Hack-A-Sat satellite capture-the-flag series (2020-2023), including the on-orbit finals against Moonlighter
What happened
Hack-A-Sat is a capture-the-flag competition targeting satellite systems, run for the US Air Force and later Space Force by Cromulence LLC with The Aerospace Corporation, across four editions from 2020. The first three editions used ground-based emulators, digital twins and flatsats; the 2022 finals ran an attack-and-defend format in which each team held control of its own satellite and attacked the others', with the most impactful attack chaining a webserver flaw that leaked radio configurations into the injection of malicious attitude-control constants. The fourth edition, at DEF CON 31 in August 2023, ran seven of its nine finals challenges against Moonlighter, a purpose-built CubeSat in low Earth orbit, making it the first capture-the-flag competition to target a live spacecraft. Published challenges included a timing side-channel attack against an onboard security application, misuse of the GPS receiver to violate a geofence and to report a latitude above 80 degrees, reverse engineering to emit a chosen telemetry message, and cracking a ground-side password manager.
A sanctioned exercise, not an adversary operation. The vulnerabilities were authored by the organisers, so the presence of a defect is not evidence about real spacecraft. What the record captures is that the listed behaviours were performed by competent third parties against real satellite systems, and against a live spacecraft in the 2023 edition. Confidence is moderate throughout because the organiser's challenge descriptions are one-line statements of goal, not of mechanism.
Attack vector
Sanctioned competition access to a purpose-built on-orbit CubeSat and, in earlier editions, to emulators and flatsats, with organiser-authored vulnerabilities in flight software, onboard security applications, the GPS receiver path and ground-side services.
Operational impact
None outside the exercise. Moonlighter exists as a hacking sandbox; earlier editions ran against ground-based emulations. In the 2022 attack-and-defend edition, teams destabilised each other's simulated satellites as the scoring mechanism.
Affected segments
space, ground, link
Disclosed
2023-08-12
SPARTA techniques evidenced
Each row is a technique this record evidences, with the reasoning and the source that attests to it.
What relationship, confidence, and evidence mean on the rows below
- Relationship
What kind of link this is between the technique and the target.
Mitigates: the target actively prevents, detects, or recovers from the technique.
Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.
Triggers obligation: the technique occurring is what triggers the duty the target imposes.
Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.
- Confidence
How strongly the source supports this mapping, not how severe the technique is.
High: the source supports the mapping squarely.
Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.
Low: the source reaches the technique only in part.
- Evidence
How close to the source text the mapping was made.
Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.
Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.
Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.
The 2022 finals' challenge material is recorded as including flight-software bugs and RISC-V return-oriented-programming chains, which is abuse of defects in software running on the vehicle. The account names the categories rather than the individual exploits, so confidence is moderate. The evidence type is derived rather than direct for the same reason confidence is moderate: the account is at the level of categories, so there is no on-point excerpt addressing this technique.
Cromulence's account of the 2022 finals records that the most impactful attack used malicious ADCS control constants to destabilise targeted satellites. EX-0012.08 names controller gains, estimator covariances and sensor bias terms as its editable targets, so control constants are the technique's own subject rather than an analogy to it.
Two Hack-A-Sat 4 challenges, 'Unintended Bug' and 'Christmas in August', required making the spacecraft act on a position that was not its true one: violating an onboard geofence, and reporting a latitude above 80 degrees. That is estimation and control treating a fabricated or biased measurement as ground truth, which is EX-0014.03's subject. The organiser's phrase is 'misuse the gps receiver', which does not say whether the signal, the receiver configuration or the downstream value was manipulated, so the mechanism is derived rather than described.
The organiser's published description of the Hack-A-Sat 4 challenge 'Ironbank' is a timing side-channel attack against the script security application running on the satellite. EX-0015 names timing among its passive side channels, so the source describes the technique by its own terms.
In the 2022 attack-and-defend format each team commanded satellites other than its own from ground infrastructure it controlled, which is the shape of IA-0008.01: transmitting mission-compatible signals to a spacecraft one does not operate. The competition supplied the ground segment, so the unauthorised quality is a property of the game rather than of the infrastructure, and the edge is derived on that account.
Cromulence records that the malicious attitude-control constants destabilised the targeted satellites, which is temporary impairment of the target's use of its own system, IMP-0002's definition. The effect was on other teams' simulated satellites within the exercise, which the editorial gloss records.
The Hack-A-Sat 4 challenge 'Script Kiddies' required reverse engineering sufficient to emit a specific telemetry message. REC-0001.01's subject is knowledge of flight and ground software sufficient to identify exploitable seams and to reproduce the system's behaviour, which is what producing a valid telemetry message from a reverse-engineered binary demonstrates.
The 2022 finals' webserver exploit is recorded as leaking radio configurations, which is exactly the RF-equipment intelligence REC-0003.01 describes competitors then acted on. The vector that produced the leak was an ordinary webserver flaw, so the edge is derived from the intelligence obtained rather than from a reconnaissance action the source names.
The Hack-A-Sat 4 ground challenge 'Finalpass' required cracking a password manager to obtain access to further system information. REC-0003.04 covers credentials that let an adversary authenticate as a legitimate actor in ground or supporting networks, which is the credential class a mission password manager holds.
Sources
The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.
A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.
Tier 2: First-party publication by the competition's organiser of the challenges it authored. Authoritative about what each challenge required; not independent, and not technical write-up depth.
Tier 2: First-party account by the competition's organiser of an event it ran. Not independent, but the only published account of the 2022 finals' attack detail.
Tier 2: The competition's own site. Authoritative for the event's format, the finalist teams, the prize pool and the on-orbit target.
Tier 3: Named defence trade outlet with a bylined report. Independent of the organiser, but reporting rather than technical analysis.
Every source SafeMode Space reproduces, and on what terms: sources and attribution.