Skip to content
safemode.space
All incidents
2023-08-11 (approximate)
security research
space

Hack-A-Sat satellite capture-the-flag series (2020-2023), including the on-orbit finals against Moonlighter

Confidence in this reading:
moderate

What happened

Hack-A-Sat is a capture-the-flag competition targeting satellite systems, run for the US Air Force and later Space Force by Cromulence LLC with The Aerospace Corporation, across four editions from 2020. The first three editions used ground-based emulators, digital twins and flatsats; the 2022 finals ran an attack-and-defend format in which each team held control of its own satellite and attacked the others', with the most impactful attack chaining a webserver flaw that leaked radio configurations into the injection of malicious attitude-control constants. The fourth edition, at DEF CON 31 in August 2023, ran seven of its nine finals challenges against Moonlighter, a purpose-built CubeSat in low Earth orbit, making it the first capture-the-flag competition to target a live spacecraft. Published challenges included a timing side-channel attack against an onboard security application, misuse of the GPS receiver to violate a geofence and to report a latitude above 80 degrees, reverse engineering to emit a chosen telemetry message, and cracking a ground-side password manager.

A sanctioned exercise, not an adversary operation. The vulnerabilities were authored by the organisers, so the presence of a defect is not evidence about real spacecraft. What the record captures is that the listed behaviours were performed by competent third parties against real satellite systems, and against a live spacecraft in the 2023 edition. Confidence is moderate throughout because the organiser's challenge descriptions are one-line statements of goal, not of mechanism.

Attack vector

Sanctioned competition access to a purpose-built on-orbit CubeSat and, in earlier editions, to emulators and flatsats, with organiser-authored vulnerabilities in flight software, onboard security applications, the GPS receiver path and ground-side services.

Operational impact

None outside the exercise. Moonlighter exists as a hacking sandbox; earlier editions ran against ground-based emulations. In the 2022 attack-and-defend edition, teams destabilised each other's simulated satellites as the scoring mechanism.

Affected segments

space, ground, link

Disclosed

2023-08-12

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

  • Cromulence LLC

    Tier 2: First-party publication by the competition's organiser of the challenges it authored. Authoritative about what each challenge required; not independent, and not technical write-up depth.

  • Cromulence LLC · Mike Walker · 2022-11-16

    Tier 2: First-party account by the competition's organiser of an event it ran. Not independent, but the only published account of the 2022 finals' attack detail.

  • Hack-A-Sat 4
    Other
    supporting

    Cromulence LLC / Hack-A-Sat

    Tier 2: The competition's own site. Authoritative for the event's format, the finalist teams, the prize pool and the on-orbit target.

  • Breaking Defense · 2023-08-14

    Tier 3: Named defence trade outlet with a bylined report. Independent of the organiser, but reporting rather than technical analysis.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.