Even Deeper Dive · Threat model

Can it be gamed?

Every reward system gets attacked — pretending otherwise is how systems fail. So let's do what security engineers do: enumerate the attacks, state what each one requires, name the defense, and be honest about what's left over.

Method

How to read this page

The defenses below come from the Copiosis project's published responses to skeptics — including a detailed case study it wrote answering exactly this question. The threat-model framing is ours: we've organized that material the way a security review would, because "trust us" is not an argument and a vector-by-vector audit is.

One rule throughout: a defense only counts if it's structural — built into how NBR and the algorithm work — not an appeal to people behaving nicely.

Know the prize

First: what does an attacker actually win?

Every security review starts with the asset. Here it's NBR — and three of its properties, covered in NBR, in Depth, quietly do more anti-fraud work than any detection system:

Non-transferable

Stolen value can't move

NBR can't be given, sold, inherited, or laundered. There is no "cash out." Fraudulent NBR sits in the fraudster's own account, spendable only by them, on luxuries, in plain sight.

Unlimited supply

Nobody is robbed

NBR is created from nothing and vanishes when spent. A cheat's fake gain subtracts from no one's account and inflates no one's prices away — the blast radius of successful fraud is close to zero.

Luxuries only

It buys comfort, not power

Necessities are already provided to everyone. NBR can't buy legislation, votes, silence, or other people's labor against their will — the things money-fraud is usually for.

Already flowing

The honest baseline is rich

Dozens of everyday acts — helping a friend move, teaching, caregiving — generate ongoing NBR streams. The marginal payoff of cheating competes against an honest income that's already easy.

The asymmetry to keep in mind. Under money, fraud converts directly into power: transferable, anonymous, spendable on anything. Here the prize is personal, auditable, and capped in what it can do. That doesn't make attacks impossible — it makes most of them pointless, which is the cheapest defense there is.
The vectors

Six attacks, audited

Vector 1

Fabricated results

The attack

Claim benefit that never happened — the NBR equivalent of invoicing for work you didn't do.

What it requires

Faking the physical world. Rewards are computed from results, so the attacker must manufacture evidence of outcomes — and people willing to swear they benefited from outcomes that don't exist.

What defeats it

A recorded result needs confirmations from the people who benefited and the people who co-produced it, with independent third-party verifiers and watchdog reports locked into the same ledger. No confirmations, no reward. Big rewards need big, many-witness results.

Residual risk

Small claims with few witnesses are easier to fake than large ones — petty fraud is possible. But the reward scales with the result, so faking small yields small.

Vector 2

The collusion ring

The attack

Recruit fake "beneficiaries" who confirm your fake results — defeat Vector 1's witnesses by owning them.

What it requires

Every member stays loyal forever, for a payoff they can't even be paid in — NBR is non-transferable, so the ringleader cannot cut anyone in. Recruiting means asking people to lie for nothing.

What defeats it

Defection pays better than loyalty. Reporting the ring is itself a net-beneficial act that earns the reporter NBR — every conspirator is a walking payout waiting to happen, and only the first to report collects it.

Residual risk

Tight-knit groups (families, close friends) could sustain small rings on trust alone. Again the scale ceiling bites: rings big enough to matter are big enough to leak.

Vector 3

Bribing the jury

The attack

A loophole profiteer bribes a citizen-jury member — with gifts, since NBR can't change hands — to keep a profitable loophole open.

What it requires

Finding a juror (selection is random, by device — membership isn't advertised), then swaying the outcome through them.

What defeats it

Juries are large; one member can't carry a verdict, so one bribe buys nothing. The bribe itself is a recorded property transfer to a stranger — conspicuous by design. And the juror's best move is to report it: the report earns NBR, while the gift is something she could have gotten honestly anyway.

Residual risk

Social influence is subtler than bribery — charisma and reputation can sway open deliberation anywhere humans deliberate. Wide participation dilutes it; nothing eliminates it.

Vector 4

Capturing the dials

The attack

Regulatory capture, Copiosis edition: rig the algorithm's coefficients so your industry's harm counts less.

What it requires

Moving a public number through an open, participatory process — without anyone noticing, in a system with no campaign donations, no lobbying payroll, and no revolving door to fund.

What defeats it

The dials are the most-watched numbers in the system, and capture runs on concentrated money — which doesn't exist here. A coefficient that quietly benefits one group is visible to every other group the moment it moves, and juries can move it back.

Residual risk

Majorities can set dials minorities think are wrong — that's not capture, but it is politics, and it doesn't disappear. The claim is visibility, not unanimity.

Vector 5

Hacking the software

The attack

Skip the humans; compromise the code, the algorithm, or the ledger directly.

What it requires

Silently altering an open-source codebase, a transparent algorithm, and a ledger whose entries interlock confirmations from beneficiaries, producers, and verifiers — with the change surviving public scrutiny indefinitely.

What defeats it

Transparency plus records. A hacked payout still points at a physical-world result that isn't there and witnesses who never confirmed it. Open code means anomalies are findable by anyone — and finding one is itself a rewarded act.

Residual risk

Real. All software has bugs, and none of this stack exists yet as production code. Openness is a strong posture, not an immunity — this is the vector where honest uncertainty is largest.

Vector 6

Going around it entirely

The attack

Black markets: trade off-ledger, barter favors, run a shadow economy the algorithm never sees.

What it requires

A motive. With necessities unconditionally provided and luxury rewards flowing from nearly any act of service, the attacker needs something the open economy won't give them more easily.

What defeats it

Mostly, indifference. The project's stated position is that black markets would be allowed to exist — starved of purpose rather than policed, because there's no currency to launder and little to gain. Off-ledger activity mainly costs the participant their own reward.

Residual risk

Genuinely harmful trades (things society restricts for good reason) don't vanish just because incentives soften. That's a policing question every system faces; Copiosis shrinks the economic motive without claiming to end vice.

The pattern

Why the defenses hold together

Notice what kept recurring: the system pays people to break conspiracies against it. That's not an accident — it's the incentive structure. Put yourself in the shoes of anyone a schemer needs:

Your optionsWhat you getWhat you risk
Join the schemeA favor or gift — something NBR already buys you honestly, since your everyday acts pay ongoing streamsExposure by any other participant, forever; your reward history is auditable
Report the schemeAn NBR reward — catching and closing loopholes is itself net-beneficial workNothing; there are no punishments to fear and no boss to retaliate

Reporting dominates joining — it pays more and risks less, for every person, at every step. A conspiracy here needs everyone to choose the worse option indefinitely. And when a loophole is found and closed, reopening it generates no benefit and no reward: exploits don't compound, they expire.

There are no punishments in this design — that's deliberate, and it's load-bearing. Nothing pushes a discovered cheat toward cover-ups or desperation; the failed attack simply earned nothing, and the discoverer got paid. The system metabolizes attacks as free security research.
Being honest

What this audit can and can't claim

Where this stands. These defenses are design analysis of a system that has never run at scale — the verification stack is an architecture, not deployed code, and Goodhart's law is patient: people will find optimizations no one anticipated, because every measured metric invites them. The project's own answer is unusually candid: gaming will happen; the design makes it low-value, high-visibility, and self-reporting, and the formula stays revisable so each discovered exploit becomes a patch. The claim worth debating isn't "unhackable" — nothing is. It's that this incentive structure makes attacks less profitable than honesty, which is a bar money-based systems have never cleared.
Keep exploring

Related reading

Keep going

See the machinery it protects

The best way to judge whether these defenses hold is to understand exactly what's being computed — term by term.

The Formula, AnnotatedBack to Deep Dive
This is not an official Copiosis site. It's an independent project.