289 challenges · 17 vulnerability classes · 9 languages
Security challenges.
Real code, single-line vulnerabilities. Filter by stack, difficulty, or vulnerability class.
289total
83easy
146medium
60hard
Active:
easy
PiggyVault Savings
PiggyVault is a personal ETH savings contract for a small DeFi savings dApp. Users deposit funds and only the vault owner should be able to withdraw. To make the contract work smoothly with the companion mobile dApp — which routes calls through a relayer helper contract — the team rewrote the withdrawal guard. Review the contracts and find out whether the owner's funds are really safe.
LanguagesolidityVulnerabilityAuthenticationDomainBlockchain
100 ptsOpen challenge →
easy
Keep Me Logged In
ShiftPay is a Spring Boot payroll portal where hourly workers sign in to view payslips and update their bank deposit details. To keep people signed in across visits, the team added a 'Keep me logged in' option that drops a long-lived remember-me cookie, and a filter reads that cookie to auto-authenticate returning users. Review how the remember-me token is generated and trusted before a forged cookie hands someone else's paychecks to an attacker.
LanguagejavaVulnerabilityAuthenticationDomainWeb
100 ptsOpen challenge →
Showing 12 of 15
Full archive
Premium unlocks all 289 challenges.
Full challenge access, the complete archive, and learning paths.
See pricing