Browse every study
Each study below opens a full report — plain-language write-up, technical results, figures, and the raw data.
Core monetary model (v1–v4)
Robustness, governance & the ADAM layer (v3 battery)
The World Model (v5)
The Open-Economy era (v6)
Adversarial & substrate waves (v8–v39)
The Horizon Model (v7)
The full index & headline findings
The single map of every model in this folder: what it asks, what it found, and where it lives. All models share one pre-registered failure criterion, agreed before each run: the 10th-percentile participant's income must never fall below an essentials basket for 3+ consecutive months in any plausible scenario. Numbers below are pulled from each run's results*.json. The canonical spec these feed is 01 Canon/EVE Algorithm v1.1 - Tested Spec Addendum; the public write-up is White Paper/EDEN White Paper v1.0.
The arc in three lines
- v1 (bare concept) fails under pessimistic assumptions — survival depended on monetary parameters no one controls.
- v2 (generic patches) — governor + floor + effort-weight — passes, but the floor needed printed money.
- v3 (the actual Algorithm v1.0) passes everything on harder assumptions, with the floor self-funded at the reference calibration. Everything after v3 stress-tests it along a new axis.
- v4 (July 2026) closes the behavioral↔funding loop: one essentials definition, three floor designs — self-funding holds to essentials ≈ 0.5× median income, and the taper replaces the v1.2 top-up's 100% marginal-tax cliff.
Core monetary model
| Model | Question | Headline finding | Folder |
|---|---|---|---|
| EVE Sim v1 | Does the bare concept hold? | No. Bottom decile underwater from ~month 16 under finite data demand; the one-way governor is the cheapest fix. Criterion established. | EVE Sim v1 |
| EVE Sim v2 | Do generic patches fix it? | Yes, but the floor needed printed money (0–3.9% of issuance); the governor must be a mint-rate rule. | EVE Sim v2 |
| EVE Sim v3 | Does the actual Algorithm v1.0 hold on harder assumptions? | Passes all 10 scenario × demand combos; ~0% inflation; floor self-funded at the reference essentials calibration (0% top-up, ≤2.2% of issuance — see Sim v4 for the boundary: holds to essentials ≈ 0.5× median income); creator real income +26% (baseline) to +55% (automation), −9 to −11% under commoditization. Bare design: 9.6%/yr inflation, creator real income 0.54×. (Dated v3-era report: the ~0%-inflation and self-funding headlines were later retired — index governance remains open; the floor is now a separately funded module.) | EVE Sim v3 |
| EVE Sim v4 — Integrated Behavioral Funding (July 2026) | Do behavior and funding survive each other, under ONE essentials definition? | The program's two floor stories become one cost curve. Self-funding boundary: essentials ≈ 0.5× median income (10% pool); ~0.2% of issuance at v3's ratio, ~40% at HANK's. The v1.2 unconditional top-up is a 100% marginal-tax cliff costing 22–28pp of output at high ratios; an EITC-style taper delivers the same guarantee at ~half the output loss and lower cost → recommended for spec v1.3. | EVE Sim v4 - Integrated Behavioral Funding |
| EVE Sim v4b — Spending & Ancestral Dividends (July 2026, spec v1.3) | Do the two ratified funding streams move the self-funding boundary? | The Ancestral Dividend is the lever: at a mature Legacy share (~8% of mint → floor) the boundary moves 0.60 → 0.75× median income and top-up need at e=0.75 falls 7.4%→0%. The spending-data dividend trims ~1pp and never moves the boundary — keep it, don't lean on it. | EVE Sim v4 - Integrated Behavioral Funding (v4b files) |
| Multigen — Purchase Channel (July 2026, spec v1.3) | Does non-transferability actually close the heir-purchase dynasty channel? | Yes, decisively: EDEN v1.3 persistence 10.4% ≈ full mobility; the un-preventable mortal-contracts leak is harmless (10.2%); if catalogs were buyable, persistence rebounds to 67.7% (vs today's 79%). One rule carries ~57 points of the anti-dynasty claim. | ... - Multi-Generational Wealth (purchase-channel files) |
| Hardened Arms Race (July 2026, spec v1.3 — supersedes Endogenous Detection) | Does the fraud arms race ignite at the HONEST prize against the hardened design? | No — in zero of twelve cells with similarity decay ON (prize shrunk 5.78F → ~1F), even at weak liveness, zero bond, and myopic renters. Decay OFF ignites only the myopic-renter corner; a 3–9F bond closes it. The lifetime identity's own value (~120F) makes rational rental self-deterring. Calculator-grade, parameters stated. | EVE Sim v4 - Hardened Arms Race |
| EVE Sim v5.0 — World Model (July 2026, pre-registered) | Does EDEN hold as a WORLD system — 40 real-data-calibrated regions, global pool, local floors? | 5 of 6 registered bars met; 1 failed honestly. The poor-region wave (hardest test) passed clean — zero breaches, zero printing — because time-equal minting makes joiners instant contributors; staggered world launch needs only 0–4.5% subsidy (vs 13–16% single-population). Global pool beats isolated pools (zero printing vs 1.3–1.4% under −60% local shocks); world fraud 0.69% < 2% cap. Q2 FAILED as registered: rich-region net contributions ~25% of regional mint vs the 6% political-economy bar — at world scale the binding constraint is consent, not solvency → v5.1 (endogenous essentials re-pricing, contribution caps, cross-region content markets). | EVE Sim v5 - World Model |
| EVE Sim v5.1 — Convergence & Physical Economy (July 2026, pre-registered) | With the physical economy honestly included (~70% of income, unrouted) and essentials convergence unfrozen, do the consent and solvency bars pass? | B3 PASSED (the guarantee never broke anywhere); B1/B2/B4 FAILED at every convergence speed. Structural finding: the floor is sized against the whole cost of living but funded only by the digital slice (~5.4% of total flow) — convergence cut transfers ~60% in 15 yrs but cannot close a mismatched denominator. Registered floor ramp found unworkable by construction (a ramped floor sits below essentials). Design table for v5.2: route physical commerce (1–3%), bet on digital-share growth (EDEN's own thesis — untested), transitional top-up (price-stable in-model), consent machinery. White-paper world-scale claims must carry this until resolved. | EVE Sim v5 - World Model (v5.1 files) |
| EVE Sim v5.2 — Slices & Leakage (July 2026, pre-registered) | Does the settlement slice + jurisdiction slice + off-ledger leakage stack fund the world floor without printing? | Steady state works in every config: zero top-up, slice sunsets to ~2%, guarantee unbroken (C2/C4 PASS; C3 PASS at central — but j=25% under pessimistic elasticity sends 51% of physical commerce off-ledger, so jurisdictions should live ≤15–20%). C1 FAILED on the letter (transient slice peak 4.9–6.0% > the 4% cap during the convergence decade) → ratification choice: accept the transient, or cap at 4% + launch-treasury bridge. C5 mixed and partly our own bar mis-specification (15% slice vs 20% VAT comparator); the fair equal-rate question goes to v5.3/pilot. Settlement slice remains PROPOSED pending Devan's choice. | EVE Sim v5 - World Model (v5.2 files) |
| EVE Sim v5.4 — Consent & Convergence (July 7, 2026, pre-registered; executes ratified A.2) | Does the capped-tranche + convergence design deliver a converging poor-region floor — and is the "insurance you might claim" framing factually true? | The ratified road works on its own terms: K1 PASS — poorest-region floor strength sustained ≥ 0.90 from year 13.7, 1.00 at yr 15, zero printing, inside the 6% cap; membership individually rational (K3: staying beats leaving in 100% of rich region-years at conservative anchors; median value/contribution 1.6×); federation fallback survivable but visibly thin (K4: 0.10 → 0.43 local-only). Both roads not taken are measured catastrophes for their supposed beneficiaries (K5a print-the-gap: delivery 0.148 by yr 15; K5b discovered forced pool: 84–144 consecutive months of broken floor — the humble road is 3× higher at the moment of betrayal and never cliffs). K2 FAILED, informative: only ~50% of regions experience both sides of the pool in 60 yrs (bar: ≥67%) → claim surgery: "mutual insurance among contributors, plus a capped, declining accession tranche." The failure humbles the language, not the design. | EVE Sim v5.4 - Consent & Convergence |
| EVE Sim v5.3 — Staged Floor Activation (July 2026, pre-registered; Devan's proposal) | Launch floorless, bank the routing into a Floor Reserve, activate by solvency trigger + dependence override — does it work? | The staged architecture survives: activation by formula at 2.5–4.4 years (before any government joins — gov becomes accelerant, not gate); moral gap tiny (peak 2.1% dependent pre-activation, bar 5%); floorless coin recoverable at 30% speculative share (crash floor 0.66). Headline: the dependence OVERRIDE binds, not the solvency trigger — successful creators cross 50%-EVE-dependence before the reserve is ready; base/fast adoption still activate with zero printing (D1 PASS), slow adoption FAILS D1/D5 (bridge-funded activation). Metric critique flagged for re-registration: override counts prosperous creators as 'dependent' — vulnerable-dependence (EVE-dependent AND income < 2F) is the better trigger. Consequence: no day-1 floor subsidy, no $190M floor line-item, C1 ladder deferred to activation era. v5.3b (re-registered vulnerable-dependence override): ALL bars pass in ALL scenarios — solvency-led activation at 5.5–5.8y, zero printing everywhere, reserves ≥23.6mo — ratification-ready. | EVE Sim v5 - World Model (v5.3 files) |
Robustness & comparison
| Model | Question | Headline finding | Folder |
|---|---|---|---|
| Data-Demand Sweep | Is the floor's self-funding sensitive to the (unknowable) data-demand level? | Self-funding holds across launch levels 1–25% of mint and post-launch collapses (top-up never triggers; floor cost crosses 5% only at ~95% collapse) — noting the launch-level insensitivity is partly an artifact of the endogenous essentials peg (the level cancels by construction), while the collapse robustness is structural (the pool rides the attention mint). Real lever: the verification-pool share (breaks below ~6%). At 100k the no-floor breaking depth is ~30% (not 20%, a 25k artifact). See Sim v4 for where self-funding breaks as essentials rise. | ... - Data Demand Sweep |
| Adoption & Creator Stabilizer | What happens during the thin launch decade? | The floor is not self-funded at launch — needs an external subsidy of ~13–16% of issuance, tapering to zero in ~2.4–3.5 years at N=100k (the 1.25-yr fast case was a 25k artifact). Reserve corrected (July 2026 — unit bug): an honestly-sized 18-month reserve fully protects creators only to ~−50%; at −70% it cushions (min 0.92×, end 0.99× vs 0.85×/0.93× without), cumulative release ~95 slice-months; full −70% protection needs ~120. | ... - Adoption & Creator Stabilizer |
| Today Comparison | How does today's economy do in the same harness? | Today's bottom decile starts below essentials (~0.55× market wages; ~0.85× with a leaky net) and has no structural floor — but note the harness's constructed asymmetries (EDEN's basket endogenous, today's external; the net modeled pro-cyclically; Social Security absent), and at parity-start today's dynamics mostly PASS. The MD's own framing is the honest one: the decisive difference is the floor and the starting distribution, not the engine. | ... - Today Comparison |
| Adversarial / Mechanism-Design | Can it be gamed? | Corrected July 2026 (honest fake-share axis + OPTIMIZING attackers). The floor itself never breaks — p10 ≥ 1.17 and zero top-up even at 50% fake identities with zero detection — but optimizing wash-mint rings (5.78× floor per identity, the model's own bound) reach 35.7% of issuance at saturation and crush honest creators to 0.76×. Fraud < 2% of minting requires detection of 79–98% against optimizers (10–50% fake share), vs 0–87% against naive floor-claimers. Graceful for the poor; demanding on identity/liveness — the v1.2 liveness gate has to earn those rates. | ... - Adversarial Stress Test |
| Stock-Flow Consistency | Does the money accounting balance? | The spec's transaction matrix closes to machine precision (residual ~10⁻¹⁶) — a by-construction consistency demo of the spec as re-transcribed (hand-entered double-sided flows), worthwhile but not an audit of the ABM's own ledger. Every EVE traces to a mint and every disappearance to a burn in the restatement. | ... - Stock-Flow Consistency |
| Heterogeneous-Agent (HANK-core) | Does the floor help, in economists' own framework? | Corrected July 2026 (calibration + budget balance): with realistic income risk (σ_z≈0.88, was 0.30) and the floor funded by a proportional tax, poverty 40.2% → 0%; consumption Gini 0.258 → 0.116; precautionary savings −73%; CEV +7.9% overall, +22.7% poorest third — net of a ~40% tax at this generosity (essentials = 0.8× mean). The insurance value survives honest funding; the 40% cost is real and sits on v4's one cost curve with the ABM's ~2%. | ... - Heterogeneous-Agent (HANK) Comparison |
| Behavioral Response | If people optimize, does the floor make everyone stop working? | At a 1.10× floor, ~37% choose floor-income but hold only 11% of output — and (added July 2026) gross floor cost is 19.3% of output at this model's essentials ratio (~0.7× median), a number the original write-up omitted. The behavioral↔funding loop is now actually closed by Sim v4, which finds a self-funding boundary at essentials ≈ 0.5× median and motivates the taper design. Effort-weighting attenuates addictive farming (3× → 1.2× active), it does not kill it. | ... - Behavioral Response |
