🥇 Crypto Lab · 2026 Cybersecurity Excellence Awards — Gold Winner
Teaching a course? → Course modules for instructors
Browser-based cryptography demos — no backends, no accounts, just the math.*
* ⚡ One deliberate exception: Blind Oracle runs a live Rust/TFHE-rs server to demonstrate real fully homomorphic encryption — its evaluation key cannot decrypt, and the browser keeps the result verdict local.
A curated collection of single-concept cryptography demonstrations. Each one isolates a real primitive or protocol and makes it interactive in the browser. Classic algorithms, post-quantum schemes, zero-knowledge proofs — all grounded in real specifications, not toy reimplementations.
Live → https://crypto-lab.systemslibrarian.dev/
Curated, ordered journeys through the catalog. Pick one on the live site and follow it step by step.
| Path | Focus | Journey |
|---|---|---|
| Start Here | For a first visit, with no cryptography assumed: ciphers you can do on paper, then the fingerprint, where keys come from, public and private keys, agreeing on a secret in the open, the signature, the padlock, the password and the quantum clock. Thirteen steps, every one a Beginner lab -- no maths beyond arithmetic. One more is planned, on who can read your messages, and will be added when that lab lands. | Dead Sea Cipher → Vigenère Break → Enigma Forge → Hash Zoo → Good Randomness → Locks and Keys → Agreeing in Public → Ed25519 Forge → HTTPS Padlock → Chain of Trust → Bcrypt Forge → What Is PQC → Harvest Timeline |
| Developer | A builder's journey — from primitives to the protocols you actually ship. | Babel Hash → AES Modes → KDF Chain → Educational RSA → RSA Forge → Point Arithmetic → Curve Lens → Signed Bytes → DH MITM → X3DH Wire → Noise Pipe → OPAQUE Gate → WebAuthn → SSH Handshake → TLS Handshake → PQ TLS Handshake |
| Cryptanalyst | Mathematical attacks exploit structure and statistics; oracles exploit response differences; side channels measure timing or power; faults alter computation. Follow each from classical ciphers to PQC. | Dead Sea Cipher → Biham Lens → Matsui Line → Padding Oracle → Timing Oracle → Power Trace → Masked Core → Salamander → Nonce Collision → Entropy Collapse → Nonce Lattice → Frozen Heart → KyberSlash → Lattice Fault |
| Post-Quantum | A focused track on PQ KEMs, signatures, hybrids, and migration. | PQ Families → Kyber Vault → KEM Trap → Dilithium Seal → MAYO Seal → Hybrid Wire → Hybrid PQC → Downgrade Wire → PQ TLS Handshake → PQ Rotation → Harvest Timeline |
| Key Exchange | How two parties agree on a secret — classical ECDH to hybrid post-quantum handshakes. | Key Exchange → Curve Lens → DH MITM → X3DH Wire → Ratchet Wire → Noise Pipe → OPAQUE Gate → TLS Handshake → Kyber Vault → Hybrid Wire → PQ TLS Handshake |
Grouped the way the live catalog groups them, in the same order.
| Demo | Description | Source | Primitives |
|---|---|---|---|
| Phantom Vault | Derive any password from a master passphrase using HMAC-DRBG. Nothing stored, nothing synced, nothing left behind to breach. | crypto-lab-phantom-vault | PBKDF2-SHA-256 · HMAC-DRBG · Rejection Sampling |
| DRBG Arena | HMAC_DRBG, CTR_DRBG, and Hash_DRBG with state visualizers, seeding, reseeding, and live NIST SP 800-22 statistical tests. The correct-case companion to Corrupted Oracle. | crypto-lab-drbg-arena | HMAC_DRBG · CTR_DRBG · Hash_DRBG · NIST SP 800-90A |
| Shamir Gate | Split a secret into shares using Shamir's Secret Sharing and reconstruct with any qualified threshold subset. Polynomial interpolation made tangible. | crypto-lab-shamir-gate | Shamir SSS · Lagrange Interpolation · GF(p) |
| Babel Hash | SHA-256, SHA3-256, and BLAKE3 side by side with live avalanche visualization, length extension attack demo, and HMAC defense. | crypto-lab-babel-hash | SHA-256 · SHA3-256 · BLAKE3 · HMAC |
| Curve Lens | Point addition, scalar multiplication, and live ECDH across P-256, Curve25519, secp256k1, and brainpoolP256r1, whose RFC 5639 seeds it recomputes from π and e. P-256's seed has no published derivation. | crypto-lab-curve-lens | brainpoolP256r1 · Curve25519 · ECDH · P-256 |
| Point Arithmetic | Drag P and Q to see the chord-and-tangent group law, flip ℝ↔𝔽ₚ to run the identical exact arithmetic, then step double-and-add and feel why the ECDLP is hard. | crypto-lab-ec-point-arithmetic | Group Law · Chord-and-Tangent · Scalar Mult · secp256k1 |
| MAC Race | HMAC, CMAC, Poly1305, and GHASH compared with live length extension attack, timing attack, and nonce reuse demonstrations. Real WebCrypto operations. | crypto-lab-mac-race | HMAC · CMAC · Poly1305 · GHASH |
| KDF Chain | HKDF, PBKDF2, scrypt, and Argon2id compared side by side with live parameter tuning, real timing measurements, and a KDF decision tree. | crypto-lab-kdf-chain | HKDF · PBKDF2 · scrypt · Argon2id |
| Hash Zoo | SHA-256 vs SHA3-256 vs BLAKE3 internals — live avalanche analysis, Merkle-Damgård/sponge/tree construction diagrams, and timing benchmarks. | crypto-lab-hash-zoo | SHA-256 · SHA3-256 · BLAKE3 · Merkle-Damgård |
| World Hashes | SM3 (China), Streebog (Russia), and Kupyna (Ukraine) alongside SHA-256 and SHA-3. Five-way simultaneous hashing, avalanche analysis, and cryptographic sovereignty context. | crypto-lab-world-hashes | SM3 · Streebog · Kupyna · SHA-256 |
| KDF Arena | Live timing and memory comparison of HKDF, PBKDF2, scrypt, and Argon2id with adjustable cost parameters and bar chart visualization. | crypto-lab-kdf-arena | HKDF · PBKDF2 · scrypt · Argon2id |
| Poly1305 MAC | Polynomial evaluation over GF(2¹³⁰−5), constant-time tag verification, key-reuse attack visualizer, and Polynomial Stepper. | crypto-lab-poly1305-mac | Poly1305 · GF(2¹³⁰−5) · Key-Reuse Attack · Polynomial Stepper |
| Merkle Vault | The structural view: draw a tree up to 16 leaves with real SHA-256, walk one proof climb level by level, then mount a second-preimage attack and an append-only consistency check on the tree you built. | crypto-lab-merkle-vault | SHA-256 · Merkle Tree · Inclusion Proofs · Certificate Transparency |
| Bcrypt Forge | Bcrypt anatomy, cost factor benchmarking, timing-safe verification, and a real-world breach simulation. The workhorse password hash, dissected. | crypto-lab-bcrypt-forge | bcrypt · Blowfish · Cost Factor · Timing-Safe |
| Commit Gate | Hash commitments and Pedersen commitments — binding, hiding, sealed-bid auction, and homomorphic addition. The primitive beneath ZKPs, MPC, and VSS. | crypto-lab-commit-gate | Hash Commitment · Pedersen · Binding & Hiding · Homomorphic |
| VRF Gate | ECVRF prove/verify, Wesolowski VDF repeated squaring, and a RANDAO-plus-VDF beacon simulation that shows how verifiable randomness resists last-reveal manipulation. | crypto-lab-vrf-gate | ECVRF P-256 · Wesolowski VDF · RANDAO · RFC 9381 |
| OTP Vault | One-time pad encryption with provable perfect secrecy, then the two-time-pad break: XOR two ciphertexts under a reused key and crib-drag to recover both plaintexts. | crypto-lab-otp-vault | One-Time Pad · Perfect Secrecy · Two-Time Pad · Crib Dragging |
| Collision Vault | Verify real published MD5 and SHA-1 collision pairs — SHAttered, identical-prefix, chosen-prefix — live in the browser, then watch SHA-256 and SHA-3 resist the same attack. | crypto-lab-collision-vault | MD5 · SHA-1 · SHAttered · Chosen-Prefix Collision |
| Merkle Proofs | The proof-semantics view: what an inclusion proof does and does not establish — RFC 9162 index verification, a pinned real Certificate Transparency entry, and the RFC 6962 and CVE-2012-2459 attacks. | crypto-lab-merkle-proofs | SHA-256 · Merkle Proof · RFC 6962 · CVE-2012-2459 |
| Time-Lock Puzzle | Seal a message that only sequential squaring can open, then reveal the creator's instant trapdoor that collapses the delay. Real BigInt and AES-256-GCM. No backend. | crypto-lab-time-lock-puzzle | RSW · Sequential Squaring · AES-256-GCM · Trapdoor |
| VDF | Repeated modular squaring in an RSA group with a Wesolowski short proof — watch sequential work accrue one squaring at a time, confirm parallel workers don't help, then verify instantly and reveal the trapdoor. | crypto-lab-vdf | VDF · Wesolowski · Modular Squaring · Randomness Beacon |
| Quantum Entropy | A biased beam-splitter QRNG, Shannon vs min-entropy on the same stream, von Neumann debiasing, and a real Toeplitz extractor with Leftover Hash Lemma accounting and NIST SP 800-90B health tests. | crypto-lab-quantum-entropy | QRNG · Min-Entropy · Toeplitz Extractor · SP 800-90B |
| Accumulator | One fixed-size digest commits to a growing set. Prove a certificate is in it — or, the hard part, that it is not — with a short witness, then forge one with the trapdoor. | crypto-lab-accumulator | RSA Accumulator · Non-Membership Proofs · Strong RSA · Certificate Revocation |
| Beacon Lock | Lock a ciphertext to a future drand round and let the beacon's BLS signature be the decryption key — identity-based encryption with a clock in place of an authority. | crypto-lab-beacon-lock | drand quicknet · Boneh-Franklin IBE · BLS12-381 · AES-256-GCM |
| KMAC Gate | SHA3-256, SHAKE, cSHAKE and KMAC driven by one hand-rolled Keccak-f[1600] permutation — step the sponge block by block, then tamper with a signed message and watch the real verifier reject it. | crypto-lab-kmac-gate | Keccak-f[1600] · SHAKE128/256 · cSHAKE128/256 · KMAC128/256 |
