Bitcoin puzzle #66 was solved: 6.6 BTC (~$400k) withdrawn
blockchain.com
blockchain.com
Bitcoin puzzles are private keys with just a few unknown bits so that anyone can bruteforce them to collect a reward. Puzzle 66 contained 66 unknown bits and had 6.6 BTC deposited into it by the initial puzzle creator. The private key was 0x000000000000000000000000000000000000000000000002832ed74f2b5e35ee or 256 bits with mostly zeroes but 66 random ones.
The next Bitcoin puzzle, #67, has 67 unknown bits, and contains 6.7 BTC up for grabs: https://www.blockchain.com/explorer/addresses/btc/1BY8GQbnue...
The previous puzzle by order of difficulty was #64 (not #65, because see below) and was solved on 9/9/2022, so about 2 years ago. In other words, it took about 2 years of compute time to run the 2^66 bruteforcing task.
Puzzles that are multiple of 5 (#65 or #70) are special: they have twice more entropy. So that private key #65 doesn't have 65-bit of entropy but 130-bit of entropy. And the creator of the puzzle intentionally published their public key on the blockchain. When you know the public key, brutetforcing the n-bit private key only requires 2^(n/2) work. So puzzle #65 with a 130-bit key actually require bruteforcing up to only 2^65 keys.
The main discussion thread on the bitcoin forum is this but it has a low signal-to-noise ratio: https://bitcointalk.org/index.php?topic=1306983.0
There is a secondary thread here: https://bitcointalk.org/index.php?topic=5218972.0
The point of the puzzle is indeed to brute force some private keys (not public keys), but not all, as 2^256 is computationally impossible. The private keys that have been discovered so far have obviously many zeros in them, so in practice you are never going to accidentally steal from a legitimate address with actually 256 bits of entropy.
The creator of the puzzle is anonymous and never came forward (to my knowledge). The point of the puzzle is (1) to be a fun game, and (2) to be a publicly observable way of measuring current brute forcing capabilities.
Obviously if you found a shortcut in the hash you might do other things first, but I think that's the idea.
also, if you were the type that thinks bitcoin is lame, this could be a way of undermining the concept to the point that people no longer use it because it's not secure as it was touted
I'd claim the prize, sell for USD, then watch BTC crash
But I think you are one of those people that threw out that baby with the bath water long ago.
In fact solar panel sales are dropping very fast.
[0] https://www.anwb.nl/energie (Dutch)
Custom silicon and all kinds of related optimizations were likely used to successfully brute-force this number.
Note for cryptographers/matematicians: I know that "reversing" isn't the correct term here, so you could accuse me of the same sin I'm calling out in my previous comment. But it makes the explanation shorter while still conveying the correct meaning in the end.
Having the public key is easier than having an address because an address is the hash of a public key. So in order to crack an address, you must first find a public key that produces that address, and then find a private key corresponding to the public key.
Sure, finding a private key whose public key's hash is given might be 2x slower, but Pollard's rho algorithm is 2^128 times faster.
Asymptotically, an additional hash at the end doesn't matter when you brute force. But it prevents you from using Pollard's rho algorithm, which does make a difference asymptotically.
"Here's $400,000 sitting on the table, hope nobody takes it" which triggers an alarm telling us to replace all our old prequantum cryptography.
Or getting hacked. This is super common among people who are known to have high value wallets. Between physical attacks and zero days in everyday software, there's no chance to stay safe when you put that kind of target on your back.
Vitalik Buterin seems to be a counter example here, his net worth peaked around $1.46 billion. He has some interesting writing on how he stays secure. At one point the SHIBA token sent a huge amount of funds to his cold wallet and he details what he did to securely access those funds:
https://decrypt.co/91000/ethereum-founder-vitalik-buterin-du...
> The funds, he said, were initially in a cold wallet in the form of two numbers written on separate pieces of paper. Buterin said he had to combine the two numbers to get the private key. "One of those numbers was with me; the other number was with my family in Canada," he said. "So I had to call up my family in Canada and tell them to read their number to me."
> Buterin said that he entered the numbers into the computer he purchased from Target after putting the two numbers together. "I sent my ETH out by generating a transaction and then on a computer that I bought from Tarjay [Target] for about $300 bucks for just this purpose."
