NHP
The OpenNHP Team
September 30, 2026 IETF 127 Hackathon Zero Trust
OpenNHP — Can You Break It? Infographic showing the NHP architecture and the hackathon call to action.
Nobody broke it at IETF 126. We're coming back and asking again.

At IETF 126, after a month of public testing and a full hackathon weekend, no participant demonstrated a way to discover or reach an NHP-protected resource without valid cryptographic authentication. Two independent teams published their work:

  • Darkmoon, an autonomous AI penetration-testing platform from France, ran a full evaluation against the demo and recorded zero findings on the protected hosts.
  • DugganUSA, a threat-intelligence firm from the USA, ran passive reconnaissance during the hackathon — Certificate Transparency, DNS, and Shodan. They found the Access Controller IPs, but no open ports on any of them. They also rightly flagged that CT and DNS still reveal the demo's component topology, and that exposed support hosts are the softer edge.

Clean results are data points, not a proof. So for IETF 127 in San Francisco, the Network-infrastructure Hiding Protocol (NHP) is back on the hackathon floor with the same request.

The Challenge
Please try to break it.

Discover, fingerprint, or reach any NHP-protected resource without first completing a valid NHP knock. Anything that violates the authenticate-before-connect model is in scope, including:

  • Discovering protected services, hidden ports, IP addresses, or domain names
  • Bypassing authentication or authorization
  • Exploiting any pre-authentication attack surface
  • Finding cryptographic or protocol-design weaknesses
  • Replay, spoofing, or relay-abuse attacks
  • DDoS and scanning resistance
  • Autonomous and AI-assisted attack techniques
  • Passive enumeration — Certificate Transparency, DNS, and other metadata that leaks without touching the protected hosts
What's New Since IETF 126

The demo environment has been simplified, and more of it is now invisible:

  • server.opennhp.org no longer exposes any HTTPS surface — it answers only a valid NHP knock
  • ac.opennhp.org now enforces access with eBPF/XDP. Packets from unauthorized sources are dropped at the network driver, before they ever reach the Linux TCP/IP stack or any application — so vulnerabilities in those layers are unreachable to anyone who hasn't passed the NHP knock
  • demo.opennhp.org shows how to put OpenNHP behind an ordinary login portal: the user signs in, the portal knocks on their behalf
  • agent.opennhp.org demonstrates the NHP-Agent JavaScript SDK in the browser
  • relay.opennhp.org translates HTTP requests into NHP UDP messages for browser-based clients

See the full demo architecture — every box links to its source code.

Two Outcomes. Both Valuable.
If you break it
We understand the weakness, fix it, and say so publicly. The protocol gets stronger.
If you can't break it
The community gains another independent data point on the security properties of the protocol.
How to Participate

The IETF 127 Hackathon runs Saturday–Sunday, November 14–15, 2026 at the Hilton San Francisco Union Square. It is free, open to everyone, and remote participation is welcome.

  1. Register for the hackathon at registration.ietf.org/127
  2. Find the OpenNHP project on the IETF 127 Hackathon wiki
  3. Start early — the live demo is online now, so you can begin probing before the weekend
  4. Read the code in OpenNHP on GitHub and the Internet-Draft
  5. Report findings by opening a GitHub issue, or find the OpenNHP team at the hackathon

Questions? Join the discussion on [email protected] or the hackathon mailing list.

Invisible by Default. Accessible Only Through Verification.

See you in San Francisco.

Questions, or want to coordinate a test? Contact us at [email protected].