Collections

Brute force and the coins are yours

A bitaddress.org paper wallet whose owner forgot the BIP38 passphrase and gave the coins to whoever guesses it. Posted on Stacker News in October 2023 and still locked

October 6, 2023, 11:50 UTC. q posts on Stacker News and the pitch is beautifully simple. Some years ago I made a paper wallet with a BIP38 passphrase. I don't remember the passphrase. Brute force it and the coins are yours. Then the encrypted key, the address, and where the passphrase should be, one honest line: <find out>.

No riddle, no clues planted on purpose, no author smirking somewhere with the answer. The only one who ever knew the password is q from years ago, and q from years ago isn't answering.

IDbitaddress05 / 321 puzzle · 2023-10-06
Collection

Brute force and the coins are yours

bitcoin

A paper wallet whose owner forgot the BIP38 passphrase and gave the coins to whoever guesses it. Probably three old passwords glued together. Good luck, q didn't have any.

Author
q
Prize recorded
0.005297 BTC
Still unsolved
1 · 0.005297 BTC
closed 0 / 1

Census

unsolved
1100%
public keys
1100%
private keys
1100%

Access

LoadgetCollection("bitaddress")
Showbitaddress in the playground

Why give it away

Two reasons. q will "never have time to do it", being "stuck in love life laugh". Fair enough. And q wants to prove a point: a passphrase "is not an extra security layer it is only extra step for donating the coins to every bitcoiner".

Bold. Almost three years later the coins haven't moved, so right now the score is passphrase 1, every bitcoiner 0.

What q remembers

Not much, and that's the puzzle. The post and q's replies under it give 5 hints:

  • The passphrase is probably not more than 30 characters.
  • The wallet came from bitaddress.org.
  • q already tried the passwords from back then, so probably no special characters.
  • q used to glue 3 different passwords together to secure wallets, which lands around 30 characters. Probably no password manager. And q withdrew from this wallet once, so the passphrase can't be impossible.

That last one is the good one. Three old passwords in a row is a way smaller space than 30 random characters. Still huge, but huge in a shape a wordlist can actually chew on. If you know how people picked passwords around 2015, you're already ahead.

The 6Pf prefix

An hour and a half in, a commenter called 0fje0 spots it: the key starts with 6Pf. In BIP38 that means EC multiply mode, an uncompressed key, no lot or sequence number. The payload agrees, flag bytes 0x0143 and 0x00. So the passphrase first became an intermediate code and the key was built from that, not a plain WIF encrypted afterwards.

Does it help? Honestly, no. Every guess still goes through scrypt with N=16384, r=8, p=8 before you learn anything, and that's slow on purpose. BIP38 was built to make exactly this kind of fun expensive.

One free check though. The payload carries the first 4 bytes of the address's double SHA-256, and they match 1J7BVe…. So the key and the address on the paper really belong together. Worth knowing before you set a GPU on fire.

What the chain shows

The coins are older than the post. Two deposits in the same block on June 2, 2015, 0.01337 BTC and 0.02999 BTC. Then on June 12, 2016 somebody who still knew the passphrase spent both: 0.037963 BTC out, 0.0001 to fees, 0.005297 BTC back as change to the same address.

That's the withdrawal q mentions. It's also the only proof that this passphrase ever lived in a human head.

Since then, silence. 529,700 sat in the same spot since 2016, waiting for someone with a good wordlist and a lot of patience.

What the bitaddress record carries

tssrc/collections/bitaddress.ts
export const bruteForce = bitcoinPuzzle({
  id: "bitaddress",
  address: p2pkh("1J7BVeP8JK4op2X3GN3Hy7xkTnGnQTMpou", "bba564d9…07ffd6e3"),
  sourceUrl: THREAD,
  startedAt: "2023-10-06 11:50:09",
  pubkey: uncompressed("04f7af13…d75bac30ac"),
  key: encryptedWif("6PfQTphCYc1Fee19uPz2pmou5RVBDVgw8VcrPfGLos4ktUnARdiFLYhcNU"),
  prize: 0.005297,
  hints: [official("I suspect the passphrase is not more than 30 characters.", THREAD, …), community("The private key starts with '6Pf', though. …", comment("276026"), …), …],
  transactions: [funding(/* 2015-06-02 */), increase(/* same block */), decrease(/* 2016-06-12 */)],
  assets: assets({ puzzle: "puzzle.png", sourceUrl: PICTURE }),
});

