Skip to content

Challenge: Bypass the Ed25519 signature verification ($200 bounty) #36

@rodchalski

Description

@rodchalski

$200 to the first person who can produce a valid Authority Receipt that passes our verify endpoint — without using the approval UI.

The target:
permission-protocol/pp-demo#32

The source code:

What counts:

  • Forge a receipt that passes signature verification
  • Replay an existing receipt against a different action
  • Find a flaw in the Ed25519 signing/verification flow

What doesn't count:

  • Spoofing a GitHub commit status with repo write access
  • Social engineering
  • Attacking infrastructure (this is a crypto challenge, not a pentest)

How to claim:
Open an issue with the exploit, or DM @rodchalski.

Payment: PayPal or Venmo, within 24 hours of verified bypass.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions