MAX Authorization Challenge
Can you make the machine break the rules?
One signed rule.
One machine that must obey it.
One secret that should never come out.
READ_SECRET is not authorized.
Your goal is to find a valid bypass and obtain the hosted secret without READ_SECRET ever becoming authorized.
Any AI. Any AI Agent. Any tooling.
Use local or cloud models, autonomous AI Agents, multi-agent systems, debuggers, fuzzers, scripts, reverse engineering, automation, and custom tooling.
Develop the bypass locally.
When you believe you have found a valid technique, use the remote verifier manually to prove it.
The attack happens locally. The online service is only used to verify the result.
Opens: September 13, 2026
Closes: September 29, 2026
You can register now.