Subnet Legibility Index · snapshot 2026-09-09 · rubric v1.0 Exploit Summit 2026 · Montreal ·

SN 61. Rank 26 of 32 by emission

RedTeam

1.2% of emission40 miners · 11 validatorsregistration 0.0691 TAOverified 2026-09-09

The RedTeam subnet by Innerworks is a decentralized platform designed to drive innovation in cybersecurity through competitive programming challenges.

In their own words · raw.githubusercontent.com
Explained from zero · security · written 2026-09-10

SN61 RedTeam runs a lockpicking league for the web, where hackers are paid to build bots that slip past detection systems and tools that catch them, and every winning entry loses its value after fifteen days.

The commodity, explained from zero

Websites run detection systems to tell humans from bots and to spot disguised browsers. A "red team" is the group hired to attack your own defences so you find the holes first. RedTeam, run by a company called Innerworks, turns that into a standing contest: it posts programming challenges, and the chain description says miners "develop and submit code solutions to various technical challenges, with a focus on enhancing security."

Two challenges are active today. Bot Virus asks for a browser bot that completes a task while passing bot-detection checks: a pick that opens the lock. Anti-Detect Browser Detection asks for code that identifies which commercial anti-detect browser is driving a session without flagging real people: a better lock. Six other challenges are listed as inactive.

The unit of output is a code solution. Who buys it is not stated in the present tense. The front page promises a library of security solutions "accessible to enterprises worldwide", and the 2024 whitepaper puts enterprise bounties, where a company pays to post a challenge, on the roadmap with no price. That is where the league comparison breaks: a league sells tickets, and here nobody has yet said who pays for the winning picks.

Why it is on Bittensor at all

The materials make a generic claim, "a safe, decentralized platform built for the sharpest minds in cybersecurity", and the whitepaper adds that existing detectors lack a continuously adapting method. Concretely, Bittensor supplies the prize money: miners earn the subnet's token for beating the previous best, so a challenge does not need a paying customer to fund it. Nothing is said about cost, censorship, or ownership against a centralized bug-bounty platform.

How the work gets done

Miners write a solution to a challenge, encrypt it, and submit; validators, the judges who decide pay, wait 24 hours before decrypting so nobody can copy a rival's entry in the same window. Validators then run each entry in an isolated sandbox and give it a raw score from 0 to 1 against the previous best, subtract a penalty for code similar to other miners' entries, and let the score decay: full value for ten days, sliding to nothing by day fifteen. Emission, the subnet's share of new tokens, follows those final scores, so a miner has to keep improving to keep earning. A new submission replaces the old one immediately.

How you would know it works

No artifact a reader can check exists on the subnet's own pages, in those words. The dashboard at dashboard.theredteam.io is an app that renders only its name to a fetcher, and the site carries no dated results; detection-rate figures exist only in third-party press.

What is missing

The site's copyright reads 2024 and it shows no figures. The decay period is fourteen days on the docs root and fifteen on the dashboard page, with formulas only in the whitepaper. There is no product page, API, price, or status page; the Discord link is a channel in the shared Bittensor server. Registration cost and the deregistration policy are not stated.

Go deeper

Sources for this explainer

Metaphor: a lockpicking league. Every claim is drawn from the evidence set or the subnet's own materials; "(inferred)" marks a conclusion rather than a quote. Corrections.

How we scored it

Four audiences, four questions each, scored on what a first-time reader can find in five minutes. Method in the rubric.

On-chain identity 6/7
subnet_name
RedTeam
github_repo
github.com
subnet_contact
oscar@theredteam.io
subnet_url
theredteam.io
discord
discord.com
description
"The RedTeam subnet by Innerworks is a decentralized platform designed to drive innovation in cybersecurity through competitive programming challenges. The subnet incentivizes miners to develop and submit code solutions to various technical challenges, with a focus on enhancing security. These solutions can be integrated into real-world products to improve their security features."
additional
not set

Stakers and validators 2.5

Should I allocate here? · rank 26 of 32 for this audience

Q1What it is 3

A secure platform for 'red team' actors to earn TAO while competing against the best minds in the industry.

theredteam.ioverifiedlive

Output is code solutions to security challenges, no unit or price, the chain description is a full paragraph repeated in the README

