Hacking Games: 15 That Actually Teach Real Skills (2026)

CTF & Practice
16 min read
Hacking Games: 15 That Actually Teach Real Skills (2026)
On this page
  1. What Counts as a Hacking Game?
  2. Hacking Games on Steam That Teach Real Skills
    1. 1. Bitburner (free): the one to start with
    2. 2. Hacknet ($9.99): the best terminal feel
    3. 3. hackmud ($18.99): scripting against other players
    4. 4. EXAPUNKS ($19.99) and TIS-100 ($6.99): assembly as a puzzle
    5. 5. Grey Hack ($19.99): a multiplayer Unix sandbox
    6. 6. NITE Team 4 ($19.99): the closest to real methodology
    7. Fun, but skip them if you want to learn
  3. Free Hacking Games Where the Hacking Is Real
    1. 7. OverTheWire Bandit (and Natas): the classic first game
    2. 8. OWASP Juice Shop: a whole vulnerable web shop
    3. 9. Google's XSS game: cross-site scripting in six small apps
    4. 10. Microcorruption: reverse engineering a lock
    5. 11. Cryptopals: breaking crypto by writing code
    6. 12. Hacker101 CTF: capture the flag from HackerOne
    7. 13. SANS Holiday Hack Challenge: the most "game" of them all
    8. 14. Gandalf: Agent Breaker: hacking AI with words
    9. 15. HackerDNA Daily Hack: one real puzzle a day
  4. Which Hacking Game Should You Start With?
  5. From Hacking Games to Real CTFs
  6. Legal and Ethical Considerations
  7. Frequently Asked Questions
  8. Your Next Steps

Search for hacking games and you get two very different piles of results. One pile is video games where you play a hacker: a moody terminal, a countdown, a trace closing in. The other pile is games where the hacking is real, because the target is a deliberately vulnerable system and the only way to win is to actually break it. Both can be fun. Only one of them teaches you anything you can use at work or in a CTF. If you want to feel the difference in the next ten minutes, open today's HackerDNA Daily Hack: one short, self-contained challenge a day, in the browser, with no setup.

This guide sorts the 15 hacking games worth your time by the only question that matters for a beginner: does the skill transfer? Six are commercial games you can buy or download on Steam, nine are free practice games run by security organizations. For each one you get what you actually do, what real skill it maps to, and who should skip it.

TL;DR: The best hacking games for learning are the ones where you type real commands or write real code. On Steam, start with Bitburner (free, real JavaScript) or Hacknet (Unix-style terminal). For real hacking, start with OverTheWire Bandit, OWASP Juice Shop, and Google's XSS game. Skip anything where hacking is a button press: it is fun, but nothing carries over.

What Counts as a Hacking Game?

A hacking game is any game whose main mechanic is breaking into, reprogramming, or defending computer systems. The label covers everything from a mini-game in an action title to a full capture-the-flag platform, so it helps to split the category into three.

  • Hacking-flavored games: hacking is a button, a mini-game, or a timing puzzle. Watch Dogs is the reference example: according to Wikipedia's development history, its core hacking mechanic "was reduced to a single button" on the hero's phone. Great for an evening, zero transfer.
  • Hacking simulators: you type into a fake terminal or write code in a sandboxed world. The systems are fictional, but the habits are real: reading output, chaining commands, automating boring steps.
  • Real hacking games: wargames, CTF platforms, and vulnerable apps. The target is real software with real flaws, and a scoreboard or level system turns it into a game. This is where actual skills get built.

The list below drops the first group entirely and ranks the other two. Commercial games come first because they are the gentler on-ramp, then the free platforms where the hacking stops being pretend.

Hacking Games on Steam That Teach Real Skills

Prices and review labels below were checked on the Steam store in September 2026. Steam prices move with sales, so treat them as a guide.

1. Bitburner (free): the one to start with

If you only try one game from this section, make it this one. Bitburner is a free, open-source incremental game where you progress by writing scripts in JavaScript against the game's own API. Steam lists the developers as "Fulcrum Games, Hydroflame, over 250 github contributors," the reviews sit at Very Positive, and you can also play it in the browser from the official GitHub project.

The JavaScript is not a toy dialect. It is the same language you will use to write XSS payloads and browser automation later, and the game's early-game loop looks like this:

/** @param {NS} ns */
export async function main(ns) {
  const target = "n00dles";
  while (true) {
    if (ns.getServerSecurityLevel(target) > ns.getServerMinSecurityLevel(target) + 5) {
      await ns.weaken(target);
    } else if (ns.getServerMoneyAvailable(target) < ns.getServerMaxMoney(target) * 0.75) {
      await ns.grow(target);
    } else {
      await ns.hack(target);
    }
  }
}

That is a loop, conditionals, async calls, and state checks: the exact building blocks of every recon script you will ever write. The "hacking" is abstract, but the programming is not. Skip it if you hate incremental games, because the first few hours are slow by design.

