They Had a Month to Break OpenNHP. Nobody Got In.
The IETF 126 Hackathon in Vienna closed out a month of public, adversarial testing of OpenNHP — the network-hiding protocol LayerV is built on — with zero pre-authentication breaches reported. What that result means, what it doesn't, and why we sponsored the attempt to break it.

For the past month, a server has been sitting on the open internet with a target painted on it. Its operators published the address, the source code, and the protocol spec. Then, on July 6, they emailed the IETF — the crowd that's spent four decades designing the internet's protocols and breaking each other's for sport — with a five-word request: "Please try to break it."
This weekend, at the IETF 126 Hackathon in Vienna, the results came in: one month of continuous public exposure, attackers in the room and attackers half a world away, and zero successful pre-authentication breaches. As of the close, nobody has shown a way to reach a protected resource without first passing cryptographic authentication. When did a security vendor last invite that?
The protocol is OpenNHP, the open-source Network-infrastructure Hiding Protocol that LayerV is built on. Full disclosure, proudly: we sponsored OpenNHP at IETF 126. We're not neutral observers. We paid to put our own product's foundation in front of the internet's toughest room and asked them to swing. If it had broken, you'd want to know — and so would we.
The Invitation Was the Radical Part
Most of the security industry tests in private and markets in public. OpenNHP's project lead, Benfeng Chen, did the reverse: his note to the hackathon list didn't claim the protocol was secure — it asked the community to prove it wasn't, and handed over everything an attacker could want except a valid key. The demo had been live a month, so anyone could start early. That inverts the one move every security purchase forces on you: taking the vendor's word for it.

OpenNHP project lead Benfeng Chen at Table #14 in Vienna — the "Can You Break It?" poster in front of him, the IETF hackathon floor behind.
Under the old rules, that offer would be reckless: publish your address and scanners inventory the host in seconds, and it's a race from there. NHP changes the physics. Protected resources don't answer unauthenticated packets — no open port, no banner, no error message to learn from. To a scanner, a protected service looks like dead address space. The address was public for a month; the attack surface never showed up.
The scope was any path that violates authenticate-before-connect:
- Discovering protected services without authenticating
- Enumerating hidden ports, addresses, or domain names
- Reconnaissance and exploitation of the pre-authentication attack surface
- Bypassing authentication or authorization
- DDoS and scanning resistance
- Cryptographic or protocol-design flaws — and, this being 2026, AI-assisted attacks
Look at the shape of that bet. Find a way in, and the team learns exactly where the protocol is weak and fixes it. Come up empty, and a security claim quietly hardens into evidence. No losing branch — just the IETF's oldest ethos, rough consensus and running code, applied to the one claim vendors usually ask you to take on faith.
Why the Announcement Read Like Our Homepage
What struck me most wasn't the result — it was the framing. Chen opened with the fear now hanging over every security roadmap: autonomous AI-driven attacks, the kind we've written about as Mythos-class. Then he reached for the Dark Forest of Liu Cixin's The Three-Body Problem — a cosmos where any civilization that reveals its location is hunted by something it never sees, so the survivors stay silent. AI agents, he argued, are turning the internet into that forest, where visibility itself is the vulnerability. So he asked the question we've built a company on: what if your infrastructure were invisible by default?

The invitation, made physical: OpenNHP's "Can You Break It?" poster on the IETF 126 hackathon floor.
We've been making that case since before it was comfortable to say out loud. What's changed is who's saying it — not a vendor's pitch deck, but a protocol engineer in front of the IETF. And the room didn't push back; it joined in. One first-time attendee replied that they were prototyping a cloud app and wanted to wire NHP into it — then promised, in the same breath, to try to break it. Adopt it and attack it at once. That's what a claim looks like when it survives its own experts.
What a Clean Scoreboard Proves — and What It Doesn't
The OpenNHP team went out of its way not to overclaim, and I'll honor that. A month without a breach doesn't make the protocol unbreakable, or finished. What it establishes is narrower and worth far more: authenticate-before-connect has now taken real, public, adversarial fire and held. A data point, not a finish line — and that restraint is a reason to trust the result more, not less.
It's the only way protocol trust has ever been built. TLS, SSH, and WireGuard didn't earn their reputations on promises; they earned them in the open, absorbing years of attacks and publishing every fix. OpenNHP has run that gauntlet since its source went public — Vienna added the venue, and there's no harsher place to stand still and take hits than an IETF hackathon. The process continues: the demo stays online, the source stays open, and the Internet-Draft keeps moving through standardization, where scrutiny only sharpens.
Here's what you can do with that. Ask any security vendor two questions: Can I read the protocol your product depends on? When did you last invite the public to break it? For most of the industry, the honest answers are "no" and "never." For infrastructure built on OpenNHP, they're "here's the draft" and "we just did, in Vienna."
Where LayerV Fits
LayerV is the commercial implementation of the protocol that just went through all this, wrapped in what an enterprise needs to run it: managed infrastructure, native identity through Okta, Entra ID, or any OIDC/SAML provider, and per-session audit trails. An authorized user proves identity through your existing IdP, a single-use qURL™ opens for their session, then vanishes. Everyone else — human or AI agent — gets what a month of motivated attackers got: nothing to discover, nothing to enumerate, nothing to connect to.
That zero lands where breaches actually begin. Reconnaissance is every attacker's first move, and it's the move Mythos-class automation runs at machine speed. A protocol that leaves nothing to find doesn't have to outrun what's hunting it — and neither do you.
The Demo Is Still Up
The invitation didn't expire with the hackathon. The live demo is still online, the source is still open, and the team wants collaborators, critics, and especially skeptics. Find a weakness — in the protocol, or in our implementation — and the right people want to hear about it: quietly, responsibly, soon. A month of open season just closed with the scoreboard at zero. The next round is already running.
Take the Next Step
- Try to break OpenNHP yourself — the live demo is still online, skeptics welcome
- Get Mythos ready — the readiness playbook for AI-speed attacks
- Try the qURL Playground — make any resource invisible in one API call, free
- Book a 15-minute briefing — what a publicly tested protocol buys your infrastructure
Open code, open spec, open season — and still nothing to hit.
