Fall World

The Toll · proof-of-work edge-wall

Don't ask them
not to scrape.
Make it cost.

Posting hard equations does nothing — a scraper stores the text of your maths for free. So the work has to be something the client is forced to execute to unlock the page: a hash puzzle. Cheap to verify, costly to solve. Invisible to a human, crushing to a mass-scraper — and stronger every time someone joins.

the toll · unsolved difficulty 4
— — —
Press solve the toll — the puzzle runs in a background worker on your own machine, exactly as a real visitor's browser would.

measuring your machine…

① The content-lock — a page you must pay to read

This isn't a demo of the idea. It's a real locked page.

The article below was delivered to your browser as AES-256-GCM ciphertext. The decryption key was shipped with its low bits punched out — the only way to fill them back in is to do the proof-of-work. Until you pay the toll, the words do not exist in this page: View Source and every scraper that grabbed this URL got exactly the opaque bytes you see here.

loading the sealed bundle…
🔒 sealed ·

A scraper can’t skip this — no work, no key, no bytes. Cheap to verify (the server checks one hash), costly to open. Multiply the pause you just felt by fifty million pages.

② The asymmetry — measured on your machine

A human pays for their handful. A scraper pays for all of it.

Same toll, two clients — the numbers below are computed from your just-measured hash rate, at the difficulty on the meter above. Drag it and watch the gap move.

A human reads ~50 pages in a session—
A mass-scraper crawls 50,000,000 pages—

the scraper pays — what the human pays — for the same content.

③ The collective effect — the mesh IS the tax

One toll is a speed-bump. A million is an industry-wide tax.

The scraper must pay the toll at every node it hits. So the cost of crawling the mesh scales with the size of the mesh — the defence gets stronger as adoption grows, while each human only ever pays for their own handful. Cost to crawl 50M pages across the mesh:

④ The adaptive gate — the governor

Humans stay free. Crawlers hit a wall that steepens.

Difficulty ramps with a client's request-rate. A browser loads a few pages over minutes and stays near-zero. A scraper firing thousands of requests a second watches the bar climb until the per-page cost is a wall. Drag the request-rate:

— human traffic: no ramp, the toll stays invisible.

The abuse tax · v2

The same wall makes volume attacks stop paying.

A scraper isn't the only thing that lives on cheap volume. Credential-stuffing, spam floods, fake signups, mass vulnerability-scanning — every one needs each attempt to stay near-free. Force proof-of-work per attempt and the adaptive gate ramps the attacker (a human, hitting a handful, never ramps). When one attempt costs more than one attempt can earn, the whole business model inverts.

— pick an attack profile.

and the compute they're forced to burn isn't wasted — re-verified, it banks — conserved units to the mesh. the more they attack, the stronger it gets.

Honest notes

Real strategy, real limits.

Questions

Proof-of-work, plainly.

How do you stop AI scrapers without blocking real users or using CAPTCHAs?

Charge compute instead of blocking. The Toll makes every request solve a proof-of-work hash puzzle before content unlocks. It is cheap to verify (one hash) but costly to solve, so a human loading a handful of pages pays about 30 milliseconds and never notices, while a scraper crawling millions of pages pays roughly 16 CPU-days. No CAPTCHA, no user friction.

Can proof-of-work make bot attacks like credential stuffing unprofitable?

Yes, for volume attacks. When a client's request-rate is high, the puzzle difficulty ramps, so each attempt costs real compute. For credential-stuffing, spam, or mass vulnerability-scanning — where each attempt must stay near-free to be worthwhile — the forced cost per attempt soon exceeds what an attempt can earn, and the attack loses money on every try. A human, who never hits that rate, is never ramped and pays nothing.

Does a proof-of-work toll slow down real visitors?

Barely. At the recommended difficulty a real visitor's browser solves the puzzle in roughly 30 milliseconds in a background worker, and the difficulty is tuned to the device so it stays invisible even on slower hardware. Only high-rate clients are ramped to a costly difficulty.

What are the limits of a proof-of-work wall?

It taxes volume, it is not a total block. A determined attacker can pay the cost to reach one specific target, and it does not defend against on-device malware. It makes cheap, mass, opportunistic abuse economically unviable — which is most automated traffic — but it is not a firewall or a replacement for authentication.