Progressive Bounty Security Competition

5.00 SOL

Prize pool valued at ≈ $700 USD — held in five live wallets.

Five vulnerabilities, each guarding its own Solana wallet. Exploit the weakness, extract the private key, and drain the bounty straight to your own address. No scoreboard points. No judges. The chain is the referee.

05
Challenges
— / 5
Wallets drained
— SOL
Still unclaimed
S1
Season
Prize Distribution

Equal bounties, escalating difficulty

Every wallet holds exactly 1.00 SOL. What changes is how hard you fight for it.

Active Challenges

Five wallets standing between you and 5 SOL

Status is read directly from the Solana blockchain and refreshes automatically.

Easy Medium Hard Expert
CH-01 Easy
1.00SOL

Git Leak

The application's .git directory is served to the entire internet. Download the repository, audit the commit history, and recover what the developers thought they had removed.

Information Disclosure Source Control OSINT
Launch →
CH-02 Easy
1.00SOL

SQL Injection

The login endpoint concatenates raw user input straight into its query. Bypass authentication, enumerate the database, and pull the key material out of the secrets table.

Web Exploitation SQLi Auth Bypass
Launch →
CH-03 Medium
1.00SOL

SSRF

A URL fetcher that makes server-side requests with no allowlist and no egress filtering. Point it inward — the internal network is more talkative than the public one.

Web Exploitation SSRF Internal Network
Launch →
CH-04 Hard
1.00SOL

Remote Code Execution

A compute endpoint evaluates arbitrary JavaScript in the server process. Escape its intended purpose, read the runtime environment, and lift the stage key from disk.

Web Exploitation RCE Filesystem
Launch →
Protocol

How a claim works

01

Exploit

Work the vulnerability. Every stage is solvable with standard tooling and technique — no guessing required.

02

Extract

Each stage guards private key material for its own Solana wallet. Find it in the environment you just breached.

03

Drain

Import the key into any Solana wallet and sweep the full balance to an address you control.

04

Prove

The scoreboard reads the chain directly. An emptied wallet is public, immutable proof of your claim.

Rules of Engagement

Competition rules

01

First blood wins

Each wallet holds its full bounty. The first person to extract the key and drain it takes everything — settlement is on-chain and irreversible.

02

Scope is this host only

ctfxt.45.12.62.157.sslip.io (45.12.62.157) is the sole authorized target. Attacks against other participants, infrastructure providers, or third parties are out of scope.

03

No denial of service

Rate limits are enforced. Flooding, resource exhaustion, and blind brute force lead to immediate disqualification. Exploits should be surgical.

04

Claims are final

Bounties are claimed by moving funds on Solana. Transactions cannot be reversed — verify your destination address before sweeping.