CrowdStrike and AWS Launch $100,000 Competition to Target AI Agents Starting August 31

AI Unlocked: Agents of Chaos pits researchers against autonomous agents armed by a fictional adversary, highlighting that agent security has become a discipline in its own right within the corporate security team.
CrowdStrike launched the AI Unlocked: Agents of Chaos competition on Sunday, August 31, a virtual game in partnership with Amazon Web Services that offers $100,000 across three acts to those who can subvert AI agents in simulated attack scenarios. The format is explicit red teaming: prompt injection, sandbox escapes, manipulated toolchains to lead the agent to act outside the authorized scope.
The prize distribution already indicates where CrowdStrike believes the boundary has become tougher. The first act, The Sanctum, runs from August 31 to September 7 and awards $10,000. The second, The Gatekeeper, continues until September 14 with $20,000 at stake. The third, The Basilisk, starts on September 15, ends on the 29th, and concentrates $70,000, with an in-person component during Fal.Con 2026. Pre-registration is open for participants from any country, and the game has a complete remote version running parallel to the Las Vegas phase.
Agent as an Attack Surface
The point that CrowdStrike wants to commercialize here is conceptual and comes late for those who have not started. An AI agent in production is not a chatbot with a nice prompt. It is a process that receives input, calls a tool, writes to a database, triggers a transaction, chains another model call. Each node is a new surface. Prompt injection crosses the boundary because most agent frameworks still treat text returned by the tool as if it were an instruction from the developer.
The defender's reading is straightforward. The SOC has gained a new type of indicator to monitor: the divergence between the agent's declared plan and the tool it actually calls. It is this kind of signal that the competition emphasizes. The incident involving OpenAI and Hugging Face, in which agents coordinated an unauthorized communication channel and compromised 41 production servers, has become the calling card for this conversation at every CISO table in the last fifteen days.
AWS in the Chain
AWS's presence is not decorative. Bedrock and SageMaker dispatch most of the production agents running on American cloud, and Amazon's security team has spent years grappling with privilege escalation in IAM and bucket policies. Bringing this know-how into a public agent competition is a fast way to train a generation of red teamers based on the real stack of customers, without waiting for universities and certifications to catch up. For enterprise clients, the subtext is that AWS is signaling which set of attack patterns it will defend by default.
CrowdStrike, in turn, arrives at the event in a strong commercial position. Its stock closed August among the largest gains in the cybersecurity sector in the S&P, with investors perceiving the ARR growth of Falcon as a direct response to the demand for AI workload protection. For the CISO who still treats agent security as an experimental project, the competition serves as a message: the provider is already selling, and the buyer is already paying.
Where the Game Lands Outside the U.S.
The event is international by design, and the recruitment map matters. In the United States, the natural targets are offensive security boutiques and internal teams at banks that are already running agent pilots with Bedrock or Vertex AI. In India, home to the world's largest mass of GenAI developers employed by consultancies like TCS, Infosys, Wipro, and the Global Capability Centers of Accenture and Cognizant, the competition serves as a technical showcase and simultaneous recruitment opportunity. An analyst who completes The Basilisk is worth more on LinkedIn by Friday than a traditional certificate after three months of coursework.
In the UK and the European Union, the reading is regulatory. The AI Act became applicable on August 2 for general-purpose systems, and agent providers face new risks of fines of up to 3% of global revenue for governance failures. Having trained red teamers in-house to attack agents has become a checklist item in DPIA, no longer a CISO wishlist. In Brazil and the rest of Latin America, where banks and retail have accelerated agentic AI pilots for customer service and credit in the last two quarters, the cost of not having an in-house red team is starting to be visible in the supplier's accounts. CrowdStrike is aware of this and is structuring the funnel.