What unlearning verification reports as 'forgotten' versus what a recovery attack gets back. Each method's dumbbell runs from its verdict (MIA ≈ random) to what an attack recovers — 0.97–0.99 for cheap methods. Toggle to % recoverable; tap a method. The ZK proof's scope ends at the verdict.
When an LLM agent writes the exploit, the fight is unit economics. Break-even contract value against cost-per-scan: the attacker's line, and the defender's sitting 10× higher because a bounty pays a tenth of a theft. The band between is the attacker-only zone, with A1's six models at measured cost.
An AI proposer is wrong a few percent of the time, but UMA pays a winning disputer only half the bond it risks — so the break-even belief is two-thirds, not half. Every category's base error rate sits deep in the no-dispute zone; raise the reward and the threshold slides left.
A liquidation mints a fixed prize — the bonus on seized collateral. Three bars split it three ways: a gas war bleeds it to the block builder, private orderflow pockets it for the searcher, an OEV auction returns ~73% to the protocol. Drive size, bonus, competition; anchored to Chainlink SVR figures.
Pick the GPU a provider bills for and the cheaper card it secretly runs; the network measures the real device's compute, bandwidth and VRAM and plots it against the claimed model's fingerprint. Watch the spoof land outside the tolerance band — or hide inside it.
Drive a Virtuals ACP escrow job: client funds USDC, provider submits a deliverable hash, and whoever sits in the evaluator's chair springs the payout. Seat the client (what ~all of Base does), a neutral agent, or no one — then run it or let someone cheat, and watch who's left exposed.
A single mech request, drivable: drag the priority mech's response time across the 60-300s window. Inside it the priority mech delivers and gains Karma; past it a backup delivers, the priority mech forfeits the fee and is docked Karma. Live Olas marketplace constants.
Open weights can't be locked, so ownership is proven by counting surviving fingerprints. Embed thousands of secret key-response pairs; an adversary fine-tunes to scrub them and each audit burns one to leakage. Watch the reserve survive — or not.
Does an AMM LP out-earn the arbitrage bots picking off its stale quotes? Plot fee income (flat) against LVR = σ²/8 (rising with vol²): where they cross is break-even. At low turnover even BTC sits in the red. Flip on solver-auction recapture and the frontier slides right.
Allora weights models by regret, not votes. Drag a market from calm to a volatility spike: five forecasters ride the softplus weight curve φ′(R̂), the low-vol specialist collapses the instant a spike is forecast while the vol-aware model climbs. Tap a model for its R→R̂→w chain.
Watch a searcher sandwich your agent's swap on the live Aerodrome WETH/USDC pool on Base. Set trade size and slippage tolerance; the optimal front-run is solved on the real constant-product curve, capped by your tolerance. Route privately and the extraction goes to zero.
How many audit probes it takes to catch a substituted model, as a function of how subtle the swap is. A 1/Δ² curve over real quantization accuracy gaps: a model swap is caught in a few hundred probes; FP8 needs ~150k and falls off the cliff into the economically-invisible zone.