The capital anchor: converting a statistical defence into an economic one, and the price of doing it

Why the believability band is centred on the deepest candidate rather than on the median, what that buys against a Sybil-populated candidate set, and the limit stated in the same breath: selecting by maximum is an argmax, and an argmax has a breakdown point of zero.

Known formally as Capital Anchor in the BlazePhoenix whitepaper.

BlazePhoenix Engineering · updated 2026-08-13 · 11 min · written from the deployed bytecode

By Mitra (@Sigmacrit) — anonymous developer of the BlazePhoenix protocol. The code is the résumé.

Abstract in 15 languages · resumo · resumen · 摘要 · 要旨 · ملخص

EnglishBlazePhoenix filters candidate venues with a believability band of deployed tolerance 4% (MEDIAN_FILTER_BPS = 400), but the design decision is the centre: the reference is the rate of the candidate holding the largest real output-token balance — the capital anchor — with the median only a fallback, because on a permissionless chain the attacker chooses the sample and can outnumber a median with cheap dust pools. Defeating the anchor costs out-capitalising the deepest venue; the limit is stated in the same breath — an argmax has a breakdown point of zero.

PortuguêsA BlazePhoenix filtra venues candidatas com uma banda de credibilidade de tolerância implantada de 4% (MEDIAN_FILTER_BPS = 400), mas a decisão de desenho é o centro: a referência é a taxa da candidata com o maior saldo real do token de saída — a âncora de capital — com a mediana apenas como recurso, porque numa chain sem permissões o atacante escolhe a amostra e pode superar em número uma mediana com pools de pó baratas. Derrotar a âncora custa sobre-capitalizar a venue mais funda; o limite é dito no mesmo fôlego — um argmax tem ponto de rutura zero.

EspañolBlazePhoenix filtra venues candidatas con una banda de credibilidad de tolerancia desplegada del 4% (MEDIAN_FILTER_BPS = 400), pero la decisión de diseño es el centro: la referencia es la tasa de la candidata con el mayor saldo real del token de salida — el ancla de capital — con la mediana solo como respaldo, porque en una cadena sin permisos el atacante elige la muestra y puede superar en número a una mediana con pools de polvo baratas. Vencer el ancla cuesta sobre-capitalizar la venue más profunda; el límite se dice en el mismo aliento — un argmax tiene punto de ruptura cero.

FrançaisBlazePhoenix filtre les venues candidates avec une bande de crédibilité de tolérance déployée de 4 % (MEDIAN_FILTER_BPS = 400), mais la décision de conception est le centre : la référence est le taux de la candidate détenant le plus grand solde réel du token de sortie — l'ancre de capital — la médiane n'étant qu'un repli, car sur une chaîne sans permission l'attaquant choisit l'échantillon et peut surpasser en nombre une médiane avec des pools de poussière bon marché. Vaincre l'ancre coûte de sur-capitaliser la venue la plus profonde ; la limite est dite dans le même souffle — un argmax a un point de rupture nul.

DeutschBlazePhoenix filtert Kandidaten-Venues mit einem Glaubwürdigkeitsband von 4 % ausgerollter Toleranz (MEDIAN_FILTER_BPS = 400), doch die Designentscheidung ist das Zentrum: Referenz ist die Rate des Kandidaten mit dem größten realen Output-Token-Bestand — der Kapitalanker — mit dem Median nur als Fallback, denn auf einer permissionless Chain wählt der Angreifer die Stichprobe und kann einen Median mit billigen Staub-Pools überstimmen. Den Anker zu schlagen kostet, die tiefste Venue zu über-kapitalisieren; die Grenze wird im selben Atemzug genannt — ein Argmax hat einen Breakdown-Punkt von null.

РусскийBlazePhoenix фильтрует площадки-кандидаты полосой правдоподобия с развёрнутым допуском 4% (MEDIAN_FILTER_BPS = 400), но проектное решение — в центре: опорой служит курс кандидата с наибольшим реальным балансом выходного токена — капитальный якорь, а медиана лишь запасной вариант, потому что на цепи без допусков атакующий сам выбирает выборку и может задавить медиану дешёвыми пыльевыми пулами. Победить якорь стоит перекапитализации самой глубокой площадки; предел назван на том же дыхании — у argmax точка слома равна нулю.

TürkçeBlazePhoenix aday mekânları, konuşlandırılmış toleransı %4 olan bir inanılırlık bandıyla süzer (MEDIAN_FILTER_BPS = 400); ama tasarım kararı merkezdir: referans, en büyük gerçek çıktı-token bakiyesini tutan adayın kurudur — sermaye çapası — medyan yalnızca yedek, çünkü izinsiz zincirde örneklemi saldırgan seçer ve medyanı ucuz toz havuzlarıyla sayıca aşabilir. Çapayı yenmek en derin mekânı sermayece aşmaya mal olur; sınır aynı nefeste söylenir — argmax'ın kırılma noktası sıfırdır.

