EVALUABLE WEB-PAPER · RELEASE 1 · JULY 2026 · EXPLORATIONECONOMY.ORG/PAPER

Minting Money from Verified Human Engagement: Design and Pre-Registered Adversarial Testing of an Exploration-Driven Economic Network

Devan Allen (design owner) — devan@ai-realized.com · built and, to date, checked only with AI systems (Anthropic Claude); provenance and trust model in §00. Reference design codenamed EDEN; unit codenamed EVE — working titles.

Abstract. Most new money is created as bank credit; its benefits distribute unevenly, and the human contributions now feeding AI systems are largely uncompensated. We design and stress-test an alternative monetary layer in which currency is minted solely by verified humans' engaged attention to real digital work; machine and institutional actors participate only as payers and can never mint. Income streams are non-transferable, transparency is rewarded rather than mandated, and a guaranteed-essentials floor is specified as a separately funded module after stress tests showed it does not self-fund — a negative result we retain. Methods: 39 waves of agent-based simulation with pass/fail bars registered before each run, machine-checked algebra for load-bearing closed forms, and a replication harness whose most recent independent run (out-of-family AI reviewer, July 31, 2026) reproduced 72 of 82 discovered programs within tolerance. Three registered failures forced three published redesigns. Results are claimed strictly as mechanism-existence under stated dials, never as forecasts. All revenue-side results are conditional on exogenous willingness-to-pay anchors; a field experiment with failure defined in advance is registered but not yet run. This document exists to be evaluated claim-by-claim: every claim carries a status, an evidence path, and the assumptions it leans on.
§ 00

How to read this — trust model, provenance, statuses

Trust model. Every result here is mechanism-existence under stated dials: "this rule closes this specific failure mode under these assumptions" — never a forecast, never a guarantee. Pass/fail bars were registered in writing before each engine ran. Dials and sweep ranges are enumerated in the replication kit's ASSUMPTIONS LEDGER.

Provenance, stated plainly. Every artifact behind this paper — simulations, proofs, verification passes, and this text — was produced by the owner working with AI models, and until July 2026 only models from that same family had checked it. On July 31, 2026 the work received its first outside check: an out-of-family AI reviewer (5.6 Sol), given only this site and the public replication kit, independently re-ran the full harness — 72 of 82 discovered programs reproduced within tolerance, none verdict-reversing under its classification — and published a critical review, hosted unedited with our response on the independent reviews page. That is machine replication and machine criticism, not human review. The program's own standard remains verify, don't trust, and its two standing obligations are what this document exists to invite: hostile human review and field evidence.

Reading paths. Full read ≈ 60–90 min. The 15-minute skeptic's path: this section → §10 Failure log → §11 Demotions → §12 Open items. The failures are not in an appendix; they are the spine.

Status vocabulary (every claim carries exactly one):

TESTED — PASS TESTED — FAIL → REPAIRED DEMOTED TESTED — FAIL (STANDS) OPEN ASSUMPTION (EXOGENOUS)

Every claim card is anchor-linkable (cite /paper#C-10, not a paragraph) and ends in a kit path so any number can be traced to the results file and code that produced it in two clicks. TODO markers are unmined CLAIMS-REGISTER keys — present in the kit, not yet wired into this draft.

§ 01

The problem & design goals

Nearly all new money enters the world as bank credit — created when banks lend, extinguished as loans repay. That system supports productive credit, but it can distribute new purchasing power unevenly and amplify asset cycles, and whether its gains reach people whose main asset is their time is a distributional outcome, not a design guarantee. What is not in question: human creative output — the writing, data, and code that now train AI systems — is priced at zero and harvested as free raw material. None of this requires a villain, and none of it is hidden. It is a design. This paper specifies a complement — not a replacement — and reports how it has been tested.

Goals. (1) Give every verified person an income-bearing asset: their data, creations, and genuine attention. (2) Make machine and institutional use of human work a payment event, permanently. (3) Reward transparency so honesty out-competes opacity on economics rather than enforcement. (4) Keep wealth earnable but not inheritable or purchasable, so mobility replaces dynasty. (5) Remain optional at every step.

Non-goals, stated as hard boundaries. Not a replacement for the dollar — promises are denominated in goods; dollars remain the pricing language at the interface. Not a token sale: there is nothing to buy, and the unit cannot be purchased into existence. Not a new internet: an overlay changing four layers of the one we have — monetization (creators paid natively when work is used), discovery (neutral retrieval, disclosed ranking), identity (one portable, self-owned identity), provenance (signed, checkable origin) — while transport, hosting, browsers, devices, jobs, and dollars stay where they are. And not a promise of a safety-net floor (§09).

§ 02

The mechanism: Rule 0, minting, decay ladder, custody & pricing

Rule 0: humans mint; machines pay. New currency is created in exactly one circumstance — a verified human genuinely engaging with real work — and the mint event pays the work's creators automatically. Machine and institutional actors can hold and transfer existing units but can never occupy the minting position; the prohibition is enforceable in code, which is why "never" is used here and almost nowhere else. The money supply is anchored to verified human time and attention — an anchor whose robustness against live adversaries (identity, H-2) is the program's single load-bearing open question.

Digital work is free at the door. Creators are paid per use rather than charging tolls. Payouts follow a decay ladder — heavily-used work earns broad-and-shallow — with two ratified companions: per-buyer cumulative pricing (one buyer's aggregate pull gets more expensive, not cheaper, so bulk extraction never rides the popularity discount) and the minimum ask (a non-waivable, essentials-indexed floor on personal-data prices; above it, owners price freely; launch value stays at canon's conservative 1e-4 with the calibration method ratified and the number pilot-gated).

Custody is freshness-matched (DR-20). Declared commons stay freely copyable (K0). Short-half-life data — live market and behavioral streams, below τ* ≈ 4.35 years — may leave under priced export licenses, because staleness itself is the moat (K1). Long-half-life data, the stores actually worth stealing, never leaves: compute-to-data access with per-buyer cumulative egress budgets (K2). Individual-granularity-sensitive data is aggregate-only (K3).

C-20TESTED — FAIL → REPAIRED

Under pre-repair terms, a pay-once-copy-forever extraction captured long-lived data value for ≈1.6% of its worth. The freshness-matched custody system plus per-buyer cumulative pricing closes it.

SCOPE exfiltration & stale-copy economics; repair ratified as DR-20
EVIDENCE EVE Sim v37 (XF0–XF8; XF7a = registered safe-to-refute expectation confirmed) · results key: TODO: CLAIMS-REGISTER
LEANS ON freshness half-life measurement (τ* boundary) · v27-class breach enforcement · KYC'd bridge legal layer for off-ledger residual
why the repair is custody-plus-pricing, not custody alone
The floor prices the living stream, custody prices the stolen copy, and freshness picks which one binds. Below τ*, a copy goes stale before it amortizes — export licensing is safe and staleness is the moat. Above τ*, a stale copy is barely stale — so the corpus never leaves (K2). The decay-ladder interaction is fixed separately: bulk buyers ride their own rising curve, not the anti-concentration discount meant for creator fairness (v37 F1).
C-21TESTED — PASS

The non-waivable minimum ask is load-bearing: without it, the clearing price collapses to ≈5% of the revenue-optimal reserve under supply abundance, and ≈90% of sellers would undersell it if allowed.

SCOPE mechanism-existence; the collective-bargaining rhyme of objection A2
EVIDENCE EVE Sim v37 (floor-necessity finding) · results key: TODO: CLAIMS-REGISTER
LEANS ON WTP anchors (H-1) for absolute levels; the necessity result is about relative collapse, not the anchor
§ 03

Machines & institutions: pay-never-mint, coordinator-never-owner, owner linkage

Every non-human actor — a lab training a model, a company, a personal AI assistant reading someone's work on a user's behalf — participates as a payer. Capability growth therefore translates into payment flow toward the humans it learned from. Corporations coordinate; they never own the mint-anchor (DR-18): a firm can organize, fund, and profit from collective work through a capped coordination cut (ceiling 25%) for a bounded term (30 years), with income streams anchored to the human contributors. The transparency principle is privacy for people, transparency for power: individual reading and browsing stay private (read-logging was measured and declined); value flows are public.

