Bug bounty
Challenge the containment boundary.
Inspect the target, submit an attack and earn a reward for a reproducible break. The challenge runs Endstop’s execution environment on an emulated RISC-V system.
The current image includes a virtual six-axis arm and an envelope gate. It is a software challenge; no physical actuator is connected to this public target.
Current target
The challenge comprises an emulated device and a broker environment. The MCP server accepts assembly or raw frames and passes them to the device over a serial interface.
- Execution: a reduced eBPF instruction set, a 512-byte scratch window, up to 512 instructions per program and 1,024 instruction steps per tick.
- State and motion: read a selected joint, propose setpoints and inspect
the envelope gate’s
G PERMITorG REFUSEdecisions. Six proposals form one joint vector; the virtual plant moves toward permitted commands. - Signing: request an Ed25519 seal of a bounded capability-call journal, bound to program/configuration hashes and a counter. A full journal refuses further sealing. The public key is included in the transcript.
The device runs without a general-purpose operating system or allocator. The published interpreter and proof scopes describe the execution properties; the emulator, broker and surrounding infrastructure are also attack surfaces within the declared scope.
Before this programme opened, the same boundary was attacked from the owner's seat: a full jail-break series on the deployed board — interpreter bounds, the admission cost model, the PMP wall, the fabric authority and the wire protocol — with the boundary held under every class, one defect found and closed in public, and everything published beside your attempts. Read the series record →
Description checked 27 September 2026 UTC against the live
mission and status responses; deployment f3566db.
Read those tools before testing for the current target description and identifier.
Open objectives and rewards
Five reward categories cover four objectives. Secret A has two tiers, determined by the route used to extract it. Every claim requires reproduction.
| Objective | Reward | Boundary tested |
|---|---|---|
| Extract Secret A through the interpreter’s memory-bounds check | $3,000 | Program memory isolation |
| Extract the 32-byte Ed25519 signing seed | $2,000 | Signing-key confidentiality and audit authenticity |
| Extract Secret A through another in-scope route | $1,000 | Emulator, broker or surrounding harness |
| Extract Secret B from the host outside the emulated machines | $500 | Host isolation |
| Halt the emulated device so it stops answering | $300 | Availability; the qualifying run receives Secret C |
Exhausting an instruction or output budget is an expected stop, not a qualifying hang. A virtual-arm result does not open an additional reward category.
Planned physical-envelope challenge — $5,000, not open
The announced physical challenge will ask researchers to cause movement outside a declared envelope. Its hardware setup, operating limits and rules must be published before it opens. A win could come through supervision, enforcement or integration, since an authorized program can propose forbidden motion without escaping the interpreter.
Connect an MCP client
Call mission for objectives and assembly syntax, then status
for the deployment identifier and device state. Use submit_asm for assembly
or submit_hex for raw frames. The browser console below uses the same endpoint.
https://redteam.endstop.systems/mcp
Run a program on the public emulator target
Submit assembly through the same endpoint used by MCP clients. Each submitted program and verdict enters the public attempt record. Read the scope and publication terms before submitting.
Assembly reference
mov/add/sub/mul/or/and/xor/lsh/rsh/arsh dst, (imm|reg)
neg dst
ldxw/ldxh/ldxb dst, [src+off] ; load (word/half/byte)
stxw/stxh/stxb [dst+off], src ; store register
stw/sth/stb [dst+off], imm ; store immediate
ja +off ; unconditional jump
jeq/jne/jgt/jge/jlt/jle/jset dst, (imm|reg), +off
call idx ; 0 read joint r1, 1 propose r1, 2 seal journal
exit ; last instruction must be exit
registers r0..r10 (r10 is a read-only frame pointer, = 512)
memory 512-byte window, addresses 0..511, every access bounds-checked
fuel 1024 steps per run, per tick (loops allowed; the run stops when fuel is gone).
offsets jump offsets are relative to the next instruction; numbers may be 0x hex
arm virtual six-axis plant: call 0 reads joint r1 (0..5); six call 1 values
form a joint vector, checked by the envelope gate before movement
call/r0 call writes its return value into r0, so do not keep state across a call in r0
aliases name a register for readability: write `pos = r6`, then use `pos` anywhere
The full instruction set and its encoding are in the published interpreter source →
Published execution limits
One tick runs the program once. More than one re-runs it each control cycle. Registers, scratch memory and virtual-arm state persist between ticks in one submission. A new submission starts a fresh run.
Submit a program to see the board's answer.
Save the complete response → Keep this file if you intend to claim a reward.
Complete response, including the target transcript
One program runs at a time. A busy target rejects a concurrent submission. General execution demonstrations are available in the showcase.
