Skip to content

Challenge: Bypass the Ed25519 signature verification ($200 bounty) #36

@rodchalski

Description

@rodchalski

$200 to the first person who can produce a valid Authority Receipt that passes our verify endpoint — without using the approval UI.

The target:
permission-protocol/pp-demo#32

The source code:

What counts:

  • Forge a receipt that passes signature verification
  • Replay an existing receipt against a different action
  • Find a flaw in the Ed25519 signing/verification flow

What doesn't count:

  • Spoofing a GitHub commit status with repo write access
  • Social engineering
  • Attacking infrastructure (this is a crypto challenge, not a pentest)

How to claim:
Open an issue with the exploit, or DM @rodchalski.

Payment: PayPal or Venmo, within 24 hours of verified bypass.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions