Zeroday Cloud
Hidden bug 1
Hidden bug 2
Hidden bug 1
Hidden bug 1
Hidden bug 1
Hidden bug 2
Wiz Research

First-of-its-kind Cloud Hacking Competition

Join the world's top researchers in a competition to find zero-day vulnerabilities in core open-source software powering the cloud. Put your skills to the test, win huge prizes from our $4.5M prize pool, and help make the cloud a safer place.

Submit your exploit by

00
Days
:
00
Hours
:
00
Min
:
00
Sec

Sunday, December 1, 2025

In Partnership With:

AWS
Google Cloud
Microsoft
Title Background

How it works

Pick your targets

Pick your targets

Research to find critical vulnerabilities in the open-source software that powers the cloud, and submit your entry by Dec 1

Demonstrate your exploit

Demonstrate your exploit

Accepted submissions will be invited to demonstrate their exploit, live on stage, in London on Dec 10-11

Claim your prize

Claim your prize

Successful exploit demonstrations will win generous payouts and be responsibly disclosed to relevant vendors

For more information check out our contest rules and FAQ


To be eligible to participate all team members must register to the HackerOne platform and complete the ID verification, Tax Forms, and payment preferences by November 20

London

Time & Place

Black Hat Europe 2025

ExCeL, London, UK | December 10-11, 2025

Title Background

Targets & Payouts

Submitted exploits should result in total compromise of the target, meaning a 0-click unauthenticated Remote Code Execution (RCE) vulnerability, unless specified otherwise.

AI
Ollama

Ollama

Runs consumer AI models in the cloud.


$25,000
vLLM

vLLM

Powers fast LLM endpoints in the cloud.


$25,000
NVIDIA Container Toolkit

NVIDIA Container Toolkit

Enables GPU access for containerized cloud workloads.


$40,000
Container escape
Kubernetes & Cloud-Native
Kubelet Server

Kubelet Server

Manages Pods on each Kubernetes Node.


$40,000
K8s API Server

K8s API Server

The central control plane for Kubernetes clusters.


$80,000
Grafana

Grafana

The unified observability dashboard for Kubernetes.


$10,000
Authenticated RCE

$40,000
Unauthenticated RCE (pre-auth)
Fluent Bit

Fluent Bit

The lightweight standard for log aggregation across clusters.


$10,000
Prometheus

Prometheus

The cloud-native standard for metrics and alerting.


$40,000
Containers & Virtualization

Exploits in this section should result in a full Container/VM Escape. This will be tested by executing a predefined binary located on the host machine.

Docker

Docker

The industry standard for running containers.


$40,000
User-provided image

$60,000
Arbitrary image
Containerd

Containerd

The core container runtime in Kubernetes.


$40,000
User-provided image

$60,000
Arbitrary image
Linux Kernel

Linux Kernel

The OS powering most cloud VMs.


$30,000
Container escape on Ubuntu host
Web servers
Envoy

Envoy

Manages microservice traffic in service mesh environments.


$50,000
Caddy

Caddy

Popular Go server for cloud apps.


$50,000
Tomcat

Tomcat

Runs enterprise Java applications in the cloud.


$100,000
Nginx

Nginx

The industry standard for web serving, reverse proxying, and ingress.


$300,000
Databases
Redis

Redis

Provides high-speed caching for cloud apps.


$25,000
Authenticated RCE

$100,000
Unauthenticated RCE (pre-auth)
PostgreSQL

PostgreSQL

Provides high-speed caching for cloud apps.


$20,000
Authenticated RCE

$100,000
Unauthenticated RCE (pre-auth)
MariaDB

MariaDB

Popular managed database engine.


$20,000
Authenticated RCE

$100,000
Unauthenticated RCE (pre-auth)
DevOps & Automation
Apache Airflow

Apache Airflow

Schedules cloud data workflows.


$40,000
Jenkins

Jenkins

Automates cloud app deployments.


$40,000
GitLab CE

GitLab CE

Popular DevOps platform.


$40,000
Title Background
Invitation to a closed research conference

Participate for a chance to get invited to a closed research conference mid-2026

Style bonus gift

Stylish exploits are much appreciated - be creative and surprise us!

Frequently Asked Questions


Anyone over the age of majority in their country/state of residence can participate. Teams of 2–5 members or individual participants may enter. Employees of Wiz, its affiliates, and partner companies (AWS, GCP, Azure) cannot participate. Participants cannot be residents of embargoed or sanctioned countries (e.g., Russia, China, Iran, North Korea, Cuba, Sudan, Syria, Libya, Lebanon, or restricted regions like Crimea, Donetsk, etc.). If competing as part of a company, only one individual or one team can represent that company, and you must have proper authorization from your employer to register and bind the company to the contest rules. For complete eligibility requirements, please review the full contest rules.

Hacker

Ready to demonstrate your exploit on stage?