An open challenge to fraudsters & researchers

Try to fool us. Seriously — take your best shot.

Photoshop a license. Print a fake. Replay a video of your friend. Our self-hosted, AI-powered ID validation reads the barcode math, not just the card — and it runs nine defenses at once. Beat them all, simultaneously, and we'll credit you.

9 layers
Beat simultaneously
2.6M faces
Duplicate network
100% caught
Our own synthetic fakes

Nine defenses. All of them. At the same time.

Beating one layer earns you nothing — a single holdout declines the whole attempt. Here's each wall you'll hit, the attack you'd naturally try, and why it doesn't work.

01

Barcode ↔ visual consistency

Your moveEdit the front of the card — new name, new birthdate, clean fonts.
Our counterThe PDF417 barcode tells on you — encoded fields are cross-checked against the printed visual zone. Edit the barcode to match? Now it doesn't match the front. Pick a side; you lose either way.
02

License-number recomputation

Your moveInvent a plausible-looking license number for your fabricated identity.
Our counterFL, IL, and WI license numbers are a hash of the holder's name, DOB, and sex. We recompute it. If your number didn't come from your identity, it's not a number — it's a confession.
03

Server-side re-decode

Your movePatch the JavaScript, fake the client-side decode, submit whatever you want.
Our counterClient-side tampering dies here: we decode the image ourselves, server-side, independently. The browser's opinion is advisory. Ours is the decision.
04

Document-discriminator replay

Your moveFound a card scan online? Reuse the same photo across attempts.
Our counterThe document discriminator is tracked across verifications. Same card photo used twice gets flagged — replay is a signal, not a shortcut.
05

Liveness + injection defense

Your moveHold up a printout. Replay a screen. Wear a mask. Feed a virtual camera.
Our counterThree seconds of live frames are scored for presentation attacks, and the capture path itself is checked for injection. Printouts, screens, masks, and virtual cameras all have fingerprints.
06

Face match on dedicated GPUs

Your moveSwap in a portrait that kind of looks like you, or borrow your friend's whole identity.
Our counterThe live selfie is matched against the document portrait with 512-dimensional embeddings on dedicated NVIDIA T4 GPUs. "Kind of looks like" is not a threshold we recognize.
07

OFAC + DOB corroboration

Your movePick a real name off the sanctions list's neighborhood and hope screening fails open.
Our counterEvery verification screens the SDN list with date-of-birth corroboration — and screening never fails open. A strong match is a hard decline, no exceptions.
08

Duplicate-face network

Your moveRotate identities: new name, new document, same you.
Our counterEvery enrolled face is searched 1:N against a 2.6-million-face network. Your documents may be new. Your face is already known.
09

Device intelligence

Your moveRun the attack from a VM, a headless browser, an automation framework.
Our counterVMs, headless browsers, and automation frameworks flag themselves through device and browser signals collected on every session. The machine you attack from is part of the evidence.

What counts as winning

This is a challenge on the decision engine, not a license to commit fraud. Here's exactly where the lines are.

How you win

  • Fool the automated decision into APPROVE with a fabricated or altered identity — not a review, not an error, a clean pass.
  • Your attempt must survive all nine layers in the gauntlet in a single session. Beating eight is a very good decline.
  • Pull it off? Email security@idcheck.now — we verify it, fix it, and credit you on this page (with your permission).

Hard rules

  • Only test documents you own or fully synthetic test data. No real IDs belonging to other people, ever.
  • No attacking infrastructure or availability. The challenge is the decision engine — DoS, scanning, and platform exploits are out of scope.
  • Every attempt is logged — document images, device fingerprint, which checks fired. We do see you. That's the point.

Honest numbers, no victory lap

We attack ourselves constantly. Here's where the record stands — updated as the challenge runs.

Internal synthetic fakes
100% caught

We generate fake IDs internally — edited fronts, rebuilt barcodes, mismatched pairs — and feed them to the engine. Every one is declined. Your mileage may vary. We don't think it will.

External bypasses confirmed
0 so far

No researcher has produced a fabricated or altered identity that the automated decision approved. The slot for the first name on this wall is open.

Attempts logged
Every one

Printouts, screen replays, patched clients, recycled card photos — each attempt is evidence in a hash-chained audit log, and training data for the next catch.

Beat the engine and this scoreboard changes — with your name on it, if you want it there.

FAQ

Before you start

Is this legal?

Yes — attacking our public demo with documents you own or fully synthetic test data is authorized and encouraged. We explicitly invite security researchers to probe the decision engine at idcheck.now/test. What is not authorized: using real IDs that belong to someone else, attacking our infrastructure or availability, or accessing data that isn't yours. Stay on the demo, use your own or invented identities, and you're on the right side of the line.

What happens to my attempt data?

Every attempt on the demo is logged — the document images, the selfie frames, the device fingerprint, and which checks fired. That logging is the point: it's exactly what a production customer gets on every verification. Attempt data is used to improve the fraud engine and is retained under the same configurable windows we offer customers. We never sell it.

Can I use real hacking tools?

Against the verification decision itself — yes. Virtual cameras, browser automation, modified clients, forged images, replayed captures: those are all fair game against the demo flow, because they're what real fraudsters throw at us. What stays out of scope is anything aimed at the infrastructure: denial of service, scanning, exploiting the platform, or touching other users' sessions. Beat the decision engine, not the server it runs on.

What if I actually beat it?

Tell us. Email security@idcheck.now with what you did and we'll verify it, fix it, and credit you (with your permission) on this page. A successful bypass of the automated decision is a bug report we'd rather get from you than from a fraud ring — that's why this page exists.

Think your onboarding can survive this?

Put the same nine layers in front of your users. Your first 100 verifications are free.