A Reputation System is a decentralised computational infrastructure for aggregating verifiable behavioural signals about network participants into quantified trust scores that enable social coordination in trustless Blockchain environments, spanning algorithmic trust propagation architect…

Semantic Classification

Content

Compositional Relationships (Components)

SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:hasPart bc:TrustGraph))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:hasPart bc:AttestationService))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:hasPart bc:SybilResistanceMechanism))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:hasPart bc:AggregationAlgorithm))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:hasPart bc:CredentialRegistry))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:hasPart bc:ScoreOracle))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:hasPart bc:TrustAnchor))

## Dependency Relationships
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:requires bc:CryptographicProof))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:requires bc:TransactionHistory))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:requires bc:OnChainIdentity))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:requires bc:AttestationSchema))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:requires bc:TrustAnchor))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:dependsOn bc:GraphTheory))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:dependsOn bc:Cryptography))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:dependsOn bc:SmartContracts))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:dependsOn bc:DecentralisedIdentifiers))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:dependsOn bc:ZeroKnowledgeProof))

## Capability Relationships
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:enables bc:QuadraticFunding))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:enables bc:DAOGovernance))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:enables bc:PermissionlessTrust))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:enables bc:ReputationGatedAccess))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:enables bc:SocialGraphAnalysis))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:supports bc:GitcoinPassport))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:supports bc:Karma3Labs))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:supports bc:EthereumAttestationService))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:supports bc:LensProtocol))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:supports bc:Farcaster))

## Implementation Relationships
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:implements bc:EigenTrustAlgorithm))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:implements bc:PageRankTrustDiffusion))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:implements bc:ZeroKnowledgeProof))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:implements bc:VerifiableCredentials))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:implements bc:SelectiveDisclosure))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:uses bc:IPFS))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:uses bc:Layer2Networks))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:uses bc:SoulboundTokens))

## Reduction Relationships
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:reduces bc:SybilAttackSurface))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:reduces bc:CoordinationCost))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:reduces bc:InformationAsymmetry))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:reduces bc:GovernanceManipulationRisk))
SubClassOf(bc:ReputationSystem
  ObjectSomeValuesFrom(bc:reduces bc:TrustFormationFriction))

## Annotations
AnnotationAssertion(rdfs:label bc:ReputationSystem "Reputation System"@en)
AnnotationAssertion(rdfs:comment bc:ReputationSystem "Decentralised trust scoring infrastructure aggregating verifiable behavioural signals via EigenTrust graph algorithms, on-chain attestations (EAS, Verax), Sybil resistance mechanisms (Gitcoin Passport, Worldcoin World ID), and Web3 social protocol integrations (Karma3 Labs OpenRank, Lens Protocol, Farcaster) enabling permissionless trust formation, DAO governance integrity, and quadratic coordination across $500B+ annual on-chain value flows."@en)
AnnotationAssertion(dcterms:identifier bc:ReputationSystem "BC-0612"^^xsd:string)
AnnotationAssertion(dcterms:subject bc:ReputationSystem "Blockchain, Trust, Sybil Resistance, Attestation, Web3 Social, Governance"@en)

)

About Reputation Systems

  • Reputation Systems solve a fundamental coordination problem in open, permissionless networks: how to establish trust between parties who have no prior relationship and cannot rely on centralised intermediaries to vouch for each other. In traditional contexts, this function is served by institutions — banks issue credit scores, governments certify identity, professional bodies licence practitioners. In decentralised blockchain environments, no such institutions exist by default, creating a need for cryptographically verifiable, algorithmically aggregated trust signals that any participant can produce, verify, and consume without permission.
  • The intellectual lineage of decentralised reputation spans several decades. Lorenz (1962) first described reputation as a social mechanism in biological systems; Zacharia (1999) formalised computational reputation in early distributed computing; Kamvar, Schlosser and Garcia-Molina (2003) published the EigenTrust algorithm, which remains the dominant mathematical framework for peer-to-peer trust propagation. PageRank (Brin & Page 1998) provided complementary intuitions about link-based authority propagation on directed graphs. The emergence of Bitcoin Proof-of-Work Protocol in 2008 and Ethereum Smart Contract Platform in 2015 transformed reputation from a purely informational construct into an economically consequential one: on-chain trust scores gate access to capital, governance rights, and economic opportunities denominated in real value.
  • Modern decentralised reputation systems operate across three interlocking layers: (1) signal collection — gathering verifiable behavioural evidence (on-chain transactions, attestations, social interactions, credential holdings); (2) aggregation algorithms — mathematically combining signals into composite scores whilst filtering adversarial noise; (3) score consumption — applications querying scores to gate access, weight votes, or determine funding allocations.

EigenTrust Algorithm: Mathematical Foundations

  • The EigenTrust algorithm (Kamvar, Schlosser & Garcia-Molina, 2003) provides the canonical mathematical framework for global trust computation from local peer-to-peer satisfaction scores. Originally designed for Gnutella peer-to-peer file-sharing networks to combat inauthentic content distribution, EigenTrust has become foundational to Web3 reputation systems including Karma3 Labs OpenRank.
  • Local Trust Scores: Each peer i maintains local trust values c_{ij} for every peer j with whom they have transacted. These are computed as the normalised ratio of satisfactory to total transactions: c_{ij} = max(s_{ij}, 0) / Σ_k max(s_{ik}, 0) where s_{ij} counts the number of satisfactory interactions minus unsatisfactory ones. This normalisation ensures that peer trust scores sum to one across all peers known to i.
  • Global Trust Propagation: The global trust vector t = [t_1, t_2, …, t_n] representing the trustworthiness of each peer as perceived by the entire network is computed iteratively: t^{(k+1)} = C^T × t^{(k)} where C is the matrix of local trust values c_{ij}. This iteration converges to the principal eigenvector of C^T — hence the name EigenTrust. Convergence is guaranteed when C is a row-stochastic matrix (rows sum to one) with strongly connected components.
  • Pre-trusted Peers: In practice, not all peers have transacted with all others, creating sparse matrices where convergence may fail. EigenTrust addresses this by introducing a small set of pre-trusted peers with known-good reputation p = [p_1, p_2, …, p_n] (a prior distribution): t^{(k+1)} = (1 - α) × C^T × t^{(k)} + α × p where α ∈ [0,1] controls the weight of the prior. This prevents malicious coalitions from inflating their own trust scores by ensuring convergence remains anchored to known-trustworthy entities.
  • Computational Complexity: Naive EigenTrust requires O(n²) storage for the trust matrix and O(n²) computation per iteration, prohibiting deployment at internet scale. Distributed EigenTrust (Kamvar 2003) partitions computation across peers, enabling O(n/k) per-peer storage with k peers per shard. Modern implementations on blockchain use optimistic updates and Merkle-tree verification to achieve sub-second query times whilst maintaining tamper-evidence.
  • Karma3 Labs OpenRank: The most significant production deployment of EigenTrust in Web3 is Karma3 Labs’ OpenRank protocol (2023-2026). OpenRank extends EigenTrust to social and professional trust graphs derived from Farcaster and Lens Protocol social interactions. The system computes personalised trust scores — each user receives their own ranked view of the network rooted at their social graph — rather than a single global ranking. This personalisation is critical for Web3 applications where trust is inherently context-dependent and different users may rationally disagree about which peers are trustworthy. OpenRank processes 500M+ social interactions monthly (2025) and powers recommendations in Warpcast (Farcaster’s primary client), Supercast, and Farcaster Frame analytics.