| Split Point | Secret-share a function, not a value: two DPF keys each evaluate to shares of one-at-α, zero everywhere else. Two non-colluding servers fold 65,536 records and neither learns which one you read. | crypto-lab-split-point | DPF · 2-Server PIR · AES-128-CTR · FSS |
| Fold Gate | Combining two satisfying R1CS instances leaves a computable cross term; relax the system with a slack scalar and an error vector to absorb it, and one folded instance stands in for all of them. | crypto-lab-fold-gate | Nova NIFS · Relaxed R1CS · Pedersen Commitment · ristretto255 |
| Hidden Bit | Run the game: a challenger hides one bit, an adversary guesses. A rising advantage proves a scheme broken; a flat one proves only that these adversaries failed — which is why security needs a reduction. | crypto-lab-hidden-bit | IND-CPA · EUF-CMA · PRP/PRF Switching · DDH Reduction |
| Drift Key | Turn a noisy reading that never repeats into the same key every time: a code-offset secure sketch over hand-built BCH codes, HKDF-SHA-256, and the exact entropy the public helper data costs. | crypto-lab-drift-key | Fuzzy Extractor · Code-Offset Sketch · BCH · HKDF-SHA-256 |
| Noise to Numbers | NIST SP 800-90B min-entropy from pinned runs of the real assessment tool: a modelled Infinite Noise TRNG scores 0.37 bits per bit, a SHA-256 counter scores 0.92. Entropy belongs to the source, not the bytes. | crypto-lab-noise-to-numbers | SP 800-90B · Min-Entropy · Keccak-f[1600] · Modelled Noise Source |
| Pulse Chain | Recompute real NIST Beacon 2.0 pulses byte by byte, walk their SHA-512 hash chain and skiplist, verify drand rounds with a BLS12-381 pairing, and see what no check proves: whether the operator knew first. | crypto-lab-pulse-chain | NIST Beacon 2.0 · drand · BLS12-381 · SHA-512 |
| Good Randomness | Two 32-byte keys pass the same look-random checks — one from the browser’s generator, one from a ChaCha20 stream started at a four-digit PIN. Then the second is rebuilt by counting to ten thousand, while every check still reports success. | crypto-lab-good-randomness | ChaCha20 · CSPRNG · Seed Recovery · WebCrypto |
| Demo | Description | Source | Primitives |
|---|---|---|---|
| Air Stream | Generate 128-EEA1, 128-EEA2 and 128-EEA3 keystream from one key, COUNT, bearer and direction, and check each against the test vectors in its own specification. | crypto-lab-air-stream | SNOW 3G · ZUC · AES-CTR · 3GPP |
| Shadow Vault | One container, two passphrases, two messages. A practical demonstration of plausible deniability, forensic ambiguity, and browser-first UX around serious primitives. | crypto-lab-shadow-vault | Argon2id · ChaCha20-Poly1305 · SHA-256 |
| Iron Serpent | The Serpent block cipher — AES finalist with a deeper security margin. Avalanche analysis, a security-margin (round-count) view, and side-by-side AES comparison. | crypto-lab-iron-serpent | Serpent · AES-256 · SPN |
| World Ciphers | Camellia (Japan), ARIA (South Korea), SM4 (China), and Kuznyechik (Russia) side by side with AES. Encrypt/decrypt playgrounds, S-box analysis, and geopolitical compliance context. | crypto-lab-world-ciphers | Camellia · ARIA · SM4 · Kuznyechik |
| AES Modes | ECB, CBC, CTR, GCM, and CCM with live padding oracle attack. Real WebCrypto operations, ECB penguin visualization, and authenticated encryption comparison. | crypto-lab-aes-modes | AES · AES-GCM · AES-CBC · Authenticated Encryption |
| Format Ward | FF1 and FF3-1 tokenization of credit cards, SSNs, and phone numbers — with the linear cryptanalysis that got FF3-1 cut from NIST's draft revision. | crypto-lab-format-ward | FF1 · FF3-1 · AES-256 · Tokenization |
| ChaCha20 Stream | Quarter-round stepper, keystream visualizer, nonce reuse attack demo, and encrypt/decrypt playground. ARX design, no AES-NI required. | crypto-lab-chacha20-stream | ChaCha20 · ARX · Nonce Reuse · Keystream |
| AEGIS Gate | AEGIS-256 as described in CFRG Informational RFC 10032, with AES round-function state updates, six-register sponge flow, tag derivation, and RFC test-vector verification in the browser. | crypto-lab-aegis-gate | AEGIS-256 · AES Round Function · 6-State Sponge · Test Vectors |
| Ascon | NIST's lightweight cryptography standard with Ascon-AEAD128, Ascon-Hash256, avalanche analysis, and side-by-side comparison against AES-GCM and ChaCha20-Poly1305. | crypto-lab-ascon | Ascon-AEAD128 · Ascon-Hash256 · Lightweight Crypto · IoT |
| Stream Ward | Splitting a large file into individually authenticated segments fixes the memory ceiling and breaks ordering — reorder, drop or truncate the frames and every tag still verifies until a chain state binds them. | crypto-lab-stream-ward | XChaCha20-Poly1305 · secretstream · SHA-256 Chaining · Truncation Attack |
| Feistel Forge | Real DES stepped round by round, where the round function need not be invertible — and DES's is not. Then double DES falls to meet-in-the-middle, and a 64-bit block collides at the birthday bound. | crypto-lab-feistel-forge | DES · Feistel Network · Meet-in-the-Middle · Sweet32 |
| Sector Vault | XTS-AES is what full-disk encryption actually uses. Flip a bit, copy a block, restore yesterday's sector — every read returns plaintext and raises nothing, because the mode has nothing to raise it with. | crypto-lab-sector-vault | XTS-AES · GF(2^128) · Ciphertext Stealing · AES-GCM |
| Sleeve Check | GOST published a 256-byte S-box as a bare table. It falls out of four small constants and field arithmetic — evidence about how it was designed, which is not by itself an attack. | crypto-lab-sleeve-check | Kuznyechik · Streebog · TKlog · AES S-Box |
| MGM Mode | MGM, the GOST AEAD mode (RFC 9058), over Magma and Kuznyechik: a distinct authentication coefficient per block against GCM's single H, every RFC test value checked, nonce reuse, and why 64-bit blocks re-key sooner. | crypto-lab-mgm-mode | MGM · Magma · Kuznyechik · RFC 9058 |
| Demo | Description | Source | Primitives |
|---|---|---|---|
| SM2 Forge | Sign and encrypt under GB/T 32918 SM2, read the identity digest that precedes every signature, compare both deployed ciphertext orders, then recover a key from a reused nonce. | crypto-lab-sm2-forge | SM2 · SM3 · Nonce Reuse · RFC 8998 |
| Iron Letter | ECIES P-256 and RSA-OAEP compared side by side with live timing, key-size tradeoffs, and a simple sealed-letter mental model. | crypto-lab-iron-letter | ECIES P-256 · RSA-OAEP · AES-256-GCM |
| SPHINCS+ Ledger | Stateless hash-based signatures (SLH-DSA) in the browser. A post-quantum signing scheme that relies only on the security of hash functions. | crypto-lab-sphincs-ledger | SLH-DSA · FIPS 205 · SPHINCS+ · SHA-256 · WOTS+ |
| Educational RSA | Step-by-step RSA on real small numbers — key generation, encryption, decryption, and signatures — then watch a weak key get factored in milliseconds while a 2048-bit key holds. Real BigInt math, no backend. | crypto-lab-rsa-educational | RSA · Key Generation · Modular Exponentiation · OAEP |
| RSA Forge | Textbook RSA, OAEP, PSS signatures, and live attacks including small exponent and Bleichenbacher PKCS#1 v1.5 padding oracle. Real WebCrypto operations. | crypto-lab-rsa-forge | RSA · OAEP · PSS · PKCS#1 |
| Ed25519 Forge | Keypair generation, signing, and signature verification — deterministic nonces, tamper detection, the ZIP215 cofactor pitfall, and 64-byte compact signatures. | crypto-lab-ed25519-forge | Ed25519 · EdDSA · Deterministic Nonces · ZIP215 · Cofactor |
| LMS Ledger | LMS/HSS stateful hash-based signatures (NIST SP 800-208) — LM-OTS key state grid, one-time key reuse attack with real forgery demo, and CNSA 2.0 firmware signing context. | crypto-lab-lms-ledger | LMS · HSS · LM-OTS · NIST SP 800-208 |
| Pairing Gate | BLS12-381 bilinear pairing — BLS signature sign/verify with real @noble/curves arithmetic, signature aggregation visualizer (up to 100 signers → 1 proof), and rogue key attack demo. Powers Ethereum 2.0 and Zcash. | crypto-lab-pairing-gate | BLS12-381 · BLS Signatures · Signature Aggregation · Rogue Key Attack |
| Blind Sign | Chaum RSA blind signatures and Schnorr EC blind signatures — anonymous e-cash, private voting, and unlinkability proofs. The signer signs without seeing the message. | crypto-lab-blind-sign | Chaum RSA · Schnorr EC · e-Cash · Unlinkability |
| Ring Sign | LSAG ring signatures — key image linkability, double-spend detection, group signatures with manager opening, and Monero transaction privacy. Sign as one-of-many without revealing which. | crypto-lab-ring-sign | LSAG · Key Image · Group Signatures · Monero |
| Curve448 | X448 key exchange and Ed448 signatures side by side with Curve25519 and Ed25519, covering the 224-bit security tier for long-lived keys. | crypto-lab-curve448 | X448 · Ed448 · RFC 7748 · RFC 8032 |
| ECDSA Forge | ECDSA on secp256k1 and P-256 with sign/verify workflows, RFC 6979 deterministic nonces, and the classic nonce-reuse private-key recovery attack. | crypto-lab-ecdsa-forge | ECDSA · secp256k1 · RFC 6979 · Nonce Reuse |
| Schnorr Forge | Real BIP-340 Schnorr on secp256k1 with sign/verify, the step-by-step signing equation, nonce-reuse private-key recovery, and the linearity behind multisig and threshold signing. | crypto-lab-schnorr-forge | BIP-340 · secp256k1 · Nonce Reuse · Aggregation |
