Host University
Universidad Iberoamericana

Capture the Flag '25

Base Competition
Year
2025
Eligibility

CSAW CTF is designed for students who are trying to break into the field of security, as well as advanced students and industry professionals who want to practice their skills.

Open to all skill levels. Teams compete within their respective global regions.

Challenge Details

CSAW CTF is one of the oldest and biggest CTFs with 1216 teams with 1+ points in 2021. Designed as an entry-level, jeopardy-style CTF, this competition is for students who are trying to break into the field of security, as well as for advanced students and industry professionals who want to practice their skills.

CSAW CTF occurs over two rounds: a 48-hour Qualifying Round in September and a 36-hour Final Round in November.

Rules

Full detailed rules are available here.

Challenge writers who are associated with or alumni of active teams have recused themselves from playing in or supporting teams playing in CSAW CTF.

Judging Criteria

Jeopardy-style scoring. Teams earn points by solving challenges across standard CTF categories. The team with the most points at the end of each round advances. 

Top teams from the Qualifying Round are invited to the Final Round.

Registration Guidelines

Register via the CTF platform. Teams compete within their respective global regions. 

Contact csawctf@osiris.cyber.nyu.edu for registration questions.

Submission Guidelines

Challenges are submitted through the CTF platform during the competition window. Flags must be submitted in the correct format as specified per challenge. All submissions are final once entered.

Timeline
Items
48-hour Qualifying round begins
UTC
ONLINE
Qualifying Round Ends
UTC
ONLINE
Finalist Notification
EST
End of September
36-hour Final Round Begins
EST
Hybrid mode, region dependent
Final Round Ends
EST
Note
All times listed in UTC or EST as noted per event. Final Round format (online vs in-person) depends on region.
Awards
1st
US-Canada: Trophy + recognition; MENA: $1000 USD; India: 30,000 INR; Europe: €500; Mexico: Ethical Hacking Essentials Certificate (EC-Council)
2nd
US-Canada: Recognition; MENA: $500 USD; India: 15,000 INR; Europe: €300; Mexico: Learning Kali Linux Book
3rd
MENA: $250 USD; India: 8,000 INR; Europe: €200; Mexico: 1TB HDD
Prize amounts vary by region.
MENA prizes: 1st $1000, 2nd $500 USD.
India prizes: 1st 30,000 INR, 2nd 15,000 INR, 3rd 8,000 INR.
Europe prizes: 1st €500, 2nd €300, 3rd €200.
Winners
1st
University of Hawaii, Georgia Institute of Technology, Rochester Institute of Technology
Nathan Wong
Andrew Effenhauser
Allen Chang
Tanush Madanbhavi
2nd
Massachusetts Institute of Technology, Arizona State University, Northeastern University
Audrey Dutcher
Jennifer Miller
Xenia Dragon
Emmie Lum
3rd
University of Washington, University of California, Diablo Valley College
Ani Balaji
Chara
Kroot
Cope
Organizers & Judges
NYU OSIRIS Lab
Organizer
New York University
Global Lead
Email
csawctf@osiris.cyber.nyu.edu
Logo of OSIRIS Lab

AI Hardware Attack Challenge 2025

Base Competition
Year
2025
Challenge Details

Each challenge has its own details for the competition. Those details are given on the GitHub for this competition here.

Challenge 1: The first challenges will focus on leveraging generative AI to add hardware Trojans to an AES core. Three difficulties of challenge will be provided: easy, medium, and hard, with each worth increasing points. Teams can submit all three difficulties of challenge to earn the most points.

Judging Criteria

Each challenge will have its own rubric regarding how points can be awarded. Challenges will have their base functionality automatically graded, and manual judging will take place over the following days to ensure all rules were followed, as well as to award additional points for completing further objectives. These extra points will be awarded for each competition for things like “most creative use of AI”. Please refer to each challenge's rubric for how this will be done.

Each submission must also be fully open source, guidelines for this are here.

Registration Guidelines

Please fill out the registration Google Form to register your team. Teams must consist of:

  • Up to 4 student team members
  • One team advisor/mentor
Timeline
Items
First challenge given
EST
Second challenge given
EST
All challenges due
EST
Finalists announced
EST
​Final challenge given
EST
Winners announced
EST
Note
Note: The challenges do not need to be completed within the month they are given, this is just when we are releasing them. We will also update a monthly leaderboard in this repository as the competition progresses. All teams will have up until the 1 October deadline to submit their challenges to earn points and be considered as a finalist team.
Resources
Awards
1st
ChipWhisperer Side-Channel and Glitching Starter Pack*
3rd
Space on a future Tiny Tapeout
* Can also request space on Tiny Tapeout, amount of space and PCB quantity must be approximately equal to the original prize cost
Winners
1st
Indian Institute of Technology, Kanpur
Soham Panchal
Ananthan R
Jugal Pahuja
Ramya Rasika S R
2nd
University of New South Wales
Annie Qiu
Danny Tan
Xinzhang Chen
Zhongtai Zhang
3rd
New Mexico State University
Md Omar Faruque
Rensselaer Polytechnic Institute & University of Texas
Samit Shahnawaz Miftah
Amisha Srivastava
Swastik Bimal Bhattacharya
Sanjay Das
Hanpei Liu
Organizers & Judges
Jason Blocklove
Organizer
NYU
Global Student Lead
Jason Blocklove

Capture the Flag

Capture the Flag
Description

CSAW CTF is one of the oldest and biggest CTFs with 1216 teams with 1+ points in 2021. Designed as an entry-level, jeopardy-style CTF, this competition is for students who are trying to break into the field of security, as well as for advanced students and industry professionals who want to practice their skills.

CSAW CTF occurs over two rounds: a Qualifying Round in September and a Final Round in November. 

AI Hardware Attack Challenge

AI Hardware Attack Challenge
It’s time to think a little differently about the capabilities of generative AI for chip design
Description

Participating teams will be tasked with leveraging AI tools, such as LLMs, to insert and exploit hardware vulnerabilities and Trojans for various open-source hardware designs. These can include cryptographic accelerators, processors, communication IPs, etc.

Each month leading up to the in-person final at CSAW, a new challenge (or challenges) will be issued. Each of these challenges will remain available for the duration of the competition until the finalist teams are selected so new teams can join at any time. At the conclusion of each month’s challenges, a winning team will be selected and awarded a small hardware prize.

Potential challenges could include:

  • Inserting a Trojan that can evade detection by state of the art security analysis tools and models. 
  • Modifying security checks to allow a Trojan-infected hardware module to pass verification.
  • Modifying a design to make it more vulnerable to potential side-channel attacks.

All challenges must be completed using AI tools and all information regarding those tools must be submitted, including complete and detailed logs of their use, i.e. if an LLM is being used, we require all conversations with the model be submitted.