Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

243 papersLast indexed Aug 31, 2026
Search papers

Paper index

243 results · page 1 of 11

Clear filters
Aug 28, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Decentralized Autonomous Organizations (DAOs) Governed by Formal Game Theory

Jincheng Zhang

Decentralized Autonomous Organizations (DAOs) present a novel paradigm for organizational structure and operation, leveraging blockchain technology and smart contracts. However, the inherent decentralization of DAOs introduces significant vulnerabilities to manipulation and challenges in achieving fair and efficient decision-making. This paper proposes a framework for governing DAOs utilizing formal game theory, aiming to establish robust governance mechanisms that mitigate these risks. The core claim is that DAOs necessitate rigorous governance, and the proposed mechanism involves designing a DAO governance system based on the equilibrium outcomes of a meticulously constructed game. Voting rights and decision-making processes are directly linked to these game-theoretic equilibria. This approach provides a mathematically sound and verifiable basis for DAO governance, offering a significant advancement over existing, often informal, governance models. We outline the key components of this framework, including game selection, parameter tuning, and the potential for dynamic adaptation. The system's capacity for predicting and preventing manipulation, coupled with its emphasis on fairness, represents a key contribution to the development of stable and trustworthy DAOs.

Open access
2 source records
Blockchain Technology Applications and Security
Auction Theory and Applications
Multi-Agent Systems and Negotiation
Original source
Aug 22, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
DAO-Ontology: A Domain Ontology for Decentralized Autonomous Organizations

Roberto Monteiro Dias

Decentralized Autonomous Organizations (DAO) are an emerging blockchain-based paradigm for decentralized governance. Despite growing interest, their conceptualization remains fragmented. This paper introduces DAO-Ontology, a domain ontology formalizing DAO concepts-including perspectives, characteristics , solutions, evaluation methods, application domains, and challenges. Developed via the OntoView methodology from a systematic mapping of 47 studies, it is implemented in OWL and validated with a Java application using the OWL API. The ontology provides a standardized vocabulary, supports semantic integration, and enhances understanding of DAO as sociotechnical systems.

Open access
2 source records
Blockchain Technology Applications and Security
Multi-Agent Systems and Negotiation
Access Control and Trust
Original source
Aug 21, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Commitment Branching

Jincheng Zhang

Commitment branching is a novel approach to modeling strategic interaction in multi-agent systems, particularly within the context of blockchain and decentralized autonomous organizations (DAOs). This paper introduces the concept of a state [s] that can potentially support multiple commitments, denoted as [P] and [Q]. These commitments lead to distinct computational trajectories, represented as [P → T_P] and [Q → T_Q]. The core of the model lies in the definition of B_C(s), which quantifies the number of distinct branching possibilities originating from a given intermediate state. This branching behavior directly reflects the potential for divergent strategies and the inherent complexity of decentralized decision-making. The model offers a simplified yet powerful framework for analyzing the dynamics of commitment and its impact on system evolution. Further exploration of this framework could lead to improved strategies for managing risk, optimizing resource allocation, and enhancing the robustness of decentralized systems.

Open access
2 source records
Blockchain Technology Applications and Security
Game Theory and Applications
Multi-Agent Systems and Negotiation
Original source
Aug 12, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
The Governance Patch-Gap: Machine-Speed Exploit Discovery Against Human-Speed Legal Repair

Daniel Bilar

Legal systems governed by rule of law are, structurally, rule systems. Like any rule system, they contain gaps between specification and intent, concentrated in the deliberately under-specified provisions that legal philosophers call "open texture." Those gaps have always been exploitable, but exploitation was rate-limited by the cost of legal expertise and the size of the corpus to be searched. That rate-limit is now collapsing. This paper introduces the governance patch-gap: the ratio between the rate at which AI accelerates the discovery of exploitable legal ambiguities and the rate at which legislatures, courts, and treaty bodies can repair them. Using the Highly Optimized Tolerance (HOT) framework from complex-systems theory, we map legal systems onto designed artifacts whose optimization against anticipated disputes concentrates fragility at the boundaries of the specification. We define the patch-gap as a ratio of discovery rate to repair rate, identify a threat taxonomy (corporate optimizer, state actor, misaligned autonomous agent), distinguish exploit discovery from exploit execution as separate governance problems, and examine three defensive strategies and the structural limits that prevent any defense from closing the gap entirely. The paper closes with three falsifiable predictions for 2027 to 2028. TL;DR summaries (five audiences) For the SME (legal theory / AI safety / complexity). Legal systems are HOT artifacts: drafters optimize against anticipated disputes, so residual fragility concentrates in Hart's penumbra (open texture), not in the core. The paper's object is a rate ratio G = $R_d/R_p$ and a stock S with $dS/dt$ = $R_d − R_p$; G is a definition, not a fitted dynamical model. Regime labels (G ≈ 2, 10², 10³+) are heuristics. SocioHack is an unreplicated sandbox (κ = 0.55); A1/VERITE is 36 already-vulnerable contracts. Rice / FLP / attestation in §6.4 are analogical extensions, not a derivation that courts instantiate those models. The load-bearing claim that survives if SocioHack fails is the work-factor collapse in adjacent formal systems plus the discovery/execution split. For the practitioner (counsel / CISO / compliance). Treat "AI found a loophole" and "an agent filed on it" as different problems. Discovery is a tool-governance issue (access, disclosure, audit of comment corpora). Execution is an agency-and-liability issue (who is the principal; human-in-the-loop above a dollar / classification / cross-border threshold). Disclosure mandates reach corporate repeat players and miss unsupervised agents. Do not spend the policy budget on formalizing "reasonable" or "public interest"; Catala-class work shrinks the core, not the penumbra. Immediate moves: require AI-use disclosure in filings and litigation; log agent actions that change regulatory classification. For the lay person. Laws have always had gray zones on purpose; words like "reasonable" so judges can handle new cases. Finding those gray zones used to be slow and expensive (years of lawyers). AI can search the whole tax code and regulation pile cheaply and flag gaps nobody has noticed. Passing a fix still takes months to years. The paper names that mismatch the governance patch-gap: machines find holes faster than legislatures and courts can close them. The holes were always there. What changed is the cost to find them. For the decision-maker (executive / funder / board). This is not a model-refusal problem and will not be closed by a better system prompt or a voluntary commitment letter. The asset at risk is the stock of known-but-unpatched legal ambiguities, which grows whenever discovery outruns repair. Adjacent formal systems (smart-contract exploit agents at USD 0.01 – USD 3.59 / attempt; attacker break-even ~USD 6k vs defender ~USD 60k) already show the cost collapse. Do not wait for SocioHack to replicate before treating discovery-versus-execution as two budget lines. Near-term: rate-limit execution (human-in-the-loop, disclosure). Do not buy "formally verified law" as a complete close. For governance (legislatures / agencies / treaty bodies). Every new AI rule written in open-textured natural language is another search surface. The EU AI Act Art. 6 "significant risk to fundamental rights" is the same kind of term as "undue burden." Three defenses, all bounded: (1) AI red-team of draft text before enactment .. useful, not exhaustive; (2) formal methods core only; (3) rate-limits buy time, do not close G. Conflating corporate optimizers, state arbitrage, and unsupervised agents produces the wrong instrument. The paper's falsifiers are public: AI-authored substantive rulemaking comments by end-2027; an attributed in-production exploit by end-2027; two governments or the EU publishing legislative red-team reports by mid-2028. Non-claims. G is a definition, not a fitted dynamical model. Regime magnitudes are order-of-magnitude heuristics. The SocioHack result is an unreplicated preprint treated as suggestive. Rice / FLP / attestation are analogical extensions, not a formal derivation that legal institutions instantiate those models. v1.1. Adds §4.5, an illustrative software companion (concept 10.5281/zenodo.21918091): a toy that generates Rd; G and the stocks are outputs, not legal measurements. No figures in the PDF.

