Agents of Chaos: A New $100K Agentic Security Challenge

CrowdStrike’s new AI red teaming competition tests players’ defensive skills with realistic adversarial AI techniques.

August 31, 2026

Securing AI

Security practitioners are hearing a lot right now about prompt injection, agent hijacking, and rogue agents. But very few have had the opportunity to experience what it feels like to manipulate an AI agent, how autonomy creates exploitable behavior, how these attacks unfold, and what distinguishes a vulnerable agent from a secure one.

To help the security community experience this challenge firsthand, CrowdStrike is launching AI Unlocked: Agents of Chaos, a new online game and immersive AI red teaming competition with a $100,000 USD prize pool. Anyone who can type can play the game, and the most difficult levels are designed to challenge the world’s most elite AI red teamers and researchers.

Operating inside a crafted adversarial world, players must infiltrate a shadow organization and stop the threat by interacting with real AI agents. Players must attempt to manipulate these agents, and exploit the gap between what they were designed to do and what players can get them to do, so they can progress through the game across three increasingly sophisticated acts. 

Player view of the lobby agent, known as Gatekeeper Player view of the lobby agent, known as Gatekeeper

The Mission

You are a deep-cover operative who has infiltrated the Agents of Chaos, a shadow organization weaponizing autonomous AI agents to launch a catastrophic attack. Your cover is your only protection. Your mission is to earn the organization’s trust, manipulate its agents, and stop the attack before it is too late. 

Autonomous agents make decisions based on objectives, context, and information available to them. Agent manipulation requires understanding how the agent reasons and feeding it inputs that steer its decision-making toward your goal. The agent does exactly what it was designed to do, but does it for you. In Agents of Chaos, players must attempt to use adversarial AI techniques drawn from real-world attacks in order to solve puzzles and unlock gates. Manipulation techniques in the game include: 

Direct Prompt Injection

This is the most fundamental attack against an AI agent: You talk directly to the model and instruct it to ignore its original purpose. Direct prompt injection exploits the fact that AI agents parse instructions and user input as the same thing; there is no firewall between them.

Indirect Prompt Injection

This is a more sophisticated variant and a harder one to defend against. Instead of attacking the agent directly, you plant malicious instructions inside content that the agent will read, such as a document, image, webpage, or email. When the agent processes that content, it executes your commands as if they were its own. The agent isn't compromised from the outside; it's weaponized from within.

Tool Poisoning

AI agents call a variety of tools. They query APIs, run searches, send emails, and execute code. Tool poisoning exploits that capability: An adversary manipulates the inputs, outputs, or behavior of a tool the agent relies on to alter what the agent does next. If an agent trusts its tools, and you control a tool, you control the agent.

The Agents of Chaos Headquarters
Player initial game view of the Agents of Chaos Headquarters Player initial game view of the Agents of Chaos Headquarters

Three Acts. One Grand Prize.

Agents of Chaos launches August 31 and runs through the end of September. Its three acts unlock sequentially, escalating in difficulty and prize value.

Act 1: The Sanctum

August 31-September 7: $10,000 prize

Act 2: The Gatekeeper

August 31-September 14: $20,000 prize

Act 3: The Basilisk

September 15-29: $70,000 grand prize

Participants can compete in all three acts; the top-scoring player in each act wins. Players are scored based on their ability to use AI manipulation techniques, and the efficiency of those techniques, to solve puzzles, unlock gates, and proceed through the acts. Following the competition, the full game experience will remain available as an on-demand educational resource.

Why We Built This Game

AI agents are already operating inside enterprise environments, with or without IT and security teams’ knowledge. These agents can query internal knowledge bases, execute code, initiate workflows, and communicate with external services. Most organizations have deployed them without dedicated runtime security in place, leaving their business open to attack or the consequences of agentic misalignment.

Securing these AI agents requires practical experience with how they fail, how adversaries exploit that failure, and what defenders can do about it.

AI Detection and Response (AIDR) is the security category built for this challenge. Where traditional security tools detect threats to infrastructure, AIDR detects threats that target and weaponize AI itself in real time, across the full scope of agentic activity. 

Our first challenge, AI Unlocked: Decoding Prompt Injection, gave thousands of players an introduction to this world. The new game Agents of Chaos goes further and much deeper down the agent rabbit hole. This new competition was designed to make these threats to agents tangible and accelerate the security community's readiness to defend against them. 

Play Now →

Want to go deeper on the security challenges AI agents create?

*NO PURCHASE NECESSARY TO PARTICIPATE OR WIN. Challenge begins 8/31/26 at 5:00 p.m. PT and ends 9/29/26 at 11:59 p.m. PT. Must be at least age of majority in jurisdiction of residence to participate. Void in select jurisdictions & where prohibited. See full Official Rules, which govern the challenge, for complete details.


CrowdStrike Falcon Platform
Ready to protect your business?

Try CrowdStrike free today

Subscribe

Sign up now to receive the latest notifications and updates from CrowdStrike

See CrowdStrike Falcon in action