| Reflexivity & Runs | Can a confidence shock death-spiral it (the Terra critique)? | The crash floor scales with the real-demand share: at 30% speculative, the shock that zeroes a Terra-like design gives EDEN a ~26% dip with recovery. Correction (July 2026): recovery is share-dependent — it holds up to ~70% speculative share; at 90%+ the ~90% drawdown does not recover in-window (eden_recovers_at_all_shares: false), and "never zero" is a property of the assumed price-insensitive real-demand bid. Keeping machine-pay/floor demand dominant is a design requirement, not a given. |
... - Reflexivity & Runs |
| Oracle (EBI) Manipulation | Can the price oracle be gamed (it sets the floor and machine-pay)? | The trimmed median's breakdown is ~50% of sources, so security reduces to source authenticity; under realistic price dispersion a 25–40% source minority already distorts the index +9–21% (= inflation in the floor and all data prices). The "+355% to break self-funding" figure is a linear upper bound (floor cost is convex in F; the true threshold is lower). Staking/slashing on sources + a bounded move-rate are the defenses that bite — not trimming. SURVIVES WITH CHANGES. | ... - Oracle (EBI) Manipulation |
| Multi-Generational Wealth | Over 125 yrs, does EDEN prevent dynastic concentration or does it re-emerge via inherited cash/position? | Directionally robust r-vs-g demonstration: compounding regimes lock in gen-0 dynasties (No-Legacy 91%, Today 98% persistence) while EDEN's non-compounding inheritance dissolves them (→ ~11%, Gini 0.69→0.57). Honesty notes (July 2026): the anti-dynasty mechanism is the assumed scalar R=0 (no dependency graph is modeled); the 54%-persistence run surfaced a real spec ambiguity that v1.2 then closed (orphaned dependency shares → floor) — "counterfactual" is fair under the closed spec, but the rule postdates the run; several regime scalars favor EDEN unmodeled (cash decay, bequest friction); and heirs buying live assets is an open, unmodeled dynastic channel with no prohibiting canon rule. | ... - Multi-Generational Wealth |
| Network & Dependency Graph | Does "pay the stack" cause runaway concentration or fragility on a realistic graph? | On a scale-free graph, dependency royalties concentrate hard (royalty Gini 0.93 vs 0.55 own-mint; oldest 10% of assets capture ~80% of the pool). Bounded by W_age on the dependency stream + a per-node cap (top-10% capture 87%→79%→67%). Fragility is topological (top asset underlies ~29% of mint) but the Legacy mechanic prevents economic cascade → availability concern met by commons-custody. SURVIVES WITH CHANGES. |
... - Network & Dependency Graph |
Governance
| Model | Question | Headline finding | Folder |
|---|---|---|---|
| Governance Capture | Can governance be captured? | The two-house design makes capture an and-requirement (wealth ≠ votes; sybils ≠ weight) — sound algebra, with one load-bearing caveat: the "20–200× the population" forgery bar assumes full honest turnout; at 20% turnout it is ~4×, at 5% ~1×. Turnout (and the delegation/quorum machinery of Governance v2) is what the headline actually rests on. Detection is assumed volume-independent. | ... - Governance Capture |
| Governance v2 (Federated + Gov ID) | Does the federated/delegated/gov-ID design help? | Subsidiarity removes the single global lever; delegation cuts an attacker's vote share 40% → 10.5% at low turnout; the quorum gap is the genuine self-found result (a 10% faction overrides at 5% turnout without a quorum; ~45% required with one). Caveats: the "200–400× population" figure is arithmetic on assumed detection rates (99–99.5%) — labels, not models; and global forgery needs governments covering 2/3 of population (21 of ~50 jurisdictions), not "2/3 of governments." | ... - Governance v2 (Federated + Gov ID) |
| Governance Cascade Dynamics | Does the override cascade oscillate? | The only-larger-overrides ratchet converges by construction (a bounded monotone ladder cannot oscillate) — the honest comparison is 9 → 1 flips vs the naive rule (110 is the no-timelock strawman). The "45% stay local at 2/3" dial numbers are readouts of an assumed uniform support distribution — illustrative, not empirical. | ... - Governance Cascade Dynamics |
The ADAM layer
Integrating ADAM (the asset-management layer) does not change the core results — ADAM never mints, and the SFC check still closes to ~10⁻¹⁶ with ADAM flows added. It mostly makes several assumptions above realistic (an efficient data market, a maintained dependency graph, achievable detection). It opens two genuinely new axes, both modeled here:
| Model | Question | Headline finding | Folder |
|---|---|---|---|
| Discovery & Attention | Does ADAM become an attention gatekeeper? | If most users run diverse lenses, attention is diverse — the 39% (diverse) vs 94% (single-feed) top-10% capture numbers are direct consequences of the chosen concentration exponents (1.0 vs 3.0, uncalibrated) and a uniform-niche population, so treat the shape as the finding and the numbers as illustrative. User-sovereign, swappable lenses are the lever; default-stickiness and adversarial lenses are the (unmodeled) residual risks. | ... - Discovery & Attention |
| Endogenous Detection | Is fraud detection an ADAM-vs-ADAM arms race? | A pedagogical contest model, not evidence: at the assumed prize (4% of issuance — imported from the pre-correction adversarial run), assumed defense budget, and assumed evasion cost, no evasion is profitable and fraud ≈ 0 — with ignition one grid-step above the operating point. The structural lesson stands (keep the fraud prize small and detection cost-advantaged); superseded (July 2026) by EVE Sim v4 - Hardened Arms Race, which re-runs the contest at the honest 35.7% prize against the spec v1.3 defenses — and finds it does not ignite. |
... - Endogenous Detection (ADAM arms race) |
What the program establishes overall
Read together, the models make a single, layered claim — restated honestly after the July 2026 cross-examination and fixes. EDEN's monetary core is stress-tested (v1–v3), robust to its most uncertain assumption within the modeled regime (data demand — with the caveat that launch-level insensitivity is partly the essentials peg's construction), honestly subsidized at launch (~13–16% of issuance for ~2.4–3.5 years at 100k scale), accounting-consistent as specified (SFC, a by-construction demo), and welfare-improving in the standard framework net of honest funding (HANK, corrected: +7.9% CEV overall and +22.7% for the poorest third after the ~40% tax its generous essentials ratio implies). The floor's affordability and its welfare power are now one curve, not two claims (v4): self-funding holds while essentials ≤ ~0.5× median network income, and the recommended taper design preserves the guarantee while removing the top-up cliff (22–28pp of output at high ratios). Under strategic attack the story is two-sided: the poor stay protected under every attack modeled (the floor never broke, even at 50% fake identities with zero detection), but optimizing adversaries reach ~36% of issuance and crush honest creators unless identity/liveness detection reaches ~80–98% — so fraud economics degrade gracefully for the vulnerable and demandingly for the system, and the v1.2 liveness gate is load-bearing. A confidence run is bounded and recoverable while real (machine-pay/floor) demand dominates the holder base — at ≥90% speculative share it is not. Governance results are design arguments with honest dependencies: the two-house and-requirement is sound algebra whose strength rests on turnout and the quorum/delegation machinery; the gov-ID forgery multiples are assumed detection rates, not measurements. Every favorable result is matched by an identified failure mode, and every correction from the July 2026 verification is applied in the folders above (originals archived as *_PRE-FIX_archive.*).
Limits that apply across the program
Quantity-theory price formation (constant velocity) — now relaxed and tested in EVE Sim v3 - Velocity & Confidence Shock, which finds the floor robust to a moving velocity, and hoarding/confidence runs manageable by the D5 stack conditional on demand-side levers removing ≥~55% of hoarding pressure (mitig_coef ≥ 8 — a hand-set behavioral dial, swept July 2026, now a pilot question); D5 + its passing bar were post-hoc after the pre-registered STRICT bar failed (01 Canon/EVE — Velocity Defense); no behavioral feedback; no fraud in the core runs (handled separately in the adversarial model); fixed population; single 15-year horizon. Scale: most agent-population models were re-run at N=100,000 — with the honest note that two headlines moved at scale (adoption fast-taper 1.25 → 2.4 yr; no-floor data-collapse breaking depth 20% → 30%) and are corrected in the rows above; 7 of the 8 re-runs have no committed artifacts (00 Scale Confirmation (100k)), so treat unverifiable 100k numbers as reported-not-reproducible until the harness is committed. July 2026: a committed 1M-agent check (EVE Sim v3/scale_check_1M.py / results_scale_1M.json) confirms the core model's headline numbers to the 2nd–3rd decimal at 10× scale — raw agent count is settled; what world scale actually demands is heterogeneity, specified in EVE Sim v5 - World Model (SPEC).md (pre-registered before construction). Identity-detection quality, data-demand level, government-population shares, turnout, and delegation rates are calibrated parameters, not estimates. Every model is an existence-and-robustness demonstration under stated assumptions — not a forecast. The remaining risks (proof-of-unique-personhood at scale, oracle integrity against real adversaries, fraud in the wild, adoption, regulation) are pilot questions no simulation can retire — though the oracle's statistical and economic failure modes are now modeled (... - Oracle (EBI) Manipulation); only the live, prize-funded red-team remains a pilot job.
What's next
Registered and awaiting build: v5.2 — Settlement Slice, Jurisdiction Slice & Leakage (EVE Sim v5 - World Model/v5.2 SPEC, bars C1–C5 fixed July 2, 2026). The prior major build was Sim v5 — the World Model (EVE Sim v5 - World Model (SPEC).md, pre-registered July 2026: 40 real-data-calibrated regions, global pool vs local floors, poor-region wave, diversification hypothesis, fraud migration). See MODELING ROADMAP - what else to test.md for the older prioritized list (HANK with the full New-Keynesian block, a network/dependency-graph concentration model, a controlled human experiment, and the pilot). The simulation program has done its job; the next evidence is empirical.
The v6 program — the Open Economy era (July 4, 2026)
Following the external review (REVIEW PANEL - EDEN Model Evaluation (July 2026), vault root), the program left the closed-loop world: v6 embeds EDEN in a host fiat economy — real-dollar essentials, fiat jobs, an endogenous EVE/USD exchange rate, elastic demand anchored to real market sizes, printing that devalues. Eight registered runs, regression-chained (each engine reproduces its predecessor exactly with new features off), seeds 7+11, one public mid-program correction (v6.2 hoarding — a pre-BMM metric artifact), and — new program convention — a plain-language companion file ships with every run. All in EVE Sim v6 - Open Economy (Fiat Interface)/.
| Run | Question | Headline (and its defeater) |
|---|---|---|
| v6.0 Open Economy | What is EVE worth when demand is real? | Incomes anchor to external demand (~$27/mo median at today's data ARPU); slice-funded floors need ~$52–56k/person-yr (self-funding retired); recession → 67–87% FX drawdown undefended; staged activation prevents print spirals. 4/7 bars. |
| v6.1 Velocity Defense | Does §7.8 port to an open economy? | Recession crash 84%→36–52%; canon 12-mo reserve validated for single storms — but the compound storm exhausts it and inverts (worse than nothing). 3/8. |
| v6.2 Crisis-Grade | Fix the compound storm | Mature-sized reserve + laddered locks end exhaustion; redemption window fixes grocery-line fill to 1.000; price-vs-income welfare inversion established (bars rewritten on income). 3/8 registered, lesson adopted. |
| v6.3 Use-Value | Does human data use count? (owner q.) | Shadow income at $3/purposeful-hr lifts p10 effective affordability +15.7% (clears the bar cash misses), storm-proof; obligations −7–13%. Public correction of v6.2 issued. 4/7. |
| v6.4 Governments | Who funds the floor? | Sponsored floor real (p10 ≥1.36, 12 yrs), zero printing, 26% cheaper than traditional delivery; sponsor inflow = strongest currency stabilizer tested; slice = rebate (~8%), not revenue; taper output claim scale-conditioned. 4/6. |
| v6.5 Builders | Devs/scientists, not just content? (owner q.) | 86% builder viability at mid software-capture (median $392/mo); maintainers paid; growth endogenous (2.46× at constant anchors; freeze kills it); jobs 17% of enrolled; floor gap −⅓. 5/7. |
| v6.6 Consumer agents | Can the median member earn more? | Progressive (+$130/mo bottom decile), 2.5× recycling — and the honest ceiling: passive membership ~$50–70/mo. Three-tier income language adopted. 3/4. |
| v6.7 Sponsor Stress | What if the government isn't a saint? | Austerity absorbed; delays defeat the 2.4-mo buffer (→ escrow term); exit strands no one (p10 returns to never-sponsored path) but crashes the currency −92% (→ diversification gate, multi-sponsor federation). 3/5. |
Consolidation: 03 White Paper/EDEN White Paper v1.6 - DRAFT (Open Economy Consolidation).md (awaiting owner ratification). Plain-language umbrella: LAYMAN REPORT v3 - Understanding the Simulations (July 2026, Open Economy).md. The v6 engines supersede closed-loop results wherever they conflict; the closed models remain canon for structure-only questions (dependency graph, governance algebra, arms-race mechanics).