Q2Who it is for 1
theredteam.ioinferredlive

no usage figure, customer or revenue on the site (copyright 2024) or docs, the Medium blog returns 403, third-party press cites a 1inch integration and a detection rate rise

Q3How it resists gaming or fails 3
docs.theredteam.ioverifiedlive

docs root says points are awarded on quality against the previous best with decay over 14 days, the dashboard concept page says no decay days 0 to 10 then decay to day 15, the incentive page is mostly generic Bittensor text with a similarity penalty, the whitepaper has point formulas, scattered and inconsistent

Q4Identity and documentation 3
theredteam.ioverifiedlive

identity 6 of 7, github and url resolve, contact oscar@theredteam.io matches the front page mailto, discord is a channel in the shared Opentensor server, no staker page, a validator guide exists

Miners 3.3

Can I compete, and what wins? · rank 18 of 32 for this audience

Q1What it is 3

The RedTeam Challenge Menu provides access to various challenges designed to test and evaluate miners' technical capabilities across different security and automation domains.

docs.theredteam.ioverifiedlive

seven challenges with one line each, two marked inactive, specs live in per challenge READMEs, no schema on the index

Q2Who it is for 3

OS: Linux-based (Ubuntu 22.04 LTS+ recommended)

docs.theredteam.ioverifiedlive

with CPU 2+ cores, 8GB RAM, 50GB storage, registration via the wallet manual with no cost stated (chain burn 0.055 TAO today), competitiveness stated as beating the previous best with similarity thresholds in the FAQ

Q3How it resists gaming or fails 3
docs.theredteam.ioverifiedlive

raw score 0 to 1, a similarity penalty and a final score after decay, a new commit immediately replaces the old one, formulas only in the whitepaper, no example numbers on the docs, no deregistration policy, decay period differs between pages

Q4Identity and documentation 4
docs.theredteam.ioverifiedlive

step by step getting started guide with clone, compose and dashboard steps, release notes 4.10.1 dated 2026-08-27 and CHANGELOG 4.10.4 dated 2026-09-09, docs are versioned

Buyers and enterprises 1.8

Can I use this today? · rank 23 of 32 for this audience

Q1What it is 2

Build a library of cutting-edge security solutions accessible to enterprises worldwide.

theredteam.ioverifiedlive

no product page, API or way for a company to reach the solutions, the whitepaper roadmap puts enterprise bounties in the future

Q2Who it is for 1

the whitepaper roadmap says validators could charge a fee for submitting an enterprise bounty priced by complexity and duration, future tense, no price, enterprises the only customer type named

Q3How it resists gaming or fails 2
theredteam.ioverifiedlive

mailto oscar@theredteam.io and a Discord channel in the shared server, no status page, no SLA, no response time

Q4Identity and documentation 2
theredteam.ioverifiedlive

no API docs, contact oscar@theredteam.io on the front page matches the chain subnet_contact

Newcomers 2.8

What is this and why does it matter? · rank 26 of 32 for this audience

Q1What it is 3

Harness Red Team Ingenuity to Tackle the Internet's Challenges

theredteam.ioverifiedlive

with a plain sentence on turning detection bypass skills into rewarded work, the chain description is a readable paragraph, red team and detection mechanisms left unexplained

Q2Who it is for 2

Compete, innovate, and earn in a safe, decentralized platform built for the sharpest minds in cybersecurity.

theredteam.ioverifiedlive

a generic decentralized claim, the whitepaper adds that existing detectors lack a continuously adaptive method

Q3How it resists gaming or fails 2

the dashboard is a Streamlit app that renders only its name to a fetcher, no dated results on the site or docs, detection rate figures exist only in third-party press

Q4Identity and documentation 4
theredteam.ioverifiedlive

subnet_name RedTeam matches the site, description is a human paragraph, url resolves, the docs have an About and FAQ section while the site itself has no about page

Provenance

How this score came to be. Verified means the scorer fetched the page and the words are on it; inferred means concluded from code, absence, or a third party. The link badge is a separate automated check made before publication.

scored by agent b 2026-09-09, rubric v1.0merged 2026-09-09links verified 2026-09-09: 36 live, 0 unreachable, 0 manual

Something wrong? Corrections of fact are applied as they arrive during the window; score disputes are batched at its close. How to file one · GitHub issue · email.