1. Open robots.txt (link on the page). A Disallow: /admin-backup/ entry points to a 'hidden' area. Why: robots.txt advertises paths the owner wants hidden from crawlers — a recon goldmine.
2. View source: an HTML comment holds the first fragment; app.js contains a hardcoded API_KEY fragment. Why: anything shipped to the browser is public.
3. The page's 'reveal' button concatenates the fragments it found into the flag once you have visited the disallowed path.
Lesson: never rely on obscurity; never hardcode secrets in client code.