Hack Monty Round 3 & Round 2 results
Blog post from Pydantic
Hack Monty Round 2, a security challenge focused on escaping Monty’s Python sandbox or accessing protected secrets, ended without any successful escapes, secret disclosures, or bounty payments, although participants submitted useful reports involving crashes, resource limits, and CPython compatibility. Round 3, running through the rest of August with a bounty of up to $20,000, is the final planned challenge before Monty V1 is released with a stable API and fewer early-adoption warnings. Since Round 2, Monty has improved CPython compatibility and moved execution into subprocess workers, enabling stronger isolation, memory and time enforcement, fault containment, and scalable parallel execution. A new protobuf wire protocol also supports remote WebSocket execution, allowing more secure separation between sandboxed code and host applications, centralized observability, and hosted commercial use cases. Participants can use a provided CLI or build clients with the Monty WebSocket API, while Round 3 adds rewards for crashing the WebSocket server itself or escaping mounted directories, subject to reproducible reporting and other stated rules.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Observability | 1 | 2,982 | 688 | 177 | -28% |
| Secrets Management | 1 | 1,985 | 445 | 125 | -23% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.