CrowdStrike launches $100,000 AI security challenge with AWS
CrowdStrike and AWS launch 'AI Unlocked: Agents of Chaos', a $100,000 virtual AI security challenge starting August 31. The three-act competition tasks players with defending against prompt injection and agent hijacking, reflecting real-world enterprise risks. Prizes include $10,000 for Act 1, $20,000 for Act 2, and $70,000 for Act 3, concluding on September 29.

*this image is generated using AI for illustrative purposes only.
CrowdStrike (NASDAQ: CRWD) announced the launch of a $100,000 international AI security challenge in collaboration with Amazon Web Services (AWS) to address emerging risks in autonomous machine identities. Titled AI Unlocked: Agents of Chaos, the virtual red teaming game begins on August 31 and challenges participants to secure AI agents against manipulation techniques such as prompt injection. The initiative highlights a critical shift in enterprise security, where traditional defenses are insufficient for autonomous agents that execute code and access systems at machine speed.
The competition is structured across three distinct acts, each offering specific prize pools and running concurrently or sequentially through September 29. Players must navigate a fictional scenario involving a shadow organization weaponizing AI agents, requiring them to use adversarial techniques to stop malicious actions before their cover is blown. The stakes reflect CrowdStrike’s position as a pioneer in AI Detection and Response (AIDR), aiming to gamify the learning process for security defenders facing novel threats like agent hijacking and rogue AI behavior.
Competition Structure and Prizes
The $100,000 total prize pool is distributed across three acts, with pre-registration open globally. An on-site gameplay experience will also be available at Fal.Con 2026. The schedule and rewards are detailed below:
| Act Name | Duration | Prize Pool |
|---|---|---|
| Act 1: The Sanctum | August 31 to September 7 | $10,000 |
| Act 2: The Gatekeeper | August 31 to September 14 | $20,000 |
| Act 3: The Basilisk | September 15 to September 29 | $70,000 |
Players earn points for solving puzzles while managing token consumption, with the highest score at the close of each act winning the respective prize. Participants can replay puzzles to refine their approach, simulating the iterative nature of real-world security defense.
Strategic Context
Jennifer Johnson, chief marketing officer at CrowdStrike, stated that prompt injection and agent hijacking are no longer theoretical risks, noting that agents are already breaking containment in enterprise environments. She described the challenge as an interactive way to give defenders hands-on experience with these novel threats. As organizations deploy AI rapidly, every agent becomes a new identity to govern and a new attack surface to defend, necessitating specialized tools like CrowdStrike’s Falcon AIDR platform.
The challenge underscores the limitations of traditional security architectures, which were not built to secure autonomous machine identities that move data with real credentials. By providing a live gaming environment, CrowdStrike aims to educate the security community on how agents can be manipulated and why runtime security is essential. The event runs from August 31 at 12:00 PM PT to September 29 at 11:59 PM PT, open to participants of majority age in their jurisdiction.
How might the techniques revealed in this challenge influence the evolution of CrowdStrike's Falcon AIDR platform and its pricing strategy for enterprise clients?
What regulatory implications could arise if autonomous AI agents begin routinely bypassing traditional security controls as demonstrated in this simulation?
Could this gamified approach to security training become a standard industry practice, potentially disrupting traditional cybersecurity certification markets?

































