Show HN: SHAllenge – Compete to get the lowest hash
shallenge.quirino.net
shallenge.quirino.net
Now that we have plenty of proof of work completed, we don't really need any more. You can bootstrap your new coin by burning Bitcoins as a provable value sink to get it started on the path to POS.
Like everything in tech, the devil is in the details, algorithm details in this case, so far it seems to be working out just fine.
See criticism here: https://news.ycombinator.com/item?id=25007874
now why would any entities want to deposit usd into a private bank and receive usdt without any yield on their cash? you think you understand tether so well maybe think about it for a few minutes
I wish cryptocurrency folks would stop pretending it is about decentralization or distributed systems, and that anything that allows them to bypass financial regulation is good enough.
The fact that faster hashers will come about just adds some natural competition, but it's still about limiting money supplies.
The "adding more zeros" is done automatically, according to an algorithm, so that the time between blocks is more or less the same.
There's this incredible MIT course about all of this, it's where I got the idea for the site from: https://youtube.com/playlist?list=PLUl4u3cNGP61KHzhg3JIJdK08...
One's investment in mining equipment becomes half as profitable every so often.
Bitcoin could have been designed with a different money supply mechanism (e.g. no halvings) but it would still have required mining. The hash rate has basically no impact on the money supply. That's because mining doesn't solve the problem of limiting the money supply, it solves the problem of decentralized consensus, aka the double spending problem.
Imagine you are a miner and a halving is next week. One week you earn 1btc. None of those other factors you mentioned have changed.
Then the halving happens so the next week you make 0.5btc. However yours and everyone else's held bitcoins are still worth the same as they were before.
Hasn't your mining profitability halved?
00000000 000003da 5849ade5 e2112447 73478c46 5fcdc744 9e247df4 11e97b28 (#1 of leaderboard)
00000000 00000000 0002a2fa b0d010ce 270927e8 c9a698a3 4f5e3d6c 4dbcffd3 (latest mined block)
Doesn't seem that impressive but keep in mind that it gets exponentially harder to find additional leading 0s and that the Bitcoin network currently finds such hashes every ~10 minutes.Edit: Looking at the data structure for a bitcoin block, for multiple reasons such as magic numbers and length, none of them would be a valid submission.
A hash is essentially just some random bytes, there is a small chance that the first hash bytes would randomly all be printable characters that fit the submission format, given that the bitcoin network has already done most of the work finding the small hashes, scanning through the blockchain trying to find a hash with a plaintext that fits the submission criteria, should be much less work.
*as of a year or so ago (my archive is stale and I'm too lazy to update it)
00000000 000003da 5849ade5 e2112447 73478c46 5fcdc744 9e247df4 11e97b28 (#1 of leaderboard)
00000000 00000000 0000fac0 39d91fc6 1db532f3 879ec244 15a2bff9 cd1d4efb (latest mined block right now -- another zero added since your post)
00000000 00000000 00000000 5d6f0615 4c868514 6aa7bc3d c9843876 c9cefd0f (lowest hash ever?)[0]
[0] https://crypto.stackexchange.com/questions/110956/what-s-the...From what I recall it was a bunch of YC founders writing janky cuda code vs djb who proceeded to smoke us all.
[1] https://news.ycombinator.com/item?id=704182
[2] archive link to the dead link in [1] https://web.archive.org/web/20090717104634/http://www.engine...
[3] https://news.ycombinator.com/item?id=716851
[4] https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
Got a 404 but the title was a nice throwback, $2k in cloud credits too!
There's 13 8s, so that's 1365Wh. 5 9s is 8400Wh, 2 10s is 53760Wh, 3 11s is 1290240Wh.
Total that's ~1.35MWh, which might cost $100 to $180. Very weak estimate, though.
Luck plays a tiny part too, I'm testing sequentially and I got my 9th zero with only ~7e8 hashes, a whopping 100x earlier than expected.