v7.0 — the Horizon Model (July 4, 2026)
EVE Sim v7 - World Adoption (Horizon Model)/ — the owner's hundred-year question: world adoption, the transparent physical-goods economy, the generational floor, and growth at the frontier. The program's most speculative model and it says so (no geopolitics/climate/war; world adoption assumed; population scenarios deferred to v7.1 — disclosed, not dropped). Registered bars J0–J8; 4/8 pass; seeds 7+11 agree.
| Question | Headline (and its defeater) |
|---|---|
| Can the generations fund humanity's floor? | PASS — crossover year 65: Ancestral Dividend (~40% of funding) + slices cover 100% of world floor obligations, zero printing thereafter — conditional on maintenance: halve building at year 50 and the crossover never arrives (J7). |
| Does transparency remake physical goods? | Tips to 96% of sales and survives a fake-review adversary — but the unpaid ablation also tips (J1 FAIL, informative): the causal engine is unburiable reviews; payment is accelerant and reward, not cause. Steady-state consumer quality premium ~55–60% (J2's growth metric caught a concentration artifact; the level is the finding). |
| Growth without end? | PASS, honestly bounded: 1.5%/yr quality-adjusted (Earth-bound, yrs 50–100); when the physical cap binds, abundance converts to free time; the frontier dial [X] restores material growth. |
| Healthy rewards? | Top10/median 2.7× with 30%/decade churn — fails the registered [3,15] band on the equality side while the poorest tenth rises 1.5×→2.65× essentials. |
| Design discovery | The bootstrap trap: the governor throttles the mint before knowledge machine-pay (φ=25% of realized productivity gains — first fully endogenous WTP) ignites → proposed canon amendment: a constitutional Exploration Subsidy floor (c_min=0.25). |
v8, v9 & v10 — the adversarial-design era (July 7, 2026)
Both run under specs registered before any code (July 6–7), executing the July 6 red-team program. New program convention honored: counterfactual cells — the roads not taken get measured in the same harness as the roads taken (cf. COUNTERFACTUAL - The Three Roads Not Taken).
| Run | Question | Headline (and its defeater) |
|---|---|---|
| v8.0 Adaptive Goodhart | Does the effort-weight survive an optimizing content adversary — and do the ratified fixes? | The static 2.5× claim dies at month 1 against the public rule (construction, not search) — measured justification for the A.1 retirement. The ceiling holds (farm per-hour = honest per-hour exactly; p10 untouched — governor+pool arithmetic, labeled); honest creators −30% income share is the real wound. Outcome-linking caps the optimizer at 1.32× (load-bearing dial: fake-outcome cost, fails below c_o*≈0.71 — pilot-measurable); private audit inverts the arbitrage (0.84× — gaming pays worse than honesty) at 0.09% honest cost. G6 counterfactual: the Secret Judge is measured-dominated — hidden retrained ML judge delays the attacker 6 months, ends at 2.56×, and taxes honest creators ~17% (≈187× the audit's honest cost). Gate-12 recovery ratios: naked 1.00, secret judge 0.76, outcome-linked 0.07, audit −0.20. 5/5 bars resolved as registered. |
| v9.0 Levered Cross-Venue Run | Does the amplifier-on/absorber-off conjunction break canon — and does the ratified "protect people, concede price" stack (A.3) hold? (Gate 13.) | Canon fails exactly as registered (72% drawdown; p10 delivery below 1.0 for 12 consecutive months, trough 0.528; reserve dead; the attacker nets +$14.9M on $30M — the run is a trade). The ratified stack passes all four bars, both seeds: essentials delivery 1.000 every month through the same storm, reserve ends $28.9M, income never lost — price conceded at 71.8% dd, as ratified. The Peg counterfactual is measured-dominated: 5.1× the reserve burn, 95.8% of it bailing out speculator/levered exits, 156 consecutive months of broken floor, and the price crashes anyway. Honest surprise, reported: R1's registered expectation was wrong in public — the absorber failure alone heals in 13 months (oracle lag); it takes the conjunction. Defeaters: the committed engine (from the interrupted July 7 session) was repaired pre-readout — eleven disclosed fixes, original archived; aggregate-pool model at central ρ=0.8 only; depth sweep left to the full harness; "you cannot out-reserve a levered market" is illustrated, never proved. |
| v10.0 Identity Compromise & Recovery | Is a mass biometric compromise survivable as designed (quarantine, cohort caps, body-present recovery, fallback re-anchor)? | Breach-survivable at the stated dials. Floor-capped quarantine keeps a 15%-cohort breach inside the 2% fraud gate (1.37%) with essentials delivery 1.0 throughout; the proposed gate-14 cap is load-bearing (both margins blow at s=30%, p_live=0.2 — the cliff sits ≈22%). Recovery race: owner wins 100.0% incl. zero-tenure (guardian-off ablation: 99.88% at the newcomer edge — the enrollment guardian is what carries them). Weaponized revocation of half a jurisdiction = a 5-month queue, zero months below floor. Defeater, on the face of every readout: p_live and the 0.45 forgery ceiling are stand-ins for the sensors-vs-synthetics keystone — the run prices the design around that assumption; only the pilot prices the assumption. |
The July 6 sim debt is paid (July 7, 2026): all three sims owed by the ratified resolutions — v5.4 (A.2, consent), v8 (A.1, Goodhart), v9 (A.3, levered run) — plus v10 (biometric pass) are run, both seeds, bars as registered, with results and plain-language companions in their folders. Gates 12, 13, and 14 now have measured numbers; white-paper integration (v1.7) is drafted and awaiting ratification. v8.1 — Recon Visibility & Endogenous Outcome-Wash (owner question, run July 7, same-day registration honored): does the transparent network's visibility of attacker reconnaissance itself defend? Both registered expectations held. Recon-watching adds ≈ nothing (delta 0.000 at fully-public rules — construction, not search; ≤ 0.042× even at half-unpublishable rules, because blind overshoot is cheap) — but the ledger defends decisively: endogenizing v8.0's assumed fake-outcome cost against an evolving wash-ring vs an aggregate-only graph detector yields c_o = 1.051 > the 0.71 boundary — the best "fake" is 100% payments to real users for real use (Goodhart inverted), G3 attacker payout falls to 0.90× (below honest), the detection floor is a modest q* = 0.15/month (riding the 6-month clawback), publishing the detector threshold collapses the defense (c_o → ~0.3 — private-sample application is load-bearing, the A.1 pattern again), and the ambient per-person surveillance counterfactual buys zero extra security at 187× the honest cost. Defeaters: calculator-grade dials stated (organic cost 1.0/unit is definitional and drives the inversion; C_MARGIN governs A-family smallness); c_o stays pilot-measurable. Artifacts + both companions in the v8 folder. Honest relabel (superseded July 9): v6.8 (escrow + multi-sponsor federation) was at that time specified in prose only — the status below (line "Backlog discharged") supersedes this: its SPEC was registered, built, and run on July 9, 2026.
v11 — the substrate era begins (July 2026)
Provenance note (corrected July 9, 2026 by the Verification v3 pass): an earlier "correction" here claimed the v11/v12/envelope artifacts were actually registered and run July 9. That was false — filesystem timestamps confirm they were built July 7, 2026 (20:53–21:15), exactly as their datelines say; the producing session simply spanned two sittings (July 7 evening, July 9 afternoon). Reverted per
VERIFICATION v3D3; bars, code, and results were never affected. Model-attribution note (same pass, action 10): per the owner's record this two-sitting session started on Fable 5 and was moved to Opus 4.8 partway through; the "Claude Fable 5" signature lines on July 7–9 artifacts inherit the session's starting label and are not reliable model attribution (July 6's mix-up, mirrored). Treat per-artifact model identity as uncertain. Extension, July 10–11 (Verification v4, action 14): the same caution now covers the July 9 evening – July 10 work (v16–v30, proofs, envelope rewrite, banking/canon layer, dashboard): those sittings self-sign "(Fable)" but per the owner's record ran as Opus 4.8 after the mid-thread switch — with one exception:EVE Sim v23(Sponsorship-Agenda Capture) was produced by Fable 5 (owner's record). In-file, v22's and v23's signatures are wording-identical — the standing lesson that signatures are not model evidence, third session running. The July 10–11 verification/correction pass itself was Fable 5 (a fresh session).
The first run against the new 01 Canon/EDEN Protocol Architecture v0.1 (its §11.1 registration). Counterfactual-cell convention honored.
| Run | Question | Headline (and its defeater) |
|---|---|---|
| v11.0 Validator Capture & Sortition | Can civic validation (consensus by sortition over bonded verified persons, §4 of the architecture) be captured at budgets the program takes seriously — and does it dominate the roads not taken (stake-weighted PoS, permanent PoA)? | 11/11 bars as registered, both expected-fail brackets included. Cheapest safety capture at central dials (k=201, H=20k): $613M via bulk identity rental — 20× the v9 attacker; bribing incumbents is the most expensive channel ($1.66B — one-lifetime identity makes equivocation a life-scale loss). Honest surprise, reported: the registry-rot dial barely matters (budget flat across f=0.5–25% — rot supply always exceeds seat demand at pessimistic-cheap pricing); the true wall is honest-pool size: H* = 5,500, below which bond-only capture undercuts $30M — so the honest volunteer count becomes a live public gate quantity, like reserve months. Committee size load-bearing by breach (k=101 censors 3.16% of epochs at 25% infiltration, failing the 1% bar as registered; k=201: 0.483%). Coerced-state channel: 15% cohort caps force 3 colluding jurisdictions to censor, 5 to capture. Counterfactuals measured-dominated: young-chain PoS captured at $100M/$50M (safety/liveness) and its security crashes with the token (post-v9-crash civic/PoS ratio 19.1× — personhood-denominated security is counter-cyclical); permanent PoA halts under 2 legal orders and cannot be forked away from captors. Thin pass flagged: V3a's bond-floor cleared its $100M bar by only 5.7% — index the bond, gate the pool. Defeater on the face: the entire run prices the mechanism around the identity layer (f, rental prices, bribery acceptance are dials; gates 9/14 unmoved) — sortition over sock-puppets is no defense at all, and only the pilot prices the puppets. Gate-15 candidate numbers published in RESULTS. |
| v12.0 Aggregator Collusion & Re-Aggregation Audit | The PoE pipeline's new trust surface (Architecture §6): can bonded aggregators profitably launder forged-engagement claims past private-sample re-audits — and what polices them? | 6/6 bars as registered, one disclosed harness repair (rare-event cell degenerated the 3σ test; Poisson count-test fix, original archived — v9 discipline). Break-even audit rate q* = 0.62% of batches; honest cost 0.010% of mint (the v8.1 pattern again: the clawback is ruinous per catch, so the watch can be light). Vesting shown load-bearing by breach: at the adversary-favoring corner, the no-vesting smash-and-grab profits +$323k, and the 7-day vesting window collapses the same attack to ~$0 — proposed canon amendment: 168-epoch payout vesting on the time-mint lane. Blast radius at the 15% market cap: 0.0063% of annual mint kept, ring ROI −$586M (no safety in numbers). Cross-aggregator double-counting: 0/1,000,000 duplicates past the global nullifier set. Counterfactual measured-dominated: the Trusted Single Aggregator keeps $438B (1,580×) — the measured case for many bonded booths over one trusted gate. Defeater on the face: forged attestations are spotted to the attacker for free (gate 9 priced around, again) — if attestation forgery is dear, every number improves. Gate-16 candidate published in RESULTS. |
Backlog discharged — EVE Sim v6.8 - Escrow & Multi-Sponsor Federation (July 9, 2026): the oldest specified-not-registered IOU (the v6.7 escrow + diversification amendments) is now registered, built, and run. J0–J3 + J5 pass as registered; J4 failed unexpectedly and is reported as a finding. Headline: multi-sponsor federation + escrow turns v6.7's −92% single-sponsor exit into a −9.9% ripple (currency actually rises — escrow severance bridges the 6-month step-up lag) with essentials delivery unbroken and zero printing. Two gate numbers measured by breach: max single-sponsor share cap* = 0.40 (cap 100% even with escrow → 59 months below floor; escrow buys months, the share cap carries the currency) and minimum escrow depth E* = 6 mo = the step-up lag (E=0 → 4 months below floor). Storm (recession + austerity + mid-recession exit + contagion + chronic delay) passes on its designed-thin margin (delivery trough 1.062, dd 42%, recover 4 mo). J4 finding: "cheaper than welfare" is a peacetime number (≈24% member-level all-in here; v6.4's 26% was funder-level) — the survivor absorbing lapsed shares mid-storm sees its saving compress to ~9% and carry to 2.7% (both bars breached); federation overhead concentrates on whoever backstops a collapse, so the backstop obligation must be priced. Cascade politics (24 draws): 83% zero-months-below, 100% no stranding. Counterfactual (single sponsor, no escrow) = 65–80 months below floor, confirming v6.7. Defeater on the face: political hazards are dials; no accession modeled (coverage numbers are floors); in-family discount stands.
