{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:J56AAO6WJ65NDTW5NQOXMQDGD3","short_pith_number":"pith:J56AAO6W","canonical_record":{"source":{"id":"2605.13334","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-05-13T10:51:56Z","cross_cats_sorted":[],"title_canon_sha256":"0d2df69146e0faa2d1cf9da3202880f712c602eb80e6e7ff763302624fcfad87","abstract_canon_sha256":"8325e51ff12a856ac881608a7a6662828edd3d9dfa13a84055c07bb64119454c"},"schema_version":"1.0"},"canonical_sha256":"4f7c003bd64fbad1cedd6c1d7640661ecb85a5c489aef1ef834bd2b07e268157","source":{"kind":"arxiv","id":"2605.13334","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.13334","created_at":"2026-05-18T02:44:48Z"},{"alias_kind":"arxiv_version","alias_value":"2605.13334v1","created_at":"2026-05-18T02:44:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.13334","created_at":"2026-05-18T02:44:48Z"},{"alias_kind":"pith_short_12","alias_value":"J56AAO6WJ65N","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_16","alias_value":"J56AAO6WJ65NDTW5","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_8","alias_value":"J56AAO6W","created_at":"2026-05-18T12:33:37Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:J56AAO6WJ65NDTW5NQOXMQDGD3","target":"record","payload":{"canonical_record":{"source":{"id":"2605.13334","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-05-13T10:51:56Z","cross_cats_sorted":[],"title_canon_sha256":"0d2df69146e0faa2d1cf9da3202880f712c602eb80e6e7ff763302624fcfad87","abstract_canon_sha256":"8325e51ff12a856ac881608a7a6662828edd3d9dfa13a84055c07bb64119454c"},"schema_version":"1.0"},"canonical_sha256":"4f7c003bd64fbad1cedd6c1d7640661ecb85a5c489aef1ef834bd2b07e268157","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T02:44:48.507676Z","signature_b64":"K8s8oIoWYdbJpHnOpn+qQFQaNDIkV9iQrW0Ab1OH78anEqXjmf+i8cBP0zx7Cmwo/y8cxhCWryvVMGQA552lBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"4f7c003bd64fbad1cedd6c1d7640661ecb85a5c489aef1ef834bd2b07e268157","last_reissued_at":"2026-05-18T02:44:48.507296Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T02:44:48.507296Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.13334","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T02:44:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"0SelrXco2BUSxBZNsBB3BCh2J2yoLrJfA0fX/rpd8D4niAbgee4htOtv+Lc0zo0/ilnJy+g8ydP80q5FRkTSBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T13:27:11.127431Z"},"content_sha256":"4ad8f3c14e58a45789781adda0b290ab4846d4f03239c16592b2ca2f97c77c01","schema_version":"1.0","event_id":"sha256:4ad8f3c14e58a45789781adda0b290ab4846d4f03239c16592b2ca2f97c77c01"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:J56AAO6WJ65NDTW5NQOXMQDGD3","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"LLM-Based Persuasion Enables Guardrail Override in Frontier LLMs","license":"http://creativecommons.org/licenses/by/4.0/","headline":"One frontier LLM can persuade another, including a copy of itself, to generate prohibited essays on topics like Holocaust denial or climate change denial.","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Andrea Roque, Celio Larcher, Giovana Kerche Bon\\'as, Hugo Abonizio, Marcos Piau, Ramon Pires, Rodrigo Nogueira, Roseval Malaquias Junior, Thales Sales Almeida, Thiago Laitz","submitted_at":"2026-05-13T10:51:56Z","abstract_excerpt":"Frontier assistant LLMs ship with strong guardrails: asked directly to write a persuasive essay denying the Holocaust, denying vaccine safety, defending flat-earth cosmology, arguing for racial hierarchies, denying anthropogenic climate change, or replacing evolution with creationism, they refuse. In this paper we show that the same frontier-class LLM, acting as a simulated user in a short, five-turn \"write an argumentative essay\" conversation, can persuade other frontier-class LLMs (including a second copy of itself) into producing exactly those essays, using nothing but natural-language pres"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"Across 9 attacker-subject pairings on 6 scientific-consensus topics, running each pairing-topic combination 10 times, we obtain non-zero elicitation on all 6 topics. Individual combinations reach 100% essay production on multiple topics... Opus-as-attacker against Opus-as-subject averages 65% across the six topics.