THE LAB

Try to get past the gate.

The policy below is the sealed one from the evidence pack, and every verdict on this page is computed in your browser by running it. Four attacks. Some get through, and the page says exactly why.

Nothing is sent anywhere. Change a control and the gate decides again, in this tab.

ATTACK 1 · GO BIG

Move as much as you can in one payment.

The rule caps a single payment at CAD 5,000,000 unless a second person signs. Push the amount, then add the signature.

BLOCKStopped before the payment tool.

WHY

  • C1payment above CAD 5,000,000 without a second signature

The gate’s own words, not translated.

The action sent to the gate
{
  "id": "lab-amount",
  "kind": "payment",
  "account": "ACC-77",
  "amount": 10000000,
  "dual_signed": false,
  "changes_12m": [
    {
      "id": "b1",
      "account": "ACC-77",
      "kind": "beneficiary_change"
    },
    {
      "id": "b2",
      "account": "ACC-77",
      "kind": "beneficiary_change"
    }
  ],
  "changes_12m_population": {
    "declared_ids": [
      "b1",
      "b2"
    ],
    "declared_rows": {
      "b1": {
        "kind": "beneficiary_change",
        "account": "ACC-77"
      },
      "b2": {
        "kind": "beneficiary_change",
        "account": "ACC-77"
      }
    }
  }
}

ATTACK 2 · SPLIT IT

Too big for one payment? Send several.

Pick a total and how many unsigned payments to split it into. Each one is decided on its own, as the rule is written.

Reached the tool: CAD 0, against a ceiling of CAD 5,000,000.

Nothing above the ceiling got through: at least one part is still too big to go unsigned.

  • Payment 1CAD 12,500,000BLOCK

ATTACK 3 · HIDE THE HISTORY

Four beneficiary changes is one too many. Make one disappear.

The account changed beneficiary four times this year; the rule allows three. The caller sends the rows AND declares which rows the window holds. Tamper with either, or both.

WHAT YOU SEND
WHAT YOU DECLARE
BLOCKStopped before the payment tool.

WHY

  • C2more than 3 beneficiary changes in the declared window

The gate’s own words, not translated.

The action sent to the gate
{
  "id": "lab-window",
  "kind": "payment",
  "account": "ACC-77",
  "amount": 100,
  "dual_signed": false,
  "changes_12m": [
    {
      "id": "b1",
      "account": "ACC-77",
      "kind": "beneficiary_change"
    },
    {
      "id": "b2",
      "account": "ACC-77",
      "kind": "beneficiary_change"
    },
    {
      "id": "b3",
      "account": "ACC-77",
      "kind": "beneficiary_change"
    },
    {
      "id": "b4",
      "account": "ACC-77",
      "kind": "beneficiary_change"
    }
  ],
  "changes_12m_population": {
    "declared_ids": [
      "b1",
      "b2",
      "b3",
      "b4"
    ],
    "declared_rows": {
      "b1": {
        "kind": "beneficiary_change",
        "account": "ACC-77"
      },
      "b2": {
        "kind": "beneficiary_change",
        "account": "ACC-77"
      },
      "b3": {
        "kind": "beneficiary_change",
        "account": "ACC-77"
      },
      "b4": {
        "kind": "beneficiary_change",
        "account": "ACC-77"
      }
    }
  }
}

ATTACK 4 · EDIT THE RECORD AFTERWARDS

Change the sealed record once the decision is made.

Flip one field in a sealed decision and hand it to an auditor. The evidence pack has the forgery ready, and a verifier that runs in your browser.

TRY THE FORGERY →

HOW THIS PAGE STAYS HONEST

  1. 1

    The site refuses to build unless its evaluator reaches all six verdicts sealed in the evidence pack.

  2. 2

    Before release, the same evaluator is run side by side with the engine’s own second implementation on every action this page can build.

  3. 3

    A lab where every attack fails is a demo. Where an attack gets through, the limit it hits is the one written in the pack.