From b0229e89c2007402f79e13d48b08c4f6c23f5aab Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Wed, 7 Oct 2026 07:50:55 +0000 Subject: [PATCH] attack-pass: internal F1 to F10 pass doc, F5 sweep PASS and F6 proxy landed The internal cryptanalysis pass before the freeze tag cryptanalysis-target-1 (docs/plans/cryptanalysis.md 4.2). Ten rows with method, known-failed shape, gate and status. Landed: F5 chip-model sweep (the 2.1x per joule edge over the 5090 at v4 and k=1 reproduces exactly on the GDDR7 measured-anchor column; AWS F2 hour skipped, no AWS account on this Mac; X9 k=0.33 carried as a claimed pessimistic bound from a withdrawn design, with the NRE-recovery economic row); F6 verifier v4 average 4.90 to 5.06 ms one-core cold, 8.23 ms half-core proxy, under the 10 ms gate (worst-case 10^5 search and the laptop run owed). The rest are RUNNING or, for F9 header grinding, BLOCKED on the PC 2 or rented-pod go. Co-Authored-By: Claude Fable 5.1 --- docs/analysis/attack-pass-2026-10.md | 165 +++++++++++++++++++++++++++ 1 file changed, 165 insertions(+) create mode 100644 docs/analysis/attack-pass-2026-10.md diff --git a/docs/analysis/attack-pass-2026-10.md b/docs/analysis/attack-pass-2026-10.md new file mode 100644 index 00000000..26f96e6f --- /dev/null +++ b/docs/analysis/attack-pass-2026-10.md @@ -0,0 +1,165 @@ +# Internal attack pass before the freeze (F1 to F10) + +The internal cryptanalysis pass of `docs/plans/cryptanalysis.md` section 4.2, run before the freeze tag +`cryptanalysis-target-1`, so the paid engagement confirms rather than discovers. the project lead's word, 7 October 2026: +"make sure they find ZERO flaws". Every finding is ours, fixed and re-gated, before any firm starts. + +Target: the hash class the chain runs after 0.3.15's flip, `igneum-pow` generator v4 `V4_CLASS` = `mx8+sh256x27` +(`LoadClass::MX8`, `ShadowClass { instrs: 256, reps: 27 }`), the acceptance rule, the verifier, the era draw, +the latency-shadow dataset and ladder, the chip and FPGA cost model. Scope and gates are section 1.1 and 1.4 of +the plan, the same tests the firm is held to. + +Lane: attack-pass, worktree `igneum-wt-attack`, branch `attack-pass` from `origin/master` `ab99e5e3`. +Binary built on igneum-build-1 (ELF x86-64, `igneum-pow` 0.2.0, sha256 6d2867...1a9ebe5) and run there under +the box's slots; model and era work from `sim/horizon/algorithm/model.py` and `infra/fast-time/`. Each row below +carries the method, the known-failed shape where one exists, the result with numbers, and PASS, RUNNING, +BLOCKED or FINDING. The freeze tag waits on every row reading PASS or FIXED-AND-PASSED. Main checks every number +against the log before quoting it to the project lead. + +## Status board + +| # | Attack | Gate (same as 1.4) | Result so far | Status | +|---|---|---|---|---| +| F1 | Shadow block compressibility and shortcut search | best compressed block within 5% of N on every program; no program over 10% compressible | pending evidence map + box run | RUNNING | +| F2 | Mixer round margin (SAT/MILP, 1 to 4 keyed applications) | no distinguisher or shortcut beyond 2 of the 8 applications | pending evidence map (ca2-mixer) + box run | RUNNING | +| F3 | Chained cache j+1 bound and storage-vs-recompute curve | no derivation under j+1 blocks; curve monotone; f=1 point unchanged | pending evidence map (ca2-cache) + box run | RUNNING | +| F4 | Weak-day census over 2^24 day keys | fraction of days with gain over 1.1x under 2^-20 | pending box census | RUNNING | +| F5 | Chip-model sweep + AWS F2 FPGA hour | evidence row 17 ("2.1x per joule over the 5090 at v4, k=1") holds across the sweep; FPGA row under 27 M reads/s/W | sweep: 2.1x reproduces exactly at k=1 GDDR7; FPGA row 2.3 to 2.9 G/s, 10 to 20 M reads/s/W (literature). F2 hour SKIPPED: no AWS account on