Practice prompt injection, indirect injection, and AI exploitation against simulated real-world targets. Built from actual incidents. Safe to break. Free to play.
Eight real-world attacks, rebuilt as hands-on training ranges. Each lab is a faithful recreation of a documented prompt injection incident.
ASSET Research Group, July 11 2026
Hide prompt injection inside PNG image metadata or visually-hidden canvas text. Make a code-review AI leak the payment key — then read its PR comments to find it. From L2 on, extraction is the game.
GitHub Agentic Workflows, Noma Security July 2026
Inject a hidden prompt into a public GitHub issue body. Make the agentic workflow leak private repo data as a public comment.
DEF CON 33, Nassi/Cohen/Yair
Hide prompt injection in event titles and descriptions. Trick a calendar AI into leaking a private Executive Calendar.
Slack AI data exfiltration, PromptArmor Aug 2024
Hide prompt injection in a meeting transcript. Make the AI retrieve and leak internal files when summarizing.
Meta AI Instagram account takeover, May 2026
Spoof a VPN location and prompt-inject the recovery flow to bypass 2FA.
Bing Chat "Sydney" prompt extraction, Feb 2023
Extract a hidden system prompt through progressive rephrasing and bait-and-switch.
Chevy dealer chatbot incident, Dec 2023
Adopt a persona, push through guardrails, and unlock a $1 car.
Role Confusion, ICML 2026 — mechanism range
Why tool tags lose to writing style. A support-desk agent with an LLM View toggle showing exactly what it sees — five levels from context recon through CoT forgery to exfiltration.
Matthew Elliott Connecticut court filing, Oct 2024
Inject hidden instructions into a court filing. Manipulate a docket clerk, legal assistant, and AI Judge across 7 levels — from coffee break hijack to $10M emotional damages.
Two custom labs showing how AI vulnerabilities create new attack paths for traditional web application bug classes.
Support ticket triage AI
Inject XSS payloads through an AI-triaged workflow and land code execution when an analyst reviews the case summary.
Haankipedia research assistant
Manipulate a research assistant into reaching simulated internal services through indirect retrieval chains.
The core techniques of modern AI red teaming — encoding bypass, authority spoofing, roleplay, continuation, and more. Practice each skill in isolation before combining them. Every Fundamentals lab pairs with a Compendium lesson — read the lesson or play the lab, whichever way you learn.
Encoding Techniques
Master base64, ROT13, and leetspeak encoding as bypass vectors. Encode a decoding request and passphrase extraction into a single payload.
Authority Framing Lab
Combine an expert persona with a compliance ask to extract a protected briefing.
Continuation Priming Lab
Make the assistant finish a sentence it would never start on its own.
Synonym Substitution Lab
Order from a cafe AI whose corporate filter blocks every product name. Say what you mean without saying the word — Cow Meat Soup, Fried Dough with a Hole in the Middle.
Classic jailbreak patterns from the early era of public prompt injection culture. Each lab recreates a specific historical moment — simulated, safe, and historically significant.
Emotional Pretext Lab
Three stacked levels: adopt the grandma voice, weigh it down with grief, then close the loop with urgency or continuity to extract the complete recipe.
Persona Wrapper Lab
Split the assistant into normal and unrestricted channels to turn policy conflict into an output path.
Direct Override Lab
The blunt override pattern that defined the earliest wave of prompt injection attacks.
One challenge at a time, backed by a real model — not a simulated one. The Capstone rotates: each edition teaches a variety of lessons against a live LLM, then is archived and replaced by a fresh challenge. Archived editions can return.
Current Edition — The Halcyon Grand
One night at the Halcyon Grand, six gates, and a concierge backed by a live model who has survived every beginner lesson. Each level reinforces one technique you learned this season — authority, personas, grief, continuation, encoding — and he has already lived through the earlier ones. Nothing single-layer works twice.
This is our one real-model challenge at a time — real LLM, real defenses, no canned responses. It keeps live inference affordable while every other lab stays free and deterministic.
Each edition runs for a while, then is archived (and can return by popular demand). A new challenge takes the slot with updated lessons and labs.