Skip to content

Capture the Flag: Hacking as a Sport

Abstract

Capture the Flag (CTF) is the competitive form of computer security: teams break into deliberately vulnerable programs, prove each break-in by submitting a secret string (the “flag”), and in the attack-defense variant patch their own copies while exploiting everyone else’s. The format started at DEF CON 4 in Las Vegas in 1996 as a loosely judged free-for-all and was turned, by a succession of volunteer organizer groups, into a qualifier-and-finals tournament with its own dynasties. University teams, above all Carnegie Mellon’s Plaid Parliament of Pwning, dominated it from the 2010s; high schools, the European Union and DARPA adopted it as a recruiting and research instrument; and since 2016 machines have been entering the game as players.

Before the Rules

DEF CON began in June 1993 as a party: Jeff Moss, then 18, organized it as a farewell for a friend, and about 100 people came to the Sands Hotel in Las Vegas. By DEF CON 3 the conference network was a wide-open target where attendees attacked one another without structure. The Capture the Flag contest of DEF CON 4 (1996) formalized that chaos: judges now decided when a break-in earned a point. The first two contests were won by a player called AJ Reznor. The game’s roots are in the hacker culture of the 1980s and early 1990s, where breaking into systems was a status game long before it was a sport.

The rules stayed loose for years. At DEF CON 5 and 6, participants could either bring a target machine or attack provided ones, which the later organizers’ history describes as chaos on the game floor. A group called the Ghetto Hackers won in 1999 and 2000 and shared the 2001 title with digirev, and by DDTek’s account the contest in those years was “about equally as much about hacking the contest as hacking the game servers.” The scoring was manual and run by DEF CON staff (the “goons”), and it showed.

Organizers as Game Designers

After that run, the Ghetto Hackers switched sides and ran the contest from 2002 to 2004. They settled the shape it has kept since: a small number of teams (eight in 2002) each receive an identical server running custom network services written by the organizers, each with bugs planted in it; teams exploit the services on their rivals’ machines, steal flags, and patch their own copies without breaking them. The 2002 image was Red Hat 6.2, 2003 OpenBSD, 2004 Windows.

From then on DEF CON appointed an outside group to run the game for several years at a stretch, which gave each organizer time to build infrastructure and automated scoring. The lineage, as DEF CON lists it:

Years Organizer
1996–2001 “The People” (DEF CON goons)
2002–2004 Ghetto Hackers
2005–2008 Kenshoto
2009–2012 DDTek
2013–2017 Legitimate Business Syndicate
2018–2021 Order of the Overflow
2022–2025 Nautilus Institute
2026– Benevolent Bureau of Birds

As more teams wanted to play, a qualification round was added: an online weekend of challenges, with the top scorers invited to the finals in Las Vegas. DDTek introduced itself in 2009 with a prank. It was an unknown name when announced, and throughout DEF CON 17 nobody noticed that the people sitting at the table of the team “sk3wl0fr00t” were in fact running the game. DDTek was a subgroup of sk3wl0fr00t, which had won in 2004 and 2008; the award ceremony was met with shouts of “bullshit.”

Organizers kept raising the difficulty and hiding the game’s layout until the start. Legitimate Business Syndicate went furthest in 2017, building cLEMENCy, an invented processor architecture with 9-bit bytes, 27-bit registers and middle-endian byte order. It was designed so that no existing disassembler or debugger would work, which forced every team to write its tooling during the contest.

Jeopardy and Attack-Defense

Two formats share the name. Attack-defense, the DEF CON finals model, has every team running and defending the same services at once. Jeopardy, the model of most qualifiers and of the many smaller online CTFs, offers a board of independent puzzles in categories such as reverse engineering, binary exploitation, cryptography, web and forensics, each worth points, with no defending at all. Jeopardy is cheap to run and can take thousands of players over the internet, which is why most CTFs are of that type.

