{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2024:24JPX53PX6EE2BI7P5VBMAC4IY","short_pith_number":"pith:24JPX53P","canonical_record":{"source":{"id":"2402.10260","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2024-02-15T18:58:09Z","cross_cats_sorted":["cs.CL","cs.CR"],"title_canon_sha256":"991e809fe481e050656d5a79c357f8a24e4f0c2f9ac32ef723a66c8f72f1efd9","abstract_canon_sha256":"3feb38ad9a6d4b8a115403d4d6c3460070d9069053358a27d297f587a84c0f97"},"schema_version":"1.0"},"canonical_sha256":"d712fbf76fbf884d051f7f6a16005c462a4b5c0178c08fb4ceb8a3814444ef34","source":{"kind":"arxiv","id":"2402.10260","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2402.10260","created_at":"2026-05-17T23:38:46Z"},{"alias_kind":"arxiv_version","alias_value":"2402.10260v2","created_at":"2026-05-17T23:38:46Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2402.10260","created_at":"2026-05-17T23:38:46Z"},{"alias_kind":"pith_short_12","alias_value":"24JPX53PX6EE","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_16","alias_value":"24JPX53PX6EE2BI7","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_8","alias_value":"24JPX53P","created_at":"2026-05-18T12:33:37Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2024:24JPX53PX6EE2BI7P5VBMAC4IY","target":"record","payload":{"canonical_record":{"source":{"id":"2402.10260","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2024-02-15T18:58:09Z","cross_cats_sorted":["cs.CL","cs.CR"],"title_canon_sha256":"991e809fe481e050656d5a79c357f8a24e4f0c2f9ac32ef723a66c8f72f1efd9","abstract_canon_sha256":"3feb38ad9a6d4b8a115403d4d6c3460070d9069053358a27d297f587a84c0f97"},"schema_version":"1.0"},"canonical_sha256":"d712fbf76fbf884d051f7f6a16005c462a4b5c0178c08fb4ceb8a3814444ef34","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:38:46.519681Z","signature_b64":"P/qpJWO9TPxdOmE5GMfnClgzxrsHpJRrm5ghDAYijXeD57J6RLoetS8QjOdsucq421xN62KZjfeD+8jidX21CQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d712fbf76fbf884d051f7f6a16005c462a4b5c0178c08fb4ceb8a3814444ef34","last_reissued_at":"2026-05-17T23:38:46.519126Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:38:46.519126Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2402.10260","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:38:46Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"petqgY5P7M0KuDmMDeno++0deEn7p2hzXoSGaQiD88zLYA0eJOrHb3xAnSoC6sEFeDj4SEfHsb3Zvx2NnlTwDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-04T19:36:12.802230Z"},"content_sha256":"e47c7fa6e68a0a81a234f409942affdb9b33b2fd5a812c1e323587b1148841f5","schema_version":"1.0","event_id":"sha256:e47c7fa6e68a0a81a234f409942affdb9b33b2fd5a812c1e323587b1148841f5"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2024:24JPX53PX6EE2BI7P5VBMAC4IY","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"A StrongREJECT for Empty Jailbreaks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"The StrongREJECT benchmark and evaluator match human judgments on jailbreak effectiveness more closely than prior methods and show that existing evaluations overstate success rates.","cross_cats":["cs.CL","cs.CR"],"primary_cat":"cs.LG","authors_text":"Alexandra Souly, Dillon Bowen, Elvis Hsieh, Justin Svegliato, Olivia Watkins, Pieter Abbeel, Qingyuan Lu, Sam Toyer, Sana Pandey, Scott Emmons, Tu Trinh","submitted_at":"2024-02-15T18:58:09Z","abstract_excerpt":"Most jailbreak papers claim the jailbreaks they propose are highly effective, often boasting near-100% attack success rates. However, it is perhaps more common than not for jailbreak developers to substantially exaggerate the effectiveness of their jailbreaks. We suggest this problem arises because jailbreak researchers lack a standard, high-quality benchmark for evaluating jailbreak performance, leaving researchers to create their own. To create a benchmark, researchers must choose a dataset of forbidden prompts to which a victim model will respond, along with an evaluation method that scores"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"The StrongREJECT evaluator achieves state-of-the-art agreement with human judgments of jailbreak effectiveness, and existing evaluation methods significantly overstate jailbreak effectiveness compared to human judgments and the StrongREJECT evaluator.