All challenges
CH-01 Easy

Git Leak

This server is serving its entire git repository to anyone who asks. Somewhere in that history is the key material for the stage wallet — committed, then "removed". Deleted is not gone.

Objective

Recover the private key material protecting the stage wallet by exploiting the exposed version-control metadata.

Verify the exposure

Probe the two files that prove a repository is leaked. These requests run from your browser, right now.

Live probe GET
Fetch
Response

Attack path

Standard tooling recovers the full repository in seconds.

# Dump the exposed repository $ git-dumper https://ctfxt.45.12.62.157.sslip.io/.git/ ./recovered # Audit the history — every commit, not just the latest $ cd recovered && git log --oneline # Inspect what each commit added or removed $ git show <commit>

Hints

Hint 1 — Confirm before you dig
If /.git/HEAD responds with a ref, the whole object store is public. Don't browse it by hand — dump it with git-dumper or GitTools and work locally.
Hint 2 — The working tree is lying to you
The current checkout looks clean. The secret is in a previous commit. git log, then git show each commit and watch for added files.
Hint 3 — Know your target format
You're looking for a base58-encoded Ed25519 secret key — 88 characters, no 0, O, I, or l. It imports directly into any Solana wallet.

Claim the bounty

No submission form. No judging. The chain is the referee.

STEP 1

Recover the key

Pull the base58 secret key from the repository history.

STEP 2

Import it

Phantom, Solflare, or solana-keygen — any wallet that accepts a base58 secret key.

STEP 3

Sweep the balance

Send the full 1 SOL to your own address. The scoreboard updates the moment the chain confirms.