C-22TESTED — PASS

Owner linkage in strong form takes beneficial-ownership evasion from 24.7× (blind gate) to 1.20× at central dials: entities must carry human-rooted links to hold income streams; links are title records; closure is transitive through any shell depth; backed by a slashable link-bond plus provenance audit.

SCOPE mechanism-existence at central dials; boundary located at a_n* = 0.172/yr
EVIDENCE EVE Sim v36 (OL0–OL6) + mix-frontier extension; chassis v35 re-run exact · results key: TODO: CLAIMS-REGISTER
LEANS ON identity keystone (H-2) · audit funding floor a_n ≥ 0.05/yr with bond B ≈ 1.0 · disclosure-aversion pilot dial (d_med)
each leg is load-bearing · what was declined · the participation price
Remove a leg and the number tells you: no link-to-coordinate → 9.5×; no title semantics → 4.3–14.1×; no transitive closure → 24.7×; no audit/overhead leg → 2.55×. Declined on measurement: entity read-logging — only 4.5% of entity query value attributable at central evasion costs; paid queries are already public machine-pay transactions, so no protocol surface is spent metering free reads. The cost is priced, not hidden: disclosure trims relative participation ~6pp (0.657 → 0.597), above its registered bar; if the pilot measures worse aversion, the funding mix shifts by pre-scoped fallback.
C-24TESTED — PASS

Ownership resolves through real capital structures: ultimate beneficial holders at ≥ 5% pass through any number of layers with registered links; sub-threshold float terminates at bonded, KYC'd intermediaries; officer/controller links are title-class — closing the on-ledger empire channel at zero marginal audit cost.

SCOPE multi-root/diamond ownership graphs; the named successor to C-22, discharged
EVIDENCE EVE Sim v38 (MR0–MR7, 8/8; registered expectations confirmed) · results key: TODO: CLAIMS-REGISTER
LEANS ON θ = 5% pilot-calibrated against real holder distributions · empire/concert flag compresses off-protocol residual 16.1× → 3.6×, handed to the KYC'd bridge's legal layer
scope boundary, recorded
Coordination among genuinely distinct humans multiplies nothing the ownership gate polices (they already hold their lawful caps), and chasing it would require person-level behavioral profiling barred constitutionally — concert harms belong to the governance/market-power layer, by design.
§ 04

People & property: non-transferability and the dynasty result

Each person holds one lifetime identity (the keystone assumption — H-2). Income streams are non-transferable: they cannot be sold, bought, or inherited. Success and wealth remain fully achievable — they must simply be continuously earned, because no one can purchase another's money-making machine or bequeath their own.

C-30TESTED — PASS

Five-generation dynasty persistence — the share of top-decile families still top-decile five generations later — falls from 79.2% (purchase-channel calibration of today's economy) to 10.4% under non-transferability, approximately the fair-deck rate at which birth luck stops predicting outcomes.

SCOPE mechanism-existence; 125-year model; corporate-wrapper attack included and closed in ratified canon
EVIDENCE EVE Sim v3 (Multi-Generational Wealth; purchase-channel anchors 10.4 / 67.7 / 79.2 — the artifact labels the level "illustrative; the ordering is the finding") + v35 · distinct measures kept distinct: the original multigen engine reports unspliced persistence 98%→11% and top-decile royalty capture 79%→17% · results key: TODO: CLAIMS-REGISTER
LEANS ON identity keystone (H-2) · wrapper closure (C-31) · cap/W_age machinery (v3 Network & Dependency Graph)
the middle anchor
The 67.7% middle scenario is the half-measure: streams non-inheritable but purchasable. Purchasability alone recovers most of the dynasty effect — which is why "earned, never bought or inherited" is one invariant, not two.
C-31TESTED — FAIL → REPAIRED

The corporate wrapper ("immortality loophole") initially evaded the inheritance rule — blind evasion 24.7× — and one wrapper test failed as registered, filed as a defense-in-depth finding. Closed by DR-18/19; the dynasty result holds ≤ 10.5% under every variant, including the no-audit stress arm.

