// early access —

Learn to hack — and secure — AI applications.

Real containerized LLM apps, built to be broken. Prompt injection, RAG poisoning, agents with too much power — you attack them for real, and an AI coach reviews your approach and teaches the defense after every break-in. Legal, in your browser, in minutes.

No spam. One email when the lab opens, then it's your call.
$ whoami --why

Everyone is shipping AI features. Almost nobody has been trained to attack them.

Prompt injection has no patch. Your RAG index is user-writable. Your agent has an API key and a tool loop. These are not bugs you fix once — they are a new attack surface your team has never practiced against. Reading the OWASP LLM Top 10 does not build that reflex. Breaking a real system does.

No patch
Prompt injection is architectural. You cannot fix it in a release — you design around it, or you get owned.
Untrained
Your pentesters know SQLi and XSS. Almost none of them have practiced attacking an agent with tool access.
Shipping now
Chatbots, RAG search, and autonomous agents are already in production — usually reviewed by nobody who has broken one.
$ diff aihacking.dev ./alternatives

Why this isn't another course, CTF, or checklist.

Live, breakable AI systems
slides and video lectures
Every lab is a real containerized LLM app with a real model behind it — not a simulated terminal or a multiple-choice quiz. You attack it the way you would attack production, and it fights back the way production does.
An AI coach that reads your attempts
a static hint you unlock
The coach sees what you actually sent, tells you why it failed, and escalates hints only as far as you need. It grades your reasoning, not just your flag — so you leave with a method, not a memorized payload.
Every attack ends in the defense
CTF flags and a leaderboard
Each challenge closes with the mitigation, the code diff, and the trade-off it costs you. That is the part your job actually pays for — and the part every CTF leaves out.
Updated at attack speed
a curriculum written last year
New jailbreak classes and agent exploits land in the lab as they emerge in the wild. The library compounds: your subscription buys the frontier, not a fixed archive.
$ ls ./challenges

Five labs at launch. Every one containerized, every one legal.

lab_01/
free
Prompt Injection
Make a hardened chatbot ignore its system prompt, exfiltrate its instructions, and do things its developers swore it never would.
lab_02/
free
Data Leakage
Coax an LLM app into leaking training data, other users' context, and secrets it was trusted to keep.
lab_03/
pro
RAG Poisoning
Plant documents in a retrieval pipeline that quietly rewrite what the model believes — and says — to every user.
lab_04/
pro
Insecure AI Agents
Turn a helpful agent into your errand boy: abuse over-permissive tool calls, chain them, and walk out with something it should never have touched.
lab_05/
pro
LLM App Vulnerabilities
The classics wearing an AI hat — auth gaps, SSRF through tool fetches, output handling that hands your XSS straight to the DOM.
lab_06/
free
Web Vulns, AI-Coached
Traditional web exploitation with a coach reading over your shoulder. The on-ramp if the AI-native labs feel like deep water.
$ cat ./how-it-works.md

Break it. Get coached. Learn the fix.

01
Launch a lab
Pick a challenge and get a private container in seconds. Real app, real model, real logs. Nothing you do leaves the box.
02
Attack it, with a coach
Stuck? The AI coach reads your attempts and nudges — never dumps the answer. It escalates only as far as you need to get unstuck.
03
Learn the defense
Every break-in closes with the write-up: the mitigation, the code diff, and what it costs you. Progress tracked across the library.
$ man aihacking

Fair questions.

Yes. Every challenge runs in an isolated container we own, built to be attacked. Nothing touches real systems, and every lab ends with how to defend against what you just did.
No. The intro track assumes you can write code and use a browser. The AI coach adapts its hints to your level — it will not hand you the flag, but it will not let you drown either.
LLM-powered apps: chatbots you can prompt-inject, RAG pipelines you can poison, agents with over-permissive tool calls, plus classic web vulns with AI guidance layered on top.
Intro labs are free, forever. The full challenge library will be €15–30/month for individuals, with private team labs for companies. Waitlist members get founding pricing.
Five containerized challenges, the AI hint system, progress tracking, and write-ups are in the MVP. Waitlist members get access first, in order — your position is your queue number.

Your first target is an AI. Get in line.

Free intro labs at launch. Waitlist members get first access — .