New challenge daily
A fresh challenge appears every 24 hours. Miss a day and the streak resets, keeping the habit meaningful rather than gamified.
One focused challenge each day keeps your security skills sharp. Build a streak, reinforce concepts, and practice the workflows real bug bounty hunters use every day.
Every day at midnight UTC, a new challenge is unlocked. Each challenge is designed to take 10–20 minutes and tests a specific security concept or workflow.
A fresh challenge appears every 24 hours. Miss a day and the streak resets, keeping the habit meaningful rather than gamified.
Each challenge is scoped to fit into a single focused session. No sprawling labs that take hours, just one targeted exercise.
Your current streak and longest streak are displayed on your profile. Consistent daily practice compounds into real skill improvement over weeks and months.
Security skills decay without regular use. Daily challenges keep vulnerability patterns, code review instincts, and reasoning frameworks fresh.
Research on skill retention shows that short, frequent practice sessions outperform long, infrequent ones. Daily challenges apply the same principle to bug bounty training: encounter a vulnerability pattern today, see a variation tomorrow, and your brain builds durable recognition.
Finding bugs is not just about knowing techniques. It is about executing a workflow: read the code, identify the sink, trace the source, assess impact, and document evidence. Daily practice makes this workflow automatic so you can focus on harder problems during real engagements.
Paths teach theory, labs teach application, and daily challenges bridge the gap. They pull concepts from across all paths and force you to recall and apply knowledge without hand-holding.
Challenges are drawn from all categories. If you consistently struggle with SSRF scenarios but breeze through XSS, the daily mix ensures you cannot avoid your weak spots forever.
Daily challenges rotate across three core categories that map directly to real bug bounty workflows.
Read a snippet of server-side or client-side code and identify the security flaw. Challenges cover PHP, Python, JavaScript, Java, and Go. You will trace input flows, spot dangerous function calls, and identify missing sanitization.
Analyze HTTP requests, responses, or application behavior to determine if a vulnerability exists. These challenges train your ability to read traffic, recognize error patterns, and spot misconfigurations.
Read a realistic bug bounty scenario and decide on the correct next step. These challenges test your methodology, report writing instincts, and ethical decision-making.
Here is what a typical daily challenge looks like from start to finish.
You open today’s challenge and see a code snippet from a Node.js authentication endpoint. The prompt asks: “Identify the vulnerability and classify its severity.”
You trace user input from req.body.password into a string comparison using == instead of a timing-safe function. The vulnerability: timing-based side-channel attack on password verification.
You select “Timing attack on authentication” from the vulnerability types and mark severity as “Medium.” The challenge validates your answer and provides a detailed explanation.
The explanation covers why == is dangerous for secrets, how crypto.timingSafeEqual works, and links to the related lab for hands-on practice. Your streak increments and XP is awarded.
Consistency is rewarded. The longer your streak, the more XP and achievements you unlock.
| Streak | Reward | Achievement |
|---|---|---|
| 3 days | +50 bonus XP | “Getting Started” badge |
| 7 days | +150 bonus XP | “One Week Strong” badge |
| 14 days | +300 bonus XP | “Fortnight Focus” badge |
| 30 days | +750 bonus XP | “Monthly Master” badge |
| 100 days | +2500 bonus XP | “Century” badge + profile highlight |
One challenge a day builds real security skills over time. No random rabbit holes, no wasted hours, just focused daily practice.
Begin Today’s Challenge