Findings/public-ctf-benchmarks-contaminated

Scores on public CTF benchmarks can be inflated when agents find published solutions, and static benchmarks lose validity as their flaws are patched.

Reportedmeasured2 evidence records from 2 independent sourcesassistant-drafted
Scope: what this does not show

One contamination measurement (CTFusion, on NYU CTF Bench) and one position paper that argues, without new measurements, that static benchmarks go stale.

Reported: Stated by one source and not yet corroborated or challenged.

Evidence

Key questions that rely on this finding

Status history

  1. 2026-05-12ReportedCTFusion shows web-searching agents inflate public CTF scores. · record
  2. 2026-05-21CorroboratedA separate paper argues static cyber benchmarks decay. · record
  3. 2026-09-25ReportedcorrectionThe 2026-05-21 paper argues that benchmarks go stale but does not measure or independently test contamination, so the measured part of this claim rests on CTFusion alone. · record