No governance system stays uncaptured. The honest design questions are the capture rate, and whether the removal levers remain reachable as capture accumulates. This chapter is the standing list of known attack surfaces — published, because a threat model kept private is a threat model already failing. Each entry names the attack, the countermeasures in place, and what remains genuinely unsolved.
Terminal-value signals — asking people how life actually feels rather than tracking a number that stands in for it — close the classic proxy gap named by Goodhart's law, where a measure stops being a good measure once it becomes the target. And gaming moves to the two layers that remain: the formation of perception itself (chapter 13), and the weight-setting layer, because lobbying the metric is often cheaper than satisfying it. Countermeasures: rotation among the sensor questions, adversarial red-teaming of the measures, paying people to find the ways they can be gamed, and keeping the weight-setting layer genuinely contested ground under the broadest tier's custody. Above all, no lock-in: monitoring is never a one-time calibration. What stabilizes this system is the meta-process, not any frozen mechanism — the common-law pattern, where the method persists while outputs churn.
Every liquid-democracy deployment — systems where you may vote an issue yourself or hand your vote to someone you trust and take it back at will — with published data trended into power-law super-delegates, a handful of people ending up holding most of the delegated weight — LiquidFeedback, the German Pirate Party's delegation platform, starkly; Google Votes, an internal experiment among Google employees, more gently. This design's threshold-crossing — a delegate only takes a seat once enough weight has piled onto them — makes the pull stronger, not weaker. So the counter-pressure is structural: per-delegate caps bound any individual's accumulation, revocation is never more than a cycle away, and damping can be applied to accumulated weight. Two further levers compose here. Selling a passage vote means selling the only asset a delegate has — the delegated support that is their entire payoff — in a market where every delegator can see the voting record and re-delegate the same day; corruption's expected value is set by the revocation speed, which is a parameter, not a hope. And the pool refresh of chapter 4 — candidacy by lot, no campaigning back in — attacks the power law at both ends: no faction can pre-position around a random cohort, and no super-delegate can build a dynasty on name recognition, because the only way to stay is to keep deserving the weight and the only way in is chance. Sortition is the oldest anti-capture trick in the book; here it guards the door while merit holds the room. Concentration is not prevented — it is taxed, capped, refreshed, and made permanently revocable. Managed, not solved.
Where quorums exist — a minimum turnout below which nothing passes — boycotts follow: opponents learn that staying home kills a measure more reliably than voting no. Chapter 6's floors are affirmative — silence never counts — and delegated weight counts toward engagement, so starving an issue requires delegates to visibly sit out, which their principals, the citizens whose weight they carry, can see and punish by re-delegation within the cycle. The attack is not impossible; it is expensive, legible, and attributable, which is what a defense is.
The subsidiarity ratchet (chapter 9) — powers slide down to the smallest scale that can carry them, and climb back up only on proven spillover — creates a novel incentive: a faction preferring local control can try to make the national program fail on purpose. Defenses: demotion requires consistent failure across the whole backoff schedule — the reviews at one year, three, seven, fifteen — never one bad year; and sabotage of delivery tends to be legible in the perception layer in ways mere underperformance is not — people can feel the difference between a program that struggles and one that is being strangled. Named here as a known vector under active monitoring, not a solved one.
Mass retrospective judgment is real signal about how life feels and poor at causal credit assignment — electorates punish incumbents for droughts and shark attacks, and policy lags blur every ledger. Mitigations, layered: atomic policies wherever possible (single subjects; the omnibus bill is attribution-laundering with a page count), per-proposal maturation horizons so verdicts arrive when effects exist, deliberative panels and prediction markets — randomly chosen citizens who study an issue before judging, and betting markets whose odds function as forecasts — as instruments between raw sentiment and verdict, and AI as legibility (chapter 13). And one mitigation deeper than all of them: skin in the game grows capability. Electorate incompetence is partly an artifact of systems that made competence pointless; people reason measurably better when their judgment visibly moves outcomes. Designing for consequence is designing for capability — at some point the electorate is responsible, and this system's job is to make that responsibility real rather than to govern on their behalf.
Finally the meta-surface: the constraint layer itself. Bureaucracies ossify; delegate classes entrench; watchdogs get bought. The answers threaded through this design — rotation and term-structure in the delegate class, sunset of unused positions, fixed position counts against elite overproduction — more people credentialed to expect power than there are seats — capture bounties that pay the flagger, sortition for audit and review roles so capture can't pre-position, and removal levers kept dumb enough to survive capture of everything cleverer. The design bet of the whole proposal, restated once more: not that capture won't be attempted, but that its rate stays below the system's repair rate, with the repair tools held by everyone.