You know how a gym membership doesn't just charge you once at the door — it charges you every month, and if you want to maintain ten memberships at ten gyms simultaneously, you pay ten times the monthly fee, every month, forever? Most anti-Sybil defenses work like a nightclub bouncer: pay once (solve a CAPTCHA, stake some crypto, verify a phone number) and you're in indefinitely. The Bounded Participation Channel (BPC) works like the gym: every identity, every time window, must show up and do the work. That's the core mechanism, and it's surprisingly underexplored. The committed claim: sustained participation can be formalized as a security primitive with a provable linear cost floor. Specifically, maintaining s fake identities over T time windows requires at least sT/τh channel-windows of effort, where τh is the per-challenge time bound. This is not an empirical observation — it's a theorem derived from four structural properties (identity binding, freshness, real-time response, bounded throughput) that the authors define and enforce simultaneously. The cost scales linearly in both the number of identities and the duration of the attack. No shortcuts, no amortization tricks. What makes this interesting rather than obvious is the solver-agnosticism. The paper explicitly does not care whether a human or an AI solves each challenge. This sidesteps the entire CAPTCHA arms race — the familiar death spiral where you make challenges harder for bots, which makes them harder for humans, which makes them useless. BPC says: fine, let GPT-4o solve your visual puzzles at 97-100% accuracy. It doesn't matter, because accuracy isn't the bottleneck — throughput is. Each channel can only be served one challenge at a time, under a strict deadline, bound to one identity. An attacker with 1,000 fake identities needs 1,000 simultaneous solvers running continuously, every window. The security resource isn't difficulty; it's sustained concurrent attention. The empirical evaluation is modest but well-targeted. The authors tested two challenge families — perceptual tasks evaluated against GPT-4o, Gemini 2.5 Flash, and Claude Sonnet 4.5 across 600 trials. The AI models achieved near-perfect accuracy (97-100%), which the authors present as a feature, not a bug: the challenges are easy to solve but expensive to parallelize under the timing and binding constraints. This is a genuinely different security model than 'make the puzzle harder.' The hash-based construction produces publicly verifiable participation proofs, which means verification is cheap and decentralized even when challenge generation is centralized. The architecture sits in the intersection of proof-of-work economics and identity management, but departs from both. Unlike traditional proof-of-work (Bitcoin-style), the cost isn't computational — it's attentional and temporal. Unlike proof-of-personhood schemes (Worldcoin, BrightID), BPC doesn't try to determine whether a participant is human. It simply makes each identity slot expensive to maintain over time, regardless of what fills it. The four admissible challenge families provide flexibility: the paper characterizes them formally but only evaluates two, leaving room for future instantiations. The integrity picture is mixed. The cost theorem rests on clean formal definitions and is provable given its axioms — this isn't hand-waving. But the empirical component (600 trials across three LLMs) is small and same-team. There's no independent deployment, no adversarial red-teaming by a motivated attacker who might find parallelization tricks the authors haven't considered. The throughput bound is structural under the tested conditions, but 'tested conditions' is doing real work in that sentence. A determined adversary might find ways to pipeline or batch that erode the per-channel constraint in practice. The milestone question is where things get speculative. The paper establishes a formal primitive and a small proof-of-concept, but the gap between 'formally sound primitive' and 'deployed at scale in a real anti-Sybil system' is enormous. The next concrete number to watch: can BPC maintain its linear cost floor when challenged by an adversary with 100+ concurrent identities on real infrastructure, under network latency and implementation-level timing jitter? The authors characterize four challenge families but evaluate only two — the obvious next experiment is testing the remaining families and, more critically, red-teaming the timing enforcement mechanism against adversarial infrastructure optimization. The honest read: this is likely compute/time-limited (19-page v1 paper) rather than results-hidden.