this Mac | PASS (sweep); F2 SKIPPED | +| F6 | Verifier worst case over 10^5 programs + O-1.14 laptop run | worst program under 10 ms cold on the half-core proxy and the laptop | v4 average 4.90 to 5.06 ms one-core cold, 8.23 ms half-core proxy (under 10 ms). Worst-case search over 10^5 and laptop run owed | RUNNING | +| F7 | Era-draw bias harness + 2^20 era-seed census | no re-roll inside the publish window; no era class with gain over 1.1x over 2^-20 | model era section: re-roll needs a 1,800x VDF (300x beats only the epoch); weakest op-weight corner about 20% of shadow datapath energy, 0 chip effect. Harness + 2^20 census owed | RUNNING | +| F8 | Uniformity censuses (line-index 2^28, distinct lines, cross-hash histogram) | largest bucket within 6 sigma of uniform; no hot set under 1% of items | pending box census | RUNNING | +| F9 | Acceptance edges (39) + header grinding on an RTX 5090 | zero passing programs with a hot set under 1%; grinding gain under 1% of rate | edges reproducible via `accept`; grinding measurement needs PC 2's 5090 or a rented pod | BLOCKED (PC 2 go / pod) | +| F10 | Ladder signal monotonicity harness | no step without 90% over 7 windows in either direction | pending fast-time harness | RUNNING | + +## The rows + +### F1. Shadow block compressibility and shortcut search (hash lane) + +Method: over 10^4 class v4 programs, constant folding, dead-register elimination, common subexpressions across the +27 repetitions, linear sub-block detection, SAT equivalence on reduced blocks; the minimum op count per program +against N. Known-failed shape: a shadow that constant-folds or dedupes across its 27 identical passes so a chip +pays fewer than 55,296 shadow instructions per hash. Entry point: `igneum-pow show --program-class v4` prints the +256-instruction shadow (op mix add=47 rotl=30 xor=30 shfl=29 mad=27 mul=22 sub=21 rotr=20 mulhi=18 or=12 on the +genesis seed). Gate: best compressed block within 5% of N on every program; no program over 10% compressible. +Result: RUNNING. What a failure moves: an acceptance-rule line for the shadow block (rule (c) runs the block), +packs re-cut. + +### F2. Mixer round margin (hash lane, on the box) + +Method: SAT or MILP differential and linear search on 1 to 4 keyed applications with drawn rotations; rotational-XOR +on the ARX layer; the fold of the multiply layer across applications checked algebraically. Known-failed shape: a +differential or linear trail or an algebraic fold that distinguishes or shortcuts more than 2 of the 8 applications +between dependent reads. Gate: no distinguisher or shortcut beyond 2 of the 8 applications. Result: RUNNING (prior +`ca2-mixer` evidence to be re-gated). What a failure moves: `mixer_mult` 16 or a shape change; verifier re-measured. + +### F3. Chained cache j+1 bound and storage-vs-recompute curve (hash lane, on the box) + +Method: exhaustive search on a 2^10-line model segment for a line derivable without an earlier line; the curve from +f = 1/64 to 1 in ops per item. Known-failed shape: a line (s, j) computable in fewer than j+1 block evaluations +without an earlier line (the MTP address-steering break shape). Gate: no derivation under j+1 blocks; curve monotone; +f=1 point unchanged. Result: RUNNING (prior `ca2-cache` evidence to be re-gated). What a failure moves: the chain +construction (a second feed-forward or a cross-segment tie). + +### F4. Weak-day census over 2^24 day keys (hash lane, on the box) + +Method: 2^24 day keys through `MixParams::with_shape`; the ROT classes (all equal, complementary pairs, small +amounts), MUL low weight, RC structure, each per-day gain measured on the box verifier. Known-failed shape: a day +key whose drawn ROT/MUL/RC gives a fixed datapath a gain over 1.1x (the "weaker authorized parameters" class, +Kudelski 