2. Hacknet ($9.99): the best terminal feel

Hacknet, released in 2015 by Team Fractal Alligator (the solo Australian developer Matt Trobbiani, per Wikipedia), is the closest thing to a hacker movie you can play that still respects a terminal. Steam describes it as "based on actual UNIX commands," and it shows: you move with ls and cd, copy files with scp, and clean up logs with rm.

The attack side is simplified. You probe a target to see which ports it has open, run programs like SSHcrack 22 or FTPBounce 21 to open them, then PortHack for admin. Real SSH does not fall over because you typed its name, but the workflow (enumerate, open services, escalate, cover tracks) is the right mental shape. With more than 26,000 reviews at Very Positive, it is also the most-reviewed game on this list. The Labyrinths DLC adds a harder campaign.

3. hackmud ($18.99): scripting against other players

hackmud, from ComCODE (2016), is a persistent multiplayer text MUD set in a retro-cyberpunk world. You start by running scripts other players wrote, which is a lesson in itself: several of them are traps. Later you write your own in the game's JavaScript environment. Steam says it "creates coders, often from players who have never written a line of code before." The learning curve is steep and the community is the content, which explains the Mostly Positive reviews.

4. EXAPUNKS ($19.99) and TIS-100 ($6.99): assembly as a puzzle

Both come from Zachtronics. In EXAPUNKS (2018) you program little agents in an assembly-like language to break into networks, reading the rules from in-game hacker zines. TIS-100 (2015) calls itself "the assembly language programming game you never asked for" and ships a printable reference manual. Neither teaches x86 directly. What they teach is registers, jumps, and thinking in tiny instructions, which is the hardest mental shift in reverse engineering and binary exploitation. TIS-100 is Overwhelmingly Positive on Steam and one of the cheapest games here.

5. Grey Hack ($19.99): a multiplayer Unix sandbox

Grey Hack (Loading Home, 2017) is an always-online hacking simulator with procedurally generated networks, a terminal "based on real UNIX commands," a file explorer, and a text editor. Commands and exploits are written in GreyScript, a fork of the MiniScript language, and players rewrite them freely. Steam still labels it a beta (version 0.9) years after its 2017 release, so expect rough edges. There is a single-player mode if other players stealing your files is not your idea of relaxing.

6. NITE Team 4 ($19.99): the closest to real methodology

NITE Team 4 (Alice & Smith, 2019) is the commercial game that leans hardest on real techniques. Its Training Boot Camp covers information gathering, port scanning, fingerprinting, exploit research, and digital forensics, across more than 70 missions. It is Windows and Mac only. We could not verify how closely its tools mirror the real ones, so treat it as a methodology primer rather than tool training.

Fun, but skip them if you want to learn

  • Uplink: a 2001 classic with a great atmosphere, but Wikipedia describes its hacking as "highly simplified, and almost fully automated." You click tools, you do not use them.
  • Hacker Simulator ($24.99): its own Steam page says it is "not a realistic 1:1 hacking simulation." It does borrow a simplified version of the Aircrack-ng Wi-Fi suite, which is a nice first look at the tool names.
  • Watch Dogs: an open-world action game. Hacking a traffic light with one button is not a skill.
GamePrice (Sept 2026)What you actually doReal skill it maps to
BitburnerFreeWrite JavaScript against a game APIScripting, automation
Hacknet$9.99Type Unix-style commandsTerminal fluency, attack workflow
hackmud$18.99Run and write scripts in a multiplayer MUDJavaScript, reading untrusted code
EXAPUNKS / TIS-100$19.99 / $6.99Write assembly-like codeLow-level thinking for reversing
Grey Hack$19.99Terminal plus GreyScript in a shared worldUnix commands, scripting
NITE Team 4$19.99Guided missions with recon and forensicsMethodology
Uplink / Watch DogsVariesClick tools or press a buttonAlmost none
💻
Practice this now: Nmap Commands Lab - the real version of Hacknet's probe: scan a live target with Nmap from a terminal in your browser, then follow the open ports to a foothold. Free, with guidance at every step.

Free Hacking Games Where the Hacking Is Real

Everything in this section is free, legal, and built by people who want you to attack it. The systems are real, which means the skills are too.

