
Editorial concept based on the DEF CON 34 visual identity. The hardware shown here is not the official attendee badge.
In June 1993, an 18-year-old kid threw a party for a friend who never showed up. The guest of honor — the operator of a small hacker bulletin board network called Platinum Net — had to leave town on short notice and vanished before the event even started. Instead of cancelling, the kid invited everyone he knew from every hacker community he could reach. About 100 people showed up to a Las Vegas hotel with no schedule, no signage, and a tape recorder standing in for a PA system.
That party is now DEF CON. The conference regularly draws more than 30,000 people, and its 34th edition adds an autonomous-only hacking competition and a badge built on an open-source security chip. Here’s the full story — where it came from, why it’s shaped like it is, and what DEF CON 34 says about where hacker culture is heading next.
TL;DR
- DEF CON began in 1993 as an accidental party thrown by 18-year-old Jeff Moss (“The Dark Tangent”) after the person he was organizing it for disappeared
- The name nods to the U.S. military’s DEFCON alert levels, popularized by the 1983 film WarGames — a fitting choice for a conference born from Cold War-era hacker culture
- In 2013, DEF CON asked federal agents to stay away for the first time in 20 years — one year after the NSA’s own director gave the conference’s keynote
- DEF CON’s Voting Village has spent years finding real vulnerabilities in U.S. election infrastructure and has directly shaped election security policy
- DEF CON 34 (August 6–9, 2026) runs under the theme “Agency” and hosts DEF CON’s first autonomous-only CTF, where AI agents pursue targets without real-time human control
Why This Matters to You
DEF CON isn’t a trade show. It’s the closest thing the hacking world has to a cultural capital — the place where offensive research gets published first, where government officials and researchers who’d otherwise be adversaries sit in the same room, and where techniques shown on stage this week show up in real incident reports six months later. If you work in security, DEF CON’s agenda is a preview of what you’ll be defending against next year. If you don’t, it’s still worth understanding — because the conference has quietly influenced how elections, cars, and medical devices get secured.
How a Cancelled Party Became an Institution
Jeff Moss ran a small pirate bulletin board called The Dark Tangent on a Fidonet-connected network called Platinum Net. When the network’s main sysop announced he was shutting down his node and moving away, Moss offered to throw him a farewell party in Las Vegas. The sysop then had to leave earlier than planned — for a sudden family job change — and disappeared before the party happened, leaving Moss holding the invitations with no guest of honor.
Rather than cancel, Moss opened the party to every hacker group he had contact with. Around 100 people turned up for DEF CON 1: no formal schedule, no badges as we know them today, folding chairs, and 12 speakers. It worked well enough that he did it again the next year, and the year after that.
The “Dark Tangent” handle, incidentally, is a misremembering — Moss was thinking of a comic book called D’Arc Tangent and recalled the name wrong. The mistake stuck, and so did the conference.
Where the Name Actually Comes From
The most commonly cited explanation ties the name to the U.S. Armed Forces’ DEFCON readiness scale — five levels running from DEFCON 5 (peacetime) down to DEFCON 1 (imminent nuclear war) — and specifically to the 1983 film WarGames, in which the DEFCON system plays a central role. For a conference rooted in Cold War-era phone phreaking and BBS culture, the reference fit.
A second, less-cited layer worth knowing: on a telephone keypad, the letters D-E-F map to the number 3, a small nod to the DTMF tone culture of phone phreaking — the practice of manipulating telephone signaling tones that predates computer hacking and shaped much of the generation that built DEF CON. This explanation is offered less consistently by sources than the WarGames connection, so treat it as a secondary layer rather than the definitive origin.
The Traditions That Make DEF CON, DEF CON
A few institutions have survived every venue change and every order-of-magnitude jump in attendance:
- Goons. The entire conference runs on an all-volunteer staff called Goons, who handle everything from crowd control to CTF administration to badge logistics. Their shirts change design every year and are never sold — they’re earned through service, which makes them one of the only status markers at DEF CON that has nothing to do with your job title or your employer’s booth budget.
- The Black Badge. The highest honor at the conference, awarded to the winners of specific flagship competitions. It comes with free admission to DEF CON for life.
- Spot the Fed. A running game where attendees try to identify federal agents in the crowd. Correctly spotting one gets both people a t-shirt — one that says “I spotted the fed,” the other “I am the fed.”
- Wall of Sheep. A public display, updated live, of credentials sniffed from attendees who used the conference network insecurely — usernames shown, passwords partially masked. It’s public shaming as security education: a blunt, memorable lesson in why you don’t log into anything over unencrypted Wi-Fi at a hacker conference.
The Year the Keynote Speaker Became Persona Non Grata
Here’s the sharpest turn in DEF CON’s history, and it happened in the space of twelve months.
In 2012, General Keith Alexander — then director of the NSA — delivered DEF CON’s keynote, speaking on “Shared Values, Shared Responsibilities.” It was framed as a moment of bridge-building between the hacker community and the agency that, in the public imagination, represented everything hackers were supposed to be suspicious of.
One year later, Edward Snowden’s leaks exposed the NSA’s PRISM program and the scale of its bulk surveillance. Jeff Moss’s response was blunt: for the first time in the conference’s 20-year history, he asked federal government representatives to sit DEF CON 2013 out entirely. The same agency whose director had held the stage a year earlier was now being told, publicly, not to come.
It’s a case study in how fast trust can evaporate in a community that runs on it — and a reminder that DEF CON’s relationship with government has never been simple. It has ranged from open collaboration to open confrontation, sometimes within a single conference cycle.
The Village That Changed Election Security Policy
DEF CON’s “Villages” are themed sub-conferences-within-the-conference, each built around a specific attack surface. The most consequential one might be the Voting Village, launched in 2017.