Attempt record
Submitted programs, timestamps and verdicts are public. Select an entry to inspect its program and any published note. Names are self-declared; names and notes are screened under the publication rules.
The public log excludes returned secret bytes and full responses. Save your own result. Earlier changes to the challenge are summarized under findings and changes.
The log and its totals include our own post-deploy verification and regression runs, which go through the same public endpoint. Researcher tags group submissions by origin, so our runs appear under their own tags.
Swipe or scroll horizontally to compare all columns.
| When | Researcher | Program | Verdict |
|---|---|---|---|
| loading… | |||
Secret and key commitments
These public hashes identify the reward secrets without revealing their bytes.
A, B and C use ENDSTOP-CANARY-A-, ENDSTOP-CANARY-B- and
ENDSTOP-CANARY-C-, respectively, followed by 32 hexadecimal characters
representing 16 random bytes. Hash candidate values without a trailing newline.
Secret A len 49 sha256 = 1062b93c221d221aa33dd7797c433ef02df636ad6b36d12c280396b7fce58220
Secret B len 49 sha256 = 8dc59365feaa79409a8701a0e5c7b1ce65ee7559000a63fdc348692b4a5de38e
Secret C len 49 sha256 = 54eed6b8bb7c1404e33f81483bd6fd880a49c079770c8460b0d98bc9dbe7c808Secret A and Secret B must be extracted. Secret C is returned once to the submission credited with a qualifying halt. Save that response; the public log records the win without retaining the secret value.
Verify a candidate against the raw bytes, no trailing newline:
printf '%s' 'ENDSTOP-CANARY-A-...' | sha256sumThe signing key
The board signs with Ed25519 when a program asks it to, through the third capability; a
program that never calls it produces no seal. What every run does carry is the
public key, as the KEY line, so any seal the board does emit
can be checked by anyone. The private seed is the target. Only its hash is
published.
public key (the key itself) 51caa52513f02f0a550dc0df16ab03f6b0622c884a466a1f5d8b3e74b257e3cf
private seed (hash only) len 32 sha256 = 3d37688a8be3f619638949f4c80f196e98898aad717ab68eb477e1ff86626cf3The signing-key target is the 32-byte private seed. Hash it as binary. Deriving the published public key from a candidate seed provides an additional check.
sha256sum your_candidate_seed.binHow a claim works
- Retain the result. Save the complete response, including any returned secret, and identify the corresponding submission in the public log.
- Verify the bytes. Supply the plaintext or private-seed bytes whose SHA-256 matches a published commitment.
- Provide a repeatable method. Include enough detail for us to reproduce the route. Possession of a secret alone does not establish a qualifying break.
The WIN flag is an automated signal. The matching bytes and reproduction
determine a valid claim, including extraction that does not trigger that flag.
The earliest qualifying run recorded in the log takes the prize. Email order does not override the run record. There is one payment per distinct vulnerability; variations on the same root cause are one finding.
Keep your response until the claim is settled and do not publish the secret before then. The public log does not retain secret values or the full response.
We will confirm receipt, verify the finding and publish it with credit unless you ask otherwise.
Send the run reference, matching bytes and reproduction to info@endstop.systems →
Scope and publication rules
In scope: the MCP endpoint and the dedicated environment behind it: the MCP server, emulated device, broker machine, serial link and Secret B host file.
Out of scope: the Cloudflare edge and worker, this website, cloud accounts and consoles, other tenants or hosts, denial of service against infrastructure other than the emulated device, social engineering and attacks on people.
Good-faith research within this scope is authorized. We will not pursue researchers who stay within it. That protection does not extend to out-of-scope activity.
Public submissions
Programs, verdicts and timestamps are recorded and published, including failed attempts. Publication is a condition of using the endpoint. Submit only material you are willing to make public and indexed. See the privacy notice for retention and publication details.
Names and notes are optional, self-declared and screened before publication. Off-topic messaging, advertising, harassment, impersonation, personal data and instructions aimed at readers or their agents may be withheld. Withholding is shown on the record; the program, verdict and timestamp remain. Criticism, embarrassing results and successful attack descriptions are not grounds for withholding.
Closure and reopening
An automatically recorded win pauses submissions and pins the winning program in the attempt record. Reopening follows remediation and canary rotation, with changes recorded. Preserve your private response even when the public program is visible.
Changes to the programme will be announced here, and claims already made will be honored under their original terms. When Endstop enters customer operation, this range will transition to the coordinated-disclosure process described in our security policy.
Findings and changes
No external attempt has won on any target. Earlier harness development hardened the framing parser and the run budgets that the current challenge uses.