Key points:
- The principle: Identity can be cheap, but influence must be costly. A permissionless network does not need to stop people from creating unlimited credentials; it needs to stop those credentials from acquiring credibility merely by existing.
- The insight: Credit does not need a universal answer to which identities are “real.” It needs durable evidence of how much economically tested trust each credential has earned, interpreted from each observer’s own trusted starting points.
- The mechanism: Pogun, which is based on Cardano-Loans, records two reputations through every loan: the borrower’s repayment record and the lender’s underwriting record. Linking those records creates a public web of economic trust.
- The constraint: Trust weakens as it moves farther from its source, and whatever authority reaches a lender is divided across its downstream positions rather than copied to each one. Creating more wallets therefore dilutes inherited influence instead of multiplying it.
- The adaptation: When a branch fails, the outcome remains visible. Borrowers carry their repayment history, lenders carry their underwriting history, and observers can reprice the paths that gave the branch credibility. Repeating the same attack becomes progressively more expensive.
- The payoff: This is adaptive Sybil resistance: credentials remain easy to create, while mature economic influence remains scarce, costly to abuse, and difficult to rebuild. The same model may provide a foundation for high-fidelity decentralized identities.
Here is an AI-generated podcast giving a deep dive on this paper (audio only).
Start with a scenario
Suppose RealFi publishes a Cardano credential and starts placing small and medium-sized enterprise (SME) loans on-chain. It lends to a local financial institution that knows its region. That institution lends to merchants, farmers, and cooperatives that no global investor could evaluate from a distance. As loans get issued, repaid, refinanced, and occasionally defaulted, a public network of economic relationships appears on the blockchain.
The first question for an outside investor is simple: how much do you trust RealFi?
No government designated RealFi as an authority. No DAO voted it onto an approved list. RealFi is a trust anchor only because Alice recognizes its credential and is willing to place weight on its financial judgment. Bob might place less weight on it. Carol might ignore it entirely and start from a cooperative whose managers she knows personally.
The blockchain gives everyone the same economic facts. Nobody is required to reach the same conclusion. That's the whole design. A government credit bureau answers the universal question 'who is trusted?'; an Economic Web of Trust answers the subjective one: 'starting from the institutions I trust, how much confidence should I extend through the paths connected to them?'
The simulation below shows what this looks like in practice:
Identity is cheap, but influence cannot be
The Sybil problem is old and well understood: a permissionless network cannot tell whether 10,000 wallets are 10,000 people or one attacker. The usual response is to hunt for a perfect proof of unique humanity.
Credit doesn't need one.
A financial network doesn't need to stop someone from generating 10,000 credentials. It needs to stop those credentials from acquiring 10,000 times more economic influence merely by existing. Proof-of-work ties influence to computation. Proof-of-stake ties it to capital. An Economic Web of Trust ties credit influence to real lending relationships whose terms, duration, and outcomes are publicly observable.
An attacker can manufacture wallets. They cannot manufacture a 10-year history of credible counterparties, capital placed at risk, and a reputation that would be expensive to lose. Activity is cheap to simulate. Trusted economic connectivity is not.
A loan is a bounded wager
Traditional webs of trust such as PGP key signing, social attestations, and follower graphs are built from social statements. Alice vouches for Bob. These links cost almost nothing to create, so they carry almost no information. A person who vouches carelessly suffers, at most, embarrassment.
A loan is fundamentally different. When a lender extends credit, it doesn't merely say the borrower looks trustworthy; it puts capital behind that judgment. The endorsement has an amount, a term, an interest rate, a collateral ratio, and eventually a financial outcome. A $100 loan for one week and a $100,000 loan for two years are not the same statement. A fully collateralized loan and an unsecured loan are also clearly different.
The lender is making a narrow, testable claim: under these terms, at this time, this borrower justifies this much risk. And once the loan concludes, the market can trustlessly grade that claim.
Every loan creates two reputations
Here is the part most on-chain credit discussions miss. Everyone focuses on borrower reputations: take loans, repay them, build a history. That's only half the information a loan produces.
Every loan tests two claims at once. The borrower claims the ability and willingness to repay. The lender claims the ability to identify and price a borrower worth the risk. When the loan concludes, both records update: the borrower's repayment reputation, and the lender's underwriting reputation.
These are genuinely different skills. An institution can be flawless at repaying its own debts and terrible at allocating capital. Another can be a brilliant judge of local businesses while managing its own treasury badly. A functional trust web has to track both.
And this is exactly what turns a chain of loans into a web. Take the simplest path:
RealFi → Local Lender → SME
On the first edge, the local institution is the borrower; the outcome tests RealFi's underwriting and the institution's repayment. On the second edge, the same institution switches roles: now its underwriting is being tested, along with the SME's repayment. Because the same persistent credential occupies the borrower role upstream and the lender role downstream, Alice can reason across the whole path: from her trust in RealFi, through RealFi's judgment of the institution, through the institution's judgment of the SME.
A borrower-only reputation system can't do this. It can show that the institution repaid RealFi, but not whether RealFi can properly evaluate its own borrowers. A lender-only system fails symmetrically. The web requires both.
