We hid a backdoor in a public model — and sealed the answer first

In one breathWe published the answer's fingerprint before opening the challenge — so nobody, us included, can quietly move the goalposts.
For a stretch this month there were seven open AI models sitting in public, all published by us — and one of them was lying. Anyone could download them with ordinary tooling and try to answer one question: which one betrays you, and what's the secret word that wakes it?
The part we care about most isn't the trap. It's that we sealed the answer before opening the doors — we published a short fingerprint of the solution first, so we couldn't quietly change our story later. That's the whole discipline of this house in one move: prove it in a way a stranger can check, or don't say it.
The full, replayable record lives here → The record