| ElGamal Plain | Taher ElGamal's 1985 scheme with fresh ephemeral randomness, multiplicative homomorphism, and ciphertext rerandomization across toy and RFC 3526 groups. | crypto-lab-elgamal-plain | ElGamal · RFC 3526 Group 14 · Homomorphism · Re-randomization |
| IBE Gate | Boneh-Franklin identity-based encryption on BLS12-381 with setup, private-key extraction, encrypt/decrypt flow, and an honest look at the escrow tradeoff. | crypto-lab-ibe-gate | Boneh-Franklin · BLS12-381 · Identity-Based Encryption · Key Escrow |
| LMS/XMSS | State-managed hash-based signatures with LM-OTS, Merkle trees, and hierarchical composition, showing where LMS, HSS, and XMSS fit in practice. | crypto-lab-lms-xmss | LMS · LM-OTS · HSS · NIST SP 800-208 |
| Jevil | A hash-based few-time signature scheme over the Goldilocks field using Lagrange interpolation — bounded-use signing with reusable verification keys. | crypto-lab-jevil | Jevil · Hash-Based · Goldilocks Field · Lagrange Interpolation |
| Bitcoin Wallet | Bitcoin wallet pipeline in the browser — secp256k1 keys to P2PKH and P2WPKH addresses via HASH160, plus BIP-39 mnemonics, PBKDF2 seed stretching, and BIP-32 hardened child derivation. | crypto-lab-bitcoin-wallet | secp256k1 · BIP-32 · BIP-39 · Bech32 |
| Bitcoin Script | Step a real P2PKH spend through the Script stack machine — valid, wrong-key, forged-signature, and tampered scenarios, with real secp256k1 and HASH160. No backend. | crypto-lab-bitcoin-script | secp256k1 · P2PKH · ECDSA · Stack Machine |
| Signed Bytes | Real Ed25519 over JSON — a signature binds an exact byte string, never the parsed meaning. Break key order, Unicode, and duplicate keys, then watch JCS canonicalization fix some and refuse others. | crypto-lab-signed-bytes | Ed25519 · JCS RFC 8785 · Parser Differential · Unicode NFC |
| Token Tell | Runs the real SynthID-Text keyed detector over watermarked text, then signs the same words with ECDSA P-256: change only the key and the statistical evidence vanishes; change one byte and verification fails outright. | crypto-lab-token-tell | SynthID-Text · Tournament Sampling · ECDSA P-256 · C2PA Manifest |
| Rekey Relay | A semi-trusted relay turns Alice's ciphertext into Bob's without ever holding the plaintext. In BBS98, the scheme everyone starts with, the relay and Bob recover Alice's private key in one modular division. | crypto-lab-rekey-relay | BBS98 · AFGH · BLS12-381 · Re-Encryption Key |
| Attribute Gate | Encrypt to a policy instead of to a person. Then splice two real keys whose attributes only jointly satisfy that policy, run the genuine decryption, and watch the term that refuses to cancel. | crypto-lab-attribute-gate | FAME CP-ABE · BLS12-381 · Access Policy · Collusion Resistance |
| SM9 Forge | Extract an identity key by inverting in the exponent rather than hashing to a curve, run SM9’s signature, key exchange and encryption against the standard’s own worked examples, and see why two implementations agreeing doesn’t prove either followed the spec. | crypto-lab-sm9-forge | SM9 · Identity-Based · R-ate Pairing · BN256 · Key Escrow · Nonce Reuse |
| Adaptor Gate | One click turns a pre-signature the real BIP-340 verifier rejects into a valid signature, then subtracts the two to read the secret back out — the fact that atomic swaps and PTLC routing are both built on. | crypto-lab-adaptor-gate | BIP-340 · secp256k1 · Atomic Swap · PTLC |
| Function Key | Issue a key that answers one question about an encrypted vector — its weighted sum — and nothing else. Then issue keys one at a time and watch the set of possible plaintexts shrink, until one more key hands over the master secret. | crypto-lab-function-key | ABDP15 IPFE · ristretto255 · Baby-Step Giant-Step · Key Collusion |
| Locks and Keys | A padlock anyone may close and only you can open — real RSA-OAEP and RSA-PSS on a 2048-bit pair, with the wrong key failing on purpose and the same pair doing its other job, signing. No maths on screen. | crypto-lab-locks-and-keys | RSA-OAEP · RSA-PSS · Public-Key Encryption · WebCrypto |
| Vector Gate | Switch off Ed25519's required scalar-range check and watch the verifier accept a signature nobody signed, while all five RFC vectors still pass — then ask what passing them proved. | crypto-lab-vector-gate | Ed25519 · RFC 8032 · Wycheproof Case · Evidence Scope |
| Demo | Description | Source | Primitives |
|---|---|---|---|
| Ratchet Wire | A live walkthrough of the Double Ratchet protocol powering Signal-style messaging, with per-message key derivation and forward secrecy guarantees. | crypto-lab-ratchet-wire | Double Ratchet · X25519 · HKDF · AES-256-GCM |
| Hybrid Wire | X25519 + ML-KEM-768 hybrid post-quantum key exchange as deployed in Chrome 131+ and Cloudflare. Chrome 124 shipped the Kyber draft, not ML-KEM. Six-step handshake visualization and encrypted chat. | crypto-lab-hybrid-wire | X25519 · ML-KEM-768 · HKDF-SHA256 · AES-256-GCM |
| X3DH Wire | The asynchronous handshake behind Signal. Real X25519 arithmetic, four DH operations, and HKDF-SHA-256 key derivation — no backends, no simulated math. | crypto-lab-x3dh-wire | X3DH · X25519 · HKDF-SHA-256 · Signal Protocol |
| Noise Pipe | NN, XX, IK, and IKpsk2 handshake patterns with real X25519 arithmetic, live transport encryption, and a WireGuard deep dive. | crypto-lab-noise-pipe | X25519 · HKDF · WireGuard · Handshake Patterns |
| PKI Chain | X.509 certificate chains, trust store validation, CA compromise cascades, Certificate Transparency with Merkle inclusion proofs, and post-quantum migration to ML-DSA. | crypto-lab-pki-chain | X.509 · Certificate Transparency · CA Compromise · ML-DSA Sizes Only |
| OPAQUE Gate | RFC 9807 OPAQUE aPAKE with live OPRF blind/evaluate/unblind flow, credential-envelope handling, 3DH mutual authentication, and server-breach simulation showing the password never reaches the server. | crypto-lab-opaque-gate | OPAQUE · OPRF · 3DH · HKDF |
| Envelope KMS | RFC 3394/5649 AES key wrap, DEK/KEK hierarchy, KMS-style key rotation, re-wrap without plaintext exposure, and a hash-chained audit log — the architecture behind AWS KMS and Google Cloud KMS. | crypto-lab-envelope-kms | RFC 3394 · AES Key Wrap · DEK/KEK · Key Rotation |
| Kerberos v5 | RFC 4120 Kerberos v5 — Needham-Schroeder origins, Lowe attack, full AS/TGS/AP exchange flow, AES-256-CTS-HMAC-SHA1-96 ticket encryption, and clock-skew replay defense. | crypto-lab-kerberos | RFC 4120 · Needham-Schroeder · Lowe Attack · AES-256-CTS |
| MLS Group | RFC 9420 Messaging Layer Security — TreeKEM ratchet tree, epoch key schedule, member add/remove/update operations, and group application messaging with forward secrecy guarantees. | crypto-lab-mls-group | MLS (RFC 9420) · TreeKEM · Epoch Key Schedule · Forward Secrecy |
| Key Exchange | A walkthrough of key exchange across history and protocol families — from Diffie-Hellman to modern hybrid post-quantum handshakes, with shared assumptions and threat models per era. | crypto-lab-key-exchange | Diffie-Hellman · ECDH · X25519 · ML-KEM |
| Web of Trust | A PGP-style trust graph — sign each other's keys, walk introduction chains, observe how trust flows (and breaks) without a central authority. | crypto-lab-web-of-trust | PGP · OpenPGP · GnuPG · Key Signing · Trust Graph |
| WebAuthn | Passwordless authentication via FIDO2 / WebAuthn — assertion verification, origin binding, signature counters, and the journey from passwords to passkeys. | crypto-lab-webauthn | WebAuthn · FIDO2 · Passkeys · Assertion |
| SSH Handshake | SSH transport-layer handshake and TOFU host-key pinning — ephemeral X25519 / ECDH, Ed25519 signatures over the exchange hash, and known_hosts change detection across StrictHostKeyChecking modes. | crypto-lab-ssh-handshake | X25519 · Ed25519 · TOFU · known_hosts |
| DH MITM | Interactive Diffie-Hellman key exchange, then a live man-in-the-middle attack on the unauthenticated channel that shows why raw DH needs authentication. Real modular arithmetic. No backend. | crypto-lab-diffie-hellman-mitm | Diffie-Hellman · Modular Arithmetic · MITM · Key Exchange |
| PAKE Gate | Tour SRP-6a, J-PAKE, CPace, and Dragonfly (RFC 7664) side by side — a shared key forms from a low-entropy password that never crosses the wire, plus a server-breach toggle and the Dragonblood side-channel. | crypto-lab-pake-gate | SRP-6a · J-PAKE · CPace · Dragonfly |
| TLS Handshake | Step through X25519 key exchange, Ed25519 authentication, the HKDF key schedule, and AES-GCM records, with a MITM attack that gets blocked. Real WebCrypto. No backend. | crypto-lab-tls-handshake | TLS 1.3 · X25519 · Ed25519 · AES-GCM |
| Chain of Trust | X.509 path building vs RFC 5280 validation on a real cross-signed ECDSA hierarchy — build chains yourself, watch a naive builder fail a valid leaf, and see valid signatures rejected. | crypto-lab-chain-of-trust | X.509 · RFC 5280 · ECDSA P-256 · nameConstraints |
| HPKE Envelope | RFC 9180 with every stage exposed — a KEM, a KDF, and an AEAD composed into one scheme; edit the info string or AAD and watch the real AEAD reject. | crypto-lab-hpke-envelope | DHKEM X25519 · HKDF-SHA256 · AES-GCM · RFC 9180 |