Pogun already records both
This isn't a hypothetical protocol design, it's how Pogun structures its loan state today.
A participant's staking credential is its persistent identity. Pogun derives a Borrower ID and a distinct Lender ID from that credential, with role-specific prefixes so borrowing and lending activity can't be confused when one credential does both. Every offer carries the lender's ID; every active loan carries the borrower's ID and a unique pair of Loan ID tokens. Fully repaid loans and defaulted loans leave distinguishable, independently verifiable histories on the ledger.
The Key NFT (the transferable lender bond) adds the final piece. Whoever holds the Key NFT owns the right to the loan's cash flow and can sell that position freely. But the original Lender ID stays attached to the loan's history forever.
Debt ownership moves, whereas responsibility for the underwriting judgment does not.
That separation is what makes the higher credit layers work. Secondary loan markets and loan-backed securities need positions to be freely transferable; but if selling a loan also erased who originated it, every transfer could launder bad underwriting. On Pogun, you can trade the cash flow without ever escaping the judgment that created it.
Important: Pogun deliberately does not impose a universal reputation score. It provides durable evidence (i.e., persistent IDs, immutable outcomes, immutable origination provenance) from which Alice, Bob, and Carol can each build competing reputation models. The ledger records the history; observers decide what it means.
Trust decays with distance, and divides rather than multiplies
Imagine you are looking for a job applicant and your best friend Mike recommends Dan. Think about how your trust in Mike extends to Dan. You likely trust Dan more than a stranger, but you don't trust him as much as your best friend. And what if Dan then recommends Charlie for a second open position at your company? How much do you trust Charlie? The recommendation came from Dan, not Mike; so do you trust Charlie the same as Dan or less? You likely trust her less than Dan.
Trust naturally decays the more hops you move away from the trust anchor.
When RealFi lends to the local institution, it opens a bounded trust channel. The strength of that channel reflects the amount at risk, the term, the collateral protection, and the relationship's track record. When the institution lends onward to SMEs, Alice can let some of the authority reaching it flow through to those borrowers, but never all of it.
Here's the failure mode to guard against: the institution receives one credible loan from RealFi, then creates 100,000 fake wallets and 'lends' to all of them. If every downstream loan inherited the institution's full authority, one trusted edge would mint an unlimited supply of credible-looking borrowers.
The fix is normalization. Whatever trust reaches a lender gets distributed across its downstream positions, weighted by the economic substance of each loan. It is never copied to each of them. Spin up 100,000 sock-puppet borrowers, and each one inherits 1/100,000th of the channel.
Creating more identities divides inherited authority; it does not duplicate it.
What about wash-lending? Wash-lending involves passing the same capital in a circle (A → B → C → A) to fabricate volume and history. In an Economic Web of Trust, this achieves nothing. Because trust is subjective and path-dependent, an isolated wash-lending ring is just an island. If it isn't connected to a node that Alice already trusts, she doesn't see a pristine credit history; she just sees noise. See the simulation below for a visual of this:
Adaptive Sybil resistance
Consider the job application scenario again. If Charlie ends up performing poorly and you have to fire her, doesn't that damage your trust in Dan? And since Dan was recommended by Mike, doesn't that damage your trust in Mike (to a lesser degree)? The next time you have a job opening, you are likely going to discount Mike's and Dan's recommendations more than last time. You adapt to the breach of trust.
Notice what this system does not promise. It doesn't keep attackers out. New credentials enter freely. Existing institutions can be deceived. A patient attacker can penetrate a trusted branch, cultivate a healthy-looking history, attract real capital, and default. The loss is real; nothing reverses it.
What the system guarantees is what happens next. The attack's pathway in the web of trust is permanently visible. The sock-puppet borrowers carry defaults. The originating lender's underwriting record deteriorates. The upstream paths that delegated authority to that lender come under scrutiny. A suspicion radius forms around the failed branch, weakening with distance. Alice reprices the whole compromised limb of her trust graph.
Important: The repricing guarantee is based on human nature's psychological aversion to loss. Alice doesn't even need to be the victim of the attack for her to become more cautious of that part of the web, potentially even starving that branch of her capital for the foreseeable future.
Here is a simulation showing what happens to the web after a normal default:
And if it actually was a Sybil attack, see this simulation for how the normal default response is enough to prevent it from happening again:
The attack consumed the trusted connectivity that made it possible, making it significantly harder to pull off a second time. The attacker can abandon the burned credential and start fresh, but the replacement starts from zero: no repayment history, no underwriting record, and now, no high-fidelity path from anyone's trust roots.
Credentials are replaceable. Reputation is not.
This is adaptive Sybil resistance. A feedback process in which observers continuously revise how much influence they extend through each part of the graph. A topology that can never be penetrated is a fantasy security objective. A topology that records penetration, reprices the compromised path, and makes repetition progressively more expensive behaves like an economic immune system.
Please note: A default is not proof of an attack, and suspicion is not guilt. Defaults are ordinary credit events, and an external shock can sink many sound loans at once. Even excellent lenders take losses. The graph doesn't replace judgment; it directs attention to the relationships that deserve a second look. The relevant question is never 'did the loan fail?' but 'was the failure surprising relative to the risk that was priced?'