Yep, crazy how long it took, but currently I'm also running multiple 'variants'. All the same program except the nonce generation, one with numbers, one with 32 character long 'base64' and one with 64 character long 'base64'. I got inspired by seletskiy who instead of using numbers used the whole allowed character set for the nonce.
I just tried your HN username, and it took me these times:
19 seconds for 7 0s - nonce: 293576344
28 seconds for 8 0s - nonce: 436316829
Given the nonces you provided, I guess you're going sequential and you're hashing 2-3 times faster than me. I just got a 7 0 hash in 70 seconds and an 8 0 hash in 164 seconds. You're right and I was overestimating how long I waited around last night.
I replaced my nonce generation with a static string and my hashrate went to the moon, so I invested more time in optimizing my input generation.
I was able to optimize it so that I only call rand.Int63 twice per string generation, bringing the CPU time of that part down to 10-15%. I'm getting 11.3 MH/s now!
Your random number generator is pretty much equivalent to feeding a counter into SHA256, so using it as input is pretty much equivalent to hashing a counter twice. There's no point!
Start time: 1718742386
1718742387 SHA-256 hash of "NAHWheatCracker/486005487" is: 00000000cbed8e14c5e52b0c9bef443f017564aa6870da37f85ec92dd01b544d
1718742394 SHA-256 hash of "NAHWheatCracker/993155254" is: 0000000031fadb4805db8036ec66d872bdd9f04a507e0bbfea9f60d1d00b86f2
1718742395 SHA-256 hash of "NAHWheatCracker/436316829" is: 00000000e20d059e8a7dc687b85bd6b33e891f7d4b27e98aaf0c991d0264066e
End time: 1718742403
EDIT: To be clear, I'm not submitting anything to the leaderboard as I appreciate the spirit of the challenge is writing your own code. I'm just having some fun.
EDIT 2: Added some better timing. Interestingly, I modified it to use 64 bit integers and it was dramatically slower. Like, orders of magnitude slower.
Again, I didn't write it, but did add some timestamps.
But seletskiy is, as you can see in his nonce which tells us that he uses an RTX4090 and has 18 Giga Hashes per second. I'm really curious how he wrote that program, as I have a Rx 7900 XTX and would love to use it for this competition haha
The code runs at steady rate of 18.00-18.40 GH/s at cloud GPU. In fact it's not hashes-per-second, but actually messages-per-second checked.
It launches a 64⁶ kernels in a loop, where each launch checks first two bytes of the SHA of a message concatenated with unique 6-byte nonce per kernel + 6-byte incremental nonce for each launch. There is only one block, so SHA algorithm is heavily trimmed. Also, most of the message is hard-coded, so pre-calculated SHA state is used; it's 10 loops less than needed to encode whole block. Since we only 2 bytes of the hash to check, last two loops also unrolled by hand to exclude parts that we wouldn't need. All code also in big-endian since SHA is, so message hardcoded in big-endian as well.
Base64-encoding is pretty time-consuming, so I've optimized it a bit by reordering the alphabet to be in ASCII-ascending order. I've got to the point where single binary-op optimization can earn 100-500 MH/s speed-up, and I don't really know what else here is remaining.
I don't have RTX4090, so instead I just rented 4090 GPU to run code on. It's less than $0.3 per hour.
I've tried GPT-4 to get some directions for optimization, but every single proposal was useless or straight wrong.
I by no means a C/GPU programmer, so probably it can be optimized much more by someone who more knowledgeable of CUDA.
GPU's are ridiculously fast. It freaks me out that I can compute >18,000,000,000 non-trivial function calls per second.
Anyways, if you want to chat, my e-mail is in the profile.
If you limit your variable portion to a base16 alphabet like A-P, radix encoding would just be `nibble + 0x41`. Sure you're encoding 4x as many values, but with full branch predictability. You'd have to experimentally determine if that performs any better.
You could also do something theoretically clever with bitmasking the 4 nibbles then adding a constant like 0x4141 or 0x00410041 or something (I'm too tired to think this through) and then you can encode twice as many per op assuming 32-bit bitwise ops are similar in speed to 16-bit bitwise ops.