7. OverTheWire Bandit (and Natas): the classic first game

Bandit is where most people's real hacking starts, and for good reason. Each level hides the password for the next one somewhere on a Linux server, and you find it with the terminal. There are currently 34 levels, numbered 0 to 33. Your first move is the whole tutorial:

ssh [email protected] -p 2220
# password: bandit0
bandit0@bandit:~$ ls
readme
bandit0@bandit:~$ cat readme

By the late levels you are dealing with setuid binaries, cron jobs, and git history, all things you will meet again in privilege escalation. When Bandit is done, Natas does the same for web security, one password-protected website per level. If you would rather stay in the browser from day one, HackThisSite's Basic missions use the same password-per-level format, and our HackThisSite beginner's guide explains what each one teaches. Our OverTheWire wargames guide walks through every wargame and the order to play them in. Site: overthewire.org.

8. OWASP Juice Shop: a whole vulnerable web shop

OWASP Juice Shop is a fake online juice store packed with real vulnerabilities, from SQL injection to broken access control. It is an OWASP Flagship project, free under the MIT license, and it runs locally in one command:

docker run --rm -p 127.0.0.1:3000:3000 bkimminich/juice-shop

Browse to http://localhost:3000 and start poking. The game part is a hidden score board that tracks every challenge you solve, and finding the score board is itself one of the challenges. Pair it with Burp Suite and you are doing exactly what a junior web pentester does on day one.

9. Google's XSS game: cross-site scripting in six small apps

Google's XSS game is short and sharp. Each level is a tiny web app with a cross-site scripting flaw, and you win by making it run alert(). It is old, but XSS has not changed much, and the later levels teach something tutorials usually skip: that the vulnerable code is often in JavaScript on the page, not on the server.

10. Microcorruption: reverse engineering a lock

Microcorruption was built by Matasano Security and Square in 2014 and is still online. You get a browser debugger attached to the firmware of a fictional electronic lock, with disassembly, memory, registers, and breakpoints, and your job is to open the lock. The code is real MSP430 assembly. It is the gentlest introduction to reverse engineering we know of, and it pairs perfectly with EXAPUNKS if the Zachtronics games clicked for you.

11. Cryptopals: breaking crypto by writing code

The Cryptopals challenges are 8 sets of exercises that start with hex and base64 conversions and end with attacks on real-world cryptography. There is no scoreboard and no story, just problems that get harder. You need to write code (Python is the usual choice), which makes it the best follow-up to Bitburner for anyone who liked the programming more than the hacking theme.

12. Hacker101 CTF: capture the flag from HackerOne

HackerOne runs Hacker101 CTF, a free set of web challenges with flags to capture. When it launched in 2018, HackerOne tied flags to invitations into private bug bounty programs. The current about page no longer mentions that, so play it as practice, not as a ticket. It is a good bridge between Juice Shop and real bug bounty targets.

13. SANS Holiday Hack Challenge: the most "game" of them all

Every year SANS opens a free online world with avatars, a story, and dozens of real challenges. The 2025 edition, "Revenge of the Gnome(s)," launched on November 5, 2025 to mark the challenge's tenth anniversary, with 10 to 15 minute micro-challenges for beginners and harder capstones for veterans. The range stays open year-round, even after the contest entries close, and a new edition usually opens in November. If you want your first hacking game to feel like an actual game, start here.

14. Gandalf: Agent Breaker: hacking AI with words

Lakera's original Gandalf was a prompt injection game: trick a chatbot into revealing a password. The old gandalf.lakera.ai address now redirects to Gandalf: Agent Breaker, launched in September 2025, where you attack ten AI-powered apps. No code needed, just English and creativity, and the skill is about as current as security gets: prompt injection sits at the top of the OWASP list of risks for LLM applications.

15. HackerDNA Daily Hack: one real puzzle a day

The daily hack is built around a simple idea: one short, self-contained challenge per day, with no Docker, no VPN, and no VM. A recent one hands you a set of public certificate transparency logs and asks which "internal-only" hostname is actually live on the internet. The trap is a freshly issued certificate for a host that no longer exists. That is real OSINT reasoning in about seven minutes, and because a new one lands every day, it is the easiest habit on this list to keep.

Which Hacking Game Should You Start With?

Pick by what you want to get better at, not by what looks coolest. Here is how we would send a friend:

  1. Never touched a terminal: play Hacknet for a weekend to get over the fear, then start OverTheWire Bandit.
  2. Want to learn to code: Bitburner first, Cryptopals second. Both reward writing scripts over clicking.
  3. Interested in web hacking: Google's XSS game for an afternoon, then OWASP Juice Shop, then Hacker101 CTF.
  4. Curious about reverse engineering: TIS-100 or EXAPUNKS to build the mindset, then Microcorruption for the real thing.
  5. Into AI: Gandalf: Agent Breaker. You will understand prompt injection better in an hour than from any article.
  6. Only have ten minutes a day: one daily hack every morning. Consistency beats marathon sessions.

