Last updated 27 September 2026
The one rule. Only attack the 0xRange sandbox, or systems you own or have explicit written permission to test. Everything else follows from that.
Testnet-only, educational use
Every lab is a sandboxed recreation. The incidents they are based on — bridge compromises, reentrancy drains, oracle manipulation — really happened, and the protocols involved (and others like them) are live systems with real users. The range exists so that you never need to practise on them.
You must not
- Use anything you learn or build here against a system, contract, wallet or network that you do not own or are not authorised in writing to test — including the live protocols named in lab briefings. Unauthorised access is a criminal offence under the Computer Misuse Act 1990 and equivalent laws elsewhere.
- Attack 0xRange itself outside our responsible disclosure policy— no denial-of-service, credential stuffing, brute forcing, mass scanning or attempts to reach other users’ data.
- Script, automate or otherwise manipulate completions, XP, leaderboards, streaks, achievements or certificates, or submit audit reports that are not your own work.
- Publish complete step-by-step solutions to labs in a way designed to let others skip the work. Writing about what you learned is welcome; spoilers that undermine the range are not.
- Use the AI Mentor (where available) to seek help attacking real systems, to extract other users’ information, or to get around its safety rules.
- Get around plan limits, rate limits, paywalls or access controls.
- Post content in your profile or reports that is unlawful, harassing, discriminatory, sexually explicit, infringes someone else’s rights, or contains malware or personal data about other people.
- Impersonate another person or organisation, or misrepresent a 0xRange certificate.
If you find a real vulnerability
Skills from the range may lead you to notice a genuine flaw in a live system. If that happens, do not exploit it. Report it privately to the project through its published channel — a security.txt file, its bug-bounty programme or its security contact — and give it time to fix the problem before saying anything publicly. If the flaw is in 0xRange, see our responsible disclosure policy.
Enforcement
If you break these rules we may remove content, reset progress, revoke achievements or certificates, and suspend or close your account. Where we believe a crime has been or is about to be committed we may report it to the relevant authorities.
Questions about whether something is allowed? Ask first at hello@0xrange.com.