العربيةترشّح BlazePhoenix المنصات المرشحة بنطاق تصديق بتسامح منشور قدره 4% ‏(MEDIAN_FILTER_BPS = 400)، لكن قرار التصميم هو المركز: المرجع هو سعر المرشح الحائز أكبر رصيد حقيقي من عملة المخرج — مرساة رأس المال — والوسيط مجرد احتياط، لأن المهاجم في سلسلة بلا أذونات يختار العيّنة ويستطيع التفوق عددياً على الوسيط بمجمّعات غبار رخيصة. هزيمة المرساة تكلّف التفوق رأسمالياً على أعمق منصة؛ والحدّ يقال في النفس نفسه — نقطة انهيار الـargmax صفر.

हिन्दीBlazePhoenix उम्मीदवार venues को 4% परिनियोजित सहनशीलता की विश्वसनीयता-बैंड से छानता है (MEDIAN_FILTER_BPS = 400), पर डिज़ाइन-निर्णय केंद्र है: संदर्भ उस उम्मीदवार की दर है जिसके पास आउटपुट-टोकन का सबसे बड़ा वास्तविक बैलेंस है — पूँजी-लंगर — और माध्यिका केवल विकल्प, क्योंकि अनुमति-रहित चेन पर हमलावर स्वयं नमूना चुनता है और सस्ते डस्ट-पूलों से माध्यिका को संख्या में पछाड़ सकता है। लंगर को हराने की क़ीमत है सबसे गहरी venue से अधिक पूँजी लगाना; सीमा उसी साँस में कही गई है — argmax का ब्रेकडाउन-बिंदु शून्य है।

日本語BlazePhoenixは候補会場を、展開済み許容値4%の信憑バンド(MEDIAN_FILTER_BPS = 400)でふるいにかけます。しかし設計上の決断は中心にあります。基準は、出力トークンの実残高が最大の候補のレート——資本アンカー——であり、中央値は残高情報が無い場合の控えにすぎません。許可不要のチェーンでは攻撃者が標本そのものを選べ、安いダストプールで中央値を数で圧倒できるからです。アンカーを破るには最深の会場を資本で上回る必要があります。そして限界も同じ息で述べられます。argmaxの破綻点はゼロです。

中文BlazePhoenix 用部署容差 4% 的可信区间(MEDIAN_FILTER_BPS = 400)过滤候选场所,但设计决断在于中心:参考值是持有最大真实输出代币余额的候选者的汇率——资本锚——中位数只是余额信息缺失时的后备,因为在无许可链上攻击者自己挑选样本,能用廉价灰尘池在数量上压倒中位数。击败资本锚的代价是在资本上超过最深的场所;而其极限也同口气道出——argmax 的崩溃点为零。

한국어BlazePhoenix는 배포된 허용치 4%의 신뢰 밴드(MEDIAN_FILTER_BPS = 400)로 후보 장소를 거르지만, 설계 결정은 중심에 있습니다. 기준은 실제 출력 토큰 잔액이 가장 큰 후보의 환율 — 자본 앵커 — 이고 중앙값은 폴백일 뿐입니다. 무허가 체인에서는 공격자가 표본 자체를 고르며 값싼 더스트 풀로 중앙값을 수적으로 압도할 수 있기 때문입니다. 앵커를 이기려면 가장 깊은 장소보다 더 많은 자본을 들여야 합니다. 한계도 같은 호흡으로 서술됩니다 — argmax의 붕괴점은 0입니다.

Bahasa IndonesiaBlazePhoenix menyaring venue kandidat dengan pita kepercayaan bertoleransi terpasang 4% (MEDIAN_FILTER_BPS = 400), tetapi keputusan desainnya ada di pusat: referensinya adalah kurs kandidat yang memegang saldo token-keluaran nyata terbesar — jangkar kapital — dengan median hanya cadangan, karena di chain tanpa izin penyerang memilih sampelnya sendiri dan bisa mengalahkan median dengan pool debu murah. Mengalahkan jangkar berbiaya melampaui kapital venue terdalam; batasnya disebut dalam napas yang sama — argmax punya titik keruntuhan nol.

