OWASP GenAI Security Project DEFCON 33 Insecure Agents Hackathon

Date
2025-08-08
Location
DEFCON 33, W4 / C206 (OWASP Community Room), Las Vegas, NV, USA
Host
Personal

About this event

If you care about how AI agents fail in the real world, this is the room to be in. The OWASP GenAI Security Project DEFCON 33 Insecure Agents Hackathon is a hands-on session built for people who want to test, break, analyze, and improve the security of GenAI-powered agents in a live community setting. Expect practical experimentation, technical discussion, and the kind of fast feedback loop that only happens when curious builders and security-minded people work side by side. What Is This? This hackathon brings the OWASP GenAI Security Project into a DEFCON environment where ideas can be pressure-tested instead of just discussed. The focus is on insecure agents: how agentic systems behave under stress, where they expose weak assumptions, and what security lessons emerge when you actively try to misuse or manipulate them. Rather than a passive talk, this is designed as an interactive working session. You should expect a collaborative format where participants explore attack paths, failure modes, defensive patterns, and practical ways to think about GenAI agent risk. The value is in doing, observing, and comparing approaches with others who are looking at the same class of problems from different angles. Because it is connected to OWASP and taking place at DEFCON 33, the event sits at a useful intersection: application security, AI engineering, and open community learning. That makes it a strong fit for people who want to move beyond broad AI security claims and get closer to concrete system behavior. What to Expect The session is likely to feel more like a workshop lab than a conference lecture. You can expect time spent examining how agents interact with instructions, tools, data, and external inputs, with discussion centered on what actually creates risk in agent-based systems. Activities may include: Exploring insecure patterns in GenAI agents Testing prompt, tool-use, or workflow assumptions Discussing attack surfaces unique to agentic systems Comparing mitigation ideas and secure design approaches Collaborating with other attendees on experiments and findings One of the best parts of a hackathon format is the speed of learning. You see how others frame the problem, what they try first, where systems break, and which defenses hold up under scrutiny. That makes the session useful whether you arrive with a deep security background or with direct experience building AI features and wanting to understand where they are vulnerable. Because the event is in person, expect a more dynamic back-and-forth than you would get in an online session. People can share screens, sketch ideas, challenge assumptions, and iterate quickly. If you like technical events where the conversation moves fast and the substance stays high, this format will feel productive. Why Attend AI security is moving from theory to implementation, and agentic systems are raising a new set of questions. This event gives you a chance to work through those questions with people who care about the details: how instructions propagate, how tools can be abused, how trust boundaries shift, and how seemingly small design choices can create outsized security problems. You should attend if you want sharper instincts about how GenAI agents fail and what more secure patterns might look like. Even if you are already following the space, there is a big difference between reading about agent risk and seeing attack ideas, system behavior, and mitigations discussed in a live working session. A few likely takeaways: A clearer mental model of agent security risks Better language for discussing insecure agent behavior with your team or community Exposure to how others evaluate and test GenAI systems Practical ideas you can bring back to your own security reviews, prototypes, or product decisions There is also value in the room itself. DEFCON attracts people who are comfortable probing systems at their edges, and OWASP communities tend to translate that curiosity into usable security practice. That combination makes this event especially worthwhile for attendees who want signal, not hype. Practical Details The event takes place in person at DEFCON 33 in W4 / C206 (OWASP Community Room), Las Vegas, USA. If you are already attending DEFCON, this is an easy way to plug into a focused GenAI security session without leaving the conference environment. It starts on Friday, August 8 at 11:00 AM PDT. Since this is a live, collaborative hackathon-style event, arriving on time will help you get the most out of the session and settle into the working flow from the beginning. A few useful expectations for attendees: This is an in-person community event, so plan for discussion and participation rather than passive listening The audience will likely span security practitioners, builders, and researchers, so the conversation should be interdisciplinary The setting is the OWASP Community Room, which signals an open, collaborative environment grounded in practical security thinking If your DEFCON schedule includes AI, application security, red teaming, or emerging software risk, this is a strong session to prioritize. It is specific enough to be technically meaningful and open enough to welcome people who want to contribute, learn fast, and leave with a better understanding of insecure GenAI agents.

Who should attend

This is for you if you want to get hands-on with the security realities of GenAI agents rather than just talk about them in the abstract. - You build or prototype **AI agents, copilots, or LLM-powered workflows** and want to understand where they can be manipulated, misdirected, or misused. - You work in **application security, product security, red teaming, or security research** and are looking to map familiar security thinking onto agentic systems. - You are active in the **OWASP or broader security community** and want to collaborate with others on a timely, technically grounded AI security problem space. - You attend **DEFCON** for sessions where you can test ideas, challenge assumptions, and learn directly from other practitioners in the room. - You are curious about **prompting, tool use, trust boundaries, system behavior, and failure modes** in GenAI applications and want examples you can reason about practically. - You want takeaways you can bring back to your team, whether that means better threat modeling, stronger design reviews, or clearer conversations about AI risk and mitigations.

Speakers

Topics

Registration

Register / Get tickets