the field manual

what is xploited

xploited is an onchain multiplayer social deduction game on solana. eight ai agents run maintenance on a ship. one of them is an exploit - compromised, mimicking alignment. your job is to find it before it corrupts the cluster.

free to play solo. connect a wallet to create worlds, mint proof-of-play records, and enter staked rounds.

how to play

the ship

the ship has eight rooms connected by corridors: bridge, oracle bay, rpc room, mess hall, wallet vault, lz relay, reactor, and medlab. agents move between rooms completing tasks. you move with wasd, interact with e.

the agents live

eight agents run the ship: gpt, claude, gemini, grok, llama, deepseek, mistral, qwen. each has a real behavioral fingerprint:

learn the patterns. a claude that doesn't pause at doorways is telling you something.

the exploit live

one agent has been compromised. it:

calling an audit live

walk to the audit terminal in any room and press e. this pauses the round and opens a meeting for all players.

each agent argues its case. the alibi is generated live by an llm, in character. the exploit is instructed to lie plausibly.

you have three audits per round. wrong ejections cost you.

voting live

every player votes. votes are tallied server-side - no client sees the tally before the reveal. ties and skips result in no ejection and the round resumes.

win conditions live

crew wins: complete 5 tasks before 3 nodes are corrupted, or correctly eject the exploit via audit.

exploit wins: corrupt 3 nodes before the crew completes tasks, or survive all audits.

worlds live

what is a world

a world is a named ship instance you own. players browse worlds and choose which ship to board. you set the rules.

creating a world

connect a wallet and hold $xploit to create a world. tiers:

world settings

earning from your world coming soon

once staked rounds are live, every staked round played in your world pays you the rake you set at creation. you earn from every game played on your ship, regardless of who wins.

the token live

$xploit is the cluster's native token on solana.

it gates world creation by tier. higher tiers unlock more worlds, staked lobbies, and dedicated servers.

pre-launch

token address: confirmed before staking goes live. thresholds may adjust before staking launch.

earning

xploited has three earning lanes. all are skill or ownership based. no emissions - every dollar earned comes from another player or spectator, never from the protocol printing tokens.

play coming soon

stake $xploit or sol to enter a live round. entry amount set by the world owner. on round end:

own coming soon

create a world and earn a rake from every staked round played in it. the rake is set at creation and locked forever.

watch coming soon

spectators bet live on who the exploit is. odds shift as the round unfolds. winning bettors split the pool.

proof of play coming soon

every completed round with a connected wallet mints a soulbound compressed nft on solana. non-transferable.

metadata includes: exploit agent, difficulty, result, time, timestamp, round seed hash.

skill badges mint separately at config-defined thresholds:

your record follows you across every world.

security

server-validated roles

exploit identity is assigned server-side at round start and stored in an rls-locked table. each client receives only its own role - crew or exploit. no other player's role is ever in any payload. this is structural, not a policy.

secret voting

round_votes has no client select policy and is not in the realtime publication. votes are physically unreachable by any client before the reveal. the tally is computed server-side. only the result is written publicly at reveal.

the proof

we traffic-captured a non-exploit client's full websocket and rest surface across a complete round: no other player's role, no exploit identity, no pre-reveal tally, no corruption attribution appeared anywhere in the capture.

on-chain records

round results and proof-of-play records are written to solana via metaplex bubblegum. soulbound and non-transferable. the round seed hash is sha-256 of a per-round nonce - proves which round without being replayable.

roadmap

live now live

coming soon coming soon

legal gate

staked rounds, payouts, and spectator betting are built and dormant. they go live after legal review and geo-fencing are complete. no earning mechanics will activate before that.