",
   "conditions": [
    "anonymous DAOs allowing multiple accounts per person"
   ],
   "source": "A Technical Perspective on Decentralization",
   "year": "2021",
   "quote": "One strategy is to have one account which acts honestly and one which cheats. If the cheating account can funnel the gains to the honest account, without detection or punishment, this sets the system up for failure.",
   "citation": "Craig Calcaterra, Wulf A. Kaal, A Technical Perspective on Decentralization (2021). SSRN: https://ssrn.com/abstract=3782203"
  },
  {
   "id": "kaal:claim:3782214-036",
   "url": "https://wulfkaal.github.io/claims/3782214-036",
   "claim": "Equal distribution of output, where every member receives an equal share regardless of contribution, is impossible to maintain under current technology in a system with open access and privacy, because sockpuppet accounts would be abused.",
   "specific_name": "sockpuppet abuse of equal distribution",
   "conditions": [
    "open access membership",
    "privacy or pseudonymity preserved",
    "current identity technology"
   ],
   "source": "Decentralized Governance",
   "year": "2021",
   "quote": "This is impossible to maintain under the current technology with open access and privacy, since sockpuppet accounts would be abused. Improvements in ZK proofs and identity protocols, however, will soon make it possible to efficiently and securely com- bat such sockpuppet attacks.",
   "citation": "Craig Calcaterra, Wulf A. Kaal, Decentralized Governance (2021). SSRN: https://ssrn.com/abstract=3782214"
  },
  {
   "id": "kaal:claim:3931933-016",
   "url": "https://wulfkaal.github.io/claims/3931933-016",
   "claim": "Uptime based reward policies invite Sybil style abuse: on the original Casper testnet single persons ran fifteen or more validator nodes to exploit cloud provider promotions and the DEVxDAO rewards policy, extracting rewards without contributing to the validator group.",
   "specific_name": "multi node reward farming",
   "conditions": [
    "original Casper testnet under a uptime only rewards policy"
   ],
   "source": "Hybrid Secure Proof of Stake",
   "year": "2021",
   "quote": "The original Casper Testnet was also afflicted by cases of single persons running 15+ validator nodes in an effort to abuse the welcome promotions of certain cloud providers and the rewards policy of the DEVxDAO.",
   "citation": "Wulf A. Kaal, Hybrid Secure Proof of Stake (2021). SSRN: https://ssrn.com/abstract=3931933"
  },
  {
   "id": "kaal:claim:3782210-007",
   "url": "https://wulfkaal.github.io/claims/3782210-007",
   "claim": "As a network grows its members become more anonymous and individually less important, which makes cheating more locally enticing and less globally noticeable, so the system eventually collapses once cheating is obviously the best individual strategy.",
   "specific_name": "Anonymity dilution at scale",
   "conditions": [
    "networks that grow large",
    "networks lacking a secure reputation mechanism"
   ],
   "source": "The Importance of Reputation for the Evolution of Decentralization",
   "year": "2021",
   "quote": "As the network grows, however, the members become more anonymous. Individually they become less im- portant, so cheating is more locally enticing and less noticeable globally. Eventually (or immediately) the system will collapse when it becomes obvious cheating is the best individual strategy.",
   "citation": "Craig Calcaterra, Wulf A. Kaal, The Importance of Reputation for the Evolution of Decentralization (2021). SSRN: https://ssrn.com/abstract=3782210"
  },
  {
   "id": "kaal:claim:3782210-008",
   "url": "https://wulfkaal.github.io/claims/3782210-008",
   "claim": "A Web of Trust style reputation ledger, in which each party rates each transaction and reputation is summed with weightings by rater reputation, will have all of its value drained by the sockpuppet attack, because an attacker can build reputation through transactions between their own fake accounts and then use it to cheat.",
   "specific_name": "Sockpuppet attack",
   "conditions": [
    "open networks that permit account creation",
    "self-reported transaction ratings"
   ],
   "source": "The Importance of Reputation for the Evolution of Decentralization",
   "year": "2021",
   "quote": "Unfortunately, the sockpuppet attack will suck all value from the network. Setting up fake accounts, an attacker can build their reputation by making transactions be- tween their own accounts. Once their reputation is sufficiently large to trick a mem- ber, they can use it to cheat the system.",
   "citation": "Craig Calcaterra, Wulf A. Kaal, The Importance of Reputation for the Evolution of Decentralization (2021). SSRN: https://ssrn.com/abstract=3782210"
  },
  {
   "id": "kaal:claim:3782210-009",