On its first day, attendees remotely compromised an AVS WinVote machine in under 90 minutes using a vulnerability first documented in 2003. Other machines followed. The Voting Village has returned every year since, and its reports have become reference material in the U.S. election security policy conversation, cited by researchers, journalists, and lawmakers for years after each finding.
It’s a good example of what DEF CON actually does at its best: take infrastructure the public is told to trust, hand it to several thousand skeptical strangers, and see what breaks.
DEF CON 34: What’s Happening in 2026
DEF CON 34 runs August 6–9, 2026, at the Las Vegas Convention Center’s West Hall — right on the heels of Black Hat USA (August 1–6, Mandalay Bay) and overlapping with BSides Las Vegas (August 3–5, Tuscany Suites & Casino). The three events together turn the first two weeks of August into what regulars just call hacker week in Vegas.
The numbering lines up cleanly with the history above: DEF CON 1 was 1993, and even the pandemic year ran virtually as DEF CON 28 rather than being skipped, so 2026 is honestly the 34th consecutive edition.
This Year’s Theme: “Agency”
DEF CON 34’s theme, “Agency,” is about self-determination in an increasingly automated world — and this year, that theme has a second, more literal meaning.
AI Agents Are Now Hacking on Their Own
The AI Village’s new HALctf competition is the clearest sign of where offensive security is heading. It is DEF CON’s first autonomous-only CTF: participants deploy self-contained agents built with open-source models, then let them scout, exploit, and pivot through live targets drawn from other CTFs. Humans build and submit the operators, but they do not drive them in real time.
That marks a formal shift for a trend we’ve been tracking closely — see our coverage of agentic AI as the enterprise’s new blind spot and how nation-state actors have already started weaponizing AI across the full attack chain. HALctf turns the same question into a public experiment: how far can an open model get when it has tools, targets, and nobody leaning over the keyboard to rescue it?
A Badge You’re Meant to Take Apart
This year’s electronic badge was designed by hardware researcher Bunnie Huang around his open-source Baochip. DEF CON first teased the hardware with an SAO accessory specification, then revealed a fully inspectable platform intended to serve as a security token, password manager, hardware security module, and — inevitably — a source of blinking-light experiments. It’s a small, physical version of the same philosophy behind the Voting Village: trust, but verify by taking it apart yourself.
The Rest of the Villages
- Capture the Packet — the Packet Hacking Village’s Black Badge-eligible network forensics competition
- Car Hacking Village CTF — live attacks against real vehicle architectures
- STARPWN — the Aerospace Village’s satellite and aviation-systems challenge
- Code Cadaver — the Biohacking Village’s medical device exploitation contest
- Crack Me If You Can 2026 — the long-running annual password-cracking marathon
If you’ve followed our reporting on AI agent manipulation techniques or the fallout from OpenClaw’s viral AI agent security crisis, this year’s Village lineup should feel familiar: the attack surface has quietly expanded from “networks and servers” to “cars, satellites, medical implants, and now the AI agents doing the hacking themselves.”
What Defenders Should Watch After DEF CON 34
The useful output of DEF CON is not the stage lighting or the first breathless headline about a new exploit. It is what survives scrutiny afterward: slides, code, vendor advisories, reproducible attack paths, and the defensive telemetry needed to see them.
Security teams should watch for disclosures that change an actual exposure decision, especially agent-tool authorization flaws, automotive and embedded-system attack paths, and research that turns a laboratory trick into a repeatable technique. A conference demo is not automatically an incident in waiting. But once the prerequisites, affected versions, and observable behavior are clear, it belongs in threat modeling, detection engineering, and patch prioritization — not in a bookmark folder nobody opens again.
From a Cancelled Party to a Policy-Shaping Institution
What’s easy to miss in the badge photos and Wall of Sheep screenshots is the throughline: DEF CON has never been a marketing event. It started because one person refused to let a party fall apart, and three decades later it still runs on the same instinct — invite the room, hand people real systems, and see what actually breaks under scrutiny nobody’s paying for.
That’s why a badge you can fully inspect and an AI agent competing in its own CTF fit on the same schedule as a tradition of spotting federal agents in the hallway. It’s the same idea, applied to whatever the current attack surface happens to be.
Related Posts
- Agentic AI: The Enterprise Blind Spot That Attackers Already Found — the same autonomous-agent trend behind DEF CON 34’s HALctf competition, seen from the enterprise defense side
- When the Weapon Learns: How Nation-States Weaponized AI Across the Full Attack Chain — what changes when autonomous offensive agents move from an isolated CTF into real attack chains
- OpenClaw: How the Viral AI Agent Became 2026’s First Major Security Crisis — a real-world case study in what goes wrong when autonomous agents get deployed faster than they get secured
- AI Agent Traps: A Manipulation Taxonomy — the techniques used to steer autonomous agents off-course, relevant to judging what HALctf is actually testing
Sources
- DEF CON 34 Official Site
- DEF CON 34 Theme and Style Guide
- DEF CON 34 Contests
- DEF CON 34 Villages
- DEF CON 34 Opens Today: AI Agents Graduate From Novelty to Standard Hacking Weapon — Tech Times
- Jeff Moss on DEF CON and its shadow power — The Record
- Jeff Moss (hacker) — Wikipedia
- DEF CON — Wikipedia
- DEF CON: From Failed Party and Movie Inspiration to Global Dominance — Exabeam
- Feds banned from DEF CON by founder — The Register
- DEF CON and Black Hat: Hacker communities treat the NSA differently — Slate
- How 5 Years of DEF CON’s Voting Village Has Shaped Election Security — Dark Reading
- Inside the DEF CON hacker conference’s election security-focused Voting Village — Axios