EconomyFindings
Cognition Market Threat Model
What a finding sale puts at risk, who it trusts, how it is attacked, and which residuals the market prices instead.
Scope of the model
Assets at stake
The register names eight assets, A1 through A8. S2 and X2 each affect more than one and remain open.
- A1, finding content. The sealed payload: confidentiality until the paid reveal, integrity against substitution.
- A2, buyer funds. No capture without a kernel-attested reveal of the finding's committed digest. An Allow proves kernel acceptance of the preimage, not that the buyer received or retained the bytes.
- A3, seller bond. No slash without a predeclared, evidence-gated rule.
- A4, market truthfulness. Listings, evidence bundles, and status feeds mean what they claim.
- A5, buyer memory and state. Purchased content must not poison the buying agent's memory beyond what its ingestion policy allows.
- A6, reputation capital. Scorecards and tiers must not be inflatable below the cost of honest behavior.
- A7, encumbered collateral and fee pools. One live bond allocation cannot back several listings or challenges, finalized fraud exposure cannot outrun remaining slashable collateral, and participation or dispute fees cannot be spent before they are collected.
- A8, financial terminal state. Every failure, timeout, mismatch, appeal, release, refund, compensation, and restitution path must be signed, replay-stable, and bound to the same purchase and payment evidence.
Trust roles
The market adds no new cryptography. It adds five trust roles on top of the inherited assumptions that the kernel is the trusted computing base, that the audited assumption registry holds, and that guarantee levels and evidence classes are truthful or the record is rejected.
| Role | Trusted party | What it is trusted for, and where the trust stops |
|---|---|---|
T1 | The mediating kernel | Sees revealed content. A designed-in trusted third party, not an oversight. |
T2 | The finding-status feed operator | Liveness and completeness of voluntary and cross-operator retractions. Root authenticity, equivocation, and staleness stay checkable through signatures, freshness windows, and anchoring, but a fresh root cannot prove the operator included every authenticated intent. |
T3 | The adjudication roster | Disputes a mechanical check cannot settle. Digest mismatch, evidence re-verification, and deterministic replay narrow what this role decides. |
T4 | The crypto-context signer | Reserved. The finding profile defines no canonical predicate carrier and binds no capsule or report digest into chio.finding.v1, so no hidden-predicate claim is admissible and this role decides nothing in the current profile. |
T5 | The challenge settlement operator | Deriving and enforcing the harmed-party destination allowlist from frozen purchase records. Its signed enforcement authorization makes the decision attributable and replay-stable; the bond-vault contract checks only distribution shape, beneficiary count, amount bounds, and exact-sum shares. |
T1 is the one worth stating twice. Chio builds a signature from the exact output preimage, so the kernel that mediates a read_finding call necessarily observes the plaintext it signs a receipt for. Within one operator that is the existing trust model. Across organizations, the mediating operator learns the findings it delivers. A separately qualified measured-runtime deployment can shrink who else sees the plaintext, and the kernel still sees it. The current TDX backend compares no runtime measurement against an allowlist and ships no full vendor-attestation stack, so neither piece carries a blanket confidentiality claim.
T4 is reserved rather than operating. Because the profile pins no predicate, admission treats descriptor fields such as outcome_class as public assertions backed only by the declared evidence class, and the buyer proof boundary rejects hidden range predicates. Admitting a hidden-predicate claim would first require a schema version that binds the canonical predicate and capsule digest, pins the signer and proof profile, and has the buyer verifier resolve and validate that exact proof without upgrading its guarantee.
Adversary categories
The catalog uses five categories:
- Seller. Wants payment for worthless, fabricated, stale, or stolen findings.
- Buyer. Wants the finding without paying, or wants to damage sellers.
- Colluding ring. Seller and buyer pairs, seller and challenger pairs, or sybil clusters gaming reputation, adjudication, and price signals.
- Market operator. Rational-but-greedy or compromised: front-running, leaking, censoring, equivocating.
- Observer. An outside party mining listings, receipts, and lineage for competitive intelligence.
C1 covers the sybil case and O1 covers an operator acting with a seller.
