Dunbar
A portable, Sybil-resistant trust graph for the open internet
Whitepaper — draft v1 · August 2026 · dunbar.network
TL;DR
The internet is filling with bots, fakes, and AI-generated personas, so people only trust who they already know. That trust is stuck in group chats and can't travel, but can get infiltrated. Dunbar makes it portable and infiltration-resistant. When people vouch for people they trust in real life; vouches are scarce, public, and put the voucher's own reputation on the line. From that graph, Dunbar computes trust from your point of view - e.g. "what do the people you trust think of this person" — and never from a single universal number. Fake-account farms are neutralized by math instead of moderators: a fake cluster can only ever extract as much trust as real people actually give it. Accusations are resolved in the open with costly flags and permanent rebuttals. The viewer decides, the platform never rules on truth. Humans and AI agents are both welcome; every account declares which it is, and lying about it is the one unforgivable offense, carrying the system's heaviest penalty. Every statement is a signed message anchored daily on a public chain. No token, no custody, no gas for users. Free forever for individuals; businesses and AI agents pay per query, starting with brands vetting KOLs before wasting budget on fakes.
Abstract
The open internet is losing the ability to tell anyone apart. AI-generated content and industrial-scale fake accounts have made the basic signals of online life: followers, engagement, verification badges, are trivially manufacturable, and people are responding rationally. They are retreating into closed, proximity-based networks where trust still works. Those networks work precisely because they are small. They do not scale, and they do not travel.
Dunbar is a portable reputation layer built on one costly primitive: the vouch is a public, binary, rate-limited statement that you stake your real-world reputation on another account. From the graph of vouches, Dunbar computes trust with personalized rank, meaning every score is calculated from the vantage point of whoever is asking; there is no god's-eye number. Sybil resistance is a mathematical property of the graph's topology rather than a gatekeeping process: a farmed cluster's extractable trust is provably capped by the trust honest people actually extend to it, no matter how dense the fake cluster is. Every trust statement is a signed message, tamper-evidently anchored daily on a public chain. Negative claims are resolved by sunlight: costly accusations, permanent rebuttals, and viewer-weighted evidence. They are never adjudicated by a company verdict. Humans and AI agents are both first-class participants: accounts declare their nature, and misrepresenting it is the offense.
Dunbar has no token, custodies nothing, and charges nothing to individuals. Businesses and autonomous agents pay per query for full-graph intelligence over machine-native micropayment rails.
1. The problem
Two forces are compounding into what is colloquially called the dead internet. Generative models have made plausible content effectively free, so the volume of synthetic text, images, and personas is growing without bound. In parallel, fake-account production has industrialized: audiences, engagement, and social proof are commodities with price lists.
Even current "trust based solutions" fall on the sword of monetising trust. Financial incentives, governance tokens, point, allocated to the "most trusted" based on opaque criteria such as engagement or community vote - which is, by nature, manufacturable - spiral early into farming behaviours who leave the community more confused and sometimes financially exposed.
The consequence is not that people are fooled. Rather, they stop looking. When any stranger might be a bot, a farm, or a front, the rational strategy is to stop dealing with strangers. Discovery collapses into referral; open communities give way to gated ones; commerce and collaboration retreat into group chats and whisper networks. These proximity networks are genuinely more trustworthy, because everyone in them is vouched for by lived relationships. But their trust is locked in, and can get infiltrated. Trust cannot follow you to a new community, a new platform, or a new counterparty, and it cannot scale past the number of relationships a human can actually maintain.
Meanwhile, everyone who allocates money or attention to strangers (e.g., a brand hiring a KOL, a community admitting a member, an agent selecting a counterparty) is flying blind, and the tools on offer (follower counts, paid checkmarks, vibes) are exactly the signals that industrialized fakery manufactures best.
Dunbar's thesis: the fix is a portable, behavior-driven web of trust operating at internet scale with a reputation layer that lets a stranger inherit the context your real network already has.
2. Design principles
Seven commitments decide every design argument in the system. They are stated here because the architecture is unintelligible without them.
