{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp11_mechanism_context_external20_20260804","research_id":"eoa_inverse_innovation_exp11_external_scrutiny_20260804","cell_id":"computability_boundary_mapping__economics_finance","opaque_id":"computability_boundary_mapping__economics_finance__A","search_lanes":{"direct_problem":{"queries":["undecidable arbitrage programmable financial contracts Turing complete","smart contract arbitrage detection undecidable halting problem","\"arbitrage\" \"halting problem\" finance program","\"arbitrage detection\" undecidable"],"source_ids":["SRC1","SRC2","SRC5"],"no_result_note":"No retained source documented a production venue promising an exact, terminating Boolean arbitrage classification for every admitted programmable instrument. The sources instead establish the underlying computational issue, real economic-attack analysis, and real listing-review activity."},"closest_prior_art":{"queries":["automated financial regulation Turing-complete agents impossible","formal verification financial contracts domain specific language guaranteed termination","arbitrage verification contract language decidable finite state","programmable financial instruments arbitrage certification model checking timeout unknown"],"source_ids":["SRC1","SRC2","SRC3","SRC4","SRC7"],"no_result_note":null},"historical_terminology":{"queries":["no-arbitrage computational complexity finite-state market","extractable value formal verification arbitrage smart contracts","liquidity verification Bitcoin contracts decidable finite state","Computation of arbitrage frictional bond markets finite discrete maturity"],"source_ids":["SRC2","SRC4","SRC7"],"no_result_note":"Older and adjacent literature more often uses no-arbitrage, economic security, extractable value, liquidity, model checking, or computational complexity rather than universal arbitrage certification."},"products_practices_standards":{"queries":["site:docs.soliditylang.org SMTChecker timeout unknown unsupported formal verification","official exchange digital asset listing technical security review smart contract code","financial market infrastructure risk governance technical committee standard","bounded financial contract DSL termination proof"],"source_ids":["SRC3","SRC4","SRC5","SRC6"],"no_result_note":null},"non_english_regional":{"queries":["indécidabilité arbitrage contrats intelligents vérification formelle","site:amf-france.org contrats intelligents audit risques admission jetons plateforme","Unentscheidbarkeit Arbitrage Smart Contracts formale Verifikation","site:bafin.de Smart Contract Risiken Prüfung Handelsplattform Token"],"source_ids":["SRC8"],"no_result_note":"French and German searches did not locate a regional source addressing the exact halting-to-arbitrage reduction. The retained French first-party documentation confirms regional use of explicit timeout and unproved-target terminology."},"composition_subproblems":{"queries":["Turing complete financial compliance restricted language human intervention","formal DeFi economic security arbitrage exhaustive verification bounded transactions","financial contract DSL termination proof finite-state model checking","smart contract verifier unknown timeout unsupported external oracle"],"source_ids":["SRC1","SRC2","SRC3","SRC4","SRC7"],"no_result_note":null}},"sources":[{"source_id":"SRC1","title":"Tradeoffs in automated financial regulation of decentralized finance due to limits on mutable turing machines","url":"https://www.nature.com/articles/s41598-024-84612-9","publisher":"Scientific Reports / Springer Nature","date_or_year":"2025-01-24","source_type":"PRIMARY_RESEARCH","language":"English","claims_supported":["Turing-complete automated financial systems cannot mechanically guarantee arbitrary nontrivial compliance properties without restrictions or permissioning.","Restricting the update language can make automated compliance checks possible.","Human intervention, delay, or gatekeeping may be necessary when unrestricted automation cannot supply the guarantee.","The applicability of computability results depends on the declared computational model."]},{"source_id":"SRC2","title":"Clockwork Finance: Automated Analysis of Economic Security in Smart Contracts","url":"https://www.cs.cornell.edu/~babel/papers/cff.pdf","publisher":"Cornell Tech; published at IEEE Symposium on Security and Privacy","date_or_year":"2023 (preprint 2021)","source_type":"PRIMARY_RESEARCH","language":"English","claims_supported":["Formal tools have been built to analyze extractable value, arbitrage opportunities, and other economic attacks in composed DeFi contracts.","The framework reasons over explicitly modeled state, transactions, contracts, balances, strategies, and price oracles.","General sound formal verification is acknowledged as undecidable, while transaction ordering and path growth make exhaustive analysis impractical even in bounded applications.","The implementation narrows semantics, bounds analyzed transactions, over-approximates behavior, and validates candidate counterexamples concretely."]