What the attacker wants
The relay attacker already has something that looks valid — a proof, envelope, or ceremony fragment minted for one route — and wants to present it against a different endpoint, method, or policy. The conversion is retargeting: keep the expensive proof bytes, swing them at a higher-value call. Classical ambient keys make this trivial because the key grants an estate of paths, not a single request context. Relay is the sibling of replay: same captured authority, different destination, still trying to cash out.