In practice, the people who stick with this are the ones who mix one "fun" game with one "real" game. Hacknet on the couch, Bandit at the desk. The fun one keeps motivation up, the real one builds the skill, and after a few weeks the real one becomes the fun one.

From Hacking Games to Real CTFs

Every real hacking game on this list is a CTF in disguise. Bandit levels, Juice Shop challenges, and Hacker101 flags all use the same loop: find the weakness, extract a secret, submit it, move on. Once that loop feels natural, you are ready for the real thing. Our guide to CTF for beginners explains the categories and the tools, and when you want a scoreboard with other humans on it, read how to enter your first CTF competition.

The biggest difference is structure. Games give you levels in order. A CTF gives you twenty challenges at once and no hint about which one is easy. The habit that bridges that gap is taking notes: write down every command you ran and why, even on Bandit level 3. Those notes turn into write-ups, and write-ups are what you show an employer.

One more honest observation. Hacking games are great at teaching tools and terrible at teaching fundamentals like networking and HTTP. If Bandit level 14 stops you cold because you do not know what a port is, that is not a gap in effort, it is a gap in theory. Fill it, then come back.

Critical reminder: Hacking games are legal because the targets were built to be attacked. The moment you point the same skills at a system you do not own, you need explicit written authorization first.

  • Stay in scope: OverTheWire, Hacker101, and the other platforms authorize attacks on their challenges, not on their own infrastructure or other players' machines.
  • Cheating in online games is a different thing: using exploits or cheat tools in a multiplayer game breaks the terms of service, gets accounts banned, and depending on the country and method can lead to legal trouble. It is not what "hacking games" means in this guide.
  • Do not share solutions for live challenges: write-ups for retired levels are fine and encouraged. Posting passwords for active ones ruins the game for everyone else.
  • Keep vulnerable apps local: run Juice Shop bound to 127.0.0.1 as shown above. Exposing a deliberately vulnerable app on a public server invites real attackers.

Frequently Asked Questions

Can hacking games actually teach you to hack?

Some can. Games where you type real commands or write real code, like Bitburner, OverTheWire Bandit, or OWASP Juice Shop, build skills that transfer directly. Games where hacking is a button press or a mini-game, like Watch Dogs or Uplink, teach nothing you can reuse. The test is simple: could you do the same thing on a real system afterward?

What is the best free hacking game?

For a video game, Bitburner: it is free on Steam and in the browser, and you play it by writing JavaScript. For real hacking, OverTheWire Bandit is the standard first stop, since all you need is an SSH client. OWASP Juice Shop is the best free option for web security.

Is Hacknet realistic?

Partly. Its navigation commands (ls, cd, scp, rm) behave like their Unix counterparts, and the enumerate, exploit, escalate, clean up flow mirrors a real intrusion. The exploits themselves are fictional: real services do not open because you run a program named after them.

Are hacking games legal?

Yes. Playing a hacking simulator or attacking a platform built for practice is legal, because the owner has authorized it. What is not legal is using the same techniques on systems you do not own or have no written permission to test, and cheating in online multiplayer games breaks their terms of service.

What hacking games are good for teenagers?

Carnegie Mellon's picoCTF competition targets middle school to college students, and in May 2026 its learning platform became CMU's free CyLab Security Academy. The SANS Holiday Hack Challenge is story-driven and beginner-friendly. Among commercial games, TIS-100 and EXAPUNKS teach logic without any violent content.

Do I need Kali Linux to play hacking games?

No. Every Steam game on this list runs on a normal computer, and most free ones need only a browser or an SSH client. Juice Shop needs Docker. You will want Kali or a similar distribution later, once you move on to CTF competitions and lab machines.

Last verified: September 2026. Steam prices and review labels checked on each game's store page, and every free platform's URL checked for availability.

Your Next Steps

The best hacking games are the ones that make you type, read, and think like an attacker, not the ones that look most like a movie. Start with one simulator you enjoy, Bitburner or Hacknet, and one real platform, Bandit or Juice Shop. Give it two weeks and you will notice the real one getting easier.

When you are ready for more structure, HackerDNA gives you the same find-the-flag loop across web, crypto, forensics, and privilege escalation. Try Capture the Flag 101 for your first flag, build the theory with the Hacking 101 course, and keep a daily hack in your routine. Everything runs in the browser, and you can start with HackerDNA's free tier - no credit card required.

HackerDNA Team

HackerDNA Team

Written by the HackerDNA team - cybersecurity professionals building hands-on hacking labs and educational content to help you develop real-world security skills.

Meet the Team

Ready to put this into practice?

Stop reading, start hacking. Real machines, in your browser, free.

Start Hacking Free
30,000+ Hackers Real labs Free
Start Hacking Free or solve today's hack, no account needed