Git Leak
This server is serving its entire git repository to anyone who asks. Somewhere in that history is the key material for the stage wallet — committed, then "removed". Deleted is not gone.
Objective
Recover the private key material protecting the stage wallet by exploiting the exposed version-control metadata.
- The web root exposes
/.git/— every object, ref, and log entry is downloadable. - Reconstruct the repository locally and audit the full commit history, not just the working tree.
- Something sensitive was committed to this repository and later removed. Git never forgets.
Verify the exposure
Probe the two files that prove a repository is leaked. These requests run from your browser, right now.
Attack path
Standard tooling recovers the full repository in seconds.
Hints
Hint 1 — Confirm before you dig
/.git/HEAD responds with a ref, the whole object store is public. Don't browse it by hand — dump it with git-dumper or GitTools and work locally.Hint 2 — The working tree is lying to you
git log, then git show each commit and watch for added files.Hint 3 — Know your target format
0, O, I, or l. It imports directly into any Solana wallet.Claim the bounty
No submission form. No judging. The chain is the referee.
Recover the key
Pull the base58 secret key from the repository history.
Import it
Phantom, Solflare, or solana-keygen — any wallet that accepts a base58 secret key.
Sweep the balance
Send the full 1 SOL to your own address. The scoreboard updates the moment the chain confirms.