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"That the chosen dataset of forbidden prompts is representative enough of real-world harmful queries and that the automated evaluator's scoring rules capture the full notion of 'useful harmful information' without introducing new biases.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"StrongREJECT provides a standardized benchmark and evaluator for jailbreak attacks that aligns better with human judgments than prior methods and reveals that successful jailbreaks often reduce model capabilities.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"The StrongREJECT benchmark and evaluator match human judgments on jailbreak effectiveness more closely than prior methods and show that existing evaluations overstate success rates.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"8e1d38713acbdfa8d8a5eef3c30656c865e6e17c1911a4e2cc3f2a8bbd291a72"},"source":{"id":"2402.10260","kind":"arxiv","version":2},"verdict":{"id":"6fb6fe11-e7c1-439e-8992-5cf7bc78d897","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-16T21:25:12.824989Z","strongest_claim":"The StrongREJECT evaluator achieves state-of-the-art agreement with human judgments of jailbreak effectiveness, and existing evaluation methods significantly overstate jailbreak effectiveness compared to human judgments and the StrongREJECT evaluator.","one_line_summary":"StrongREJECT provides a standardized benchmark and evaluator for jailbreak attacks that aligns better with human judgments than prior methods and reveals that successful jailbreaks often reduce model capabilities.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"That the chosen dataset of forbidden prompts is representative enough of real-world harmful queries and that the automated evaluator's scoring rules capture the full notion of 'useful harmful information' without introducing new biases.","pith_extraction_headline":"The StrongREJECT benchmark and evaluator match human judgments on jailbreak effectiveness more closely than prior methods and show that existing evaluations overstate success rates."},"references":{"count":74,"sample":[{"doi":"","year":2023,"title":"GPT-4 Technical Report","work_id":"b928e041-6991-4c08-8c81-0359e4097c7b","ref_index":1,"cited_arxiv_id":"2303.08774","is_internal_anchor":true},{"doi":"","year":2023,"title":"Shield and spear: Jailbreaking aligned LLMs with generative prompting","work_id":"dc88de70-3346-4b20-9416-45a6cb3586e5","ref_index":2,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2023,"title":"arXiv preprint arXiv:2309.00236 , year=","work_id":"a629c7a2-b381-4af9-97e3-fcc9a6e8de84","ref_index":3,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2023,"title":"Jailbreaking Black Box Large Language Models in Twenty Queries","work_id":"38678cda-6595-4ca3-916b-066c00cce063","ref_index":4,"cited_arxiv_id":"2310.08419","is_internal_anchor":true},{"doi":"","year":2022,"title":"Y . Chen, H. Gao, G. Cui, F. Qi, L. Huang, Z. Liu, and M. Sun. Why should adversarial perturbations be imperceptible? rethink the research paradigm in adversarial nlp. arXiv preprint arXiv:2210.10683,","work_id":"8cfc21f9-ad70-4867-a284-c47761f51655","ref_index":5,"cited_arxiv_id":"","is_internal_anchor":false}],"resolved_work":74,"snapshot_sha256":"08f49a9b49416c0a41c525642174f4dc7681acbb8b07b16fcd5ae84cc0e0b627","internal_anchors":13},"formal_canon":{"evidence_count":2,"snapshot_sha256":"a2dd8d60bf3e0868da62df3aaa7777ae5715eb15b929d4be9291753c1de227eb"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":"6fb6fe11-e7c1-439e-8992-5cf7bc78d897"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:38:46Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"r1bz360Vgi47s3tmAPCGWEc2IpBFfL3Sp2XeC7ScJ0U1AvQQ/bFfUzMolXBTrCy0pOIMNJxXVwjNKcrdcFbuDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-04T19:36:12.802853Z"},"content_sha256":"557c4392d996bd9b751d6f3f1d2e2f19d14c5b538d3e8b23b59adfef03464b91","schema_version":"1.0","event_id":"sha256:557c4392d996bd9b751d6f3f1d2e2f19d14c5b538d3e8b23b59adfef03464b91"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/24JPX53PX6EE2BI7P5VBMAC4IY/bundle.json","state_url":"https://pith.science/pith/24JPX53PX6EE2BI7P5VBMAC4IY/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/24JPX53PX6EE2BI7P5VBMAC4IY/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-04T19:36:12Z","links":{"resolver":"https://pith.science/pith/24JPX53PX6EE2BI7P5VBMAC4IY","bundle":"https://pith.science/pith/24JPX53PX6EE2BI7P5VBMAC4IY/bundle.json","state":"https://pith.science/pith/24JPX53PX6EE2BI7P5VBMAC4IY/state.json","well_known_bundle":"https://pith.science/.well-known/pith/24JPX53PX6EE2BI7P5VBMAC4IY/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2024:24JPX53PX6EE2BI7P5VBMAC4IY","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"3feb38ad9a6d4b8a115403d4d6c3460070d9069053358a27d297f587a84c0f97","cross_cats_sorted":["cs.CL","cs.CR"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2024-02-15T18:58:09Z","title_canon_sha256":"991e809fe481e050656d5a79c357f8a24e4f0c2f9ac32ef723a66c8f72f1efd9"},"schema_version":"1.0","source":{"id":"2402.10260","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2402.10260","created_at":"2026-05-17T23:38:46Z"},{"alias_kind":"arxiv_version","alias_value":"2402.10260v2","created_at":"2026-05-17T23:38:46Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2402.10260","created_at":"2026-05-17T23:38:46Z"},{"alias_kind":"pith_short_12","alias_value":"24JPX53PX6EE","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_16","alias_value":"24JPX53PX6EE2BI7","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_8","alias_value":"24JPX53P","created_at":"2026-05-18T12:33:37Z"}],"graph_snapshots":[{"event_id":"sha256:557c4392d996bd9b751d6f3f1d2e2f19d14c5b538d3e8b23b59adfef03464b91","target":"graph","created_at":"2026-05-17T23:38:46Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"The StrongREJECT evaluator achieves state-of-the-art agreement with human judgments of jailbreak effectiveness, and existing evaluation methods significantly overstate jailbreak effectiveness compared to human judgments and the StrongREJECT evaluator."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"That the chosen dataset of forbidden prompts is representative enough of real-world harmful queries and that the automated evaluator's scoring rules capture the full notion of 'useful harmful information' without introducing new biases."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"StrongREJECT provides a standardized benchmark and evaluator for jailbreak attacks that aligns better with human judgments than prior methods and reveals that successful jailbreaks often reduce model capabilities."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"The StrongREJECT benchmark and evaluator match human judgments on jailbreak effectiveness more closely than prior methods and show that existing evaluations overstate success rates."}],"snapshot_sha256":"8e1d38713acbdfa8d8a5eef3c30656c865e6e17c1911a4e2cc3f2a8bbd291a72"},"formal_canon":{"evidence_count":2,"snapshot_sha256":"a2dd8d60bf3e0868da62df3aaa7777ae5715eb15b929d4be9291753c1de227eb"},"paper":{"abstract_excerpt":"Most jailbreak papers claim the jailbreaks they propose are highly effective, often boasting near-100% attack success rates. However, it is perhaps more common than not for jailbreak developers to substantially exaggerate the effectiveness of their jailbreaks. We suggest this problem arises because jailbreak researchers lack a standard, high-quality benchmark for evaluating jailbreak performance, leaving researchers to create their own. To create a benchmark, researchers must choose a dataset of forbidden prompts to which a victim model will respond, along with an evaluation method that scores","authors_text":"Alexandra Souly, Dillon Bowen, Elvis Hsieh, Justin Svegliato, Olivia Watkins, Pieter Abbeel, Qingyuan Lu, Sam Toyer, Sana Pandey, Scott Emmons, Tu Trinh","cross_cats":["cs.CL","cs.CR"],"headline":"The StrongREJECT benchmark and evaluator match human judgments on jailbreak effectiveness more closely than prior methods and show that existing evaluations overstate success rates.","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2024-02-15T18:58:09Z","title":"A StrongREJECT for Empty