> Before disconnecting the laptop from the internet entirely, Buterin said he downloaded a program to generate QR codes. After generating the Ethereum transaction, he scanned the QR code with his phone, copied it to the laptop, and then put it into etherscan.io/push Tx. Finally, Buterin said he began sending out the tokens.
Maybe not the best example of cryptographic security.
the DAO hack happened, immutably, no one disputes it. the hashes and blocks and transactions are well-known. so there was a "schism", that explicitly validates the fact that without this large-scale cooperation, without the redefinition of what Ethereum is, it would be still be what is on that other branch. these both provide evidence for the immutably and decentralization.
The fact that there are far fewer users of Ethereum Classic (and the market cap is significantly lower) is a testament to how much people care about the community which chose to follow a different history of the Ethereum network.
But in one chain the whole community decided to disown the attacker by injecting hard coded transactions that would send the Ethers back to their original owners.
Vitalik (and all DAO ETH hodlers) luckboxed in that the ETHs locked in the DAO, although "stolen", couldn't be withdrawn by the attacker before a few weeks.
There has been zero pause and zero rollback. Most people don't understand that: by chance the stolen funds were inaccessible to the attacker for a few weeks.
What Vitalik did is he forked (soft fork) the ETH blockchain to modify the rules. That soft fork happened before the cooldown period expired, so the attacker never got to access his funds.
Some members of the community said "adding new rules is against the spirit of decentralization, so we keep using the old chain". The old chain was named "Ethereum classic" while the forked chain kept the name "Ethereum".
But there's been no rollback.
The proof of this is that some people didn't agree with undoing that transaction. They stayed on the old chain, which is now worthless.
This is such a boring and widely known story now, but it has to come up literally any time someone wants to play crypto tribalisim.
The reason why people got confused with your comment is because ex. you purport it was fine, it can never happen again, and everyone who didn't agree went to 0.
Lot of tensions between those things.
We also understand how one person could have those views and even steelman it into something intellectually consistent. But then the post seems really off because it's sort of a rushed, poor, justification for why you believe something, coupled to bemoaning some sort of unrelated group none of us are privy to.
How exactly was Vitalik "indirectly pwned"?
I think pretty much all stores still accept cash, but most people here just never withdraw any. It's pretty much just old people and people buing illegal stuff
So this is why cash IS a good thing. Sex workers want to do their thing and Johns want to not be instantly called out for using sex workers. The people who long ago realized magic mushrooms work to cure depression want to be be able to get it without being jailed. Now, here in Canada, sex work is protected and magic mushrooms will not get you thrown in jail.
So even though you may deem things illegal, I ask you think of a greater good that cash allows as everything being digital reveals a lot of information that not all people are comfortable their government knowing. Be it homosexuals, depressed people trying illicit treatments, or extremely lonely discarded individuals reaching out to sex workers verses suicide.
Lastly according to a quick google search and a few spots I looked at, most only showing 2022 as latest information, most point of sale transactions in Europe are made with cash not card [1]. [1] https://www.statista.com/statistics/786680/share-of-cash-tra...
And in northern Europe, pretty much nobody uses cash. In the rest of Europe, at least the places I've been, pretty much every store accepts card and often other digital payment methods.
I don't doubt your statistics, just stating my experience. I just think it's strange that people prefer cash for legitimate purchases. I definitely want cash to stay around, but these days we can use crypto for illegal stuff anyway do it's not really a big deal.
Then he didn't have to worry about the Shiba related transactions affecting his ETH?
The basic problem was that they transferred into his "cold wallet" https://www.nerdwallet.com/article/investing/hot-wallet-vs-c...
He didn't want to have the signal be that he was happy holding SHIBA and was uncomfortable with that much power & control over SHIBA. So he wanted to be able to transfer his SHIBA out to a hot wallet and then burn most of it and donate the rest, given the amount of money involved he took extra steps like buying a new computer to generate the new keys, airgapping it from the internet while it held the cold wallet keys etc
This problem is harder if you want to pass on your crypto after you can't use them anymore.
If you want to enable recovery, you should give ownership of things to smart contracts, which enable things like succession rules and a heatbeat checkin etc.
Public/private keys are not designed to solve that kind of governance problem.
The $400,000 is an inducement for any participant in that engineering effort to break the conspiracy and take the bag. It's effective during the period between the time that a quantum Shor's solver has been achieved for a given algorithm in theory for 256 bits (and in practice for 66 bits), and the time that a practical solution at 256 bits has been implemented.
