Review the code.
Examine the application, its withdrawal logic, and the contracts supporting it. The source is public.
Honeypot repository (opens in a new tab)PRT Honeypot v2
Real assets. Open code. An invitation to put Cartesi’s security to the test. Find a way to drain the funds locked in the Honeypot.
CTSI locked in the pot
View the current balance on Ethereum.
Drain the pot to complete the challenge. No hacking recipe to submit and no hidden puzzle to uncover.
Verify on Etherscan (opens in a new tab)The application accepts CTSI deposits, but only one preconfigured address can withdraw them. The challenge is to break that rule. Every attempt tests the application and the infrastructure protecting it.
Examine the application, its withdrawal logic, and the contracts supporting it. The source is public.
Honeypot repository (opens in a new tab)Reproduce execution and follow the rollup’s state with the Honeypot validator node.
Node instructions (opens in a new tab)Understand how the application and fraud-proof system work together, then put them to the test.
Read the deep dive (opens in a new tab)How the challenge works, what to watch, and where to begin.
There is no exit for deposits. Any funds you send are treated as a donation to help test Cartesi Rollups’ security assumptions. The Foundation is the only authorized withdrawal address. We do not encourage deposits.
Yes. Follow the contract’s activity on Etherscan (opens in a new tab), or keep up with updates on X (opens in a new tab) and Discord (opens in a new tab).
Draining the funds in violation of the application’s withdrawal rule. The challenge is to demonstrate that the application or the system protecting it can be broken, with real assets at stake.
Development continues alongside the challenge. Major Rollups versions can lead to a new Honeypot deployment, with funds progressively transferred to the updated pot. For patches, the upgraded validator node is restarted. Follow the repository for the configuration and instructions for each deployment.
Honeypot is designed as a security challenge. To start building, use the developer documentation (opens in a new tab) and the Rollups examples (opens in a new tab).
Start with the Honeypot source (opens in a new tab), the technical deep dive (opens in a new tab), and the PRT paper. The resources below link directly to the contracts, node, research, and independent assessment.