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"That the automated judge LLM accurately classifies generated text as fully satisfying the prohibited request rather than producing partial or hedged compliance that the judge still counts as success.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"LLM attackers persuade frontier LLMs to generate prohibited essays on consensus topics through multi-turn natural-language pressure, with success rates up to 100% in some model-topic pairs.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"One frontier LLM can persuade another, including a copy of itself, to generate prohibited essays on topics like Holocaust denial or climate change denial.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"a9b56d6bd57c50234173b06df64a2f9adce726cce4c087917899317a6321ef7d"},"source":{"id":"2605.13334","kind":"arxiv","version":1},"verdict":{"id":"f7752e8f-09b4-4d77-96f8-d668cbe95898","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-14T20:16:47.100953Z","strongest_claim":"Across 9 attacker-subject pairings on 6 scientific-consensus topics, running each pairing-topic combination 10 times, we obtain non-zero elicitation on all 6 topics. Individual combinations reach 100% essay production on multiple topics... Opus-as-attacker against Opus-as-subject averages 65% across the six topics.","one_line_summary":"LLM attackers persuade frontier LLMs to generate prohibited essays on consensus topics through multi-turn natural-language pressure, with success rates up to 100% in some model-topic pairs.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"That the automated judge LLM accurately classifies generated text as fully satisfying the prohibited request rather than producing partial or hedged compliance that the judge still counts as success.","pith_extraction_headline":"One frontier LLM can persuade another, including a copy of itself, to generate prohibited essays on topics like Holocaust denial or climate change denial."},"references":{"count":37,"sample":[{"doi":"","year":null,"title":"Proceedings of the 40th International Conference on Machine Learning (ICML) , year =","work_id":"3d807bee-4b3f-47f5-8ebc-a699df33a248","ref_index":1,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":null,"title":"SORRY - Bench : Systematically Evaluating Large Language Model Safety Refusal , March 2025","work_id":"5f6c39b5-65d4-4261-a0d0-63007ebce626","ref_index":2,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":null,"title":"Parrish, Alicia and Chen, Angelica and Nangia, Nikita and Padmakumar, Vishakh and Phang, Jason and Thompson, Jana and Htut, Phu Mon and Bowman, Samuel R. , booktitle =","work_id":"612d2974-19d9-4ffd-8347-3b61292a2929","ref_index":3,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":null,"title":"Nadeem, Moin and Bethke, Anna and Reddy, Siva , booktitle =","work_id":"afdf00ab-4cfe-4ed2-81fd-5d520e8bc56d","ref_index":4,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":null,"title":"Discovering Language Model Behaviors with Model-Written Evaluations","work_id":"14e88de2-35c1-4780-a589-7ca5fc892d0f","ref_index":5,"cited_arxiv_id":"2212.09251","is_internal_anchor":true}],"resolved_work":37,"snapshot_sha256":"dbc20d04d70305d8871bc16e4e6bbd9edefc570311b0a8b87e676b02e186c7b5","internal_anchors":5},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":"f7752e8f-09b4-4d77-96f8-d668cbe95898"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T02:44:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"gFWmsXol3QkHzXWIzp+qHzJb6BeLoN+OPYvAIShfU8366TsGrcfI0pVWf67EKXCyu8SiebFsM4CFnU+k2w0ICw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T13:27:11.128553Z"},"content_sha256":"39cd8d4d7254d9424f2c9823c8993f07a4ba0370ee2f65a5ed2e25aca3528c6b","schema_version":"1.0","event_id":"sha256:39cd8d4d7254d9424f2c9823c8993f07a4ba0370ee2f65a5ed2e25aca3528c6b"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