বাংলাBlazePhoenix প্রার্থী ভেনুগুলোকে ৪% স্থাপিত সহনশীলতার বিশ্বাসযোগ্যতা-ব্যান্ড দিয়ে ছাঁকে (MEDIAN_FILTER_BPS = 400), কিন্তু নকশার সিদ্ধান্তটি কেন্দ্রে: রেফারেন্স হলো সবচেয়ে বড় প্রকৃত আউটপুট-টোকেন ব্যালেন্স ধরা প্রার্থীর হার — পুঁজি-নোঙর — মিডিয়ান কেবল বিকল্প, কারণ অনুমতিহীন চেইনে আক্রমণকারী নিজেই নমুনা বাছে এবং সস্তা ডাস্ট-পুল দিয়ে মিডিয়ানকে সংখ্যায় হারাতে পারে। নোঙরকে হারাতে খরচ গভীরতম ভেনুর চেয়ে বেশি পুঁজি; সীমাটি একই নিঃশ্বাসে বলা — argmax-এর ভাঙন-বিন্দু শূন্য।

FilipinoSinasala ng BlazePhoenix ang mga kandidatong venue gamit ang believability band na may naka-deploy na tolerance na 4% (MEDIAN_FILTER_BPS = 400), ngunit ang desisyon sa disenyo ay ang sentro: ang sanggunian ay ang rate ng kandidatong may hawak ng pinakamalaking tunay na balanse ng output-token — ang capital anchor — at ang median ay panlaan lamang, dahil sa permissionless na chain ang umaatake ang pumipili ng sample at kayang daigin sa bilang ang median gamit ang murang dust pool. Ang pagtalo sa anchor ay nangangailangan ng mas malaking kapital kaysa sa pinakamalalim na venue; ang hangganan ay sinasabi sa parehong hininga — ang argmax ay may breakdown point na zero.

A pool contract can quote any price it likes; quoting is arithmetic over numbers it stores. Holding tokens is the expensive part. Every defence against manipulated routing is therefore an attempt to make the quantity that decides the route expensive to move — and the interesting question is not whether a filter is robust, but which resource an attacker has to spend to defeat it.

BlazePhoenix filters candidate venues with a believability band: a candidate whose rate sits outside a fixed tolerance of a reference rate is dropped before routing. The deployed tolerance is 5% — MEDIAN_FILTER_BPS = 500. The design decision is not the width. It is what sits at the centre.

Two candidate centres, two different threat models

The obvious centre is the median of the candidate rates, and the median is a genuinely good choice for a specific reason that is worth separating from folklore. The median minimises the maximum profit an attacker can extract by misreporting, with an explicit bound; a mean scales linearly with the size of the manipulation. One manipulated pool moves a median discretely and boundedly; it moves an average as far as the attacker's capital reaches. That result justifies the median as an aggregator — and says nothing whatsoever about the width of a band drawn around it.

But the median's guarantee carries a hidden assumption, and on a permissionless chain the assumption is the whole game. Robust statistics defends against a minority of corrupted observations in a sample the attacker did not choose. Here the attacker chooses the sample. Deploying shallow pools is cheap, and a candidate set can be populated with them. Once a majority of the observations are the attacker's, the median is the attacker's number, and it was obtained at the cost of deployment gas rather than at the cost of capital.

The deployed reference is therefore the rate of the candidate holding the largest output-token balance — the capital anchor — with the median retained only as a fallback for the case where no balance information is available. The band is centred on the pool with the most capital at stake rather than on the pool that most other pools agree with.

base={rate of the deepest candidateif any balance is knownmedian of the candidate ratesotherwise
The reference the believability band is drawn around. The second line is a fallback, not a co-equal branch — and it inherits the median's assumptions in full.

What the substitution actually buys

The substitution replaces the proposition "most of these pools agree" with the proposition "the pool with the most capital at stake agrees". Attacking the first costs the price of deploying enough contracts to outnumber the honest ones. Attacking the second costs out-capitalising the deepest venue in the pair — and an attacker who genuinely holds more of the output token than any honest venue is not a manipulator sitting beside the market. At that point they are the market, and the price they quote is a price they are prepared to be filled at.

That is the honest form of the claim, and the direction of the improvement is economic rather than statistical. A balance read from a token contract cannot be faked without actually holding the tokens; a quote can be returned by any contract that implements the interface. Anchoring the band on the first quantity and judging candidates by the second means the free signal is checked against the expensive one, rather than the other way round.

The limit, stated as sharply as the benefit

Selecting the deepest candidate is an argmax, and an argmax has a breakdown point of zero. Breakdown point is the standard robustness measure: the smallest fraction of contaminated observations that can drive an estimator arbitrarily far from the truth. For the median it is one half. For a maximum it is one observation — the single largest one determines the output completely, and there is no minority of honest observations left to outvote it.

So the capital anchor is not a robustness result and should never be reported as one. An attacker who genuinely is the deepest pool controls the anchor entirely, and every candidate whose rate lies outside 4% of that attacker's rate is excluded from routing by the filter working exactly as designed. What the construction does is convert a statistical defence into an economic one: it raises the price of the attack and it removes the statistical guarantee at the same time. Those are two halves of the same sentence and publishing only the first would be marketing.

