Nano Solutions

Why We Compete in DownUnderCTF | Nano Solutions

6 min read Petr Cervenka Petr Cervenka
hackathon cybersecurity perth
Why We Compete in DownUnderCTF | Nano Solutions
On this page 5 sections
  1. What a CTF actually is
  2. Why we actually do it
  3. The elephant: AI has broken the scoreboard
  4. What it doesn't prove
  5. The honest summary

The short version

  • We placed 180th of 2,167 teams at DownUnderCTF 2024, and 272nd of 1,668 in 2025. Worse, in a smaller field.
  • A CTF is a timed set of security puzzles. The skill it tests is triage under pressure, not any single exploit.
  • Frontier models have changed what a placing means. One competitor estimates he would have finished 75th rather than 5th without LLM help, and sixteen teams fully solved a recent event against one the year before.
  • So discount our ranking, including ours. A CTF placing is not a security credential, and a number without its denominator is marketing.

Every year a few thousand people spend a weekend trying to break deliberately broken software. It's called a capture-the-flag competition, and DownUnderCTF is the largest one in Australia. We've entered as a team twice now.

Here are our results, without the spin:

Teams Our rank Percentile Challenges solved Points
2024 (DUCTF 5) 2,167 180th top 9% 19 of 66 2,021 / 15,223
2025 (DUCTF 6) 1,668 272nd top 17% 15 of 64 1,612 / 13,683

We didn't win. We didn't make the podium, or the top hundred. In 2024 we finished in the top 9% of the field, and in 2025 we went backwards in a smaller field. Those are the numbers on the certificates and they're the numbers we'll quote.

What a CTF actually is

A capture-the-flag competition is a set of security puzzles. Each one hides a "flag" — a short string — behind some flaw you have to find and exploit. Challenges are usually grouped into categories like web exploitation, cryptography, reverse engineering, binary exploitation, forensics and open-source intelligence. Solve a challenge, submit the flag, score points. Harder challenges are worth more, and in most scoring systems a challenge is worth less the more teams solve it.

The clock is the point. You have a fixed window, far more challenges than you can finish, and no idea which ones are tractable. So the real skill on display isn't any single exploit — it's triage. Which of these 66 things can we actually land in the time we have?

Why we actually do it

The honest answer is that we like it.

We like hacking. We like the moment a thing that was supposed to be closed turns out to be open. Most of us got into software because we wanted to know how it worked underneath, and taking something apart is still the fastest way to find out — you learn more about how a system is built in the hour you spend breaking it than in a week of reading its documentation.

And we love the game of it. The countdown, the scoreboard ticking over, four people in a room going quiet because someone has a lead. Submitting a flag at 1am to a hard challenge you've been chewing on for three hours is a genuinely great feeling, and there is not a lot in professional life that reproduces it. That's the reason. Everything below is a consequence, not a motive.

The consequences are real, though. Spend a weekend exploiting other people's deserialisation bugs, path traversals and JWT mistakes and you write your own code differently on Monday — the categories that come up in CTFs map closely onto the OWASP Top 10 issues we look for in client code reviews. And arriving at an unfamiliar system under a time limit to work out where it gives is, structurally, what a penetration test is, minus the client and the scope document. Curiosity is the reason we turn up. Getting better at the security work is what happens while we're there.

The elephant: AI has broken the scoreboard

We can't publish a CTF ranking in 2026 and not address this.

In May 2026 Kabir Acharya — who has won DownUnderCTF multiple times with Blitzkrieg — published The CTF scene is dead, arguing that frontier models have compromised the competitive format outright. His summary is blunt: "The scoreboard does not measure human skill cleanly anymore, and the old game is not coming back." You can paste a crypto challenge into a chatbot, come back in ten minutes and have the solution. Worse, orchestrated agents scale: as he puts it, "the more tokens you can throw at a competition, the faster you can burn down the board." Open CTFs have become, in part, pay-to-win.

It isn't an isolated view. Laurence Tennant's CTFs in the AI Era records what that looks like on the ground: at BSidesSF 2026 sixteen teams fully solved every challenge, against one team the year before, and no challenge went unsolved. He estimates he'd have finished 75th rather than 5th without LLM assistance. Some events have responded by banning the tools outright — LakeCTF now runs a no-LLM policy covering agentic workflows and even Copilot autocomplete.

Which makes our own numbers awkward, so let's be straight about them. Our 2025 result was worse than 2024 — 272nd of 1,668 against 180th of 2,167 — and it landed squarely in the period these posts describe. We're not going to tell you AI is why we slipped. Plenty of humans still finished above us, and a smaller, sharper field will do that to you. But it does mean a mid-table placing in a modern open CTF carries less information about human skill than the same placing did three years ago, and anyone reading a ranking on an agency website should discount it accordingly. We'd rather say that than have you work it out later.

DownUnderCTF 2025 certificate for team Nano Solution, showing a team ranking of 272 out of 1,668 and 15 of 64 challenges solved
DownUnderCTF 6, 2025 — 272nd of 1,668. The organisers spelled us "Nano Solutlon", which we have decided to keep.

What it doesn't prove

A CTF placing is not a security credential. It isn't IRAP, it isn't Essential Eight maturity, and it isn't an accredited qualification. Nobody should hire a security consultant because they were 180th at anything.

CTF challenges are also artificial in a specific way: you know a flaw exists, because someone put it there. Real assessment work is mostly the opposite — long, unglamorous, and frequently ending in "this is fine, here's the evidence." The competition rewards fast, clever, narrow work. Client work rewards thorough, documented, boring work. They're different jobs and we don't pretend otherwise.

And a middling result is a middling result. Top 9% of a field that includes a lot of first-timers is a decent showing for a small team with day jobs; it is not elite. We publish the ranking and the denominator together for that reason — a number without its denominator is marketing, not evidence.

The honest summary

We compete because breaking things is fun, and because we want to stay the kind of people who are good at it. The scoreboard meant more three years ago than it does now, and we've said why. What hasn't changed is the part that was always the actual point: a weekend of hard puzzles, a room full of people who enjoy them, and a handful of new ways software fails that we didn't know about on Friday.

If you want the credentials that actually govern the work, they're on our cyber security consulting page: Essential Eight, IRAP readiness, secure code review, and our WA Government CUAICTS2021 panel listing. The CTF certificates sit alongside those on our awards and recognition page, at exactly the weight they deserve.

DownUnderCTF 7 runs next year. We'll enter, and we'll publish whatever happens.

Petr Cervenka

Petr Cervenka

Petr is the founder and lead developer at Nano Solutions, a Perth-based custom software firm. With over a decade of experience building enterprise platforms for government and private sector clients, he leads delivery of complex projects across Australia.

Connect on LinkedIn