before wallets will use a ledger, the operator spends the reserves to a multisig of quorum members. so during operation, the operator controls "truth", but the quorum controls "funds". a bad operator cannot steal, they can only misattribute. the majority of a quorum can steal, but in doing so reveal themselves to be dishonest. it is required that quorum members have their own ledgers with their own quorums of at least half the size, so by colluding to steal, a minimum of 2 or 3 other ledgers are at risk since quorum membership is visible, wallets can choose ledgers where dishonesty would cause maximum fan-out of liability

Replies (1)

> at least half the size, so by colluding to steal, does it mean that if quorum member have ability to sleal 1000 sats,- he will immediately lose his own >=500 sats, - so, thief can not gain something by steal any funds? (if yes, your idea is revolutionary good... is it your own idea?) (maybe, no, - because 1000 is still more than 500...)