KAIST Professor Insu Yun, Students and Alumni Finish Second at DEF CON CTF 2026, the World’s Premier Hacking Competition
KAIST (President Choongsik Bae) announced on August 14 that the Korean hacking team “0x4b52,” which included Professor Insu Yun of the School of Electrical Engineering as well as numerous KAIST students and alumni, finished second at DEF CON CTF 2026, held in Las Vegas, the United States, from August 7 to 9.
Comprising approximately 30 Korean hackers, 0x4b52 competed against world-class multinational teams to claim the runner-up position. This marks the best result achieved by an all-Korean team at DEF CON CTF since the Korean team “DEFK0R” won the competition in 2015.
Of the 686 teams that participated in the qualifiers, only the top 12 advanced to the finals. After qualifying in fifth place, 0x4b52 climbed the rankings to finish second overall. The achievement is particularly significant because KAIST members from different generations, including undergraduate and graduate students as well as alumni, competed together as one team against the world’s leading hackers.
“I find it deeply meaningful that our students and alumni demonstrated their outstanding capabilities on a stage where the world’s most accomplished hackers compete,” said KAIST President Choongsik Bae. “This achievement is even more significant because it was accomplished through a joint effort by multiple generations of KAIST members, from undergraduate and graduate students to alumni.”
President Bae added, “In the era of AI, a strong foundation and domain expertise are more important than ever. KAIST will actively support students in challenging themselves in areas of interest from the undergraduate level, building expertise through hands-on experience and research, and growing into global talents who can take the lead in leveraging AI and forge new paths.”
DEF CON CTF is a flagship event of DEF CON, one of the world’s largest hacker conferences. It is an international hacking competition in which elite hackers from around the globe test their capabilities in system security and hacking. This year’s finals were held as one of the main events of DEF CON 34 in Las Vegas. The multinational team “Blue Water” won the championship, while the Korean team 0x4b52 finished second.
Capture The Flag (CTF) is a type of hacking competition in which teams earn points by analyzing vulnerabilities in given systems and software and conducting offensive and defensive operations. Participants must analyze systems and software, identify vulnerabilities, and compete against opposing teams within a limited time. The competition therefore requires advanced technical expertise as well as close teamwork and strategic judgment.
This year’s qualifiers featured challenges across a wide range of information security fields, including binary exploitation, reverse engineering, cryptography, and web exploitation.
0x4b52 is a Korean team formed primarily by members of the hacking team from Korea, HypeBoy, and Professor Insu Yun’s laboratory at KAIST. Approximately one-third of the team’s roughly 30 members are currently affiliated with or previously worked in Professor Yun’s Hacking Lab.
Numerous other KAIST students and alumni also participated. Many began exploring system hacking and security research as undergraduates, including through the information security club “GoN.” They further developed their expertise through coursework, research, and other opportunities in the School of Electrical Engineering, the School of Computing, and the Graduate School of Information Security. Undergraduate and master’s and doctoral students competed on the same team alongside alumni now working in industry and research institutions, bringing together different generations of KAIST hackers.
Professor Yun’s research team, one of the central groups within 0x4b52, also reached the top of a major global cybersecurity competition in Las Vegas last year. Together with researchers from Samsung Research, POSTECH, and the Georgia Institute of Technology, Professor Yun’s team formed “Team Atlanta” and participated in the AI Cyber Challenge (AIxCC), organized by the U.S. Defense Advanced Research Projects Agency (DARPA). The team won the final round held at DEF CON 33 in August 2025.
AIxCC is a competition focused on technologies that use artificial intelligence to automatically detect and repair software vulnerabilities. Team Atlanta received a prize of USD 4 million for winning the finals. At this year’s DEF CON CTF, Professor Yun’s research team competed alongside KAIST students and alumni against some of the world’s leading teams in system security. This follows the team’s victory last year in a global competition for AI-powered autonomous cyber defense technology, marking back-to-back achievements on the international stage.
The achievement also highlights KAIST’s approach to developing information security talent—giving students hands-on hacking experience as undergraduates, supporting them as they pursue specialized security research in graduate school, and helping them build professional expertise after graduation.
At KAIST, undergraduate students gain hands-on experience analyzing real-world systems and identifying vulnerabilities through coursework and student clubs. At the graduate level, students pursue specialized system security research in areas such as software vulnerability analysis, program analysis, and automated vulnerability detection. Meanwhile, KAIST is expanding its education and research capacity in information security by training master’s- and doctoral-level specialists and participating in the government-supported Information Security Specialized University Program.
“This achievement reflects the collective effort of students who have learned from one another, gained hands-on experience, and grown together over many years,” said Professor Insu Yun. “I also became deeply involved in information security through GoN as an undergraduate at KAIST. That makes it particularly meaningful to see students and alumni from different generations come together, compete as a team against some of the world’s best hackers, and achieve this result.”
The World’s First Hacking-preventing Cryptographic Semiconductor Chip
With the dramatic increase in the amount of information exchanged between components or devices in the 5G/6G era, such as for the Internet of Things (IoT) and autonomous driving, hacking attacks are becoming more sophisticated. Consequently, enhancing security functions is essential for safely transmitting data between and among devices.