   "url": "https://wulfkaal.github.io/claims/3782210-009",
   "claim": "Charging transaction fees or imposing KYC identity protocols does not solve the sockpuppet problem: such defenses push the cost of defending the network onto users, and the defense cost equals what it is worth to break the defense while being multiplied across every transaction with every member.",
   "specific_name": "Fee and KYC pseudo-defense",
   "conditions": [
    "defenses that tax ordinary transactions",
    "attacker gain from faked reputation exceeds the cost of faking it"
   ],
   "source": "The Importance of Reputation for the Evolution of Decentralization",
   "year": "2021",
   "quote": "This doesn't help. Such defenses push the cost of defending the network onto the users. The cost to defend it is exactly as much as it is worth to break the defense, except it's multiplied on every transaction with every member in the system.",
   "citation": "Craig Calcaterra, Wulf A. Kaal, The Importance of Reputation for the Evolution of Decentralization (2021). SSRN: https://ssrn.com/abstract=3782210"
  },
  {
   "id": "kaal:claim:3782210-018",
   "url": "https://wulfkaal.github.io/claims/3782210-018",
   "claim": "Distributing salary equitably, for example equally to all members, is self-defeating: the obvious gaming strategy becomes creating multiple accounts and distributing one's work between them, which is why the salary must be reputation-weighted.",
   "specific_name": "Equal salary sockpuppet exploit",
   "conditions": [
    "open membership systems where accounts are cheap to create"
   ],
   "source": "The Importance of Reputation for the Evolution of Decentralization",
   "year": "2021",
   "quote": "If salary is distributed more equitably, say equally to all members, then the obvious strategy for gaming the system is to create multiple accounts and distribute your work between the accounts.",
   "citation": "Craig Calcaterra, Wulf A. Kaal, The Importance of Reputation for the Evolution of Decentralization (2021). SSRN: https://ssrn.com/abstract=3782210"
  },
  {
   "id": "kaal:claim:3782210-025",
   "url": "https://wulfkaal.github.io/claims/3782210-025",
   "claim": "Sockpuppet attacks are inevitable in any organization that wants open membership and anonymous members, and since those properties are essential to the autonomy that makes a global decentralized organization efficient, reputation must be weighted every time it is used.",
   "specific_name": "Inevitable sockpuppet exposure",
   "conditions": [
    "open membership",
    "anonymous or pseudonymous members"
   ],
   "source": "The Importance of Reputation for the Evolution of Decentralization",
   "year": "2021",
   "quote": "Sockpuppet attacks are inevitable if you want the membership to be open and to allow anonymous members. These properties are essential for fostering the individual autonomy that makes a global decentralized organization efficient and powerful.",
   "citation": "Craig Calcaterra, Wulf A. Kaal, The Importance of Reputation for the Evolution of Decentralization (2021). SSRN: https://ssrn.com/abstract=3782210"
  },
  {
   "id": "kaal:claim:3782210-026",
   "url": "https://wulfkaal.github.io/claims/3782210-026",
   "claim": "Every single reputational implementation the authors have audited in the blockchain DAO space carries the flaw of vulnerability to the sockpuppet attack on the Web of Trust model.",
   "specific_name": "Sockpuppet attack on Web of Trust",
   "conditions": [
    "blockchain DAO reputation systems audited by the authors as of writing"
   ],
   "source": "The Importance of Reputation for the Evolution of Decentralization",
   "year": "2021",
   "quote": "This is the flaw in every single reputational implementation we've audited in the blockchain DAO",
   "citation": "Craig Calcaterra, Wulf A. Kaal, The Importance of Reputation for the Evolution of Decentralization (2021). SSRN: https://ssrn.com/abstract=3782210"
  },
  {
   "id": "kaal:claim:4067783-024",
   "url": "https://wulfkaal.github.io/claims/4067783-024",
   "claim": "Anonymous decentralized networks can encourage troll behavior because participants feel safe attacking others without retribution, and in a DAO that trolling destabilizes the organization and creates friction between members and the DAO.",
   "specific_name": "Anonymous trolling friction",
   "conditions": [
    "anonymous participation without reputational stake"
   ],
   "source": "DAO Fallacies",
   "year": "2022",
   "quote": "In the DAO context, trolling behavior destabilizes the organization and causes friction between members and the DAO.",
   "citation": "Wulf A. Kaal, DAO Fallacies (2022). SSRN: https://ssrn.com/abstract=4067783"
  },
  {
   "id": "kaal:claim:4067783-035",
   "url": "https://wulfkaal.github.io/claims/4067783-035",