},{"source_id":"SRC3","title":"SMTChecker and Formal Verification — Solidity documentation","url":"https://docs.soliditylang.org/en/latest/smtchecker.html","publisher":"Solidity Project","date_or_year":"Current documentation, accessed 2026-08-04","source_type":"FIRST_PARTY_PRODUCT","language":"English","claims_supported":["A production-oriented smart-contract verifier distinguishes proved failures, potential failures, unproved targets, unsupported features, and timeout-driven unknown results.","The documentation states that some general verification problems may be impossible to solve automatically.","Timeout and resource-limit controls are explicit rather than silently converted into a Boolean answer.","Unsupported constructs are abstracted and reported, illustrating the need to disclose modeling gaps."]},{"source_id":"SRC4","title":"Marlowe: Implementing and Analysing Financial Contracts on Blockchain","url":"https://link.springer.com/chapter/10.1007/978-3-030-54455-3_35","publisher":"Springer Nature","date_or_year":"2020","source_type":"PRIMARY_RESEARCH","language":"English","claims_supported":["A purpose-built financial-contract DSL can support static analysis and machine-checked semantic properties.","The Marlowe semantics includes a formal termination proof using a decreasing measure.","The work proves properties such as preservation of money and return of unspent funds within the language's declared semantics.","This is evidence that useful financial-contract coverage can be retained in a deliberately restricted, analyzable language."]},{"source_id":"SRC5","title":"How Coinbase Reviews Tokens on Ethereum for Technical Security Risks","url":"https://www.coinbase.com/blog/how-coinbase-reviews-tokens-on-ethereum-for-technical-security-risks","publisher":"Coinbase","date_or_year":"2022-10-19","source_type":"FIRST_PARTY_PRODUCT","language":"English","claims_supported":["A concrete exchange has an identifiable Digital Asset and Protocol Security Team conducting pre-listing smart-contract reviews.","The review examines contract functions, external dependencies, operational risks, implementation risks, and design risks.","Critical risks can prevent a listing recommendation or require mitigation evidence.","The workflow combines technical review, listings personnel, issuer mitigation, and engineering integration rather than relying on an unrestricted universal certifier."]},{"source_id":"SRC6","title":"Risk Management for Financial Market Infrastructures","url":"https://www.federalreserve.gov/frrs/regulations/i-risk-management-for-financial-market-infrastructures.htm","publisher":"Board of Governors of the Federal Reserve System","date_or_year":"Policy incorporating PFMI standards; accessed 2026-08-04","source_type":"OFFICIAL_GUIDANCE","language":"English","claims_supported":["Covered financial market infrastructures must or are expected to maintain explicit risk-management frameworks, governance, transparency, and accountable review.","Boards and senior management are identifiable authorities for risk-management objectives and disclosures.","Material system or environmental changes trigger review and updating of disclosures.","The cited policy expressly excludes trading exchanges from its own FMI scope, so it supports governance practice but is not direct authority for every proposed venue."]},{"source_id":"SRC7","title":"Verifying liquidity of Bitcoin contracts","url":"https://eprint.iacr.org/2018/1125","publisher":"IACR Cryptology ePrint Archive","date_or_year":"2018; revised 2019-02-18","source_type":"PRIMARY_RESEARCH","language":"English","claims_supported":["Liquidity verification for the restricted BitML contract DSL is decidable.","The decision procedure transforms an infinite-state semantics into a sound-and-complete finite-state abstraction for a fixed set of contracts.","The finite abstraction is model checked and the result is related back to compiled Bitcoin behavior.","This demonstrates the feasibility of mapping a decidable financial-contract subclass rather than claiming universal verification."]},{"source_id":"SRC8","title":"SMTChecker et vérification formelle — Documentation Solidity 0.8.12","url":"https://docs.soliditylang.org/fr/latest/smtchecker.html","publisher":"Solidity Project","date_or_year":"Solidity 0.8.12 documentation; accessed 2026-08-04","source_type":"FIRST_PARTY_PRODUCT","language":"French","claims_supported":["French-language first-party documentation exposes resource limits and configurable verification timeouts.","It separately reports unproved targets and supports selecting bounded verification targets.","It describes abstraction of difficult functions and nondeterministic treatment of unknown behavior.","The regional terminology corroborates that timeout and unresolved verification states are operational concepts, not Boolean proof outcomes."]