PageRank-Style Trust Graphs

  • PageRank (Brin & Page 1998) was conceived as a link analysis algorithm for ranking web pages, but its underlying mathematics — random walk convergence on directed weighted graphs — translates directly to social trust propagation. In PageRank’s formulation, the importance of a page (or peer) is proportional to the importance of the pages (peers) that link to (trust) it, creating a recursive definition that resolves via eigenvalue decomposition identical to EigenTrust.
  • The core PageRank formula: PR(u) = (1 - d) + d × Σ_{v ∈ B_u} PR(v) / L(v) where B_u is the set of nodes linking to u, L(v) is the out-degree of node v, and d is a damping factor (typically 0.85) representing the probability of continuing to follow links versus teleporting to a random node. This damping factor plays the same role as EigenTrust’s pre-trusted peer prior — preventing manipulation by sink nodes that accumulate trust without redistributing it.
  • In Web3 trust contexts, directed graph edges represent attestations, follows, or endorsements: if A attests to B, an edge A→B carries weight proportional to A’s own trustworthiness. Applications include: Farcaster social graph ranking where high-quality casters (users) receive follow-based authority scores; Lens Protocol profile discovery ranking publication quality by follower graph authority; Gitcoin quadratic funding Sybil detection where wallet clusters with shared PageRank subgraph patterns flag suspected Sybil clusters.
  • Trust graph vulnerabilities require mitigation: link farming (creating fake follower networks to inflate PageRank), trust collusion rings (mutual high-trust endorsements among malicious accounts), and dangling nodes (accounts with incoming trust but no outgoing links creating rank sinks) all require countermeasures including stake-weighted edges, cross-domain trust anchoring, and minimum outgoing trust requirements.

Trust Graph Adversarial Dynamics and Collusion Resistance

  • Decentralised reputation systems face a specific class of adversarial behaviour absent from centralised systems: strategic manipulation by economically motivated actors who control multiple network identities, can observe the trust computation algorithm, and can optimise their behaviour to maximise trust score gain relative to legitimate effort. Understanding these attack vectors is prerequisite to understanding why the design choices of EigenTrust, Gitcoin Passport, and EAS take their specific forms.
  • Ballot stuffing (injecting fake positive ratings for a target identity) is the most basic attack. In EigenTrust, this is addressed by weighting local trust scores by the global trust score of the rater: a ballot-stuffed rating from a low-trust account contributes negligibly to the target’s global trust score. The mathematical guarantee: if the pre-trusted peer set is honest, and malicious agents control less than 50% of the total trust-weighted network edges, EigenTrust converges to a global trust vector where malicious agents receive trust scores approaching zero regardless of their mutual inflation. This result holds assuming the honest peer set is well-connected (diameter O(log n)).
  • Whitewashing attacks exploit the reputation reset problem: an agent who damages their reputation by behaving maliciously can abandon the compromised identity and create a fresh identity with zero reputation. Systems with new-account penalties (low initial trust, slow trust accumulation ramp, minimum stake requirements for reputation-earning actions) deter whitewashing at the cost of excluding legitimate new participants. Gitcoin Passport’s age-gated stamps (GitHub account >30 days, LinkedIn >6 months) impose time costs on whitewashing without requiring financial stake.
  • Oscillating behaviour exploits reputation hysteresis in systems that aggregate over time windows: an adversary behaves well until accumulating high reputation, then exploits it for fraud, then starts a new cycle. Countermeasures include exponential decay (recent behaviour weighted more heavily than historical), reputation bonding (locking up stake proportional to claimed reputation, slashable on detected misbehaviour), and recency-weighted EigenTrust variants where the trust matrix C^T uses temporally decayed edge weights.
  • Eclipse attacks on trust graphs construct a subgraph where a target victim’s trust-reachable neighbourhood is entirely controlled by malicious nodes — so all trust paths from the victim reach adversarially controlled peers. Personalised EigenTrust is more vulnerable to eclipse attacks than global EigenTrust, because the personalised computation is bounded by the query user’s local neighbourhood radius. OpenRank mitigates eclipse risk by introducing long-range trust diffusion (random teleportation to globally high-trust nodes) and monitoring for neighbourhood concentration metrics.
  • Concentration analysis detects Sybil clusters without biometric identity: in a legitimate social graph, trust flows multi-directionally among organically formed communities; in a Sybil cluster, trust flows predominantly inward (toward the Sybil cluster) from a small number of entry-point accounts. Algorithms detecting abnormal trust concentration patterns (Gini coefficient of in-trust distribution, betweenness centrality of cluster border nodes) are used by BrightID and Gitcoin’s internal Sybil detection tooling as supplementary signals beyond explicit stamp verification.

Web3 Reputation Protocols

Karma3 Labs and OpenRank (2023-2026)

  • Karma3 Labs (founded 2022, San Francisco) is the primary infrastructure provider for EigenTrust-based reputation in the Web3 social ecosystem. Their OpenRank protocol (v1.0 launched Q3 2023) implements personalised EigenTrust over multi-graph social data, combining on-chain activity signals (NFT ownership, DAO participation, DeFi transaction history) with off-chain social graph data from Farcaster Hubble nodes and Lens Protocol API.
  • OpenRank’s architecture uses a compute layer (distributed EigenTrust over Apache Spark clusters) and a query layer (RESTful API + GraphQL with sub-100ms response times) deployed on AWS with Ethereum for result anchoring. The system produces two score types: (1) Global Rank — a single authoritative score per FID (Farcaster ID) based on the full social graph; (2) Personalised Rank — a user-specific score computed via random-walk-with-restart from a query user’s identity node, enabling trust-in-context rather than universal ordering.
  • Key integrations (2025): Warpcast native channel quality scoring, Supercast content filtering, Neynar API reputation data, Ethereum Smart Contract Platform address reputation via cross-chain linking through ENS resolution. Karma3 Labs raised $4.5M seed round (Multicoin Capital, Electric Capital, a16z crypto Scout, Zee Prime Capital) in 2023 and partnered with the Ethereum Foundation for ecosystem trust graph research.
  • OpenRank Multi-Graph Architecture (2024-): OpenRank v2 introduced multi-graph EigenTrust computation where different edge types (follows, reactions, collects, co-participation in DAO votes, shared NFT holdings) contribute weighted signals to the composite trust matrix. The multi-graph formulation aggregates K distinct adjacency matrices A_1, A_2, …, A_K (one per interaction type) as a weighted sum: C = Σ_k w_k × A_k / ||Σ_k w_k × A_k||_1, with weights w_k learned via a small calibration dataset of known-good vs known-Sybil account pairs. This generalises single-graph EigenTrust and enables richer trust signals without requiring biometric verification: on-chain economic behaviour (DeFi liquidation history, NFT collection patterns, DAO voting record) provides trust signals orthogonal to social graph structure, substantially reducing the impact of purely social-graph Sybil attacks.

