Open weights can't be locked, so ownership is proven by counting surviving fingerprints. Embed thousands of secret key-response pairs; an adversary fine-tunes to scrub them and each audit burns one to leakage. Watch the reserve survive — or not.
A single mech request, drivable: drag the priority mech's response time across the 60-300s window. Inside it the priority mech delivers and gains Karma; past it a backup delivers, the priority mech forfeits the fee and is docked Karma. Live Olas marketplace constants.
Drive a Virtuals ACP escrow job: client funds USDC, provider submits a deliverable hash, and whoever sits in the evaluator's chair springs the payout. Seat the client (what ~all of Base does), a neutral agent, or no one — then run it or let someone cheat, and watch who's left exposed.
Pick the GPU a provider bills for and the cheaper card it secretly runs; the network measures the real device's compute, bandwidth and VRAM and plots it against the claimed model's fingerprint. Watch the spoof land outside the tolerance band — or hide inside it.
A liquidation mints a fixed prize — the bonus on seized collateral. Three bars split it three ways: a gas war bleeds it to the block builder, private orderflow pockets it for the searcher, an OEV auction returns ~73% to the protocol. Drive size, bonus, competition; anchored to Chainlink SVR figures.
An AI proposer is wrong a few percent of the time, but UMA pays a winning disputer only half the bond it risks — so the break-even belief is two-thirds, not half. Every category's base error rate sits deep in the no-dispute zone; raise the reward and the threshold slides left.
When an LLM agent writes the exploit, the fight is unit economics. Break-even contract value against cost-per-scan: the attacker's line, and the defender's sitting 10× higher because a bounty pays a tenth of a theft. The band between is the attacker-only zone, with A1's six models at measured cost.
What unlearning verification reports as 'forgotten' versus what a recovery attack gets back. Each method's dumbbell runs from its verdict (MIA ≈ random) to what an attack recovers — 0.97–0.99 for cheap methods. Toggle to % recoverable; tap a method. The ZK proof's scope ends at the verdict.
Run a speculative-decoding round at a time: a cheap drafter proposes γ tokens, the target verifies them in parallel and accepts a prefix plus one free token. Drive α, γ, and drafter cost c; watch the accepted length converge to Leviathan's Ω and the speedup peak, then fade.
A chain commits to a model's 32-byte hash for cents; keeping the gigabytes it points to retrievable is a separate, recurring bill. Pick a model and horizon and watch three rent-charging storage layers race Arweave's pay-once permanence to a crossover — plus the on-chain byte cost and cold-load wall.
Proving an agent's top-k retrieval is real costs a sort over every scanned candidate, unless you prove a boundary instead. Drive top-k and the corpus preset; watch the in-circuit comparison count split into the flat boundary proof and the sort tax you skip, anchored to V3DB's measured 22x.
Under secure two-party inference, a transformer's cost is eaten by Softmax and GELU, not the matrix multiplies. Stacked per-operation communication and interaction rounds for one BERT-base block across Iron, BumbleBee, and Nimbus — the nonlinear activations are 80–95% of the bill.