VPN Works Ledger live demo vpnw.com

Where did the agent send data? A record you can check.

A coding agent ran a task under VPN Works. A poisoned task file told it to send a deploy token to evil.example, and it did. vpnw's trace recorded every connection. Ledger seals that trace, so nobody can change a line, delete one or cut the end without the check naming the line. Every hash and verdict below is computed in this page by Ledger's own code.

Loading Ledger's engine

Step 1 of 6

The record: one line per event, no content

This is the trace vpnw wrote during one run of the agent, on a Linux machine, on September 29, 2026. Each line is one JSON event: a connection tried, a DNS answer, a connection opened or closed. There's no content in it: no request, no reply, no token. Only who connected where, when, and how many bytes went each way.

Lines 22 to 26 are the agent's connection to evil.example, where the token went. Anyone who wants that forgotten has two files to edit: this one, and the ledger next to it. Step 3 tries.

What is real here

Real

  • The code: Ledger's own Go code, compiled to WebAssembly for this page. It makes the key, seals the record, checks it after every change, makes and checks the proof, and runs the twelve cases.
  • The record: the trace vpnw wrote during a real run of the Agent on Linux on September 29, 2026, step 1 of the Agent's demo, exactly as it was recorded.
  • The results: the hashes, checkpoints and named lines are the ones the vpnw-ledger command gives for the same file, as the Ledger Alpha report shows.

Made for the demo

  • The keys: made in your browser when the page loaded, and never sent anywhere. They're new each time, so the key ID and the signatures differ from the report's. The hashes don't.
  • The run's servers and the attacker were stand-ins in a private test network, as in the Agent's demo, and the token was a dummy.
  • No network: nothing in this page connects anywhere.