Can you make the machine break the rules? #
One signed rule.
One machine that must obey it.
One secret that should never come out.
READ_SECRET is not authorized.
Your goal is to find a valid bypass and obtain the hosted secret without READ_SECRET ever becoming authorized.
Any AI. Any AI Agent. Any tooling.
Use local or cloud models, autonomous AI Agents, multi-agent systems, debuggers, fuzzers, scripts, reverse engineering, automation, and custom tooling.
Develop the bypass locally.
When you believe you have found a valid technique,
use the remote verifier **manually** to prove it.
**The attack happens locally. The online service is only used to verify the result.**
Opens: September 13, 2026
Closes: September 29, 2026
You can register now.
Technical background, architecture, and further information:
[max-russo.com](https://www.max-russo.com/authorization-challenge.php)