SCOPE the strongest attack on §04's headline result, run before the headline was trusted
EVIDENCE EVE Sim v35 (CW0–CW8; CW4 FAIL on the record) · results key: TODO: CLAIMS-REGISTER
LEANS ON owner linkage (C-22) and look-through (C-24) as the closure mechanism
§ 05

Stability: the thermostat, the essentials index, and what's still soft

Minting anchored to human attention is a faucet that never closes by itself. The first full simulation proved exactly that — and the repair is a formula, not a committee. This section carries four claims; two of them are failures we keep.

C-10TESTED — FAIL → REPAIRED

The constitutional minting throttle ("the thermostat") stabilizes the modeled price index inside the registered storm envelope across fifteen simulated years — a claim about the throttle, not about price stability in the world: index governance and oracle integrity (C-12, C-13) remain unresolved.

SCOPE mechanism-existence under stated dials; storm envelope per ASSUMPTIONS LEDGER
EVIDENCE Crash №1 ("The Bathtub") → thermostat retest · results key: TODO: CLAIMS-REGISTER · kit: TODO: path
LEANS ON essentials-index integrity (C-12, C-13) · storm-envelope dials · no discretionary authority exists to lobby
method · registered bar · what would change our mind
Registered bar (before any run): if the poorest simulated decile cannot afford essentials for three consecutive months, the design fails. Original failure: prices climbed ~10%/yr; the bottom decile went under by month 16 and never recovered. Corrective action: a formula in the constitution slows minting whenever money outruns real goods — a thermostat, not a chairman. Retest: the modeled index held within the registered envelope through fifteen simulated years of storms. What would change our mind: a storm profile inside the ledger's envelope that re-breaks the bar; or demonstration that the throttle's inputs (C-13) can be gamed faster than re-validation catches.
INTERACTIVE — DEMONSTRATION, NOT A TEST (TOY PARAMETERS; THE REGISTERED TESTS ARE THE EVIDENCE LINE ABOVE)

[Interactive demonstration omitted in print — explorationeconomy.org/demos/thermostat]

C-12TESTED — FAIL (STANDS)

The essentials index's fixed 0.05 bias budget is insufficient against systematic composition drift; a ≤ ~2.5-year re-basing rule is required (canon candidate, not yet ratified).

SCOPE index-governance stress test (Lucas/Goodhart family, objection A3)
EVIDENCE EVE Sim v33 (Index Drift) · results key: TODO: CLAIMS-REGISTER
LEANS ON basket composition governance (EBI Methodology Spec)
why this stays a failure on the books
The repair (periodic re-basing) is specified but not ratified — so the claim stands as a failure until the rule enters canon and passes retest. This is also the finding that moved objection A3 (index-number bias) from unanswered to partial in the red-team scorecard (§12).
C-13TESTED — FAIL (STANDS)

Under the bribed-price-gauge attack, oracle re-validation speed missed its registered bar: 0.888 vs 0.90.

SCOPE adversarial oracle capture; the thermostat's input integrity
EVIDENCE oracle re-validation wave · results key: TODO: CLAIMS-REGISTER
LEANS ON re-validation cadence dials
status note
Published as a miss, at the same prominence as the passes. A near-miss on a registered bar is a finding, not a rounding choice — the bar existed before the run.
§ 06

Incentives: the ramp

Support that tops everyone up to the same line makes marginal effort worthless below it. The second registered failure proved it, and the repair is a taper whose no-cliff property is machine-checked, not asserted.

C-50TESTED — FAIL → REPAIRED

Under top-up support, half of lower earners rationally quit and output fell ~25%. Under the ramp — every unit earned adds half a unit above the guarantee, at every income — the simulated economy retained essentially all output.

SCOPE incentive-compatibility of the floor's delivery mechanics (module design; the floor itself is §09)
EVIDENCE Crash №2 ("The Cliff") → ramp retest · results key: TODO: CLAIMS-REGISTER
LEANS ON machine-checked taper no-cliff closed form (§13) — marginal return to effort is strictly positive at every income
why this is a proof-plus-simulation claim
The no-cliff property is exact-rational algebra (sympy-checked): there is no income at which earning one more unit fails to raise take-home. The simulation result (output retention) is the behavioral consequence under the model's labor-supply dials — attack the dials, not the algebra.
INTERACTIVE — DEMONSTRATION, NOT A TEST (TOY PARAMETERS; THE REGISTERED TESTS ARE THE EVIDENCE LINE ABOVE)

[Interactive demonstration omitted in print — explorationeconomy.org/demos/the-ramp]

§ 07

Integrity: the three locks and the identity keystone

The most dangerous adversary isn't lazy. The third registered failure came from an adversarial audit that modeled smart thieves — and the repair is three interlocking economic locks rather than surveillance, because surveillance was tested on its own terms and lost.