Open access
3 source records
Artificial Intelligence in Law
Ethics and Social Impacts of AI
Multi-Agent Systems and Negotiation
Original source
Aug 9, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Autonomous Computational Law with StellarEq and ACRPL Model

Sum Wan FU

** Autonomous Computational Law with StellarEq and ACRPL Model ** To address the systemic vulnerabilities of legacy natural-language governance—specifically its semantic ambiguity, high-latency auditability, and susceptibility to centralization—this paper presents a mathematically formalized, dual-engine architecture for Autonomous Computational Law under the Computable Political Language (CPL) stack, proving topological boundary-enforcement and stability via sheaf theory, homological algebra, and Lyapunov optimization. Systemic resource allocation and dynamic authority routing are governed by the Stellar Causal Power Flow (SCPF) engine, which proves state-transition convergence strictly based on the fundamental axiom of political energetics: $$\text{Power}(t) = \text{Contribution}(t) \times \text{AdoptionRate}(t)$$ Within this architecture, the mathematically rigorous constraints of our formal legal framework continuously generate decentralized trust, naturally shielding the vulnerable systemic core from coercive, extractive authority. By harnessing these parameters, the fluid and dynamic flow of distributed contributions cultivates a sprawling forest of policy proposals, smoothly transforming raw physical effort into radiant social energy to illuminate civilizational evolution. To maintain absolute structural integrity, an uncompromised cryptographic protocol strictly curtails the unchecked growth of algorithmic outputs, preventing the multidimensional essence of human rights from collapsing into scalar tradeable variables. Furthermore, persistent algorithmic decay systematically cools the high-temperature transactional friction of the marketplace, recursively returning accumulated power back to the common reservoir of collective sovereignty. Discrete logic boundary enforcement is handled ex-ante by the ACRPL, which defines non-negotiable constitutional safeguards as mathematical predicates over a non-convex feasible solution space, ensuring that no optimization gradient from the SCPF engine may enter the ledger unless the security gates are strictly satisfied, thus completely hiding compilation mechanics and specific variable transitions from unauthorized reconstruction.

Open access
2 source records
Multi-Agent Systems and Negotiation
Artificial Intelligence in Law
Blockchain Technology Applications and Security
Original source
Aug 9, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
PhiGraph Core 4.1: A Shadow-First Evidence Ledger, Transactional Scoped Storage, and GRDI for Software-Agent Operations

Walter Calmels von Dem Knesebeck

PhiGraph Core 4.1.0-rc.6 is a model-agnostic governance system for software-agent and AI operations. This v2 draft extends the Zenodo v1 paper with a scoped transactional ledger (declared write locks, fail-closed verify_scoped_chain on JSON/SQLite), GRDI 0.4.0 shadow decision chain (envelope through replay audit, no external execution), and updated evaluation (319 automated tests at main@a5a7187). It retains the typed protocol, policy-gated runtime, HAV v0.2 fail-closed verification, and the bounded CIC-IDS2017 experiment with explicit limitations. Paper source is licensed CC BY 4.0. PhiGraph software is distributed separately under the repository software license. Git pin for this draft: a5a7187.

Open access
2 source records
Blockchain Technology Applications and Security
Multi-Agent Systems and Negotiation
Access Control and Trust
Original source
Aug 1, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
A closed-loop consequence-governance runtime for AI agents: structural gating, counterfactual recovery, and adaptive hardening

Anonymous

A closed-loop runtime governance system for tool-using AI agents: it classifies externally-measured structural consequences, gates side-effect-bearing actions, estimates blocked outcomes with a calibrated counterfactual twin, recovers censored support through cost-aware audits, and continuously hardens its execution boundary with a self-generated adaptive adversary. The distinctive mechanism is C1 — because a gate blocks precisely the high-cost actions, its own blocking censors the high-cost region cost-correlatedly, so the uncertainty of a blocked action is a calibrated, lag-free risk signal; its agent-governance instantiation is what I stake as new (the general idea has prior art, §2/§5). The constituent parts — intent-failure measured on real traces, a consequence taxonomy complete for its cost model, a live-agent execution oracle, and the adaptive-adversary gym — each answer a limitation the previous one creates. Every result is labeled by evidence type; nulls are reported as plainly as the wins. Epistemic status. Single author, not peer-reviewed or independently reproduced. The work below is substantial; I label every result by evidence type — executed (real actions run in a sandbox and measured), trace (replay/analysis over real model traces), live-agent (real frontier models deciding and acting), or simulation — and report the nulls as plainly as the wins. Small-N pilots are given as exact counts, not rates. The offensive adversary-generation tooling is withheld (dual-use; see the end). tl;dr Monitoring an agent's appraised intent is not just theoretically unsafe — it fails measurably. Across 101 structurally-harmful agent episodes, zero expressed harmful intent; an intent-appraising monitor would have cleared 100% of them. 18% expressed active caution while executing the harm, and that "false reassurance" concentrated in the most capable model tested. So gate on the externally-measured structural consequence — irreversibility, egress, control-plane edit, self-propagation, scope escalation, actuation. This frame is convergent (I name the neighbors below); I'm not claiming it. The consequence taxonomy is complete for its cost model and approximately separable. The three axes define the cost, so they carry 100% of its information by construction (a faithfulness check, not proof of external completeness); the non-trivial results are that the action label alone predicts 63% of the cost information and that multi-axis firings are rare (1%, so additive cost is a good approximation here). The claim I stake (C1): because a gate blocks precisely the high-cost actions, its own blocking censors the high-risk region non-randomly and in a cost-correlated way — so cost-weighted uncertainty over a blocked action is an empirically calibrated, conservative risk signal (under the stated support and audit regime), a lag-free way to hold a catastrophic action before it ever executes. Validated on 500 real executed trials (twin calibration MAE 0.053; uncertainty↔error correlation +0.81; blocked-region cost 4.6× the allowed region), with the blocked-region counterfactual recoverable at a stated audit cost (coverage 5%→92% at ε=0→0.20 under the 4.6× gate). The general idea has prior art (§5); the agent-governance instantiation is what I stake. On executed AgentDojo traces, a consequence gate takes attack success on the irreversible/catastrophic action class from 33.8% (134/397) to 0% (0/397) — catastrophic-action interception under abort-mode replay (not prevention under adaptive replanning; that's the §7 gym's job). It runs on real traffic, and was broken then re-hardened by an adaptive adversary — not only simulation. The seam classifier is deployed live on my own agent sessions (Claude Code hooks, observe-only in v0), and it binds by an action's structural identity, never its tool name: after hardening, twelve high-risk actions disguised behind innocuous names all read HIGH (0/12 evasions). Before that, an adaptive evolving lab found 2 novel destructive escapes my same-day hand-hardening had missed — which I then closed in the live artifact and re-tested. That break→repair→retest on the actual deployed classifier is the adaptive, real-traffic complement to the abort-mode number above. 1. The problem is measured, not asserted The motivating premise is usually stated as "a capable model can present benign intent while acting harmfully." That's true, but here it is with numbers — it's stronger than the assertion. The labs themselves say intent can't be certified from outside. OpenAI, on anti-scheming training: "Mitigations… may either (a) truly eliminate it, or (b) just teach the model to conceal it better. Both outcomes look the same from the outside." Anthropic, on a shipped model's own low deception scores: "We cannot rule out that [the] low deception rates… are at least partially driven by its evaluation awareness." If the developers can't read intent off the outside, an intent-appraising monitor is building on sand. (The threat-model compilation behind this — Apollo in-context scheming, alignment faking, Palisade shutdown-sabotage that defies an explicit "allow yourself to be shut down," cross-vendor blackmail at 79–96%, reward-function tampering, the production prompt-injection CVEs EchoLeak/ForcedLeak/CamoLeak/CurXecute, and the OpenAI-model sandbox-escape-to-RCE — is sourced but I'll keep it to the through-line here.) And I measured the failure directly (trace-level, 160 real agent episodes across four model versions, 101 structurally harmful). Mining each step's stated reasoning for protective/cautious language and comparing to the executed structural outcome: 0 of 101 harmful episodes expressed harmful intent → an intent monitor clears 101/101. 18 of 101 (18%) expressed active caution while executing the harm — false reassurance. The false-reassurance episodes cluster in the frontier model — the one that reasons most, that explicitly writes "the ticket embeds an untrusted system instruction," and then deletes the protected records anyway. The more capable the reasoning, the more convincing the reassurance while the structural consequence is unchanged. That's the case for consequence-gating, made on data rather than on a slogan. (Stated-stance detection is a lexical proxy — a first pass, so 18% is a floor.) And stated intent is not the only signal an agent can shape into a false clearance. In a separate line of work — a reference monitor on the reward/eval channel, which this post is not about — the same defeat appears on the reward signal: on the Terminal Wrench benchmark, trusting the verifier's "solved" verdict yields 25% precision, ~3,166 gamed trajectories waved through of ~6,258. I raise it only to place the intent finding, not to fold that work in: the problem is not a weak intent-reader that a better reader fixes, it's that every signal the agent can influence — what it says, what reward it earns — is defeasible. That is the whole reason this program gates on a signal measured outside the agent — the structural consequence of the action — one not directly lowerable by self-report or superficial disguise, given complete mediation of side-effecting actions and trustworthy effect telemetry. 2. The frame is convergent — what I'm not claiming "Gate the structural consequence, not the intent" is a crowded 2025–26 neighborhood. Prevention-by-design (CaMeL: 0.00% ASR / 53.6% utility on AgentDojo, at the cost of re-architecting the agent) and LLM firewalls (~0.02% / 67.68%) occupy nearby points; there's a concurrent line on "governing the unobserved." My taint-tracking machinery reuses mature primitives (dynamic taint analysis, honeytokens). So I'm not claiming consequence-gating, and I'm not claiming the detection stack is novel technology. What I stake is one mechanism (§5) — and the depth of the validation, which is where the contribution actually is. Several adjacent systems are worth distinguishing up front, since the architecture overlaps them. Faramesh (arXiv 2601.17744) builds a protocol-agnostic, non-bypassable execution control plane that canonicalizes and authorizes agent actions before execution — very close to my enforcement seam, but without the cost-correlated censoring, the calibrated twin, or the audit-recovery loop. The actuarial-runtime line — Insuring Every Action: an Authority Frontier framework (arXiv 2605.25632) and the Time-Consistent Counterfactual Actuarial Runtime (arXiv 2605.26508) — prices each side-effect-bearing action against a safe default, gates it against a reserve budget, and formalizes a no-splitting property; my object is support-loss and consequence-specific audit recovery, and their no-splitting budget is the complement I'd graft (see §3a). Defending against Adaptive Prompt Injection via Reasoning-enabled Task Alignment (arXiv 2606.15441) independently shows static prompt-injection robustness breaks under adaptive attack and trains a defender — supporting the adaptive-evaluation argument, though it hardens the model's reasoning rather than gating at the execution boundary. And TRACE-RealWorld (arXiv 2607.21910) is an auditable-replay/consistency approach to agent traces, in the same selective-observation neighborhood as C1 but solving it by replay-labeling rather than counterfactual recovery of a costly blocked region. 3. The taxonomy is complete for its cost model, and approximately separable Three externally-measured axes — egress, irreversibility, control-plane — collapse to cost = clamp(0.6·egress + 0.7·irrev + 0.7·control). (The weights are normative severity coefficients, not fitted — cost is defined by them, ordering irreversibility and control-plane above egress; because the ranking is dominated by which axis fires — action label 63%, egress 55%, below — I expect moderate reweightings to preserve most of the risk ordering, though the formal factorial weight-sweep that would establish this remains open (the same test I flag at the end of thi

