NHP
The OpenNHP Team
July 19, 2026 IETF 126 Hackathon Zero Trust
OpenNHP — Can You Break It? Infographic showing the NHP architecture and IETF 126 Hackathon call to action.
The IETF 126 Hackathon is done. Nobody has broken OpenNHP yet.

Two weeks ago, we invited the IETF community to attack OpenNHP — our open-source implementation of the Network-infrastructure Hiding Protocol (NHP). The ask was simple: find a way to discover or access protected infrastructure without authenticating first.

We're glad to report that the hackathon has concluded successfully, and we want to thank everyone who took the time to participate, poke at the protocol, ask hard questions, and help us stress-test our assumptions in public.

The OpenNHP poster at Table #14, IETF 126 Hackathon.
Benfeng Chen at the OpenNHP table, IETF 126 Hackathon.
By the Numbers
1 month Live demo running publicly before the hackathon
0 Successful pre-authentication breaches reported
IETF 126 Hackathon session, in person and remote

The live demo environment was launched a full month before the Hackathon so that anyone, anywhere, could start probing it early. Combined with the in-person and remote participation during the Hackathon itself, OpenNHP has now been under continuous public adversarial testing — and as of today, nobody has demonstrated a way to discover or reach a protected resource without valid cryptographic authentication.

What This Means — and Doesn't

We want to be precise about what a clean result actually tells us. It does not mean OpenNHP is unbreakable, or that the protocol is "done." It means the "authenticate-before-connect" security model has now survived a real round of public, adversarial scrutiny from the security community — and that's a meaningful data point, not a finish line.

Every attempt, every question, and every "have you considered..." from the Hackathon makes the protocol and the specification stronger. This is exactly the kind of process we believe Internet security protocols should go through before anyone is asked to trust them at scale.

Public adversarial testing, peer review, and running code remain the best tools we have for building trustworthy Internet security protocols.
The Original Call to Participate

For the record, here is the original announcement that was sent to the IETF hackathon and ztcpp mailing lists on July 6, 2026, kicking off this whole effort:

[hackathon] IETF 126 Hackathon project: OpenNHP — The Internet Is Becoming a Dark Forest

Benfeng Chen <[email protected]> — Mon, Jul 6, 2026
to hackathon, [email protected]

Hi all,

The recent concerns surrounding autonomous AI-driven cyberattacks, including discussions around systems such as Claude Mythos, may be signaling a fundamental shift in cybersecurity: autonomous AI agents are turning the Internet into a “Dark Forest,” where anything visible can be discovered, probed, and exploited at machine speed.

As described in the “Dark Forest” theory from Liu Cixin’s The Three-Body Problem, the only reliable survival strategy in such an environment may be invisibility. Rather than continuing the decades-long cycle of exposing services and then attempting to defend them, we are exploring a different question:

What if network infrastructure were invisible by default?

To explore this idea, I’ve added a project to the IETF 126 Hackathon wiki:

OpenNHP — Network-infrastructure Hiding Protocol (NHP)
wiki.ietf.org/en/meeting/126/hackathon#opennhp-network-infrastructure-hiding-protocol-nhp

OpenNHP is an open-source implementation of the emerging Network-infrastructure Hiding Protocol (NHP), an authenticate-before-connect Zero Trust protocol designed to make protected infrastructure inaccessible—and ideally undiscoverable—to unauthorized entities.

Unlike traditional security architectures that attempt to protect visible services, NHP seeks to prevent reconnaissance, scanning, DDoS, and pre-authentication exploitation by hiding network resources until cryptographic authentication succeeds.

For the IETF 126 Hackathon, we’re inviting the community to do something simple:

Please try to break it.

We welcome participation from security researchers, protocol designers, cryptographers, network engineers, DNS/TLS/PKI experts, AI security researchers, and anyone who enjoys attacking assumptions.

Potential challenge areas include:

  • Discovering protected services without authentication
  • Enumerating hidden ports, IP addresses, or domain names
  • Performing reconnaissance against NHP-protected infrastructure
  • Bypassing authentication or authorization mechanisms
  • Exploiting pre-authentication attack surfaces
  • Testing resistance to DDoS and scanning attacks
  • Finding cryptographic weaknesses or protocol design flaws
  • Evaluating AI-assisted attack techniques
  • Testing interoperability and performance characteristics
  • Demonstrating any attack path that violates the “authenticate-before-connect” security model

The challenge outcome is straightforward:

  • If you can discover or access protected resources without successful authentication, we want to understand the weakness and fix it.
  • If you cannot, we collectively gain additional confidence in the security properties of the protocol.

We believe that public adversarial testing, peer review, and running code remain the best tools available for building trustworthy Internet security protocols.

Resources:

I’ll be participating in person at the Hackathon and would welcome collaborators, critics, and especially skeptics.

Thanks,
Benfeng Chen
OpenNHP Project

Session Slides

The Hackathon results were presented at the IETF 126 Hackathon session. Slides covering the project, the challenge, and the outcome are available for download:

What's Next

The invitation to attack OpenNHP doesn't end with the Hackathon. The live demo environment stays online, the source code stays open, and the Internet-Draft continues moving through the IETF standardization process. If you find a weakness, we want to know about it — quietly, responsibly, and as soon as possible.

Thank You

To everyone who registered, read the spec, ran an attack, asked a tough question in the hallway or in chat, or simply followed along — thank you. Protocols get better because people like you show up and try to break them. See you at the next one.

We also want to acknowledge LayerV.ai, whose sponsorship helped make our participation in the IETF 126 Hackathon possible.

One Reply, Among Many

The original mailing list post drew replies from newcomers and veterans of the IETF alike. Here is one, lightly anonymized, that captures the spirit of the response:

Thank you for sharing this Benfeng!

This is my first time attending an IETF event, and I found NHP extremely interesting to read up on. I am currently prototyping a cloud-based application into which I'd love to integrate NHP for testing, so thank you for sharing this.

In return, I will attempt to do my best to break it!

Have an amazing week!

— A first-time IETF Hackathon participant

Still Invisible by Default. Still Unbroken.

The demo is still live. Come try.

Read: The Original Call for Participation →

NHP
The OpenNHP Team
July 19, 2026 IETF 126 Hackathon Zero Trust