The recursive split
2016 DAO-style recursive withdrawal. An attacker exploited a reentrancy flaw to drain a public investment fund before the balance was zeroed.
▦ The cyber range for crypto defenders
Wallets, contracts, exchanges, bridges and DeFi systems fail in specific, learnable ways. Exploit faithful recreations on a sandboxed testnet, then read the fix beside the flaw. Beginner to auditor, defence-first.
→ How it works
01 — LEARN
Theory, annotated vulnerable contracts, and the patched version side by side.
02 — PRACTISE
Live workspace, a real objective, a live target, progressive hints.
03 — EARN
Solved labs build verifiable reputation and rank.
▦ Incident recreations
Faithful sandboxed reconstructions of landmark exploits. Run the same attack, read the same post-mortem.
2016 DAO-style recursive withdrawal. An attacker exploited a reentrancy flaw to drain a public investment fund before the balance was zeroed.
Ronin-style validator-key compromise on a cross-chain bridge. Attacker obtained majority validator signatures to authorise fraudulent withdrawals.
Wormhole-style signature-verification bypass on a cross-chain bridge. A missing validation step allowed fabricated guardian signatures to pass.
Recreations are educational reconstructions on isolated testnets, for responsible learning and disclosure — never to target live systems.
The channel and the range are one classroom. Watch an exploit unfold, then reproduce it yourself. The two reinforce each other.