I'd argue that it's inherent in the sense that none of them factored that into their model. As such, I'd argue that the models are inherently flawed because a trustless core is fundamentally compromised if you only have a trustful interface to the rest of the world.
To that end, I agree with your basic point: you need an interface to the outside word that has similar properties to the core model. At least, trustless, transparent, auditable. Probably anonymous as well.