Codegate 2026 Pits a KAIST AI Hacker Against Human Teams

Codegate 2026 put a security agent built by KAIST and the Codegate Security Forum into the finals alongside human white-hat hackers in Seoul on July 23-24. The competition drew 3,333 preliminary entrants from 88 countries; Japan's BunkyoWesterns won the general division, while the public reports did not disclose a comparable score for the AI agent.
Codegate 2026 brought an autonomous security agent into the same final-round setting as human white-hat hackers at Seoul's Coex on July 23 and 24. The agent, jointly developed by the Korea Advanced Institute of Science and Technology and the Codegate Security Forum, was invited to work on the same capture-the-flag problems as the human contestants and search for system vulnerabilities.
The competition followed an online preliminary round with 3,333 entrants from 88 countries. Eight countries sent 20 teams to the general final, while 20 competitors from three countries reached the junior final. Japan's BunkyoWesterns won the general division and received 50 million won. Kim Jun-won of South Korea won the under-19 junior division and received 3 million won.
What the AI participation showed
The AI system's presence was the notable change in the event, but the public reporting does not support a simple machine-versus-human verdict. The Korea Times described the agent as a special guest participant, and Newsis said it faced the same problems as human hackers. Neither retrieved report published the agent's score, completion rate, ranking, or the amount of human supervision involved.
That makes the showcase evidence that autonomous agents can be placed inside a live competition workflow, not a benchmark proving that an AI system outperformed expert teams. The distinction matters because capture-the-flag performance depends on the challenge mix, tool access, time limits, and rules governing assistance.
Why security teams should care
For practitioners, the useful signal is operational. An agent that can inspect unfamiliar targets, form hypotheses, test them, and continue after failed attempts could compress parts of vulnerability research. The same autonomy also raises familiar control questions: which systems the agent may touch, how actions are logged, when a person must approve a step, and how organizers distinguish a valid finding from unsafe behavior.
Codegate did not answer those deployment questions publicly. It did, however, move the discussion from a staged demonstration toward a shared problem environment with experienced human competitors. Future evaluations will be more informative if organizers publish task-level results, resource limits, supervision rules, and reproducible comparisons rather than relying on the novelty of an AI entrant.
Key Points
- 1A KAIST and Codegate Security Forum AI agent entered the Codegate 2026 finals as a special guest and worked on the same vulnerability-finding problems as human contestants.
- 2The preliminary round drew 3,333 entrants from 88 countries; BunkyoWesterns won the general division and Kim Jun-won won the junior division.
- 3The retrieved reports did not disclose the AI agent's score, ranking, completion rate, or supervision level, so the event should not be treated as a human-versus-AI performance benchmark.
Scoring Rationale
A live international security competition placed an autonomous AI participant into the same challenge environment as expert human teams, making the event relevant to agentic vulnerability research. Its practical significance is limited by the absence of published AI scores, supervision details, or reproducible performance data.
Sources
Public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems
