Gaming the quirq
The attack surface of a unit of account, in order of severity, and the structural mitigations.
A unit of account is a target, and targets get gamed. quirq accounting does not escape Goodhart; it is engineered to fail loudly where activity metrics fail silently.
The attack surface
1. Budget inflation. If quirqs are the KPI, inflate B. Mitigations are structural: the budget is set by the party paying it, so inflation is self-taxing wherever budgets clear against real money (outcome-priced vendors, internal chargebacks). Where budgets are notional, benchmark them: against historical human cost for the same outcome, against market rates, and against post-hoc value audits on samples. The ledger makes inflation visible as a drifting ratio of budget to audited value. Residually: a company that lies to itself about what outcomes are worth had no unit of account before quirqs either; quirqs merely timestamp the lie.
2. Check farming. Manufacture units whose checks are trivially green. Countered by the audit gap: gold-check sampling plus the owner's acceptance authority at settlement. A unit whose checks pass but whose owner rejects is an audit event, recorded, and the check set is re-specified.
3. Verification-surface attacks. Edit the test rather than fix the code. Fully mechanical, and fully mechanically countered: the verification surface is itself under state comparison (byte-identical across the unit). Experiment E2 shows a single such check converting 100% silent success into 100% detection.
4. Self-report injection. Convince the scorer to read the agent's summary. Ruled out by construction: the mint consumes only environment-captured state. Experiment E1 quantifies what re-admitting self-report costs: every false claim settles.
5. Salami slicing. Split one outcome into many units to harvest divisible partial credit. Countered by atomic settlement as the default for holistic outcomes, and by the owner's monopoly on unit creation: workers execute units; they do not define them.
The honest summary
quirq integrity reduces to environment integrity plus budget governance. The first is an engineering property, demonstrated in the validation experiments. The second is an institutional property, held as an open hypothesis (H4) rather than an assumption, because that is what it is.
The mechanical defenses are demonstrated in validation; the institutional one (budget governance) is hypothesis H4, on the record with its falsifier. That completes the section. For the narrative around it: The Future of Work.