Inspiration
ScamLab was inspired by a problem I see around me in Cameroon: students are regularly exposed to scams through WhatsApp, SMS, social media, and email. Fake exam-result updates especially these past weeks with the exam results looming, scholarship offers, job opportunities, prize messages, and mobile-money warnings can look surprisingly convincing.
I realized that simply telling students to "watch out for scams" isn't enough. People need a chance to practice recognizing them before encountering the real thing. That led me to build ScamLab—a safe environment where students can learn by actually making decisions.
What it does
ScamLab turns scam awareness into interactive training.
Users encounter realistic scam or legitimate messages and have to decide whether they can trust them. They can investigate clues, submit their answer, receive immediate feedback and an explanation, and earn XP based on their performance.
The platform includes different categories such as phishing, prize scams, mobile-money scams, job scams, and legitimate messages. It also tracks attempts and performance so future training can be adapted around areas where a user struggles.
How we built it
ScamLab was built primarily with Python and Flask.
The backend handles authentication, scenarios, attempts, scoring, XP, progression, and performance tracking. We used Flask-SQLAlchemy for the database layer and built the scenario system around structured scam/legitimate message data.
The frontend uses HTML, CSS, and JavaScript to create an interactive training experience designed around familiar messaging-style scenarios.
We also designed the system so user performance can feed into an AI layer that can recommend what the user should practice next.
Challenges we ran into
One of the biggest challenges was getting the game logic and database relationships working correctly. We had to debug issues involving SQLAlchemy relationships, database configuration, Flask application factories, routing, and scenario ordering.
Another challenge was designing a scoring system that rewarded correct decisions while still making clues useful without allowing users to simply rely on them.
We also had to balance building the core product with the limited time available for the hackathon. That forced us to prioritize the actual learning experience over unnecessary features.
And finally during deployment with a problem with our database and our seed.py scripts scenarios where the scenario would run locally but failed when tested live this was because the scenarios where seeded in our local db but not in the production database so we added the python seed.py command to our build command and the scenarios where successfully added in production.
Accomplishments that we're proud of
We're proud that ScamLab became a functional training experience rather than just an idea or a static collection of scam examples.
We built authentication, persistent user attempts, scenario progression, difficulty-based training, scoring, XP, clues, explanations, and performance tracking.
We're especially proud of the idea of making cybersecurity education practice-based. Instead of asking students to memorize a list of scam warning signs, ScamLab lets them experience the decision-making process themselves.
What we learned
We learned that building a product is very different from simply writing code that works.
Small architectural decisions can create major debugging problems later, especially around databases, Flask application structure, and relationships between models.
We also learned the importance of prioritization. During a hackathon, there will always be another feature you could add, but getting the core experience working is more valuable than having a long feature list.
Most importantly, we learned that cybersecurity education can be more engaging when users actively practice rather than passively consume information.
What's next for ScamLab
The next step is to make ScamLab more personalized and realistic.
We want to strengthen the AI layer so that ScamLab can analyze a user's mistakes, identify patterns in what they struggle with, and recommend or generate appropriate training scenarios.
We also want to expand the scenario library with more regionally relevant scams, improve the realism of the simulated messages, add stronger progression and achievement systems, and eventually make ScamLab accessible to schools and student communities across Cameroon and beyond.
Our long-term goal is to make ScamLab a practical cybersecurity training tool that helps young people build scam-detection instincts before they need them in the real world.
Log in or sign up for Devpost to join the conversation.