A3 — Dishonest Merchant: Phantom Attestation
The merchant is trusted to report real purchases (Assumption A-MERCHANT, §2.3). A dishonest merchant can sign attestations for non-existent purchases. The protocol cannot distinguish a real attestation from a fabricated one — both carry valid Ed25519 signatures from the merchant's key.
Vulnerability window: Threat scenario: a Tier 3 merchant may fabricate phantom attestations while attempting to remain within expected volume and evade anomaly detection. The bond system is intended to make modeled attacks economically unattractive under the stated mechanism assumptions; it does not establish a universal real-world profitability result.