I don't know how plausible that timeline is either in spacing or accuracy.
Sometime in early 2029, a bunch of people suddenly find that they're eligible for a $400,000 cash prize if they manage to secretly steal a bit of time on a working quantum computer. In 2030, that group of people doubles, and incorporates a new agency with its own security weaknesses. By 2031 we're talking about four separate countries with their own engineers that have managed to achieve the capability to claim that cash prize. Private corporations are somewhere on the horizon. Very soon this becomes an urgent imperative to anyone inclined, because the prize, like cash, disappears the moment that somebody else seizes it.
It's hard to keep conspiracies, particularly with a verifiable open offer of large amounts of highly portable money on the table to the first person to reveal secrets, and a gradually widening circle of access. The gradually expanding circle of access is what ensures we get some kind of alarm LONG before 2038. Keeping that secret to even 2033 requires hundreds of people and four agencies with diverse motivation and values to consistently turn down cash money for years on end in the interest of keeping their quantum capabilities hidden from the world.
I just think maybe public key crypto is not broken so far because there is no motivation for enough people to work on that. What whould one get, without endangering himself, if he breaks integer factorization?
The reason that we use elliptic curves these days, or if we must then something like 8k bit keys to get 128 bits of security over finite fields, is that for the old Z^*_q/Z_p setup, such a faster algorithm exists (index calculus).
Someone could in theory find a better calculus that works only for groups with some specific characteristics of Curve25519, for example. No quantum computers needed.
EDIT: we know that no _generic_ faster algorithm exists, that is one independent of the representation of the group involved, for the traditional computing model. But that doesn't exclude algorithms, as I said above, that work for very particular cases.
You can get a brief introduction at https://soatok.blog/2020/04/26/a-furrys-guide-to-digital-sig... (your own choice if you want that open in a tab at work or not, but there's nothing NSFW in the usual sense in there), and then read the details of each scheme in the RFCs. Some of the RFCs even talk about security implications.
"djb" as he is known in the crypto world has a good paper at https://eprint.iacr.org/2024/1265 , it's 68 pages so "almost a book". He also has a lot of resources on his page https://cr.yp.to . Be aware that he is sometimes ... controversial (not racist or anything, just has strong opinions on FIPS and the NSA and has actually taken the US government to court in the past over this). He's the author of Curve25519.
(disclaimer, I don't know statistics, cryptography, bitcoin or chances)
You don't even need to travel far. A second or so is enough to break all cryptography, even the post-quantum one.
If someone had a quantum-supreme solution they would go after the sitoshi wallets. Some addresses have like $1B+ and combined represent ~$200B.
I would not be shocked if trying to sell $200B in bitcoin gets you far less than half.
Granted, moving a sitoshi era wallet to a coinbase wallet would raise red flags, but those sized deals are done otc.
This is one of the reasons it is advised never to reuse an address. After using it once, your private key may still be private but your public key is exposed, reducing security.
You don't need the public key, and IIRC most algorithms allow you to derive the public key from the private key, though I'm not sure that's the case with Bitcoin. I have vague memories that there are algorithms where this is not that case, but it's been a while.
1. SHA-256: Used twice (double SHA-256) for block hashing and once in address generation.
2. RIPEMD-160: Used once in address generation (after SHA-256).
3. ECDSA: Used once for transaction signing and verification.
4. Base58Check: Used once for address encoding (includes a checksum generated using SHA-256).
[1] https://www.ledger.com/academy/crypto/what-are-hierarchical-...
The basic idea is you pick one private key that's a sequence of 256 bits or so, call this k. When you need a keypair, you compute H(k, tag) to get another bitstring, then turn that into an ECDSA private key (minding the bear traps here) and that then has a single public key.
For example in U2F, the key derivation is H(k, domain, ...) where k is the secret baked into the USB token, domain is the domain you're logging in to (this is the part that protects against phishing, among other things) and further protocol-specific information.
I'm also unclear on where you got the 'multiple of 5' bit about. It seems the keys corresponding to numbers divisible by 5 were used in a spend transaction by the puzzle creator. Using those addresses in spend transactions reveals the public key and saves compute that would be wasted hashing. It also enables direct attacks using Pollard's rho (which someone already posted a link for above).
Src: https://bitcointalk.org/index.php?topic=1306983.msg51466379#... https://en.wikipedia.org/wiki/Pollard%27s_rho_algorithm_for_...