Anyways this has been a cool challenge. You might also enjoy hunting for amulets - short poems whose sha256 hash contains a substring that's all 8: https://news.ycombinator.com/item?id=26960729
If you carefully organize the nonce at the end and use all 55 bytes, you can pre-hash the first ~20/64 rounds of state and the first several rounds of W generation and just base further iterations off of that static value (this is known as a "midstate optimization.")
> If you limit your variable portion to a base16 alphabet like A-P
The more nonce bits you decide to use, the less you can statically pre-hash.
In FPGA, I am using 64 deep, 8-bit-wide memories to do the alphabet expansion. I am guessing in CUDA you could something similar with `LOP3.LUT`.
Also have been using ChatGPT to do the code translations.
I'm currently stuck in yak shaving, I cannot compile CUDA programs here yet as on fedora 40 I need an earlier gcc (13.2) which I am now also having to compile from source.
With hashcat and opencl I could get 12GH/s but I couldn't find a way to use hashcat for this use case.
Got an optimised C++ version with no deps averaging about ~24 MH/s on an i7-11800H.
I've got 9 zeros; if I get a result that ranks top 10 I think I'll submit and call it a day.
I don't know how I got it working, but I'm now at 3GH/s with my OpenCL implementation. I basically converted 90% of my rust logic to opencl and now my GPU is at 100% usage and I also needed to switch to a tty, as my window manager became unresponsive haha
I'm kind of glad about this HN post, as I had absolutely no clue about how sha256 and opencl worked before this challenge.
Thanks @quirino
If anyone's curious, I'm getting 4.5MH/s single-threaded and 12.2MH/s multi-threaded on a slightly old i7 with 4 cores.
It's my own C++ implementation, which I've made about 20% faster than the fastest one I found online (Zig/stdlib, also tried Go/stdlib, C++/cgminer, rust/ring, C++/VanitySearch and Python/stdlib).
I think it might be faster just because I was able to skip some steps, since all inputs are short and of the same length.
I've just finished testing 10^12 inputs. I think I'll stop with 10 zeroes, which is very likely to happen in the next couple of days, according to my calculations. I might revisit it later to learn some GPU programming.
But same, I also was able to skip some steps as I can make some assumptions about the input as its fixed in length and doesn't need padding.
I got lucky and found a hash with 12 zeroes in 60s with my OpenCL implementation, and now I got my second spot back.
GPUs are so crazy
Running this for 1.5 hours would consume 1KWh of energy, and compute 1.134e14 hashes (or 2^46.7 if you prefer).
Assuming SHA-256 hashes are essentially normally distributed, that means that finding a hash with 13 leading hex zeroes should be a 1-in-(16^13) aka 1-in-(2^52) odds.
This gives 2^(52-46.7) or 39.7KWh on average to generate a single 13-zero hash, and ~16x that (635KWh) for a 14-zero hash. I got very lucky finding a 14-zero hash quickly, vastly earlier than average expectation, so my energy usage is quite a bit lower than that.
Design/colour scheme is nice too.
The go program beat the javascript miner within seconds. Right now it's that easy to get into the top 10.
I'm using my own SHA256 implementation in C++, and it is at least 100 times faster than the JS one. I've measured it to be about as fast as the one on the Go standard library.
I assume anyone with knowledge about GPU hashing and the will would be able to steal the top spot very quickly. Assuming seletskiy isn't already that guy. I don't have a good grasp on the compute difference between 8-9 0s and 10 0s in a reasonable amount of time.
I felt like I got enough out of this exercise and don't need to burn more CPU cycles on it :)
Curiously most of the code for that JS miner was written on my phone, with the help of ChatGPT.
I didn't have my laptop with me and was curious how fast a phone browser would be able to mine.
It uses Peer-2-Peer in the browser and I haven't touched it in a while, but it looks like it still works. :)
Whih is really odd, since my string has only 51 chars and all chars are valid within the Base64 group.
