Peter Todd (Bitcoin core dev) set up a SHA-1 “Pinata” and it's been claimed
twitter.com
twitter.com
If you 'unhexlify' both hex strings on that page, you can see that the first 320 bytes of each PDF from shattered.io were used as input.
In [1]: import binascii, hashlib
In [2]: input1 = binascii.unhexlify('255044462d312e330a25e2e3cfd30a0a0a312030206f626a0a3c3c2f57696474682032203020522f4865696768742033203020522f547970652034
...: 203020522f537562747970652035203020522f46696c7465722036203020522f436f6c6f7253706163652037203020522f4c656e6774682038203020522f42697473506572436f6d706
...: f6e656e7420383e3e0a73747265616d0affd8fffe00245348412d3120697320646561642121212121852fec092339759c39b1a1c63c4c97e1fffe017f46dc93a6b67e013b029aaa1db2
...: 560b45ca67d688c7f84b8c4c791fe02b3df614f86db1690901c56b45c1530afedfb76038e972722fe7ad728f0e4904e046c230570fe9d41398abe12ef5bc942be33542a4802d98b5d70
...: f2a332ec37fac3514e74ddc0f2cc1a874cd0c78305a21566461309789606bd0bf3f98cda8044629a1')
In [3]: input2 = binascii.unhexlify('255044462d312e330a25e2e3cfd30a0a0a312030206f626a0a3c3c2f57696474682032203020522f4865696768742033203020522f547970652034
...: 203020522f537562747970652035203020522f46696c7465722036203020522f436f6c6f7253706163652037203020522f4c656e6774682038203020522f42697473506572436f6d706
...: f6e656e7420383e3e0a73747265616d0affd8fffe00245348412d3120697320646561642121212121852fec092339759c39b1a1c63c4c97e1fffe017346dc9166b67e118f029ab621b2
...: 560ff9ca67cca8c7f85ba84c79030c2b3de218f86db3a90901d5df45c14f26fedfb3dc38e96ac22fe7bd728f0e45bce046d23c570feb141398bb552ef5a0a82be331fea48037b8b5d71
...: f0e332edf93ac3500eb4ddc0decc1a864790c782c76215660dd309791d06bd0af3f98cda4bc4629b1')
In [4]: input1[:8], input2[:8]
Out[4]: ('%PDF-1.3', '%PDF-1.3')
In [5]: hashlib.sha1(input1).hexdigest() == hashlib.sha1(input2).hexdigest()
Out[5]: TrueThe script is just checking that the spender knows 2 pieces of data that are different but have the same SHA1 hash. I can't see a way to do that that can't be easily replayed by somebody else spending to a different address.
As soon as the transaction is broadcast, you reveal your 2 pieces of data that are different but have the same SHA1 hash.
(And to not put too fine a point on it: the existing track record of ethereum smart contracts suggests that if such a bounty had been created there it would have simply been stolen due to contract/vm flaws by now.)
Unless it is SHA-1 hash :)
You'd need a system supporting zero knowledge proofs.
ZKCP is a much more robust solution.
Usually the challenge is to prove that you have the private key to a public key included in the challenge so that the public key can function as an address for you and only you can spend the coins because only you have the private key.
But in this case Peter Todd placed 2.48 BTC in the block chain with the challenge to provide two different but otherwise arbitrary pieces of data yielding the same SHA-1 hashes. Someone now used the collision generated by Google to spend those coins.
If Google had not publish the collision but you found it yourself, miners could still just steal the collision from your transaction, throw your transaction away and spend the coins themselves.
Actually everybody could just watch all new transactions, steal your collision once they see it and try to front-run you. So this kind of challenge is not really a good idea in general, at least not in this simple form.
With normal transaction this is not an issue because there you only reveal a signature proving that you know the private key, you do not reveal the private key itself and therefore others can not sign their own transaction and try to front-run you.
[...] and, as a followup challenge, something encrypted with your public key so only you can decrypt it later on.
That is not entirely correct, as mentioned above this works by signing and not encrypting. Everybody and especially miners have to be able to verify your transaction but they could not do that if you simply encrypted something. Well, they could if you published the private key but then you get into said front-running issue.
https://bitbet.us/bet/1351/a-sha1-collision-will-be-found-be...
(Not pointing this out to be critical. With a bit of thought, the policy makes enough sense to me, for various reasons. Pointing this out to prevent people from doing silly things, and because it's an interesting document on its own.)