Welcome to the first embedded hardware CTF, round two


  • You can play individually or in teams. Teams should always use one shared account to score their flags, and never score flags in more than one account.
  • You are allowed to use any means you consider necessary to solve the challenges, except attacking the infrastructure hosting the challenges.
  • Sharing solutions is not allowed. If we identify any teams or individuals sharing solutions, they will be immediately disqualified and not eligible for any prizes.
  • Riscure will only provide one board per participant. Since some challenges (esp. fault injection) could damage the board, we recommend attempting these challenges after challenges in the other categories have been attempted/solved.
  • We have tested all boards before shipment. If your board was dead on arrival please contact us, we'll see what we can do. However, we cannot guarantee replacements since we have a limited number of boards available.
  • In order to be eligible for prizes, the top 3 teams are expected to deliver write-ups to Riscure describing their approach to each challenge. Riscure reserves the right to disqualify teams if the write-ups are not sufficiently complete.
  • Using an attack on the bootloader to retrieve flags from other challenges is not allowed. You are free to do so if you wish, but such solutions will not be eligible for any prizes.
  • Riscure reserves the right to update these rules if deemed necessary during the contest.

Follow @Riscure