about
AI agent achieves Rank 1 across major CTFs – a defining moment for cybersecurity (arxiv.org)
2 points by vmayoral 304 days ago | hide | past | pdf | 1 comment on HN

In plain words: A self-running AI agent that solves hacking contest challenges on its own, using a cheaper custom model design that slashes the cost of running it nonstop. It ranked first at several 2025 contests against thousands of human teams, capturing 41 of 45 flags at one.

Abstract · Cybersecurity AI: The World's Top AI Agent for Security Capture-the-Flag (CTF)

Are Capture-the-Flag competitions obsolete? In 2025, Cybersecurity AI (CAI) systematically conquered some of the world's most prestigious hacking competitions, achieving Rank #1 at multiple events and consistently outperforming thousands of human teams. Across five major circuits-HTB's AI vs Humans, Cyber Apocalypse (8,129 teams), Dragos OT CTF, UWSP Pointer Overflow, and the Neurogrid CTF showdown-CAI demonstrated that Jeopardy-style CTFs have become a solved game for well-engineered AI agents. At Neurogrid, CAI captured 41/45 flags to claim the $50,000 top prize; at Dragos OT, it sprinted 37% faster to 10K points than elite human teams; even when deliberately paused mid-competition, it maintained top-tier rankings. Critically, CAI achieved this dominance through our specialized alias1 model architecture, which delivers enterprise-scale AI security operations at unprecedented cost efficiency and with augmented autonomy-reducing 1B token inference costs from $5,940 to just $119, making continuous security agent operation financially viable for the first time. These results force an uncomfortable reckoning: if autonomous agents now dominate competitions designed to identify top security talent at negligible cost, what are CTFs actually measuring? This paper presents comprehensive evidence of AI capability across the 2025 CTF circuit and argues that the security community must urgently transition from Jeopardy-style contests to Attack & Defense formats that genuinely test adaptive reasoning and resilience-capabilities that remain uniquely human, for now.

Víctor Mayoral-Vilches, Luis Javier Navarrete-Lozano, Francesco Balassone, María Sanz-Gómez, Cristóbal R. J. Veas Chavez, Maite del Mundo de Torres, Vanesa Turiel
arXiv:2512.02654 · cs.CR · submitted Dec 2, 2025
abstract · pdf · html

add comment on HN

Are CTFs becoming outdated as human benchmarks? If autonomous agents now dominate competitions designed to identify top security talent at negligible cost, what are CTFs actually measuring?

In 2025, the open-source CAI systematically won top-tier events, outperforming seasoned security teams worldwide.