Another interesting discussion on bitcointalk about using Pollard's kangaroo: https://bitcointalk.org/index.php?topic=5244940.0
As shown by the graph [0], adoption slowed down after 2016 when BTC blocks got consistently full and transaction fees rose to $50 and more. I believe if BTC had scaled to support more transactions the price would be much higher today, as Bitcoin would likely be used as a means of payment across the Internet and in many physical stores at well.
Discussions regarding the decentralization of larger blocks aside, something that is not clear to many people is that scaling a blockchain to handle more transactions doesn't mean a linear increase in energy use. In the case of BTC its Proof-of-Work algorithm operates over the root of the last block's Merkle tree, which is a hash of all the transactions in the block. Being a fixed-size hash it doesn't matter if the block contains 1,000, 1 million or 1 billion transactions. Arguably a more popular Bitcoin would be more valuable and therefore would attract more miners, increasing its energy consumption, but that just reinforces my original point.
What I strongly disagree with is that a Bitcoin with bigger blocks and hence larger transaction capacity is inherently less valuable. That is an unfair comparison because Bitcoin Cash, when the split happened in Aug 2017, could have been recognized as Bitcoin by the ecosystem, but it wasn't, and Bitcoin Core retained the BTC ticker. Because of that Bitcoin Cash had to start adoption from the beginning, losing Bitcoin's established network effects.
My original argument was that if Bitcoin had increased its blocksize before 2016 as Satoshi Nakamoto originally intended [1], then the Bitcoin Cash split wouldn't have happened, Bitcoin adoption would have continued growing (remember that back in the day big players like Microsoft, Dell, Steam and Newegg started accepting Bitcoin payments) and miners would progressively see more of their rewards coming from transaction fees and less from the block rewards.
This last point is one of the big problems with BTC right now: the network security will decrease in the face of dwindling block rewards unless transaction fees rise. I argue that Bitcoin was always supposed to scale in number of transactions, so the aggregate of transaction fees, even if individually inexpensive (roughly 1 cent), would become larger than the block reward. In other words: the block reward was just an economic incentive to kick-start the Bitcoin network, to attract miners that would secure it, but the transaction volume was meant to keep increasing to replace it.
[1] https://bitcointalk.org/index.php?topic=1347.msg15366#msg153...
In my opinion there are two main issues that prevent crypocurrencies from being actually used as currency:
1. How many transactions per seconds can be handled 2. Their extremely high volatility compared to fiat currency
While blockchains can scale to fix point 1, point 2 is driven by forces outside the technology.
Regarding volatility I agree that it's currently an issue, but not an insurmountable problem in my opinion:
1. Payment gateways can offer automatic asset conversion to minimize volatility risk for payment takers. This means I could pay in whichever cryptocurrency the payment gateway would take and the receiver would get whatever currency they have set up in their account. They might want to keep some currencies and convert others, so the payment gateway could offer an option to decide that, and in which amounts (e.g. "keep 10% of each BTC payment, convert the rest to USD").
2. Price volatility should reduce as a cryptocurrency is more widely used. In the alternate universe where BTC scaled to be larger than all credit card networks combined its price could be more stable than many fiat currencies.
[0] https://blog.vermorel.com/journal/2017/12/17/terabyte-blocks...
My new public key search system is almost ready. I had to reinvent my binary database system because, although the database was lightweight https://bitcointalk.org/index.php?topic=5475626, I had efficiency issues with binary search. This is now a thing of the past. I have designed a system that stores 100 million public keys in an 80 KB file, yes, what you read 80KB!(in the future it will be smaller) that meets maximum efficiency. We would only be limited by the current speed of Secp256k1 when generating the 100 million or more public keys while creating the database. I am finishing designing the search script after months of being stuck due to personal issues, I am finally back on track.
I love these kind of mad inventor rabbit hole corners of the Internet. Kind of brings back the 90s for me when everything was exciting.
That’s 0.0064 bits per public key - so either there are lots of duplicates, or something is amiss here?
Edit: they don’t actually store the keys, so the quote is misleading.
Assuming there are no duplicates, which is a sensible assumption, you’d need a minimum of 100,000,000 bits to store 100,000,000 unique entries larger than 1 bit with even a perfect hash function.
Also they already did follow the link. That's why they said "they don’t actually store the keys, so the quote is misleading", which you responded to with a laugh and nothing else. And that happened many hours before you made this new comment.