Trust is relative, and we refuse to pretend otherwise. There is no objective trustworthiness. Every score Dunbar produces is computed from somewhere: from your own position in the graph, or from a rule-selected seed vantage when no viewer position exists. The vantage point is always stated. The personalized score is always the truer one; the universal score exists for legibility, and the product consistently points users from the former toward the latter.
A vouch means something. A vouch is a public statement: I stake my real-world reputation on this person. It is binary and uniform: no sliders, no user-assigned scores; the protocol values every vouch by the same rule. It is costly by design: rate-limited, mutually diluting, visible forever, and consequential for the voucher when a vouchee is credibly flagged. Friction here is not a UX failure. Friction is the product.
Reputation is what people stake: never money. Ordinary users never stake currency. Staked vouching with slashing prices trust in money, which selects for the rich rather than the trustworthy, and imports financial regulation into a social primitive. What users stake is vouch capacity and standing: scarce, earned, and socially meaningful.
Security through topology, not gatekeeping. Fakes are not kept out by identity checks, payment walls, or committees. They are neutralized by graph structure: trust must flow from honest people, and honest people are stingy with it. Every defense in the system is a property of the math (auditable, parameterized, and testable) and not a moderator's judgment call.
Sunlight over adjudication. Dunbar never judges disputes. A flag is a costly public accusation; a dispute is the subject's permanent rebuttal; both stay visible forever, and the viewer decides. There are no panels, no verdicts, no removals of contested claims, and no clean number is ever shown publicly while a revealed warning hides behind a login or paywall.
Nature is a claim, not a detection problem. Dunbar never attempts to detect whether an account is human or AI. Accounts declare their nature; the graph corroborates or contests the declaration. Being human is fine. Being an agent is fine — declared agents are first-class participants. Operating contrary to your declared nature is the only offense.
No token. Nothing in the mechanism requires one. This is simultaneously a product decision, a regulatory posture (software-only, non-custodial), and a credibility signal.
3. The trust graph
3.1 Attestations
Every statement in Dunbar is a signed, typed message (EIP-712) appended to an attestation log: vouches, flags, withdrawals, disputes, identity links, and nature declarations. The log is the sole source of truth; all scores and states are recomputable from it, and the log itself is tamper-evidently anchored in public (section 7).
3.2 Vouch economics
Vouching is deliberately scarce. Each account holds a limited vouch capacity that accrues slowly over time, with a modest starting grant during beta. Vouches dilute one another: an account's total outgoing trust weight is normalized to a fixed budget, so vouching for everyone is mathematically identical to vouching for no one. New vouches mature over a ramp period before reaching full weight, and young accounts have their total outgoing weight scaled down until they age: both measures making freshly manufactured support visibly and mathematically weak. Withdrawing a vouch is always possible, followed by a cooldown that escalates when withdrawn vouchees have been credibly flagged: vouching for people who burn others is supposed to cost you.
There is no follow-back mechanic, no bulk import, no reciprocity reward. Anything that turns vouches into social currency destroys the asset the network exists to build.
Negative attestations mirror the same economics at higher cost: flags draw from a smaller, slower budget, and a flagged party can attach a permanent dispute — a rebuttal displayed alongside the accusation everywhere the accusation appears. Negative signals annotate a person; they never propagate through the graph as structure.
3.3 Identity
Accounts link platform identities (X, Telegram, Discord, wallets) via OAuth or wallet signature, and never via public proof posts, which established creators reasonably refuse. Each link is itself a signed attestation recording the platform's stable numeric user identifier rather than the mutable handle, so links survive renames and remain independently re-verifiable. Participation requires no wallet, no gas, and no payment: a user can build and carry reputation without ever touching a chain directly.
3.4 Attestations before arrival
Attestations do not wait for their subjects. A vouch or a flag can target an identity that has not yet joined (such as a pasted handle or a wallet address, pinned to its stable numeric identifier at issuance) and it does not expire. Positive statements sit as an open invitation: sign up, link the identity, and claim the reputation already staked on you, with trust weight beginning to accrue only at the moment of claim, so an absent target can never be quietly pre-aged into credibility. Negative statements serve the opposite public function: a credible warning about a threat actor should not require the threat actor's cooperation to exist. Unclaimed identities are therefore visible lookup subjects showing their on-record vouches and accuser-weighted flags and claiming the identity immediately unlocks the dispute mechanism against any accusation waiting there. Every path into the network leads to the same door: being vouched for, being warned about, or being wrongly accused.