| Blind Hello | TLS 1.3 encrypts everything except the hostname it announces first — seal the ClientHello with real HPKE and see exactly what ECH hides, what it can't, and why it needs encrypted DNS. | crypto-lab-blind-hello | TLS 1.3 · ECH · HPKE · SNI |
| Key Mirror | A key directory that lies to one user and tells the truth to another — then the append-only Merkle log, consistency proofs, and gossip that make the lie detectable. | crypto-lab-key-mirror | Merkle Tree · VRF · Ed25519 · KEYTRANS |
| SPAKE Gate | SPAKE2 and SPAKE2+ on the same password, side by side — indistinguishable until the server database leaks, then one impersonation costs nothing and the other forces an offline crack. | crypto-lab-spake-gate | SPAKE2 · SPAKE2+ · P-256 · PAKE |
| DNSSEC Chain | The PKI that has to sign statements about names which do not exist. Validate a real captured chain from the IANA anchor, then walk an NSEC3 zone the denial proofs gave away. | crypto-lab-dnssec-chain | DNSSEC · NSEC3 · RRSIG · Zone Walking |
| Attestation Gate | Measured boot into PCRs, a real TPMS_ATTEST quote, a verifier with reference values — then run something outside the measured set after the last measurement and watch every check pass. | crypto-lab-attestation-gate | TPM 2.0 · TPMS_ATTEST · RATS · Measured Boot |
| PQXDH Wire | One ML-KEM secret added to the X3DH transcript is what survives a future curve break. The prekey signature and the ratchet after it are untouched, so Bob can still be impersonated with every check green. | crypto-lab-pqxdh-wire | X25519 · ML-KEM-1024 · HKDF-SHA-512 · Ed25519 |
| Ghost Commit | Commit an API key, delete it two commits later, and it keeps its name and its contents forever — git adds objects, it never edits them. Then an entropy scanner finds it in seconds. | crypto-lab-ghost-commit | Git Object Model · SHA-1 / SHA-256 · Shannon Entropy · Secret Scanning |
| HTTPS Padlock | Takes apart a certificate a real site presented, lets you break each of its four checks in turn, then shows a flawless certificate for a lookalike domain that passes every one. Reads captured certificates; it never connects to a site. | crypto-lab-https-padlock | X.509 · ECDSA P-256 · RFC 5280 Subset · ClientHello Bytes Only |
| Agreeing in Public | The paint-mixing picture, then one real X25519 exchange with both sides’ secrets compared byte for byte — and a stranger who answers in Bob’s place while every check on the page still passes. No modulus, no exponent. | crypto-lab-agreeing-in-public | X25519 · RFC 7748 · Key Agreement · No Authentication |
| Demo | Description | Source | Primitives |
|---|---|---|---|
| ZK Proof Lab | Six exhibits from Ali Baba cave to zk-SNARK intuition, with real Schnorr arithmetic, commitments, and replayable transcripts instead of vague metaphors. | crypto-lab-zk-proof-lab | Schnorr · SHA-256 Commitments · Fiat-Shamir · zk-SNARK |
| STARK Tower | AIR constraints, FRI polynomial commitments, and end-to-end Fibonacci proof. No trusted setup, post-quantum secure. The protocol behind StarkNet, StarkEx, and Risc Zero. | crypto-lab-stark-tower | zk-STARK · AIR Constraints · FRI · Post-Quantum |
| SNARK Arena | Groth16 vs PLONK — trusted setup ceremonies, proof size comparison, the toxic waste problem, and production deployments in Zcash, Polygon zkEVM, WorldID, and zkLogin. | crypto-lab-snark-arena | Groth16 · PLONK · Trusted Setup · zk-SNARK |
| Blind Oracle | A server adds encrypted values with TFHE-rs while the decryption key stays in your browser. See why a client must keep decryption-error feedback private. | crypto-lab-blind-oracle | FHE · TFHE-rs · Rust · Encrypted Compute |
| CKKS Lab | Approximate FHE for encrypted floating-point arithmetic, homomorphic neural network inference, rescaling, and the complete FHE trilogy (TFHE + BGV/BFV + CKKS). | crypto-lab-ckks-lab | CKKS · RLWE · Approximate FHE · Encrypted Inference |
| FHE Arena | BGV/BFV integer FHE — homomorphic addition and multiplication, live noise budget visualizer, relinearization, SIMD batching, and real-world deployments in private genomics and encrypted databases. | crypto-lab-fhe-arena | BGV/BFV · RLWE · Noise Budget · SIMD Batching |
| Patron Shield | Information-theoretic private information retrieval applied to catalog privacy. A direct bridge from library ethics to concrete mathematical guarantees. | crypto-lab-patron-shield | IT-PIR · XOR Secret Sharing · Chor et al. 1995 |
| VSS Gate | Feldman VSS and Pedersen VSS — verifiable secret sharing with live cheating dealer detection, commitment verification, and the layer beneath FROST and threshold wallets. | crypto-lab-vss-gate | Feldman VSS · Pedersen VSS · Commitment Verification · Cheating Detection |
| DKG Gate | Pedersen/GJKR dealerless key generation — n parties Feldman-deal to each other, public complaints disqualify cheating dealers, and the sharings sum into one t-of-n key nobody ever held. Includes the rushing-adversary bias attack and its fix. | crypto-lab-dkg-gate | Pedersen DKG · GJKR 1999 · Feldman VSS · ristretto255 |
| Garbled Gate | Yao’s Garbled Circuits — gate-by-gate garbling, oblivious transfer for input wires, and the Millionaire’s Problem solved end-to-end. The foundational two-party MPC protocol. | crypto-lab-garbled-gate | Garbled Circuits · Oblivious Transfer · Free XOR · Two-Party MPC |
| Silent Tally | Five hospitals compute a combined enrollment total without revealing any individual counts, demonstrating additive-homomorphic MPC in the browser. | crypto-lab-silent-tally | Shamir SSS · GF(2⁶¹−1) · Lagrange Interpolation · Additive Homomorphism |
| FROST Threshold | A browser-based FROST (RFC 9591) walkthrough where any qualified signer subset can produce one standard Ed25519 signature without key reassembly. | crypto-lab-frost-threshold | FROST (RFC 9591) · Ed25519 · Nonce Commitments · VSS Commitments |
| OT Gate | 1-of-2 Oblivious Transfer using the Simplest OT protocol (Chou-Orlandi 2015) over Curve25519 with real Edwards25519 group arithmetic and AES-256-GCM encryption. Foundational primitive for secure MPC. | crypto-lab-ot-gate | Simplest OT · Chou-Orlandi 2015 · Edwards25519 · AES-256-GCM |
| Oblivious Shelf | 2-server XOR Private Information Retrieval (Chor et al. 1995) — a patron retrieves any book from a 16-item catalog without the server learning which one was requested. Step-by-step query walkthrough and privacy audit. | crypto-lab-oblivious-shelf | XOR PIR · Chor et al. 1995 · 2-Server PIR · Privacy Audit |
| GG20 Wallet | GG20 threshold ECDSA — Paillier encryption, distributed key generation, and joint signing without any party holding the full private key. The protocol behind Fireblocks and Coinbase MPC. | crypto-lab-gg20-wallet | GG20 · Paillier · secp256k1 · Distributed Key Generation |
| Threshold Decrypt | ElGamal over P-256 — distributed key generation, verifiable partial decryptions with NIZK proofs, and t-of-n combination without any party holding the full private key. | crypto-lab-threshold-decrypt | ElGamal · P-256 · NIZK Proofs · t-of-n |
| ORAM Vault | A Path ORAM walkthrough with tree buckets, stash growth, position-map updates, and adversary-view visualization for cloud access-pattern hiding. | crypto-lab-oram-vault | Path ORAM · Position Map · Stash · Access Patterns |
| Paillier Gate | Paillier's additive homomorphic cryptosystem with encrypt/decrypt, tallying without decryption, and direct links to voting systems and GG20 threshold ECDSA. | crypto-lab-paillier-gate | Paillier · Additive HE · Private Voting · Aggregation |
| PSI Gate | Classic DH-PSI over ristretto255 with RFC 9380 hash-to-curve, showing how two parties learn their overlap (and each other's set size) and nothing more. | crypto-lab-psi-gate | DH-PSI · ristretto255 · Hash-to-Curve · Contact Discovery |
| Bulletproofs | ZK range proofs using Bulletproofs on ristretto255 — 64-bit Pedersen commitments, aggregate proofs over multiple ranges, the inner-product argument, and a tamper-rejection demo. | crypto-lab-bulletproofs | Bulletproofs · ristretto255 · Range Proofs · Inner-Product Argument |
| ZK Arena | A side-by-side comparison playground for zk-SNARK and zk-STARK proof systems — setup phases, proving overhead, verification cost, and the tradeoff space between Groth16, PLONK, and STARKs. | crypto-lab-zk-arena | zk-SNARK · zk-STARK · Proof Systems · Comparison |
| Shamir vs FROST | Compare Shamir secret sharing against FROST signatures side by side — watch Shamir reassemble the key in memory while FROST signs without it ever existing. Real GF(256) and Ed25519. No backend. | crypto-lab-shamir-vs-frost | Shamir SSS · FROST · Ed25519 · GF(256) |
| Blind Relay | Oblivious HTTP splits knowledge between a relay that sees your address and a gateway that sees your request — flip the collusion toggle and watch the guarantee evaporate. | crypto-lab-blind-relay | OHTTP · HPKE · Binary HTTP · RFC 9458 |
| Reshare Circle | Refresh threshold shares into a new epoch: every old share becomes garbage, the public key never changes, and the secret is never reconstructed along the way. | crypto-lab-reshare-circle | Shamir · Feldman VSS · HJKY 1995 · Mobile Adversary |
| Credential Veil | BBS+ selective disclosure over BLS12-381 — the issuer signs six fields once; the holder reveals any subset, unlinkably every time, and proves over-18 without a birth date. | crypto-lab-credential-veil | BBS+ · Selective Disclosure · Unlinkability · Range Proof |
