RetiredCoder's mini-puzzles
In 2023 somebody emptied puzzles 120 and 125 of the b1000 transaction and said nothing. In September 2024, 130 went the same way. A few weeks later a fresh Bitcointalk account called RetiredCoder started posting mini-puzzles, one a month, each opening with "Guys, I'm bored today". The trick is where the prize was. Those addresses got their first coins before the August 2017 fork, so the same keys still unlocked a copy on Bitcoin Cash. Whoever holds the key to the BTC side holds the BCH side too. RetiredCoder had three such keys and gave the BCH away through riddles.
RetiredCoder's mini-puzzles
bitcoincash
Three solved Bitcoin puzzle keys, played again for the Bitcoin Cash still on their addresses. A swapped key, a shuffled key, one signature too many.
- Author
- RetiredCoder
- Prize recorded
- 3.75 BCH
- Still unsolved
- none
Census
- solved
- 3100%
- public keys
- 3100%
- private keys
- 3100%
Access
- Load
getCollection("mini") - Showmini/130 in the playground
- Listall 3 in the playground
How the three mini-puzzles work
#120: three characters swapped
October 14, 2024, 13:48 UTC. The post prints the private key of puzzle 120, with "three characters changed randomly":
0xB50F22572A497A836EA18AF2E1FC23
That's 30 hex characters, three of them wrong. Pick three positions, try every other hex digit in each and compare with something you already know about puzzle 120. kTimesG counted almost 14 million variants and asked how anyone checks the balance of all of them. You don't. RetiredCoder, blunt as usual: "If you don't know what is puzzle #120 and its address, well, you are out of the game." The public key of 120 has been on chain since 2019, so you compare pubkeys and never touch an explorer. "Correct, pubkey is the fastest way."
The real key is b10f22572c497a836ea187f2e1fc23. Positions 1, 9 and 21 were changed: 5 for 1, A for C, A for 7. The prize moved at 18:33 UTC. sneeky777 said "solved it in 3 mins" twelve minutes later and posted the key at 18:59. That was also the first time anybody saw the key of puzzle 120, over a year and a half after its BTC was taken.
#125: twelve pieces
November 14, same opener. "The key fell and shattered into 12 pieces":
804 E09 77 1C5 225 AC 960 33B 7F0 E4 6BB 48
Twelve pieces is 479,001,600 orders. But a 125-bit key starts with 1, and only one piece does, so it's 11! and about 40 million. Nothing for a laptop. It fell in under two hours: 1C5 33B 6BB 7F0 804 E09 960 225 E4 48 77 AC, so 1c533b6bb7f0804e09960225e44877ac. The loudest reaction came later, from someone who missed it: "What an easy puzzle". RetiredCoder shrugged. They're mini-puzzles, meant for "everyone with minimal skills", and if you want hard ones, there's #67 and #135.
#130: one signature too many
December 14, and this time "a bit more challenging". One message, one signature, both from the address of puzzle 130:
Message: Anything one man can imagine, other men can make real
Signature: IIONt3uYHbMh+vUnqDBGHP2gGu1Q2Fw0WnsKj05eT9P8KI2kGgPniiPirCd5IeLRnRdxeiehDxxsyn/VujUaX8o=
The thread ran four pages. First "a hint is in the message". Then "you should have some understanding of ECDSA signature vulnerabilities". Etar checked a weak nonce in 80 bits and found nothing. "Same K or weak K would be too easy." A day later, "don't take anything from the blockchain". A minute after that the thread saw the prize move, and the claim confirmed at 17:21 UTC. The winner never said a word, so the author explained it instead.
The message is where the 80 comes from, the explanation says. The quote is usually credited to Jules Verne, so Around the World in 80 Days, we guess. Look for a weak nonce K1 in 80 bits, fail. Now remember RetiredCoder had posted another signature from the same key earlier. Its nonce K2 isn't weak either. But the two nonces sit close together. Each signature carries its R point, R1 = K1·G and R2 = K2·G, so R1 − R2 is (K1 − K2)·G. That difference is small, so kangaroos find it in the same 80-bit range. With the delta known, two signatures and one linear equation give the private key:
pk = (delta_k·s1·s2 + z2·s1 − z1·s2) / (r1·s2 − r2·s1) mod n
Etar posted the numbers that evening: delta 0x22175083b1fc19218d84, and the key, 33e7665705359f04f28b88cf897c603c9. Puzzle 130's own key again. The steps we could rerun without the first message all check out. The signature verifies against the pubkey of 130. The nonce it implies gives R2 = 03838db7…. Adding the delta gives exactly the 03de9709… Etar quoted as R1. And the delta has 78 bits, inside the 80 the hint promised. The first signature's text isn't in the thread, so z1 is the one step we couldn't redo.
Where the Bitcoin Cash came from
All three addresses got their first coins in the 2015 transaction and the big top up of July 11, 2017. Both happened before the fork on August 1, 2017, so both exist on Bitcoin Cash too. The later BTC deposits don't. That's why the prizes are 1.2, 1.25 and 1.3 BCH, each puzzle number over a hundred. The same copies sit on Bitcoin SV and Bitcoin Gold. For #130, privatekeys.pw lists the prize as "1.3 BCH, BSV, BTG". Those chains stay out of the records until this library can read them.
What the mini records carry
export const mini130 = bitcoinCashPuzzle({
id: "mini/130",
address: p2pkh("bitcoincash:qz3yjg59ypg6jqpwhaxgvjj44jm4hdx0w5wsxw2qez", "a2492285…b4cf75"),
sourceUrl: "https://bitcointalk.org/index.php?topic=5522785",
startedAt: "2024-12-14 16:22:32",
status: Status.Solved,
pubkey: compressed("03633cbe3ec02b9401c5effa144c5b4d22f87940259634858fc7e59b1c09937852"),
key: hex("000000000000000000000000000000033e7665705359f04f28b88cf897c603c9", 130),
prize: 1.3,
hints: [/* the message and signature with the author's explanation, then four hints */],
solvedAt: "2024-12-15 17:21:10",
solveTime: 89_918,
transactions: [funding(/* 2015 */), increase(/* 2017 */), claim(/* 2024 */)],
solver: party(undefined, {
addresses: ["bitcoincash:qrda29v338en6lkt5s8mv3wls0l778qg0sdxk42358"],
}),
});
The same key twice
mini/130 and b1000/130 share a key, a public key and a HASH160. They're still two puzzles. One was 13 BTC and fell in September 2024. The other was 1.3 BCH and fell in December. Different chain, different prize, different claim. The CashAddr and the 1-address are just two spellings of the same hash.
Addresses nobody printed
None of the three posts prints a CashAddr. They name the puzzle and say the BCH is there. The records take the HASH160 of the b1000 address and spell it the Bitcoin Cash way. For #130, privatekeys.pw prints the same address. For all three, the chain agrees: the prize leaves each address within a day and a half of its post, and nothing big leaves it before.
Solvers with an address and no name
sneeky777 said they solved #120 in three minutes and posted a signature. It doesn't recover to the address the prize went to, not with any text we could read into their post. iceland2k14 said "Got it" three minutes after the #125 claim, and nobody tied a name to the #130 claim at all. So each record keeps the claim's output address and no name. RetiredCoder, "congrats to the winner (though he did not appear), done!"
Keyed by the puzzle number
mini/130 resolves as 130, "130" or mini/130. The number is the Bitcoin puzzle each mini-puzzle is built on, not a running count. It's how RetiredCoder titled them.