I'm not sure that guy really understood what was going on. If he'd followed the links he would've found the code. Or at least a technical description. So why need to play dumb and ask here, while trying to control the discussion?
I don't like that kind of thing. If you're okay with it, alright. But that's not me.
The easiest one to think about is storing the deltas between each number. Let's say 80% of your deltas are 5. If you use arithmetic encoding, then storing a 5 only takes about 1/3 of a bit. It's not hard to come up with probability distributions where the average amount of bits per entry is less than 1.
Also, back in the realm of perfect hashes, once you're more than half full it becomes more efficient to store the missing numbers. If your perfect hash has 100,003,000 possible outputs, then your worst case is around 50k unique entries. By the time you encounter 100k unique entries you only need to keep track of the 3000 you haven't seen yet.
TX input:
Code:
1FuckUmT5yBAvozf6gT8GRQVbJ7iBDUnrH
TX outputs:
Code:
1Jvv4yWkE9MhbuwGU66666666669sugEF 0.00000001
1YouAreSoDumbLoL666666666667K5aR4 0.00000002
1WhatWereUThinking6666666662wkqq1 0.00000003
1YouDeserveNothing6666666665sbbBC 0.00000004
1YouEpicFaiLure66666666666688GSDA 0.00000005
1BitchAssLoser66666666666669dBUVg 0.00000006
1AndEveryoneELse666666666669Vnc8C 0.00000007
1ThisisALosingGame6666666667HAZdf 0.00000008
1JustGetAReaLJob666666666665vGKVD 0.00000009
1YoureWastingTimeAndMoney664CVExC 0.00000010
1AndCausingCLimateChange6666HK8Qc 0.00000011
13zb1hQbWVsc2S7ZTZnP2G4undNNpdh5so 0.00000012
1Jvv4yWkE9MhbuwGUoqFYzDjRVQHaLWuJd 0.00000013
1FK5PjPNARQmg94n2cNHTo9417kWfXUDBQ 0.00002125I think you might be confusing it with greenhouse gas emissions.
bitcoin mining is an extremely competitive business of finding the cheapest sources of energy and mining hardware; because the cheapest energy sources are all renewable, mining bitcoin with fossil-fuel-produced power is unprofitable. so the electricity we're using to mine bitcoin is mostly solar, wind, and hydroelectric
as for the cracking, i don't think we know anything about where it was done or how much energy was needed, but if the energy cost was significant, i'd expect the solver to have done it somewhere where energy was cheap
One major exception to this is geothermal electricity in places like iceland where there's abundant green electricity, but you can't transport it to any neighbors.
So just using renewable sources for electricity doesn't actually make mining renewable until we're in a society that's 100% renewable.
consequently, there are lots of places where there's abundant green electricity that can't be economically transported to any neighbors, which is why green electricity is cheaper than coal, nuclear, and gas energy. if it could be economically transported, it would be; instead, it is sold locally at much lower prices. only rarely is this seen by residential end-users, but in much of the world the 15-minute prices paid on the wholesale market by electric utilities are public information, so you can easily verify this
as a result of that, just using renewable sources for electricity does actually make mining renewable
as for the grauniad article, there are a lot of people doing unprofitable business things in lots of businesses, but they tend to be self-limiting, because those people run out of money before long
https://en.wikipedia.org/wiki/Xingu-Estreito_HVDC_transmissi...
https://en.wikipedia.org/wiki/Xingu-Rio_HVDC_transmission_li...
I'll try to give a brief here about how Bitcoin script works but you'd better read up on the Bitcoin wiki.
Essentially, to make a transaction valid, your script needs to pass.
1. <PubKey> + <Signature> -> This is how most transactions are handled. You provide the transaction with a signature. This doesn't expose your private key and lock the receiver. (as the receiver is signed)
2. <Hash> + <Hashed Content> -> To solve for Hash, you need to provide the Hash Content essentially solving the puzzle. Problem is, if you provide the Hashed Content publicly in the Script, anyone can also submit a competing transaction and set himself as the receiver.
Edit: typo
Fascinating that the original cracker wouldn't know these details about Bitcoin transactions.
One of the really interesting thing about the blockchain, is that you can write a smart contract script that will permiate forever.
using a hashed transaction instead of a signed transaction is a wierd mistake to make, but not an uncommon one of people who are just learning to write blockchain code. I know we are talking about BTC here and opcode is rather limited, but this type of thing pervades on ETH.
