Nobody crossed the line. Here is what that is worth.
The Pulse Bond Challenge ran 28 days, from July 4 to August 1, 2026. This is the account of what was claimed, what it should have cost to break, what the window showed, and — the part that matters — what a null result does not establish.
Who came to look
Site traffic for the challenge origin over the contest window, as Google Analytics reported it. These are visitors, not attack attempts. The two are counted in different places, and this page keeps them apart.
- Active users
- 158 +54.9% People who loaded a page.
- Event count
- 3.5K +143.5% Views and interactions, not attempts.
- New users
- 147 +44.1% First-time visitors in the window.
- Key events
- 0 No conversion events were configured.
- under 1%
- 1–3%
- 3–10%
- 10% and over
- no visitors
- United States: 73.07% of users
- Netherlands: 6.19% of users
- Israel: 4.33% of users
- Canada: 2.48% of users
- China: 2.48% of users
- India: 2.48% of users
- Ireland: 2.48% of users
- Poland: 1.24% of users
- Egypt: 0.62% of users
- Finland: 0.62% of users
- Hong Kong: 0.62% of users
- Indonesia: 0.62% of users
- Lithuania: 0.62% of users
- Russia: 0.62% of users
- Singapore: 0.62% of users
- Sweden: 0.62% of users
- Ukraine: 0.31% of users
What we claimed
The challenge was never “can you break Pulse.” It was one narrow, falsifiable question, and the brief listed the claims a challenger had to disprove with reproducible evidence:
- An application completion cannot be recorded unless the server can verify a device-bound Pulse bond for that session — one continuous visit to a site.
- A browser cannot talk its way into a completion. Client state, a green check, or a replayed response is not authority.
- A relayed genuine phone is not the same thing as a bonded visit, and must not be able to stand in for one.
The target was a server-recorded accepted completion for a synthetic profile without a genuine bonded phone. A screenshot did not win. A green check in a browser did not win. That boundary is the line between digital theater and a real identity-assurance failure.
What breaking it should have cost
The landscape analysis behind the challenge compares identity defenses by attacker economics rather than by feature list. The question is never whether a control can be bypassed in theory — it is what a serious attacker has to pay, build, operate, and repeat to bypass it at useful scale.
| Archetype | Loaded cost per identity | What AI does to it |
|---|---|---|
| SMS OTP / SIM swap | $300–$5,000 | Little. Carrier and insider logistics set the floor. |
| TOTP / real-time phishing relay | $5–$50 | A lot. Lures and automation get cheaper. |
| Industrial synthetic credit fraud | $1,500–$5,000 | Some. Documents get cheaper; seasoning does not. |
| Document + selfie + liveness | $50–$600 | The most. AI attacks the core signal directly. |
| NFC + behavioral IDV | $8,000–$40,000 | Bounded. Chip signatures resist generation. |
The pattern is a split, not a ranking. Defenses whose signal an attacker can generate — phishing pages, documents, selfies, liveness video, client-side state — got dramatically cheaper to beat. Defenses whose signal requires real-world state — hardware-backed device presence, cryptographic document evidence, carrier and device context, longitudinal behavior — did not.
The thesis in one line: the lie should be expensive, and the truth should not. A snapshot is one artifact at one instant, and snapshots are now cheap to forge. A continuity is sustained coherence across channels and time. The honest person pays nothing for continuity because they simply live it. The counterfeit pays continuously, and that recurring bill is the defense.
What actually happened
No accepted completion without a genuine bond was recorded. No payout was triggered.
That result deserves a precise reading, because the strongest thing we can say about it is structural rather than statistical. The mechanic derives whether an application was accepted and whether the phone was bonded from the same verification result, so the payout condition — accepted, but not bonded — is not merely unobserved. It is unreachable through the mechanic. That invariant is asserted by a test over every possible verification outcome, not inferred from a quiet month.
Which is the honest framing of a null result: the contest did not demonstrate that the boundary holds under a funded attack. It demonstrated that the boundary was not crossed by anyone who showed up, and that the code path a crossing would require does not exist.
The useful conclusion is the one the landscape analysis started with. If a defense rests on a signal an attacker can generate, its cost curve is collapsing. If it rests on continuity an attacker has to live, the bill keeps arriving. This challenge tested the second kind, and the next one should be harder to enter and better instrumented on the way out.