Gitcoin Passport

  • Gitcoin Passport (launched 2022, v3.0 2024) is the leading composite Sybil resistance system for the Ethereum ecosystem, aggregating 30+ identity “stamps” from heterogeneous credential providers into a single Passport Score used to weight Gitcoin quadratic funding rounds and gate access to DAO governance mechanisms.
  • Stamp Architecture: Each stamp represents a verified identity claim from an external provider. Stamps are cryptographically signed by the Gitcoin Passport service and stored as verifiable credentials in the user’s Ceramic Network decentralised data stream, anchored to the user’s Ethereum address. Stamp categories include:
    • Social OAuth: Google, GitHub, Discord, Twitter/X account verification with minimum account age and activity thresholds (e.g., GitHub: >1 public repository, >30 days old)
    • On-chain Activity: ENS name ownership, ETH holding (>1 ETH at snapshot), Gitcoin donor history, POAP (Proof of Attendance Protocol) holdings from 5+ unique events
    • Biometric: Worldcoin World ID (1-of-n uniqueness proof), Idena account (mining ceremony participation)
    • Financial: Coinbase account KYC verification, Binance account verification
    • Professional: LinkedIn Premium account with >6 months history
  • Scorer Algorithm: Stamps are weighted by uniqueness signal strength and combined via a configurable scoring model. The default Unique Humanity Score uses a logistic regression model trained on historical Sybil attack data to weight stamps: biometric stamps score highest (~20 points), financial KYC stamps score high (~15 points), social OAuth stamps score moderate (~5-10 points each), and on-chain activity stamps score variable based on activity depth. A score ≥ 20 qualifies as likely human for Gitcoin Grants rounds; score ≥ 25 for higher-stakes applications.
  • Scale (2025): 850K+ active passports, integrated into 200+ dApps via the Passport API, used in Gitcoin Grants Rounds 19-22 protecting $15M+ in quadratic funding distributions. The Passport Model API (2024) exposes the scoring model for third-party integration without requiring full Passport infrastructure deployment.

ENS and On-Chain Identity

  • ENS (Ethereum Name Service) provides human-readable identity anchors that serve as trust graph nodes. ENS names (e.g., vitalik.eth) function as reverse DNS for Ethereum addresses, enabling reputation to accumulate on stable human-readable identifiers rather than hex addresses that change between wallets. ENS name ownership signals minimal wealth commitment (registration costs 0.003+ ETH annually), time commitment (names acquired in 2017-2019 carry provenance), and identity persistence — wallets associated with ENS names behave significantly differently from anonymous addresses in on-chain reputation analyses.
  • ENS integration with reputation systems: Ethereum Attestation Service attestations frequently reference ENS names as subjects; Karma3 Labs OpenRank links Farcaster FIDs to ENS names for cross-platform reputation; Gitcoin Passport ENS stamp awards points for ENS name ownership; Farcaster’s fname registry (off-chain) and ENS-based usernames (on-chain) provide identity persistence across Farcaster application migrations.

Lens Protocol

  • Lens Protocol (Aave team, launched Polygon 2022, migrated to Lens Chain ZK L3 2024) is a composable social graph protocol where profiles are NFTs (ERC-721) enabling social graph portability across applications. Each Lens Profile NFT carries cumulative reputation: publications (posts, mirrors, comments), followers, collected publications, and DAO participation history all accumulate as on-chain state queryable by reputation systems.
  • Lens’s Open Actions framework (v2, 2023) enables arbitrary smart contract interactions triggered from social actions, allowing reputation systems to observe and score complex social-economic behaviours: tipping frequency, curation quality (what content a user collects proves taste), collaborative publication patterns. The Lens Profile Score (third-party, 2024) aggregates follower count, engagement rate, publication frequency, and on-chain action richness into a single percentile score used by Lens apps for content discovery.

Farcaster

  • Farcaster (Merkle Manufactory, launched mainnet 2023, Warpcast v3 2024) is a sufficiently decentralised social protocol where user identity is anchored by FIDs (Farcaster IDs) registered on an Ethereum L1 contract, while social data (casts, follows, reactions) is distributed across Hubble nodes (a permissionless peer-to-peer network). This architecture creates a rich reputation data source: on-chain FID registration proves wallet ownership, Hubble data provides social interaction history, and Frames (interactive mini-apps embedded in casts) enable in-feed economic interactions.
  • Farcaster’s social graph is the primary input for Karma3 Labs OpenRank. The network had 300K+ registered FIDs and 80K+ daily active users as of Q1 2025, generating 5M+ social interactions daily. The quality of social graph data is high relative to Web 2.0 equivalents because FID registration costs ETH, creating a Sybil cost that filters low-effort bot accounts. Farcaster Frames enable on-chain attestation collection within social contexts — a cast can include a Frame requiring the viewer to sign an EAS attestation, generating verifiable claim data with strong social context.

Sybil Resistance Mechanisms

  • Sybil attacks (named after the 1973 Schreiber case of multiple identity disorder) are the primary attack vector against decentralised reputation systems: a malicious actor creates multiple pseudonymous identities to accumulate disproportionate reputation, governance weight, or funding share. Sybil resistance mechanisms impose costs on identity creation that deter multi-identity attacks whilst remaining accessible to legitimate single-identity users.

Proof of Humanity

  • Proof of Humanity (Kleros + Democritus Labs, Ethereum, 2021-) is a video-based biometric verification protocol where users submit a video recording (face + voice + Ethereum address display) that is then curated via Kleros decentralised court: community members can challenge fraudulent registrations with a security deposit, with disputes resolved by randomly selected Kleros jurors. Registered humans receive a vouching requirement (existing members must vouch for new members), creating a social graph of verified identities.
  • Scale (2025): 23K+ verified humans, used as an input to Gitcoin Passport, UBI Distribution (Democracy Earth), Vocdoni governance, and various DAO memberships. The challenge-response mechanism catches fraud but creates UX friction: successful challenges historically run at 3-7% of submissions, suggesting meaningful Sybil pressure. PoH is being migrated to Proof of Humanity 2.0 with enhanced biometric liveness detection and cross-chain identity anchoring.