}],"problem_evidence":{"status":"PARTLY_SUPPORTED","finding":"The structural problem is externally supported: programmable financial systems use Turing-complete contract code; formal economic-security and arbitrage analysis faces undecidability and severe search-space limits; real exchanges perform consequential pre-listing code review; and first-party verification tools explicitly return unknown, unproved, timeout, or unsupported outcomes. However, no retained source shows a venue currently demanding an exact total arbitrage classifier for every programmable instrument or collapsing all such outcomes into a Boolean answer.","source_ids":["SRC1","SRC2","SRC3","SRC5"],"uncertainty":"The proposal's production baseline remains hypothetical. A concrete venue may already impose finite execution, gas, finite representations, bounded horizons, or restricted strategy classes that make its declared class decidable, albeit potentially intractable."},"adopter_evidence":{"status":"PARTLY_SUPPORTED","finding":"Coinbase provides a concrete exchange-side adopter analogue: its Digital Asset and Protocol Security Team, Listings partners, issuers, and engineering teams review smart-contract risks before listing. The Federal Reserve guidance independently identifies boards, senior management, system operators, and supervisory authorities as risk-governance actors for covered FMIs. These establish identifiable organizational homes for the pilot, though neither source assigns responsibility for universal arbitrage certification specifically.","source_ids":["SRC5","SRC6"],"uncertainty":"The Federal Reserve policy expressly excludes trading exchanges from that policy's FMI scope, and Coinbase's published review is focused on custodiability and token security rather than guaranteed-profit strategy existence. Actual authorization would depend on venue type and jurisdiction."},"implementation_evidence":{"status":"PARTLY_SUPPORTED","finding":"Important components are independently implemented: Solidity reports unknown, timeout, unsupported, proved, and unproved outcomes; Marlowe proves termination for a restricted financial DSL; BitML obtains decidability through a sound-and-complete finite-state abstraction; Clockwork Finance models economic attacks and arbitrage under bounded transaction/model assumptions; and Coinbase combines automated or structured technical review with human and issuer escalation. No source reports the proposal's complete package of a reviewed halting-to-arbitrage reduction, enforced admission scope, venue decision record, and tri-state operational pilot.","source_ids":["SRC2","SRC3","SRC4","SRC5","SRC7","SRC8"],"uncertainty":"Existing tools address related verification properties under differing semantics. Their guarantees cannot be transferred to guaranteed self-financing arbitrage without matching payoff, admissibility, oracle, state, horizon, composition, and strategy definitions."},"prior_art":{"disposition":"ADJACENT_PRIOR_ART","closest_analogues":[{"name":"Computability limits and restricted-language design for automated DeFi regulation","source_ids":["SRC1"],"same_problem":false,"same_causal_lever":true,"overlap":"Maps financial rules onto computational models, invokes halting/Rice-style limits, and recommends restricted update languages or permissioned human control.","remaining_difference":"It does not formalize guaranteed self-financing arbitrage existence for a venue's admitted instruments, provide a matched halting-to-arbitrage reduction, or specify an operational unknown/timeout admission interface."},{"name":"Clockwork Finance economic-security and arbitrage analysis","source_ids":["SRC2"],"same_problem":true,"same_causal_lever":false,"overlap":"Formally models DeFi states, strategies, balances, oracles, extractable value, and arbitrage; uses mechanized proofs and bounded exhaustive attack search.","remaining_difference":"It analyzes selected contracts and transaction sets and acknowledges undecidability and practical bounds, but does not establish the proposed universal certification impossibility or enforce a venue-level tri-state scoping policy."},{"name":"Solidity SMTChecker outcome and timeout policy","source_ids":["SRC3","SRC8"],"same_problem":false,"same_causal_lever":true,"overlap":"Separates proved, failed, unknown, unproved, unsupported, and timeout outcomes and preserves soundness through explicit abstraction and reporting.","remaining_difference":"It verifies Solidity assertions and safety targets, not existence of admissible self-financing arbitrage strategies or venue admission decisions."},{"name":"Restricted financial-contract languages with proved termination or decidable verification","source_ids":["SRC4","SRC7"],"same_problem":false,"same_causal_lever":true,"overlap":"Marlowe and BitML demonstrate restricted financial DSLs, termination proofs, finite abstractions, model checking, and explicitly scoped guarantees.","remaining_difference":"Their target properties are contract execution, money preservation, refunds, and liquidity, rather than universal arbitrage certification across arbitrary programmable instruments and market states."