Devpost copy — Don't Take the Bait
Title: Don't Take the Bait
Tagline: A phishing-literacy card game built from 4,800 real phishing URLs
Theme: Education & Learning
Inspiration
Anti-phishing education still teaches 2010-era tells: "check the padlock," "watch for typos." Meanwhile, we measured today's phishing landscape directly — running a 40-signal heuristic engine against 4,800 verified phishing URLs pulled from OpenPhish, PhishTank and URLhaus.
The result reframed the problem: URL-level detection caught only ~39%. The rest hid behind trusted hosting (github.io, blogspot, workers.dev), perfect spelling, and clean HTTPS. Detection has a ceiling — and the classroom is still teaching to a threat that no longer exists. The last firewall is a person; we decided to train it with real data.
What it does
Don't Take the Bait is a print-and-play classroom card game. A 40-card deck of URLs — every card cut from a real pattern in the dataset (sanitized). Teams vote BAIT or SAFE, flip the card, and learn the tell:
- Homoglyph swaps (
paypa1), letter-doubling (meetamassklogaiin), transpositions (bradecso) - Bait words in five languages —
oferta,banque,atendimento,compte - Machine-made domains: numeric (
679336.xyz), vowel-less (jfvlqz.top) - Legitimate lookalikes that punish gut instinct —
apples.comscores zero; it really is a fruit site
A facilitator guide maps every card to the dataset statistic behind it — students learn the numbers, not folklore. One round takes 15 minutes, needs zero devices, and costs $0 to print.
How we built it
The project is data-first. We benchmarked a heuristic phishing engine against four public threat feeds, iteratively fixing false positives (dictionary plurals like apples.com, institutional names like login.gov) and adding signals until the misses plateaued. The miss analysis became the product: every recurring miss pattern turned into a card category.
The deck and pitch materials were designed in Figma (single typeface, three-color system, stat-first hierarchy). The interactive card sample and print-ready deck are HTML/CSS rendered to PNG and PDF — the same cards you'd print are the ones in the demo video.
Challenges we ran into
- Data honesty vs. a good story. Our first headline number (43.5% detection) was inflated by a phantom signal from a domain-slicing bug. We kept the honest 39% — the "detection ceiling" argument only works if the number is real.
- False-positive whack-a-mole. Every new signal caught real phish and legitimate edge cases (plural words, short brand names, cloud storage URLs). Fix the cause, not the threshold.
- Making "boring" patterns legible. A URL string isn't obviously game material — the card back has to teach the tell in one sentence plus one stat.
Accomplishments that we're proud of
- The card content is mined from real attacks, not imagined ones — including the multilingual bait most curricula never mention
- Zero false positives on our 58-URL legitimate control set — the "SAFE" cards teach precision, not paranoia
- A complete print-and-play kit: 40-card deck, facilitator guide, printable PDF — $0 marginal cost per classroom
- The pitch video itself is generated end-to-end: declarative scene file → automated capture → TTS + burned captions
What we learned
Mining live feeds revealed how far curricula lag reality: trusted-hosting phishing, multilingual bait, and vowel-less machine domains appear in almost no teaching material. We also learned that a detector's failure modes are a curriculum in disguise — the 61% the machine misses is exactly the syllabus a human needs.
What's next for Don't Take the Bait
- Pilot: 3 schools, with pre/post quizzes measuring detection accuracy — not just awareness
- Regional packs: localized card decks from FR/ES/PT/ID bait-word datasets (already mined)
- Living deck: quarterly refresh pipeline — new threat feeds → new cards, so the game never teaches stale patterns
Built With
- education
- figma
- phishing
- security-awareness
Log in or sign up for Devpost to join the conversation.