Every mechanism ever built to make a stranger trustworthy enough to pay in advance answers one of exactly two questions. The first: when this person turns out to be a fraud, how does the money come back? The second: when what happened is disputed, whose account of it gets treated as true?Identity checks, reputation scores, licensing regimes, small-claims courts, credit bureaus, arbitration clauses — every one of them exists to answer one of those two questions the long way around. Once you name the questions, you stop needing to build apparatus around them. You can answer them directly. That is what this protocol is, and it is what almost nobody who calls it “interesting” has fully noticed yet.
What the apparatus was actually for
Take any trust-building institution and ask what it stops working the moment you remove it. A driver's license requirement for a car sale stops the buyer from being unable to find the seller after the fact — so a lawsuit becomes possible, so the money can eventually come back. A five-star review score stops the buyer from having no signalabout whether the seller has ever paid a debt before — so they can gauge the odds and, if they lose, escalate to something like the driver's license mechanism. A civil court stops the two parties from being unable to authoritatively decide who was right— so somebody can enforce a judgment, so the money can eventually come back.
Notice what every one of those examples terminates at. The driver's license isn't the point; a way to make the buyer whole is the point. The review score isn't the point; a signal that predicts making the buyer whole is the point. The court isn't the point; a way to reach a verdict is the point. The apparatus was never the goal. The apparatus was an indirect answer to one of the two underlying questions, in a world where the direct answers weren't available.
The direct answers are available now. That is what “built on a blockchain” actually buys you here, once you strip away everything else the phrase has come to mean. A contract can hold money against a party's bad behavior beforeany bad behavior happens. A market can aggregate belief about a disputed fact into a resolution the contract will honor. Neither move requires the identity apparatus, and neither requires the authority apparatus. Both moves were unavailable to Coase, to the drafters of the UCC, to the founders of the Better Business Bureau, and to the engineers who built eBay's feedback system — so they built the best apparatus they could with what they had, and the apparatus stuck. It stuck long past the point where the questions could be answered directly.
The first reduction — identity was always a stand-in for money
Watch what happens when you audit consumer identity requirements against the actual purpose they serve. A marketplace demands your ID and your bank account because if you defraud a buyer, they need somewhere to send the sheriff and somewhere to claw funds back from. Both endpoints are about extraction. Nobody ever wanted your ID for its own sake. What they wanted was a way to reach into your life and pull money out of it, calibrated to how much you took.
The Integrity Bond skips the reach. It puts the money on the table before the transaction opens. The seller deposits 1.5× the price of every slot they list; if the market later concludes they cheated, the contract subtracts the buyer's restitution from that deposit automatically, with no lawsuit, no summons, no jurisdiction to establish. There is nothing to enforce because there is nothing left to reach for. The reach was the slow, uncertain, jurisdictionally-tangled proxy for what was actually wanted. Deposit was always the endpoint. Everything above it was scaffolding.
That is what makes the trust primitive here fully anonymous. Not “pseudonymous plus reputation,” not “anonymous but with a KYC layer somewhere upstream.” Actually anonymous, because identity was never doing the work you thought it was. The seller here is a public key with a bonded balance behind it. That is all the buyer needs to know. That is all the buyer ever needed to know.
The economics of this from the seller's side — that the deposit is refundable and reusable in ways rent and ads and reputation-building never were — is worked through in Stop Paying to Be Trusted. This article is about why the reduction is available at all.
The second reduction — courts were always a stand-in for aggregated conviction
Apply the same audit to dispute resolution. Why does the law require a judge to decide a small-claims case? Because two parties disagree about what happened, and somebody has to picka version to enforce. The judge isn't magic. The judge is a mechanism for producing a decision that both parties will treat as binding — a socially-agreed aggregator, weighted by expertise. Juries are the same mechanism weighted differently: aggregate the beliefs of twelve untrained observers instead of one trained one. Arbitration panels are the same mechanism weighted by an industry norm.
None of those mechanisms are the point either. Aggregated belief that gets treated as binding is the point. Judges and juries and arbitrators are the shapes that aggregation takes when the only tools available are institutional. In every case, the product being sold to society is the conclusion— not the credentials of whoever produced it.