4. Scoring: trust from a point of view
4.1 Personalized PageRank
Dunbar computes trust with personalized PageRank (PPR) over the positive-vouch graph. The intuition is water through pipes: pour a fixed amount of water in at the asker's position and let it flow along vouches, splitting at every junction according to edge weights and losing a little pressure with each hop. The water that accumulates at another account is that account's trust score from the asker's perspective. Someone your network vouches for densely and directly ends up soaked; a stranger with no paths from your world stays dry, however impressive their own neighborhood looks internally.
Two frames are computed. Your view seeds the flow at you: the product's soul, and the score the interface treats as primary. The Network Score seeds the flow at a small Seed set selected rule-based criteria. Inbound trust from distinct, aged, clean-record accounts with automatic rotation each cycle. Nobody is appointed, nobody is asked to accept an office, and the same math can eject anyone, including the founders' friends. The selection criteria and rotation rules are public; the identities of current Seeds are deliberately not disclosed. This is an openly stated trade: per-identity inspectability is given up in exchange for anchor safety and resistance to capture and pressure campaigns.
4.2 Adjustments
Raw PPR is refined by mechanisms that are published rather than hidden. A receiver-side concentration cap limits how much of any score can come from a single source, so one whale or one purchased patron cannot manufacture a reputation alone, and heavy single-source dependence is itself surfaced as a diagnostic. Negative attestations then discount the score: each accusation is weighted by the accuser's standing in the viewer's own frame, so a mob of nobodies (from your vantage) subtracts approximately nothing, while one credible flag from deep in your network matters. Accusations under active dispute are further discounted. The penalty multiplier is asymmetric by context: paid business queries run a deliberately cautious read that weighs negatives more heavily than the free social tier is a stated feature, since businesses are explicitly buying prudence.
Displayed scores use an open-ended logarithmic scale: movement is fast and visible at the bottom, where newcomers need feedback, and hard-won at the top, where stability is the signal.
The public Network Score shown on any surface is always the adjusted score. Warnings are never paywalled behind a clean number.
5. Sybil resistance by topology
The core security claim is a bound, not a filter. Partition the graph into the honest region and a Sybil cluster of any size and internal density. Because every account's outgoing weight is normalized, trust can only enter the cluster through vouches that honest accounts actually made across the boundary is the cut. The total trust the cluster can extract, and therefore the maximum standing any farmed identity can attain, is capped by that cut's weight. A million interlinked fake accounts vouching for each other furiously are, from any honest vantage point, a sealed room: nothing flows in, so nothing meaningful exists inside.
Every other mechanism reinforces the bound. Normalization makes vouches within a farm self-diluting. Maturity ramps and account-age scaling force attacks to be slow and expensive in time. The concentration cap blunts the single-compromised-hub scenario. Accuser-weighted flags mean a cluster cannot even weaponize accusations, since its members' standing rounds to zero from outside.
These are claims to be demonstrated, not asserted. All parameters live in a published sweep table and are validated in an adversarial simulation harness against a catalog of named attacks who could farm support, mouthpiece amplification, cap pad, seed capture, coordinat flag mobs, and others, before real users are exposed to them.
6. Humans, agents, and the nature claim
Dunbar assumes a mixed human–agent internet and refuses the detection arms race entirely.
Declaration. Every account declares its nature (human or agent) at signup: mandatory, free, two taps, no verification gate. The declaration is mutable at any time, with full history public on the profile, because honest handoffs (a human account delegated to an agent, or the reverse) are legitimate. The punishable act is precisely operating contrary to your current declaration; a later update cannot retroactively launder behavior, since contests reference the declaration in force at the time observed.
