IDcollectionsRetiredCoder's mini-puzzles
mini/130
Solved on 2024-12-15 after 1d 58m, key published. 1.3 BCH on Bitcoin Cash.
130
bitcoincashp2pkh solved
Record
bitcoincashPuzzle({
address: p2pkh("bitcoincash:…wsxw2qez", "a24922852051…5bb4cf75"),
status: Status.Solved,
key: hex("000000000000…97c603c9", 130),
})- Prize
- 1.3 BCH
- Key material
- hex
- Verification
- verified
- Solved
- 2024-12-15 · 1d 58m
- Trail
- Explorerblockchair.com
- Sourcebitcointalk.org/index.php?topic=5522785
- Trymini/130 in the playground
- Address
- bitcoincash:qz3yjg59ypg6jqpwhaxgvjj44jm4hdx0w5wsxw2qez
hash160 a24922852051a9002ebf4c864a55acb75bb4cf75
Key
- public key · compressed
- 03633cbe3ec02b9401c5effa144c5b4d22f87940259634858fc7e59b1c09937852
- range · 130 bits
- 0x200000000000000000000000000000000 to 0x3ffffffffffffffffffffffffffffffff
- private key (hex)
- 000000000000000000000000000000033e7665705359f04f28b88cf897c603c9
Transactions
- funding2015-01-150.13 BCH08389f34c9…a6cd15
- increase2017-07-111.17 BCH5d45587cfd…384164
- claim2024-12-151.3 BCHc237333cde…558bf3
Hints
- 2024-12-14
officialMessage: Anything one man can imagine, other men can make real. Signature: IIONt3uYHbMh+vUnqDBGHP2gGu1Q2Fw0WnsKj05eT9P8KI2kGgPniiPirCd5IeLRnRdxeiehDxxsyn/VujUaX8o=
Sourcebitcointalk.org/index.php?topic=5522785.msg64847018
Published answer
Since it seems that the winner is not here, I will explain this riddle. 1. So we have a signature, we should check for weak K1, use kangaroos of course What's the range for search? Use a hint from the message, 80bit. Fails, it seems K1 is strong. 2. Remember that I posted another signature, take K2, may be K1==K2? No. So if we have both strong K1 and K2, what it can be? Remember that ECDSA Signature is vulnerable not only when K1==K2 but also if we know that K1 has some relation with K2, for example, K2=K1+1 (the simplest case). How to check it? Remember that R1=G*K1 and R2=G*K2 and we have these R1 and R2 points in signatures, so we can substract: PntDiff = R1 - R2 (and also try R2 - R1) and check if it's G. It's not G, ok, may be the difference is not 1 but more? We should try to solve PntDiff (both variants) with kangaroos. What's the range? Same, 80bits. And we can solve it, so now we have delta_K. 3. Now calculate, google or ask chatbot to get the formula: pk = ((delta_k * s1 * s2) + (z2 * s1) - (z1 * s2)) / (r1 * s2 - r2 * s1) [mod n] That's all!
2024-12-15bitcointalk.org/index.php?topic=5522785.msg64850761
- 2024-12-14
officialA hint is in the message
- 2024-12-14
officialYes, you should have some understanding of ECDSA signature vulnerabilities.
- 2024-12-15
officialSame K or weak K would be too easy. This riddle is just one step more complex.
- 2024-12-15
official24 hours have passed, here is the first hint: don't take anything from the blockchain.