ᛞᚨᚲᚨᚱᚢᚾ

The Cracking Challenge

We built a Lua obfuscator. Now try to break it — and tell us exactly how you did it, so we can make it stronger.

1The targets

Two scripts sealed with Dakarún v2 (custom bytecode, ChaCha20 encryption, per-build hardening — the works). Each one hides a secret canary string inside. It is never printed, never sent anywhere. Your job: recover a canary, or write up your bypass well enough that we can reproduce it.

warm-up

unbound.lua

No executor lock. Runs in any Lua 5.1 / Luau environment. Start here.

Download target
hard mode

bound.lua

Locked to the Delta executor: the decryption key itself is derived from the executor identity, so it fails closed anywhere else.

Download target

Both artifacts are signed with throwaway keys generated just for this challenge — not the production builder key. Cracking them teaches you nothing about anyone else's sealed scripts.

2How to play

3Rules of engagement

There is no cash bounty — this is a community hardening exercise. Real, reproducible bypasses get credited publicly (if you want) and directly shape the next version of Dakarún. Low-effort or automated spam reports will be ignored.

4What we're not claiming

Dakarún is not unbreakable. Anyone who controls the execution environment can, with enough effort, watch the VM decrypt and take notes. These stones raise the cost of that work — per-build polymorphism, anti-hook checks, environment-derived keys, junk and opaque predicates — and this challenge measures whether the cost is high enough to matter. If you break it cheaply, that's the most valuable result of all.

Submit your crack

Send your canary and your write-up on Discord. Include your method, your tools, and how long it took you.

Submit on Discord

Please don't post canaries publicly — send them to us first so the challenge stays fun for everyone else.