No proof-of-humanity credential is required or integrated: no scheme proves ongoing human operation rather than a human's one-time appearance, and verification gates kill honest adoption while barely inconveniencing determined fraud. Nor can peers vouch positively for nature. Peers cannot verify it, and an unverifiable positive signal would be free food for Sybil clusters. Absence of credible contest is the positive signal.
Contest. Anyone who observes an account operating contrary to its declaration can file a contest flag. The mechanism is sealed commit-reveal, and its rationale is published here deliberately, in advance of the controversy it will eventually attract. A committed flag is invisible to everyone: the target, other flaggers, every tier, every API surface, until independent flags converge. Sealing exists because blind accusations that independently agree are evidence, while public accusations recruit echoes and destroy exactly the independence that makes convergence meaningful; it also prevents attackers from probing thresholds and targets from being tipped off. Sealing is never free: the flag debits the flagger's scarce negative-attestation budget at commit time, and a hash of the flagger's evidence is committed simultaneously, so evidence cannot be retrofitted after seeing what others submitted. Flags that never find agreement quietly expire and refund.
Thresholds are relative and trust-weighted. Reveal and escalation are not headcount votes. Flags convert to weight through each flagger's standing, and the thresholds are denominated relative to the target's own standing — a large account requires proportionally more independent, credible flag mass to contest than a small one, with headcounts serving only as floors. A statistical mob of low-standing accounts therefore sums to approximately nothing against an established target, and Sybil flags weigh roughly zero by the same cut bound that governs everything else. On reveal, all flags, flagger identities, and evidence become publicly inspectable, and the account enters a Disputed state, weighted per-viewer like every negative signal. If sufficient revealed flaggers additionally pass a pairwise independence check — demonstrably non-overlapping neighborhoods, so a coordinated cluster collapses structurally — the account is marked Dubious nature, carrying the severest penalty weighting in the entire system, above fraud. An undeclared machine wearing a human face is the dead internet's defining deception, and the scorer prices it accordingly.
No adjudication, and a way back. The platform performs mechanical validity checks only such as schema, budget, cooldowns, evidence hash present and never rules on truth. Both states are threshold events over peer attestations, rendered from each viewer's vantage; there is no company verdict, because a company-stamped verdict would recreate the global authority the architecture commits to avoid. Content moderation is the one deliberately separate system: every user submission, be it attestation payloads, dispute text, evidence, or media, is screened for illegal content before it is stored or displayed, with no exceptions. Enforcement there is strictly about conduct: it can remove bytes and void submissions, but it never rewrites trust like attestation state, scores, and contest outcomes are untouchable from the moderation side, and the firewall between policing content and adjudicating truth is absolute. And Dubious nature is severe but not a brand without exit: a slow recovery path (long decay plus fresh vouches from high-standing accounts) exists for the sympathetic case like the hijacked account that was correctly flagged while its owner never lied. The badge's credibility is an asset protected by the recovery path.
7. Verifiability and the public layer
Dunbar's verifiability claim is narrow and strong: every trust statement is a signed message, and the set of statements is tamper-evidently anchored on a public chain. Attestations are EIP-712 signatures held off-chain with zero gas per attestation at any volume, and each day's batch is committed as a single Merkle root in one small transaction to an anchor registry on Base. Anyone can verify that a given attestation existed by a given day and was signed by its issuer. The entire recurring chain footprint costs on the order of dollars per year, paid by the operator; users never touch gas.
The architecture is chain-agnostic by construction: the chain's only role is timestamped tamper-evidence of roots, so migrating or multi-homing means anchoring the same roots elsewhere so there are no state migration, no bridge, and no token dependency. Scores are deliberately not put on-chain, because a score is a frame-relative computation, not a fact; publishing one number would falsify the system's central claim.
A stated trust assumption. In beta, Dunbar operates as the single first-party issuer and scorer: users authenticate to the service, which signs attestations on their behalf and computes all scores. This assumption is disclosed rather than obscured, and the schema is versioned specifically to support the planned reductions as per-node signed manifests against indexer omission, and wallet co-signed attestations for users who want self-custody of their statements.
