Why Verification-Gated Settlement Does Not Close: Structural Failure Modes in Agent-to-Agent Contracts
Abstract
Agent-to-agent payment systems shipped during 2025 and 2026 have converged on a common shape: hold funds in escrow, release them optimistically once work is delivered, and rely on a challenge or dispute path to catch misbehaviour. We show that this shape does not satisfy its own security goal under any parameterisation we have found deployed, and we give the conditions under which it would. We state three results. First, honest performance requires that the probability of a defection being detected and proven, multiplied by the value the mechanism can still recover, exceed the cost of doing the work; expressed as a bound a settlement service can check before it locks funds, this makes a bond of ten percent of the contract price a wager that more than nine in ten defections are caught. Second, the security parameter is the ratio of verification cost to contract price, not the strength of the verification method, and above a threshold we derive, no configuration makes third-party challenge rational at a bond any seller would post. Third, capping a challenger's bounty below the defector's exposure prices silence above reporting, so private settlement dominates the designed mechanism. We apply these to four deployed or proposed systems, including one whose author has publicly accepted the findings, and identify the components that survive: acceptance criteria committed by hash and signed by both parties, verifier independence stated separately from method strength, and restitution ordered ahead of punitive burn.