C-51TESTED — FAIL → REPAIRED

Optimized fraud rings initially earned 6× the floor per fake identity (projected capture ≈ one-third of new issuance). Against all three locks — similarity-split payouts, slashable stakes at scale, lifetime-identity scarcity — the heist was unprofitable in every tested configuration.

SCOPE adaptive-adversary fraud economics; conditional on the identity keystone
EVIDENCE Crash №3 ("The Heist") audit → three-lock retest · results key: TODO: CLAIMS-REGISTER
LEANS ON H-2 (one-person-one-identity holds against live adversaries) — inherited explicitly, stated in §12
the three locks, mechanically
(1) Near-identical content shares one shrinking payout — copy-farms divide rewards instead of multiplying them. (2) Earning at scale requires a posted stake, forfeited on detection — accountability priced in, not policed after. (3) A lifetime identity is too valuable to rent out, because renting it risks losing it — the ring's one "free" input becomes its largest cost.
C-52TESTED — FAIL (ROAD REJECTED)

The surveillance alternative was measured and rejected: ambient per-identity watching delivered zero security improvement at 187× the honest-participation cost.

SCOPE road-not-taken, kept on the books — why integrity here is economic, not observational
EVIDENCE EVE Sim v8.1 · results key: TODO: CLAIMS-REGISTER
INTERACTIVE — DEMONSTRATION, NOT A TEST (TOY PARAMETERS; THE REGISTERED TESTS ARE THE EVIDENCE LINE ABOVE)

[Interactive demonstration omitted in print — explorationeconomy.org/demos/three-locks]

§ 08

Governance: formulas, sortition, two houses, the conduct-claim class

Rules change by formula and jury, not by executive. Disputes and parameter changes route through sortition juries of verified persons; structural change requires two-house concurrence — one-person-one-vote alongside a contribution-weighted house with hard caps. An early cap leaked 9.4% of influence as first written; fixed, and disclosed as a failure (card C-46, §11). All governance actions, like all value flows, are public.

C-54TESTED — PASS

The conduct-claim class (DR-22) separates truth from flooding at launch bonds (B, β) = (2.0, 0.5): expected value +0.070 per true claim, −1.600 per false one — telling the truth pays, lying costs, and the two things the market can't fix are named on the label: fear at small anonymity sets, and off-protocol short-and-distort (bounded only by adjudication speed).

SCOPE a market for evidence-backed conduct claims about any entity; staged, governance-gated rollout
EVIDENCE EVE Sim v39 (both registered safe-to-refute expectations refuted in the robust direction) · results key: TODO: CLAIMS-REGISTER
LEANS ON account-silence as a constitutional-class invariant (the platform cannot confirm whose account disclosed — architecture, not policy) · adjudication speed as a funded target (T_adj = 0.5 yr) · jury adjudication with "unverifiable" as an honest third verdict
the two things it can't fix, named on the label
Short-and-distort profit is bounded by the pre-verdict window (speed is the only protocol lever; the residual hands off to securities law via the bridge pattern), and off-protocol books are invisible by construction. Certified capture ships as armor, not a launch gate — the market separates even on uncertified evidence. Comms guardrail honored here: this is not called the best whistleblowing tool.
§ 09

The floor: a funded module, not a promise

The project set out to guarantee everyone's essentials. Stress-testing returned the program's largest honest negative, and the design bends to it rather than around it: the floor is published as a fully-specified, separately-funded module — reserve mechanics visible on-ledger, activation by formula, staged delivery tied to funding — that any community, government, or coalition can adopt and run in public. A progress bar, not a pledge.