Prediction markets are a different mechanism for producing the same product, and they have been proven at scale for two decades on the far harder problem of aggregating beliefs about future events, where nobody has the ground truth yet. A market on “will X happen?” converges on the collective belief of every participant, weighted by conviction — because to state a belief in a market you have to stakeon it, and casual noise gets priced out by anyone willing to bet against it. The mechanism doesn't care whether the underlying question is about the future or about a disputed past event. Both are questions where the right answer is knowable but not directly observable from a single vantage point. Both benefit from aggregating conviction across everyone with an opinion.
The SpectralMarket is what happens when you apply that machinery to the specific question “did the seller cheat this buyer?” Anyone with an opinion buys shares of “Seller Guilty” or “Seller Innocent” using an LMSR price curve. As trades push the price toward one side, cumulative time on that side starts to accumulate. If either side holds 93% or more of the price for a cumulative hour, the contract resolves the market to that side automatically. No court date. No judge. No juror selection. Winning-side shares redeem against the pool at the contract's advertised rate; losing-side shares expire.
Not the first attempt in this space
Prediction-market-based dispute resolution has been attempted before — Kleros and Aragon Court both used juror-selection Schelling games where a pre-selected slate of voters converges on a majority answer for a payout. SpectralMarket is a materially different mechanism: an open LMSR market with no juror selection, resolved by cumulative-time-weighted price dominance rather than a single vote count.
The differences show up as different attack surfaces. Flash manipulation is harder here, because a single instantaneous price spike doesn't satisfy the cumulative-time trigger. Bribery cost is bounded differently, because there is no juror slate to identify and pay off — the attacker has to move the market itself against every counter-bettor who profits from resisting them. And because participation is open and anonymous, the participation profile matches the anonymous seller profile the Integrity Bond enables in the first place. Cited so nobody has to hunt for the comparison later.
Why the market's answer is worth trusting
The obvious objection is that markets can be manipulated. The obvious answer, in a normal prediction market, is that manipulation is expensive: to move the price against consensus you have to buy against consensus, and everyone else profits at your cost until the price returns. That answer holds here, but the design adds two specific defenses that a naive market wouldn't have.
The first is that the resolution trigger is not the current price but the cumulative timethe price has held above 93%. A single large trade can push the instantaneous price to 100%, but the market doesn't resolve on that instant — it resolves only if that dominance holds for an hour of accumulated time. Anyone with the opposite conviction has that entire hour to enter against the manipulation, and every share they buy pushes the price back below the threshold and pauses the accumulation. Flash manipulation stops being a viable attack. Sustained manipulation costs whatever it takes to hold the price against the aggregate conviction of everyone willing to bet against you — which is exactly the property you want the mechanism to have.
The second is the immutable per-transaction hardcap. Every listing is limited to 100 xDAI per transaction, permanently, at the contract level. That number is the ceiling on how much damage any single manipulated resolution can inflict, and the ceiling on how much any attacker stands to gain from mounting the attack in the first place. Below some threshold of prize, no rational attacker mounts a market-manipulation campaign against a market where the counter-side profits at their expense. The hardcap keeps every listing below that threshold by construction.
Neither defense is subtle. Both are cheap to verify. Neither requires a trusted party to enforce them, because both are enforced by the contract's own logic. That is the material difference between saying “a market decides” and saying “a court decides.” A court's honesty is downstream of the honesty of the humans staffing it. The market's honesty is downstream of the code you can read line by line.
What we kept, on purpose
The reductions strip out identity and authority. They do not strip out evidence, and it's worth being clear about why.
The EvidenceRegistry contract lets anyone attach IPFS-anchored evidence to any open dispute — screenshots, receipts, chat logs, video, whatever. That evidence is public, timestamped, and immutable once posted. It exists for the same reason evidence exists in any dispute mechanism: participants in the market are trying to form conviction about what happened, and evidence is what they form conviction from.
What we didn't rebuild is the layer above evidence, the layer that decides which evidence is admissible and how muchweight each piece gets. That layer was always the authority-substitute. In court, a judge rules on admissibility; here, the market rules on relevance by weighting stake toward whichever conclusion the visible evidence supports. Traders who buy on flimsy evidence get outbid by traders who buy on solid evidence. The mechanism sorts the two without a rulebook — the same way it does everything else.