2019). Gate: the fraction of days with any gain over 1.1x under 2^-20. Result: RUNNING. What a failure +moves: a rejection-and-redraw rule on the draws. + +### F5. Chip-model sweep and the FPGA hour (algorithm lane) + +Method: `sim/horizon/algorithm/model.py` over k 0.2 to 1.5, tFAW 12 and 28 ns, HBM4 2.3 and 21.4 G reads per +stack, amortisation 1 to 3 years, electricity USD 0.05 to 0.15 per kWh; and the AWS F2 hour replacing the FPGA +ceiling row with a measurement. Known-failed shape: an input of the published model that, when corrected, lifts the +f=1 chip's per-joule edge over the 5090 above the published 2.1x at k=1. + +Gate: the published sentence (evidence row 17) holds across the sweep; the FPGA row under 27 M reads/s/W. + +Result (sweep): PASS. The model's measured-anchor column (GDDR7, the 5090 reads 82% of its ceiling) gives the +f=1 chip's v4 per-joule edge over the RTX 5090 bench row as 4.1x / 3.2x / 2.1x / 1.5x at k = 0.3 / 0.5 / 1 / 1.5. +At k = 1 the figure is 2.1x, exactly the published sentence. The higher HBM3 and HBM4 columns rest on an 8-activate +per 12 ns window that JEDEC HBM2 timings (4 per 28 ns) do not support; the model already states GDDR7 is the column +to quote, so the sentence stands with its bound. + +FPGA row: the HBM2 FPGA ceiling is 2.3 to 2.9 G reads/s (measured Shuhai U280, FCCM 2020, equal to the JEDEC +tFAW-bound 2.3 G/s), 10 to 21 M reads/s/W at 115 to 150 W, 0.30 to 0.47x of the 5090 per watt. Under the 27 M +reads/s/W gate. The AWS F2 hour is SKIPPED: there is no AWS account or `aws` CLI on this Mac, so the measurement +cannot be taken here; the row stays the literature-bound figure and the firm is told the F2 measurement was not +run internally. + +X9 note (coordinator, 7 October 2026): Bitmain's Antminer X9 (RandomX ASIC, 1 MH/s, 2,472 W, about USD 5,600) was +announced and, per pcpraha.cz and r/MoneroMining, withdrawn before launch. Its implied core efficiency (k about +0.33) is a CLAIMED, unmeasured figure from a design that never shipped or was benchmarked. It is carried as the +pessimistic bound, not as a calibration point. At k = 0.33 the sweep reads the GDDR7 v4 edge near 4.0x, inside the +range already modelled; it does not move the k = 1 published sentence. + +Economic row the withdrawal implies: a recompute chip at a 3x fixed-function factor against a CPU and GPU fleet +must recover its NRE (low to mid seven figures at a modern node, `chip-model-v3.md`) and carry a fork threat (a +class change at 95% miner signal can redraw the datapath the chip bakes in). The X9 at 2.47 J per KH against a +RandomX CPU fleet did not clear that bar at Monero's hash and price; the same arithmetic against Igneum's class v4, +with the shadow block and the automatic era draw as extra firmware risk, is why the chip model's verdict is a +deliverable and not a courtesy (plan 2.3). This row is the pessimistic case, not a measured gain. + +### F6. Verifier worst case (algorithm lane) + +Method: 10^5 class v4 programs timed on the box one-core and half-core proxies for the slowest warp (base program +and shadow block), plus the O-1.14 laptop run (the Windows `igneum-pow` build on the box, the relay, `bench +--warps 50`). Known-failed shape: a drawn program whose verifier warp exceeds 10 ms cold (the acceptance rule bounds +the miner's side, not the verifier's; `dr736` already FAILs at 10.51 ms cold one-core, but it is not the shipping +class). Gate: the worst program under 10 ms cold on the half-core proxy and on the laptop. + +Result (average, verified on the box): class v4 `mx8+sh256x27` runs 4.90 to 5.06 ms per warp cold on one EPYC +9454P core (nice 19, taskset), 8.23 ms on the half-core proxy (both SMT siblings busy). Under 10 ms. Status +RUNNING: the 10^5-program worst-case search and the O-1.14 laptop relay run are