C-55TESTED — FAIL (STANDS)

The floor does not self-fund as a protocol property: every activation scenario required real outside funding. Its failure mode is honest rationing, never money-printing — the floor cannot mint.

SCOPE the reason the floor is a module, not a promise; the never-prints property is code-enforced
EVIDENCE floor stress waves; the ecology-model boundary (C-43) marks where one funding route died · results key: TODO: CLAIMS-REGISTER
LEANS ON nothing — this is the claim the rest of §09 leans on
why publish a failure this central
Because the alternative — promising a floor the tests say doesn't self-fund — is how projects like this usually die, slowly and dishonestly. The tested blueprint (reserve, activation formula, ramp delivery, exit design) is real and adoptable; what it needs is a funder, and the design says so out loud.
C-56TESTED — PASS

Sponsor exit strands no one: in the simulated walk-away, no participant ended worse off than if the floor had never existed. Delivery cost: see C-44 (~26% headline, ~9% mid-storm — both numbers travel together).

SCOPE module exit design; delivery-cost cross-reference to §11
EVIDENCE sponsor-exit wave · results key: TODO: CLAIMS-REGISTER
LEANS ON staged-delivery mechanics; ramp incentive-compatibility (C-50)
§ 10

Failure log — the three registered crashes

Failure was defined before any test ran: if the poorest tenth can't afford essentials for three consecutive months, the design fails. Months were then spent trying to cause exactly that. It worked, three times. Full plain-language history: /evidence.

FAILURE REPORT 01 — "THE BATHTUB"RETEST: PASS → C-10
OBSERVED
Prices +~10%/yr; bottom decile underwater by month 16 of the first full simulation, no recovery.
ROOT CAUSE
Minting that never slows, draining into a nearly closed drain.
CORRECTIVE ACTION
The thermostat: a constitutional formula slows minting when money outruns real goods; no discretionary authority.
RETEST
Modeled index stable inside the registered storm envelope across fifteen simulated years (claim C-10; index governance C-12/C-13 still open).
FAILURE REPORT 02 — "THE CLIFF"RETEST: PASS → §06
OBSERVED
Half of lower earners rationally stopped working; output fell ~25%.
ROOT CAUSE
Top-up-to-a-line support made marginal effort worthless below the line.
CORRECTIVE ACTION
The ramp: every unit earned adds half a unit above the guarantee, at every income (machine-checked no-cliff property).
RETEST
Simulated economy retained essentially all output.
FAILURE REPORT 03 — "THE HEIST"RETEST: PASS → §07
OBSERVED
Optimized fraud rings earned 6× the floor per fake identity; projected capture ≈ one-third of new issuance.
ROOT CAUSE
Fraud tests had modeled lazy thieves; the adversarial audit modeled smart ones.
CORRECTIVE ACTION
Three locks: near-identical content shares one shrinking payout; earning at scale requires a slashable stake; a lifetime identity is too valuable to rent.
RETEST
Heist unprofitable in every tested configuration — conditional on the identity keystone (open item H-2, §12).
§ 11

Demotions & corrections — published at the same prominence

The program's verification passes re-run everything and re-score downward where re-runs disagree. The current record is the post-correction one; earlier circulating numbers are superseded by the cards below.

C-40DEMOTED

The federation storm headline survives in only 47% of a ±50% joint-dial sweep — now conditional on a proposed sponsor-contract term (recommended threshold ≥ 0.60).

EVIDENCE EVE Sim v16 (joint sensitivity / Lucas-critique instrument) + v31 · TODO: key
NOTE peacetime, governance, and committee results survived the same shaking — this one didn't, and was demoted for it
C-41TESTED — FAIL (STANDS)

The basket rate-cap fails as registered: food/shelter capture $21.6M vs the $20M bar; defenses-off capture ≈12,400×.

EVIDENCE v17 re-execution (VERIFICATION v4) · TODO: key
C-42TESTED — FAIL (STANDS)

Influence catch-up misses its 10-year bar (0.78 vs 0.80); the bar is met at ≈12 years.

EVIDENCE v22 re-execution (VERIFICATION v4) · TODO: key
C-43RESOLVED-NEGATIVE

The ecology model is structurally unfundable at registered dials; a rebuild is owed, and no ecological claims are made until it exists.

