When first viewed page source, notice that the header references a hidden /secret/assets folder where index.css resides. But going to /secret/assets will greet us with a 301. So the next logical thing to do is to access /secret, which we can. The following code snippet will apply for all subsequent folder hops, with simple appending.

curl 'http://saturn.picoctf.net:63724/secret/.' -v

Upon viewing the page source, we are once again hinted at the existence of a hidden /hidden subfolder.

Upon accessing /secret/hidden, there will be a login page. Once again we access the page source then we can find a hidden <input> tag with the value superhidden/xdfgwd.html, which tells us, again, to access the subfolder. Only then will we find our flag in the page source. Pretty fun problem.