52 weeks. 52 vulnerabilities. 52 chances to level up.
Real vulnerabilities from production audits.
Every Monday. No exceptions.
The problem isn't that practice platforms don't exist.
- You finish the challenges. Then what?
- You wait for a new CTF. Then what?
- You do one audit competition. Then wait weeks for another.
There's no RHYTHM. No consistency. No weekly forcing function to get better.
Like trying to get fit by going to the gym once a month.
We're building something different inside our community.
Not another static challenge set.
Not another one-time CTF.
A WEEKLY release of real vulnerabilities.
- ✅ Every Monday. New challenge.
- ✅ New attack vector. New pattern to master.
- ✅ 52 challenges per year.
- ✅ 52 opportunities to level up.
- ✅ 52 weeks of consistent practice.
Because skill development needs FREQUENCY.
- One challenge per month = You forget what you learned
+ One challenge per week = You build muscle memoryThis is how our auditors got good:
→ Reviewing code EVERY WEEK
→ Finding bugs EVERY WEEK
→ Learning patterns EVERY WEEK
Not once a quarter. Not when a CTF drops.
Every. Single. Week.
|
❌ Finish the set, you're done |
✅ New challenge every Monday. Forever. |
The stuff we actually find in production.
This is how we train our junior auditors internally.
Now we're opening it to everyone.
The talent gap is real.
And the only way to close it is:
→ More researchers
→ Better training
→ Consistent practice
→ Weekly forcing function to improve
First challenge drops early February.
Then every Monday.
And the Monday after that.
52 weeks of getting better at breaking things.
- New challenge released — Real vulnerability from production code
- Submit your findings — Use our submission portal
- Compete on leaderboard — Weekly rankings + all-time stats
- Learn from solutions — Detailed writeups published after each week
📅 Week XX — [Vulnerability Type]
🎯 Difficulty: Progressive
🔍 Category: DeFi / NFT / L2 / Cross-chain
⏱️ Submission Window: Monday 00:00 UTC → Sunday 23:59 UTC- Speed — First to find gets bonus points
- Quality — Detailed writeups earn more
- Completeness — Find all bugs, not just one
- Impact — Higher severity = higher points
"I want to break into Web3 security but don't know where to practice."
"I've done the basics. Now I need real-world patterns."
"I learn best when there's a leaderboard and weekly deadlines."
"I want to go from 'interested in security' to 'actual researcher' in 6 months instead of 2 years."
Discord Community — Get notified about new challenges
Every Monday — New challenge drops
Use the submission portal (link in Discord)
Weekly leaderboard + cumulative rankings
Progressive challenges covering:
- ✅ DeFi Exploits — Reentrancy, flash loans, oracle manipulation
- ✅ Access Control — Privilege escalation, authorization bypasses
- ✅ Economic Attacks — Incentive misalignment, MEV vulnerabilities
- ✅ Cross-Chain Issues — Bridge exploits, message verification
- ✅ NFT Vulnerabilities — Minting exploits, metadata manipulation
- ✅ L2 Security — Rollup bugs, state management issues
- ✅ AI Agent Risks — Prompt injection, execution vulnerabilities
- ✅ Advanced Patterns — Zero-day discoveries from our audit portfolio
challenges/
├── week-01-reentrancy-defi/
│ ├── challenge.md
│ ├── contracts/
│ ├── solution.md (released after deadline)
│ └── leaderboard.md
├── week-02-access-control/
├── week-03-oracle-manipulation/
└── ...
Each week includes:
- Challenge description & scope
- Vulnerable contract code
- Submission guidelines
- Solution writeup (published Monday after)
- Weekly leaderboard
52 weeks. 52 vulnerabilities. Real production patterns.
This is how you go from interested to researcher.
Not in 2 years. In 6 months.
|
Join Community |
@Radcipher |
radcipher.com |
| Metric | Value |
|---|---|
| Challenges Released | TBA |
| Active Participants | TBA |
| Vulnerabilities Found | TBA |
| Average Completion Time | TBA |
| Top Researcher | TBA |
Q: When does the first challenge drop?
A: Early February 2025. Then every Monday after.
Q: Are these real vulnerabilities?
A: Yes. Pulled from our production audit findings (sanitized for privacy).
Q: What if I can't solve it in one week?
A: Solutions are published the following Monday. You can still practice on past challenges anytime.
Q: Is there a prize?
A: Weekly leaderboard recognition + cumulative reputation. Top performers get noticed by our team for opportunities.
Q: Do I need to be an expert?
A: No. Challenges start easy and progressively get harder. Perfect for learning.
Q: What tools do I need?
A: Foundry, Hardhat, or your preferred testing framework. We'll provide setup instructions.
Every Monday. Forever.
We're building the weekly practice ground we wish existed.
© 2025 Radcipher — Building the next generation of Web3 security researchers