Bitcoin puzzle transaction
Bitcoin puzzle transaction
bitcoin
256 addresses with keys of 1 to 256 bits. The one everybody scans.
- Author
- saatoshi_rising
- Prize recorded
- 1008.53080207 BTC
- Still unsolved
- 77 ยท 903.01676807 BTC
Census
- solved
- 8332%
- unsolved
- 7730%
- swept
- 9638%
- public keys
- 18472%
- private keys
- 8332%
Access
- Load
getCollection("bits") - Showbits/71 in the playground
- Listall 256 in the playground
Hints
- 2017-04-2706:41:08
officialThere is no pattern. It is just consecutive keys from a deterministic wallet (masked with leading 000...0001 to set difficulty).
Sourcebitcointalk.org/index.php?topic=1306983.msg18765941Confirmweb.archive.org
The puzzle
One transaction in January 2015 funded 254 addresses. Puzzles 1 and 2 were already there, funded in 2013 and 2014. The author said what the keys were in the one post the account ever made, on bitcointalk in April 2017: "There is no pattern. It is just consecutive keys from a deterministic wallet (masked with leading 000...0001 to set difficulty)." That mask puts the key of puzzle n somewhere in [2^(n-1), 2^n - 1]. That quote is the collection's hint, so every record inherits it through bits.hintsFor(n) and puzzles_hints, with the post as its source and a Wayback capture of the thread as what confirms it. The low ones fell in hours. Puzzle 1 is key 1. The high ones are out of reach for anyone without a very specific budget. The middle is where the scanning community lives. The prizes were raised in 2017 and again in 2023, so bits/71 holds 7.1 BTC today for a key of 71 bits.
An open record declares its width with bits(n). A solved one carries it as the second argument of hex(key, n). Either way keyRange() turns it into the two bigint bounds. The width marks a search space and nothing else, so it's absent on every other collection.
const puzzle = bits.require(71);
puzzle.keyRange(); // [2n ** 70n, 2n ** 71n - 1n]
puzzle.hasPubkey(); // false by design: no public key, so nothing beats scanning the range
Why bits
The key used to be b1000, a number you couldn't explain from any record, on prizes that got raised twice anyway. Now it says the one thing that never moves: puzzle n hides a key n bits wide. So bits/71 tells you the width before you open it. Well, 70 unknown bits, because the top one is always set.
The old key still resolves. get("b1000/71") lands on bits/71, and old links to these pages redirect here. Keep two names apart, though. The root's bits(n) writes a record's width, while this collection's bits holds the puzzles. Same word, two jobs. Need both in one file? An import alias settles it.
Solved, swept, unsolved
A solved puzzle has its key on the record as hex(โฆ, n).wif(โฆ). The data gate derives the address from it on every test run. The highest published key is 135 bits, solved in July 2026 for 13.5 BTC.
swept is the other large group. Once a puzzle's public key became known, through an earlier spend or a reveal, its address could be attacked with Pollard's kangaroo instead of brute force. And people did. Those records carry the sweep transaction and, where the sweeper published it, the key. The status is written down because the transaction list alone can't tell a sweep from a solve.
bits.solved().length; // keys published by whoever found them
bits.unsolved().length; // still funded, still waiting
(await selectPuzzles({ collection: "bits", status: Status.Swept })).length; // emptied once the public key leaked
The record
export const bits1 = puzzle({
id: "bits/1",
chain: "bitcoin",
address: "1BgGZ9tcN4rm9KBzDn7KprQz87SZ26SAMH",
sourceUrl: "https://bitcointalk.org/index.php?topic=5218972",
startedAt: "2013-01-09 11:59:15",
status: Status.Solved,
pubkey: compressed("0279be667ef9dcbbac55a06295ce870b07029bfcdb2dce28d959f2815b16f81798"),
key: hex("0000000000000000000000000000000000000000000000000000000000000001", 1).wif(
"KwDiBf89QgGbjEhKnhXJuH7LrciVrZi3qYjgd9M7rFU73sVHnoWn",
),
prize: 0.001,
solvedAt: "2013-01-10 02:54:44",
solveTime: 53729,
preGenesis: true,
transactions: [
funding("9223โฆ808e", "2013-01-09 11:59:15", 0.03),
claim("3da9โฆ4277", "2013-01-10 02:54:44", 0.03),
],
});
preGenesis: true marks puzzles 1 and 2, funded in 2013 and 2014 before the January 2015 transaction. That's why puzzle 1 moves 0.03 BTC in its transactions while the recorded prize is the 0.001 the series assigns it. The collection is a NumericCollection. bits.get(71), bits.get("71") and bits.get("bits/71") all land on the same record.
Every puzzle
One page each: the record, the transactions and the live balance.
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- 21
- 22
- 23
- 24
- 25
- 26
- 27
- 28
- 29
- 30
- 31
- 32
- 33
- 34
- 35
- 36
- 37
- 38
- 39
- 40
- 41
- 42
- 43
- 44
- 45
- 46
- 47
- 48
- 49
- 50
- 51
- 52
- 53
- 54
- 55
- 56
- 57
- 58
- 59
- 60
- 61
- 62
- 63
- 64
- 65
- 66
- 67
- 68
- 69
- 70
- 71
- 72
- 73
- 74
- 75
- 76
- 77
- 78
- 79
- 80
- 81
- 82
- 83
- 84
- 85
- 86
- 87
- 88
- 89
- 90
- 91
- 92
- 93
- 94
- 95
- 96
- 97
- 98
- 99
- 100
- 101
- 102
- 103
- 104
- 105
- 106
- 107
- 108
- 109
- 110
- 111
- 112
- 113
- 114
- 115
- 116
- 117
- 118
- 119
- 120
- 121
- 122
- 123
- 124
- 125
- 126
- 127
- 128
- 129
- 130
- 131
- 132
- 133
- 134
- 135
- 136
- 137
- 138
- 139
- 140
- 141
- 142
- 143
- 144
- 145
- 146
- 147
- 148
- 149
- 150
- 151
- 152
- 153
- 154
- 155
- 156
- 157
- 158
- 159
- 160
- 161
- 162
- 163
- 164
- 165
- 166
- 167
- 168
- 169
- 170
- 171
- 172
- 173
- 174
- 175
- 176
- 177
- 178
- 179
- 180
- 181
- 182
- 183
- 184
- 185
- 186
- 187
- 188
- 189
- 190
- 191
- 192
- 193
- 194
- 195
- 196
- 197
- 198
- 199
- 200
- 201
- 202
- 203
- 204
- 205
- 206
- 207
- 208
- 209
- 210
- 211
- 212
- 213
- 214
- 215
- 216
- 217
- 218
- 219
- 220
- 221
- 222
- 223
- 224
- 225
- 226
- 227
- 228
- 229
- 230
- 231
- 232
- 233
- 234
- 235
- 236
- 237
- 238
- 239
- 240
- 241
- 242
- 243
- 244
- 245
- 246
- 247
- 248
- 249
- 250
- 251
- 252
- 253
- 254
- 255
- 256