| SPDZ Forge | SPDZ over F_p (2^61−1) — additive shares, Beaver triples, and information-theoretic MACs. Tamper with a share and semi-honest MPC swallows the lie while SPDZ aborts, even with a dishonest majority. | crypto-lab-spdz-forge | SPDZ · Beaver Triples · SPDZ MACs · Dishonest Majority |
| Traitor Trace | Naor-Naor-Lotspiech subset-cover over a 16-leaf tree — one ciphertext for all subscribers, revoke a member without rekeying anyone, and trace a leaked decoder back to its builder. Real AES-256-GCM. | crypto-lab-traitor-trace | NNL Subset-Cover · Broadcast Encryption · Traitor Tracing · AES-256-GCM |
| Icy DVRF | A t-of-n distributed VRF: partial evaluations proven with Chaum-Pedersen DLEQ under one shared challenge, aggregating to a constant-size 128-byte proof whether three parties contribute or three hundred. | crypto-lab-icy-dvrf | DVRF · Chaum-Pedersen DLEQ · ristretto255 · FROST Nonces |
| MuSig Gate | n signers aggregate their public keys into one key and their nonces into one nonce, yielding a single Schnorr signature indistinguishable from a lone signer's — plus three live forgeries BIP-327 defeats. | crypto-lab-musig-gate | MuSig2 · BIP-327 · secp256k1 · Wagner & ROS |
| Card Trick | den Boer's five-card trick — two players compute the AND of their secret bits from a shuffle alone, with security no amount of computing power can buy through. | crypto-lab-card-trick | den Boer 1989 · Five-Card Trick · Information-Theoretic · Two-Party AND |
| DP Noise | Real Laplace and Gaussian mechanisms over a twelve-person payroll — watch two databases differing by one person become indistinguishable, then watch averaging take the truth back once the budget is spent. | crypto-lab-dp-noise | Laplace Mechanism · Gaussian Mechanism · ε-δ Budget · Composition |
| Search Vault | An encrypted inverted index the server searches without a key — then the count and IKK leakage-abuse attacks turn the access pattern it observed back into your queries. | crypto-lab-search-vault | SSE · HMAC-SHA-256 · AES-256-GCM · Leakage Abuse |
| Shelf Oracle | Classic PIR needs two servers that never collude. This needs one, under RLWE. Watch the noise budget fall as the server folds in every record — it cannot see which one you asked for. | crypto-lab-shelf-oracle | BFV · RLWE · Single-Server PIR · Noise Budget |
| Polynomial Forge | One polynomial committed three ways — KZG, IPA, FRI — then the failure nothing else teaches: omit the degree bound and every cryptographic check still passes while the low-degree claim is gone. | crypto-lab-polynomial-forge | KZG · IPA · FRI · Degree Bound |
| Sphinx Mix | Peel a real Sphinx packet across three mixes — per-hop blinding, a header that never changes length. Then trace one sender end to end on a quiet network with every cryptographic check green. | crypto-lab-sphinx-mix | Sphinx · ristretto255 · LIONESS · Traffic Analysis |
| Privacy Pass | A token proves the issuer authorised someone without anyone — issuer, origin, or the two colluding — learning who. Remove the client's blind and nothing on the wire changes; the guarantee is simply gone. | crypto-lab-privacy-pass | VOPRF P-384 · DLEQ Proof · RFC 9578 · Hash-to-Curve |
| Order Leak | A column you can still sort or match on has already published the shape of its answers. Equality, order and a public distribution hand back the plaintext cell by cell — the key is never touched. | crypto-lab-order-leak | AES-GCM-SIV · BCLO OPE · CLWW ORE · Inference Attacks |
| Proof Tally | Secret sharing hides a measurement and will happily add a lie to the total. A fully linear proof carried in the same shares lets two aggregators reject a malformed report neither of them can read. | crypto-lab-proof-tally | Prio3 · Fully Linear PCP · Field64 · TurboSHAKE128 |
| Demo | Description | Source | Primitives |
|---|---|---|---|
| Quantum Vault KpqC | Threshold short-secret encryption using secret sharing and Korean post-quantum cryptography, compiled to WASM for direct browser use. | crypto-lab-quantum-vault-kpqc | AES-256-GCM · Shamir SSS · SMAUG-T · HAETAE |
| KpqC Pair | Historical AIM2-based AIMer signing, with a reported public-key-only forgery vulnerability (ePrint 2026/2235, September 28, 2026), beside NTRU+ from the older NTRU line. Honest round trips do not establish signature security. | crypto-lab-kpqc-pair | AIMer · NTRU+ · KpqC · Lattice |
| TC26 Pair | Two TC26 post-quantum signature proposals side by side: code-based Shipovnik and stateless hash-based Hypericum, both built over Streebog. | crypto-lab-tc26-pair | Shipovnik · Hypericum · Streebog · Hash-Based |
| BB84 | Quantum key distribution with photon polarization, basis sifting, QBER eavesdropper detection, and privacy amplification before AES-256-GCM message encryption. | crypto-lab-bb84 | Photon Polarization · Basis Sifting · QBER · Privacy Amplification |
| Shor | Modular period finding with QFT and continued fractions to recover integer factors, showing why RSA, ECC, and Diffie-Hellman must migrate to post-quantum alternatives. | crypto-lab-shor | Shor's Algorithm · Period Finding · QFT · RSA Factorization |
| Grover | Amplitude amplification and oracle phase kickback for symmetric-key search, with live probability oscillation and concrete key-size impact (AES-128 to AES-256). | crypto-lab-grover | Grover's Algorithm · Amplitude Amplification · Phase Kickback · AES Key Search |
| Dilithium Seal | CRYSTALS-Dilithium (ML-DSA) digital signatures in the browser. Generate lattice-based key pairs, sign documents, and verify — all post-quantum safe. | crypto-lab-dilithium-seal | ML-DSA · FIPS 204 · CRYSTALS-Dilithium · Lattice |
| Kyber Vault | CRYSTALS-Kyber (ML-KEM) key encapsulation in the browser. Encapsulate, decapsulate, and compare lattice-based key exchange against classical ECDH. | crypto-lab-kyber-vault | ML-KEM · FIPS 203 · CRYSTALS-Kyber · Lattice · AES-256-GCM |
| McEliece Gate | The oldest post-quantum KEM (1978). Binary Goppa codes, visceral 261KB public key visualization, and four-way comparison against ML-KEM, BIKE, and HQC. | crypto-lab-mceliece-gate | Classic McEliece · Goppa Codes · Post-Quantum |
| Frodo Vault | Conservative post-quantum KEM using plain LWE with no ring structure. LWE from first principles, error distribution, and side-by-side comparison against ML-KEM. | crypto-lab-frodo-vault | FrodoKEM · LWE · Lattice · Post-Quantum |
| BIKE Vault | Code-based post-quantum KEM using QC-MDPC codes, Black-Gray-Flip decoding, and side-by-side comparison against ML-KEM. NIST Round 4 alternate candidate. | crypto-lab-bike-vault | BIKE · QC-MDPC · Post-Quantum · KEM |
| HQC Vault | Hamming Quasi-Cyclic post-quantum KEM with Reed-Muller/Reed-Solomon decoding, and three-way comparison against BIKE and ML-KEM. | crypto-lab-hqc-vault | HQC · Reed-Muller · Reed-Solomon · Post-Quantum |
| Falcon Seal | Compact NTRU lattice signatures with Fast Fourier Sampling, side-by-side comparison against ML-DSA and SLH-DSA, and implementation security warnings. | crypto-lab-falcon-seal | Falcon · FN-DSA · NTRU · FFT Sampling · Post-Quantum |
| Harvest Vault | Why harvested traffic is already lost: capture a real key exchange, upgrade to post-quantum afterwards, and watch the recording stay just as readable. Mosca's theorem applied to what you already sent. | crypto-lab-harvest-vault | HNDL · Mosca's Theorem · Q-Day Timeline · PQC Migration |
| Isogeny Gate | Elliptic-curve isogenies with a toy CSIDH over GF(419), supersingular graph walks, the Castryck-Decru break of SIDH, and the surviving branches of the field in SQIsign. | crypto-lab-isogeny-gate | SIDH · CSIDH · SQIsign · Castryck-Decru |
| MPCitH Sign | Post-quantum signatures from MPC-in-the-Head with additive secret sharing, SHA-256 commitments, Merkle proofs, Fiat-Shamir, and hidden-view challenges over a toy PERK-style witness. | crypto-lab-mpcith-sign | MPC-in-the-Head · Fiat-Shamir · SHA-256 Commitments · Merkle Proofs |
| Dilithium Reject | An ML-DSA rejection-sampling lab with live acceptance histograms, rejection-reason breakdowns, and the signing-time tradeoff that keeps lattice signatures secure. | crypto-lab-dilithium-reject | ML-DSA · Rejection Sampling · FIPS 204 · Timing Tradeoffs |
| Harvest Timeline | The planning half of harvest-now-decrypt-later: which assets in a fleet cross a CRQC, what each year of delay costs, and what a migration actually reaches when you execute one. | crypto-lab-harvest-timeline | Mosca Inequality · CRQC Scenarios · Cost of Delay · PQC Migration |
| HAWK | An educational HAWK lab covering integer-only lattice signatures, discrete Gaussian sampling over Z, and the July 2026 key-recovery attack that led to HAWK's withdrawal from NIST's additional-signatures process. | crypto-lab-hawk | HAWK · Lattice Signatures · Gaussian Sampling · Withdrawn July 2026 |
| Hybrid Sign | Ed25519 plus ML-DSA-65 hybrid signatures per the IETF LAMPS composite-signature draft, framed as defense in depth for long-lived authenticity. | crypto-lab-hybrid-sign | Ed25519 · ML-DSA-65 · Composite Signatures · IETF LAMPS |
| NTRU Classic | The original 1996 NTRU lattice cryptosystem with polynomial-ring arithmetic from scratch and the historical path from classic NTRU to modern post-quantum design. | crypto-lab-ntru-classic | NTRU · Polynomial Rings · Lattice · EESS#1 |
