Hardware CTF Challenges: What to Expect and How to Prepare
Hardware CTF challenges explained: radio, NFC, BLE, serial buses, firmware and side-channel. Public write-ups worth reading and the minimum kit to take part.
A hardware CTF is a security competition whose challenges are about physical hardware: a radio signal to decode, an NFC card to read, a serial bus capture to interpret, a firmware image to extract or analyse. The "flag", the string that proves you've solved it, is hidden in the object or its signals rather than on a web server. This guide covers the main challenge families, walks through public examples and lists the minimum kit to get ready.
If the idea of a CTF is new to you, start with our guide What Is a CTF in Cybersecurity?.
What makes a hardware CTF different
A "classic" CTF is played entirely remotely: a vulnerable website, a binary to exploit, an encrypted file. A hardware CTF adds a physical dimension, and that changes how you play.
- The object is the target. A circuit board, a conference badge, a radio beacon. You start by observing it: which components, which pins, which signals.
- The tools are physical. A logic analyser (a device that records digital signals), an SDR dongle (a software-controlled radio receiver), an NFC reader, a USB serial adapter.
- Electronics matter. Finding ground, not mixing up 3.3 V and 5 V, reading a component datasheet. A wiring mistake can destroy the target.
- Time is spent differently. A good share of the work is getting a clean capture. The analysis comes afterwards, usually on a computer.
Many online competitions sidestep the hardware question by handing you the capture directly: a logic analyser file, a radio recording, a flash memory image. That's an excellent way in, with nothing to buy.
The main challenge families
| Family | What you're given | What you're expected to do | Typical tools |
|---|---|---|---|
| Serial buses (UART, I2C, SPI) | A board or a logic analyser capture | Identify the protocol, decode the bytes exchanged | Logic analyser, PulseView, USB-UART adapter |
| Firmware | A binary image or a device whose memory you must read | Find a secret, understand an algorithm | binwalk, Ghidra, strings, Python |
| Radio (sub-GHz, SDR) | An IQ recording or a transmitter | Demodulate, recover the frame, decode it | RTL-SDR, Universal Radio Hacker, inspectrum, GNU Radio |
| NFC / RFID | A card or tag | Read the memory, understand its structure and authentication | NFC phone, reader, Proxmark3 |
| Bluetooth Low Energy | A beacon or connected device | Read advertisements, explore services, decode a message | nRF Connect, Wireshark, bleak |
| Side-channel and fault injection | Power consumption traces or a target board | Infer a key from power use, disrupt execution | ChipWhisperer, Python, NumPy |
| Electronics and PCBs | A board photo, a schematic, a badge | Follow traces, identify parts, fix things | Multimeter, datasheets, magnifier |
Two families deserve a closer look.
Side-channel analysis means inferring a secret from physical effects: a chip's power consumption varies with the data it handles. Challenges often supply thousands of measurements in a file, and it all comes down to statistics in Python. It's the most mathematical family.
Fault injection means briefly disturbing a chip's power or clock to make it skip an instruction. It needs specific hardware and is mostly practised at conferences or with dedicated platforms such as NewAE's ChipWhisperer.
Worked examples: public write-ups
The best way to see what a challenge looks like is to read a write-up, the solution a player publishes after the competition. Here are reliable public sources.
RHme (Riscure)
RHme (Riscure Hack Me) is a series of hardware CTFs run by Riscure, an embedded security company. For the 2016 edition, each participant received an Arduino Nano-style board (ATmega328P microcontroller) programmed with the challenges: side-channel, fault injection, cryptanalysis and software exploitation. The challenge binaries are published in the RHme 2016 GitHub repository (Riscure is now part of Keysight), so you can flash them onto your own Arduino and replay the edition. The repository links to many player write-ups and videos.
What it teaches you: most challenges start with a plain serial console. Everything else follows from being able to talk to the board.
Hackropole (ANSSI)
Hackropole is a platform from ANSSI, France's national cybersecurity agency, that lets you replay the France Cybersecurity Challenge (FCSC) all year round. It has a hardware category, with solutions published by players. It's one of the best free sources: challenges range from decoding bus captures to analysing circuits.
What it teaches you: many hardware challenges are played on files. Open a logic analyser capture in PulseView and the work begins.
Microcorruption
Microcorruption is an online CTF that emulates an electronic lock driven by a Texas Instruments MSP430 microcontroller. You get a debugger in the browser and need to understand the assembly code of each lock version. No physical parts, but genuine practice at reading embedded code.
Hardware villages at conferences
Big conferences have spaces dedicated to hardware. In Paris, Le Hack runs a hardware village, leLAB, which in 2026 offered badge-soldering workshops, NFC/RFID labs and IoT workshops. Electronic conference badges often hide small challenges of their own. It's the best place to try hardware you don't own yet.
The minimum kit to take part
There's no need to buy everything before your first competition. Here's a sensible progression.
| Step | Hardware | Indicative price | What it's for |
|---|---|---|---|
| Buy nothing | A Linux computer (or virtual machine), an NFC phone | €0 | File-based challenges, NFC, BLE |
| First purchase | USB-UART adapter, jumper wires | A few euros | Serial consoles |
| Second purchase | 8-channel logic analyser | €19.90 | UART, I2C, SPI |
| Third purchase | RTL-SDR dongle | €60 | Receive-only radio challenges |
| Later | Multimeter, test clips, possibly an RFID reader | Varies | Electronics, badges |
On the software side, everything is free: PulseView/sigrok for bus captures, binwalk and Ghidra for firmware, Universal Radio Hacker and GNU Radio for radio, Wireshark and Python for the rest.
For the first two rows, our tutorial on finding a UART port shows how to practise on an old router you own. And if you're looking for a gift for someone who already plays, our gifts for CTF players selection brings these tools together.
Practising at home: physical puzzles
Between competitions, the hardest part is finding a hardware target designed to be attacked, at the right level, with a solution to check your reasoning against. That's what we're building with our physical CTF puzzles, designed in France:
- BLE Beacon Decode Challenge (€32, summer 2027): a Bluetooth beacon broadcasting a message to decode.
- NFC Escape Tag (€26, Christmas 2027): an escape room in a box, with five contactless tags.
- Firmware Dump (€32, 2028): a memory chip to read, USB programmer included.
Each has three honestly labelled levels, nothing to solder, and an official solution published 60 days after delivery, so you can check your own write-up against it. All three are on a waitlist: sign up from the CTF puzzles page to hear when they launch.
Frequently asked questions
Do I need to solder to play a hardware CTF?
Rarely. Most challenges are played from capture files or a ready-to-use object with connectors already fitted. Soldering becomes useful in conference workshops and some advanced challenges, not for getting started.
Can I play a hardware CTF without any hardware?
Partly, yes. Many challenges hand you a logic analyser capture, a radio recording or a firmware image to analyse on your computer. Hackropole (the archive of ANSSI's FCSC) has a hardware category you can play online, and Microcorruption emulates a microcontroller in the browser.
What level do I need to start?
Being comfortable in a terminal and able to read a bit of Python is enough for the first challenges. Electronics basics (voltage, ground, serial buses) come along the way, often from the write-ups published after each competition.