The Toll · proof-of-work edge-wall
Posting hard equations does nothing — a scraper stores the text of your maths for free. So the work has to be something the client is forced to execute to unlock the page: a hash puzzle. Cheap to verify, costly to solve. Invisible to a human, crushing to a mass-scraper — and stronger every time someone joins.
measuring your machine…
① The content-lock — a page you must pay to read
The article below was delivered to your browser as AES-256-GCM ciphertext. The decryption key was shipped with its low bits punched out — the only way to fill them back in is to do the proof-of-work. Until you pay the toll, the words do not exist in this page: View Source and every scraper that grabbed this URL got exactly the opaque bytes you see here.
A scraper can’t skip this — no work, no key, no bytes. Cheap to verify (the server checks one hash), costly to open. Multiply the pause you just felt by fifty million pages.
② The asymmetry — measured on your machine
Same toll, two clients — the numbers below are computed from your just-measured hash rate, at the difficulty on the meter above. Drag it and watch the gap move.
the scraper pays — what the human pays — for the same content.
③ The collective effect — the mesh IS the tax
The scraper must pay the toll at every node it hits. So the cost of crawling the mesh scales with the size of the mesh — the defence gets stronger as adoption grows, while each human only ever pays for their own handful. Cost to crawl 50M pages across the mesh:
④ The adaptive gate — the governor
Difficulty ramps with a client's request-rate. A browser loads a few pages over minutes and stays near-zero. A scraper firing thousands of requests a second watches the bar climb until the per-page cost is a wall. Drag the request-rate:
The abuse tax · v2
A scraper isn't the only thing that lives on cheap volume. Credential-stuffing, spam floods, fake signups, mass vulnerability-scanning — every one needs each attempt to stay near-free. Force proof-of-work per attempt and the adaptive gate ramps the attacker (a human, hitting a handful, never ramps). When one attempt costs more than one attempt can earn, the whole business model inverts.
and the compute they're forced to burn isn't wasted — re-verified, it banks — conserved units to the mesh. the more they attack, the stronger it gets.
Honest notes
Questions
Charge compute instead of blocking. The Toll makes every request solve a proof-of-work hash puzzle before content unlocks. It is cheap to verify (one hash) but costly to solve, so a human loading a handful of pages pays about 30 milliseconds and never notices, while a scraper crawling millions of pages pays roughly 16 CPU-days. No CAPTCHA, no user friction.
Yes, for volume attacks. When a client's request-rate is high, the puzzle difficulty ramps, so each attempt costs real compute. For credential-stuffing, spam, or mass vulnerability-scanning — where each attempt must stay near-free to be worthwhile — the forced cost per attempt soon exceeds what an attempt can earn, and the attack loses money on every try. A human, who never hits that rate, is never ramped and pays nothing.
Barely. At the recommended difficulty a real visitor's browser solves the puzzle in roughly 30 milliseconds in a background worker, and the difficulty is tuned to the device so it stays invisible even on slower hardware. Only high-rate clients are ramped to a costly difficulty.
It taxes volume, it is not a total block. A determined attacker can pay the cost to reach one specific target, and it does not defend against on-device malware. It makes cheap, mass, opportunistic abuse economically unviable — which is most automated traffic — but it is not a firewall or a replacement for authentication.