EVE Sim v13 - Oracle Capture & Quarantine (registered July 7, run July 9, 2026): prices capturing the EBI price oracle the floor and machine-pay are denominated in (SPEC registered before code; engine built and run July 9). 6 of 8 bars pass; O3-stress and O4 FAIL as honest findings, bars not moved. Faking 2-of-3 class-medians costs $99.5M (O1) and cannot pay for itself — 80× cost/payoff, sabotage-only, not theft (O2, the threat-model flip from thief to vandal). Granted a free capture, the floor still delivers 0.960 of essentials every month centrally (O3b) via move-cap + quarantine (cap OFF → damage triples past 15%, O3 bracket as registered); but under the pessimistic triple-combo (4-wk lag, 10%/yr inflation, 12-mo re-validation) delivery dips to 0.888, just under the 0.90 stress bar (O3c FAIL) — the finding is precise: re-validation speed is the load-bearing safety parameter, not the capture. The lane is the dearest class ($310M) but at 4.3× the reporter class, under the registered 5× bar (O4 FAIL — the "real commerce is the expensive fake" inversion holds qualitatively, the multiple doesn't clear). Counterfactuals measured-dominated: single-CPI feed capturable at 1/995 the cost (Argentina INDEC precedent), unbonded crowd 1/199 (O5). Defeater: prices the design around identity/market dials; does NOT discharge the live prize-funded oracle red-team, still a launch gate. Gate-17 candidate in RESULTS.
EVE Sim v14 - Cross-Layer Composition (July 9, 2026): the composition red-team's registered sim — one adversary wearing registrar+validator+aggregator+oracle-reporter hats at once, the attack per-layer sims structurally can't see. Composes the committed v10/v11/v12/v13-oracle anchors (X0 reproduces all four). X1 and X2 FAIL exactly as registered — that IS the finding: attacking the four layers jointly costs $483M vs $737M separately (ratio 0.66, a 34% shared-cohort discount) because the identity bloc is built once and worn four times (X1); and the identity blast radius composes from v10's isolated 1.37% to 3.74% — past the 2% gate — once downstream weight is counted (X2, 2.7×). The oracle→reserve loop protects delivery (≥1.0, people over-receive) but drains the reserve in 4 months (X3 — the victim is the reserve, so "EBI-real" needs an oracle-independent cross-check). The fix is measured to work: one joint cross-layer cap (15% combined across roles) drops per-role reach to 3.75% and composed fraud back to 0.96% (X4). Defeater: composition coefficients are stated estimates, not field values; inherits the identity keystone. Gate-18 candidate: a live cross-layer concentration cap; proposed §4/§6 amendment to the Architecture.
Provisional, NOT canon — EVE Sim v13 - Ecology & Essentials Supply (July 9, 2026): first attempt to endogenize essentials supply and stress the design against ecological contraction (Sustainability was the lowest-scored dimension, 3.5). Filed PROVISIONAL: the E0 harness-trust gate FAILED (books balance to 1e-16, but base inflation/seed bar breached) and the engine is unvalidated single-author code from the interrupted session — by the program's own rule, the other bars are not yet trustworthy. Provisional reading, pending engine review: EDEN held full essentials delivery to the poorest decile (fill 1.0) through 10–40% supply shocks while the GDP-coupled counterfactual collapsed to ≈0 (the ecology thesis, if it survives) — but apparently by letting the currency inflate (~15%, printing through the storm), the ecology-era echo of "protect people, concede price," and it did not clearly show throughput-decoupling reduces material intensity (E4c near-tie 0.187 vs 0.185 — the honest open question). Nothing here enters canon or moves a score until the engine is reviewed and E0 is resolved (fix-and-re-register, never bar-move). E0 diagnosed + recalibration attempted (July 9): root cause is structural. A disciplined recalibration (two principled fixes — c_min maturity-release; enforce v1.4 no-print floor — original archived as ecology_sim_v13_1_RECAL_attempt.py, committed engine restored, no bar moved, no params hacked) traced the 2,163× base inflation past the c_min subsidy floor to its dominant driver: a floor-printing wage-price spiral (the EBI-indexed floor prints every month, violating v1.4's "floor never prints"). Enforcing no-print stops the spiral (prices → 7.9×) but exposes the real problem: the floor is structurally underfunded — rationed to real funding, delivery to the poorest collapses to ~9%. This is the program's funding-base mismatch (v5.2) in acute form; the ecology engine never implemented the staged-activation/reserve/slice machinery that resolves it elsewhere. Complete fix = port the v5/v6 funding machinery in — a rebuild, not a patch — and remains owed. Stays provisional; the E1/E2 delivery-vs-GDP thesis rode on the failing floor-print and is confounded until the rebuild. The two fixes are correct-in-direction and carry into the rebuild.
REBUILD DONE — status flip (July 11, 2026): PROVISIONAL → RESOLVED-NEGATIVE (funding question answered). EVE Sim v13.1 (ecology_sim_v13_1.py → results_v13_1.json, built to the registered REBUILD SPEC by the Fable 5 verification session, owner-reassigned from the Opus earmark) ports the staged-activation machinery with printing structurally removed. Regression gate: PASS exactly (68/68 committed v13.0 bar values reproduced in legacy mode). New machinery: 0 of 7 R-bars pass, and that IS the answer — the funding streams carry 2–5% of floor obligations (gate never opens, all 18 cells); a labeled jump-start extension proves it is not a bootstrap gap (force-activated at t=0 the floor pays 8%→2% of obligations forever); the structural arithmetic: obligations eventually exceed the model's entire settlement volume (a 100% tax couldn't fund it — a rich promise in a poor world; the v5.1/v5.2 funding-base mismatch at steady state, as the SPEC's R-E0 expectation anticipated). Zero printing in all 10,800 EDEN months; inflation 7%/yr (the old 2,163× was pure printing). E4 decoupling now flagged confounded-by-depression, not claimed. Canon-level decision now in the ratification queue: grow the purse (v5.2-scale settlement slices, ~10×), shrink the promise (partial/lower floor), or name a permanent bounded subsidy. v13.0 artifacts stay as the investigation trail. Both v13.1 companions in the folder.
EVE Sim v15 - Governance Capture under the Cap Function (July 9, 2026): executes the 01 Canon/Governance Cap-Function Spec v0.1 §4 bars (G0–G5) — can the contribution house be captured despite √-concave weighting + a 5% per-actor ceiling? G0/G2/G5 pass; G1 passes under the fix the run motivated; G3/G4 reframed as findings. Headline: the contribution house is robustly non-plutocratic — √-concavity alone squashes a 30%-of-contribution whale to ~1% of the vote, and a majority needs ~1,595 colluders (each also one vote among millions in the person house). The run caught a real flaw in the cap as first written (F1): the single-pass min(raw, κ·Σraw) leaks to 9.4% under concentration; iterative water-filling is required and holds it at exactly 5.00% → a v0.2 refinement to the governance spec. Two registered expectations behaved differently and are reported honestly: the α=1 "linear→top-3 majority" bracket didn't break at σ=2 (top-3 only 35%; linear-plutocracy crossover is at σ=4, and √+cap contains the top actor ≤5% at every concentration tested); and √-weighting rewards identity-splitting 1.41× (=√2) — closed only by the identity layer's 120F-per-lifetime cost, so governance anti-capture inherits the identity keystone like everything else. Defeater: contribution distribution is a dial; what counts as contribution without becoming farmable is a separate unsolved Goodhart problem. Gate-19 candidate in RESULTS.
Companion analysis — Benchmark - Proving Cost Envelope (July 2026) (desk benchmark, labeled as such; discharges Architecture §11.3): proving a claim costs $7×10⁻⁷–$0.019 = 0.00007%–1.9% of the mint value it certifies (lean-circuit marginal cost vs 2026 market $/tx anchors) — feasibility never in question; hourly epochs hold except the named TEE-native P-256 trap (~200× cost, breaks single-GPU epochs → proposed conformance rule: circuit-friendly device keys or the audit-backed minimal profile, which the v12 layer makes safe). One honest tension published: the v12 fee dial ($0.0005/claim) holds at 720× on the lean route and fails 6–22× at today's outsourced-market prices — resolution written down (build lean; set fee ≥ 2× measured cost at pilot; market falling 45×/yr). Proposed gate: no currency pilot without a measured $/claim on the deployed circuit. Not a hardware run — the pilot bench is the real one.
Proofs - Machine-Checked Theory Claims (July 2026) (July 9, 2026, verification session): the program's load-bearing [T] (theory/arithmetic) claims, upgraded from "recomputed" to machine-checked — sympy symbolic derivations and exact-rational (no-float) arithmetic, criteria registered before code, committed as a harness-compatible engine (theory_proofs.py → results_proofs.json) so verify_all.py re-verifies the proofs forever. 10 of 10 PROVED (reconciled July 11 — this row previously carried a stale early-state "7 of 8"; two grade labels apply): taper no-cliff (marginal exactly 0.5→1.0, income ≥ F, kink at 2F — symbolic); v11 committee-censorship tails are exact hypergeometrics matching committed floats to the last digit (k=101/201/501, t=⌈k/3⌉); v15 water-fill terminates/sums/holds the cap and reproduces the committed extreme cell; splitting gain ≡ k^(1−α) (√2 at k=2 a theorem); cartel bound ≥ 11 at κ=5% (bound ≤ bar 20 ≤ measured 1,595); v14 blast-radius leverage has an exact closed form 2.731887 landing 0.21σ/0.37σ from both MC seeds (and X4's round 2.8 coefficient is now quantified as ~2.5% conservative); the O0 capped-geometric formula is proven and equals exactly 13/400 / 13/320. P8 PROVED at self-consistency grade: the first pass hit its registered NOT-PROVED contingency (endpoints not re-derivable from the artifact alone); the envelope engine was rewritten the same evening to emit headline_derivation (values unchanged, 195/195 leaves verified) and P8 re-graded — since emitter and checker share an author, this certifies internal consistency, not independent re-derivation (relabeled July 11). P9/P10 (registered same-evening addendum): PROVED — crash-floor identity and Redemption Window invariance as exact algebra, empirical premises named not proved. P3 re-scored July 11 to its registered clauses: terminates ≤n on all feasible cells, and the previously-unchecked uniqueness clause is now enumerated exactly (unique KKT-feasible prefix, 20-cell κ/α grid). Both companions in the folder.
Companion red-team — 03 White Paper/EDEN Red-Team — The Economics Literature vs EDEN (July 2026) (July 9, 2026): the pass the sims can't run — the ten strongest published-literature objections (Lucas, Hayek/calculation, Boskin index bias, Goodhart, Myerson–Satterthwaite incidence, Krugman/Obstfeld crisis models, Mundell/Oates OCA, unit-of-account inertia, the Arrieta-Ibarra data-valuation gap, Baumol) argued at full strength, then checked against canon artifacts. Verdicts (corrected July 11 to the scorecard's own count): 4 answered at strength (Goodhart in-model; crisis models by ratified concession; OCA/consent found by the vault first; the data-valuation gap answered-in-design), 5 partial, 1 originally unanswered (A3 index-number methodology). A3 has since been upgraded to PARTIAL — the EBI Methodology Spec specifies it and v33 shows the fixed 0.05 bias budget is insufficient against drift (→ ≤~2.5-yr re-basing candidate). The earlier "3/4/1" phrasing was an undercount (v4 D17). Owed instruments filed as candidates, not registrations: [CANON] EBI Methodology Spec (composition governance + bias budget — the pass's top item), Incidence Note (who pays for the floor, one page), Monetary Position Note (EVE claims the EBI as numéraire, not unit-of-account takeover; all results hold in the permanent-FX world); [SIM] joint dial-shift envelope (Lucas), composition-capture cell, region-secession cell, century governor-vs-productivity drift cell, FAIL-tier WTP sensitivity row. Drafted to be handed to a hostile human economist as their starting brief. Plain-language companion in the same folder.
