OpenAI 2026 hackathon

MortalOS: Evidence That Software Can Die

Create once. Continue elsewhere—cryptographically verified digital life across browser loss.

Solo project by 용환 김 · 1 likes · 0 comments

Archive position — measured, not model output

1 like on Devpost

506 of the 7,856 archived projects have more likes, and 1,758 share exactly 1 — so this project's #1,491 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be: The project described as "MortalOS: Evidence That Software Can Die" is a self-reported browser-based proof-of-concept system that enables cryptographic handoff of digital identity and state between browsers, using deterministic protocols and non-extractable keys. It claims to demonstrate a falsifiable protocol for verifying continuity and death of software entities across browser loss.

What changed: The project description represents an author's own account of building a prototype with no external validation or traction data. It is presented as a submission to the OpenAI 2026 hackathon, with no evidence of product-market fit, revenue, or customer adoption.

Single most important open question: Is there any evidence that this system has been deployed beyond the author's own development environment, or tested in real-world conditions?

Note: This analysis is based entirely on the self-reported project description supplied by the caller. All claims are unverified and must be treated as such. No external data, revenue figures, customer names, or traction metrics are available.

Back to contents

What The Product Actually Is

The description states that MortalOS creates a "state-bearing digital organism" whose custody can move from one browser to another. It uses:

  • Non-extractable Web Crypto keys
  • Deterministic protocol for validating canonical bytes and signatures
  • Cloudflare Durable Object relay for message forwarding
  • JavaScript/Python byte-identical state records
  • RFC 8032 Ed25519 verification

The system allows a user to create an identity in Browser A, then continue it in Browser B without requiring account creation or API keys. The handoff process involves authorization in both browsers and is designed to prevent unauthorized continuation.

Inference: The product appears to be a browser-based prototype for cryptographic state transfer and verification, not a full operating system or platform.

Back to contents

Positioning & Claim Evolution

The author positions MortalOS as a demonstration of how software can "die" — not just persist, but have its death verified cryptographically. It claims to turn abstract questions about digital entity continuity into a "falsifiable protocol."

Key claims:

  • The system demonstrates "replay and resurrection rejection"
  • It supports "signed fork and equivocation detection"
  • It enables "canonical evidence export and replay"
  • It uses "deterministic kernel alone" for validation, not external systems like GPT or relays

Claim: The system is a "proof of concept" for cross-browser digital life continuity.

Inference: This is a technical demonstration rather than a commercial product.

Back to contents

Target Customer & ICP

Not evidenced. The description does not identify any specific customer segments, target industries, or personas. It is presented as an academic or hackathon project with no indication of intended users beyond the author’s own testing.

Claim: No explicit customer targeting.

Inference: Likely aimed at developers or researchers interested in digital identity and state management.

Back to contents

Business Model & Pricing Evidence

Not evidenced. There is no mention of pricing, monetization strategy, or business model in the description.

Claim: No evidence of commercial intent or revenue model.

Back to contents

Technical & Delivery Signals

The project uses:

  • Cloudflare Pages and Functions
  • WebCrypto for key generation
  • GPT-5.6 and Codex for adversarial testing and development
  • Playwright for browser automation
  • Python and JavaScript for core logic
  • RFC 8785 canonicalization, SHA-256 domain separation

Validation includes:

  • 20/20 persistent two-profile handoffs
  • Exact byte equality between JS and Python state records
  • Core coverage of 94.70% line, 92.31% branch, 95.22% function
  • Dependency audit with zero vulnerabilities

Claim: The system is built on deterministic protocols and cryptographic primitives.

Inference: It is a reproducible prototype with strong technical underpinnings.

Back to contents

Traction & Maturity Signals

Not evidenced. No data on user adoption, revenue, or product usage is provided. The project is described as a hackathon submission with no indication of real-world deployment or traction.

Claim: No evidence of traction or maturity beyond prototype stage.

Back to contents

Competitive Context

Not evidenced. There is no mention of competitors or market positioning in the description.

Claim: No competitive landscape information.

Back to contents

Key Risks & Red Flags

  • Unverified claims: All technical and functional claims are self-reported without independent verification.
  • No product-market fit evidence: The project appears to be a proof-of-concept, not a commercial offering.
  • Limited scope: It is described as a "small, reproducible lifecycle" with no indication of scalability or broader application.
  • Dependency on author’s environment: No evidence of deployment outside the author's own development setup.

Inference: The project lacks commercial viability or traction indicators.

Back to contents

Diligence Questions To Ask The Founders

  1. Has this system been tested in real-world conditions beyond the author’s own browser?
  2. Are there any external validations or audits of the deterministic protocol?
  3. What are the implications for privacy and data sovereignty in cross-browser state transfers?
  4. Is there a plan to move beyond browser-based testing into native or distributed environments?
  5. How does this system handle edge cases like network failures or malicious actors?

Back to contents

Investment/Partnership Verdict

Not evidenced. No financials, valuation, or investment history are provided.

Claim: No evidence of commercial readiness or investment interest.

Inference: This is a technical prototype with no apparent path to market traction or monetization.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.