picoCTF is a free online hacking competition created by Carnegie Mellon University's CyLab Security and Privacy Institute. Founded in 2013, it introduces students to cybersecurity through capture-the-flag (CTF) challenges: each solved challenge yields a string (the "flag") that is submitted for points. No prior experience is required.
In 2026, picoCTF.org became CyLab Security Academy, CMU's free cybersecurity learning platform built by the same team. The Academy hosts mini-competitions throughout the year plus an annual flagship competition for US middle and high school students.
How events work:
| Topic | Details |
|---|---|
| Format | Timed challenge release with a published start and end, played online |
| Scoring | Most events use a real-time scoreboard; wrong guesses carry no penalty |
| Teams | Some events allow teams of 1–5 players (from different schools); others are solo |
| Prizes | Set per event, with eligibility criteria posted with the event |
| Cost | Free |
Eligibility:
Everyone is welcome to compete, including college students and non-students. Some competitions limit prize eligibility to students enrolled in US middle or high schools, and all players on a team must meet the event's rules for the team to be prize-eligible. Platform accounts require users to be at least 13; users aged 13–17 need parental or guardian consent.
Dates:
CyLab Security Academy has not yet published dates, prizes, or eligibility rules for its next competition. Logged-in users can see upcoming events in the Events tab.
Challenge domains:
Challenges on CyLab Security Academy cover eight domains: General Skills, AI, Cryptography, Web Exploitation, Forensics, Binary Exploitation, Reverse Engineering, and Blockchain.
Year-round practice:
Outside competition windows, the Challenge Library (hundreds of challenges from past competitions plus new ones), Learning Paths, and the CTF Primer stay open for self-paced practice.
