— web clipping, 985 words — published 2026-08-12
Post by @S1r1u5_ on X
i talked to a lot of people who played the defcon ctf finals to understand how llms affected them, both professionally and mentally.
i went in hoping to learn that human intuition still mattered. instead, ctfs in their current form as everyone saying is dead, players are forced to operate slot machines because anyone who refuses to token-max loses to those who do.
almost everything i learned, including how to learn, came from grinding ctfs. but the pipeline for developing that kind of skill and expertise now seems broken, juniors are rewarded for token-maxxing rather than going through the process of actually understanding things which is quiet sad and ctfs might not produce high quality security researchers any more.
this also has serious implications for people who can’t afford tokens. five years ago, i wouldn’t have been able to afford access to something like gpt-5.6, and I would have been locked out of the very competitions that helped me build my career.
anyway these are questions i asked if interesting for anyone:
did they have fun?
almost everyone was unhappy. it has largely become slot-machine operating, if they refuse to use llms, they lose to teams that do. it is not there is no fun at all, playing with friends and competing was all fun just process of solving which is main part and it isn't fun.(please let me know if you had fun)
did having a skilled human in the loop still matter?
i got mixed answers, but the leaderboard tells a fairly clear story, the top teams aggressively token-maxxed, by pooling gpt accounts and stuff. the #1 team allegedly spent around $50k on tokens xd.
how much of the outcome came from human skill versus token-maxxing?
its probably 95% token-maxxing and 5% human skill. some challenges, especially visual ones, remain difficult for llms, and human intuition to prompt mattered. but overall, the dominant strategy appears to be throwing more tokens at problems, one interesting observation, people who were better before llms were also better after the llms and they are the ones solving lot of challenges so it seems still 5% operating skill will put u in top and can't be dumb operator.
will a new generation of players simply adapt to this new kind of competition?
i thought maybe current players are just behaving like boomers who hate every new technology. but unlike previous technology stuff, there doesn’t seem to be much for the human to master here. token-maxxing is literally just token-maxxing. it doesn’t reward human ingenuity, it discourages it, and may eventually atrophies and makes us dumb
let me know if i missed something or if you have different opinions
---
it is all fucked up~
think about it, although ctf challenges are sometimes unrealistic, the skills largely translate to the real world. pick almost any top ctfer and i bet they could become a top security researcher. in that sense, ctfs have always been more educational than entertaining to me.
if they were purely entertainment, you could simply ban ai onsite and preserve a competition of human skill. but would anyone still be incentivized to play? ctfs would stop reflecting the actual field, because the frontier of security research will increasingly involve ai.
so you need to keep ai in the loop, right? but if you do, you get something like this year’s defcon ctf, people sitting in front of slot machines, token-maxxing and slowly drilling holes into their brains. remove ai and ctfs risk becoming irrelevant. keep ai and they risk destroying brains
---
note: 50k spend from #1 seems fake
---
##### Comments
> **Raymond Arnold @Raemon777** · [2026-08-13](https://x.com/Raemon777/status/2087776374539104465)
>
> I'm not familiar with the culture here, but, this seems like a situation where it's just correct to ban LLMs?
>
> I'm not sure how much the competition here was supposed to reflect real work environment, and in "real work" obviously you spend tokens on things insofar as it's
>
> > **s1r1us in sf @S1r1u5\_** · [2026-08-13](https://x.com/S1r1u5_/status/2087776878648300007)
> >
> > i think banning llms is one way to deal but it has its issues.
> >
> > https://x.com/S1r1u5\_/status/2087630564618907810?s=20…
> >
> > > **s1r1us in sf @S1r1u5\_** · 2026-08-13
> > >
> > > i think banning llms is one way to deal but it has its issues.
> > >
> > > https://x.com/S1r1u5\_/status/2087630564618907810?s=20…
> **Aleksandre Khokhiashvili @skkhokho** · [2026-08-12](https://x.com/skkhokho/status/2087585677542068336)
>
> Wrong conclusions, if it was just pay to win scoreboard would not be this similar to last year
>
> > **s1r1us in sf @S1r1u5\_** · [2026-08-12](https://x.com/S1r1u5_/status/2087586598431178851)
> >
> > yea for sure, i don't disagree with that
> >
> > \> one interesting observation, people who were better before llms were also better after the llms and they are the ones solving lot of challenges so it seems still 5% operating skill will put u in top and can't be dumb operator.
> **0ca @francisco\_oca** · [2026-08-13](https://x.com/francisco_oca/status/2087827789692960813)
>
> Is the real security work also token maxing? Imo is it not because all the complexity of real systems.
>
> Maybe what CTFs need to do is to increase the complexity and dependency of the challenges so it’s closer to a big messy & complex system instead of isolated challenges.
> **Igor Kozlov @iekozlov** · [2026-08-13](https://x.com/iekozlov/status/2087909373553025074)
>
> LLMs were trained to solve CTFs - see offensive benchmarks like CyberGym. But this generalization doesn't appear to transfer to defenders, as shown by the Cyber Defense Benchmark. Human expertise is still essential. Keep grinding.
> **lukas seidel @pr0me** · [2026-08-12](https://x.com/pr0me/status/2087581406255809022)
>
> my favorite take on this so far: ctfs are now 'temperature gacha".
>
> it's really sad to see, and I hope the community will find to adapt or better, revolutionize the format. because ctfs are how I acquired a lot of my skills and found a place in the community and many friends.