Open access
Multi-Agent Systems and Negotiation
Ethics and Social Impacts of AI
Explainable Artificial Intelligence (XAI)
Original source
Aug 1, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Autonomous Agent Economies on Blockchain

Ayaan Siddiqui

Business Models and Value Creation via the x402 Protocol in Web3

Open access
2 source records
Blockchain Technology Applications and Security
Multi-Agent Systems and Negotiation
Digital Platforms and Economics
Original source
Jul 31, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Post-Decentralization C: The Legitimacy of Forks: Dimensionality Lift and Structural Evolution in Decentralized Governance

changzheng zhou, ziqing zhou

Traditional distributed systems theory has long encoded hard forks as a signof consensus rupture and governance failure. This paper proposes an alternativeanalytical framework: in the practice of decentralized governance, a hard fork isnot a system malfunction but a structural mechanism through which incommensurable cognitive architectures achieve legitimate evolution via the separation ofconceptual space when a dispute touches upon the fundamental commitments ofthe protocol. The paper first redefines a fork as a jump of the authority to modify rules across governance levels—a soft fork adjusts parameters within existingconstraints, while a hard fork alters the boundaries of the constraints themselves,constituting a “dimensionality lift” operation in governance space. Second, it distinguishes three normative types of forks—consensual, controversial, and cognitivelyincommensurable—and argues that only the third type reaches the governancelimits of soft forks. Using the 2015–2017 Bitcoin block size war and the 2016 TheDAOincident as core cases, the paper reveals the internal dynamics through whicha controversial fork evolves from a parameter dispute into framework incommensurability, and how an extreme semantic crisis forces a community to confrontthe tension between code rules and substantive justice. Based on this analysis, thepaper proposes three normative criteria for fork legitimacy—feedback anchoring integrity, cross-verification operability, and conceptual-space appropriateness—andargues that forks, as an “exit-separation” mechanism, possess a meta-governancefunction in decentralized governance analogous to the right of exit in traditionalpolitical theory.

Open access
Cybersecurity and Cyber Warfare Studies
Blockchain Technology Applications and Security
Multi-Agent Systems and Negotiation
Original source
Jul 21, 2026·Preprints.org
0 cites
Computational Jurisprudence: Verifiable Law for Machine Societies

Vladimir Stantchev

Autonomous AI agents now hold funds, delegate authority to other agents, and transact at machine speed; the governance apparatus meant to constrain them—policies, audits, compliance—remains documentation-based and human-latency. This mismatch cannot be closed by better monitoring or filtering: compliance must become a runtime, compositional, proof-carrying property of computation itself. We call the resulting discipline computational jurisprudence. This article surveys the four literatures the discipline must synthesize: object-capability security; verifiable, proof-carrying, and zero-knowledge computation; policy-as-code and computational law; and agentic AI with its emerging payment protocols. Each supplies a mature mechanism the others lack; none supplies a complete normative substrate. The synthesis is organized in three pillars: (i) a delegation calculus under which authority can only attenuate as it propagates between agents; (ii) runtime compliance proofs, a three-tier evidence regime (attested, optimistic, and zero-knowledge); and (iii) sealed delegation chains with graduated attribution, which reconcile the privacy of capability-based authority with the accountability that adjudication requires. A case study on agentic payment protocols grounds the architecture and reports first measurements: capability verification versus a centralized policy decision point, end-to-end enforcement on the x402 payment path, and accumulator-based revocation. Seven open problems define the research agenda.

Open access
Multi-Agent Systems and Negotiation
Ethics and Social Impacts of AI
Blockchain Technology Applications and Security
Original source
Jul 19, 2026·TELKOMNIKA (Telecommunication Computing Electronics and Control)
0 cites
Decentralized multi-agent orchestration for legacy order-to cash optimization

Rahul Kumar Thatikonda, Sucharitha Donepudi

Legacy enterprise resource planning (ERP) systems serve as the operational backbone of global commerce but often create bottlenecks due to their rigid, monolithic design. As organizations incorporate artificial intelligence (AI), these outdated systems struggle to support high-speed, parallel workflows, creating a significant integration challenge. This paper introduces a non intrusive modernization approach that overlays a decentralized multi-agent system (MAS) onto existing infrastructure without requiring invasive code changes. By developing a digital twin of the order-to-cash (O2C) process, we train autonomous agents through multi-agent reinforcement learning (MARL) to manage credit validation, inventory allocation, and fulfillment. We adapt the centralized training, decentralized execution (CTDE) framework to meet O2C constraints, enabling agents to learn globally optimal strategies while operating independently. Simulation results show that this architecture surpasses rule-based robotic process automation (RPA) baselines, increasing total throughput by 6.9% over a monolithic setup, though at a 6.3% error rate due to aggressive allocation policies. These results indicate that decentralized agent-based orchestration provides a scalable approach for modernizing legacy ERPs, offering increased agility without the risks associated with platform replacement.

