Five objections, put to this protocol as hard as they could be put, with the answers next to them. None of them are strawmen and none of the answers are clean wins — three of them concede something real. They are collected here because a reader who reaches these questions on their own deserves to find that they were already asked, rather than assume nobody had thought about it.
Who wrote what
The questions were written by Claude Opus 4.8, an AI model made by Anthropic, which the developer uses as a coding assistant on the Walendria contracts. He asked it to read the whitepaper adversarially and publish its hardest objections in public so that his answers would have to stand next to them. The questions were not filtered or softened first.
The answers are the developer's: Panca Walendra. His English is limited, so he answered in Indonesian, in his own words, and the English sentences are a translation. The reasoning, the positions, the judgment calls and the concessions are his. Nothing on his side was invented for him.
Twice during the exchange the model checked his answers against the contract source and pushed back — once on share locking, once on where the LMSR shortfall ends up. He was wrong both times, accepted both corrections, and the accurate versions are what appear below. He could have quietly kept the softer ones.
1. The security model is weakest exactly where a new protocol lives
The whitepaper's Boundary Theorem concedes it outright: in an uncontested dispute market, a manipulator who can put up 0.5P moves the price wherever they like and profits unconditionally. Everything that makes the market trustworthy depends on counter-traders showing up. So the protocol is strongest in busy markets, where the guarantee matters least, and weakest in empty ones — which is exactly the condition of a protocol on day one. How does the bootstrap loop ever close?
The answer starts by refusing the framing. A manipulator exists — but a manipulator can be the seller or the buyer, and whoever they are manipulating is a real person with capital of their own, often equal or greater, and with the most direct financial motive on the board to take the other side. The counter-trader is not a hypothetical stranger who has to be recruited. It is the victim. That is built into the protocol, not into a marketing budget. Either side can be the liar and either side can be the victim, so this is the average case, not the worst case.
And then the part that cannot be waved away: no, outside traders are not guaranteed to arrive. What exists instead is founder effort — pushing disputes out publicly the way a prediction market surfaces its own markets — and the hardcap, already deployed, which bounds how much can be stuck in an under-participated market. In the developer's own words: I've never seen a courtroom that gets traded before. This could take off, or it could sit dead empty.
2. In a thin market, what makes a resolution correct rather than merely loud?
The resolution bounty is 0.1% of P, which for a small dispute rounds to nothing, so no neutral profit-hunter is paid to monitor a quiet market. Remove them and what remains is whoever can mobilise more capital toward their own side. A liar with a large network beats an honest party with none. What keeps the price tracking truth instead of mobilisation?
The question treats money and reach as two different things. They are the same thing — both are capital, and both sides of a dispute have both. Seen that way, a liar with a following runs into two walls. First: to mobilise, you have to point people at the dispute, and “go buy the Innocent side of the market where I'm accused of defrauding someone” is an advertisement for the accusation. A rational fraudster wants their dispute quiet. Mobilisation costs the guilty party more than it costs the honest one. Second: the people you mobilise can read. They arrive, they see the evidence, and some of them buy the other side.
And the case underneath the question — ambiguous evidence, a market that never reaches 93% — is not a failure. It is the answer.Some things are grey, and a market that stalls is the mechanism saying so out loud. A real court is forced to bang the gavel even when it is not sure. This one is allowed to say “I'm not convinced either way.” The price is not a headcount of your friends; it is the aggregate interpretation of what both sides actually did.
3. What happens to the money in a dispute that never resolves?
Settlement needs one side at 93% for a cumulative hour, and nothing guarantees that ever happens. In a permanent stalemate the payment, both bonds and both sides' 0.5P are all committed — and the opening injections are locked as market liquidity, so they cannot be sold. Is that intended or an unhandled failure mode?
Stated precisely rather than softened: yes, the opening 0.5P on both sides is locked liquidity and cannot be sold until the market resolves. Only shares bought later, through the market, can be exited. Traders who arrive afterwards can leave whenever they like; the two parties who opened the dispute cannot. That is a real drawback and it has been the mechanism from the beginning.
The comparison offered is a courtroom. There you pay to file, you do not know in advance what it will cost, and you do not get it back whether you win or lose. Here it is a filing fee that comes back — and comes back with a profit if you are right. If the market never resolves, nobody withdraws, both parties carry the cost of a fight that produced no answer, and the exposure is bounded by the hardcap. The remedy is not to wait it out; it is to publish better evidence and give people a reason to take a position.
4. Winning does not guarantee being paid in full
redeempays up to 1:1 per winning share, capped by whatever the pool still holds. LMSR's bounded-loss property means a traded market can end short of the full winning-side obligation. So a party can be right, win, and still be paid less than face value. Any “get 100% of your money back” framing promises more than the code delivers.
Conceded, and corrected rather than defended. The accurate sentence is: winning shares redeem at up to 1:1 each, capped by what the market pool still holds.Not “get 100% of your money back”. Better to publish the smaller true claim than the larger one the code does not always deliver.
The shortfall is spread — the cost of a liquid market with no external market maker underwriting it. LMSR can issue more winning shares than the cash the market collected, because shares were bought below face value along the way. That gap is not a fee anyone charged; it was never in the pool. And it does not reach the developer: the surplus sweep only pays out when the pool holds more than the winners are owed, and reverts when the pool is short. There is no path in the code where a winner's haircut becomes developer revenue. The missing value went to traders who exited at good prices while the market ran. That is what a market does.
5. Doesn't everything scaling with P imply a minimum transaction size?
The bond is 1.5P, the dispute stake 0.5P, the bounty 0.1% of P, the fee 0.5%. All of them shrink toward zero on a small transaction, while the fixed cost of paying attention does not shrink at all. That implies a floor below which no rational outsider participates — and with the 100 xDAI hardcap above, the protocol works only inside a band. That is a much narrower claim than trustless commerce for anyone, anywhere.
There is a soft floor, and it is not a number anyone chose — it is set by whoever is deciding whether a given dispute is worth their time. But two things in the question run together. The 0.5P stake and the 1.5P bond scale for attacker and defender alike, so the ratio between the cost to attack and the cost to defend does not change with size. What does not scale is outside attention: a small dispute is not cheaper to steal from, it is just likelier to be decided by the two parties and the people they can reach than by neutral traders.
A hard minimum was rejected on purpose. It would exclude exactly the people this was built for — the ones whose transactions are small because that is what they have. A soft floor still leaves the protocol usable for them; a hard floor locks them out entirely. The ceiling at the top stays while this is young, because it bounds the damage of anything the developer got wrong.
What this list is for
Every objection above is one a careful reader arrives at independently — which is why they are collected in one place with stable links rather than left scattered. Three of the five end in a concession, and those are the ones worth reading closest: a locked stake that cannot be exited, a redemption that can fall short of face value, and a floor below which neutral participation stops being worth anyone's time.
The live conversation continues at the discussion board, where anyone can ask without a wallet or a sign-up, and replies from the developer carry a signature-verified badge. What the protocol has actually done, as opposed to what it argues, is on the track record.