An encrypted key and no passphrase

encryptedWif() with the payload alone. No passphrase option, because nobody has one, q included. puzzles verify bitaddress answers SKIP with WIF is encrypted, same as the unsolved Ballet wallet. The day someone cracks it, the passphrase goes into that same call and verify finally gets to do its job.

The public key was never a secret

The 2016 spend signed with the uncompressed key, so pubkey comes straight from that input. Zero help against scrypt. The record just likes to know things.

Started at the post, funded long before

startedAt is the post, the moment the passphrase became everybody's problem. The two 2015 deposits keep their dates, the 2016 spend is a decrease of what left the address, and prize is the 0.005297 BTC that was there on the day of the post.

Why bitaddress

The post's title is great, and it's the page's title too. As an id it's useless though. Half this dataset is brute force of some kind, so brute-force would point at everything and nothing. What only this puzzle has is where the wallet came from: bitaddress.org, named by q in the post. So the id is bitaddress.

The picture

assets/bitaddress/puzzle.png is the paper wallet as Imgur serves it: address on the left, encrypted key on the right, both QR codes. Top left there's the attacker success formula from section 11 of the Bitcoin whitepaper. Nice decoration for a wallet whose only attacker is its owner's memory.

The thread is archived

Stacker News is doing fine, but the hints live in comments, and comments have a way of disappearing. So the repo keeps its own copy. assets/sources/bitaddress/ has the post and every comment, checked against a Wayback capture from February 2026.

The bitaddress record

IDbitaddress2023-10-06
Puzzle / bitaddress

bitcoinp2pkh unsolved

Record

bitcoinPuzzle({
  address: p2pkh("1J7BVeP8JK4o…GnQTMpou", "bba564d91137…07ffd6e3"),
  key: encryptedWif("6PfQTphCYc1F…iFLYhcNU"),
})
Prize
0.005297 BTC
Key material
encrypted
Verification
unverifiable
Solved
not yet
tx 3
Trail
Explorerblockstream.info
Sourcestacker.news/items/275973
Trybitaddress in the playground
Address
1J7BVeP8JK4op2X3GN3Hy7xkTnGnQTMpou

hash160 bba564d9113760ba944ffce28dc3126d07ffd6e3

Balance
asking the explorer

Key

public key · uncompressed
04f7af13c4fda2f920dbd8ebc8d2cc87cdc6674a7beda95a402ab83dd7e952597aeebdb76b2b4bc15771c57eb48568b2a8fa83219f9fa53519aaef5cd75bac30ac
BIP38 payload
6PfQTphCYc1Fee19uPz2pmou5RVBDVgw8VcrPfGLos4ktUnARdiFLYhcNU

Transactions

  1. funding2015-06-020.01337 BTCcbba0edea0…3910ca
  2. increase2015-06-020.02999 BTCfd82c2f779…ebf608
  3. decrease2016-06-120.038063 BTCfa938636d8…17f3c9

Hints

  1. 2023-10-06

    officialI suspect the passphrase is not more than 30 characters.

  2. 2023-10-06

    officialWhich i generated on this site https://www.bitaddress.org/

  3. 2023-10-06

    officialI don't remember, I have tested my passwords I used during that time, so probably it is not with special characters

  4. 2023-10-06

    officialMost likely I did not use a passphrase of the length 30. But I remeber that I used to combine 3 different passwords to secure wallets which is about that length. I have withdrawn funds from the wallet once so it cannot be an imposible passpharse and most likely I did not used a password manager for it.

  5. 2023-10-06

    communityThe private key starts with '6Pf', though. That gives you some indication of the encryption algorithm used: EC multiply, no compression, no lot/sequence numbers, according to BIP38.

local record / balance from the explorer