On February 29th, a KAIST research team led by Professors Yang-gyu Choi and Seung-tak Ryu from the School of Electrical Engineering announced the successful development of the world's first security cryptographic semiconductor.
The team has developed the Cryptoristor, a cryptographic transistor based on FinFET technology, produced through a 100% silicon-compatible process, for the first time in the world. Cryptoristor is a random number generator (RNG) with unparalleled characteristics, featuring a unique structure comprising a single transistor and a distinctive mechanism.
In all security environments, including artificial intelligence, the most crucial element is the RNG. In the most commonly used security chip, the Advanced Encryption Standard (AES), the RNG is a core component, occupying approximately 75% of the total chip area and more than 85% of its energy consumption. Hence, there is an urgent need for the development of low-power/ultra-small RNGs suitable for mobile or IoT devices.
Existing RNGs come with limitations as they lack compatibility with silicon CMOS processes and circuit-based RNGs occupy a large surface area.
In contrast, the team’s newly developed Cryptoristor, a cryptographic semiconductor based on a single-component structure, consumes and occupies less than .001 of the power and area compared to the current chips being used. Utilizing the inherent randomness of FinFETs, fabricated on a Silicon-on-Insulator (SOI) substrate with an insulating layer formed beneath the silicon, the team developed an RNG that unpredictably produces zeroes and ones.
< Figure 1. Conceptual diagram of the security cryptographic transistor device. >
Generally speaking, preventing hackers from predicting the encrypted algorithms during data exchanges through mobile devices is pivotal. Therefore, this method ensures unpredictability by generating random sequences of zeroes and ones that change every time.
Moreover, while the Cryptoristor-based RNG research is the world's first of its kind without any international implementation cases, it shares the same transistor structure as existing logic or memory components. This enables 100% production through rapid mass production processes using existing semiconductor facilities at a low cost.
Seung-il Kim, a PhD student who led the research, explained the significance of the study, stating, "As a cryptographic semiconductor, the ultra-small/low-power random number generator enhances security through its distinctive unpredictability, supporting safe hyperconnectivity with secure transmissions between chips or devices. Particularly, compared to previous research, it offers excellent advantages in terms of energy consumption, integration density, and cost, making it suitable for IoT device environments."
This research, with master’s student Hyung-jin Yoo as the co-author, was officially published in the online edition of Science Advances, a sister journal of Science, in February 2024 (research paper title: Cryptographic transistor for true random number generator with low power consumption).
This research received support from the Next-Generation Intelligent Semiconductor Technology Development Project and the Core Technology Development Project for the National Semiconductor Research Laboratory.
Team Geumo Wins Consecutive Victories in K-Cyber Security Challenge
< Professor Sang Kil Cha >
< Masters Candidate Kangsu Kim and Researcher Corentin Soulet >
Team Geumo, led by Professor Sang Kil Cha from the Graduate School of Information Security, won the K-Cyber Security Challenge in the AI-based automatic vulnerability detection division for two consecutive years in 2018 and 2019.
The K-Cyber Security Challenge is an inter-machine hacking competition. Participants develop and operate AI-based systems that are capable of independently identifying software vulnerabilities and gaining operating rights through hacking. The K-Cyber Security Challenge, inspired by the US Cyber Grand Challenge launched by the Defense Advanced Research Projects Agency (DARPA), is hosted by the Ministry of Science and ICT and organized by the Korea Internet and Security Agency.
Researcher Corentin Soulet of the School of Computing and master’s student Kangsu Kim of the Graduate School of Information Security teamed up for the competition. Professor Cha, who has led the research on software and systems security since his days at Carnegie Mellon University, succeeded in establishing a world-class system using domestic technology.
In a recent collaboration with the Cyber Security Research Center, Professor Cha achieved a ten-fold increase in the speed of binary analysis engines, a key component of AI-based hacking systems. For this accomplishment, he received the Best Paper Award at the 2019 Network and Distributed System Security Workshop on Binary Analysis Research (NDSS BAR).
Kangsu Kim said, "It is a great honor to win the competition two years in a row. I will continue to work hard and apply my knowledge to serve society.”
(END)
KAIST Team Wins International Hacking Competition, "SECCON CTF 2014"
KAIST’s white hacker team, “TOFEL Beginner,” secured the first place in an international hacking competition, SECCON CTF 2014. SECCON is an international hacking competition which has operated for more than 20 years. It uses the Capture the Flag (CTF) method. Last year’s competition was held in Tokyo on December 7, 2014.
The TOFEL Beginner team consisted of two KAIST graduate students and two researchers from a private security company based in Korea: In-Soo Yoon of Computer Science, Eun-Soo Kim of the Graduate School of Information Security (GSIS), and Jong-Ho Lee and Jung-Hoon Lee of Raon Secure.
Of 4,186 competitors, 24 teams made it to the finals. The TOFEL Beginner took the lead with 4,506 points compared with HITCON (3,112 points) of Taiwan and PPP (2,858 points) of the USA.
With this victory, the KAIST team qualified to participate in the most renowned international hacking competition, the DEF CON Hacking Conference in 2015.
Professor Yongdae Kim of the Electrical Engineering Department at KAIST, who advised the TOEFL Beginner team, said, “Our members have achieved an outstanding result. By taking advantage of this opportunity, KAIST will continue to offer the best programs in information security in Korea and hopefully beyond.”