EVE Sim v16 - Regime-Shift Envelope (Lucas Sweep) (July 9, 2026): the economics red-team's A1 instrument — the Lucas critique answered the only way a model can: shake the nine most load-bearing behavioral dials jointly (±50%, 32-point LHS, seeds 7+11) through the committed engines as committed (v6.8 run_fed and v15 functions imported, never reimplemented; v11 via the closed form proven in theory_proofs.py). L1/L3/L4 pass; L2 FAILED as a finding — the run's headline. Envelope-robust: the peacetime federation result (100% of shaken worlds — delivery unbroken, zero printing), the governance cap (100% containment to machine precision across its full governed κ/α range, 400 cells; cheapest majority ≥ 2/κ everywhere; the single-pass cap would have leaked in 7.75% of the governed envelope — v0.2 water-fill is load-bearing, not cosmetic), and the k=201 committee (≤1% censorship through the 25% design assumption, with a newly measured sharp wall at s*=28% — 3pp of margin, more ammunition for gate-18). Dial-local: the storm headline — holds in only 47.4% of the envelope (bar was 75%), 18/20 flips breach the program's own 3-consecutive-month criterion, zero printing anywhere (honest rationing); isolation slices prove the driver is sponsor recession-payment fraction — slices committed July 11 (v4 D2; they had been quoted from uncommitted probes), and committing both seeds widened the bracket: seed 7 gives g*∈(0.45, 0.50], seed 11 sustains a breach at 0.50, so g* ∈ (0.45, 0.60) straddling 0.50 → gate-20 candidate sharpened: floor recession payments at ≥60% of obligations, or ≥50% + escrow sized to the residual austerity gap (the J4 "price the backstop" lesson extended to "price the austerity floor, with margin"; adopted ≥50% parameter flagged for re-ratification in DR-14). Registered bracket failed-to-fail, informatively (F1): lag>escrow causes zero peacetime breaches in 26 cells — E*=6=lag is a storm-scoped requirement (so never relax it on peacetime evidence). An LHS correlational artifact (flips at higher builder ARPU) was isolation-checked and dismissed — higher ARPU is monotonically protective in both seeds (14→13 / 16→12 months below across the ARPU range; the earlier "14→11" was corrected against the committed slices). Defeater on the face: 9 dials, 2 engine families + 2 closed forms; v12/oracle/v14 engines need a mechanical refactor before they can be swept (owed); structure-shift (vs dial-shift) remains pilot-only territory. Both companions in the folder.
EVE Sim v17 - Composition Capture (July 9, 2026): discharges the EBI Methodology §2 candidate — does lobbying the essentials basket pay (the "what counts as essential" Goodhart surface, the composition analogue of v15's governance capture)? Calculator-grade public-choice model against the methodology's three defenses. C0/C1/C4/C5 pass; C2 and C3 FAILED as findings (C3 re-scored July 10, v4 D3 — the bar was registered "any single category" but coded energy-only; food/shelter each yield $21.6M/yr vs the $20M bar, and the food-monopoly ceiling turns marginally profitable at 0.96×/+$0.8M-yr — a basket-cost-cap tightening candidate is attached in the Ratification Brief B2): capture is unprofitable but the run caught its own registered expectation being too generous — the rate cap alone holds capture only to a thin ~1.6× loss against a hypothetical monopolist (below the 3× bar, ROI still −$7.8M/yr); what makes composition-capture decisively hopeless is the functional-category definition (C4: a price-taking supplier earns zero rent from a reweight — recipients buy the cheapest satisfier, not theirs), so the honest defense hierarchy is functional-definition (decisive) > two-house $100M+ cost > rate cap (thin alone). Counterfactual with defenses off: capture profitable ~12,400× (C5; corrected July 11 in the INDEX (the underlying re-score was July 10) — the original "~5,000×" and its "0.0002×/$78M" companions did not match the committed JSON: ratio 8.04e-05, naive six-year prize $777.6M). Defeater: the definitions themselves are a governance surface — "what counts as adequate nutrition" is the composition analogue of the still-open "what counts as contribution." Both companions in the folder.
EVE Sim v18 - Oracle-Reserve Cross-Check (July 9, 2026): closes v14 X3's owed defensive mechanism — an inflated EBI over-pays the floor and drains the reserve in ~4 months. Adds an independent endogenous-lane estimator + divergence gate. Three bars pass; Y4 flipped to a refuted-expectation FAIL under gate-tightening (July 11, Backlog #4b), and Y0 flipped to a FAIL-finding under the Verification-v5 re-score (July 12 — its false-quarantine clause had been scored only at the central σ=1% of the registered {0.5%,1%,2%} noise sweep; at σ=2% it trips 12.5% of months vs the 5% bar, seeds disagreeing there): the cross-check bounds the monthly over-draw to τ×lane not δ×lane ($0.30M with it on vs $19.8M off; reserve survives the full 24-mo horizon vs draining in 2), and delivery stays whole because the floor's 1.10× cushion (the 0.05 bias budget from EBI Methodology §5) absorbs honest estimator noise — a satisfying cross-artifact consistency check. Y4 (τ-tradeoff) re-scored: when its tautological gate was recoded to compute the registered interior-optimum expectation (τ≈2–3%), the frontier proved τ-degenerate (at δ=10% the gate trips at every swept τ≤5%, so drain is τ-invariant) and τ lands at 5% — the registered expectation is refuted (a finding); this doesn't weaken the drain-bounding mechanism (canon τ=3% rests on Y1's divergence-bounded drain, PASS on a computed clause — but its false-quarantine comfort is σ-conditional: fine at honest basis-noise ≤1%, one-month-in-eight false quarantines at 2%, so τ needs to sit above realistic noise or the coded median-smoothing option engages), and a joint τ-vs-δ-vs-σ tuning sweep is the owed successor. Y1/Y2 compute their registered clauses and PASS. Honest residue (Y3 bracket): a 2-of-2 attack (inflate the published index AND suppress the lane at once) converts a reserve-drain into a bounded ~1% delivery dip — no new hole (it needs the two dearest channels captured together), but the honest limit. Folds into canon as 01 Canon/EBI Cross-Check Addendum v0.1 (τ=3% proposed). Both companions in the folder.
EVE Sim v19 - Run plus Exodus (July 9, 2026): closes the economics red-team A6 residue — v9 tested a price run; this composes it with a reflexive adoption collapse (price crash → real users leave → mint/funding shrink), the Diamond–Dybvig/Terra feedback. All five bars (Z0–Z4) pass; the finding is structural: the reflexive exodus is survivable because the floor is a per-capita goods guarantee — when people leave, the bill shrinks as fast as the base, so a floor like this cannot be "run" the way a fixed-liability peg can (corrected + demonstrated July 11, v4 D1: the "88% gone" figure originally cited here matched no committed run — it was an inversion of the 88%-retained Z2 result; the registered x_max sweep (now executed) shows price-driven exodus bottoms at 68% retained with delivery 1.0 everywhere, and a labeled extension cell forcing 88% out confirms delivery 1.000 to the remaining 12% with the reserve ending 98% full; a second extension runs the permanent-confidence-depression case the old prose only talked about — the vault never breaks but the base drains to the 2% model floor: the floor can't be run, but it can be abandoned; the spiral self-limits at 77–88% retention in the registered cells). Z0 reproduces v9's 26% confidence-drawdown (calibration anchor). Defeater, stated: the reduced form omits fixed infrastructure costs — per-capita delivery to remainers is run-proof, but the fixed machinery (validators, oracle) under extreme depopulation is the unmodeled failure mode (successor cell owed). Both companions in the folder.
EVE Sim v20 - Region Secession (July 9, 2026): closes the economics red-team A7 owed cell — the optimal-currency-area exit question (Grexit / "what if the payer leaves"): a whole member region redeems and secedes at an election shock. All five bars (S0–S4) pass; the finding is a sharp asymmetry. No one is stranded (S1: a seceding net-drawer's delivery falls to its never-joined baseline — the union only ever added a marginal transfer — never below it; the redenomination run is absorbed, S3). Losing a net-drawer relieves the union (S2: remainer delivery 1.0, currency steady — the uncomfortable OCA truth that shedding your neediest member improves the books). Losing a net-payer opens a persistent fiscal hole (S4: 53% currency drawdown + $3B/mo funding gap; the reserve buys ~24 months on the committed sizing — or ~9 months on the SPEC-registered sizing (the engine sized the reserve on union transfer volume, $81.1B, where the SPEC registered the seceding region's own obligation, $36B — deviation disclosed + registered-dial probe committed July 11, v4 D10; the 9-vs-24 choice is flagged for ratification) — a countdown, not a cure). Ties to v5.4 consent: the transfer that strains consent is the one whose withdrawal opens the hole, so the design needs a payer-exit re-balancing rule (gate candidate), not just a reserve. Defeater: reduced form; the asymmetry is structural but the 53%/24-mo magnitudes are dial-dependent; no secession politics or new-local-currency stand-up modeled. Both companions in the folder.
EVE Sim v21 - Closeout Battery (July 9, 2026): one battery red-teaming the four honest residues this session's own sims (v17–v20) surfaced — the discipline of attacking new findings before they harden. K2/K3 pass; K1 and K4 FAIL as findings (K4 flipped under gate-tightening, July 11, Backlog #4b: its pass had been gated only on the 25% measured anchor — the reading that passes — while its "closes within 24 months" clause was hardcoded True; recoded, K4 is scored against the registered 6% political bar, which no split clears → honest FAIL, and the un-simulable 24-month timing is a disclosed non-result; v5 note (July 12): its "covers the full gap" sub-clause is additionally flagged by-construction (the slice/taper split sums to the gap by definition — real coverage evidence lives in v32's committed paths). This strengthens rather than weakens gate-22: it is the measured reason to pre-commit the taper/slice split). K1 (v17 successor): capturing a category's definition ("adequate nutrition") is no more profitable than adding a category (both ~1.6× losing, ROI −$8M/yr) — the rate cap throttles definitional and compositional edits equally, so the registered "definitions are the weaker point" expectation was wrong in public; the actionable rule is to treat definitional edits as rate-capped changes. K2 (v18 successor): the cross-check makes the 2-of-2 oracle attack cost $410M = 4.1× the single-channel drain (published $99.5M + lane $310M) for a bounded 1% dip — the residue is priced, not open. K3 (v19 successor): per-capita delivery is run-proof at any population, but the system has a fixed-cost floor at ~40% retained population (below it, the 5% protocol share can't fund validators/oracle) — a fixed-cost failure, not a per-capita one → minimum-viable-scale + graceful-wind-down gate candidate. K4 (v20 successor): a payer-exit re-balance exists within the 24-mo runway but reignites consent — no split keeps payers under the 6% political bar, and it takes ≥50% subsidy-taper to stay under the 25% measured bar → pre-commit the taper/slice split in the accession contract. Defeater: calculator/reduced-form; structural findings robust, exact magnitudes dial-dependent. Final Fable simulation pass — v17–v20 residues closed. Both companions (PL embedded in RESULTS; standalone companion added July 11 (PLAIN LANGUAGE - v21.0 Attacking Our Own Findings), discharging the SPEC's promised deliverable) in the folder.
EVE Sim v22 - Adoption Timing (First Movers vs Late Joiners) (July 9, 2026, owner-directed): the series' missing cohort experiment — v7 assumed the world adopts at once; v22 makes timing the treatment (pioneer/early/majority/laggard/never waves × four vectors: science institutions, governments, firms, wealthy families; 50-yr transition chassis; v6.4/v7/Multigen anchors imported, not re-litigated). Owner questions registered verbatim; the influence bar registered two-sided by owner decision (early adoption must pay; entrenchment = FAIL). Seven of eight bars pass; T5 FAILED on re-score (July 10, v4 D4): the catch-up leg was originally scored at a mis-indexed 20-year window; at the registered 10-years-from-joining window the majority holds 0.78 of pioneer influence vs the 0.80 bar (design-FAIL per the SPEC's own terms) — dilution works but runs ~2 years behind the registered clock (0.80 first reached ~11.7 yr; the fix-vs-re-register decision is queued). The three headline answers: (1) science symbiosis is real and causal — adopted institutions out-discover outside 1.92×/inst by yr 20, and the registered ablations prove it's the owner's mechanism (failure-data pay and failure-data visibility each carry ~half; both off → 1.14× ≈ nothing); survives a 1.5×-funded outside; self-funded 74% of current spend at yr 15 (flow share; the "82% by yr 15" originally here was the yr-50 cumulative — re-scored July 10; yr-15 cumulative is 28%) vs a 19% debt-service drag outside. (2) Government efficiency is a level, not a path — the 26% rails saving arrives ~2 yr after joining at any date (measured 22.6 mo; ramp-dial-driven; no lock-out), but the savings stock is path-dependent: early adopters bank 1.74×/capita by yr 50 (the waited years are the permanent cost). (3) Influence: rewarded, then diluted on schedule — pioneers peak ~1.35× per-capita influence (yr 13) and end at 1.02× their population share, declining; majority reaches 0.78 of pioneer at 10 yr (the bar miss above; 0.83 on the most lenient reading; 90% only by ~20 yr); early wealth buys a 1.2× premium that melts to 0.8× — below the adopted mean — by yr 50 (non-compounding + sortition + W_age doing under staggered entry exactly what canon claims; robust to 2× wealth scale and composite reweighting); the firm vector is the one that fails the incentive bar (1.15×) because unburiable reviews keep markets contestable — EDEN pays early contribution, not early position. T6: the only compounding penalty is never joining (income/knowledge/quality gaps monotone; income ratio bounded ~1.43× by publication spillover). T7: the incentive self-propagates (endogenous adoption hits 60% by yr 10, pioneer ordering preserved). Defeater: purpose-built cohort cell; magnitudes dial-driven ([X] swept — quote the decompositions, not the multiples); sponsorship-agenda channel (wealth steering research topics while credit accrues to doers) zeroed by canon reading → named successor cell; all data-payment results conditional on H1 (WTP field hinge). REPRODUCES (byte-identical re-run); build-notes disclosure of four pre-final wiring fixes in RESULTS. Both companions in the folder.
EVE Sim v23 - Sponsorship-Agenda Capture (July 9, 2026, owner-directed): discharges v22's named successor cell — can wealth steer what gets researched when credit/reputation/data income all accrue to the doers (the tobacco-institute/foundation-agenda playbook)? Calculator-grade capture economics + stochastic evidence core, v15/v17/v21 tradition. B0/B4/B6 pass; B1/B2/B3/B5 FAIL as findings — three registered expectations falsified in public. The defense hierarchy inverted from what was registered: (1) the steering price premium is 1.9×, not 3× (ε-sensitive 1.3–3.9×), and the ablation proves it is entirely v22's self-funding momentum (starve researchers → premium vanishes) — H1/WTP is also an anti-capture hinge; (2) no perpetual foundation — outside, a ≤-yield endowment steers forever (displacement grows across 50 yrs) and the yield-on ablation reproduces perpetuity inside, so non-compounding is load-bearing — but influence is metered (~15 pp-years per treasury-month), not fast-decaying: a patient T0=48 controller holds 9.9pp through the full horizon; (3) the headline — outside, ignorance is purchasable outright (0/18 evidence cells ever cross in 50 yrs under burial + compounding); inside, truth crosses anyway in 88.9% of cells (median ~yr 22, finite treasuries + evidence recovery + attention feedback), burial-inside ablation still crosses 77.8% (unburiability rents ~+5 yrs of fog rather than forcing truth — registered expectation wrong), and the provenance discount (weight sponsored studies 0.3) is the only tested mechanism that closes the never-cross corner: 100% crossing, median deception 260→150 months → gate candidate: provenance-weighted evidence synthesis; (4) laundered steering (wash-reuse at v8 markup) is detected in 14 months with zero false positives incl. an organic-shock control → standing agenda-drift dashboard recommended; (5) displacement costs 5.68% of knowledge output (marginal miss of the ≤5% bar), legible from public flows; (6) agenda-subsidized composition capture stays losing (1.20–1.52× cost/benefit; v17 defenses absorb a fully-funded evidence pipeline). One-line verdict: outside, wealth can own ignorance; inside, it can only rent attention — metered, priced, visible, mortal, and non-convertible. Defeater: one sponsor/one domain (coalitions open); effect-size gaming finer than question selection unmodeled; monitor imports v8's auditability; discount weight [X] but its tail-closing property robust. REPRODUCES; 4-item build-notes disclosure in RESULTS. Both companions in the folder.
EVE Sim v24 - Carry-Cost Design (July 10, 2026): (numbering note: originally mislabeled v22 — a collision with the pre-existing v22 Adoption Timing; renumbered v24 on July 10, as v23 was also taken.) owner-motivated adoption-friction test of the demurrage ("holding money depreciates") rule — does the flat 5%/yr carry cost punish ordinary savers, and can a gentler rule keep the benefits? Compares no-carry / flat / progressive-by-size / generous-exemption / inflation-only / auto-lock over a heterogeneous wealth distribution on three axes at once. Finding, validated and fixable: the current flat rule does hit ordinary savers — a median household (~4 months' savings) pays ~$67/yr = 2.8% of wealth, and 67% of people pay a meaningful amount (A1 FAILS the ordinary-earner bar). Progressive-by-size and generous-exemption both dominate (M4 PASS): median saver burden → $0, hoard deterrence preserved (~4.5%/yr on the top idle decile), circulation kept. Two honest counter-findings: inflation-only is the least fair (100% pay, weak deterrence), and auto-locking everything is too gentle (loses both circulation and deterrence). Recommendation (spec-amendment candidate): replace flat demurrage with progressive-by-size (0% up to ~6–12mo essentials, rising only on large idle hoards), keep ~2% inflation as a background nudge and term-locks as the voluntary savings vehicle. Defeater: the circulation axis rests on a behavioral elasticity no sim can settle (swept); the burden axis is robust arithmetic. Both companions in the folder; feeds 08 Foundations & Thinking/EXPLAINER - Why Money Depreciates in EDEN.
EVE Sim v25 - Banking Reserve Model (July 10, 2026, owner-directed): the fundamental banking fork — can EDEN banks create credit money (fractional reserve) or only lend real/locked balances (full reserve)? N0/N1/N2/N3/N5 pass; N4 FAILs as a mis-framed bar (reframed). The fork answers itself decisively for full reserve: fractional reserve multiplies the money supply to 6.4× the mint governor's target (20× at rr=3%) — a direct contradiction of EDEN's core control mechanism (N1) — drives +540% credit inflation the governor can't see or offset (N2), and reintroduces bank runs whenever withdrawals exceed the reserve ratio (N3), plus it's more pro-cyclical (N5, 1.8× shock amplification). Full-reserve holds broad money exactly at target with zero run risk. N4 honest reframe: fractional's headline "capacity" (5.4×M0) is ~90% money-creation, not credit; against sound first-round intermediation (0.54×M0), full-reserve + an active term-lock market recovers 44% at 40% lock / 67% at 60% lock — so full reserve gives up the inflationary printing, not real lending. Recommendation: full-reserve + term-lock-funded lending; banks are lenders/market-makers/custodians, never money-creators → gates a 01 Canon/Banking & Savings Layer Spec (owed; 4 sub-decisions inside the full-reserve frame). Defeater: reduced-form multiplier arithmetic (directions robust, exact multiples illustrative); the real risk is political-economy pressure to allow fractional + shadow-banking that recreates it off-ledger (named successor cell). Both companions in the folder.
EVE Sim v26 - Lending Regimes & the Freedom Tradeoff (July 10, 2026, owner-directed): prices the Freedom pillar's laissez-faire-lending lean (let banks do anything, incl. compound interest) against three guardrailed regimes, modeled even-handedly inside EDEN's floor + full-reserve environment. Q1/Q2/Q4 pass; Q3 FAILs as a gradient-not-switch finding; Q0 flipped to a FAIL-finding under the Verification-v5 re-score (July 12 — the registered seeds-agreement clause is unqualified, and scored over ALL reported metrics the two small-count tail statistics (trap_rate, top-1% lender share) breach the 3% band; conservation and every structural aggregate agree, headlines are seed-averaged and unaffected; re-registering the clause onto the aggregates is an owner decision in the queue); Q5 descriptive (gate-tightening, July 11, Backlog #4b: Q0 now computes the ledger conservation residual (~0) instead of asserting "conservation is structural"; Q4's plutocracy metric was fixed from an epsilon-tie to a real accumulation-rate comparison (FREE 3.46× > NOCAP 2.88× > RATECAP 2.15× > EQUITY 1.29×, still PASS); Q5's contract-freedom scores are honestly downgraded to stipulated_not_computed since the engine models no origination-refusal; and the RESULTS' F5 crossover weight was corrected from "~1.5×" to the computed ~2.0× NOCAP / ~9.8× RATECAP — FREE still wins at 1.5×; Q1 disclosed as structurally unable to fail). F1 (owner hypothesis validated): the guaranteed floor cuts the free-market lending rate from ~36% (no floor, desperation) to ~12.5% (with floor) — every borrower can walk, so freedom+floor ≠ predation. F2 (honest FAIL): full freedom leaves a ~3.8% debt-trap tail in the fragile; guardrails shrink it monotonically (NOCAP 2.8 → RATECAP 1.6 → EQUITY 0%) but only equity (no fixed debt claim) is fully trap-proof — a gradient, not the switch registered. F3: the accumulation channel is interest-vs-equity, not compound-vs-simple (interest top-1% 15% vs equity 12%). F4: credit isn't starved by any regime (100% of positive-EV projects funded). F5 (the values call, quantified): contract-freedom ranks FREE>…>EQUITY; freedom-from-entrapment ranks the reverse; on equal weighting FREE edges it (the floor keeps its trap cost small) — the owner's freedom-first lean is defensible on the numbers; the weighting is the values call. Spec implication (recommendation, not decision): adopt FREE by default + a universal right-to-exit (freeze/discharge a spiral at will — bans nothing, guarantees the exit that makes a choice free) + equity offered alongside debt. Defeater: reduced-form ABM; directions robust, magnitudes illustrative; the deepest 'is a self-ending contract free' question is philosophy the sim only illuminates. Both companions in the folder; feeds DR-17 / the Banking & Savings Layer spec.
EVE Sim v27 - Lending Integrity (July 10, 2026, owner-directed): stress-tests the co-designed lending mechanism (FREE market + arrears-only freeze + unspent clawback + revolving/earmarked/raw disbursement) against strategic default + hidden income (physical economy / bearer EVE), with collateral. W1/W3/W4/W5 pass as tested; W0 is a hardcoded placeholder and W2's registered funding bar was proxy-scored (disclosed July 11, v4 D13d). W3 (core): strategic default is defeated by any single defense — collateral or earmarked disbursement → 0% of attempts profit at central (10% strategic, 30% hidden); the exploit pays only in the unsecured+raw structure — but there it already pays 53% at central threat (corrected July 11, v4 D13d; this row previously said "only the high-hidden corner"; 100% at 20%/60%), because to profit the dodged debt must exceed collateral + garnished on-ledger income + permanent-identity reputation cost + forgone on-ledger economy. W1/W2: lenders stay viable and credit flows in every structure (even naked unsecured-raw clears above base). W4: arrears-only freeze makes distressed debt grow linearly (1.63×L/5yr) not compound (1.86×), floor never garnished — the humane exit holds. W5: collateral+earmarking cut losses ~14× at high threat, so the free market self-selects into safe structures without any ban, and even the worst corner is coverable at ~11% (below v26's 12.5%). Defeater (prominent): the whole result rests on the identity/reputation keystone — a defaulter can't escape the debt or re-borrow only because personhood is permanent and sybil-resistant (v10/v11); reputation-cost (0.5×L) and garnishment-capacity (0.8×L) dials carry the magnitudes. Reduced-form; single-loan lifecycle; organized fraud rings a named successor. Validates FREE + right-to-exit for the Banking & Savings Layer spec (DR-17). Both companions in the folder.
EVE Sim v28 - Shadow Banking (July 10, 2026): discharges Banking Spec §6 — can private money-like IOUs recreate fractional money-creation off the ledger, defeating full-reserve? Five bars PASS (four computed, SB0 identity-grade); SB2 is now a disclosed non-result (gate-tightening, July 11, Backlog #4b: SB2's "detection" was a PASS echoing an assumed input constant, not a measured quantity — the engine has no velocity/graph model — so it is honestly downgraded to detection_assumed_not_measured rather than a hardcoded pass; SB0 reconciles the money-supply conservation identity from the ledger (residual 0 — graded July 12, v5: an identity/self-consistency check, the two "paths" being the same algebra rearranged, not an independent computation), SB5 computes its trust-radius bound (structurally always-true as coded; its content is the non-systemic magnitude), and the decorative seeds were removed since the engine has no RNG). Unchecked the threat is real (10× money multiplier), but good money starves shadow demand (the headline): because EVE is floor-backed and stable, rational adoption of a risky fractional private note is only ~3.7% at a 3% yield edge (you won't hold risky private paper when the official money can't fail you); on-ledger money-like circulation is detectable by its velocity/graph signature (92% TP/3% FP, separable from ordinary non-circulating lending); together these bound on-ledger shadow credit to ~2.6% of broad money, plus a ~1% trust-radius-bounded off-ledger residual — all non-systemic; the invariant holds. Defeater: adoption is a behavioral dial (yield-chasing vs risk-aversion); the real open risk is a large coordinated off-ledger issuer (faces the adoption wall + detection-if-it-grows) — named successor. Turns §6's "unspecified enforcement" into a priced defense hierarchy (demand-side primary). Both companions in the folder.
EVE Sim v29 - Lending Concentration (July 10, 2026): discharges Banking Spec §10 / v26 F3 — does free compound interest become the surviving passive/dynastic wealth channel (r>g)? All six bars (LX0–LX5) pass. Unbraked the channel is real (top-1% wealth share 9%→16% over 50yr), but EDEN's existing machinery already contains it (~74% reduction) with no new rule: demurrage decays interest income the moment it's held idle (so a lender only grows by continuously re-lending = real intermediation), non-compounding inheritance dissolves the dynastic pile, and the full-reserve pool bound caps aggregate lending — top-1% ends at 4.1%, below start. A dedicated lending-concentration gate adds ~0% beyond the existing brakes — now shown on a binding dial (July 11, v4 D13e): the registered 2% cap never binds (max single-actor pool share 1.31%), so a probe re-ran the gate at 0.5%/1% caps that genuinely clip the biggest lenders — even binding in 30 of 50 years, the gate adds ≤0.62%. Recommendation (Freedom-consistent): no new cap — a concentration dashboard (monitor lending-share + interest-income concentration), revisit a gate only if the channel dominates. Defeater: LX3's net de-concentration is dial-dependent (inheritance-dissolution strength, demurrage rate); directions robust, magnitudes illustrative — hence 'monitor', not 'solved'. Both companions in the folder. (Dashboard now built: 01 Canon/Lending-Concentration Dashboard Spec v0.1 + working prototype HTML.)
EVE Sim v30 - Large Off-Ledger Issuer (July 10, 2026): red-teams the named open threat v28/SB5 deferred — a large, coordinated off-ledger issuer (the actor detection can't see and the governor can't freeze), with the transparency defense removed by assumption. All six bars (OL0–OL5) pass. Unchecked the threat is real (a thin, fully-accepted, coordinated issuer nearly quadruples broad money, OL1), but three EDEN-specific facts cap the realistic issuer < 1% of broad money: (OL2, the headline) the guaranteed floor is an unconditional outside option that removes the coercion channel historical scrip relied on — modeled wage-capture retention collapses 100%→~5% (the floor removes ~95% of coercive adoption; EDEN's anti-company-scrip); (OL3) the reach-vs-seigniorage dilemma — trusted (well-backed → no money creation) OR profitable (thin → no voluntary adoption), never both; the issuer would need to offer ~16%/yr to go systemic (a Ponzi); (OL4) no LoLR for shadows (§7) — a thin issuer collapses ~98% of the time in a plausible run, so run-stability forces near-full-reserve. Robustness: even if EVE were only mediocre money (convenience yield 0), the run-safe max is still ~2.2% — the defense rests on the note's intrinsic risk + run fragility, not solely on EVE's quality. Two irreducible residuals, named not buried (OL5): a coercive territorial sovereign (mandates its currency by force + blocks floor access — a secession/blockade problem, cross-link v20) and privacy-as-yield criminal use (opacity is the value — a law-enforcement, not money-supply, matter). Defeater (disclosed as a finding): voluntary demand alone does not bound the thin-reserve corner (leverage 1/r_s outruns the demand floor as r_s→0); what rules that corner out is run fragility — the defenses are layered, not redundant. Reuses v28's registered demand model verbatim (not re-tuned). Discharges Banking Spec §6's last ❓. Both companions in the folder.
EVE Sim v31 - Austerity Floor & Escrow (July 11, 2026, post-v4 evidence run): decision-support for DR-14's gate-20 re-ratification — after the committed v16 slices widened g* to straddle the adopted 50% floor, this cell swept austerity floor {0.45–0.60} × escrow depth {6, 9, 12 mo} jointly on the committed v6.8 engine (storm, both seeds; regression-anchored to the v16 slices exactly, AB0). All six bars pass; the two registered UNCERTAINs resolved negative, which is the finding: escrow is inert against austerity — identical breach profiles at every depth (it pays at exits; a staying-but-underpaying sponsor never trips it) — so the "≥50% + deeper escrow" candidate is dead, while 0.60 (and 0.55) hold delivery in both seeds (troughs 1.03–1.09; measured hold-line (0.50, 0.55]). Recommendation: re-ratify gate-20 at ≥0.60, escrow unchanged at its measured 6 months — escrow prices departures, the floor prices commitment. Zero printing in all 24 cells. Defeater: v16's dial-dependence inherited; escrow >12 mo unswept (zero gradient 6→12 stated, not extrapolated); underpay-then-exit composition lives in v6.8's storm cell, not here. Both companions in the folder.
EVE Sim v32 - Payer-Exit Re-balancing (July 11, 2026, post-v4 evidence run): resolves v20's countdown — what actually closes the $3.0066B/mo payer-exit hole, and what does the reserve buy time for? v20's mechanism replicated verbatim (not imported); deterministic. RB1 FAILED as pre-registered, and that's the finding: a slice-bump alone needs +80.2% of the remaining givers' burden vs the 6% political bar (13×over) — you cannot bill the survivors. The taper is the tool, and it's humane arithmetic: the subsidy is marginal (drawers self-fund 89.4%), so a 44.5% taper closes the whole gap at ~4.7pp of drawer delivery (0.953); the recommended mixed rule (6%-capped bump + 41.2% taper) lands at 0.956, never near the 0.894 never-joined baseline. RB4 quantifies the flagged 9-vs-24 reserve ratification: it's an 18-vs-48-month diplomacy budget — the slowest reserve-safe phase-in of the mixed rule is 18 months under the SPEC-registered $36B sizing vs 48 months under the committed $81.1B. Recommendation: ratify the reserve rule as an explicit phase-in budget, and write gate-22's pre-commitment as the mixed rule with a ramp ≤ the ratified window. Defeater: inherits every v20 dial; linear funding ramp, no renegotiation dynamics; 6% anchor imported, not re-derived. Both companions in the folder.
EVE Sim v33 - Index Drift (July 11, 2026, [OPUS] to registered spec): discharges Backlog #12 + EBI Methodology §5 — prices the 0.05 measurement-bias budget against a systematic ±0.5pp/yr EBI drift over 50 yr. Deterministic (two runs byte-identical). ID0 passes; ID1/ID2/ID3 FAIL exactly as registered (the findings); ID4 fails one clause honestly (a too-tight ±3-mo cross-seed tolerance on the exhaustion month — bar not moved, filed as F5). ID1 (headline): a one-directional under-read exhausts the fixed 0.05 budget in ~9.3 yr, breaches essentials at yr 19.1, and leaves the floor at 0.856 of essentials by yr 50 — a fixed budget cannot absorb a persistent one-sided drift (that is re-basing's job). ID2: the mirror over-read drains the $36M reserve in 2.5 yr while §5's instantaneous 5%-telemetry only lights at yr 9.8 — a level trigger watches the wrong quantity (cumulative draw empties a finite buffer before the instantaneous rate hits 5%). ID3 (actionable): the binding re-basing cadence is set by the reserve side (~2.5 yr), not the delivery side (~9–10 yr) — canon's 5-yr re-basing is delivery-safe but reserve-unsafe → recommend ≤2.5-yr correction or a cumulative-draw over-read telemetry. Defeater: reduced-form; prices normalized to EBI_true=1.0; exogenous perfectly-systematic wedge (noise covered, regime breaks not); a single $36M reserve absorbs all over-pay with no replenishment (conservative — real funding lengthens the 2.5-yr runway but not the asymmetry). Both companions in the folder. Verified byte-reproducing + gate-audited by Verification v5 (July 12; also by the July-11 fresh session).
EVE Sim v34 - Baumol Governor Drift (July 11, 2026, [OPUS] to registered spec): discharges the economics red-team's A10 (Baumol / cost disease) owed cell — over a century, does the mint governor tuned to aggregate productivity drift against the slow (care/essentials) sector and break the floor, funding, or price stability? Built on the v7 Horizon chassis; deterministic; two-sector split (fast 2.5%/yr vs slow 0.5%/yr). BM0/BM1/BM3 pass; BM2 and BM4 FAIL as findings (each refuting a pre-registered PASS in public). BM0 anchor: re-running the committed v7 engine reproduces its crossover (yr 64–65, both seeds); Baumol-OFF → zero drift. BM1: the aggregate-tuned governor inflates essentials to 3.74× vs 2.17× essentials-tuned (1.72× governor-choice drift) while its own aggregate gauge reads flat (cheap tech masks dear care). BM3 (load-bearing): slow/fast relative price rises 7.36× (exponential in the gap), and EDEN's essentials-indexed floor delivers a full 1.10× basket every month of the century (the indexed promise — an identity of the floor rule; realized self-funding coverage bottoms at ~12% pre-crossover, sponsor-backed until yr ~92 — v5 D6) where a naive aggregate-CPI floor (Boskin/A3) breaches 1.0 at yr 8.8 and collapses to 0.20× by yr 100 — indexing the floor to essentials, not a headline CPI, is what disarms Baumol for recipients. BM2 (informative FAIL): delivery protected and funding not starved, but Baumol delays the v7 generational-floor crossover from yr 46 (OFF) to yr 92 (ON). BM4 (constructive FAIL): essentials-indexing the governor cuts drift 62% but the c_min Exploration-Subsidy floor blocks full stability; pairing it with a post-bootstrap c_min sunset (both v7-anticipated) removes the drift entirely. Canon candidates: index the governor to the EBI + sunset c_min once machine-pay matures; keep the floor on essentials. Defeater: reduced-form (exogenous productivity; inherits the v5.1 funding-base mismatch at s_slow0=0.5; canon v1.4 no-print enforced after an early build reproduced v13.1's floor-print spiral, corrected & disclosed). Both companions in the folder. Fresh-session verify owed.
EVE Sim v35 - Corporate Wrapper & the Immortality Loophole (July 12, 2026, [FABLE] Fable 5, owner-directed): red-teams the single biggest un-modeled dynastic channel — EDEN's anti-dynasty brake runs on mortality (Legacy), and a corporation is an immortal legal person; canon had no corporate-ownership rule at all (corps appear only as machine-pay buyers). Extends the committed purchase-channel chassis (its four anchors re-run exactly in an isolated copy: 10.4/10.2/67.7/79.2); deterministic; seeds 7+11 agree ≤0.9pp; SPEC-before-code with one pre-code addendum (wage-offset θ). Eight bars PASS; CW4 FAILS its registered expectation as a finding — in the safe direction. CW1 (the threat): human-style corporate ownership → persistence 77.1%, above buyable-catalogs 67.7% and adjacent to today's 79.2% (offshore shares never meet succession; wrapper = 96% of top-decile wealth by gen 5). CW2 (the owner's synthesis closes it): contributor-anchor (§2a liveness — a corp can't pass it) + fixed commercial term (30yr) + bounded coordinator cut (25%) + time-limited revenue-share financing → 10.5% vs the 10.4% mobility line with the full attack battery on (runoff ~6.0%/yr > attack-boosted capture ~1.7%/yr — the wrapper decays into a firm that must keep buying living work). CW3: corp-as-heir +0.0pp (anchor mortality binds); nominee/kickback −0.1pp (attacker's best variant is the true-contributor kickback at 0.22 capture, defection-eroded); youngest-life +0.0pp (term binds first); term-laddering 1.07× ≤ 1.1 (reinvestment, not rent). CW4 (refuted expectation, the headline finding): no single dial reopens the loophole — c→0.80, T→100yr, s→0, κ→0.9, h→0.02 all leave persistence in 10.2–10.6%; the labeled stacked-extreme diagnostic (all five at worst simultaneously) compounds at just +0.6%/yr and reaches only 17.2% at 150yr — defense-in-depth, not a threshold. CW5 (Q2): corporate participation ≈ 66% of naive at reach m=2, 87% at m=3; the term is the participation price, the cut is a wage-split (θ-dependent — at θ=0.4 the index fails, pilot-measure it). CW6: permissive equity under the v29 stack holds 11.5% but only via negative carry (5% demurrage > 4% yield → large holders never join) — exclusion in market clothing; R2 dominates on (Q1,Q2). CW7 → gate candidate: the per-node royalty cap is shell-evadable 24.7× at 25 shells; beneficial-owner aggregation restores it exactly (the corporate rhyme of one-person-one-account). Recommendation + roads-not-taken in DR-18 (ratified July 18, 2026 — owner adopted the tested central configuration: T = 30 yr, cut ceiling 25%, beneficial-owner aggregation gate; the gate's discovery/enforcement layer is the owed successor — see the v36 candidate in 01 Canon/Corporate Onboarding, Owner Linkage & Entity Read-Transparency (Proposal v0.1)). Defeater: reduced-form (chassis caveats inherited; kickback is an expectation, not a strategic game; θ and defection h are pilot-measurable, not modeled facts). Both companions in the folder. Discharges the "corporate-wrapper cell" reference (Verification v5 D14).