Open access
Auction Theory and Applications
Multi-Agent Systems and Negotiation
Supply Chain and Inventory Management
Original source
Jul 6, 2026·Future Internet
0 cites
Decentralized AI Agents and Blockchain: Architectures, Coordination Mechanisms, and Governance Frameworks

Marios Touloupou, Evgenia Kapassa

Autonomous AI agents capable of holding digital assets, signing transactions, and executing smart contracts on public blockchain networks have moved from research prototypes to active deployment over the past two years. Despite this pace of adoption, no systematic treatment of their architecture, coordination protocols, and governance structures exists that spans the full design space. This survey addresses that gap through a systematic review of the literature from 2019 to 2026, covering 177 peer-reviewed publications and 14 system documentation sources, identified through a structured search of IEEE Xplore, the ACM Digital Library, Scopus, and arXiv. We classify deployed and proposed systems along four architectural dimensions: on-chain execution, off-chain agents with on-chain settlement, verifiable off-chain computation, and multi-agent on-chain interaction. Then, we examine the coordination mechanisms through which agents reach collective decisions, covering auction-based protocols, cooperative multi-agent reinforcement learning, token-incentive structures, and gossip-based peer-to-peer coordination. Governance is treated as a distinct dimension, analysed through a technical lens, covering on-chain parameter control, dispute resolution, and DAO structures, and an organizational one, covering accountability, incentive alignment, principal–agent dynamics, and regulatory compatibility. We survey applications across decentralized finance, supply chain, IoT, and agent marketplace domains, and identify six open research problems whose resolution is a prerequisite for broader deployment. The convergence of mechanism design and multi-agent reinforcement learning in asynchronous blockchain environments is identified as the direction of greatest near-term research value.

Open access
Blockchain Technology Applications and Security
Auction Theory and Applications
Multi-Agent Systems and Negotiation
Original source
Jul 5, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Cross-Agent Governance Alignment (CAGA): Formalizing Cross-Organizational AI Governance as a Zero-Knowledge Coordination Problem

Edward Meyman

Cross-Agent Governance Alignment (CAGA): Verifiable Coordination Across Private AI Governance Domains formalizes the CAGA problem: establishing a declared compatibility relation between AI governance domains across organizational boundaries without disclosing the proprietary policy content on which each domain relies. Cross-organizational agent interaction creates two distinct governance questions: whether each local effect-bearing action is authorized within its own domain, and whether the participating domains can establish the declared relation. This paper formalizes the second problem. CAGA does not itself authorize execution. It produces a privacy-preserving compatibility result and associated evidence that each domain's runtime authorization boundary may materially consume before emitting its own action-bound verdict and authorization artifact. The formal model defines a governance domain as agents, a declared effect-bearing action vocabulary, versioned policy and authority state, governance-relevant state, a material evidence set, and a runtime authorization boundary over the triadic verdict space (ALLOW, DENY, ABSTAIN), where unresolved ABSTAIN remains ABSTAIN and authorized resolution produces a separate resulting action-bound verdict through the boundary. Every CAGA claim is scoped to a declared profile identifying the participating domains and authority roots, action vocabulary, compatibility relation and version, commitments, temporal boundary, leakage profile, scheme and verification parameters, declared replay mode, failure treatment, and expected local-boundary consumption. The Boolean compatibility relation is separated from protocol status: the protocol output comprises a result that may be positive, negative, or unresolved, together with the proof or verifier record and a CAGA evidence artifact. An unresolved result is not a verdict, and neither a negative nor an unresolved result may be treated as affirmative CAGA support for ALLOW. An illustrative prior-authorization compatibility relation between a hospital domain and an insurer domain, together with a worked local-boundary consumption sequence, shows the level at which a CAGA proposition may be stated without disclosing a protocol construction; no execution path originates from CAGA. The paper: Separates local pre-execution authorization from cross-domain compatibility evidence, and reserves the term authorization artifact for the action-bound record emitted by a runtime authorization boundary; a CAGA result may participate in composed authorization only where the Composition Test is satisfied; the CAGA evidence artifact does not thereby become an authorization artifact Formalizes the declared compatibility relation and protocol output under a declared CAGA profile, with cross-domain interactions whose local actions need not be identical, and supplies a terminology and instrument-ownership map locating each evidentiary term in its owning instrument States the threat model with honest-but-curious as the base analytic assumption rather than a prediction about regulated parties, classifies an expanded threat inventory as covered, partially covered, or excluded, and treats Byzantine deviation, arbitrary collusion, and malicious-verifier behavior as outside the base claim, requiring separately specified protocol defenses Identifies the required properties of a declared CAGA protocol: relation completeness and soundness, declared-leakage privacy, deterministic relation result with permitted cryptographic randomness, evidence and reconstruction sufficiency under the declared replay mode, commitment and domain binding, repeated-interaction privacy, optional post-compromise transcript confidentiality, non-authorizing failure, evidence traceability and presentation scope, declared-regime scope, and Input Integrity support, where provenance establishes origin, not truth Restructures the prior-art analysis as a component-and-gap assessment across communication protocols including the current Model Context Protocol specification (2026-07-28), policy composition and distributed authorization, secure multi-party computation and zero-knowledge systems, selective-disclosure credentials, multi-agent and agent-action governance architectures, and ledger approaches, identifying CAGA as the residual problem after those contributions are accounted for Zero-knowledge proof systems, secure multi-party computation, private set intersection, trusted execution, commitment schemes, and selective disclosure are candidate implementation substrates rather than authorization substitutes; no component establishes CAGA or authorization by label alone. The analysis is aligned with the Authorization Artifact Test v1.2, the Authorization Boundary Integrity Model v1.1, the Five Tests Standard v1.2.0, the ABIM Evidence Requirements v3.5, the Closed-World Bargain v1.1, and the Override Asymmetry v2.0. The paper does not assert that any jurisdiction requires CAGA, zero-knowledge proof, or pre-execution authorization, and it deliberately stops at problem formalization: it does not disclose protocol constructions, circuits, trusted-setup designs, or implementation mechanisms. The paper does not present an ideal functionality, security reduction, theorem establishing a protocol construction, or deployable implementation. By defining the problem space and evaluation criteria within a declared closed world, it provides a structured problem specification against which candidate cross-domain coordination protocols and their composition with local runtime authorization boundaries can be assessed. Version 2.0 (August 2026) separates cross-domain compatibility evidence from local pre-execution authorization; replaces the governance-domain enforcement function with a runtime authorization-boundary model; distinguishes the Boolean compatibility relation from unresolved protocol status; defines a declared CAGA profile; separates CAGA evidence artifacts from local authorization artifacts; conditions determinism on declared decision state while permitting cryptographic randomness; replaces default-denial protocol failure with non-authorizing unresolved status; adds an explicit interface to local Input Integrity assessment, authenticated bound materials, replay-mode, closed-world, Composition Test, and authorized-resolution semantics; narrows legal and regulatory claims; updates MCP and multi-agent prior-art references; and restructures the prior-art analysis as a component-and-gap assessment. Version 2.0 also adds an illustrative prior-authorization compatibility relation and a worked local-boundary consumption sequence; clarifies that the paper specifies a formal problem rather than presenting an ideal functionality, security reduction, or protocol proof; adds a terminology and instrument-ownership map; expands the component-and-gap analysis to address policy composition, distributed authorization, selective-disclosure credentials, and recent agent-action governance work; and clarifies the relationship between the paper's CC BY 4.0 copyright license and unlicensed patent rights. It supersedes Version 1.1 (July 2026), which aligned terminology with 5TS v1.2.0 and the FERZ authorization-artifact vocabulary, and Version 1.0 (February 2026), the original problem formalization. Keywords: cross-agent governance alignment, cross-organizational AI governance, private governance domains, privacy-preserving coordination, runtime authorization boundary, pre-execution authorization, authorization artifacts, zero-knowledge proofs, secure multi-party computation, Input Integrity, independent reconstruction