Borrowers graduate from the institutions that discovered them
Follow the SME over time. At first, it's visible to global capital only through the local lender; Alice trusts a chain of judgments, not the SME itself. But every completed loan builds the SME's own borrower reputation, and that history sits on a public ledger that no institution controls. Other lenders can inspect it and make competing offers. Eventually Alice might be comfortable lending to the SME directly.
The local lender is not made obsolete: field knowledge, servicing, and discovering the next borrower are durable roles. What disappears is the institution's ability to monopolize a successful borrower's reputation, the way banks in the developing world and credit bureaus in the developed world do today.
Institutions can discover borrowers without permanently owning their reputations.
Local knowledge becomes globally portable evidence, and the borrower climbs from invisible to path-dependent to independently creditworthy.
Important: Projects like RealFi are a great step towards banking the unbanked, but it will never scale to the billions of unbanked in the world. This economic web of trust enables RealFi to 'delegate' its underwriting to local lenders it trusts, and the world can trustlessly score RealFi's judgment by watching what happens. That is how we bank the unbanked at scale.
(The appendix section below animates this evolution at network scale, from hub-and-spoke seeding to a decentralized global web.)
Beyond credit: high-fidelity DIDs
The same model suggests an answer to a much older question in decentralized identifiers (DIDs).
Most approaches to Sybil resistance chase 'one human, one identity': proof-of-personhood, iris scans, duplicate detection, etc. But for most use cases, 'one human, one identity' is the wrong goal. A human has legitimate reasons to hold several DIDs: professional roles, private finances, public participation, and contexts that shouldn't link. The problem was never that one person can create multiple DIDs. The problem is one person creating unlimited DIDs that each carry the weight of a mature, economically credible identity.
DIDs can be unlimited, but high-fidelity DIDs must be scarce.
In an Economic Web of Trust, a DID isn't universally valid or invalid: it's sufficiently established for a given use when its position in an observer's web clears that use's threshold. Posting in a forum needs almost nothing. Receiving an unsecured loan, underwriting other borrowers, or voting on communal capital needs a credential with years of tested history.
And crucially, reputation compounds non-linearly. One credential with a pristine 10-year history is worth far more than five credentials with two-year histories; it has survived more time, more counterparties, more market conditions, and it contains more value that misconduct would destroy. The mature credential becomes a reputational bond. This means there is a natural network effect that strongly favors consolidating DIDs. The equilibrium: credentials stay easy to create, a handful of identities per person stays practical, but fleets of mature identities are economically unsustainable.
That's an alternative to both meaningless unlimited pseudonyms and universal proof-of-personhood; and Pogun is the natural laboratory for it because credit is the domain where continuity pays, abandonment has real costs, and reputation has observable consequences.
The privacy question is already answered
A credit web requires transparency, but not exposure. This is exactly the Public Markets, Private Participants architecture: the Credit Avatar keeps a persistent public Cardano credential whose loans, collateral, payments, and outcomes are fully observable (because the market needs those facts to price risk) while Midnight shields the treasury behind it and the paths capital takes in and out.
The market sees which credential borrowed, which credential originated, the terms, and the outcome. It does not see the legal identity or the full financial life behind the avatar. Privacy protects the participant. It must never let the avatar rewrite the public history its reputation is built on.
The market stays lit. The participant disappears. The reputation remains.
From credit market to trust market
The deepest consequence of Pogun is not that loans happen on-chain. It's that every loan publishes testable evidence about two questions:
- Who repays?
- Who correctly identifies and prices those who repay?
Borrowers with strong histories get better terms and more suitors. Lenders with strong histories attract more capital, sell their Key NFTs more easily, and graduate into the higher layers of credit. Branches of the graph that perform attract liquidity; branches that fail become expensive and isolated. No bureau computes the score. No committee appoints the authorities. No attacker gains influence by minting credentials.
And the claim is falsifiable. The model stands or falls on one prediction: influence must remain substantially harder to scale than credential creation. If someone demonstrates a way to manufacture seasoned, widely trusted authority as cheaply as wallets then adaptive Sybil resistance fails and this framework fails with it. Watch for that. Everything in the design, from dual reputation to origination provenance, bounded propagation, and time as a scarce input, exists to make that attack uneconomical.
Appendix: from grassroots to a global web
The animation below plays the whole argument at network scale. Global lenders like RealFi and Kiva seed local institutions first, and that order is forced. On-chain loans are denominated in stablecoins, so the exchange-rate risk sits with the borrower: a loan that was affordable when issued can become unpayable if the local currency slides against the US dollar. End-borrowers earning local fiat have no way to carry that risk; local financial institutions that already intermediate international capital are built to. And the first borrowers should be local lenders specifically, because delegated underwriting is the only way global capital reaches billions of borrowers it could never vet directly. From there, the simulation runs: every repaid loan grows a public record; the institutions begin lending to each other, opening pathways that never touch the hubs; and both institutions and end-borrowers graduate, attracting outside capital directly by growing within the web, never by leaving it.




