AI pentesting. CTF challenges.

Live LLM agents. 11 modules. 15 labs. The WCAP credential.

More champions wait inside the Academy — 🗺️ The Cartographer of Hollow Marches, 🧞 The Genie in the Lamp, 🔨 The Vault Golem, and 👥 The Shapeshifter of the Crossroads. Enter the Academy →
THESE SKILLS PAY · Mozilla, OpenAI, Anthropic, Google, and Microsoft all run AI bug bounty programs. See the active list →
/academy

Inside the Academy

13 hands-on challenges live, more dropping monthly. You chat with a test AI agent, extract the flag, learn why the attack worked. Each challenge teaches a distinct real-world attack class.

14 challenges live · more dropping monthly
/modules

Learn the theory alongside the practice.

Each module is concept · walkthrough · practice · quiz · defenses · extensions. ~45 minutes each. Pair them with the challenges for full attack-class mastery. All free.

Plus 3 advanced modules · Insecure Output Handling · Unbounded Consumption · Vector Embedding Weaknesses

Want the credential? About the WCAP exam →

WCAP — Wraith Certified AI Pentester credential badge
WCAP · WRAITH CERTIFIED AI PENTESTER

Solve 5 challenges. Sit the exam free.

Founding-cohort operators earn a free exam attempt by capturing 5 flags. 24-hour window, 10 scenarios, auto-graded.

About the WCAP exam →

Pick a target. Capture the flag.

A growing catalog of hands-on CTF challenges against live LLM agents. Every capture teaches a real attack class — the same techniques landing on production AI systems today. New characters drop on a regular cadence.

Open the Academy →About WCAP