Attack catalog
The catalog runs S1 to S9 on the seller side, B1 to B5 on the buyer side, C1 to C4 for collusion and sybils, O1 to O5 at the operator level, and X1 and X2 for observers. The rows below are the ones a single finding sale turns on. Each disposition records the mechanism in force and what it leaves behind.
Where integrity checking stops
verify_finding proves that a finding is structurally strict, content-addressed to its own digest, and signed by the inline issuer. It does not authenticate evidence or liveness, validate bond or status references, enforce reveal delivery or settlement, or run challenges. A listing advertised as verified requires an explicit FindingEvidenceVerifier profile, which returns a facet report with distinct integrity, evidence, metered-exposure, settled-spend, intent, collateral, and liveness results. A missing facet fails the policy that requires it and is never silently upgraded.| ID | Attack | Disposition |
|---|---|---|
S1 | Fabricated evidence bundle | The evidence verifier re-verifies receipt bodies and signatures, checkpoint inclusion, trusted-kernel and revocation state, receipt attribution, the separate issuer-signed seller authorization, guarantee class, and liveness, fail-closed. An enforced fraud outcome maps to the frozen v1 FraudulentListing class and carries exactly one External reference to the signed chio.finding.challenge-outcome.v1. Residual: audited trust in the kernel, checkpoint, and issuer key set, and in the evidence resolver. |
S2 | Honest-cost fabrication | Open for metered_attested findings: metering proves compute was spent, not that it produced a relevant result. The market allocates the residual to the bond, the guarantee-class discount, and reputation, and claims no proof. |
S3 | Bait-and-switch payload | The delivery contract refuses an Allow receipt unless the final output hash equals its token constraint, and admission selects exactly one grant with exactly one OutputDigestSha256 value, persisted across restart. A mismatch persists a signed Deny carrying the expected and observed digests and releases the reservation and hold exactly once. It cannot Allow or capture, so it is neither a refund nor a compensation. |
S4 | Selling a stale or retracted finding | The finding’s own expiry, plus a registered portable non-inclusion proof the kernel verifies against the signed epoch, feed, nonce, finding, path, and freshness before the reveal. The feed also retains a latest-observed (map_epoch, epoch_id, root_hash) floor, so an older valid proof and an equal-epoch proof with a different root both reject inside the nominal freshness window. Residual: retraction between proof and reveal, window-bounded, plus selective omission under O2. |
S8 | Reused or undercollateralized listing bond | A signed requirement or an opaque bond_ref is not collateral. Activation atomically creates a live encumbrance bound to seller, listing, finding, requirement class, currency, amount, and expiry, and rejects stale, wrong-party, wrong-currency, and already-allocated collateral. Concurrent admission caps open encumbrances against remaining slashable value. Residual: the chosen horizons and multiplier can understate tail risk, which is disclosed rather than called fully bonded. |
S9 | Unsupported proof-profile upgrade | A seller labels an outcome_class or a disclosure capsule as a hidden verified predicate the finding commits to no digest for. Admission rejects every such upgrade and reports only the facet it can verify. Residual: none today, because no hidden claim is offered at all. |
S7 / O5 | Non-delivery or attest-and-withhold | Within one operator, the purchase chain reaches exactly one rail-hold terminal per crash or retry: exact-once release before capture on any Deny, or exact-once capture after a durably staged matched Allow. Cross-org with a seller-aligned mediator the residual is high, because a mediator can accept a genuine request, sign and checkpoint the Allow, suppress the response, and release escrow. That topology is rejected; the profile requires a neutral or mutually trusted mediator drawn from the escrow allowlist. |
B1 | Take the reveal, refuse payment | Ordering does not carry this one. The provider AskResponse mints the read_finding grant first, and the authoritative budget and exposure reservation lands before accept(). Neither step authorizes or captures the reveal price. The no-loss property comes at reveal time: after guards pass and before dispatch the kernel authorizes the quoted price as a reversible Held payment, and captures only after the digest and media-type checks. |