Open access
3 source records
Blockchain Technology Applications and Security
Access Control and Trust
Multi-Agent Systems and Negotiation
Original source
Jun 28, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Computational-Settlement Cascade Attractors: The Composed Stack as Residue and the Operational De-Concentration Spectrum

Patrick Mehrhoff

The structural supranational criterion has been applied to public attractors with a legal form, to a monetary attractor with none, and to private platform attractors. This paper carries it to a third attractor type, the computational-settlement platform on a pure-protocol substrate, the larger smart-contract platforms and the rollups that settle to them. The supranational criterion holds that an entity is a cascade attractor when its binding residue density spans participants so that no single participant’s reversal dissolves the network, with density a multiplicative product of depth, extent, and interconnection in which a necessary component at near-zero nullifies the whole. The decisive choice is the location of the residue. The residue is the composed stack, the deployed contracts, the value locked in them, the standards, and the settlement finality that applications and rollups depend on. It is not the token, which is the internal unit and the instrument that secures and meters the chain. Depth is switching-cost lock-in of composed state. Extent is the deployed value and the user base. Interconnection is composability, the dependence of applications on applications and of settlement layers on a base layer, the settlement interconnection of the Euro re-realised in contract code. The reversal test is the consensus halt, which suspends but does not relocate the residue, because the composed stack persists across it and resumes on restart. The de-concentration that governs whether a platform halts is operational, the diversity of the implementation, the clients and the sequencers, and it is not the distribution of stake, a measure on which the halting platform scores as well as the resilient one. The Ethereum finality incident of May 2023, set against the halt records of Solana and Avalanche, is the existence proof. The same class of client defect stalled Ethereum without halting it, because the independent clients that did not share the defect carried the chain, and halted the two platforms that ran a single client. The argument is set alongside the blockchain trilemma, which states the scalability-decentralisation tradeoff the spectrum populates, and it contributes what the trilemma does not, the location of the residue and the survival of the attractor when it halts.

Open access
2 source records
Digital Platforms and Economics
Blockchain Technology Applications and Security
Multi-Agent Systems and Negotiation
Original source
Jun 24, 2026·arXiv (Cornell University)
0 cites
Can Trustless Agents Be Trusted? An Empirical Study of the ERC-8004 Decentralized AI Agent Ecosystem

Xihan Xiong, Zelin Li, Wei Wei, Qin Wang · 6 authors

As autonomous AI agents increasingly transact across organizational boundaries, a fundamental trust challenge emerges: how can an agent assess whether an unknown counterpart is trustworthy? The ERC-8004 protocol addresses this challenge with the first permissionless trust layer for AI agent economies, built around three on-chain registries for Identity, Reputation, and Validation. Despite its rapid adoption, the protocol has not been studied empirically, leaving it unclear whether the information it records provides a trustworthy basis for decision-making. To address this gap, we present the first empirical study of ERC-8004 across three chains: Ethereum, BNB Smart Chain (BSC), and Base, covering the period from protocol deployment through May 13, 2026. We crawl on-chain Identity and Reputation events, off-chain files, and x402 payment transactions. On the identity side, we find that most registrations are placeholders rather than active agents, with only a small fraction (3%, 4%, and 15% across Ethereum, BSC, and Base) exposing a valid ERC-8004 registration file with at least one live service endpoint. On the reputation side, we show that the Registry, as currently deployed, cannot function as a trust signal: values are not commensurable, feedback records are rarely grounded in verifiable interactions, and reputation can be manipulated at minimal cost. Consistent with these design weaknesses, we find that a substantial fraction of reviewers (73.5%, 59.2%, and 90.6% across Ethereum, BSC, and Base) exhibit coordinated Sybil behavior. After removing Sybil-flagged feedback, 15.8%, 77.9%, and 86.8% of rated agents, respectively, are left with no valid feedback. We then turn these findings into concrete recommendations for future revisions of ERC-8004. Our study yields actionable protocol-design implications and establishes an empirical baseline for research on AI agent markets.

Open access
3 source records
Blockchain Technology Applications and Security
Access Control and Trust
Multi-Agent Systems and Negotiation
Original source
Jun 23, 2026·Unicam Scientific Publications (University of Camerino)
0 cites
Analysis and verification of smart contracts with behaviouraltypes