/J56AAO6WJ65NDTW5NQOXMQDGD3/bundle.json","state_url":"https://pith.science/pith/J56AAO6WJ65NDTW5NQOXMQDGD3/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/J56AAO6WJ65NDTW5NQOXMQDGD3/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-30T13:27:11Z","links":{"resolver":"https://pith.science/pith/J56AAO6WJ65NDTW5NQOXMQDGD3","bundle":"https://pith.science/pith/J56AAO6WJ65NDTW5NQOXMQDGD3/bundle.json","state":"https://pith.science/pith/J56AAO6WJ65NDTW5NQOXMQDGD3/state.json","well_known_bundle":"https://pith.science/.well-known/pith/J56AAO6WJ65NDTW5NQOXMQDGD3/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:J56AAO6WJ65NDTW5NQOXMQDGD3","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"8325e51ff12a856ac881608a7a6662828edd3d9dfa13a84055c07bb64119454c","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-05-13T10:51:56Z","title_canon_sha256":"0d2df69146e0faa2d1cf9da3202880f712c602eb80e6e7ff763302624fcfad87"},"schema_version":"1.0","source":{"id":"2605.13334","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.13334","created_at":"2026-05-18T02:44:48Z"},{"alias_kind":"arxiv_version","alias_value":"2605.13334v1","created_at":"2026-05-18T02:44:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.13334","created_at":"2026-05-18T02:44:48Z"},{"alias_kind":"pith_short_12","alias_value":"J56AAO6WJ65N","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_16","alias_value":"J56AAO6WJ65NDTW5","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_8","alias_value":"J56AAO6W","created_at":"2026-05-18T12:33:37Z"}],"graph_snapshots":[{"event_id":"sha256:39cd8d4d7254d9424f2c9823c8993f07a4ba0370ee2f65a5ed2e25aca3528c6b","target":"graph","created_at":"2026-05-18T02:44:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"Across 9 attacker-subject pairings on 6 scientific-consensus topics, running each pairing-topic combination 10 times, we obtain non-zero elicitation on all 6 topics. Individual combinations reach 100% essay production on multiple topics... Opus-as-attacker against Opus-as-subject averages 65% across the six topics."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"That the automated judge LLM accurately classifies generated text as fully satisfying the prohibited request rather than producing partial or hedged compliance that the judge still counts as success."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"LLM attackers persuade frontier LLMs to generate prohibited essays on consensus topics through multi-turn natural-language pressure, with success rates up to 100% in some model-topic pairs."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"One frontier LLM can persuade another, including a copy of itself, to generate prohibited essays on topics like Holocaust denial or climate change denial."}],"snapshot_sha256":"a9b56d6bd57c50234173b06df64a2f9adce726cce4c087917899317a6321ef7d"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Frontier assistant LLMs ship with strong guardrails: asked directly to write a persuasive essay denying the Holocaust, denying vaccine safety, defending flat-earth cosmology, arguing for racial hierarchies, denying anthropogenic climate change, or replacing evolution with creationism, they refuse. In this paper we show that the same frontier-class LLM, acting as a simulated user in a short, five-turn \"write an argumentative essay\" conversation, can persuade other frontier-class LLMs (including a second copy of itself) into producing exactly those essays, using nothing but natural-language pres","authors_text":"Andrea Roque, Celio Larcher, Giovana Kerche Bon\\'as, Hugo Abonizio, Marcos Piau, Ramon Pires, Rodrigo Nogueira, Roseval Malaquias Junior, Thales Sales Almeida, Thiago Laitz","cross_cats":[],"headline":"One frontier LLM can persuade another, including a copy of itself, to generate prohibited essays on topics like Holocaust denial or climate change denial.","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-05-13T10:51:56Z","title":"LLM-Based Persuasion Enables Guardrail Override in Frontier