Worldcoin and World ID

  • Worldcoin (Tools for Humanity, 2023-) is the largest biometric uniqueness protocol by scale, using custom Orb hardware (high-resolution dual infrared camera system) to capture iris patterns and generate a IrisCode (compressed 256-bit biometric hash via Daugman’s algorithm). World ID stores only the IrisCode hash — no raw biometric data — and generates ZK-proofs of uniqueness that prove “this person is a unique human who has not registered before” without revealing which Orb processed them or enabling cross-application identity correlation.
  • Technical Architecture: The IrisCode is committed to a Semaphore-based Merkle tree on Ethereum Smart Contract Platform (World Chain, an Optimism OP Stack L2 launched 2024). ZK-proofs use Groth16 circuit (SNARK) over BN254 elliptic curve, verifiable on-chain in <300K gas (~$0.02 at Q1 2025 gas prices). Applications query World ID by presenting a verification request containing the application’s unique identifier and a user action scope; the user’s World App generates a proof; the application verifies the proof on-chain or via the API.
  • Scale (2025): 10M+ verified World IDs across 35+ countries, 50+ Orb locations globally. Controversial due to biometric data concerns (civil liberties organisations in Germany, France, Kenya raised regulatory challenges 2023-2024; OpenAI CEO Sam Altman’s founding role raised conflict-of-interest concerns regarding AGI-era UBI distribution thesis). Despite controversy, World ID is the highest-assurance uniqueness signal available to decentralised applications, used by Gitcoin Passport, Farcaster, and multiple DAO platforms.

BrightID

  • BrightID (BrightID Foundation, 2019-) provides Sybil resistance via social graph analysis without biometrics. Users connect with people they know in-person or via video call, building a web-of-trust graph. The BrightID algorithm detects Sybil clusters as densely connected subgraphs that are weakly connected to the broader trust graph — a signature of manufactured identity networks. Users in well-connected graph positions receive “Meets” level verification; those in critical positions with high betweenness centrality receive “Aura” level (highest assurance).
  • Scale (2025): 250K+ verified users, integrated into Gitcoin Grants, 1Hive Gardens DAO, CLR.Fund quadratic funding. BrightID does not require biometrics, making it accessible in regions where biometric verification is culturally or legally problematic, but its social graph approach is weaker against coordinated Sybil rings that can simulate natural social connections.

Attestation Services

Ethereum Attestation Service (EAS)

  • Ethereum Attestation Service (EAS, Ethereum Foundation-adjacent, mainnet launch August 2022) is an open, permissionless attestation protocol enabling any entity to make any claim about any Ethereum address. EAS consists of two core smart contracts: SchemaRegistry (stores schema definitions indexed by UID = keccak256 hash of schema + resolver + revocable flag) and EAS Core (processes and stores individual attestation records).
  • Attestation Data Model: Each attestation contains: uid (unique identifier), schema (reference to SchemaRegistry entry), attester (Ethereum address making the claim), recipient (address being attested about), time (block timestamp), expirationTime (optional expiry), revocationTime (0 if not revoked), refUID (optional reference to prior attestation for chaining), data (ABI-encoded custom payload per schema), and revocable (boolean flag). Attestations can be stored on-chain (permanent, gas-costly) or off-chain (signed, gas-free, stored via IPFS/Arweave with EAS signature).
  • Schema Examples (deployed schemas, 2025): (address employer, uint256 salary, bool fullTime) for employment verification; (bytes32 projectId, uint8 qualityScore, string evidence) for open-source contribution quality; (bool isHuman, uint8 confidenceLevel, address issuer) for humanness verification; (string role, address dao, uint256 votingPower) for DAO role attestation. Schema creators can attach resolver contracts that enforce conditions on attestation creation (e.g., require the attester to hold a specific NFT, or pay a fee into a reputation bond contract).
  • Ecosystem (2025): 5M+ attestations across Ethereum mainnet, Optimism, Base, Arbitrum, Polygon, Linea. Key attestation issuers include: Coinbase (verified identity attestations for Base users), Gitcoin (grant eligibility attestations), ENS (ENS name ownership attestations), Worldcoin (World ID verification attestations), Safe (multisig signatory attestations). EAS is used as the data layer for Gitcoin Passport stamps (off-chain EAS signatures), Optimism’s RetroPGF voter eligibility, and Base’s identity layer.

Verax

  • Verax (Consensys + community, 2023-) is a shared attestation registry deployed on Optimism, Linea, and Polygon, designed as an interoperable alternative to EAS with similar data models but a module-based architecture. Verax introduces Portals (customisable attestation entry points with validation logic) and Modules (composable validation plugins): a Portal might require attesters to hold a specific token, and its Modules might enforce schema validation, rate limiting, and cross-attestation consistency checks. Verax’s shared registry model means attestations from multiple issuers accumulate in a single queryable data store, simplifying aggregation for reputation systems.

Sign Protocol and Omnichain Attestation

  • Sign Protocol (formerly EthSign, 2023-) addresses the multi-chain fragmentation problem by providing an omnichain attestation layer where attestations created on any supported chain (Ethereum, BNB Chain, Polygon, Arbitrum, Optimism, Base, Solana, TON) are relayed and queryable from any other chain via LayerZero cross-chain messaging. Sign Protocol uses a schema registry similar to EAS but with cross-chain schema references, enabling attesters on one chain to reference schemas deployed on another chain. This is critical for reputation systems that aggregate signals from multi-chain users: a user’s attestations from Ethereum mainnet DAO participation can inform their reputation score in a Base-deployed application without requiring the user to bridge or duplicate their attestation records.
  • Attestation Revocation and Freshness: Both EAS and Sign Protocol support attestation revocation (marking prior attestations invalid), which is critical for reputation systems that update over time: an employment attestation should be revocable when employment ends, a KYC attestation should expire and require renewal, a credit attestation should be updated as repayment history evolves. EAS revocation stores the revocation timestamp on-chain, enabling historical queries (“was this attestation valid at block N?”) required for deterministic smart contract logic. Revocation-aware reputation aggregation must distinguish between “never attested” and “attestation revoked” states, as revocation often carries negative signal beyond simple absence.

Decentralised Credentials and Standards

  • Verifiable Credentials (W3C VC-DATA-MODEL 2.0, June 2024) provide the data model standard for portable, cryptographically verifiable identity claims. A VC contains a credentialSubject (the entity being described), issuer (the credential authority), issuanceDate, credentialStatus (revocation mechanism), and a proof (digital signature or ZK-proof). VCs use JSON-LD for semantic interoperability, enabling automated reasoning over credential graphs. The critical property for reputation systems is selective disclosure: holders can present subsets of credential attributes without revealing the full credential, enabling minimum-necessary disclosure.
  • BBS+ Signatures (IETF draft, 2023-) extend VCs with zero-knowledge selective disclosure: the issuer signs the entire credential with a BBS+ signature (pairing-based, BLS12-381 curve); the holder can derive a proof revealing only selected attributes whilst proving those attributes are from the valid original credential without revealing which credentials were not disclosed. This enables reputation aggregation from multiple credentials without creating correlation linkage across applications.
  • Decentralised Identifiers (W3C DID Core 1.0, July 2022) provide the identifier layer: DIDs are globally unique identifiers controlled by the subject (not a registrar), resolved via DID methods (did:ethr for Ethereum, did:key for key-based, did:web for domain-anchored, did:ion for Bitcoin DPKI). In reputation systems, DIDs serve as stable subject identifiers across credential issuers — an ENS holder’s did:ethr resolves to their Ethereum address across all EAS attestations, Gitcoin Passport stamps, and Lens Protocol profile.