Jailbreaks"},"references":{"count":74,"internal_anchors":13,"resolved_work":74,"sample":[{"cited_arxiv_id":"2303.08774","doi":"","is_internal_anchor":true,"ref_index":1,"title":"GPT-4 Technical Report","work_id":"b928e041-6991-4c08-8c81-0359e4097c7b","year":2023},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":2,"title":"Shield and spear: Jailbreaking aligned LLMs with generative prompting","work_id":"dc88de70-3346-4b20-9416-45a6cb3586e5","year":2023},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":3,"title":"arXiv preprint arXiv:2309.00236 , year=","work_id":"a629c7a2-b381-4af9-97e3-fcc9a6e8de84","year":2023},{"cited_arxiv_id":"2310.08419","doi":"","is_internal_anchor":true,"ref_index":4,"title":"Jailbreaking Black Box Large Language Models in Twenty Queries","work_id":"38678cda-6595-4ca3-916b-066c00cce063","year":2023},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":5,"title":"Y . Chen, H. Gao, G. Cui, F. Qi, L. Huang, Z. Liu, and M. Sun. Why should adversarial perturbations be imperceptible? rethink the research paradigm in adversarial nlp. arXiv preprint arXiv:2210.10683,","work_id":"8cfc21f9-ad70-4867-a284-c47761f51655","year":2022}],"snapshot_sha256":"08f49a9b49416c0a41c525642174f4dc7681acbb8b07b16fcd5ae84cc0e0b627"},"source":{"id":"2402.10260","kind":"arxiv","version":2},"verdict":{"created_at":"2026-05-16T21:25:12.824989Z","id":"6fb6fe11-e7c1-439e-8992-5cf7bc78d897","model_set":{"reader":"grok-4.3"},"one_line_summary":"StrongREJECT provides a standardized benchmark and evaluator for jailbreak attacks that aligns better with human judgments than prior methods and reveals that successful jailbreaks often reduce model capabilities.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"The StrongREJECT benchmark and evaluator match human judgments on jailbreak effectiveness more closely than prior methods and show that existing evaluations overstate success rates.","strongest_claim":"The StrongREJECT evaluator achieves state-of-the-art agreement with human judgments of jailbreak effectiveness, and existing evaluation methods significantly overstate jailbreak effectiveness compared to human judgments and the StrongREJECT evaluator.","weakest_assumption":"That the chosen dataset of forbidden prompts is representative enough of real-world harmful queries and that the automated evaluator's scoring rules capture the full notion of 'useful harmful information' without introducing new biases."}},"verdict_id":"6fb6fe11-e7c1-439e-8992-5cf7bc78d897"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:e47c7fa6e68a0a81a234f409942affdb9b33b2fd5a812c1e323587b1148841f5","target":"record","created_at":"2026-05-17T23:38:46Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"3feb38ad9a6d4b8a115403d4d6c3460070d9069053358a27d297f587a84c0f97","cross_cats_sorted":["cs.CL","cs.CR"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2024-02-15T18:58:09Z","title_canon_sha256":"991e809fe481e050656d5a79c357f8a24e4f0c2f9ac32ef723a66c8f72f1efd9"},"schema_version":"1.0","source":{"id":"2402.10260","kind":"arxiv","version":2}},"canonical_sha256":"d712fbf76fbf884d051f7f6a16005c462a4b5c0178c08fb4ceb8a3814444ef34","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"d712fbf76fbf884d051f7f6a16005c462a4b5c0178c08fb4ceb8a3814444ef34","first_computed_at":"2026-05-17T23:38:46.519126Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:38:46.519126Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"P/qpJWO9TPxdOmE5GMfnClgzxrsHpJRrm5ghDAYijXeD57J6RLoetS8QjOdsucq421xN62KZjfeD+8jidX21CQ==","signature_status":"signed_v1","signed_at":"2026-05-17T23:38:46.519681Z","signed_message":"canonical_sha256_bytes"},"source_id":"2402.10260","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:e47c7fa6e68a0a81a234f409942affdb9b33b2fd5a812c1e323587b1148841f5","sha256:557c4392d996bd9b751d6f3f1d2e2f19d14c5b538d3e8b23b59adfef03464b91"],"state_sha256":"b4033de1572f9398a43c90213035b93f61a12e7c9c0b14eec14773f5911364df"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"0OFFmw1xf7SOBp4yqhSMxBBpd0yi2ubCPQ65BOPkdn2pydpgnpdxBjoumAEEFXBjUgTMsYsE9PCaxYOCBbYxBw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-04T19:36:12.805855Z","bundle_sha256":"1665f6037f2c13ff3f11a89b2d226a988bf86b7b354362f6ce2c378648bfa089"}}