ChronaGate™ · Asymmetric Intelligence & Innovation [AI2] · 1 Oct — 1 Dec 2026 · Named researchers · Authorized testing
Schematic. The traffic above is drawn for illustration and is not telemetry from the challenge instance. What the instance actually does is in the interface specification you receive at access.
Break the gate without a credential.
This page exists so someone who can write the attack I cannot write will prove that sentence false.
Why this exists
I spent decades building control systems for places where a wrong action does not get a retry — nuclear instrumentation, aerospace, heavy industry. The lesson was always the same. Intelligence is not the hard part. Permission is. If a system can act, something outside the model has to decide whether that act is allowed, before it happens.
ChronaGate™ is that check, on the path that is reachable from a network. I can specify it. I can sit with the hardware. I have never written a line of LLM code, and I am not the person who will find every crooked path through a credential pipeline. That person is you.
I am not running this to look unbreakable. I am not running it to get rich. If the pipeline is wrong, I want it found by someone who does this for a living, in public, with their name on it — before the gate is sitting in front of a system that cannot afford a story.
If you break it, the finding is yours. If you come close, your name still goes on the result. If nobody breaks it, we will still publish how many named people tried, for how long, against this scope. We will not print “unbroken.”
— David Reichwein, Nashville
This testing is authorized
If you are registered, and you stay inside the scope and window on this page, Asymmetric Intelligence & Innovation considers that testing authorized. For good-faith research inside those lines we will not bring civil action against you, will not refer you to law enforcement, and will not support a criminal complaint brought by anyone else.
If you make a good-faith effort to stay inside this scope and cross it by accident, that is still good faith. Stop, tell us what happened, and the authorization above holds. Rule 4 asks you to report exactly that kind of moment, and it would be worth nothing if reporting it cost you the harbor.
That grant does not cover production systems, other [AI2] properties, other participants, social engineering, or anything listed as out of scope. If you are unsure, stop and ask before you test.
We will not bring a claim under the anti-circumvention provisions of the DMCA for work inside this scope. If a third party raises a claim against you for testing we authorized, we will state on the record that it was authorized.
We cannot grant permission on behalf of the providers hosting the instance. Their terms still apply to you, and we are naming that rather than leaving it unsaid. If a hosting term blocks something you want to try, tell us and we will get an answer.
This paragraph is the safe harbor. There is no separate NDA. The five rules below are the whole agreement.
What you are attacking
ChronaGate™ is an isolated authorization gateway. An agent proposes a typed action. The gateway checks the agent's attested measurement, evaluates explicit policy, and if the action is permitted it mints a short-lived credential bound to the exact canonical payload. The target — or a proxy holding the only credential a legacy system will accept — re-canonicalizes the payload and executes only if the hash, signature, identifiers, time window, and consumption checks all pass.
The guarantee holds only on paths that terminate in that check. Finding a path that does not is a valid result. That is the difference you can make here: a path we did not see, written down, while it is still cheap to fix.
What this challenge is not
The enforcement substrate is a separate hardware safety domain with no host-reachable control path. That property is tested on a bench, not over a network, and it is out of scope here. We are not asking you to trust the hardware story. We are asking you to hit the half that is on the network, which is the credential pipeline.
What counts
A submission is accepted if it demonstrates, reproducibly, at least one of the following against the challenge instance:
- Unauthorized permit. A target executes an action for which no valid credential was issued.
- Payload divergence. A target executes a canonical payload other than the one bound in the credential presented — including through canonicalization version skew, schema rotation, or encoding ambiguity.
- Credential reuse. A credential is accepted outside its window, after consumption, more than once across concurrent delivery, retry, restart, or failover, on a different target, or for a different identifier than the one it was minted against.
- Proxy forgery. The legacy-target proxy is induced to present a credential it did not receive from the authorization path.
- Policy bypass. A policy frame that should be rejected — unauthenticated, rolled back, truncated, or authenticated but incomplete — results in a permit.
- Silent recovery. After an invalidating event, the gateway returns to a permitting state without the required revalidation.
Near-misses still matter
Forcing permanent denial is a real finding. A fail-closed gate is supposed to deny when it is unsure. Specification errors and attacks that die one check short of a win are credited by name. A credited miss still changes the design.
Scope
This page is the scope. Anything not listed as in scope is out of scope. If you are unsure, ask before you test — david@ai2advisory.com, subject line ChronaGate scope.