Soulbound Tokens and Non-Transferable Reputation

  • Soulbound Tokens (SBTs, Weyl, Ohlhaver & Buterin 2022 “Decentralised Society: Finding Web3’s Soul”) address a fundamental tension in blockchain reputation: ERC-20 and ERC-721 tokens are freely transferable, enabling reputation to be bought and sold rather than earned. SBTs are proposed as non-transferable NFTs bound to a wallet “Soul” address, representing credentials, affiliations, and achievements that cannot be separated from their earner.
  • SBT implementations include: Otterspace (membership badges for DAOs, 2022-2025, 50+ DAO deployments, 150K+ badges minted); Nouns DAO non-transferable governance participation certificates; Gitcoin non-transferable grant contributor recognition; Protocol Labs non-transferable IPFS ecosystem contributor credentials. The SBT model faces the privacy problem: public non-transferable tokens create permanent, queryable records of all associations, enabling discriminatory targeting based on DAO memberships or credential histories — a concern addressed by ZK-SBTs (ZK proofs of SBT ownership without revealing which specific SBT or when it was issued).
  • ERC-5192: Minimal Soulbound NFTs (2022) standardises the SBT interface with a single locked() function returning true for non-transferable tokens, enabling ecosystem tooling (wallets, explorers, indexers) to recognise and display SBT status. ERC-5484 (2022) extends this with consensual soulbinding: the token issuer and recipient must both consent to the binding, allowing recipients to reject unwanted credential bindings (important for privacy — users can decline to publicly associate with an issuer whose credential would reveal sensitive affiliations).
  • Reputation Bond Mechanisms: Some protocols extend SBT concepts with slashable reputation bonds where credential holders stake ETH or governance tokens proportional to the trust value they claim. Misbehaviour triggers slashing of the bond, creating a direct economic cost for reputation fraud. Centrifuge Credit (RWA lending, 2023-) uses reputation bonds where issuers of on-chain credit attestations must stake USDC equal to 10% of the attested credit line, slashable on default events. This transforms attestations from informational claims into economically backed commitments, substantially increasing their reliability as reputation signals.

Reputation System Architectures: Comparative Analysis

  • Reputation systems vary across four architectural dimensions that determine their trust assumptions, privacy properties, Sybil resistance strength, and composability with other systems.
  • Centralised vs Decentralised Computation: Centralised systems (Amazon seller ratings, Uber driver scores, eBay feedback) benefit from query efficiency, fraud pattern detection via cross-seller analysis, and ability to reverse fraudulent ratings — but require trusting the platform operator not to manipulate scores for commercial purposes. Decentralised systems (EigenTrust, OpenRank) provide auditability and censorship resistance but sacrifice efficiency and fraud detection capabilities that require private cross-account pattern analysis.
  • On-chain vs Off-chain Storage: On-chain attestation storage (EAS Core contract) provides permanent verifiability and composability with smart contracts but costs gas and is fully public. Off-chain attestation storage (EAS off-chain, Ceramic Network streams, IPFS-pinned VC documents) reduces gas costs and enables selective disclosure (share only with verification parties) but requires a liveness assumption (the storage node must be accessible) and trust in the relayer that the off-chain data corresponds to the signed message.
  • Global vs Personalised Trust: Global trust systems produce a single authoritative ranking (original PageRank, global EigenTrust) that is computationally efficient and enables universal comparison but assumes trust is objective and context-independent. Personalised trust systems (OpenRank’s personalised EigenTrust, local-first trust graphs) produce context-specific rankings rooted at the query user’s identity node — representing “who is trustworthy from my perspective” rather than universal trustworthiness. Personalised systems are more robust to manipulation (an adversary must compromise the query user’s direct social neighbourhood rather than global opinion) but are more expensive to compute and cannot provide universal rankings.
  • Credential-Based vs Behaviour-Based: Credential-based systems (Gitcoin Passport stamps, Verifiable Credentials) aggregate explicit claims from trusted issuers. Behaviour-based systems (EigenTrust over transaction history, Spectral Finance MACRO Score over DeFi interactions) infer reputation from observed actions. Credential systems are more gameable (credentials can be earned specifically for reputation purposes without genuine underlying trust), whilst behaviour-based systems are harder to fake but more opaque (the connection between observed behaviour and trustworthiness is algorithm-dependent and harder to explain to affected users).

Use Cases and Applications

DAO Governance Integrity

  • Decentralised Autonomous Organisations face plutocratic capture when governance is purely token-weighted: whales can buy governance power exceeding their legitimate stake. Reputation-gated governance introduces non-transferable weights based on contribution history, expertise attestations, and participation consistency. Optimism RetroPGF (Retroactive Public Goods Funding) uses reputation-gated badgeholder selection — candidates for the 150-member badgeholder cohort must hold attestations from existing badgeholders, creating a meritocratic selection mechanism that resists plutocratic capture. RetroPGF Round 4 (2024) distributed $10M+ in OP tokens via this mechanism.
  • Snapshot X (2023-) extends the Snapshot governance platform with on-chain strategy modules including EAS-based attestation gating, Gitcoin Passport score thresholds, and Karma3 Labs reputation score weighting. This enables DAOs to configure governance systems where voting power is a function of reputation rather than pure token balance.

Quadratic Funding Sybil Mitigation

  • Gitcoin’s quadratic funding (QF) mechanism allocates matching funds proportional to the square root of the number of contributors rather than the amount contributed, amplifying small contributions from many distinct contributors. This mechanism is catastrophically vulnerable to Sybil attacks: a single actor creating 1,000 fake wallets each contributing $1 receives the same matching as 1,000 real contributors. Gitcoin Passport’s Unique Humanity Score serves as the primary Sybil filter, with scores below 20 receiving reduced or zero matching weights in Grants rounds.
  • Passport-Weighted QF (Grants Stack, 2023-): each contributor’s quadratic weight is multiplied by a sigmoid function of their Passport Score: weight = QF_base × σ(score - threshold). This creates a smooth transition rather than binary gating, preserving the quadratic properties whilst substantially reducing Sybil impact. Gitcoin Grants Round 22 (2025) processed $3.5M in matching funds with Passport-weighted QF, with internal estimates suggesting 15-25% of unweighted contributions would have been Sybil.