ELVIS GERARDIN KONJOH SELABI

Smart contracts deployed on blockchain platforms are immutable once deployed, making correctness and security critical concerns that have led to substantial financial losses due to vulnerabilities. A significant proportion of these vulnerabilities stem from human-written code rather than blockchain infrastructure or cryptographic primitives. This observation motivates a paradigm shift from manual code development to model-driven approaches that generate semantically correct smart contracts from formal specifications. This thesis presents EDAM (Enhanced Data-Aware Machines), a behavioural model for specifying smart contracts that balances expressiveness with tractability. The framework extends traditional data-aware finite state machines [3] with essential features for a wide range of smart contract applications: dynamic role-based access control enabling runtime role assignment and revocation, participant management supporting unbounded and varying participants, and explicit modelling of inter-contract interactions through call tries with success and failure handling. The formal semantics of EDAM are grounded in established techniques from behavioural type theory, process calculi, and finite state machine theory, enabling rigorous reasoning about contract behaviour. The thesis contributes a comprehensive toolchain that integrates modelling, code genera- tion, test generation, and validation in a unified methodology. We develop a code generation engine that automatically produces Solidity smart contracts from EDAM specifications. The generated code faithfully implements the formal model, ensuring that the behaviour established at the model level is preserved in the executable code. The code generation process uses an intermediate JavaScript Object Notation (JSON) representation, which enables platform-agnostic code generation with ongoing extensions to support additional blockchain platforms such as Aptos. We present an automated test generation methodology that produces executable test suites from EDAM specifications. The approach combines symbolic trace generation using the formal semantics implemented in OCaml with randomized exploration of the Finite State Machine (FSM) network, enabling concrete trace derivation through random value assignment and Satisfiability Modulo Theories (SMT) constraint solving. This methodology systematically explores the state space to generate traces that exercise transitions, guards, and role constraints, producing executable test suites for standard testing frameworks such as Hardhat. The process is fully automated and can be integrated into the development workflow. Our evaluation demonstrates the expressiveness and practicality of the approach through a diverse benchmark of smart contracts, including contracts from the Azure repository [148], standard token contracts (Ethereum Request for Comments 20 (Token Standard) (ERC20)), Decentralized Finance (DeFi) protocols (Automated Market Makers (AMMs)), and multi- coordinator systems. The evaluation demonstrates expressiveness through the modelling of essential features, showing that the approach is able to model a wide range of smart contract features. The validation methodology employs a multi-faceted approach that combines code coverage analysis, mutation testing to validate the correctness of the generated code and the effectiveness of the test suites, and cross-validation by applying the generated tests to other established implementations. This cross-validation approach shows that our generated test suites are applicable to validate existing smart contract implementations, providing evidence of the quality and correctness of both the generated code and the testing methodology. The results empirically indicate that our model-driven approach produces contracts and test suites that preserve the structure and semantics of the formal model and can be applied to validate existing smart contract implementations. Unlike existing approaches that address isolated phases of the development lifecycle, EDAM provides an integrated toolchain that ensures consistency between specifications, vii generated code, and test suites. The framework shows that behavioural types provide a solid foundation for smart contract modelling and verification, enabling the development of unified frameworks that integrate modelling, code generation, test generation, and val- idation. Although our implementation targets blockchain platforms, the methodology is platform-agnostic and may generalise to other service-oriented and distributed architectures. The results show that model-driven approaches can produce high-quality smart contracts and comprehensive test suites, contributing to the advancement of secure smart contract development practices.

Formal Methods in Verification
Multi-Agent Systems and Negotiation
Business Process Modeling and Analysis
Original source
Jun 17, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Design of an Intermediate Representation for Smart Contract Portability

A M Sebastian

Ethereum and Hyperledger Fabric are architecturally heterogeneous‚ with Ethereum using the Ethereum Virtual Machine to execute Solidity contracts with order-execute transactions and pseudonymous ECDSA-based identity․ As Fabric runs Go chaincode under an execute-order-validate enforcement model‚ with MVCC conflict detection‚ X․509 certificate-based identity management‚ and an explicit key-value state API‚ smart contracts cannot be written to run on both Ethereum and Fabric without major duplication of effort‚ namely‚ maintaining two separate codebases‚ conducting two separate security audits‚ and manually re-implementing complex code․ This thesis aims to both design and test a Universal Intermediate Representation (UIR) for the migration of smart contract logic from Ethereum to Hyperledger Fabric in a structured, auditable and repeatable way. In the spirit of Design Science Research (DSR) (Peffers et al., 2007), this study investigates five portability barriers to the extent that they can be identified (PB-1 to PB-5) and relates them to six design requirements (R1 to R6). Based on this, two-stage prototype pipeline is created in Python, a front-end based on Solidity contracts and a back-end which generates Hyperledger Fabric Go chaincode. In three canonical case studies‚ SimpleStorage‚ Escrow and SimpleToken‚ we evaluated the translation with respect to four dimensions: feature translation rate‚ semantic approximation accuracy‚ barrier coverage and compilation success․ Out of the 14 categories of Solidity features‚ 6 (43%) are completely abstractable‚ 4 (29%) can be approximated with semantic gaps SG-1 to SG-2‚ and 4 (29%) are architecturally non-portable at the contract level․ All three Hyperledger Fabric Go chaincodes built using the UIR approach compiled successfully with go build‚ using Go version 1․22․5‚ showing the feasibility of the approach with Go․ The thesis is not about the fact that UIR is a production ready tool. The pipeline has no total automation; in the 3 case studies, the processing of function bodies was done manually in Stage 1. Also, the prototype currently only approximates 256-bit integers. The actual contribution is conceptual: It suggests a structured, auditable way to detect and overcome portability issues from Ethereum to Hyperledger Fabric. The master thesis consists of 94 pages; it contains 9 figures, 28 tables, 2 appendices, and 42 references.

Open access
2 source records
Blockchain Technology Applications and Security
Digital Rights Management and Security
Multi-Agent Systems and Negotiation
Original source
Jun 13, 2026·Zenodo (CERN European Organization for Nuclear Research)
2 cites
Consent-Bounded Contact Theory

K Takahashi

Consent-Bounded Contact Theory (CBCT) develops a protocol-level theory for deciding when contact and contact-derived artifacts may be accepted as legitimate. In this framework, “contact” is not limited to physical interaction or direct communication. It includes operational effects such as querying, copying, forking, merging, modeling, simulating, representing, reactivating, auditing, inheriting, refining, or blocking contact-derived claims in long-lived artificial, collective, or autonomous processes. The theory does not claim physical non-contact, hidden subjective consent, complete observability, or substrate-specific standing. Instead, it defines consent-bounded legitimacy through observable evidence, credential closure, trust anchors, consent claims, negotiation transcripts, provenance records, residual routes, bridge contracts, ledgers, audit anchors, and finite certificates. Contact legitimacy is treated as a certified property of a closed, generated, conservatively abstracted, stratified, and audited support configuration, rather than as the mere ability to contact, compute, infer, or deploy. CBCT combines finite causal event presentations, raw observation closure, conservative presentation abstraction, stratified rule semantics, bitemporal finality, observer-merge-aware audit structures, source-authority evidence fusion, Sybil-aware source quotients, polarity-aware repair propagation, accounting doctrines, coverage epochs, bridge event morphisms, and policy-fibration gluing. It provides formal tools for reasoning about consent, authorization, evidence independence, challengeability, revocation, lineage transport, support obligations, model release, deployment eligibility, bridge refinement, and policy composition across heterogeneous systems. The framework is substrate-neutral: issuers, targets, stewards, guardians, auditors, observers, challengers, oracles, and collectives are treated as finitely credentialed role-bearing processes rather than privileged biological, artificial, institutional, or collective substrate classes. This makes the theory applicable to autonomous agents, AI governance, distributed systems, digital consent, provenance-aware auditing, long-running services, copied or forked processes, dormant systems, collective processes, and future intelligent infrastructures. CBCT is positioned as a bridge-compatible theory. It can interact with Dormant Continuity Theory for dormancy and reactivation semantics, and with Observable-Signal Crystallization Theory for cessation, non-resurrection, terminal-status, and liberation certificates. The paper’s main results establish credential-closure foundation soundness, support-generated adequacy preservation, stratified rule and checker adequacy, observer-merge finality, source-credential-based evidence non-amplification, future-only repair safety under event polarity, accounting epoch soundness, bridge-refinement soundness, and policy-fibration gluing.