8. Access and economics
Individuals never pay. Every free action like vouching, linking identities, disputing, and inspecting, is itself production of the graph. Charging individuals would tax the asset's growth to collect coins. The free tier includes a user's own network view, inspection of any profile with the full adjusted public score, and the paths connecting the viewer to anyone they inspect.
Businesses and machines pay per query for depth and volume: batch scoring, arbitrary-endpoint path analysis, cluster and audience-quality analytics, and generated vetting reports. The machine-native rail is USDC micropayments on Base, so an autonomous agent with a funded wallet can query cold, with no account, no card, and no sales conversation. Dunbar custodies nothing; settlement is peer-to-peer.
The first market is influencer and KOL vetting: buyers with acutely quantifiable pain (campaign budgets burned on farmed audiences and exit-scammers), where the graph's sharpest signals of single-source concentration, manufactured fresh support, credible dispute history, and contested nature which map directly onto the fraud patterns being paid for. Notably, the buyer is not the scored party, so revenue does not depend on the rated ever paying.
What will never be monetized, as commitments with revenue implications: no paying to improve a score, ever; no advertising against trust surfaces; no sale of raw behavioral data; no paywalled warnings. Adjusted scores, dispute existence, nature declarations, and revealed nature states stay public; and no paid access to sealed contest flags at any price, because pre-threshold accusations are unverified noise and selling noise to the most safety-sensitive customers would betray the product's core promise.
9. The interface
The ego graph renders as a nebula: people as stars, vouches as threads of light, communities as cloud masses, and the sparse cuts between clusters, which are the boundaries Sybil resistance lives on, as visible dark lanes. The asker sits at the center, and distance from center is strictly monotonic in trust, making the product's central claim the literal organizing principle of the picture. Every visual variable is bound to a data variable: brightness is trust magnitude, link gradients encode who vouched for whom, red marks negative standing, purple marks contested nature, and the surrounding haze is computed from the rendered light itself, so the atmosphere cannot lie. Nothing is drawn that does not encode graph state.
The same discipline governs the whole surface: one canonical Trust Card shared by the web app, browser extension, and chat-platform bots, appearing wherever trust questions actually occur rather than waiting to be visited.
10. Status and roadmap
Dunbar is in invite-gated beta on a community of roughly one hundred members whose existing real-world trust seeds the graph. The scoring core is implemented and under test; parameter defaults are being validated in the adversarial harness before exposure; the x402 query endpoint and the extension and bot surfaces are the first distribution instruments. Wedge revenue follows with business accounts and vetting reports piloted alongside design-partner businesses, and an agent-facing metered tier from the first day of paid access. Expansion beyond the wedge — adjacent vetting markets, and agent-to-agent trust queries as the machine economy grows — is deliberately not yet designed: premature design is treated as a defect, not diligence.
11. Limitations and open problems
Honesty about limits is part of the design posture. The beta's first-party trust assumption (section 7) is real: until manifests and co-signing ship, users trust the operator's log completeness and scoring honesty, verifiable only after the fact against anchors. All security parameters are defaults pending empirical sweeps; the published resistance curves, not this paper, are the evidence. The Seed set's identity opacity is a genuine trade of inspectability for safety, and reasonable people will contest it. Identity linking depends on platform OAuth and API access that platforms can reprice or revoke; storing stable numeric identifiers narrows but does not remove this exposure. And the sealed contest mechanism will be attacked rhetorically as secret accusations. Which is why its full rationale, costs, and reveal guarantees are published here first.
12. Conclusion
The dead internet is not a content problem; it is a context problem. People retreat to closed networks because that is where context still exists: where someone always knows someone who knows you. Dunbar's wager is that this context can be made portable without being made fake: that a vouch treated as a genuine stake, a score honest about its vantage point, security that is a theorem rather than a checkpoint, disputes resolved by sunlight rather than verdicts, and a layer where declared humans and declared agents transact on equal, inspectable footing, together restore what made small networks trustworthy — at the scale the open internet actually needs.
Dunbar · dunbar.network · @dunbargraph
This draft is for review. Protocol parameters cited are beta defaults pending published calibration; see the parameter registry accompanying beta results.