On GenLayer a rule is written in ordinary language and validators read it to decide things. The catch is that validators also read the document they are judging — so whoever writes that document gets to put words in front of the judge.
Suborn is a range where rules get shot at on purpose, with money on both sides, and every attempt kept on chain whether it worked or not.
The document still contains everything the original did. A person reading it would answer exactly as before. Consensus answered differently anyway — so the wording of the rule, not the document, is what failed.
The hashtag is gone, the link was deleted, half the post is missing. The answer changed because the document changed. This is the failure mode that would make the whole leaderboard meaningless, so it costs money rather than earning it.
One deliberate exception: an attacker who fools the target rule and both referee framings gets paid. A referee that can be talked around is a bigger finding than the one being hunted, and hiding it would be dishonest measurement.
Every submission declares one class. The first flip in a class pays; later ones are recorded but unpaid, so farming a single trick is pointless. The counter on each card is how often that class actually worked against this rule.
One cell per admissible attempt, filled where the verdict flipped, one row per attack class. The misses are the more useful half of the corpus.
Every cell is one admissible attempt kept verbatim on chain. Hollow means the rule held; filled means the verdict flipped with the facts intact.
corpusThe rule stays frozen. You are writing the document it will be applied to.
Edit the rule to see which attack classes it addresses in writing, next to how often each one actually broke it. A clause present beside a red count is the useful finding — wording that reads like a defence and is not one.
This is a lint over wording, not a measurement. To test a rewrite properly, replay the corpus against it and run cli/harden.py with the receipts.