bmenrigh
9 hours ago
I'm one of the BSidesSF CTF organizers and challenge authors (symmetric). The article is a few months old now (May) which is ancient history as far as AI advancements go. That said, I'm still emotionally coming to terms with what happened.
Speaking from my own perspective (and not any of my challenge co-authors), I felt completely blindsided by the incredible progress frontier models made in solving CTF challenges between 2025 and 2026. We've been running the BSidesSF CTF for more than 10 years now, gaining experience on what makes a good, fun, and fair (solvable without random guessing) CTF challenge. 2026 was the first year where all of our past experience didn't seem to apply. Challenges that I designed to be hard, that I expected to take a dedicated human 10-20 hours to solve, fell to LLM automation in minutes.
I don't know what the future of CTFs is going to be, but I wouldn't be surprised if they're largely dead in 1-2 years. A lot of the satisfaction I get from making challenges is in seeing players struggle, learn, and then eventually solve them. I'm not sure there are going to be many players willing to sink 20 human hours of their weekend into one challenge when a dozen teams using AI solved the challenge in under an hour.
Overall I'm thrilled with the capabilities we're getting with AI, but saddened by what we're losing. I hope CTFs can somehow hold on, and that I can still get a lot of satisfaction out of building challenges and having players solve them.
arecsu
5 hours ago
Maybe they will evolve to search actual exploits live in a competition or something like that :) or a marathon to research jailbreaks for certain devices and give control back to the user, like smart tvs, I don't know! Something that would be more involved and maybe real. It's just a matter of rising the difficulty, and the bright side could be that it might be used for something even more creative and good!
binary132
4 hours ago
I think there will definitely still be people interested in understanding these sorts of things (that is: solving CTF’s without automatic assistance), even if at the end of the day they solve them using automation when it comes to a professional context. What I am more afraid of is people giving up and losing hope that there is any reason for humans to develop and understand systems. We need to keep in mind that even very powerful automation is still a tool for a human to make use of, and that is something I’m not confident many people are able to be conscious of. It’s a little like believing that an advanced CNC machine makes carpentry pointless to practice or understand, since now a computer can just do it.