The CTF contract is not exploited, it’s an internal address we use for ops.
POL was being sent to that address because it was in an internal refiller service that checks and refills balances every couple of seconds.
All user funds are safe and the address is being rotated.
Announcing the first-ever Simplicity CTF challenge!
I've locked 0.01 LBTC in a contract. Your task is to find how to unlock it and claim the reward!
I've also sent this challenge to our internal Blockstream chat.
Here is the description. Good luck!