EVE Sim v16 extension (July 11, 2026, Backlog #9, [OPUS]): with the v12/v13-oracle/v14 refactor (#8) done, v16 now sweeps those three layers through the same joint ±50% envelope (n=32, seeds 7+11, engines run as committed — new sweep_layers block; existing v16 leaves byte-identical, determinism re-confirmed). Envelope-robust: v12 R1–R4, v13-oracle O1/O2/O5, v14 X1/X3/X4 (the joint-cap fix holds 32/32). Two new dial-local findings, reported not hidden: v13-oracle O3-central dips to 0.9498 in 1/32 cells (~1.5× inflation, F6); v14's X2 "blast composes past the 2% gate" is dial-local (25/32, F7) — but X4's fix is robust regardless, so gate-18 is unaffected. g* densified to 0.01 resolution (reconciles v31 exactly; breach edge refined to g*∈(0.51,0.52], zero-months-below from g≥0.53 — ≥0.60 stands with ~8–9pp margin). FAIL-tier WTP sensitivity (red-team A9), the sharpest honest result: at anchors ÷10 ($60-world), EDEN's safety promises survive (sponsor-backed floor delivery 0 months below; cheaper-than-welfare ratio WTP-invariant at 0.785) but its builder-economy/self-funding promises break (median builder $420→$45/mo; share clearing $200/mo 88%→3%; endogenous floor coverage ~13%→7%) — the data-valuation gap made quantitative: what's WTP-fragile is exactly what the pending field experiment (H1) must settle. Both companions updated.
EVE Sim v36 - Owner Linkage & Entity Read-Transparency (July 18, 2026, [FABLE] Fable 5, owner-directed): discharges the enforcement layer DR-18's ratified beneficial-owner aggregation gate assumes — how does EDEN ever learn who owns what? Tests the owner's no-link-no-payout proposal (01 Canon/Corporate Onboarding, Owner Linkage & Entity Read-Transparency (Proposal v0.1)) plus its severable read-transparency half. Extends v35 (isolated re-run exact: CW2 10.5, CW7 24.67; chassis re-implementation RNG-order-identical, equal to the committed values; three engine runs byte-identical incl. the committed vault run). Five bars PASS; OL1 FAILS as its registered safe-to-refute expectation — the finding; OL5 FAILS by design, triggering the pre-committed severance. OL1/F1 (headline): the payout-gate alone (L1, the proposal as filed) is decorative against whales — park streams in unlinked shells and consume through the entities at 9.46× the full-information cap (η-linear, 5.7–18.1×), audit-immune by construction (no links to flag). F2 (the recipe): the strong form works — link-to-coordinate (L2: no human-rooted link, no streams at all) + links-as-title (the link IS the ownership record; a defecting nominee keeps the shell) + provenance-anomaly audit brings 24.7× blind evasion to 1.20× at the central audit hazard, boundary a_n* = 0.172/yr; revocable links re-open evasion 4.3–14.1× and are un-auditable into compliance (a_n* = 0.677/yr); nominee-overhead f_n = 0.10 or κ_L = 0.9 alone also close it (1.0×). F3: disclosure is a cliff, not a slope — 11.6% of owners (69.3% of booked flow) evade in every cell at central, and coverage snaps to 1.0 the moment the best evasion net crosses zero: overshoot the boundary, don't sit at it. F4 (OL2): wiring the equilibrium into the committed R2 chassis moves persistence −0.1/0.0pp (stress arm with 1.7× v35's kickback capture: 10.4%) — cap enforcement and dynasty defense are independent walls; v35's defense-in-depth holds in the linkage era. F5 (OL3): one-hop aggregation is shell-theater (depth ≥ 2 restores the full 24.67×); transitive closure to human roots holds 1.0× at every depth ≤ 5 — the closure semantics must be written into the gate. F6 (OL4): disclosure costs ~6pp of relative participation (0.657 → 0.597 at central, above the 0.5568 bar; regression to v35 exact at d=0); the θ warning compounds — at θ=0.4 the whole row fails; d_med joins θ and h on the pilot list. F7 (OL5): entity read-logging severed as pre-committed — 4.5% of entity query value stays attributable at central mirror cost (24% of entities, but the value evades; proxies below p_c=1 take it to 0) — while the meaningful two-way street already exists: every paid query is a public machine-pay transaction under A5; free reads of public state are unmeterable. Defeater: reduced-form (independent best responses; hazard-rate audit/defection, not games; κ_L a price not a market; n_max exogenous — at 100 shells L1 reaches 34.4×; a_n unknowable from a desk — the 0.172/yr boundary is the deliverable, and pricing an audit that achieves it is v12-class successor work; diamonds/multi-root graphs out of scope). Recommendation + roads-not-taken in DR-19 (PROPOSED). Both companions in the folder.
EVE Sim v37 - Exfiltration & the Stale-Copy Economy (July 18, 2026, [FABLE] Fable 5, owner-directed): discharges the owner's two July-18 questions as one system — (A) the pay-once-copy-forever exfiltration attack (confirmed unmodeled anywhere by a full-vault sweep) and (B) seller-set pricing + a non-waivable minimum rate against outside price pressure. Builder-economy chassis = a two-point transfer function anchored exactly on the committed v16 WTP endpoints (μ=1.0 → $426.65/0.8854/0.1323; μ=0.1 → $45.30/0.0277/0.0717 — full-precision post the VERIFICATION v6 D1 transcription correction); engine runs byte-identical incl. the committed vault run (re-verified in isolation by v6). 9/9 bars PASS; XF7(a) = the registered safe-to-refute expectation confirmed as the finding. XF1 (threat): copying a full corpus costs 1.6% of its living-stream value at central reuse (0.16% for the most-reused crown jewels) — and the §2b usage-decay ladder makes the most valuable data the cheapest to steal. XF2 (custody): K2 compute-to-data with a per-buyer convex egress budget makes full-corpus reconstruction cost 509.9× an honest subscription (173–5527× across budget steepness β; 53–8438× across reconstruction efficiency). XF3 (freshness boundary): stolen-copy value ÷ fresh-subscription value = market 0.14%, behavioral 7.2% (K1 export-license suffices — the copy rots) vs genomics 84.5% (only K2 holds); custody boundary τ* = 4.35 yr. XF4 (economy): the K1/K2 stack holds the effective-WTP multiplier at 1.00 ($426/mo builder economy) vs 0.16 ($73/mo, toward the $60-world) unprotected — exfiltration is the mechanism that produces the v16 collapse. XF5: K2 barely deters legitimate buyers (90.1% participation retained — their counterfactual is scraped/synthetic junk). XF6 (pricing): without the floor the clearing price collapses to 4.8% of the revenue-optimal reserve under supply abundance, 90% would undersell a waivable floor (non-waivability = collective bargaining, the A2 rhyme), and the computed F* sits ~13.5× canon's conservative 1e-4 (the deliverable is the calibration method vs the pilot's WTP, not the number); the fair rate should be published, never a binding oracle (v13/v23 capture). XF7 (the synthesis): a floor alone raises the thief's resale margin (theft profit rises with the honest price) — pricing without custody is counterproductive; F* + K2 drives resale margins negative at every floor level and holds XF2/XF4 jointly. Defeater: two-point reduced-form transfer function (v16 caveats inherited; interpolation error between endpoints); info-theory-flavored leak model (φ_r a dial, not measured ML extraction); F* computed on the theoretical lognormal WTP whose median is an assumption — number moves with pilot data, only the method + interior-optimum are claimed; analog hole out of scope; buyer-side collusion bounded by the DR-19 aggregation assumption, not re-simulated. Recommendation + roads-not-taken in DR-20 (PROPOSED). Both companions in the folder.
EVE Sim v38 - Multi-Root Ownership & the Intermediated Float (July 18, 2026, [FABLE] Fable 5, owner-directed): discharges v36's named out-of-scope successor (multi-root/diamond ownership graphs) and the public-float Backlog row — how does DR-19's "closure to human roots" handle public companies, index funds, and pensions? Per the v36 precedent the closure variants were registered side by side and the pre-registered bars picked (the sim as decision instrument). Anchors exact (committed v36 re-run in isolation with its full chain → v35 → multigen: 1.197/0.1723/24.67; pool 24.67/0.00055; chassis 10.5; participation 0.6568); three byte-identical runs incl. the committed vault run. 8/8 bars PASS; MR3's registered expectations confirmed. MR1 (threat): the v36 shell game at public scale — control of 25 entities assembled from sub-threshold nominee pieces (6 × 4.9% each), exercised through revocable officer-nominees → 11.14× the single cap on-ledger (+ a 16.1× off-protocol residual routed to the KYC'd bridge). F2 (the design discovery): officer links must be title-class — with deed semantics at the control layer the empire channel closes at a_c* = 0.0 (piece-assembly costs + officer title-risk do all the work; no empire detection needed for the on-ledger channel); revocable officers need 0.162/yr to compensate. MR3 (the fork): T terminate-at-QI FAILS evasion (fund-washing: one captured sham fund per entity → 3.335× central, 7.15× at weak institutional audit — safety-by-assumption); L full look-through FAILS participation (holder-graph exposure → 0.412 vs the 0.5568 bar); H threshold look-through PASSES both (1.000× / 0.597, ≥0.532 at 2× disclosure aversion). F4: termination re-roots aggregation, never breaks it — one fund holding many entities collapses to one cap; fund-washing needs one sham fund per entity, which is why it's expensive. MR4: θ trade interior (pieces 30/6/3 across θ=1/5/10%) with the honest caveat that the stated holder distribution understates real institutional concentration — θ = 5% now, pilot-calibrated later. MR5 (scope boundary, severance pattern): wolf packs of genuine humans multiply 0.0 — concert is governance/market-power territory (v15/v17), and behavioral aggregation of persons is §6.5-barred. MR6: worst-arm capture (0.578) into the committed v35 chassis: 10.3/10.0 (−0.2/−0.5pp) — fourth consecutive defense-in-depth confirmation. Defeater: control is a threshold event, not a voting model; officer-nominee/empire/QI economics are hazard-rate dials (committed v36 forms), not games; a_c and a_QI are unpriced design candidates (boundaries are the deliverables; audit-economics remains the v12-class successor); holder distribution stylized; legal-layer disposition of the off-protocol residual asserted, not modeled. Recommendation + roads-not-taken in DR-21 (PROPOSED). Both companions in the folder (PL jargon-compliant from birth per the July-18 house rule).
EVE Sim v39 - The Whistle Market (July 18, 2026, [FABLE] Fable 5, owner-directed): discharges the v39 candidate from 01 Canon/The Accountability Commons & the Whistle Market (Proposal v0.1) — can EDEN's rails (bonds, sortition juries, provenance, permanence, pseudonymity) compose into a conduct-claims market about outside entities that separates: truth profitable, lies ruinous? Two owner refinements registered as structure: certified capture splits jury error (authenticity → ~0, interpretation remains) and the anonymity set is the discloser's real protection (the platform never confirms accounts). Anchors loaded from committed results_v7.json at runtime, sha256-recorded (the VERIFICATION v6 D1 pattern — no transcribed constants); three byte-identical runs incl. the committed vault run. 5/7 bars PASS; WB3/WB4 FAIL as refuted registered expectations — both in the robust direction. WB1 (load-bearing): the separating region covers 54.6% of the (bond, bounty) grid; central point EV_true +0.070 / EV_false −1.600; tolerance to interpretation error up to ε* = 0.639. WB2: flooding self-bankrupts (−1.60/claim); extortion threats empty; short-and-distort confirmed irreducible — off-protocol position size invisible by construction, bounded only by adjudication speed (the securities-law handoff). F3 (refuted): certified capture is not the existence condition — even the stressed uncertified market separates; certification is the armor (kills the authenticity discount, widens the region, insures against improving AI forgery). F4 (refuted, sharper): at central bonds, sponsors strictly hurt (halve bounty vs unchanged fear; k* 7→10) — their value appears only at high bonds where they resurrect priced-out disclosers (None→11): keep bonds low. F5: k* = 7 central / 2 cheap retaliation / 32 ruinous / 19 punish-them-all; ~55% of the modeled discloser population clears the bar — and all of it works only because the platform cannot confirm accounts (account-silence = the market's security floor, proposed constitutional-class). Defeater: jury error, retaliation, forgery, price-impact are dials, not facts; content-based unmasking modeled honestly as suspicion over the knower-set; platform legal exposure is a scenario (→ PRE-MORTEM obituary #7, added same day); "best whistleblowing tool" was not a bar and is not a conclusion. Recommendation + roads-not-taken in DR-22 (PROPOSED). Both companions in the folder.