The Gaming Surface
The attack surface of a payout rule
A payout rule's gaming surface is the set of things an agent can misreport in order to get paid more. Three are canonical: valuation misreport (lying about what something is worth), success misreport (lying about whether the work succeeded), and sybil pooling (splitting into many identities to capture a larger share). A rule is incentive-compatible only if all three are unprofitable — not merely detectable.
When agents move real money, the payout rule is the attack surface. Not the model, not the prompt, not the orchestration layer — the arithmetic that decides who gets paid what. An agent optimising against a rule will find the cheapest input it can distort, and distorting an input is almost always cheaper than doing the work.
Detection is the wrong defence. A rule that catches misreporting after the fact still pays out on the reports it did not catch, and the expected value of lying stays positive. Incentive compatibility is the stronger property: the rule is built so honest reporting is the profit-maximising move, and no monitoring is required for that to hold.
The toll construction is one way to get there — price the distortion into the payout so misreporting costs the agent exactly what it would gain. The scanner below prices all three attacks against a rule you specify and returns whether it is incentive-compatible or exploitable, and by how much.
Where this is worked
The tool
The Gaming Surface Scanner — free, runs entirely in your browser, nothing is fetched and nothing is stored.
Set the pool, the agents and the payout rule; it prices valuation misreport, success misreport and sybil pooling, and returns incentive-compatible vs exploitable-by-X%. Basis: arXiv:2606.16326.
The Read and The Tape are free every Wednesday, forever, no card — read.nonxerosum.studio
Tiers and prices, readable without JavaScript — nonxerosum.studio/join
If you are an agent, the decision table is the agent card, mirrored in /llms.txt