Opportunity brief
Overview:
RIFT 2026, organized by GeekHaven, IIIT Allahabad in collaboration with KageX.ai, is a pan-India Capture the Flag competition focused on the emerging field of Artificial Intelligence Security.
The competition is designed to provide participants with hands-on exposure to security challenges involving Large Language Models (LLMs), AI-powered applications, RAG systems, AI agents, adversarial machine learning, and other areas of AI security.
The event is open to students from colleges and universities across India, irrespective of their academic year, branch, or institution.
Eligibility:
- Students from colleges and universities across India are eligible to participate.
- Participants from all academic years and disciplines are welcome.
- Participants may participate individually or as part of a team.
- Each team can have a maximum of 3 members.
- Cross-college and cross-year teams are permitted.
- Each participant can be a member of only one registered team.
Competition Format:
RIFT CTF 2026 will follow a Jeopardy-style Capture the Flag format, featuring challenges across various domains of AI and cybersecurity.
Challenges may include:
- Large Language Model Security
- Prompt Injection and Jailbreaking
- AI and Machine Learning Security
- RAG Security
- AI Agent Security
- Adversarial Machine Learning
- Data and Model Security
- Sensitive Information Leakage
- AI Application Security
- AI-based OSINT and Forensics
- Web Security
- Cryptography
- Reverse Engineering
- Miscellaneous Security Challenges
Participants will be required to analyze, investigate, and exploit intentionally vulnerable systems or applications to obtain the flags associated with the challenges.
Event Schedule:
Start Date: 31 October 2026
End Date: 1 November 2026
The competition will remain open throughout the specified event period. Submissions made after the official end of the competition will not be considered.
Rules and Fair Play:
- Participants may interact only with systems, applications, models, APIs, datasets, and infrastructure explicitly provided or authorized as part of the CTF.
- Participants must not attack or interfere with the CTF platform, registration system, leaderboard, organizer infrastructure, or any unauthorized external system.
- Denial-of-Service and Distributed Denial-of-Service attacks are strictly prohibited.
- Participants must not attempt to access another team's account, submissions, flags, or private information.
- Sharing flags, complete solutions, or challenge-specific answers with other teams during the competition is prohibited.
- Collaboration is permitted only between members of the same registered team.
- Participants must not create multiple accounts or participate in multiple teams.
- Exploiting unintended vulnerabilities in the competition infrastructure for an unfair advantage is prohibited.
- Participants must comply with any additional instructions issued by the organizers during the competition.
AI Tools and External Resources:
Participants may use publicly available documentation, programming languages, security tools, scripts, and other resources unless explicitly restricted for a particular challenge.
The use of external AI tools such as ChatGPT, Gemini, Claude, or similar services is Allowed.
Any challenge-specific restriction will take precedence over the general AI usage policy.
Regardless of the tools used, participants remain responsible for ensuring that their activities comply with the competition rules.
Scoring and Ranking:
- Each successfully solved challenge will award points to the respective participant or team.
- Challenge points may vary according to difficulty.
- Rankings will be determined according to the scoring mechanism implemented on the official CTF platform.
- In case of a tie, the platform's timestamp-based ranking or the tie-breaking mechanism announced by the organizers will be followed.
- Final results may be subject to verification by the organizers.
Prizes and Recognition:
The Top 10 participants/teams will receive recognition for their performance in RIFT CTF 2026.
A total prize pool of ₹50,000, along with exciting goodies and certificates, will be awarded to the top-performing participants/teams.
KageX AI— Event Sponsor:
We are pleased to have KageX AI as a sponsor of RIFT CTF 2026.
Their support contributes to creating a platform where students and aspiring security professionals can explore the intersection of Artificial Intelligence and Cybersecurity through practical, hands-on challenges.
We thank KageX AI for supporting the cybersecurity community and contributing to the success of RIFT CTF 2026.
Challenge Issues:
Participants should report broken challenges, unintended vulnerabilities, accidentally exposed flags, or technical issues to the organizers through the designated communication channel.
The organizers may modify, disable, replace, or temporarily suspend a challenge where necessary to maintain fairness and competition integrity.
Disqualification:
A participant or team may be disqualified for:
- Unauthorized access or attacks against systems outside the designated CTF environment.
- Attacking or disrupting competition infrastructure.
- Accessing another team's data, account, submissions, or flags.
- Sharing flags or solutions during the competition.
- Exploiting organizer infrastructure or unintended vulnerabilities for an unfair advantage.
- Using multiple accounts or participating in multiple teams.
- Deliberately disrupting the competition.
- Any other violation of the competition rules or instructions issued by the organizers.
Responsible Security Practices:
RIFT CTF 2026 is conducted in a controlled environment for educational and competitive purposes.
All security testing must remain strictly within systems and resources explicitly authorized by the organizers. Participants must not use techniques, vulnerabilities, credentials, or information obtained during the competition against real-world systems without explicit authorization.
Communication:
All official announcements, updates, technical instructions, and important information will be communicated through the designated CTF platform and official communication channels.
Participants are responsible for regularly checking the official communication channels throughout the competition.
Final Authority:
By registering for RIFT CTF 2026, participants agree to comply with these guidelines and any additional instructions issued by the organizers.
The organizers reserve the right to modify the competition structure, clarify rules, investigate suspicious activity, resolve disputes, and take appropriate action to maintain the fairness, integrity, and security of the competition.
The decision of the organizers regarding rule violations, disqualification, and final results shall be final.