A3 — Dishonest Merchant: Phantom Attestation
The merchant is trusted to report real purchases (Assumption A-MERCHANT, §2.3). A dishonest merchant can sign attestations for non-existent purchases. The protocol cannot distinguish a real attestation from a fabricated one — both carry valid Ed25519 signatures from the merchant's key.
Vulnerability window: A Tier 3 merchant can fabricate limited phantom attestations within normal volume without triggering anomaly detection. The bond system makes it economically irrational, but not mathematically impossible.