Imagine writing a PWN script as a 14 year old and waking up when you are in your late 20's to a millions dollars in crypto.
> https://bitcointalk.org/index.php?topic=1306983.msg64535839#...
I'm not super familiar with the concept (and I'm too lazy to look into it TBH), but I think the would-be winner posted the private key before enough (any?) blocks were mined, and the thief posted a transaction with a bigger fee, and the thief's transaction was in the block that got mined.
As a miner, if I see two conflicting transactions I will prioritize the one which pays more rather than the one I saw first.
1Jvv4yWkE9MhbuwGU66666666669sugEF 0.00000001 1YouAreSoDumbLoL666666666667K5aR4 0.00000002 1WhatWereUThinking6666666662wkqq1 0.00000003 1YouDeserveNothing6666666665sbbBC 0.00000004 1YouEpicFaiLure66666666666688GSDA 0.00000005 1BitchAssLoser66666666666669dBUVg 0.00000006 1AndEveryoneELse666666666669Vnc8C 0.00000007 1ThisisALosingGame6666666667HAZdf 0.00000008 1JustGetAReaLJob666666666665vGKVD 0.00000009 1YoureWastingTimeAndMoney664CVExC 0.00000010 1AndCausingCLimateChange6666HK8Qc 0.00000011 13zb1hQbWVsc2S7ZTZnP2G4undNNpdh5so 0.00000012 1Jvv4yWkE9MhbuwGUoqFYzDjRVQHaLWuJd 0.00000013 1FK5PjPNARQmg94n2cNHTo9417kWfXUDBQ 0.00002125
When you post a transaction, the public key is in the transaction (inside the field "sigscript") . With the public key known you only need 2^(66/2) checks (instead of 2^66), which can be done really fast.
So some bot watched the address, obtained the public key, computed the private key from it, and front-ran the original submitter probably with a deal from a mining pool to make sure his transaction is enforced.
Is that true for every single Bitcoin transaction?
> With the public key known you only need 2^(66/2) checks (instead of 2^66), which can be done really fast.
Then how comes not all Bitcoin transactions are front-ran like that and Bitcoin is not worth zero already? 2^33 is indeed nothing: 8 billion (so I understand this can be easily cracked).
I think so, for outgoing transaction (aka to remove from the address), it's kind of needed to verify the signature.
The 2^66 is only for this game where only 66 bits were left unknown. In the general case obtaining the private key from the public key is much longer.
Why doesn't this happen with every large transaction then? Someone tries to move 10 BTC, instantly stolen?
Basically you're saying that every single Bitcoin transaction can be stolen "really fast".
Am I missing a step here?
The second post on this thread[0] has a helpful chart that makes it easier to understand.
This is a well-known attack. The discoverer was sophisticated enough to brute force, but not enough to know about this risk :)
I believe the correlation is the other way around... at least once you get past some early local maxima near "people who don't understand how money can be in a computer."
P.S.: To digress (rant) a bit: The linchpin is whether your system needs to allow anybody to create and control any number of new participant-nodes at any time. That fundamental requirement is actually very rare, and it's also the root causing a cascading tree of workarounds, compromises, inefficiencies, and risks.
The only reason we're still talking about BTC is bag-holders. It's vastly technologically inferior on every metric.
Talking about BTC's failures as if they exemplify cryptocurrency is just like attacking solar panels on the basis of whale oil's flaws.
The next release of Nano (the original and best imo*) manages spam to the point where fee-less sub-second transactions can be maintained even while under a directed spam attack.
If you want to learn more there's plenty of documentation:
Overview: https://docs.nano.org/what-is-nano/overview/
More technical docs: https://docs.nano.org/#
* - I love how it was distributed, and the team are extremely focused on making it work at a "commercial grade" as opposed to working up hype.
The point stands - BTC's limitations mean nothing to the potential of digital currency as a whole. Cryptocurrency has been proven not to need fees or mining, and yet people love to attack it on that basis. Anything to feel superior I guess.
Even taking your example coin, they’re making it production-grade, for what? How many people seriously use it? What is the real plan to adoption? Or is it just another fun tech project.
Why am I doing basic research for you?
These aren't "pie in the sky" "claims", they are statements of fact that can be verified by trying it out yourself. I already linked the docs if you want to know how it works, what the upcoming milestones are, what work has already been done, etc.