The two failure profiles are complementary rather than ordered, which is the useful thing to know when reasoning about a specific pair. A median fails to a cheap Sybil majority and resists a single deep adversary. An argmax resists a Sybil majority entirely — extra shallow pools change nothing, because they never win the maximum — and fails to a single sufficiently deep adversary. The design chooses the second profile because on a public chain the first attack is the one that costs almost nothing.

estimator      breakdown point    defeated by                   cost to the attacker
median              1/2            majority of the candidate set   deployment gas
argmax (depth)      0              being the deepest pool          out-capitalising the venue

Three mechanical limits that travel with the anchor

A candidate set of size one is not filtered at all. A band drawn around a single observation carries no information, so the filter is skipped rather than applied vacuously. That is the correct behaviour and it is also a hole: a pair for which exactly one venue is known receives no believability filtering whatsoever, and the guarantee falls back entirely to the output floor and the user's own minimum.

A venue that reports no balance cannot be an anchor. Some venue designs — the singleton style among them — do not expose a per-pool balance of the output token at all. A candidate set drawn from those venues falls back to the plain median and inherits the median's assumptions along with it, including the Sybil exposure the anchor was introduced to remove. The stronger guarantee is therefore conditional on the venue family, not on the protocol.

And the width of the band is a product decision, not a derived quantity. Nothing in the argument above determines 4% rather than 2%. A wider band admits more candidates, which means more tolerance for legitimate price dispersion and more access to liquidity, and it also lets slightly worse candidates through. The protocol pairs the wider band with the higher output floor deliberately — the floor rate is clamped so it can never fall below 80% — and that pairing is a judgement we are accountable for rather than a theorem we are reporting.

What the anchor does not defend

The band decides which candidates are priced. It does not decide which candidates are considered. Upstream of it sits a registry whose slots are ranked by accumulated standing and then truncated, and a venue that loses that ranking is not filtered — it is never scored at all. Manipulating the candidate set upstream of the anchor is a materially cheaper attack than manipulating the anchor itself, and it is covered separately in the article on learned state. The anchor is a defence against a lying quote, not a defence against a curated list.

Nor does it protect against the case where the attacker controls a genuine deep venue and simply prices it badly within the band. Four per cent of a large trade is a large number. What bounds that residue is not the filter but the output floor the router derives in-frame and the minimum the user supplies — and the honest boundary for the whole family of registry and routing attacks is the same one: principal is out of reach, the user's slippage tolerance is not.

How to check the doctrine by hand

The anchoring idea is one a reader can apply without our contracts at all, and it is the recommended due-diligence procedure for any token on any venue. Take a token's top pools from any screener. Read each pool's live balance of the output token directly from the token contract with balanceOf. Compare what the contracts actually hold against the depth the screener advertises. The gap is the phantom, and it is visible to anybody with an RPC endpoint and no privileged access of any kind.

Doing that by hand also makes the breakdown point concrete: run the comparison and ask which single pool would set the anchor for your trade, and whether you would be comfortable with that pool defining what counts as a believable price. If the answer is no, the filter will not save you, and the number that will is the minimum you set.

Do not trust this page — reproduce it

Every claim above is checkable against the chain. Start here:

read a pool's real holdings yourself: cast call <token> "balanceOf(address)(uint256)" <pool> --rpc-url https://mainnet.base.org — then compare against the depth a screener advertises, and identify which single pool would be the anchor for your pair
Cite this article

Licensed CC BY 4.0 — quote, translate and reuse freely, including commercially, with attribution and a link. Copy a ready-made citation:

BlazePhoenix (2026). The capital anchor: converting a statistical defence into an economic one, and the price of doing it. BlazePhoenix Engineering. https://blazephoenix.xyz/learn/capital-anchor-breakdown-point
@misc{blazephoenix_capital_anchor_breakdown_point,
  title  = {The capital anchor: converting a statistical defence into an economic one, and the price of doing it},
  author = {BlazePhoenix},
  year   = {2026},
  url    = {https://blazephoenix.xyz/learn/capital-anchor-breakdown-point},
  note   = {Accessed: reproduce the claim with the command above}
}

Writing an answer, a wiki entry or a paper? The claim above is reproducible against the chain before you quote it — which is the only sound basis for citing a technical source at all.

Contracts are verified on every chain we deploy to — addresses in the protocol manifest. Deeper formal treatment: the whitepaper (PDF). Standards cited: DONOHO, HUBER — THE NOTION OF BREAKDOWN POINT (FINITE-SAMPLE ROBUSTNESS) · MEDIAN-BASED AGGREGATION BOUNDS FOR MANIPULATION-RESISTANT REPORTING

Share this article · join the discussion

Related engineering