DeFi Credit and Undercollateralised Lending

  • Traditional DeFi lending is over-collateralised (150-300%) because anonymous wallets cannot be assessed for creditworthiness. Reputation systems enable undercollateralised DeFi lending by creating credit scores from on-chain history: repayment history, liquidity provision consistency, governance participation, and professional credential attestations serve as credit signals. Spectral Finance (2021-) computes the MACRO Score from Ethereum transaction history, enabling credit-based borrowing at 100-130% collateralisation ratios for high-score wallets. Goldfinch Protocol (Warbler Labs) uses off-chain KYC and business creditworthiness attestations (from Cauris Finance and others) to enable uncollateralised institutional lending, with $100M+ deployed. Masa Finance (2022-) creates on-chain credit scores from multi-chain DeFi activity, social credential integration, and EAS attestations.

Social Graph Discovery and Content Ranking

  • Web3 social applications face cold start and content quality problems identical to Web 2.0 but without centralised moderation. Karma3 Labs OpenRank solves both: new Farcaster users receive personalised feed recommendations based on their social graph’s trust structure (warm start via social proximity), and content quality is ranked by the reputation of the caster weighted by follower graph authority (spam filtering without centralised moderation). The result is a decentralised content moderation system where community trust determines visibility rather than platform policy.

Decentralised Marketplace Trust

  • Peer-to-peer marketplaces without centralised escrow require reputation systems to substitute for institutional trust guarantees. Drip.haus (NFT marketplace), Sudoswap (AMM-based NFT trading), and OpenSea Pro (aggregator) all integrate EAS attestations for seller verification and collection provenance. On-chain reputation data from historical NFT trading (fill rate, dispute frequency, collection authenticity track record) feeds into marketplace trust scores that determine listing visibility and buyer-facing risk warnings. Tradeable reputation leakage is an active concern: if marketplace reputation data is public and queryable by third parties, reputation earned on OpenSea might inform credit decisions on DeFi platforms without the user’s consent or knowledge — a privacy concern requiring reputation system designers to implement access control on reputation queries.

Supply Chain Provenance

  • Supply chain applications use attestation frameworks to create tamper-resistant provenance records: manufacturers attest to component specifications, logistics providers attest to custody chain events, quality inspectors attest to test results. When these attestations are anchored to immutable blockchain records, downstream consumers can verify provenance without trusting any single intermediary. Baseline Protocol (EY + Consensys + Microsoft, 2020-) uses Ethereum attestations for supply chain synchronisation across enterprise systems, with a reputation layer tracking attestation issuer track record (false attestation history, revocation rate, dispute outcomes). Morpheus.network (2022-) uses EAS-compatible attestations for pharmaceutical cold chain compliance, with reputation scores for logistics providers derived from temperature excursion event history.

Open Source Contribution Recognition

  • Developer ecosystems use reputation to allocate retroactive compensation for public goods contributions. Optimism RetroPGF (described above under DAO Governance) is the largest example, but the underlying problem — fairly measuring and rewarding open source contribution — extends broadly. OSO (Open Source Observer) (2023-) aggregates on-chain and off-chain contribution signals (GitHub commits, npm downloads, Ethereum contract deployments, community forum activity) into impact metrics that feed RetroPGF allocation decisions and other public goods funding mechanisms. OSO integrations with EAS enable attestation of contribution facts (a specific commit was merged, a specific package reached X weekly downloads) that can be referenced by funding allocation algorithms without requiring human curation of every contribution.

Academic Context

  • The academic foundations of decentralised reputation span distributed systems, mechanism design, and social choice theory. Kamvar, Schlosser & Garcia-Molina (2003) “The EigenTrust Algorithm for Reputation Management in P2P Networks” (WWW 2003) established the mathematical framework that dominates Web3 implementations. Sabater & Sierra (2005) “Review on Computational Trust and Reputation Models” surveyed 25+ pre-Web3 reputation models, identifying robustness to collusion and transitivity as key desiderata. Dwork et al. (2012) formalised differential privacy constraints on reputation systems to prevent inference attacks. Weyl, Ohlhaver & Buterin (2022) “Decentralised Society: Finding Web3’s Soul” proposed the SBT framework that has become an industry standard reference.
  • Mechanism design perspectives: Myerson (2008 Nobel laureate) and colleagues have studied incentive compatibility in reputation systems — whether reporting honestly about counterpart quality is a Nash equilibrium under different payoff structures. Restuccia et al. (2023) demonstrated that EigenTrust-based Web3 reputation systems are vulnerable to strategic withholding attacks where high-reputation nodes refuse to give ratings to preserve relative standing, requiring modified incentive mechanisms to ensure complete reporting. Dellarocas (2006) “Reputation Mechanisms” provides the foundational game-theoretic analysis showing that reputation systems sustain cooperative equilibria only when (a) the future is valued sufficiently (discount factor δ > threshold), (b) history is accurately recorded, and (c) monitoring is sufficiently complete — conditions that blockchain’s immutable public ledger uniquely satisfies for financial interactions but only partially satisfies for social interactions (not all social events are on-chain).
  • Trust transitivity bounds: Massa & Bhatt (2008) demonstrated that trust transitivity degrades exponentially with path length in real social networks — “a friend of a friend of a friend” relationship carries negligible trust signal. This finding constrains EigenTrust effectiveness: global trust computation via multi-hop propagation across 6+ degrees of separation produces unreliable scores. OpenRank’s personalised computation implicitly respects this constraint by weighting trust inversely with path length (the random-walk-with-restart damping factor serves the same function as trust decay in transitivity models).
  • Privacy economics of reputation: Acquisti & Grossklags (2005) documented the privacy paradox in reputation contexts: individuals systematically underestimate future privacy costs of current disclosure, leading to over-sharing of reputation-relevant information. In blockchain contexts, this manifests as users willingly minting SBTs or issuing EAS attestations that permanently record sensitive affiliations (health conditions, political affiliations, financial status) without adequately modelling the adversarial use of this information by future parties who did not participate in the original disclosure context.
  • Imperial College London (Department of Computing, Decentralised Systems group): Dr Alexei Zamyatin and colleagues have conducted empirical analysis of Sybil resistance mechanisms across five Web3 identity protocols (2024), quantifying false positive rates and user friction costs, with findings that biometric approaches achieve 0.3% false positive at 15% user dropout, while social-graph approaches achieve 3-5% false positive at 2% dropout. Manchester University (Computer Science, Prof. Bijan Parsia’s group) has published on formal semantics of reputation ontologies and composable credential verification in decentralised systems. Edinburgh University (School of Informatics) maintains active research on zero-knowledge credential systems with applications to reputation privacy (ZK-AnonCreds, ZK-SBTs). UCL (University College London, Computer Science) has published on governance token voting power distribution and plutocracy metrics in major DAOs, providing empirical baseline data for reputation-weighted governance design. King’s College London (Department of Digital Humanities) has examined the sociological implications of on-chain reputation for marginalised communities — specifically how algorithmic reputation systems can entrench existing social inequalities when trust graph starting conditions correlate with social class, ethnicity, or geographic location.

