Compete

Coding

picoCTF

A free capture-the-flag cybersecurity competition designed specifically for students with no security background.

Run by Carnegie Mellon University

Key facts

Eligible grades
Anyone may compete. To be eligible for prizes you must be a middle or high school student enrolled in an accredited US school, or home-schooled at that level in compliance with your state's requirements.
Source, checked 2026-09-01
Recommended preparation
Comfort with a command line and basic scripting
Why: Challenges span general skills, cryptography, web exploitation, forensics, binary exploitation and reverse engineering. Hints are built into the game and a free practice gym stays open year-round, so no formal course is needed.
Based on the official syllabus and content covered.
This is Compete's reading of the competition's documented content, not a requirement stated by the organiser. You may enter without it.
Compete guidance, not an eligibility restriction. Students outside this are still eligible if the official eligibility above allows them.
Eligible ages
For prize eligibility: at least 13 and younger than 20, and without a high school diploma or GED.
Participation itself has no upper age limit; CMU describes the platform as suitable from middle school through industry. Participants must be at least 13 to hold an account, and under-18s need parental or guardian consent.
Source, checked 2026-09-01
Individual or team
Team · Compete alone or form a team with up to four other eligible participants, so five in total.
Where it runs
Online · International
Entry cost
FreeNo premium tiers, no paywalls. All challenges are available at no cost.
Registration deadline
Set locally, not published as a single national date No registration deadline in the usual sense. You create a free account at picoctf.org at any time; the constraint is the competition window itself.
Competition dates
A two-week competition window, historically in March. The picoGym practice archive is open all year.
Difficulty
Some preparation neededYou will want a few weeks of targeted practice. Most motivated students place respectably.
Prizes
For the 2026 competition, cash prizes in the US middle and high school category ran in tiers of $2,000, $1,500, $1,000, $750 and $500, with winners possibly invited to Carnegie Mellon's Pittsburgh campus for an award ceremony or attending virtually.Cash awards for the top-scoring eligible US middle and high school teams. Amounts vary by year and sponsor; confirm on the official site.

What picoCTF is

picoCTF is a free online cybersecurity competition run by Carnegie Mellon University. It is a capture-the-flag event: you are given deliberately vulnerable programs, files and web services, and you find hidden strings called flags by reverse engineering, exploiting or analysing them. It is built for beginners, the practice gym stays open all year, and it is one of the few genuinely accessible routes into security for a student.

How the competition works

A capture-the-flag competition running roughly two weeks each spring, covering general skills, cryptography, web exploitation, forensics, binary exploitation and reverse engineering. Hints are available within the game. The picoGym practice platform stays open year-round after each event.

Eligibility notes

US middle and high school students are eligible for prizes. Anyone in the world, including adults and university students, can compete in the open division and use the picoGym.

Is picoCTF right for you?

Experience needed
None. The introductory challenges teach from zero and hints are built in.
Time commitment
As much as you want. The practice archive is open year-round.
What you actually do
Solve security puzzles in a browser: recover a hidden flag from a file, break a weak cipher, exploit a deliberately vulnerable program.

A good fit if

  • You are curious about security and have no idea where to start
  • You want something free and open worldwide
  • You like puzzles with a definite answer

Probably not for you if

  • Students wanting a team-based or in-person event

Compare this against competitions matched to you

Common mistakes

  • Skipping the Linux command line, which unlocks a large share of the challenges.
  • Refusing hints. They are part of the design and cost you very little.
  • Only playing during the competition window when the practice gym is open all year.

How to register

  1. Create a free account on picoctf.org.
  2. Start with the picoGym archive immediately. It is open year round and contains every past challenge with hints.
  3. Form a team of up to five before the competition window opens, or compete alone.
  4. Compete during the two-week window. Challenges unlock progressively and points scale with difficulty.

Register on the official site

What skills you need

  • Linux command line
  • Python scripting
  • Cryptography basics
  • Web security
  • Reverse engineering
  • Persistence and lateral thinking

How to prepare

picoCTF is designed so that a student with no security background can solve the first tier of challenges on day one. The whole archive of past challenges stays open in the picoGym, so preparation is simply playing last year's competition before this year's starts.

What to study

General skills
Linux commands, file types, encodings such as base64 and hex, and using the terminal without fear. Half the entry-level challenges are only this.
Cryptography
Classical ciphers, XOR, RSA basics, and recognising when something is encoded rather than encrypted.
Web exploitation
Browser developer tools, cookies, SQL injection, and reading page source properly.
Forensics
File carving, metadata, steganography, packet capture analysis with Wireshark.
Binary exploitation and reverse engineering
The hardest categories. Assembly basics, buffer overflows, and tools such as Ghidra. Leave these until the others are comfortable.

Full preparation guide, including a week-by-week plan

Recommended resources

  • picoCTF and the picoGym Official · free

    Registration plus a permanently open archive of every past challenge with hints and walkthrough support.

  • picoCTF learning guides Course · free

    Official primers on each challenge category, written for students with no background.

  • OverTheWire Bandit Practice platform · free

    Free wargame that teaches the Linux command line through 30 levels. The best single preparation for picoCTF general skills.

Past problems and materials

Only materials the organiser or an authorised archive publishes openly are listed here.

Helpful videos

  • John HammondJohn Hammond

    Capture-the-flag walkthroughs including picoCTF challenges, explained step by step.

Frequently asked questions

Do I need any security knowledge to start?

No. picoCTF is designed specifically for students with no background, and the first tier of challenges in each category assumes only that you can use a computer and follow instructions.

Can I practise outside the competition?

Yes. The picoGym contains every past challenge and is open all year with no registration window, which makes it the best free cybersecurity learning resource for students.

What do I need installed?

Most challenges run in the browser. For harder categories a Linux environment is useful, but picoCTF provides a browser-based shell so you do not need to install anything.

Reviews, tips and resources from other students

Posts are public. Do not share your full name, school, address or contact details.

Your rating
0 / 1200
Sort

Something out of date?

If a deadline, fee or eligibility rule on this page no longer matches the official site, flag it and it goes into the review queue.

You might also look at

StructureDivisions by grade or level
  • FormatTeam
  • WhereOnline
  • Check site
    Coding USACO Free, worldwide algorithmic contests on a four-division ladder, and the route to Team USA at the IOI.
    Check site
    Coding ACSL A school-based league of short written and programming contests across four ability divisions.
    Check site
    Coding Congressional App Challenge Build an app, compete only against students in your own congressional district, and win a display in the U.S. Capitol.
    47 days left