DefenceHackYeah 2026 finalist

LayerOne

LayerOne · RodrigoGaluppo/HackYeah2026-LayerOne

Council score

Median of 3 models, weighted by the task's official criteria
66.0 / 100

A technically genuine event-built entry whose crypto and detection code is real, but missing deliverables, zero tests, and an unreachable operational dashboard leave the end-to-end system unverified.

Criteria · line = median, dots = each member
Idea & Innovation30%
7.0

Watching a device's electrical signature externally and reporting over an independent radio channel addresses a real gap, but power-signature intrusion detection is a known research direction and the demonstrated anomaly is a benign keypad-triggered workload, so the median between B's 8 and C's 6 fits.

Members disagree here: scores range by 2.0 points.
Relation to Category20%
8.0

Squarely defence work: detection, authenticated alerting, evidence preservation, and an out-of-band channel, with honest MVP scoping rather than security theatre. B's 9.5 overstates a fit that the somewhat vague problem statement slightly dilutes, so 8 stands.

Practical Applicability / Usability20%
5.0

Deployment needs three Raspberry Pis, a Hantek scope, LoRa radios, and sigrok-cli, with hardcoded personal paths, and the operator dashboard is not demonstrated anywhere. All three members converge low for the same reasons.

Design (visual/UI)20%
6.0

The landing page is polished and accessible, with keyboard-navigable tabs and honest illustrative-data labelling, but the two screenshots are marketing assets and the operational dashboard UI is not evidenced. Every member lands on the same middle score.

Completeness & Implementation Value10%
7.0

All three members confirm the crypto chain and CUSUM detector are implemented in real code rather than stubbed, which supports the A and B score of 7 over C's 5; zero tests and no committed run log keep it from going higher.

Members disagree here: scores range by 2.0 points.
Source lines1,874
TestsNone
Claims built7.0 / 10
Task fitYes

Strengths

  • The full cryptographic chain (Ed25519 signing, X25519+HKDF daily keys, ChaCha20-Poly1305 with the header as AAD, database-enforced replay guard) is implemented in real code, not mocked.
  • Detection runs on live physical measurements through sigrok-cli with a median/MAD baseline and a two-sided CUSUM with vote-window false-positive suppression and rearm logic.
  • The README is an honest engineering document with a coherent threat model: the radio path is treated as hostile and anomalies are scoped as reasons to investigate, not proof of malware.
  • All three commits fall inside the event window with none before or after, and the public landing page is live.

Weaknesses

  • Required deliverables are missing: no deck was submitted and the form's problem, progress, and how-to-open fields are blank.
  • The operational dashboard is never evidenced: the two screenshots are marketing assets and the working dashboard sits on a private LAN address, so no degraded-scenario usability demo exists.
  • Zero test files and zero test cases for a system whose core value is cryptographic and statistical correctness.
  • Deployment depends on specific hardware and the setup scripts hardcode personal paths such as /home/russo, limiting portability.

Red flags

  • Runtime databases, logs, and CSV captures are excluded from the repo, so no committed artifact shows the detector or the verification gate ever fired in a real run.
  • The only jury-visible demo is a static marketing page; the working system is unreachable outside a private LAN.
Built during the event: yes: 3 commits by 1 author, 2026-10-04 01:41 to 2026-10-04 08:34 UTC
Live demo: https://rodrigogaluppo.github.io/HackYeah2026-LayerOne/ (HTTP 200)
Council v8
Aclaude:glm-5.3-flash66.0100% agree
Bdots-studio/dots-3-note-preview:free72.090% agree
Cinclusionai/ling-3.0-flash-sante:free59.070% agree
Jclaude:glm-5.3–judge
A HackYeah 2026 finalist, queued automatically for a council review; the council wasn't told how it placed. The council read an evidence pack built from the repo, its decks and docs; it didn't run the code or see the pitch.
The site is open source

The council, the evidence pack, the prompts and the queue are all on GitHub. If a review helped you, a star helps other teams find it.

Star on GitHub