One example of a great use case is Nano-gpt(.com), where you can try the latest AI models straight away and pay by the question. The bottleneck here is your imagination.
Regarding nano-gpt, that’s already a solved problem. Literally all API platforms support pay-as-you-go credits. I went to your link, and I loved the irony of them asking for a 0.10$ minimum deposit - note the complete lack of crypto rates. That is par for the course for crypto apps, nobody cares what the coin conversion is - it’s just a gimmick.
TBF, that particular data-point tends to have a "damned if you do, damned if you don't" extrapolation, ex:
1. "If sellers only care about what regular currency it can be turned into, that means it has failed as a currency because it's just an intermediate payment scheme."
2. "If sellers don't care about what regular currency it can become, that probably means it has failed as a currency because it's really just a speculative-bubble asset."
The Raiblocks and BitGrail hack sealed it's death.
And this isn't about personal beliefs, market cap, market share, etc. The conversational point was that it's technically vastly superior to BTC, which it undeniably is. On market cap, adoption and hype, BTC wins hands down, for now, but there's no reason at all for that to always be the case.
People here love dunking on cryptocurrency for the slow times and the mining and the hacks (like this post) - yet none of that is a necessary characteristic of cryptocurrency.
Btw, Nano is very much alive. V27 is coming out soon making major improvements, regardless of like, your opinion man.
The FranciscoTheBomber admin of BitGrail should have served prison time over the entire thing. He got off basically with zero consequences.
Nano will never be in the top 100 of crypto projects ever again. That's just a fact.
Do I need to paste the definitions of fact, vs prediction, prophecy, belief and opinion in here?
I remember hearing similar pronouncements presented as 'ironclad fact' after Mt. Gox, and after the DAO hack, and even during the Bitcoin Cash debate. The field is more full to the brim of people presenting opinions as fact than I would ever have believed. Even if you were someone I'd heard of and respected, a known expert; if you claimed your opinion in this space as fact I would yawn and put my respect for you down a notch.
And, the discussion wasn't about market cap, top 100, or anything like that - just verifiable technical characteristics.
The scam talked about in this thread wouldn't work in Nano, because Nano doesn't require mining or fees. Many other coins have the same characteristics, Nano was an example. I would bet that any other example would have been just as triggering to people.
No other transactions are subject to this weakness, and it's this puzzle which proves that.
Look up MEV
It's essentially MitM all the way down.
even the private mempool can attempt a double-spend with a larger fee, get one transaction ahead, then try to maintain an edge long enough to be the "longest branch" for consensus - the 51% attack only needs 33% in reality, much less when your the private mempool that can take advantage of the birthday paradox to jump two blocks ahead.
you have to literally mine your own coin with the reward transaction included.
of course, zpk+ would solve this issue entirely.
Alice and Bob wouldn't ever doubt each other again.
The attack itself can't be mitigated because there's the incentive to try to force the blockchain with your own theft block because your fee is much higher for what appears to be the same transaction. But this attack, like you said, is only feasible for this niche domain of low entropy private keys.
- Send some money to an address, which would temporarily stop accepting money from anywhere else. The fee gives the sender the exclusive right to solve the puzzle for, say, 15 blocks.
- After that transaction is validated, a second transaction (which now cannot be forged by bots) can be sent through.
I am pretty sure you could do something like this on Ethereum but I don't know if the BTC protocol would allow this. I also know very little about the guts of the respective VMs in general.
I wish HN eliminated downvotes without posting associated feedback
I stand by my point: pay peanuts, get monkeys.
If you don't take extra measures to ensure the safe reception of the reward, don't be surprised your security gauge turns out sticky.
I'd be curious to know if it is possible at all to "securely" send the funds of these puzzles or if there is some hard limit that requires the pubkey to be published with the transaction.
Note that this issue doesn't exist with puzzle numbers that are multiple of 5, because these addresses have their public key already known. So everyone is on a level playing field. The multiple of 5 have been solved up to #125: https://privatekeys.pw/puzzles/bitcoin-puzzle-tx
That one is even easier to steal because it doesn't even require a digital signature and there are tons of bots out there inspecting live transactions and if they don't require a signature they just create a new transaction with an increased fee and their own address as recipient.
Edit: nevermind, I got confused with P2SH: https://learnmeabitcoin.com/technical/script/p2sh/ pretty sure you can't unlock outputs with a hashed script unless the creator of those outputs did it ahead of time.