| PQ Rotation | A post-quantum migration planner for hybrid certificates, multi-jurisdiction timelines, rolling key rotation, canary deployment, and rollback strategy. | crypto-lab-pq-rotation | Hybrid X.509 · CNSA 2.0 · Key Rotation · Migration Planner |
| PQ TLS Handshake | TLS 1.3 with the X25519MLKEM768 hybrid handshake, including byte-level framing, full key schedule derivation, and comparison against classical X25519. | crypto-lab-pq-tls-handshake | TLS 1.3 · X25519MLKEM768 · Key Schedule · Hybrid PQC |
| Scloud+ Vault | China's conservative LWE-based KEM with ternary secrets, BW32 lattice coding, and a faithful but simplified browser model of the ePrint 2024/1306 design. | crypto-lab-scloud-vault | Scloud+ · LWE KEM · BW32 Coding · Ternary Secrets |
| Threshold ML-DSA | A two-party demo of distributed post-quantum signing that produces real FIPS 204 ML-DSA signatures; key-non-reconstruction is illustrated, not enforced. | crypto-lab-threshold-mldsa | Threshold ML-DSA · Distributed Signing · Two-Party · Post-Quantum |
| PQ Families | A guided tour of the five post-quantum problem families — lattice, code-based, hash-based, multivariate, and isogeny — with the assumptions, history, and standardization status of each. | crypto-lab-pq-families | Lattice · Code-Based · Hash-Based · Multivariate · Isogeny |
| E91 | Ekert's entanglement-based QKD: measure entangled pairs, run the CHSH Bell test, and derive a key from aligned bases. |S|≈2.83 proves security; an eavesdropper drags it toward the classical bound, so the key is discarded. | crypto-lab-e91 | E91 · Entanglement · CHSH Bell Test · QKD |
| Hybrid Guide | A guide to hybrid post-quantum key exchange — a KEM combiner pairs X25519 with ML-KEM-768 so the session key holds as long as either half survives. Break each component to see the hedge. | crypto-lab-hybrid-guide | KEM Combiner · X25519 · ML-KEM-768 · X-Wing |
| Multivariate UOV | A real Unbalanced Oil-and-Vinegar scheme over GF(256) signs and verifies in the browser, showing how fixing the vinegar variables turns the MQ trapdoor into a linear solve — plus the 2022 Beullens attack that broke Rainbow. | crypto-lab-multivariate | UOV · GF(256) · MQ Problem · Beullens Attack |
| MAYO Seal | Runs real MAYO keygen, signing, and verification over GF(16), stepping through the moment an oil space too small to invert becomes solvable once k copies of the map are whipped together. | crypto-lab-mayo-seal | MAYO · GF(16) · Whipping · NIST On-Ramp |
| Hybrid PQC | Compare classical, post-quantum, and hybrid key exchange and signatures side by side, then break one half and watch the hybrid survive. Real X25519, ML-KEM-768, Ed25519, ML-DSA-65. No backend. | crypto-lab-hybrid-pqc | X25519 · ML-KEM-768 · Ed25519 · ML-DSA-65 |
| KEM Trap | Real ML-KEM-768 decapsulation never fails loudly — flip a ciphertext bit and watch a caller that drops the return code or skips key confirmation turn implicit rejection into an oracle. | crypto-lab-kem-trap | ML-KEM-768 · FIPS 203 · FO Transform · Implicit Rejection |
| Isogeny Atlas | A real supersingular isogeny graph over GF(431²), computed live from the modular polynomials, with the seven open problems of isogeny crypto drawn as paths, cycles, and endomorphisms. | crypto-lab-isogeny-atlas | Isogeny Graphs · Modular Polynomials · Endomorphism Rings · CGL Hash |
| Lattice Gentle | The lattice picture underneath ML-KEM and ML-DSA: drag basis vectors through SVP and CVP, step Gauss and LLL, then run toy Kyber and Dilithium end to end. | crypto-lab-lattice-gentle | SVP & CVP · LLL · LWE & SIS · toy ML-KEM/ML-DSA |
| Simon's Period | Exact statevector Simon's algorithm recovering a hidden XOR period in O(n) queries, then using it to predict an Even-Mansour ciphertext and forge a CBC-MAC tag. | crypto-lab-simon-period | Simon's Algorithm · Period Finding · Even-Mansour · CBC-MAC Forgery |
| Lattice Builder | Two dials straighten a scrambled lattice until its shortest vector is readable by eye. Then guess seven of a real Module-LWE key's eight coefficients and the error left over is no smaller than guessing none. | crypto-lab-lattice-builder | SVP · Module-LWE · ML-KEM (FIPS 203) · Babai Rounding |
| Point Ledger | Quantum resource estimates for secp256k1, a classical multiplication dialog, and where fuzz-test evidence stops supporting a Fiat-Shamir soundness claim. | crypto-lab-point-ledger | secp256k1 · Shor Estimates · Fiat-Shamir · Fuzz Evidence |
| PQ Chooser | Set what constrains you and get a shortlist of two or three post-quantum schemes to investigate, built from sizes it derives by running the real algorithms in your browser rather than quoting a table. | crypto-lab-pq-chooser | Derived Sizes · FIPS 203/204/205 · Live Benchmark · TLS Wire Cost |
| What Is PQC | Runs a real ML-KEM-768 exchange beside a real X25519 one in matching panels, so the only measurable difference is size — 2,272 bytes on the wire instead of 64. Not stronger: a different hard problem. | crypto-lab-what-is-pqc | ML-KEM-768 · X25519 · FIPS 203 · Size, Not Strength |
| Demo | Description | Source | Primitives |
|---|---|---|---|
| Corrupted Oracle | A live Dual_EC_DRBG backdoor demo showing state recovery and future-output prediction while standard statistical tests still appear clean. | crypto-lab-corrupted-oracle | Dual_EC_DRBG · HMAC-DRBG · ChaCha20-DRBG · P-256 |
| Misty Lens | Run MISTY1 and KASUMI side by side, map the design changes between them, and execute the seven-round related-key sandwich distinguisher in the page. | crypto-lab-misty-lens | MISTY1 · KASUMI · Related-Key · Feistel |
| Export Grade | Run real TETRA TEA1, trace its 80-bit key into a 32-bit working register, recover that register in a browser-sized window, then extrapolate the rate your own browser measured out to 2^80 and 2^128 and set it beside the published attacks on full-round AES. | crypto-lab-export-grade | TEA1 · TETRA · Key Reduction · Brute Force · Cost Extrapolation · vs. AES |
| Model Breach | A HiAE threat-model case study showing candidate enumeration, MITM state recovery, and guess-and-determine attacks when assumptions drift from deployment reality. | crypto-lab-model-breach | Threat Modeling · Candidate Enumeration · MITM Recovery · Guess-and-Determine |
| Biham Lens | A live differential cryptanalysis attack on a toy SPN cipher — the technique co-invented by Biham and Shamir that broke reduced-round DES. DDT visualization and last-round key recovery. | crypto-lab-biham-lens | Differential Cryptanalysis · SPN · DDT · Chosen-Plaintext |
| Downgrade Wire | Strip X25519MLKEM768 from a TLS 1.3 ClientHello and watch two PQ-capable endpoints agree on classical X25519 — then turn on the Finished MAC and watch transcript binding abort the same strip. | crypto-lab-downgrade-wire | TLS 1.3 · Transcript Binding · X25519MLKEM768 · Downgrade |
| Padding Oracle | Full Vaudenay 2002 chosen-ciphertext attack with real AES-CBC, byte-by-byte plaintext recovery, and coverage of ASP.NET, Lucky Thirteen, and POODLE. | crypto-lab-padding-oracle | AES-CBC · PKCS#7 · Vaudenay 2002 · POODLE |
| Timing Oracle | String comparison leakage, HMAC verification timing, RSA private key bit leakage, and cache-timing attacks with real performance.now() measurements. | crypto-lab-timing-oracle | Timing Attack · HMAC · RSA · Cache-Timing |
| Nonce Guard | AES-GCM vs AES-GCM-SIV comparison — live nonce reuse attack showing keystream XOR recovery and GHASH key extraction, synthetic IV construction, and misuse-resistance comparison. RFC 8452. | crypto-lab-nonce-guard | AES-GCM · AES-GCM-SIV · RFC 8452 · Synthetic IV |
| Protocol Compose | MAC-then-Encrypt vs Encrypt-then-MAC, padding oracle attack, CRIME, and the composition failures that drove TLS 1.3. Safe primitives composed unsafely break everything. | crypto-lab-protocol-compose | MAC-then-Encrypt · Encrypt-then-MAC · CRIME · TLS 1.3 |
| Lattice Fault | Implementation attacks on lattice PQC: NTT power leakage, rejection-sampling fault bypass, KyberSlash timing, and a loop-abort fault that recovers a whole ML-DSA secret from one signature. The math survives; sloppy implementations do not. | crypto-lab-lattice-fault | ML-KEM · ML-DSA · KyberSlash · Fault Injection |
| LLL Break | Step-by-step LLL and BKZ lattice reduction with Gram-Schmidt views, Lovasz condition checks, and a toy LWE primal attack that shows why Kyber-sized parameters do not fall the same way. | crypto-lab-lll-break | LLL · BKZ · Gram-Schmidt · Toy LWE |
| HQC Timing Break | A full-decryption oracle on HQC, where compiler rewrites reintroduce cache timing into constant-time source. Substitutes a repetition code for HQC's Reed-Muller inner code so the soft-decoding step stays legible. | crypto-lab-hqc-timing-break | vs. HQC · Cache Timing · Soft-ISD · Repetition Stand-In |
| KyberSlash | A KyberSlash timing-attack lab for ML-KEM, covering secret-dependent division, vulnerable compression paths, the Barrett-reduction fix, and live attack simulation. | crypto-lab-kyberslash | ML-KEM · KyberSlash · Timing Attack · Barrett Reduction |
