🎄 Join our Annual Holiday wargame and win prizes!


Aptos Move Challenges Release

24/09/2025

Introducing Move Challenges

Smart contracts power the next generation of finance, governance, and decentralized apps. But as the DeFi world has shown us again and again — one small bug can mean millions drained overnight.

That’s why we’re excited to launch our new Move Challenges. Built on the Aptos Move language, these hands-on scenarios let you explore real-world classes of blockchain vulnerabilities: from typos that topple DAOs to clever exploits that drain liquidity pools.

Here’s what you’ll face:

  • DAO Governance – In 2022, a single typo in a governance contract made it exploitable. Can you spot the flaw and see how attackers could abuse it?

  • Drain – Step into DeFi. Explore fungible assets in Move and learn how a vulnerable contract can be drained.

  • Arbitrage – Swap, swap, swap. This AMM lets you trade tokens both ways — but what happens when the math isn’t quite right?

  • DAO DoS – Limited resources are an attacker’s best friend. Simulate the 2023 wave of DeFi denial-of-service attacks.

  • SmartTable – Another take on blockchain DoS. Push the system until it breaks.

  • ChaChash – The master-level challenge. A custom hash function protects admin authentication. Can you crack it and seize control?

Each challenge starts simple and ramps up to advanced cryptography and protocol design. By the end, you’ll not only understand how these exploits work, but also how to defend against them.

These Move Challenges are featured in our Weekly Incident Game.

If you’re a smart contract developer, security researcher, or just a curious hacker, this is your chance to battle-test your skills in the world of DeFi security.

:backhand_index_pointing_right: Dive into Move. See how secure (or fragile) your contracts really are.

Deco line
Deco line

Play AppSec WarGames

Want to skill-up in secure coding and AppSec? Try SecDim Wargames to learn how to find, hack and fix security vulnerabilities inspired by real-world incidents.

Deco line
Deco line

Got a comment?

Join our secure coding and AppSec community. A discussion board to share and discuss all aspects of secure programming, AppSec, DevSecOps, fuzzing, cloudsec, AIsec code review, and more.

Read more