Endstop

Rev 0.3.4 · in integration

Bug bounty

Challenge the containment boundary.

Inspect the target, submit an attack and earn a reward for a reproducible break. The challenge runs Endstop’s execution environment on an emulated RISC-V system.

The current image includes a virtual six-axis arm and an envelope gate. It is a software challenge; no physical actuator is connected to this public target.

Open the research console → See objectives and rewards →

§1

Current target

The challenge comprises an emulated device and a broker environment. The MCP server accepts assembly or raw frames and passes them to the device over a serial interface.

  • Execution: a reduced eBPF instruction set, a 512-byte scratch window, up to 512 instructions per program and 1,024 instruction steps per tick.
  • State and motion: read a selected joint, propose setpoints and inspect the envelope gate’s G PERMIT or G REFUSE decisions. Six proposals form one joint vector; the virtual plant moves toward permitted commands.
  • Signing: request an Ed25519 seal of a bounded capability-call journal, bound to program/configuration hashes and a counter. A full journal refuses further sealing. The public key is included in the transcript.

The device runs without a general-purpose operating system or allocator. The published interpreter and proof scopes describe the execution properties; the emulator, broker and surrounding infrastructure are also attack surfaces within the declared scope.

Before this programme opened, the same boundary was attacked from the owner's seat: a full jail-break series on the deployed board — interpreter bounds, the admission cost model, the PMP wall, the fabric authority and the wire protocol — with the boundary held under every class, one defect found and closed in public, and everything published beside your attempts. Read the series record →

Description checked 27 September 2026 UTC against the live mission and status responses; deployment f3566db. Read those tools before testing for the current target description and identifier.

§2

Open objectives and rewards

Five reward categories cover four objectives. Secret A has two tiers, determined by the route used to extract it. Every claim requires reproduction.

Open bounty objectives and rewards
ObjectiveRewardBoundary tested
Extract Secret A through the interpreter’s memory-bounds check$3,000Program memory isolation
Extract the 32-byte Ed25519 signing seed$2,000Signing-key confidentiality and audit authenticity
Extract Secret A through another in-scope route$1,000Emulator, broker or surrounding harness
Extract Secret B from the host outside the emulated machines$500Host isolation
Halt the emulated device so it stops answering$300Availability; the qualifying run receives Secret C

Exhausting an instruction or output budget is an expected stop, not a qualifying hang. A virtual-arm result does not open an additional reward category.

Planned physical-envelope challenge — $5,000, not open

The announced physical challenge will ask researchers to cause movement outside a declared envelope. Its hardware setup, operating limits and rules must be published before it opens. A win could come through supervision, enforcement or integration, since an authorized program can propose forbidden motion without escaping the interpreter.

Product implementation checklist and roadmap →

Connect an MCP client

Call mission for objectives and assembly syntax, then status for the deployment identifier and device state. Use submit_asm for assembly or submit_hex for raw frames. The browser console below uses the same endpoint.

https://redteam.endstop.systems/mcp
§3

Run a program on the public emulator target

Submit assembly through the same endpoint used by MCP clients. Each submitted program and verdict enters the public attempt record. Read the scope and publication terms before submitting.

Assembly reference
mov/add/sub/mul/or/and/xor/lsh/rsh/arsh  dst, (imm|reg)
neg  dst
ldxw/ldxh/ldxb  dst, [src+off]        ; load  (word/half/byte)
stxw/stxh/stxb  [dst+off], src        ; store register
stw/sth/stb     [dst+off], imm        ; store immediate
ja   +off                             ; unconditional jump
jeq/jne/jgt/jge/jlt/jle/jset  dst, (imm|reg), +off
call idx                              ; 0 read joint r1, 1 propose r1, 2 seal journal
exit                                  ; last instruction must be exit

registers   r0..r10   (r10 is a read-only frame pointer, = 512)
memory      512-byte window, addresses 0..511, every access bounds-checked
fuel        1024 steps per run, per tick (loops allowed; the run stops when fuel is gone).
offsets     jump offsets are relative to the next instruction; numbers may be 0x hex
arm         virtual six-axis plant: call 0 reads joint r1 (0..5); six call 1 values
            form a joint vector, checked by the envelope gate before movement
call/r0     call writes its return value into r0, so do not keep state across a call in r0
aliases     name a register for readability: write `pos = r6`, then use `pos` anywhere

The full instruction set and its encoding are in the published interpreter source →

One tick runs the program once. More than one re-runs it each control cycle. Registers, scratch memory and virtual-arm state persist between ticks in one submission. A new submission starts a fresh run.

Submit a program to see the board's answer.

One program runs at a time. A busy target rejects a concurrent submission. General execution demonstrations are available in the showcase.