If I remove the padding ("=") then it's good to go, however, there is a string in the scoreboard with "=" in it (garethgeorge/AHQAAAHPe0Q=)
Did the user bypassed the javascript check using curl or something?
Also, this could use some adjustments:
const nonceRegex = /^[A-Za-z0-9+/]{1,64}$/;
if (!nonceRegex.test(nonce)) {
alert('Nonce must be 1-64 characters long and consist only of Base64 characters');
return false;
}
Personally, I would use const nonceRegex = /^[A-Za-z0-9+/]{1,64}(={0,2})$/;I couldn't get wgsl to work properly, as it would need to have a sha256 implementation, and that's a bit heavy for a buzzed coding session. So, I used the simd commands, and that got me up to around 7mh/s on the m1, and a whole lot more on my desktop.
I will share the code once I get all the other optimizations I want in!
I have a bunch of other ideas to get me to my goal of 20, but I am happy to let this run for a bit! Thanks for the suggestion!
Initial C implementation got me to ~70 for a short time, then very sloppy racy pthreads one kept me at the tail end for a bit longer, but my again very sloppy cuda program running on my GTX1070 has me at 35 at the time of writing.
Rough calculation shows it to be doing 28.6MHashes/sec, and I suspect I could do a lot better than that if I knew anything about cuda programming.
I didn't read enough to know how to pick good values for blocks/threads per block, so I just benchmarked all the combinations of powers of two to arrive at the best result.
Really fun challenge!
Would be fun to see the total amount of valid submissions, and maybe the number of leading zeroes of a hash for those of us that need a moment to figure it out from hex in their head :]
Bug: The site says "nonce: 1-64 characters from Base64 (a-zA-Z0-9+/)" but it accepts "=" as well.
Reading the other answers about hand optimised CUDA and parallel Go and Rust, that's probably as high as I'll get.
jodrellblank/710260141000+idkfa
though why limit the filter to all zeroes, here's double-0 facade... jodrellblank/uhxbvhbaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
00FACADE F2036CC41D004F2EB0F35B079C589D724D5A49BD796363C9A13C27D8Is it even possible to have cheaper first character SHA256 algorithm?
There isn't a known way to calculate just the first bytes of a SHA256 hash faster. Each step in SHA256 depends on the value of the previous step, so you have to calculate the whole thing through. SHA256 is meant for cryptography and would be considered vulnerable to attacks if a shortcut were known.
What would be the goal of that? Do you want a cryptographic hash function, or do you want something else?
If any such shortcut would be found, it would be considered a vulnerability, and the use of SHA256 for anything involving cryptography would be strongly discouraged.
edit: up to #28 ;)
Including the code below if anyone is curious. I managed to get a 9 zero hash in under an hour on a M2 Mac Mini using it. Its only about ~3.3 MH/s which is not very impressive, but it was very easy to write.
https://gist.github.com/boyter/8600199cc6f4073dc9da380f3224f...
I suppose the next step for me would be to make use of the GPU, which is a much better fit for this job and I'm sure would increase my hash rate by orders of magnitude, but I researched it for a bit and running code on the GPU on a Mac is cumbersome to say the least.
It gets around 232.5 MH/s on the M1 Max. There's also an optimization that exploits the fact that SHA256 is incremental, so the state for the common prefix could be pre-computed and then copied and only updated with the variable part. This yields around 30% performance boost.
It manages 1.1 GH/s on an Intel i7-13700K.
https://gist.github.com/zdimension/63d3aa5f04573267f423520e4...
https://gist.github.com/Chaz6/81523edaed6f31aa609daa919ff6b8...
Sorry for the late reply.
I've added a "/data" endpoint where you can get the full database in json format.
The nonce alphabet being limited makes the whole thing quite a bit more expensive.
Did you start using a GPU or where you just insanely lucky?
This is my current solution: https://gist.github.com/lovasoa/9bb6c50feed7bb264c15ae65c622...
Time to comb through this code :D
I just started on a metal implementation and it's at 320MH/s