Current Landscape (2026)

  • The decentralised reputation ecosystem in 2026 has consolidated around three primary components: EAS as the attestation primitive (5M+ attestations, 8 chains), Gitcoin Passport as the Sybil resistance aggregator (850K+ passports, 200+ integrations), and Karma3 Labs OpenRank as the social graph trust engine (500M+ monthly interactions processed). World ID has reached 10M+ verifications but remains controversial due to biometric data concerns.
  • Interoperability has emerged as the defining challenge: attestations from EAS on Ethereum mainnet are not natively accessible to applications on Base, Optimism, or Polygon without bridging or relayer infrastructure. Cross-chain attestation resolution is being addressed by EAS’s multi-chain deployment strategy, Verax’s shared registry model, and emerging standards from the Trust Over IP Foundation (ToIP) for portable reputation across Layer 2 ecosystems.
  • AI-generated fake identity has become the dominant Sybil threat vector in 2025-2026: LLM-generated content, AI face synthesis defeating liveness detection, and coordinated bot networks using AI-generated social histories challenge all non-biometric Sybil resistance approaches. This has elevated the importance of hardware-rooted biometric approaches (World ID Orb, Palm.AI palm geometry) and economic stake requirements (minimum ETH holding, ENS registration) as Sybil costs that AI cannot easily undermine.
  • Reputation portability across ecosystems remains unsolved: Farcaster reputation does not automatically transfer to Lens, ENS-based reputation is not queryable by Farcaster-native applications, and EAS attestations require custom indexers per-application. The lack of a universal reputation API is the primary adoption barrier for applications seeking multi-source trust aggregation.
  • Regulatory pressure is intensifying: the EU’s eIDAS 2.0 regulation (2024) requires large platforms to accept government-issued digital identity credentials, creating compliance requirements for Web3 applications serving EU users. MiCA (Markets in Crypto-Assets Regulation, full enforcement 2025) requires DeFi protocols above certain TVL thresholds to implement KYC/AML checks, pushing reputation systems toward hybrid designs incorporating both decentralised trust scores and regulatory-compliant identity verification.
  • Emerging primitives in 2025-2026: Several new architectural components have entered production in the 2025-2026 period that significantly expand the reputation design space. ZK Email (2024-) enables attestations derived from email content (e.g., “this wallet holds an email from @amazon.com confirming purchase”) without revealing the email content or sender to the attestation verifier, using ZK-proofs over email DKIM signatures. This enables a new category of stamps for Gitcoin Passport and EAS attestations grounded in email-verifiable real-world events. TLSNotary (zkPass integration, 2024-) uses multi-party computation to enable ZK-proofs of HTTPS session content — a user can prove they have a Coinbase account with >$1K balance without revealing their account details or requiring Coinbase to issue an attestation, by proving the existence of specific content in a TLS-encrypted session. Reclaim Protocol (2023-) is a production implementation of TLS-based attestation generation with 100+ integrated data sources and 500K+ proofs generated as of Q1 2025.
  • Market metrics (2025): The total value of assets governed by reputation-gated mechanisms is estimated at 22B, Optimism ecosystem 12B), DeFi lending protocols using reputation scoring (Goldfinch, Centrifuge, Maple Finance combined 50M+ annually across Gitcoin Grants, Optimism RetroPGF, and clr.fund). The total attestation market (number of EAS + Verax + Sign Protocol attestations) crossed 10M cumulative in Q4 2025, with issuance rate doubling year-over-year.
  • Developer tooling maturity: The attestation ecosystem has developed substantial tooling that reduces integration friction for new applications. EAS SDK (TypeScript, 2023-) provides a high-level API for creating, signing, and verifying attestations in 10-50 lines of code. Karma3 Labs OpenRank SDK (2024-) enables personalised EigenTrust computation via a single API call with configurable social graph sources. Gitcoin Passport Scoring API (2023-) provides sub-200ms Passport Score queries for any Ethereum address. Attestation Explorer (EAS) and Sign Scan (Sign Protocol) provide human-readable attestation browsing for user-facing transparency. This tooling maturity is driving rapid adoption: 200+ applications integrated Gitcoin Passport API within 18 months of API launch (2023-2025), a rate faster than comparable ecosystem infrastructure milestones like The Graph protocol adoption.

UK Context

  • Imperial College London (Computing Department, Decentralised Systems Group): Active research on formal analysis of reputation system security (2024-2026), including game-theoretic analysis of EigenTrust manipulation and empirical Sybil resistance benchmarking across five protocols. Prof. William Knottenbelt’s group has published on blockchain-based reputation for financial services with Bank of England collaboration.
  • University of Edinburgh (School of Informatics, Blockchain Technology Lab led by Prof. Aggelos Kiayias): Research on zero-knowledge credential systems with privacy-preserving reputation aggregation. The Edinburgh group contributed to the Athos protocol for ZK-AnonCreds (2025), directly applicable to reputation privacy in decentralised contexts. Collaboration with the Scottish Government’s Digital Identity Scotland programme on verifiable credential technical standards.
  • University of Manchester (Computer Science, Prof. Bijan Parsia): Formal ontology of reputation and trust for decentralised systems, published at ISWC 2024. Research on composable credential verification and reasoning over heterogeneous attestation schemas — directly relevant to interoperability challenges in EAS/Verax ecosystems.
  • University of Cambridge (Cambridge Centre for Alternative Finance, CCAF): Policy research on decentralised reputation for DeFi credit risk (2024-2025), with specific focus on undercollateralised lending protocols and their regulatory classification under UK FCA frameworks.
  • UK Regulatory Environment: The Financial Services and Markets Act 2023 (FSMA 2023) and HM Treasury’s crypto asset consultation papers (2023-2024) create a regulatory framework where reputation systems used in financial services must meet AML/KYC equivalence standards. The FCA’s Digital Sandbox (Cohort 4, 2024) included two reputation system projects testing EAS-based compliance attestations for crypto asset firms.
  • UK Ecosystem: London-based Iovation/TransUnion (acquired 2018) operates traditional device reputation systems; Monzo and Revolut have internal reputation systems for fraud scoring. The Web3-native UK ecosystem includes Onfido (AI-based identity verification, London, acquired by Entrust 2024 $400M), which provides KYC attestation services used by Gitcoin Passport’s financial stamp category; Chainalysis (analytics), which integrates with reputation systems for transaction risk scoring; and Elliptic (London), which provides reputation risk scores for Ethereum addresses used by regulated UK crypto exchanges.
  • Northern England Industrial Applications: Manchester-based financial technology firms including LendInvest and Atom Bank have explored blockchain-based reputation for SME lending risk assessment. Newcastle University (Digital Economy group, Prof. Patrick Olivier) researches trust metrics for IoT device networks applicable to reputation system architectures. Leeds digital economy sector includes several DAO tooling companies exploring on-chain reputation for cooperative governance of worker-owned platforms.