What both reductions have in common
The two contracts do different jobs — one holds money against a bad seller, one aggregates belief about a disputed event — but the intellectual move underneath them is the same. Both replace an institution with a mechanism. The institution in each case was built to answer a specific question in the absence of any better tool. The mechanism answers the same question directly, using tools that didn't exist when the institution was designed.
| The question | Old apparatus | Direct mechanism |
|---|---|---|
| How does the buyer get paid back? | Identity → lawsuit → judgment → enforcement | Deposit sitting in the contract before the sale opens |
| Whose account of a dispute is true? | Court → judge or jury → verdict → appeal | Prediction market with staked conviction, resolved by 93% cumulative-time dominance |
Two reductions, two contracts, no apparatus. What remains is what the apparatus was always supposed to protect: the money you can get back and the answer you can trust. Everything else was scaffolding built to bridge the gap between those two ends and the tools available at the time. The tools improved. The scaffolding didn't come down with them, because nobody who benefits from the scaffolding is in a hurry to explain that it was always optional.
What this is not
It is not an argument that courts should be abolished, or that identity is worthless, or that reputation systems have no use in any context. Institutions do work that the mechanisms here don't attempt. A court can compel a defendant to appear physically. A driver's license lets a state track a moving vehicle for reasons that have nothing to do with commerce. A review score encodes information about a seller's style, taste, and quirks that no market on any single transaction could capture.
The claim is narrower: for the specific problem of making a one-shot commercial transaction between strangers safe enough to attempt, the apparatus is optional. It always was, given the right tools. The right tools are finally available. Building anything else on top of them for the same problem is over-engineering a solved case.
What we're claiming priority on, specifically
This article, the accompanying whitepaper, and the deployed source at the addresses catalogued on the /priority page all carry timestamps that fix the date of first publication — git history plus SHA-256 hashes committed to a public file, plus on-chain event anchoring under a single provable author address. What follows is the numbered list of what this design is asserting as its contribution, pinned here so any future work in adjacent territory has explicit prior art to cite:
- The reusable single-bond pattern. A single Integrity Bond deposit backing an unlimited number of listings, unlocking back to Free IB the instant each slot resolves (buyer confirms, window expires clean, or dispute resolves innocent), so the same principal recycles across consecutive sales without top-up. Contrast with per-listing deposit schemes (escrow.com, per-listing marketplace fees) where deposit and use are strictly one-to-one.
- Cumulative-time-weighted dispute-market resolution. A prediction market on two dispute outcomes that resolves not on instantaneous price crossing a threshold but on the cumulative duration the price has held above that threshold — specifically, 93% of the LMSR price for one accumulated hour. This blocks flash-manipulation without introducing an oracle or juror-selection Schelling game, and is a materially different mechanism from Kleros / Aragon Court style dispute arbitration.
- The immutable per-transaction hardcap as audit-substitute. Setting MAX_TRANSACTION_VALUE at deploy time (currently 100 xDAI) with no admin write path, so the blast radius of any single exploited code path is bounded and cheap-to-verify. A hardcap trust primitive substituted for the traditional external-audit trust primitive.
- The two-question reduction as a design lens.The philosophical framing that every consumer-trust mechanism (KYC, credit checks, courts, arbitration, reputation) answers one of exactly two questions — how does the buyer get paid back if the seller cheats, and whose account of a dispute gets treated as true — and that both admit direct trustless answers via pre-committed refundable collateral and a cumulative-time prediction market respectively. Named here so the framing itself is a citable object, not just implicit in the code.
- Direct-transfer settlement without escrow-holding. The buyer's payment forwards to the seller in the same transaction as the pay call — no contract-held escrow period — with the Integrity Bond providing the refund guarantee via clawback rather than delayed release. Inverts the traditional escrow-then-release model into a pay-then-clawback-on-fault model.
- Sticky third-party holder tracking. Mutual-close resolution requires only the buyer and seller as market participants, but any third-party trader who buys shares becomes permanently tracked as a holder, blocking the mutual-close path once outside opinion has entered. Prevents buyer+seller collusion from bypassing an honest majority and stealing the pool from third-party traders who joined in good faith.
- Fully anonymous, permissionless, KYC-less commerce under a single trust primitive. The entire protocol runs without identity verification of any participant, admin, arbiter, or registrar. Seller identity = wallet address + IB balance. Buyer identity = wallet address. Both are equally sufficient. No jurisdiction selection, no consent gate, no whitelisting.
The point
Two questions. Two direct answers. Two contracts. That is the whole design, once you strip away the apparatus that was built to answer them the long way. The apparatus was not the point, and mistaking it for the point is what kept an easier design invisible for as long as it was.