UofTCTF 2026
73 challenges with 127 published solutions between them. CTFtime lists this event but has no writeups filed against it, so it is absent from the index CTFtime feeds. These were found in public repositories instead. Each link is pinned to the commit it was read from.
The event on CTFtimeCryptography14
Recover a plaintext or a key from something that was supposed to protect it. In practice: identify the scheme, find the parameter the author got wrong, exploit it.
Analysis
8 official solutionsGamblersfallacy
5 official solutionsLeaked D
3 official solutionsMAT247 writeup
2 official solutionsOrca Writeup
2 official solutionsGamblers Fallacy Writeup
1 official solutionMat247
1 official solutionMAT247 Crypto
1 official solutionMat347
1 official solutionRotor Cipher
1 official solutionUoft Lfsr Labyrinth
1 official solutionUoft Lfsr Labyrinth Writeup
1 official solution
Misc14
Everything that fits no other box: esolangs, puzzles, scripting exercises, and the jail escapes that have not yet earned their own category.
Encryption Service
3 official solutionsLottery
3 official solutionsGuess The Number
2 official solutionsVibe Code
2 official solutionsCheck
1 official solutionEncryption Service Writeup
1 official solutionFile Upload
1 official solutionGuess The Number Writeup
1 official solutionKk Training Room
1 official solutionLottery Writeup
1 official solutionNothing Ever Changes
1 official solutionNothing Ever Changes Writeup
1 official solutionVibe Code Writeup
1 official solutionWordle
1 official solution
Web14
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Firewall
6 official solutionsNo Quotes
5 official solutionsNo Quotes2
4 official solutionsNo Quotes3
3 official solutionsPersonal Blog
2 official solutionsFirewall Writeup
1 official solutionNo Quotes 2 Writeup
1 official solutionNo Quotes 3 Writeup
1 official solutionNo Quotes Writeup
1 official solutionPasteboard
1 official solutionPersonal Blog Writeup
1 official solutionUnrealistic Client Side Challenge Flag 1
1 official solutionUnrealistic Client Side Challenge Flag 2
1 official solutionVulnerability Research
1 official solution
Reverse engineering10
Work out what a compiled program does without its source, then work backwards from the check to the input that passes it.
Symbol of Hope
4 official solutionsBring Your Own Program
3 official solutionsBaby Obfuscated Flag Checker
2 official solutionsWill U Accept Some Magic
2 official solutionsBaby Obfuscated Flag Checker Writeup
1 official solutionBring Your Own Program Writeup
1 official solutionConnoisseur
1 official solutionConnoisseur Writeup
1 official solutionSymbol Of Hope Writeup
1 official solutionWill U Accept Some Magic Writeup
1 official solution
Binary exploitation6
Turn a memory-safety bug in a native binary into control of execution. Usually a stack overflow, a format string, or a heap primitive.
extended eBPF
3 official solutionsBaby Bof
2 official solutionsUprobe
2 official solutionsAes Aead
1 official solutionCalculator
1 official solutionExtended Ebpf Writeup
1 official solution
Uncategorised6
The upstream scoreboard did not say, so neither do we.
Leakdd
1 official solutionLSFT Labyrinth
1 official solutionWriteup01
1 official solutionWriteup01 Out
1 official solutionWriteup02
1 official solutionWriteup03
1 official solution
Forensics5
Recover something from a file, a capture, or a disk image - often from a part of it the format says is unused.
Baby Exfil
3 official solutionsMy Pokemon Card is Fake!
2 official solutionsBaby Exfil Writeup
1 official solutionMy Pokemon Card Is Fake Writeup
1 official solutionYellowDotDecode
1 official solution
OSINT4
Answer a question about the real world from public sources. The work is pivoting between identifiers, not exploiting anything.
Gogocoaster
3 official solutionsGo Go Cabinet
2 official solutionsMy Pokemon Autograph Is Fake
1 official solutionMy Shikishi Is Fake
1 official solution