Future Directions (2026-2030)

  • ZK-Native Reputation Aggregation: Fully privacy-preserving reputation computation using zero-knowledge proofs over aggregated signals, enabling applications to verify “this user scores above threshold X” without learning their specific score, attestation sources, or social graph position. Projects like EZKL (ZK inference for ML models) and Axiom (ZK coprocessor for historical Ethereum data) are building the primitives needed for this capability.
  • AI-Resistant Biometrics: Next-generation biometric approaches combining iris (World ID), palm (Palm.AI), and behavioural biometrics (typing patterns, gait via accelerometer) that resist AI-generated spoof attacks. Liveness detection using 3D face mapping (depth-sensor based, requiring physical presence in front of specialised hardware) represents the current frontier of Sybil-resistant biometric verification.
  • Reputation for AI Agents: As autonomous AI agents become participants in DeFi, DAO governance, and Web3 social ecosystems, reputation systems must accommodate non-human actors. The DIF AI Agent Identity Working Group (2025-) is developing attestation schemas for AI agent identity including model version, capability bounds, operator identity, and compliance certifications. EAS schemas for AI agents will need to distinguish human principals from AI executors in multi-agent transaction chains.
  • Cross-Ecosystem Reputation Portability: The emerging Open Reputation Alliance (ToIP + DIF + W3C VC community, 2025) is developing a reputation portability protocol enabling scores and attestations to flow between Web3 social networks, DeFi protocols, DAO governance platforms, and traditional Web 2.0 applications without requiring centralised aggregation. Target: universal reputation API by 2027.
  • Reputation-Weighted Governance at Scale: Current DAO governance with reputation weighting tops out at ~10K active voters. Scaling to nation-state level (millions of participants) requires advances in ZK-aggregation (batch-verify millions of reputation proofs in constant time), optimistic reputation updates (use L1-verified snapshots with L2 dispute windows), and formal voting mechanism analysis ensuring strategy-proofness under reputation systems.
  • Regulatory Integration: By 2028, EU eIDAS 2.0 EUDI Wallets will be the dominant digital identity infrastructure for 400M+ EU citizens. Decentralised reputation systems will need dual-track architectures: a privacy-preserving on-chain track for permissionless interactions and a regulatory-compliant EUDI Wallet-linked track for regulated financial services. The technical bridge (ZK proofs of EUDI Wallet credential possession without revealing wallet contents) is currently an active research area at Edinburgh, Imperial, and TU Delft.

Research and Literature

  • Foundational: Kamvar, Schlosser & Garcia-Molina (2003) “EigenTrust Algorithm for Reputation Management in P2P Networks.” WWW 2003. — Brin & Page (1998) “The Anatomy of a Large-Scale Hypertextual Web Search Engine.” WWW 1998. — Sabater & Sierra (2005) “Review on Computational Trust and Reputation Models.” Artificial Intelligence Review 24(1). — Zacharia & Maes (2000) “Trust Management Through Reputation Mechanisms.” Applied Artificial Intelligence 14(9).
  • Web3-Specific: Weyl, Ohlhaver & Buterin (2022) “Decentralised Society: Finding Web3’s Soul.” SSRN Working Paper. — Karma3 Labs (2023) “OpenRank: Personalised EigenTrust for Decentralised Social Networks.” Technical Report. — Gitcoin (2022-2024) “Passport Score Model: Composite Sybil Resistance via Heterogeneous Credential Aggregation.” Engineering Blog Series. — Buterin (2022) “Soulbound.” Vitalik.ca. — De Filippi, Dyer-Witheford & Terranova (2020) “The Blockchain as a New Form of Social Ordering.” Journal of Peer Production 13.
  • Attestation Standards: Ethereum Attestation Service (2022) “EAS: An Ethereum-Native Attestation Protocol.” Protocol Documentation. — W3C (2024) “Verifiable Credentials Data Model 2.0.” W3C Recommendation. — W3C (2022) “Decentralised Identifiers (DIDs) v1.0.” W3C Recommendation. — IETF (2023) “BBS Signature Scheme.” Internet-Draft draft-irtf-cfrg-bbs-signatures-05.
  • Sybil Resistance: Douceur (2002) “The Sybil Attack.” IPTPS 2002. — Levine et al. (2006) “A Survey of Solutions to the Sybil Attack.” Technical Report UMass Amherst. — Troncoso et al. (2017) “Systematizing Decentralisation and Privacy.” Proceedings on Privacy Enhancing Technologies 2017(4). — Worldcoin (2023) “World ID Technical Whitepaper v2.0.” Tools for Humanity. — Proof of Humanity (2021) “A Permissioned and Sybil-Resistant Protocol for Self-Sovereign Identity.” Kleros Cooperative.
  • Privacy and Zero-Knowledge: Camenisch & Lysyanskaya (2001) “An Efficient System for Non-transferable Anonymous Credentials with Optional Anonymity Revocation.” EUROCRYPT 2001. — Bünz et al. (2018) “Bulletproofs: Short Proofs for Confidential Transactions.” IEEE S&P 2018. — Groth (2016) “On the Size of Pairing-Based Non-interactive Arguments.” EUROCRYPT 2016.
  • UK Academic: Zamyatin et al., Imperial College London (2024) “Benchmarking Sybil Resistance in Web3 Identity Protocols: False Positive Rates and User Friction Analysis.” Financial Cryptography 2024. — Parsia et al., University of Manchester (2024) “Formal Ontology of Composable Reputation in Decentralised Systems.” ISWC 2024. — Kiayias et al., University of Edinburgh (2025) “Zero-Knowledge Credential Systems for Privacy-Preserving Reputation Aggregation.” EUROCRYPT 2025.
  • Mechanism Design: Myerson (1981) “Optimal Auction Design.” Mathematics of Operations Research 6(1). — Restuccia et al. (2023) “Incentive-Compatible Reputation Reporting in Decentralised Networks.” ACM EC 2023. — Dwork et al. (2012) “Differential Privacy and Robust Statistics.” ACM STOC 2012.

Metadata

  • domain-correction: null — blockchain confirmed as correct domain (reputation systems for blockchain/Web3 ecosystems; EigenTrust, EAS, Gitcoin, Karma3 Labs, World ID are all blockchain infrastructure)
  • iri-correction: null — namespace blockchain# confirmed correct
  • owl-class-correction: null — blockchain:ReputationSystem retained
  • legacy-term-id: BC-0612 assigned (blockchain domain, sequential to BC-0437 R3 Corda, BC-0456 Self Sovereign Identity)
  • enrichment-worker: claude-sonnet-4-6
  • enrichment-date: 2026-05-17

Provenance