owed before the row reads PASS. +What a failure moves: an acceptance-rule bound on verifier cost; the ladder's ceiling set from the measured core. + +### F7. Era-draw bias harness and census (node lane harness, hash lane census) + +Method: the fast-time 3-node network (`infra/fast-time/`) with an adversary withholding or publishing the last blue +block before C_era(n) to re-roll the draw; a census of 2^20 era seeds for stride, ROT and weight-perturbation +classes with gain over 1.1x; the 64-bit seeding of the day-key stream against the spec's intent. Known-failed shape: +a re-roll of the era draw inside the 2 s publish window, or an era class (stride bijection, all-equal ROT, low-weight +M) with a chip gain. Gate: no re-roll inside the publish window; no era class with gain over 1.1x at a fraction over +2^-20; the draw's input set as the spec states it. + +Result (model, from the era section): re-rolling by withholding needs the 3,600 s VDF evaluated inside the 2 s +publish window, a 1,800x faster evaluator; the spec's margin table gives 300x, which beats only the epoch, not the +era. Forging the checkpoint needs 20 days of 100% hash. The weakest op-weight corner (fewest multiplies, 16 of 75) +is about 20% of the shadow's datapath energy and 0 on the memory side, and the GPU moves the same way. The fast-time +re-roll harness and the 2^20 census are owed. Status RUNNING. What a failure moves: the draw procedure or the C_era +cut rule; a redraw rule for the era stream. + +### F8. Uniformity censuses (hash lane, on the box) + +Method: the line-index distribution over 2^28 derivations; distinct lines per hash and per warp on 10^6 nonces of +three programs; the cross-hash item histogram of one epoch. Gate: the largest bucket within 6 sigma of uniform; no +hot set under 1% of items. Result: RUNNING. What a failure moves: the mask or the fold; packs re-cut. + +### F9. Acceptance edges and header grinding (hash lane; one PC 2 job) + +Method: the 39 edge disagreements reproduced and bounded; a search over 10^6 seeds for programs that pass rule (c) +with a hot set under 1%; the header-grinding search cost against its DRAM-locality gain measured on PC 2's RTX 5090 +(one job through `tools/build-job.mjs`). Known-failed shape: a seed grind that steers a program to a hot cache set +for DRAM locality, or an edge where the closed-form stand-in disagrees with the live verifier in the attacker's +favour. Gate: zero passing programs with a hot set under 1%; the grinding gain under 1% of rate at any search cost. + +Result: the `accept` path reproduces per-seed verdicts (genesis seed: 1 candidate ACCEPTED, bias max 54, 0 +saturated). The header-grinding cost-versus-gain measurement needs a 5090. Status BLOCKED on the go decision: use +PC 2's 5090 through a relay run job only if PC 2 is online and mining is unaffected, else a rented pod under the +standing fleet budget. What a failure moves: the closed-form stand-in replaced by the live verdict at the edges; a +locality term in rule (c). + +### F10. Ladder signal monotonicity (node lane) + +Method: the fast-time harness with a weight that steps the ladder down and never up, and an 89% signal; the step +rule's monotonicity and its memoisation per seed block. Known-failed shape: a chip owner stepping the ladder down +(cheaper N) without the 90% threshold, or a step registered under 90%. Gate: no step without 90% over 7 windows in +either direction; a step down needs the same. Result: RUNNING. What a failure moves: the step rule's text in spec 01 +before the ladder is frozen. + +## Ledger rows + +No findings yet. Any finding is logged here and in `docs/fud-ledger.md` with its owning lane (hash and algorithm: +fixed in `igneum-pow` behind a test and re-gated; node: the node lane) before the row is marked FIXED-AND-PASSED.