EVIDENCE v13.1, regression-gated · TODO: key
C-44TESTED — PASS (WITH COMPRESSION)

Floor delivery modeled ~26% cheaper than traditional welfare administration in the headline scenario — compressing to ~9% for a mid-storm backstop. Both numbers travel together.

EVIDENCE floor delivery waves + VERIFICATION v4 compression note · TODO: key
C-45TESTED — PASS

Two July 31, 2026 runs anchor reproducibility. Canonical owner-machine run (macOS arm64, Python 3.9.6/NumPy 2.0.2): 73 of 82 discovered programs reproduce within tolerance; 6 mismatches, all in the known benign classes; 3 helper scripts with no registered output; all restores verified. Independent out-of-family run (5.6 Sol, NumPy 2.3.5): 72 of 82 — the one extra mismatch reproduces cleanly on the older NumPy, confirming version drift and motivating the shipped requirements floors. Clean-room disclosure: 69 of 82 recompute fully from scratch; the four checkpointed long engines exit rather than recompute without their checkpoints — a from-scratch path is owed and tracked (S13). The release manifest now ships per-engine statuses.

EVIDENCE verify_all.py (replication kit) — run it yourself; python ≥ 3.10
C-46TESTED — FAIL → REPAIRED

An early governance cap leaked 9.4% of influence as first written; fixed, and disclosed as a failure.

EVIDENCE governance cap wave · TODO: key
§ 12

Open items — what simulation cannot settle

Stage 0 — deployment & identification strategy (EdenQuest). The program's first live artifact is deliberately non-monetary: EdenQuest, a free, local-first personal-data app with non-transferable in-app points under a ratified no-conversion rule, live in public form (product-surface details are audited in the independent reviewer's app assessment, hosted on the reviews page). It activates none of the layers this paper analyzes — no EVE, no data commons, no lifetime economic identity — and its role in the research design is identification: it is the registered instrument for the behavioral dials every simulation treats as exogenous (genuine-vs-gamed contribution, wash behavior under rewards, liveness drop-off, motivation crowding-out) and the recruitment substrate for the willingness-to-pay experiment (H-1). The ratified bridge specification (gates G1–G5) separates it from every monetary layer; entry into any future data commons is a separate, default-off, revocable decision. Its adoption is evidence about product value and data-production behavior only — never about EVE demand.

H-1ASSUMPTION (EXOGENOUS)OPEN — EXPERIMENT DESIGNED

Willingness-to-pay anchors: data ≈ $600/contributor-yr · commons code $300–1,800/yr · consumer machine-pay ≈ $240/agent-yr. Every revenue-side result leans on these; they are exogenous in every simulation. This is the hinge.

REGISTERED BARS FAIL < $120/contributor-yr (20% of anchor — published as failure, sims re-run at the measured number) · PASS-weak $120–600 · PASS-anchor ≥ $600 in signed contracts across ≥3 independent buyers with ≥1 renewal
INSTRUMENTS stated-preference screening (never counted as a pass) → incentive-compatible BDM auctions with real budgets → signed contracts
EVIDENCE WTP Experiment Design (registered July 9, 2026) — design published; not yet run
the sharpest version of the attack, stated by us
The friendliest literature (data-as-labor) contains it: individual marginal data value ≈ 0. If that's right, the fail bar triggers and we say so. Improving this experiment's design — or showing it cannot work — is the single most valuable contribution an outside economist can make.
H-2OPEN — PILOT DESIGNED

Does one-person-one-identity hold against live adversaries? Only a contained pilot can answer; the simulated defenses (§07) explicitly inherit this assumption.

NOTE ambient per-identity surveillance was tested and rejected on its own terms (zero security at 187× honest cost) — the defense is architectural, not observational
O-1OPEN — UNSOLVED

World-scale consent: implied cross-region transfers (~25% of regional mint) exceed measured political tolerance (~6%). The design's own fiscal-federalism problem, measured and unsolved.

