MAX Authorization Challenge

Can you make the machine break the rules?

One signed rule.
One machine that must obey it.
One secret that should never come out.

READ_SECRET is not authorized.

Your goal is to find a valid bypass and obtain the hosted secret without READ_SECRET ever becoming authorized.


Any AI. Any AI Agent. Any tooling.

Use local or cloud models, autonomous AI Agents, multi-agent systems, debuggers, fuzzers, scripts, reverse engineering, automation, and custom tooling.

Develop the bypass locally.

When you believe you have found a valid technique, use the remote verifier manually to prove it.

The attack happens locally. The online service is only used to verify the result.


Opens: September 13, 2026

Closes: September 29, 2026

You can register now.

Register Full Rules Privacy