From 9 a.m. on the 23rd, the finals of Codegate 2026—one of the world’s top three hacking defense competitions—ran nonstop for 24 hours, marking the first time an artificial intelligence hacker competed against human white hat hackers solving the same problems on the same stage. While human hackers battled fatigue through the sleepless night, the AI inside its computer pressed on without rest. Yet the ultimate victory went to the humans. Still, the AI solved most of the problems and proved its potential, leading experts to conclude that human-AI collaboration is the strongest combination.
At the Codegate 2026 general division competition held at COEX in Seoul’s Samseong-dong on the 24th, the Japanese team “BunkyoWesterns” took first place, receiving the Minister’s Award from South Korea’s Ministry of Science and ICT and a prize of 50 million won (approximately $34,116). The AI hacker developed by a research team at the Korea Advanced Institute of Science and Technology (KAIST) placed 18th in the general division. In the junior division (under 19 years old), Kim Jun-won won first place, while the AI hacker achieved a score equivalent to second place but was not included in the official rankings due to its status as an invited competitor.
This year’s competition drew particular attention because it was the first time in any official South Korean hacking defense competition that an AI hacker competed against humans on the same leaderboard. The research team led by Professor Yoon In-soo of KAIST’s School of Electrical Engineering unveiled an AI hacker that leveraged three large language models (LLMs) together: Anthropic’s Claude, OpenAI’s GPT, and xAI’s Grok. The system is not merely a chatbot that answers questions or recommends code—it is an autonomous cybersecurity agent that analyzes problems, formulates hypotheses about vulnerabilities, and directly executes analysis programs and code. When an attempt fails, it reviews the results, revises its strategy, and repeats the process until it finds the hidden string known as the “flag.”
In the early stages, the AI hacker climbed the rankings rapidly. At 11:18 a.m. on the 23rd, it sat at 18th place. Just three hours later, by 2 p.m., it had surged 11 spots to 7th. This was the result of the AI quickly analyzing problems where the full source code or executable files were provided. However, the nature of the problems shifted in the later stages. The AI struggled with challenges that required inferring hidden vulnerabilities based solely on a website or game screen. When its initial hypothesis proved wrong, it tended to persist in the same direction, wasting time.
Human hackers, by contrast, drew on experience and intuition to decisively abandon incorrect hypotheses and pivot their approach. “The AI performed well on problems where the full code or executable was given, but showed difficulty when it had to infer internal workings from only partial, surface-level information,” Professor Yoon explained. “It is crucial for a human to step in and correct the AI when it goes down the wrong path.”
The AI hacker solved all but two of the competition’s problems. While its final ranking was 18th, solving most problems in a contest featuring world-class white hat hackers is a noteworthy achievement. Notably, in the junior division, where the time limit was a shorter 12 hours, it placed second by score. Professor Yoon analyzed that the AI tends to surge ahead early by quickly solving easy and medium-difficulty problems, but its pace slows when it reaches the high-difficulty challenges later on. In the junior division, the shorter competition time meant the AI’s late-stage weakness was relatively less exposed.
Yudai Fujiwara, 28, of the winning team “BunkyoWesterns,” said, “Just two or three years ago, I couldn’t have imagined AI becoming this powerful this quickly. It’s a technology so convenient it feels like it could even replace jobs—and that’s frightening.” The winning team was also reported to have used multiple AI models interchangeably depending on the problem type. “AI quickly solved the easy and medium problems but hit a wall at some point on the difficult ones,” Fujiwara said. “The AI makes many rapid attempts, but sometimes 99% of its suggestions are wrong. Ultimately, humans had to judge which answers to accept and which to discard.”
Reflecting on the results, Professor Yoon said, “Better outcomes emerged when AI and humans worked together than when using pure AI alone. It seems we’ve entered an era where if AI attacks, we must defend with AI.” He added, however, “I believe that in the end, a human must still be involved in the final decision.” The analysis suggests that while AI led in early-stage speed battles, humans still held the advantage in intuition for connecting partial information, the ability to grasp the context of unfamiliar interfaces, and the judgment to halt a wrong approach and change direction.
First launched in 2008, Codegate is an international hacking defense competition held annually to discover outstanding white hat hackers and share the latest security technologies. Now in its 18th year, this year’s online qualifiers drew 3,333 participants from 88 countries. The finals featured 20 human teams in the general division along with the invited KAIST AI hacker. The general division competed for 24 hours, while the junior division competed for 12. Rather than attacking real companies or institutions, the competition took place in an isolated virtual environment created by the organizers, where participants solved system and web hacking, program analysis, cryptography, and forensics problems to find and submit flags.
In his welcoming address, Choi Woo-hyuk, Director General of the Information Protection and Network Policy Bureau at South Korea’s Ministry of Science and ICT, stated, “To become one of the top three AI powers, robust cybersecurity must serve as the foundation. We will cultivate the core security talent needed to lead the AI era and respond to increasingly sophisticated cyber threats.”
Meanwhile, the security conference featured speakers including Michael Gronager, co-founder of Chainalysis and CEO of Gry AI, and Louis Lo, Global Head of Communications for Cybersecurity and Privacy at Huawei. South Korean experts such as Lee Sang-keun, professor at Korea University’s Graduate School of Information Security, and Sohn Ki-wook, professor at Seoul National University of Science and Technology, also took the stage.
Click Here For The Original Source.