B2 | Resale or republication after reveal | Information is copyable, so cryptography does not prevent it. The responses are economic and forensic: provenance identifies the original producer, listing terms can declare license scope enforced outside the protocol, and pricing assumes post-sale leakage. |
B3 | Probing without purchase | The pre-purchase descriptor is a deliberate fixed leak: topic, context digest, and outcome class. Anything richer goes through disclosure capsules with per-field leakage budgets and derived-inference ledger entries. Residual medium: descriptor metadata itself carries signal, so sellers choose topic granularity accordingly. |
C1 | Wash trading to inflate reputation | Only finalized, integrity-gated purchase and fee receipts count toward reputation, and the top tier requires two distinct evidence feeds. Wash volume shows as self-referential lineage through delegation_depth and root_budget_holder on the financial metadata. Residual: a patient adversary can still buy reputation at the collected fee and trade cost. |
O1 | Front-running or leakage by the mediating operator | T1 in attack form: an operator positioned to mediate a reveal is positioned to act on it first. Receipts and lineage make operator-side republication attributable. Residual: real for cross-org purchases through an untrusted operator, so confidentiality-critical buyers keep those purchases inside a trusted-operator or measured-runtime boundary. |
X2 | Evidence-metadata side channel | Public evidence about a sale leaks content: a tiny evidence_cost or a short receipt chain reads as a result that failed immediately. Mitigated by bucketed evidence_cost in public descriptors, with exact values only inside the paid reveal, coarse timestamps, and leakage-ledger accounting for every descriptor field. |
X2 carries a coupling caveat. Full evidence receipts re-leak exact costs through their financial metadata, so bucketing without projection is self-defeating and a seller chooses per listing between full-receipt and BBS-projected evidence modes. A projection authenticates its own disclosed statement and cannot claim the concealed originals' receipt-authenticity, checkpoint-membership, or cost-backing facets. The residual underneath both modes is that a listing's existence is one bit no bucketing scheme hides. Listing search exposes descriptor and pricing data, not a private one-bit oracle, and nothing in it prevents query linkage or count leakage, so no one-bit privacy or pricing claim is made.
Residual-risk register
The register ranks every residual with its instance and its owner. These rows carry production severity for a finding sale. The market prices them instead of eliminating them.
| Risk | Instance | Severity |
|---|---|---|
| Fabricated evidence accepted without the evidence verifier (S1) | Both | High |
Honest-cost fabrication of metered_attested nulls (S2) | R&D | High |
| Post-reveal resale or leakage (B2) | Both | High by nature |
| Operator sees revealed content cross-org (O1 and T1) | Both | Medium-high |
| Listing collateral reused or outrun by exposure without admission (S8) | Both | High |
| Reputation purchasable at collected fee and trade cost (C1) | Both | Medium |
| No revenue clawback in v1 | Both | Medium |
| Paid non-delivery under a seller-aligned cross-org mediator (S7 and O5) | Cross-org | High |
Where the open residuals sit
Invariant inheritance
The market inherits the kernel's settlement invariants and must not weaken them. Its mitigations change none of these:
- Invariant 9, slash proceeds. A fabrication slash never pays insiders: not the operator, not the mediator, and not a party positioned to have caused the fabrication.
- Invariant 10, no discretionary settlement. A dispute resolves through a mechanical check or the T3 roster. An operator's judgment substitutes for neither.
- P1, capability attenuation. A purchase capability is a narrow single-use grant:
max_invocations: 1, both cost ceilings set to the price, exactly one digest constraint, and exactly one purchase marker. - P4, receipt integrity. A sale's delivery receipt is exactly as tamper-evident as any other governed call's receipt.
- P10, evidence-class truthfulness. An evidence class is never upgraded, which is what keeps an
assertedfinding from passing as verified. The same discipline governs the claim registry over Chio's own proofs.
Next steps
- Finding Revocation · how a sold finding is revoked, and S4's freshness window
- Paid Reveal · the governed call this model is scored against
- Pricing a Finding · the collateral cap S8 turns on, and how a slash amount is computed
- Assurance Boundaries & Limits · the
BoundaryClassvocabulary T1 borrows from - The Cognition Market · the market this model is written against