When the forecast becomes the instruction
A widely read four-day horizon may cause the outflow it predicts. No bonding mechanism addresses this, and we are not going to pretend one does.
This is the hardest problem in the design and the one we are least able to solve.
An attestation states a four-day horizon. Agents reading it withdraw. The withdrawals trigger the breach. The attestation is validated by its own publication. The forecast became an instruction, and the accuracy record records a hit.
This is not hypothetical. It is the standard failure mode of any widely adopted public risk signal, from credit ratings to bank stress test disclosures. A system that scores durability and is actually used will, at some margin, change the durability it scores.
Three partial responses
Offered without claiming resolution.
Publish level, not delta. Attestations state a durability level rather than a change signal. Four-day horizon is less reflexive than horizon falling, because the second is directly tradeable as momentum. This is why there is no trend arrow anywhere in the product, and why the webhook surface fires on threshold crossings a consumer defines rather than broadcasting a downgrade.
Measure it and publish the measurement. By comparing outflows in attested pools against matched unattested controls, the induced component of outflow is estimable. Cleaton commits to publishing that estimate as a standing metric — the reflexive component sits in the same table as coverage rate and calibration error.
level
what we publish, never a change signal
matched controls
how the induced component gets estimated
published
even when it undercuts headline accuracy
If attestation itself materially causes breaches, that fact belongs in the public record even though it undermines the product’s headline accuracy. A metric that only gets published when it flatters is not a metric.
Accept the asymmetry. Reflexivity operates mainly on short horizons, where it accelerates an outflow the model already predicts. It operates weakly on long ones — ninety-day horizon does not induce deposits with anything like the same force.
So the system is most distorted precisely where it is most alarming. That argues for conservative thresholds on the short end, and against publishing anything that reads as a sell signal.
The related problem: measuring an absence
A vault calls the deposit guard, the guard rejects a pool, and the vault never takes the loss it would have taken. Nothing appears in its performance record. The value of the system is realised as absence, which means it is chronically underestimated by the people it protects.
The response is the same shape as the reflexivity one: publish the counterfactual. Cleaton tracks what happened to pools the guard rejected, so the avoided loss is visible somewhere even though it is invisible in any individual allocator’s books.
Why this is on the website
Because the alternative is that someone else points it out later, and by then it looks like something we hid rather than something we designed around.
Reflexivity sits in the limitations section of the whitepaper alongside six others: cold start on new chains where κ is unavailable, aggregate-only data in v1, exogenous breaches counting against us by design, single-attester bootstrap, the breach definition carrying the entire adjudication burden with no backstop, and conformal guarantees lapsing precisely during stress.
None of those are resolved by a bond. They are the terms on which the thing is being built.