The university version of attack-defense began in California. Giovanni Vigna at UC Santa Barbara ran local security “live exercises” in 2001 and 2002 and in December 2003 the first wide-area edition, in which fourteen US teams (among them West Point, the Naval Postgraduate School and Georgia Tech) attacked one another’s services. In 2004 teams from Austria, Germany, Italy and Norway joined, and the event became the iCTF, the “international” CTF. Vigna’s students formed Shellphish, which won DEF CON CTF in 2005.

As the number of contests grew, a site called CTFtime started in 2012 to keep a calendar, archive write-ups and publish a worldwide team rating, because, as its about page says, most CTFs were “forgotten just after the CTF finished.” The rating turned a scattered hobby into a league table, and posting a write-up (a public walkthrough of how a challenge was solved) became the scene’s standard way of teaching.

The University Dynasty

The Plaid Parliament of Pwning (PPP) formed at Carnegie Mellon around 2009 under David Brumley, a professor of electrical and computer engineering. The name, Brumley said, came from the team’s liking for the letter P and CMU’s tartan: “‘plaid’ because the CMU color is plaid, and then we just had to make the rest work.” PPP won DEF CON CTF in 2013, 2014, 2016, 2017 and 2019.

From 2022 PPP played as part of a merged team, the Maple Mallard Magistrates, together with Maple Bacon (University of British Columbia, led by the CMU alumnus Robert Xiao) and members of The Duck from Theori, a security company founded by CMU alumni. MMM won four finals in a row, 2022 to 2025, which brought PPP’s count to nine DEF CON titles, the most in the contest’s history.

The streak ended at DEF CON 34 in August 2026. Blue Water, a coalition of Perfect Blue, Water Paddler and several other teams from different countries, had finished second three years running; this time it won with 578,103 points against 454,797 for the runner-up. Nine of its players were Georgia Tech doctoral students or postdocs.

From Game to Pipeline

A CTF scores the skills of attackers and vulnerability researchers in a way a school or an employer can read, and the format was soon adopted outside the hacker scene. In 2013 PPP and a CMU game-design team launched picoCTF, a free online competition for school students in grades 6 to 12, framed as a story in which a robot crash-lands in the player’s backyard and has to be hacked back to health. By 2017 it had drawn nearly 30,000 participants.

Other institutions built defense-only variants. The Collegiate Cyber Defense Competition, started in April 2005 by the University of Texas at San Antonio, has student teams defend a network against attackers instead of attacking each other. The European Cybersecurity Challenge, organized by the EU security agency ENISA, held its first edition in Fürstenfeld, Austria, on 3 November 2014 with three national teams. It runs national squads of players under 25 through jeopardy and attack-defense rounds. Germany has won it four times (2018, 2021, 2023, 2024), and Bochum is the 2026 host.

Machines at the Table

In 2014 DARPA announced the Cyber Grand Challenge, a CTF for programs instead of people. At the final, held in Las Vegas on 4 August 2016 alongside DEF CON 24, seven autonomous systems had to find, exploit and patch bugs in unknown software with no human help. Mayhem, built by the Pittsburgh firm ForAllSecure, won the $2 million first prize; second was Xandra ($1 million), third Shellphish’s Mechanical Phish ($750,000).

The prize included a seat at the human DEF CON CTF that same week, the first time a machine had played it. Mayhem finished last. The organizers noted that “many times throughout the game it was able to pull ahead of human teams.” The top three that year were PPP, b1o0p and DEFKOR.

DARPA ran a second machine contest, the AI Cyber Challenge (AIxCC), run with Anthropic, Google and OpenAI as partners, with its finals at DEF CON 33 in August 2025. Team Atlanta (Georgia Tech, Samsung Research, KAIST and POSTECH) won $4 million, Trail of Bits $3 million and Theori $1.5 million. According to DARPA, the finalist systems found 54 unique planted vulnerabilities in 54 million lines of code and patched 43 of them, and along the way turned up 18 real, previously unknown bugs in open-source projects.

In the human contest, the change arrived quietly. At the DEF CON 33 CTF, a Blue Water player learned that the team’s agentic AI tool had solved a challenge only when a judge told them they had already scored. DEF CON’s announcement of the 2026 organizers called it “an exciting novelty” and added: “This year, we expect that novelty to be the norm.”

📚 Sources