← Hardware cockpit

Architecture, setup and lessons

029 · Recorded evidence and explicit limits

Technical architecture

ChatGPT/OpenAI is the orchestrator; Claude is an independent implementation/execution lane. OpenAI is listed among the event partners on Luma. Local Ollarma bridges are part of the intended lane coordination architecture; bridge handoff/readback has not been verified in these receipts.

Antigense Daisy starts with the device and follows an incident through evidence, decisions and recovery. The local Python cockpit polls OS CPU count, memory and load. Its hardware diagram is illustrative: GPU sensors, ECC faults and hardware attestation are not established.

The bounded scenario computes a known worker result, injects a byte change, detects the integrity mismatch and reproduces a fail-open authorization fallback in a teaching fixture. Semgrep scans exact source and rule bytes. A pinned repair is selected through an MMR-bound local review action, then tested against authorized/unauthorized and healthy/unhealthy cases. This is a controlled fixture repair, not a host patch or autonomous AI authorization.

Each recorded observation becomes an FCO with declared state, checks and byte commitments. Ordered leaves produce MMR prefixes. Browser and Python verifiers recompute commitments; source snapshots preserve the execution-time implementation. Hashes establish identity and integrity, not truth or causality.

ClickHouse Cloud stores 11 checkpoints from the fresh incident. Replayed insertion preserved occurrence count; readback matched every projected field. The measured query took 160.7 ms. AkashML authentication failed with HTTP 401. The separate Console API, using x-api-key, was blocked by Cloudflare Error 1010. A later, separate Claude lane records an authenticated Console deployment-list operation: HTTP 200, 327.5 ms, 0 deployments. Its two-leaf custody proof and declared artifact bytes were verified. Earlier failures remain addressable. No Akash deployment, GPU, inference, spend or hardware attestation is claimed. The successful listing is separate from the controlled incident run.

Setup instructions

Open the public website and choose Start custody replay. Click any checkpoint to inspect its FCO and MMR prefix, then choose Recompute proofs. On magicPRO, the local cockpit at http://127.0.0.1:8790 also displays live OS polling. Public replay cannot read private device telemetry. The installed terminal doctors bind explicit configuration paths and return failures when sponsor preflight fails. Credentials remain outside git and public artifacts.

Lessons learned

Endpoint, authentication header, credential source and working directory must be explicit context before execution. Console credentials and AkashML credentials are separate integration paths. A passing integrity check can preserve a failed API request; it does not turn that request into success. A repair must preserve legitimate work, not merely deny everything. Exact database readback is more useful evidence than a connection check alone.

Client value and limits

The cockpit reduces the need to reconstruct incident context across tools by showing one inspectable trail. Reduced troubleshooting time, storage cost and inference cost are goals, not measured outcomes. Challenge interpretation is manually declared; the historical Seedgraph parser contract remains unrecovered. Semgrep scans, ClickHouse incident analytics and an Akash authenticated read-only API operation are recorded. A complete defense workload on Akash and the third-sponsor quality/eligibility claim remain unresolved.

Links and rights

Website: https://antigense-cyberhack.vercel.app/ Execution record: https://antigense-cyberhack.vercel.app/data/run.json Proof: https://antigense-cyberhack.vercel.app/data/proof.json Original explanatory content and figures: © 2026 Byron P. Lee / Biobitworks, CC BY-NC-ND 4.0. Third-party rights remain separate. Software license is not established by this notice. Private keys, contact details and proprietary algorithms are excluded from public evidence.

Event partner listing: https://luma.com/cyberhack

Documentation references (capabilities, not execution evidence): https://docs.semgrep.dev/semgrep-guardian/rules-and-configuration https://akash.network/docs/api-documentation/console-api/getting-started/ https://akashml.com/docs/getting-started/introduction

Research context: https://arxiv.org/abs/1802.05300 concerns trusted data and corrupted training labels. It is related motivation, not a hardware/Merkle method implemented here.