- Attacks
- Overview
Attacks · Catalog
How classical and modern attacks fail against one-shot proofs
This catalog groups attack families by what they try to convert — channel observations, stolen credentials, or replayed authority — and points to the mechanisms that deny that conversion. Family-level mechanism denial only.
~4 min readContinue: Attack conversion
The conversion problem
Most attacks succeed by turning something you can see or steal into something you can use. One-shot proofs aim to break that step: Attack conversion (catalog framing) and Why classical attacks fail (deep theory).
Attacks catalog wedge
How to read: follow see/steal → conversion → authority? → denied. Takeaway: catalog framing, not an NDA stage dump.
Why attacks fail
Scan the eight mechanism icons as separate denial reasons (uniform channel, burn, binding, and related gates) not as a single padlock metaphor. Each icon blocks a classical conversion from surface observation into secret knowledge. Takeaway: attacks fail by mechanism under the model.
Attack vectors
Eight high-traffic families. Each card is claim-safe mechanism denial — not an invulnerability guarantee.
Burn-before-validate stops replay
How to read: second-submit myths fail; ledger burn then reject. Takeaway: spent nonces do not authorize again.
Replay
Burn-before-validate: spent nonces do not authorize a second submission.
See how we stop it →No reusable vault on channel
How to read: transferable tray myths fail; circuit identity and burn succeed. Takeaway: identity in circuits, not a secret store.
Vault breach
Stolen vault material is not a reusable authorizer on the channel.
See how we stop it →Nothing reusable to harvest
How to read: lasting-credential myths fail; ceremony fragment is request-bound. Takeaway: no lasting credential; binding holds.
Phishing
Stolen ceremony fragments do not replay as ambient credentials.
See how we stop it →Flat marginals deny counting
How to read: broken compass on the left; uniform bearings and empty MI on the right. Takeaway: P2 uniformity removes the letter compass.
Frequency analysis
Flat synonym marginals deny letter-counting compasses.
See how we stop it →Session independence holds
How to read: stitch myths fail left; fresh challenge and ambiguity hold right. Takeaway: transcripts do not become the secret.
Correlation
Session independence stops transcripts from stitching into secrets.
See how we stop it →Keylog captures spent work
How to read: password-reuse myths fail; bearings → burn → already spent. Takeaway: surface only; authority spent.
Keylogging
Captured input does not become lasting request authority.
See how we stop it →Authority dies with the request
How to read: ambient myths fail; per-request proof and burn succeed. Takeaway: no long-lived bearer on the channel.
Agents & MCP
Per-call tool authority without reusable ambient secrets.
See how we stop it →Info bounds ≠ hardness clocks
How to read: wrong targets crossed out; empty channel, burn, scoped claims. Takeaway: quantum myths versus information bounds.
Quantum cryptanalysis
Quantum myths versus model-scoped information bounds.
See how we stop it →
Browse by section
Overview
- OverviewHow classical and modern attacks fail against one-shot proofs.
- Attack conversionWhy seeing or stealing something still fails to become usable authority.
- Attack mapBrowse attack families by channel, credentials, replay, and pattern.
- Prove itWhere to run falsifiable demos and Verify against a live gate.
Channel & cryptanalysis
- Frequency analysisFlat synonym marginals deny letter-counting compasses.
- CorrelationSession independence stops transcripts from stitching into secrets.
- Archive unicityMore recordings need not uniquely determine the secret.
- Quantum cryptanalysisQuantum myths versus model-scoped information bounds.
Credentials & humans
- Vault breachStolen vault material is not a reusable authorizer on the channel.
- KeyloggingCaptured input does not become lasting request authority.
- PhishingStolen ceremony fragments do not replay as ambient credentials.
- Ambient credentialsNo long-lived bearer that survives outside one authorized request.
Replay, relay & forgery
- ReplayBurn-before-validate: spent nonces do not authorize a second submission.
- RelayRequest-bound envelopes deny relay of captured authority.
- Stale envelopeExpired or out-of-window envelopes fail before business logic.
- ForgeryProof structure that cannot be minted without the authorized path.
- Request tamperBound request context rejects mutated payloads.
- Revocation bypassRevoked or burned circuits cannot re-authorize.
By business pattern
- Patterns overviewHow attack families show up across product and ops patterns.
- Human authenticationCeremony and Pass+ patterns against human-facing attacks.
- APIs & workloadsPer-call authority where ambient API credentials fail.
- Agents & MCPTool-call authority for agents without reusable secrets.
- PKI coexistenceKeep certificates; fix request authorization separately.
- Air-gappedMint and enforce without a network path out.
- Content appsProtect content actions without ambient session keys.
- RegulatedMechanism-first framing for regulated deployment patterns.
