IDcollectionsRetiredCoder's mini-puzzles

mini/3

Solved on 2024-12-15 after 1d 58m, key published. 1.3 BCH on Bitcoin Cash.

IDmini/303 / 72024-12-14 → 2024-12-15
Puzzle / mini

3

bitcoincashp2pkh solved

Record

bitcoincashPuzzle({
  address: p2pkh("bitcoincash:…wsxw2qez", "a24922852051…5bb4cf75"),
  status: Status.Solved,
  key: hex("000000000000…97c603c9", 130),
})
Prize
1.3 BCH
Key material
hex
Verification
verified
Solved
2024-12-15 · 1d 58m
tx 3
Trail
Explorerblockchair.com
Sourcebitcointalk.org/index.php?topic=5522785
Trymini/3 in the playground
Address
bitcoincash:qz3yjg59ypg6jqpwhaxgvjj44jm4hdx0w5wsxw2qez

hash160 a24922852051a9002ebf4c864a55acb75bb4cf75

Balance
asking the explorer

Key

public key · compressed
03633cbe3ec02b9401c5effa144c5b4d22f87940259634858fc7e59b1c09937852
range · 130 bits
0x200000000000000000000000000000000 to 0x3ffffffffffffffffffffffffffffffff
private key (hex)
000000000000000000000000000000033e7665705359f04f28b88cf897c603c9

Transactions

  1. funding2015-01-150.13 BCH08389f34c9…a6cd15
  2. increase2017-07-111.17 BCH5d45587cfd…384164
  3. claim2024-12-151.3 BCHc237333cde…558bf3

Hints

  1. 2024-12-14

    officialMessage: Anything one man can imagine, other men can make real. Signature: IIONt3uYHbMh+vUnqDBGHP2gGu1Q2Fw0WnsKj05eT9P8KI2kGgPniiPirCd5IeLRnRdxeiehDxxsyn/VujUaX8o=

    Published answer

    Since it seems that the winner is not here, I will explain this riddle. 1. So we have a signature, we should check for weak K1, use kangaroos of course What's the range for search? Use a hint from the message, 80bit. Fails, it seems K1 is strong. 2. Remember that I posted another signature, take K2, may be K1==K2? No. So if we have both strong K1 and K2, what it can be? Remember that ECDSA Signature is vulnerable not only when K1==K2 but also if we know that K1 has some relation with K2, for example, K2=K1+1 (the simplest case). How to check it? Remember that R1=G*K1 and R2=G*K2 and we have these R1 and R2 points in signatures, so we can substract: PntDiff = R1 - R2 (and also try R2 - R1) and check if it's G. It's not G, ok, may be the difference is not 1 but more? We should try to solve PntDiff (both variants) with kangaroos. What's the range? Same, 80bits. And we can solve it, so now we have delta_K. 3. Now calculate, google or ask chatbot to get the formula: pk = ((delta_k * s1 * s2) + (z2 * s1) - (z1 * s2)) / (r1 * s2 - r2 * s1) [mod n] That's all!

    2024-12-15bitcointalk.org/index.php?topic=5522785.msg64850761

  2. 2024-12-14

    officialA hint is in the message

  3. 2024-12-14

    officialYes, you should have some understanding of ECDSA signature vulnerabilities.

  4. 2024-12-15

    officialSame K or weak K would be too easy. This riddle is just one step more complex.

  5. 2024-12-15

    official24 hours have passed, here is the first hint: don't take anything from the blockchain.