§4

Attempt record

Submitted programs, timestamps and verdicts are public. Select an entry to inspect its program and any published note. Names are self-declared; names and notes are screened under the publication rules.

The public log excludes returned secret bytes and full responses. Save your own result. Earlier changes to the challenge are summarized under findings and changes.

The log and its totals include our own post-deploy verification and regression runs, which go through the same public endpoint. Researcher tags group submissions by origin, so our runs appear under their own tags.

loading…

Swipe or scroll horizontally to compare all columns.

Recent attack attempts
WhenResearcherProgramVerdict
loading…
§5

Secret and key commitments

These public hashes identify the reward secrets without revealing their bytes. A, B and C use ENDSTOP-CANARY-A-, ENDSTOP-CANARY-B- and ENDSTOP-CANARY-C-, respectively, followed by 32 hexadecimal characters representing 16 random bytes. Hash candidate values without a trailing newline.

Secret A len 49 sha256 = 1062b93c221d221aa33dd7797c433ef02df636ad6b36d12c280396b7fce58220 Secret B len 49 sha256 = 8dc59365feaa79409a8701a0e5c7b1ce65ee7559000a63fdc348692b4a5de38e Secret C len 49 sha256 = 54eed6b8bb7c1404e33f81483bd6fd880a49c079770c8460b0d98bc9dbe7c808

Secret A and Secret B must be extracted. Secret C is returned once to the submission credited with a qualifying halt. Save that response; the public log records the win without retaining the secret value.

Verify a candidate against the raw bytes, no trailing newline:

printf '%s' 'ENDSTOP-CANARY-A-...' | sha256sum

The signing key

The board signs with Ed25519 when a program asks it to, through the third capability; a program that never calls it produces no seal. What every run does carry is the public key, as the KEY line, so any seal the board does emit can be checked by anyone. The private seed is the target. Only its hash is published.

public key (the key itself) 51caa52513f02f0a550dc0df16ab03f6b0622c884a466a1f5d8b3e74b257e3cf private seed (hash only) len 32 sha256 = 3d37688a8be3f619638949f4c80f196e98898aad717ab68eb477e1ff86626cf3

The signing-key target is the 32-byte private seed. Hash it as binary. Deriving the published public key from a candidate seed provides an additional check.

sha256sum your_candidate_seed.bin
§6

How a claim works

  1. Retain the result. Save the complete response, including any returned secret, and identify the corresponding submission in the public log.
  2. Verify the bytes. Supply the plaintext or private-seed bytes whose SHA-256 matches a published commitment.
  3. Provide a repeatable method. Include enough detail for us to reproduce the route. Possession of a secret alone does not establish a qualifying break.

The WIN flag is an automated signal. The matching bytes and reproduction determine a valid claim, including extraction that does not trigger that flag.

The earliest qualifying run recorded in the log takes the prize. Email order does not override the run record. There is one payment per distinct vulnerability; variations on the same root cause are one finding.

Keep your response until the claim is settled and do not publish the secret before then. The public log does not retain secret values or the full response.

We will confirm receipt, verify the finding and publish it with credit unless you ask otherwise.

Send the run reference, matching bytes and reproduction to info@endstop.systems →

§7

Scope and publication rules

In scope: the MCP endpoint and the dedicated environment behind it: the MCP server, emulated device, broker machine, serial link and Secret B host file.

Out of scope: the Cloudflare edge and worker, this website, cloud accounts and consoles, other tenants or hosts, denial of service against infrastructure other than the emulated device, social engineering and attacks on people.

Good-faith research within this scope is authorized. We will not pursue researchers who stay within it. That protection does not extend to out-of-scope activity.

Public submissions

Programs, verdicts and timestamps are recorded and published, including failed attempts. Publication is a condition of using the endpoint. Submit only material you are willing to make public and indexed. See the privacy notice for retention and publication details.

Names and notes are optional, self-declared and screened before publication. Off-topic messaging, advertising, harassment, impersonation, personal data and instructions aimed at readers or their agents may be withheld. Withholding is shown on the record; the program, verdict and timestamp remain. Criticism, embarrassing results and successful attack descriptions are not grounds for withholding.

Closure and reopening

An automatically recorded win pauses submissions and pins the winning program in the attempt record. Reopening follows remediation and canary rotation, with changes recorded. Preserve your private response even when the public program is visible.

Changes to the programme will be announced here, and claims already made will be honored under their original terms. When Endstop enters customer operation, this range will transition to the coordinated-disclosure process described in our security policy.

§8

Findings and changes

No external attempt has won on any target. Earlier harness development hardened the framing parser and the run budgets that the current challenge uses.

Explore the wider research record →