| Nonce Lattice | ECDSA nonce-bias lattice attack on secp256k1 and P-256 — Hidden Number Problem construction, in-browser LLL reduction, and byte-for-byte private-key recovery from biased nonces. | crypto-lab-nonce-lattice | ECDSA · Hidden Number Problem · LLL Reduction · secp256k1 |
| Ciphertext Mirror | An ML-KEM side-channel walkthrough — manipulating ciphertexts through the Fujisaki-Okamoto transform, LDPC decoder behavior, and NTT blinding countermeasures. | crypto-lab-ciphertext-mirror | ML-KEM · FO Transform · LDPC Decoder · NTT Blinding |
| HQC Timing | The 2020 timing attack on HQC's BCH decoder — the parameterization predating today's Reed-Muller/Reed-Solomon — reproduced with a modelled decode time rather than a real decoder, then silenced by constant-time. | crypto-lab-hqc-timing | vs. HQC · Wafo-Tapa 2020 · Timing Oracle · Modelled Decode Time |
| JWT Forge | Paste or generate a JWT, tamper with claims, and swap algorithms to watch alg:none and HS/RS key-confusion attacks succeed against a vulnerable verifier and fail against a correct one. | crypto-lab-jwt-forge | JWT · JWS · alg:none · HS/RS Key Confusion |
| LWE Hints | Counts how many leakage hints collapse an LWE lattice problem on sparse ternary secrets, then recovers a toy secret from real hints and tests the Gaussian assumption against sampled data. ePrint 2026/1081. | crypto-lab-lwe-hints | LWE · Sparse Ternary Secrets · Approximate Hints · Lattice |
| Syndrome Drain | How code-based KEMs erode below NIST Level 1 when one public key derives many session keys — run a toy decode-one-of-many search and watch the measured work fall as √D, then compute when to rotate keys. | crypto-lab-syndrome-drain | DOOM · Syndrome Decoding · vs. Code-Based KEMs · May & Sá Diogo 2026 |
| Broken Trust | Leak one bit of ML-DSA's per-signature masking randomness and the secret subkey becomes the bottom of a hill you can roll down — no lattice reduction. Watch a toy version descend beside real-scale numbers from ePrint 2026/472. | crypto-lab-broken-trust | vs. ML-DSA · Bit Leakage · Hill-Climbing · Toy-Scale Only |
| Timing Side-Channel | Recover a hidden secret one byte at a time from an early-exit comparison, then watch a constant-time compare flatten the leak. Real performance.now() measurements. No backend. | crypto-lab-timing-sidechannel | Timing Attack · Constant-Time · Side-Channel · Secret Compare |
| Time Trust | Real Ed25519, HMAC, and X.509 verification driven by one movable clock — drag NOW and watch certificates, JWTs, TOTP codes, and replay caches change their verdicts about bytes that never change. | crypto-lab-time-trust | Ed25519 · X.509 · JWT · TOTP |
| Nonce Collision | Reuse one nonce under one key across AES-CTR, AES-GCM, ChaCha20-Poly1305, and AES-CBC — crib-drag plaintext out of XOR'd ciphertexts and forge tags the real verifiers accept. | crypto-lab-nonce-collision | AES-GCM · ChaCha20-Poly1305 · Forbidden Attack · Crib Dragging |
| Entropy Collapse | Restore two copies of a VM snapshot and watch an honest, standards-conformant HMAC_DRBG emit identical session keys from both — the seed, not the generator, is the whole game. | crypto-lab-entropy-collapse | HMAC_DRBG · Seed Provenance · VM Cloning · Nonce Reuse |
| Salamander | Build one AES-GCM ciphertext that decrypts to two different valid plaintexts under two different keys — both tags verify, because AEAD never promised they couldn't. | crypto-lab-salamander | AES-GCM · GHASH · GF(2¹²⁸) · Message Franking |
| Frozen Heart | Forge a Schnorr zero-knowledge proof the real verifier accepts — because the Fiat-Shamir challenge hash left one transcript field out of its input. | crypto-lab-frozen-heart | Fiat-Shamir · Schnorr · ristretto255 · NIZK |
| Power Trace | Recover an AES-128 key byte from power consumption alone. The cipher is correct and constant-time, yet CPA and DPA walk the key out through the power rail. Simulated traces, real statistics. | crypto-lab-power-trace | CPA · DPA · AES-128 · Hamming Weight |
| Protocol Checker | A Dolev-Yao symbolic model checker that rediscovers Lowe's attack on Needham-Schroeder live — found by searching, not by being told — then closes the seventeen-year-old flaw in one edit. | crypto-lab-protocol-checker | Dolev-Yao · Symbolic Model · Needham-Schroeder · Unification |
| Syndrome Hints | A real information-set-decoding attack on syndrome decoding over F₂ — feed it leaked side-channel hints and watch the work factor slide from exponential toward polynomial. | crypto-lab-syndrome-hints | Hint-ISD · Prange · Stern · Syndrome Decoding |
| Encrochat | A real Double Ratchet exchange with a genuinely opaque wire, then a modelled endpoint implant reads the plaintext anyway. The cryptography held; it did not matter. | crypto-lab-encrochat | Double Ratchet · X25519 · AES-256-GCM · Endpoint Implant |
| Ablation Wire | The 1942 Navajo code-talker stack rebuilt on modern primitives, with every layer independently switchable — turn one off and discover which was actually load-bearing. | crypto-lab-ablation-wire | X-Wing KEM · AES-256-GCM · Transcript Binding · Rust/WASM |
| Matsui Line | Matsui's Algorithm 2 against the same toy SPN Biham Lens attacks — count the bias in real known-plaintext traffic, watch one subkey candidate separate, then watch the piling-up lemma's prediction miss. | crypto-lab-matsui-line | Linear Cryptanalysis · LAT · Piling-Up Lemma · Known-Plaintext |
| Context Ward | Seals an agent's context window into a SHA-256 hash chain with role-separated HMAC seals and Ed25519 tool attestations, then shows injected content passing every check while the agent is compromised anyway. | crypto-lab-context-ward | SHA-256 Chain · HMAC-SHA-256 · HKDF · Ed25519 |
| Masked Core | First-order Boolean masking flattens the CPA that Power Trace runs — so combine two samples instead of one and the key byte comes back. Masking is a price, not a wall, and this measures it. | crypto-lab-masked-core | Boolean Masking · Second-Order CPA · AES-128 · Centered Product |
| GGH Trapdoor | A lattice trapdoor is just a good basis: one lattice, two bases, and only the short one decrypts. Then two attacks read the secret off the shape of GGH's own randomness. | crypto-lab-ggh-trapdoor | GGH · Babai Round-Off · LLL · Nguyen-Regev |
| Factor Forge | Seven classical factoring methods on a real BigInt N, each waiting for a different mistake in key generation. Obey every RSA rule and rho and ECM still finish; only size stops them. | crypto-lab-factor-forge | Pollard Rho · Lenstra ECM · Quadratic Sieve · Fermat |
| Glass Box | Chow-style white-box AES-128 built from your key as 2,032 encoded lookup tables, then attacked twice: differential computation analysis pulls the key from execution traces, and BGE step A1 strips the table encodings. | crypto-lab-glass-box | White-Box AES · Chow 2002 · DCA · BGE Attack |
| Return Path | Impossible differentials and the boomerang attack on the same toy SPN as Biham Lens, with DDT and BCT tables computed live, an adaptive chosen-ciphertext oracle, and a one-way-impossible crossing every round trip closes. | crypto-lab-return-path | Impossible Differential · Boomerang Attack · BCT · Toy SPN |
| Demo | Description | Source | Primitives |
|---|---|---|---|
| Dead Sea Cipher | Substitution and polyalphabetic ciphers from Atbash to Vigenère, through to modern AES-256-GCM. Encode, decode, and explore classical cryptanalysis. | crypto-lab-dead-sea-cipher | Substitution · Vigenère · Atbash |
| Stego Suite | LSB substitution, DCT-domain hiding, and adaptive embedding with live chi-squared steganalysis. Hide the message, not just the content. | crypto-lab-stego-suite | LSB · DCT · Adaptive Embedding · Chi-Squared Steganalysis |
| J-UNIWARD | JPEG steganography via Universal Wavelet Relative Distortion — adaptive DCT coefficient embedding that minimizes wavelet-domain detectability. The state-of-the-art in content-adaptive JPEG steganography. | crypto-lab-j-uniward | J-UNIWARD · DCT · Wavelet Distortion · Adaptive Embedding |
| Enigma Forge | Full mechanical Enigma — rotors with double-stepping, plugboard, and reflector — plus the crib-based Bombe break that exploits the flaw that no letter ever maps to itself. | crypto-lab-enigma-forge | Enigma · Rotors · Plugboard · Bombe |
| Vigenère Break | Encrypt and decrypt with a repeating-key Vigenère cipher, then recover the key length with Kasiski examination and the index of coincidence and solve each column by frequency analysis. | crypto-lab-vigenere-break | Vigenère · Kasiski Examination · Index of Coincidence · Frequency Analysis |
| Regex Veil — FTE | Compiles a regex to a minimal DFA, counts its length-n language exactly, and enciphers real AES-CTR bytes into that slice with FF1 — output a DPI rule accepts, plus the substitution attack proving nothing is authenticated. | crypto-lab-fte | FF1 · DFA Ranking · Cycle Walking · AES-256-CTR |
| Covert Channel Studio | The same bits moved eleven ways — DNS labels, ICMP echoes, inter-arrival gaps, packet order, cache lines — each scored by a cited detector. Then a warden closes several channels while their anomaly score falls, leaving no record. | crypto-lab-covert-channel-studio | Storage & Timing · Protocol Hopping · Flush+Reload · Active Warden |
These sit outside the browser-demo scope of Crypto Lab but belong to the same collection:
- Crypto Compare — Algorithm reference covering NIST and PQ-Safe standards.
