The recursive split
2016 DAO-style recursive withdrawal. An attacker exploited a reentrancy flaw to drain a public investment fund before the balance was zeroed.
▦ The range for Web3 security
Train on real exploits. Break realistic systems. Build a reputation that protocols trust — from complete beginner to Principal Researcher.
→ The loop
Anyone can hide a flag in a contract. 0xRange trains the full loop a working researcher runs — exploit, explain, and write the finding that gets a protocol to pay attention.
Exploit a faithful recreation of a real vulnerability on an isolated testnet. Watch the target’s balance and storage flip live as the attack lands.
A side-by-side post-mortem puts the vulnerable code next to the patched version, so you see exactly what the one-line fix changes.
Turn the exploit into a structured audit report — severity, impact, PoC, remediation. This is the differentiator: real auditor output, not a flag.
the moatEvery solve banks XP up the hex ladder, 0x00 → 0xFF, and lands on a public profile that recruiters and protocols can verify.
◇ The ladder
Seven tiers from 0x00 to 0xFF. XP from labs, 0xPuzzles and quizzes all climb the same ramp — and from 0x9F Auditor up, you can earn a verifiable certificate.
▦ Incident recreations
Faithful sandboxed reconstructions of landmark exploits. Run the same attack, read the same post-mortem.
2016 DAO-style recursive withdrawal. An attacker exploited a reentrancy flaw to drain a public investment fund before the balance was zeroed.
Ronin-style validator-key compromise on a cross-chain bridge. Attacker obtained majority validator signatures to authorise fraudulent withdrawals.
Wormhole-style signature-verification bypass on a cross-chain bridge. A missing validation step allowed fabricated guardian signatures to pass.
Recreations are educational reconstructions on isolated testnets, for responsible learning and disclosure — never to target live systems.
▦ What you get
No real chain, no real funds. Break anything, replay as often as you like.
Briefing → Code → Exploit → Post-Mortem → Report. The whole workflow, not a flag.
Every solved lab becomes a portfolio-grade finding on your public profile.
A zero-Solidity on-ramp — learn to think like an attacker before you read code.
A fresh puzzle every day, with a streak to keep you sharp.
Themed knowledge checks that teach from every answer, right or wrong.
XP from everything you do climbs one public ranking of the range.
Learn offence to build defence — ethically, on isolated systems, every time.
The channel and the range are one classroom. Watch an exploit unfold, then reproduce it yourself. The two reinforce each other.
◇ Step onto the range
Start with a puzzle, break your first contract, and write a finding worth showing — all free, all in a sandbox. No setup, no real funds, no risk.
Isolated sandbox · no real chain · no real funds · no setup required