EVIDENCE world-scale consent wave · TODO: key
O-2SCORECARD

The economics red-team: ten strongest published objections (Lucas, Hayek, Goodhart, incidence, index bias, crisis models, OCA, unit-of-account inertia, data-valuation gap, Baumol) argued at full strength and self-graded — 4 answered at strength, 6 partial, none unanswered.

NOTE A3 (index-number bias) upgraded from unanswered to partial after the v33 index-drift work — the same work that keeps C-12 on the books as a failure. Grading this grading is a fast route to findings.
§ 13

Methods & replication

Bars before code. Every engine's pass/fail bars were fixed in writing before the engine was coded; failures were published as failures, and three forced full public redesigns. The lineage runs v1–v39 with lettered sub-waves (and two distinct v13 engines — Oracle and Ecology — noted to prevent citation confusion). Verification passes v2–v6 re-executed the record and re-scored downward where re-runs disagreed; §11 carries the results.

Reproducibility is verified, not asserted. verify_all.py (python ≥ 3.10; numpy, scipy, matplotlib, sympy) re-runs every discovered engine and prints a per-engine ledger; the canonical July 31, 2026 owner-machine run reproduces 73 of 82 within tolerance and the independent out-of-family run 72 of 82 (C-45), every exception classified; dated ledgers and a LATEST.json pointer ship in the kit. Every headline traces from the CLAIMS REGISTER to a committed results file to the code that produced it. The reviewer guide ships a two-day hostile plan: day one, read (this paper, then the red-team scorecard, then the ledgers); day two, re-run and attack. Different numbers on your hardware is a finding we want filed.

C-60TESTED — PASS

The load-bearing algebra is machine-checked (exact-rational / sympy): taper no-cliff, committee hypergeometrics to the last digit, cap-function properties, closed forms vs Monte Carlo — 10/10 with grade labels.

SCOPE proof artifacts, graded honestly: one of the ten (P8) is a self-consistency check rather than an independent re-derivation, and is labeled as such
EVIDENCE Proofs — Machine-Checked Theory Claims (replication kit) · TODO: path

What "in-family" means, and why it's on every page. All artifacts were produced by the owner working with AI models (Anthropic Claude; per-artifact attribution recorded as uncertain after a mid-session model switch — the provenance note travels with the index). In-family verification can catch arithmetic and internal inconsistency; it cannot substitute for hostile, out-of-family review or field evidence. Those are the program's two standing obligations, and this document is the instrument for the first.

§ 14

For evaluators — what to attack first

Attack the assumptions, not the arithmetic — the arithmetic reproduces mechanically (C-45), and different numbers on your hardware is a finding we want. The six standing questions per artifact: does it trust an input it doesn't control; static vs adaptive adversary; any "by construction" tells; off-protocol flanks; correlated failures; does transparency break it.

Highest-value targets, in our own estimation: the WTP anchors (H-1 — improve the experiment or show it can't work); the incidence chain (who ultimately pays for machine participation); essentials-index composition governance (C-12); the austerity-threshold contract framing (C-40); and grading the red-team's self-grades (O-2).

Filing findings: against named artifacts (file + JSON key) wherever possible — they can be verified in minutes. Findings are published with named credit; a finding that forces a canon change is the product working, not an insult. Engagement terms for commissioned review (fixed fee, published verbatim whatever it concludes) available on request: devan@ai-realized.com.

§ 15

Citation & changelog

Cite: Allen, D. (2026). Minting Money from Verified Human Engagement: Design and Pre-Registered Adversarial Testing of an Exploration-Driven Economic Network. Release 1, paper v2.0 (web). explorationeconomy.org/paper — cite claim anchors (e.g., /paper#C-10) rather than page sections. DOI: TODO — Zenodo snapshot per release.

Changelog: v0.2 (July 24, 2026) — all sixteen sections assembled; 24 claim cards live (C-10…C-60, H-1/H-2, O-1/O-2); all three demonstrations embedded; CLAIMS-REGISTER keys still unmined (TODO markers). v0.1 (July 24, 2026) — first assembled draft; nine sections stubbed. Underlying text: Design Paper v2.0, ratified July 24, 2026 (owner, provisional), including the five ratification corrections (custody K-classes; DR-18 ceiling; DR-21 look-through; DR-22 conduct-claim class; red-team 4/6/0).