288 challenges · 17 vulnerability classes · 9 languages
Security challenges.
Real code, single-line vulnerabilities. Filter by stack, difficulty, or vulnerability class.
288total
82easy
146medium
60hard
hard
Atomic Zap Router
ZapRouter is a gas-saving helper for an NFT marketplace that lets users batch several on-chain actions into one transaction. Power users call multicall(bytes[]) to mint multiple Genesis Pass NFTs atomically without paying gas for each individual call. The team prides itself on a tiny, audited core. Review the batching logic and the priced mint path — does paying for a batch always cost what it should?
LanguagesolidityVulnerabilityWeb3DomainBlockchain
200 ptsOpen challenge →
easy
Keep Me Logged In
ShiftPay is a Spring Boot payroll portal where hourly workers sign in to view payslips and update their bank deposit details. To keep people signed in across visits, the team added a 'Keep me logged in' option that drops a long-lived remember-me cookie, and a filter reads that cookie to auto-authenticate returning users. Review how the remember-me token is generated and trusted before a forged cookie hands someone else's paychecks to an attacker.
LanguagejavaVulnerabilityAuthenticationDomainWeb
100 ptsOpen challenge →
medium
Unlock The Door
SmartHome is an Android app that pairs with smart locks, lights, and cameras around the house. A background service listens for internal app events to react instantly when the homeowner taps 'Unlock' on their phone or on the paired smartwatch. Review the event wiring that drives the lock hardware and decide whether anything other than the SmartHome app itself can trigger it.
LanguagekotlinVulnerabilityAuthorization & Access ControlDomainMobile
150 ptsOpen challenge →
Showing 12 of 288
Full archive
Premium unlocks all 288 challenges.
Full challenge access, the complete archive, and learning paths.
See pricing