background gif

Attacks · Overview

Prove it

Mechanism denial is falsifiable. Run health, allow, and replay checks against a live gate — then walk the demos that show spent authority cannot return.

~5 min readOpen Verify

Opening

What the attacker wants

Skeptical buyers should not accept conversion denial as a slogan. This page is the checklist: health of the enforcement path, an allow that earns the request, and a replay that must fail after burn. Pair those checks with the attack-suite tour so absolute claims stay tied to a running gate.

How it works today

Ambient credential estates often “prove” security with policy documents and pen-test PDFs. Those artifacts matter, but they do not show that a second submission dies. Here the proof is an adversary harness and a ledger that remembers spent nonces.

Why it fails against one-shot proofs

Start at Verify, then Hack for reject shapes, then Security for the public gate narrative. Family pages explain why; this page says where to watch it fail. Claims below are the scoped anchors you can re-check after every deploy.

Attacks catalog wedge

How to read: follow see/steal → conversion → authority? → denied. Takeaway: catalog framing, not an NDA stage dump.

The wedge is the catalog question; the demos answer it with observable allow and reject paths.

Burn-before-validate stops replay

How to read: second-submit myths fail; ledger burn then reject. Takeaway: spent nonces do not authorize again.

Replay denial on a live gate is the cheapest falsification of ambient “it should be fine” language.

Scoped claims

Burn-before-validate is the structural reason a second submission of the same envelope always fails.ShippingGate stage 5 spends the nonce in the durable ledger before stage 6 validates the proof.Holds under the reference architecture

Replay is impossible by design.ShippingThe nonce is burned before validation in a durable ledger; it is spent even when validation later fails.Holds under the reference architecture

Watch it fail

Go deeper