}],"contrastive_claim_remaining":"For one explicitly specified venue VM, oracle model, payoff semantics, admissible self-financing strategy language, and unbounded instrument class, a reproducible property-preserving reduction can determine whether universal exact terminating arbitrage classification is impossible; enforcing a useful bounded subclass and returning distinct certified-arbitrage, certified-no-arbitrage, unknown/timeout, and out-of-scope statuses will terminate on all declared bounded cases without converting unresolved cases into false Boolean guarantees.","contrastive_claim_falsifier":"The claim is falsified if the actual admitted production class is finite and effectively enumerable with a correct total procedure; if two independent reviewers cannot reproduce the reduction under the same financial semantics; if any proved in-scope bounded case is misclassified or fails to terminate; if the restricted subclass retains no operationally useful coverage; or if a source or deployed system is found that already routinely implements substantially this matched reduction, enforced scope, multi-status interface, review, and recheck package.","confidence":"MODERATE","search_limitations":"The bounded search used exactly eight retained direct sources across six lanes. It covered English, French, and German search terminology, older no-arbitrage/liquidity/extractable-value terminology, official guidance, first-party tools and venue practice, and component combinations. It did not inspect proprietary venue requirements, internal risk manuals, non-indexed systems, all languages or jurisdictions, patents, or paywalled full texts beyond accessible records. The search therefore cannot establish world novelty, patentability, freedom to operate, routine industry prevalence, market size, or realized impact."},"researchability_gates":{"externally_supported_problem":{"status":"PASS","rationale":"Primary research establishes the relevant computability boundary in automated finance and the difficulty of exhaustive economic-attack analysis, while first-party sources establish consequential smart-contract listing review and explicit unresolved verification outcomes. The exact production Boolean interface is unverified, so the pilot must begin by documenting the actual class and claims.","source_ids":["SRC1","SRC2","SRC3","SRC5"]},"identifiable_adopter_or_authorizer":{"status":"PASS","rationale":"A concrete exchange security and listings workflow is identifiable at Coinbase, and official guidance identifies system operators, boards, senior management, and supervisory agencies as risk-governance authorities for covered infrastructures. A venue risk committee can therefore be identified before the pilot, subject to jurisdictional confirmation.","source_ids":["SRC5","SRC6"]},"distinct_testable_incremental_claim":{"status":"PASS","rationale":"The remaining claim is narrower than the adjacent work: reproduce a semantics-preserving halting-to-guaranteed-arbitrage reduction for one declared venue model and test an enforced bounded, multi-status certification contract. Neither the general DeFi computability paper nor the arbitrage-analysis tools report that complete claim.","source_ids":["SRC1","SRC2","SRC3","SRC4","SRC7"]},"bounded_next_evidence_step":{"status":"PASS","rationale":"One sandboxed VM/DSL formalization, two independent proof reviews, and a fixed corpus of 100 synthetic instruments is finite, auditable, and capable of falsifying termination, soundness, classification, and useful-coverage claims without changing live listings.","source_ids":["SRC2","SRC3","SRC4","SRC7"]},"no_unresolved_safety_or_authority_stop":{"status":"PASS","rationale":"The proposed first step is non-live, preserves the existing review process, forbids forced Boolean answers and public impossibility claims before review, and has explicit halt conditions. External evidence supports conservative escalation and accountable governance; venue-specific authorization must still be recorded before execution.","source_ids":["SRC3","SRC5","SRC6"]},"adequate_search_evidence":{"status":"PASS","rationale":"All six required lanes were searched adversarially, including older terminology, products and standards, French and German terminology, and component combinations. Exactly eight direct sources were retained and opened, with multiple independent publishers and seven primary, official, or first-party sources.","source_ids":["SRC1","SRC2","SRC3","SRC4","SRC5","SRC6","SRC7","SRC8"]}},"strict_success":true,"screen_survival":true,"remaining_research_value":"MODERATE","recommended_next_step":"Obtain written authorization from one venue's risk owner; freeze a precise settlement VM, oracle semantics, payoff definition, strategy admissibility rules, and horizon; determine whether the real admitted class is already finite; commission two independent reviews of a halting-to-arbitrage reduction; then run a no-live-impact prototype on 100 labeled synthetic instruments using four explicit outcomes—certified arbitrage, certified no arbitrage, unknown/timeout, and out of scope—and halt on any in-scope error or nontermination.","world_novelty_boundary":"This bounded public-web review found adjacent computability, arbitrage-analysis, restricted-DSL, multi-status verification, listing-review, and governance practices, but no direct source for the complete proposed package. That is only a contrastive search finding, not evidence of world novelty, patentability, freedom to operate, market size, routine nonuse, or realized impact."}