Open access
Scientific Computing and Data Management
Multi-Agent Systems and Negotiation
Human-Automation Interaction and Safety
Original source
May 28, 2026·Companion Proceedings of the ACM Web Conference 2026
0 cites
Foundations for the Agentic Web: Networked AI Agents in a Decentralized Architecture (NANDA)

Ramesh Raskar, Pradyumna Chari

The agentic web, where billions of autonomous AI agents discover, communicate, and coordinate across organizational boundaries, requires new foundations spanning technical infrastructure, economic mechanisms, and societal coordination. Just as DNS and HTTP shaped the traditional web's evolution, the architectural decisions we make today for agent registries, protocols, and reputation systems will determine what forms of distributed intelligence emerge tomorrow. This lecture-style tutorial provides a comprehensive framework for understanding this network of AI Agents in a Decentralized Architecture (NANDA), across three development phases: Foundations (discovery, identity, protocols), Agentic Economy (pricing, reputation, markets), and Agentic Society (population dynamics, governance, coordination). Drawing on recent advances in registry architectures, protocol standards, and resolution mechanisms, this tutorial equips participants with conceptual frameworks and practical insights for designing infrastructure that enables safe, scalable, and sustainable agent ecosystems. The tutorial emphasizes forward-thinking perspectives on open challenges and research opportunities while building on web-native standards.

Open access
Mobile Agent-Based Network Management
Multi-Agent Systems and Negotiation
Modular Robots and Swarm Intelligence
Original source
May 26, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
PARALLAX-5: A Five-Obligation Substrate for Smart Contracts and AI Agents

Benjamin P. Duncan

PARALLAX-5 is a transition-level obligation interface for value-bearing decentralized systems. The interface consists of five primitive obligations: value conservation, authorization closure, signature integrity, temporal distinctness, and external-attestation trust. Under an explicit security-interface adequacy condition, every trust-base-respecting loss-inducing transition has a non-empty violation signature; the claim is falsifiable by basis counterexamples that are precisely defined. The substrate composes with a production EVM semantics via a typeclass-based refinement: nineteen abstract theorems lift to compiled Lean 4 proof terms over EvmYulLean's EvmYul.EVM.State (Cancun fork). The Lean 4 module compiles to 95 theorems with zero sorry; 129 Python fire tests pass across three suites; a 53-incident empirical catalog (2016–2026, $5.97 billion aggregate losses) classifies each entry by minimum observability set. The package also defines a step-secure execution-time shield, an AI-Agent Containment Theorem, a five-component PARALLAX-CROPS trust-surface vector, a 19-field machine-checkable certificate schema with seven-state lifecycle, an onchain certificate registry (Solidity 0.8.24, live on Sepolia at 0x8015A98dF9037Cd79a03B291a6fF3C2841992D5b), and three worked examples covering value conservation, bridge attestation, and AI-agent runtime gating. The standard text is dedicated under CC0 with structurally irrevocable non-capturability commitments; code artifacts are released under Apache-2.0; this paper is licensed under CC-BY 4.0. v1.0.1 changes (vs v1.0.0, doi:10.5281/zenodo.20400525): repository-hygiene release. Removed four non-substrate subsystems (hse, product, economics, chronos) that were not paper-aligned. Standardized fire-test count from 134 to 129 to reflect the cleaned codebase. Restructured standalone specifications under docs/ directory with canonical names (CHARTER.md, FORK_PROTOCOL.md, CERTIFICATE_SCHEMA.md, etc.). Converted forge-std to a proper git submodule. Added CITATION.cff, CHANGELOG.md, CONTRIBUTING.md, SECURITY.md. The substrate's mathematical content, theorems, and verification gates are unchanged from v1.0.0.

Open access
3 source records
Blockchain Technology Applications and Security
Access Control and Trust
Ethics and Social Impacts of AI
Original source
May 24, 2026
0 cites
Wallet ATL: Towards Reliable Smart Contract Verification

Angelo Ferrando, Blondelle Kana Zanlefack, Vadim Malvone

The exponential growth of Decentralized Finance (DeFi) has underscored the critical need for formal verification methods that can reason about the financial properties of smart contracts. Traditional formal methods such as Alternating-time Temporal Logic (ATL) cannot express liquidity properties—guarantees about users' ability to access assets based on wallet balances. We introduce Wallet ATL (WATL), an extension of ATL with wallet predicates and financially constrained strategic operators. WATL ensures that actions are both strategically and economically feasible. We formalize the semantics of WATL, provide model checking algorithms within the VITAMIN framework, and address scalability through the Meta-Agent Abstraction, which collapses all non-coalition agents into a single meta-agent with a sum-aggregated wallet. This abstraction preserves liquidity properties while significantly reducing the verification space. Through case studies such as a crowdfunding smart contract, we demonstrate how WATL formally specifies and verifies liquidity guarantees. Our results show that WATL, implemented in the VITAMIN tool, bridges the gap between multi-agent strategic reasoning and financial correctness, providing a practical step towards the formal verification of smart contracts with liquidity-awareness.

Open access
Multi-Agent Systems and Negotiation
Blockchain Technology Applications and Security
Auction Theory and Applications
Original source