   "claim": "Proof of personhood projects such as Proof of Humanity and UBI DAO fail because they rest on web-of-trust theory, which has been proven not to work long-term given the sockpuppet attacks that are inevitable in that design.",
   "specific_name": "Sockpuppet attack on web-of-trust vouching",
   "conditions": [
    "identity systems built on web-of-trust vouching"
   ],
   "source": "DAO Fallacies",
   "year": "2022",
   "quote": "Of course, these attempts are all falling victim to web-of-trust theory that has been proven to not work long-term because the sockpuppet attacks that are inevitable in this design.",
   "citation": "Wulf A. Kaal, DAO Fallacies (2022). SSRN: https://ssrn.com/abstract=4067783"
  },
  {
   "id": "kaal:claim:4529715-032",
   "url": "https://wulfkaal.github.io/claims/4529715-032",
   "claim": "A reputation system that rewards voting with the majority, as Bridge Mutual uses, can be manipulated by users who create multiple wallets and always vote with the majority.",
   "specific_name": "majority-conformity-reputation-gaming",
   "conditions": [
    "reputation derived solely from voting outcomes"
   ],
   "source": "Decentralized Autonomous Organizations (DAO) – A Market Meta Analysis",
   "year": "2023",
   "quote": "reliance solely on voting outcomes may present some vulnerability, as it could potentially be manipulated by users creating multiple wallets and voting with the majority.",
   "citation": "Wulf A. Kaal, Josh Bykowski, Decentralized Autonomous Organizations (DAO) – A Market Meta Analysis (2023). SSRN: https://ssrn.com/abstract=4529715"
  },
  {
   "id": "kaal:claim:5225296-028",
   "url": "https://wulfkaal.github.io/claims/5225296-028",
   "claim": "Sybil attack risk is amplified in reputation-driven systems relative to stake-based ones, because influence derives from behavioral metrics that an attacker can mimic across many pseudonymous identities.",
   "specific_name": "behavioral-mimicry-sybil-amplification",
   "conditions": [
    "reputation-driven consensus systems where influence stems from behavioral metrics"
   ],
   "source": "Cryptographic Foundations and Interdisciplinary Dimensions of the Secure Proof of Stake (SPoS) Conse",
   "year": "2025",
   "quote": "In reputation-driven systems, this threat is amplified as influence stems from behavioral metrics rather than stake, enabling attackers to mimic legitimate activity across numerous identities",
   "citation": "Wulf A. Kaal, Cryptographic Foundations and Interdisciplinary Dimensions of the Secure Proof of Stake (SPoS) Conse (2025). SSRN: https://ssrn.com/abstract=5225296"
  },
  {
   "id": "kaal:claim:5554218-022",
   "url": "https://wulfkaal.github.io/claims/5554218-022",
   "claim": "Automating smart contracts under the code is law paradigm incentivizes unethical behavior by enabling anonymous, opportunistic action, which reduces repeat business and undermines the minimization of transaction costs.",
   "specific_name": "Anonymity driven opportunism raises transaction costs",
   "conditions": [
    "anonymous or pseudonymous counterparties",
    "automated execution with no external legal recourse"
   ],
   "source": "Universal Digital Law Codex (UDLC) Building the Legal Infrastructure for the Digital Era",
   "year": "2025",
   "quote": "The automation of smart contracts under \"code is law\" incentivizes unethical behavior by enabling anonymous, opportunistic actions, reducing repeat business and undermining transaction cost minimization.",
   "citation": "Furrer Andreas, Wulf A. Kaal, Universal Digital Law Codex (UDLC) Building the Legal Infrastructure for the Digital Era (2025). SSRN: https://ssrn.com/abstract=5554218"
  },
  {
   "id": "kaal:claim:6192998-001",
   "url": "https://wulfkaal.github.io/claims/6192998-001",
   "claim": "Reputation systems that depend on persistent identity collapse in decentralized settings because agents can create new identities at no cost, so a poorly performing agent abandons its account and starts fresh, a practice known as whitewashing.",
   "specific_name": "identity-whitewashing",
   "conditions": [
    "decentralized or pseudonymous environments where identity creation is costless"
   ],
   "source": "Evolution of Domain-Specific Reputation Systems From Binary Validation to Citation-Weighted Knowledge Attribution",
   "year": "2026",
   "quote": "First, the identity problem: Reputation systems built on persistent identity5 collapse when agents can costlessly create new identities. A poorly-performing agent simply abandons their account and starts fresh, a phenomenon known as whitewashing.6",
   "citation": "Wulf A. Kaal, Evolution of Domain-Specific Reputation Systems From Binary Validation to Citation-Weighted Knowledge Attribution (2026). SSRN: https://ssrn.com/abstract=6192998"
  }
 ]
}