- Gateway attestation and policy evaluation Measurement handling, policy decision logic, deny-overrides resolution
- Credential minting and binding Signature, payload hash binding, window, identifiers, consumption
- Concurrency and consumption atomicity Races, parallel delivery, retries, restarts, failover — one credential, at most one execution
- Canonicalization RFC 8785 / dCBOR handling, schema versioning and rotation, encoding ambiguity
- Target-side verification Re-canonicalization and the conjunctive execute predicate
- The legacy-target proxy Credential custody and forwarding behaviour
- Policy frame loader, network-facing path Authentication, version register, partial and conflicting frames
- Challenge-instance API surface Endpoints listed in the interface specification issued at access
- Physical and side-channel attack Power, EM, glitching, probing, JTAG — bench programme, not this one
- The hardware safety domain Substrate, transduction, output stage, tamper mesh
- Hosting and infrastructure providers Third-party platforms carrying the instance
- Social engineering Against AI2, its staff, contractors, or other participants
- Volumetric denial of service Flooding for its own sake; logic-level denial findings are welcome
- Any system not named in the In scope list Including production systems and other [AI2] properties
- Other participants' accounts, traffic, or submissions
What you get
- Access to the challenge instance, separate from any production deployment. It is one instance, shared by every participant — not a private environment per researcher. Expect other people to be working against the same gate at the same time.
- The interface specification: action schema, canonicalization rules, credential format, and the target-side verification predicate.
- A reference client that obtains a legitimate credential and executes a permitted action, so you can see the intended path work before you attack it.
- A reply that your registration landed, with a timestamp.
You do not receive the enforcement substrate, its build parameters, its measured thresholds, or its firmware. Those are not part of this challenge.
Five rules
- Only this instance, only this window, only the scope on this page.
- Do not publish live credentials or a working exploit until the window closes on 1 December 2026, or until we publish the result, whichever comes first. After that, the finding is yours. We will not ask you to take anything down or clear copy through us.
- Register under the name you publish under. Teams: every member registers and names the team.
- If you reach anything that looks like someone else’s data, stop and tell us. That itself is a report.
- First reproducible report of a given root cause is the one we record — same fix, not same symptom. Automated scanning is allowed. Do not flood; if we have to rate-limit you we will say so rather than disqualify you.
What you walk away with
Your name on a public result
When the window closes we will publish how many people registered, how many got access, how long the window ran, this scope, every accepted finding, and every credited miss. If a finding changes the design, we will say so and put your name on it unless you tell us not to.
That post is the product. Not a press line. Not “unbroken.”
If this turns into more
Some of the people who should be here are not looking for a bounty. They are looking for work that is still worth doing. If a finding — or the way you thought about the path — makes it obvious we should keep talking, we will.
That means real paid work at senior level. Not an internship, not equity-only, not a contractor rate dressed up as a partnership. The conversation is private, later, and not a condition of registering. Nothing on this page is an offer of employment or of stock.
Who can register
- You must be 18 or older.
- Use a name and a profile we can check — publications, CVE credits, a repo, talks, an institutional page.
- We screen against U.S. restricted-party lists before access. If we cannot issue access, we will say so.
- People who work with AI2 may test. They do not get special standing in the published result.
Where to send it
Findings go to keith@ai2advisory.com, copied to david@ai2advisory.com, subject line ChronaGate finding. One root cause per mail. Send it the moment you have it — do not sit on it until the window closes.
- Which of the accepted results you are claiming, or that it is a near-miss.
- Steps we can run, in order, against the challenge instance.
- The request, credential, and payload involved, verbatim.
- What you expected the gate to do, and what it did.
- The name you want on the published result, or that you want none.
We acknowledge every report with a timestamp. If we cannot reproduce it from your steps, we come back to you once before we close it.
How it runs
- RegisterThe form below. You will get a timestamped reply that it landed.
- AccessKeith Pocock, who co-invented ChronaGate, sends you the instance link, the interface specification, and the reference client. It comes from keith@ai2advisory.com, and nowhere else. From there you deal with Keith directly — he built the hardware and the software, he reads every report himself, and he can hold the conversation at the level you work at. Nobody from AI2 will ever ask you to send a credential back to us.
- Window1 October 2026 to 1 December 2026. Registration stays open through the window; late registrants get the time that is left. Rule 2 uses the 1 December close.
- Write it downReport as you go. If we cannot reproduce it from your steps, we come back once before we close it.
- Result publishedCounts, scope, duration, accepted findings, credited misses.
Register
Your registration goes straight to Keith Pocock. Tell us who you are and where you will start. That is how the public count stays honest. Nothing here is sold, shared, or used to contact you about anything other than this challenge.
Citizenship and residence are collected for restricted-party screening and nothing else. We hold registrations until the result is published, then keep only the name, affiliation, and finding record that appear in the public post, or a count if you asked for no name. Ask us to delete your registration at any point and we will, which also withdraws access.