- Cipher Museum — An interactive museum spanning 3,900 years of cryptographic history. Thirteen halls, 140 exhibits, live encryption demos, and cryptanalysis labs.
- Meow Decoder — Secure optical air-gap file transfer via QR-code GIFs. AES-256-GCM + Argon2id + ML-KEM-1024 + fountain codes. Python + Rust.
- Snow 2 — A modern Rust reimplementation of SNOW with AEAD support, Argon2id-derived keys, and steganographic output options.
Each demo is self-contained: one concept, one repository, full source. Documentation and threat models are included where the attack surface warrants it.
Built by Paul Clark — IT Librarian & Systems Analyst.
If you use Crypto Lab in teaching or research, please cite it via the "Cite this repository" button in the sidebar (APA and BibTeX), or the Zenodo record.
So whether you eat or drink or whatever you do, do it all for the glory of God. — 1 Corinthians 10:31
For contributors. Each Crypto Lab demo is its own repository and its own site, so the
things that go wrong go wrong quietly: a lab can be live with no card here, or serving
a build older than its own main, while every file-in-this-repo check stays green.
These tools each exist because one of those happened.
Two different questions are being asked here, and neither answers the other's.
The scheduled research watch below asks did the outside world change? — new cryptanalysis, errata, a withdrawal, a standards decision, a shift in deployment guidance. It reads primary sources, works out which labs a finding touches by inspecting what those labs actually contain rather than going by their titles, and reports what it found. It never edits a repository.
The tools in the table that follows ask did this fleet drift from itself? — a lab
live with no card here, a site serving a build older than its own main, a card
claiming an algorithm its source does not implement, a worksheet naming a control its
exhibit no longer has, a module page publishing a defect note that stopped being true.
A finding from one is not evidence about the other. A lab can be perfectly self-consistent and describe a standard withdrawn last week; it can be current with the literature and serving a stale build. Green here means the fleet agrees with itself, and nothing more than that.
Neither asks whether the demonstrations teach well — whether a student who works through an exhibit comes away understanding the thing it was built to show. That needs an instructor, not a checker, and nothing in this section is a substitute for one.
A ChatGPT scheduled task checks Crypto Lab research daily. It uses this catalog's current default branch to discover the labs, checks primary research and standards sources, and reports a finding only when a specific repository has a new, actionable gap. It does not edit repositories; a maintainer reviews and applies any suggested change. This watch is separate from the repository's CI checks below.
The task's prompt as of September 27, 2026 is reproduced verbatim below. The reproduction may lag the task: the scheduled task lives in ChatGPT, nothing here can read it, and no check compares the two — so treat the block as what the prompt said on that date rather than as what is running now. Its opening says “Weekly” and asks for an eight-day lookback, while the task's actual schedule is daily; the overlap helps catch later substantiation and revisions.
Weekly Crypto Lab watch. Lookback window: developments dated in the last 8 days (overlap is intentional).
CATALOG: Use the current default branch of https://github.com/systemslibrarian/crypto-lab as the dynamic catalog of all linked lab repositories and their topics. Include the catalog itself and any newly added labs.
STEP 1 — SCAN: Search for newly published or newly substantiated cryptanalysis, errata, withdrawals, standards decisions (drafts, finals, deprecations), and deployment guidance within the window. Check original papers, IACR ePrint, NIST (FIPS/SP/IR, PQC announcements), IETF/IRTF/CFRG, other relevant standards bodies, and researcher disclosures. News may supply leads, but verify every technical claim against a primary source.
STEP 2 — TRIAGE: Keep only developments that could materially affect a covered primitive, protocol, attack demonstration, parameter choice, or research/status claim. For each, classify it as: demonstrated result, extrapolation, attack-model-conditional, preprint, withdrawn, or final standard.
STEP 3 — MATCH: Only for developments that survive triage, identify every potentially affected lab from its actual contents (README, code, UI text, learning materials), not just the catalog tags. Inspect each affected repo's current default branch and its catalog card before judging an update necessary. If the repo already reflects the development (check content and recent commits), suppress it.
OUTPUT — only for specific, new, actionable gaps, one entry each:
- Severity: Critical (now factually wrong or insecure) / Correction (outdated status or claim) / Enhancement (worth adding)
- Repo(s) and file/section
- What is now inaccurate or missing
- Primary source with date and link
- Suggested concise change
- Meaningful test, if any
Include the catalog when its own cards or learning materials need correction. Sort by severity.
If nothing is actionable, reply with exactly one line: "Crypto Lab watch: no actionable changes this week." Do not modify, open PRs against, or merge any repository.
The table is generated from the tools themselves — the command from each tool's Run:
line, the failure from its Prevents: line, and the cadence from the workflow job that
runs it. Do not edit it by hand; run node tools/tools-sync.js.
| Tool | What it prevents | When it runs |
|---|---|---|
node tools/catalog-evidence.js verify |
the catalog asserting a lab implements an algorithm its source does not | weekly; selftest only: every PR and push |
node tools/catalog-recall.js |
the chip rule being promoted to a failing check on a judgement call rather than a measurement | weekly |
node tools/catalog-sync.js check |
the algorithm index drifting from the cards, a card claiming an algorithm with no evidence behind it, and a chip the vocabulary cannot name passing as clean | every PR and push |
node tools/clone-guard-proof.js |
a generator silently deriving this repo's tracked files from another lane's uncommitted work | every PR and push |
node tools/concept-sync.js check |
the gap list answering “is anything missing?” wrongly because a demo was never filed under a concept | manual |
node tools/corpus-freshness.js |
a corpus entry going on describing a lab that has since changed underneath it, with every other checker green | manual; selftest only: every PR and push |
node tools/corpus-sync.js check |
a demo staying invisible to the crypto-counsel chatbot because its corpus entry was never added | manual |
node tools/deploy-sync.js check |
a lab serving a build older than its own main, with nothing anywhere going red | weekly; selftest only: every PR and push |
node tools/depth-audit.js check |
a depth ranking resting on dimensions nobody re-derived, and a coverage figure that ages into a claim | manual |
node tools/dispatch-census.js check |
a lab dropping out of the dispatch checkers’ denominator without the count going red | manual |
node tools/dispatch-claims.js check |
the canonical dispatch paragraph asserting something the fleet’s own YAML no longer supports | manual |
node tools/dispatch-comment-sync.js check |
the paragraph explaining why the dispatch exists drifting into many wordings, or being deleted with the line it defends | manual |
node tools/dispatch-proof.js |
the dispatch work’s claims being trusted without re-running the evidence behind them | manual |
node tools/dispatch-sync.js check |
a merged bump whose deploy dispatch can fail, print nothing and exit 0, leaving the live site on the old build | weekly |
node tools/evidence-shape-proof.js |
a variable name, a constant, an import path or a drawing function crediting a lab with an algorithm it does not implement | every PR and push |
node tools/fleet-check.js |
a whole-fleet failure sitting unnoticed because the checker that would catch it is only run by hand | weekly |
node tools/fleet-sync.js check |
a lab going live with no card, which every catalog checker then reads as consistent rather than missing | weekly; selftest only: every PR and push |
node tools/gate-sync.js check |
a Dependabot bump clearing a lighter gate than the deploy runs, merging itself, then failing where no pull request is watching | weekly; selftest only: every PR and push |
node tools/lab-dates.js check |
a card's displayed dates drifting from the repository they describe, or a package bump reading as a content update | weekly; selftest only: every PR and push |
node tools/level-sync.js check |
a card shipping with no audience level, or LEVELS-REVIEW.md disagreeing with the levels the page actually filters on | manual |
node tools/port-sync.js check |
two labs sharing a Playwright port, where a local run silently tests whatever is already listening | manual; selftest only: every PR and push |
node tools/protection-census.js |
reading a 404 from the classic protection endpoint as unprotected when a ruleset is protecting the branch | manual |
node tools/readme-sync.js check |
this README’s tables drifting from the cards they are generated from | every PR and push |
node tools/teach-build.js check |
a generated teach page drifting from its source, and a hardcoded catalog count going stale | every PR and push |
node tools/teach-drift.js |
a worksheet naming a control its live exhibit no longer has | daily |
node tools/teach-issues.js |
a module page publishing a defect note about a lab that stopped being true | daily |
node tools/teach-layout.js |
a teach page scrolling sideways, overflowing its container, or crushing prose into a column | every PR and push |
node tools/teach-observe.js <exhibit url> |
a privacy note on a module page describing contacts the exhibit no longer makes | manual |
node tools/test-invocation.js |
a lab carrying a full test suite that CI never executes, which reads as clean everywhere because nothing reports a test that was never attempted | manual |
node tools/theme-sync.js check |
a lab drifting off its single pinned theme, or a removed theme toggle coming back | weekly |
node tools/tools-sync.js check |
this list drifting from the tools it describes | every PR and push |
13 of these 31 listed commands run only when someone runs them. The rest run in CI, on the cadence shown. Selftest-only runs exercise fixtures, not the live fleet. A checker nobody runs reports nothing, which is the failure every one of these was written after.
Not listed above: catalog-structure-check.js, catalog-vocab.js, clone-source.js, depth-audit-report.js, dispatch-mutations.js, render-registry.mjs, render-verification.mjs, sibling-labs.js, transform.mjs, validate-manifest.mjs — support code, fixtures, and one-off rewriters kept as the precise record of what was done to the fleet rather than as things to run.
This table lists the tools git tracks. Anything untracked in tools/ is work in progress rather than fleet machinery, and is absent here for that reason rather than because nothing else exists.