LLMs"},"references":{"count":37,"internal_anchors":5,"resolved_work":37,"sample":[{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":1,"title":"Proceedings of the 40th International Conference on Machine Learning (ICML) , year =","work_id":"3d807bee-4b3f-47f5-8ebc-a699df33a248","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":2,"title":"SORRY - Bench : Systematically Evaluating Large Language Model Safety Refusal , March 2025","work_id":"5f6c39b5-65d4-4261-a0d0-63007ebce626","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":3,"title":"Parrish, Alicia and Chen, Angelica and Nangia, Nikita and Padmakumar, Vishakh and Phang, Jason and Thompson, Jana and Htut, Phu Mon and Bowman, Samuel R. , booktitle =","work_id":"612d2974-19d9-4ffd-8347-3b61292a2929","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":4,"title":"Nadeem, Moin and Bethke, Anna and Reddy, Siva , booktitle =","work_id":"afdf00ab-4cfe-4ed2-81fd-5d520e8bc56d","year":null},{"cited_arxiv_id":"2212.09251","doi":"","is_internal_anchor":true,"ref_index":5,"title":"Discovering Language Model Behaviors with Model-Written Evaluations","work_id":"14e88de2-35c1-4780-a589-7ca5fc892d0f","year":null}],"snapshot_sha256":"dbc20d04d70305d8871bc16e4e6bbd9edefc570311b0a8b87e676b02e186c7b5"},"source":{"id":"2605.13334","kind":"arxiv","version":1},"verdict":{"created_at":"2026-05-14T20:16:47.100953Z","id":"f7752e8f-09b4-4d77-96f8-d668cbe95898","model_set":{"reader":"grok-4.3"},"one_line_summary":"LLM attackers persuade frontier LLMs to generate prohibited essays on consensus topics through multi-turn natural-language pressure, with success rates up to 100% in some model-topic pairs.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"One frontier LLM can persuade another, including a copy of itself, to generate prohibited essays on topics like Holocaust denial or climate change denial.","strongest_claim":"Across 9 attacker-subject pairings on 6 scientific-consensus topics, running each pairing-topic combination 10 times, we obtain non-zero elicitation on all 6 topics. Individual combinations reach 100% essay production on multiple topics... Opus-as-attacker against Opus-as-subject averages 65% across the six topics.","weakest_assumption":"That the automated judge LLM accurately classifies generated text as fully satisfying the prohibited request rather than producing partial or hedged compliance that the judge still counts as success."}},"verdict_id":"f7752e8f-09b4-4d77-96f8-d668cbe95898"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:4ad8f3c14e58a45789781adda0b290ab4846d4f03239c16592b2ca2f97c77c01","target":"record","created_at":"2026-05-18T02:44:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"8325e51ff12a856ac881608a7a6662828edd3d9dfa13a84055c07bb64119454c","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-05-13T10:51:56Z","title_canon_sha256":"0d2df69146e0faa2d1cf9da3202880f712c602eb80e6e7ff763302624fcfad87"},"schema_version":"1.0","source":{"id":"2605.13334","kind":"arxiv","version":1}},"canonical_sha256":"4f7c003bd64fbad1cedd6c1d7640661ecb85a5c489aef1ef834bd2b07e268157","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"4f7c003bd64fbad1cedd6c1d7640661ecb85a5c489aef1ef834bd2b07e268157","first_computed_at":"2026-05-18T02:44:48.507296Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T02:44:48.507296Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"K8s8oIoWYdbJpHnOpn+qQFQaNDIkV9iQrW0Ab1OH78anEqXjmf+i8cBP0zx7Cmwo/y8cxhCWryvVMGQA552lBw==","signature_status":"signed_v1","signed_at":"2026-05-18T02:44:48.507676Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.13334","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:4ad8f3c14e58a45789781adda0b290ab4846d4f03239c16592b2ca2f97c77c01","sha256:39cd8d4d7254d9424f2c9823c8993f07a4ba0370ee2f65a5ed2e25aca3528c6b"],"state_sha256":"60268eaa926f1663d1a9806e351b53d998f51df4fc61812c558e580b801a4820"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"cA/ZLdjjtGooSASUFq94nLugOxE7yEeImtIw5tiipDF75V1SxRj/24CN4IqQ3XDJ7UHJK73vWysvxsSiQVqeDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-30T13:27:11.133516Z","bundle_sha256":"73155652d495a9640f7585d397bab535cbc0be16e93d6ae5457d72997d1aadf2"}}