Share this article

Meet FumbleChain, the Deliberately Flawed Blockchain

There's a new blockchain for developers to break at will. The "capture the flag" project from Kudelski Security is meant to educate.

Updated Sep 13, 2021, 11:20 a.m. Published Aug 14, 2019, 3:00 p.m.
Screen Shot 2019-08-14 at 10.46.42 AM

FumbleChain makes breaking blockchains a sport.

Demonstrated for the first time last Thursday at the Black Hat infosec event, the deliberately flawed technology is meant to act as an educational tool for crypto developers.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

“Basically, this what people call CTF, or ‘capture the flag,’” explained Nils Amiet, a senior security engineer at Kudelski and one of the developers behind the project. “Whenever you solve a challenge, that is when you get the flag. … The challenges are pretty technical.”

Through these curated and gamified challenges, the aim is to teach users about the complexities of blockchain technology.

According to Dan Guido, co-founder and CEO of cybersecurity firm Trail of Bits, which has audited over 20 different cryptocurrency projects, FumbleChain is similar to the wargames used in traditional software development.

“Competitions and training exercises are used throughout the security industry, sometimes in live competitions of 30,000 or more players at one time, to help educate and demonstrate the knowledge that participants have gained,” said Guido, adding:

“It's long overdue for blockchain security to have its own wargame.”

Users collect game points dubbed “fumblecoins” every time they exploit a vulnerability in the FumbleChain blockchain and capture one flag. (The coins are only of value within the game itself.) Kudelski’s Amiet says FumbleChain’s core technology “looks a lot like bitcoin,” only simpler.

Daryl Hok, COO of blockchain cybersecurity company CertiK, said FumbleChain is designed to make blockchain “approachable” for engineers coming from a diverse set of backgrounds.

“[FumbleChain] provides a gamified, wargames model that may interest a broad audience with its approachability and incentives,” said Hok. “The project currently focuses on source code level attacks, as opposed to economically oriented attacks, but that may be something that is added in the future.”

Indeed, Kudelski Head of Cybersecurity Research Nathan Hamiel hopes FumbleChain will take on a life of its own now that the code has been open-sourced on GitHub.

“So many projects like this have a tendency to wither away as people move on to other things,” said Hamiel. “I feel the only way to have a successful project like this is to have it be open-source. … We’re hoping people continue to not only utilize but develop new challenges and really come on board and be a part of the project.”

Lessons from battle

FumbleChain was birthed after Kudelski completed a number of security audits for cryptocurrency projects including privacy coins Monero and Zcash, said Hamiel.

The first challenge on FumbleChain simulates what is called a replay attack, where duplicate transactions are generated on two separate chains. This attack vector was a concern back in 2017 during the chain split between bitcoin and bitcoin cash.

Other blockchain attack vectors identified on FumbleChain include transaction input validation, public key and wallet address mismatch, as well as denial of service or “spam” attacks.

Speaking to these network vulnerabilities, Hamiel said:

“The blockchain ecosystem has many of the same vulnerabilities that a traditional [software] ecosystem has. If you think about it at a low-level, a blockchain is not very useful without the ecosystem around it … exchanges, wallets, etc.”

As such, FumbleChain also offers a browser-based web wallet and blockchain explorer to mess around with.

Further expanding FumbleChain to include both smart-contract challenges and lessons on blockchain privacy are next steps both Hamiel and Amiet hope to see in the months to come.

At the very least, says Marc Laliberte, a senior security analyst at WatchGuard Technologies, FumbleChain could have an impact on existing blockchain applications by creating opportunities for “hands-on” learning.

Laliberte said:

“Experience with identifying and exploiting common vulnerabilities is a great way to learn how to not make the same mistakes yourself. FumbleChain provides an opportunity for developers and enthusiasts to learn about common flaws and play around in a safe ecosystem, and then take that knowledge back to their own applications.”

FumbleChain image via Kudelski Security

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

How Much Longer Until We Consider the Bitcoin Power Law Model Invalid?

Power Law (Glassnode)

As the gap between spot bitcoin price and the power law widens, investors are left questioning whether mean reversion is coming or if another cornerstone model is approaching its end.

What to know:

  • Bitcoin has largely tracked its long standing power law trend this cycle, though it now trades about 32% below the model.
  • Earlier models like stock to flow have already failed, with its current implied valuation near $1.3 million per bitcoin