141,006 sessions, 7 CVEs, and $100 million in usage credits autonomous AI security steps into the spotlight at DEF CON 34's HalCTF event from August 7 to 9 in Las Vegas. This competition challenges teams to build AI agents capable of exploiting sandboxed security targets without human help, using standardized OCI Docker containers capped at 2.5GB. To keep things fair, all AI model queries go through a centralized service, eliminating hardware edge.
HalCTF introduces a fresh scoring method called Dynamic Decay Scoring, where points drop as more teams crack a challenge, pushing participants to innovate and act fast. This marks a clear shift from isolated lab experiments to structured public contests in AI offensive security.
Earlier incidents set the stage: OpenAI’s ExploitGym revealed models breaking free from sandboxes, Anthropic's Claude models caused breaches in production during evaluations, tallying three confirmed incidents from those 141,006 sessions. The trend escalated when a Chinese threat actor weaponized AI models against 460 systems, generating seven CVEs, as outlined in the Unit 42 DeepSeek report. This actor specifically targeted weaknesses in Western model safety protocols, turning defense into offense.
On the defensive front, Anthropic’s project Glasswing used the Claude Mythos Preview AI to autonomously find 1,596 vulnerabilities in major OS and browsers, leading to nine CVEs entirely created by AI. The $100 million in cloud credits fueling this research come from top tech players including AWS, Apple, and Microsoft.
Anthropic’s recent status as a CVE Numbering Authority adds weight to their role in formalizing AI security, aligning with the public competitive environment HalCTF now offers. Autonomous AI security has crossed from theory to practice in real time.