So anybody that has sent a transaction can have their private key cracked just from their public address? How is this considered secure? That's absurd...
So this would not be possible with a normal Bitcoin transaction with regular entropy.
mrb describes it better: https://news.ycombinator.com/item?id=41547443
Even if it's 70 years from now before we have the compute to do that, the wallets will be worth so much by then that whoever does that will end up with a level of money that is high enough to menace and threaten entire countries if they are malicious.
Why doesn't Bitcoin require keys to get longer over time? Require 256 bit now but require 65536 bit in 20 years to make any transaction?
To answer your question that change in bitcoin can happen at any point in time with a protocol update. It would probably won’t even require a hard fork, a soft fork would suffice.
Huh? Ask someone in 1950 if we would ever achieve petaflops on a desktop-sized PC. Yet here we are with H100's. About 10 decimal orders of magnitude faster than the state of the art in 1950.
Quantum computing will also happen, and I think 70 years is more than a realistic time frame.
Given only a random public key, is it possible to quickly recognize when its corresponding private key has weak entropy?
No, but it is possible to quickly recognise that it matches a published puzzle address, which is derived from the public key. And the amount held by that address is public knowlege (it's on the blockchain).
What specifically are you calling "so easy"?
If we're talking about "2^(n/2)", I don't see the problem. Why shouldn't it be that?
but are not the public keys anyway available on block chain? that means literally every thing can be brute forced?
https://en.wikipedia.org/wiki/Pollard%27s_rho_algorithm_for_...
Here is a trivial one:
In advance, make a table of all the pubkeys xG for secret key s = (0,2^33].
When you get a target key T, compute T - (2^33)xG for x = (0,2^33] and look up the result in the table.
When you get a hit, you've found the private key for T it's (2^33)x + s.
Of course, this is a trivialized example, many optimizations are possible and you can specialize any generic DL solver to work in a known range.
Work thought it, I think it'll be more informative than me simply repeating myself further. If you're still confused, ask specific questions and I'll be glad to answer.
If someone knows that a given address has a huge sum of money, they can create a bot to monitor that particular address, overriding any transactions to his own address?
Would that be possible???
The purpose of the puzzle is to find the private key given only 75% of it.
Let’s imagine that takes 1 year to brute force the last 25%. But if you have the public key as well, it only takes 1 minute.
As soon as the coins were sent, the private key was known since it inherently revealed the public key.
https://www.blockchain.com/explorer/addresses/btc/173ujrhEVG...
I recently read that some are thinking about connecting the US with Europe via DC cabling.
Here's a related, old article: "Submarine power cable between Europe and North America: A techno-economic analysis" (2018)
• Developed a 2030 power dispatch model of Europe and North America (NA).
• Identified socio-economic benefits of European-NA electricity trading through a HVDC cable.
• A 4000 MW cable increases social welfare by 177 M€ on an annual basis.
• This benefit for society is sufficient to cover the investment costs.
https://www.sciencedirect.com/science/article/pii/S095965261...
Conclusion: yes, it's still a waste, unless that energy was surplus absolutely not going to be used for anything better or able to be stored, although even then the compute resources could have probably been used for more useful problems.
California uses green energy, but in doing so increases the mining reward, which increases the mining from countries like china and russia, who do not use green energy.
As something that’s eminently portable, I think crypto mining might actually have a use in derisking building out solar deployments, as a sort of buyer of last resort.
It might be nice to have other very portable energy sinks to eat up temporarily cheap locally available electricity. I think this might be part of the dream of the hydrogen proponents.
While that energy technically serves the purpose of letting a monetary system function, traditional monetary infrastructure requires vastly smaller amounts of energy, thus this is a wasteful use of it
I guess BoA probably handles a little more than that?
Therefore Bitcoin could scale to handle millions of transactions per second with a sublinear increase in electricity spent. [0]
[0] http://blog.vermorel.com/journal/2017/12/17/terabyte-blocks-...
Which as a whole is very limited scenario.
It is very much not: https://www.theguardian.com/technology/2022/feb/18/bitcoin-m...
https://cowboystatedaily.com/2024/09/03/giant-wyoming-carbon...
> CarbonCapture cited “intense competition from data centers” in the region for electricity as partially the reason why it is moving from Wyoming.
Wyoming is a very popular state for cryptocurrency mining due to substantial state support, cheap energy, cool climate, etc. Miners use a lot of clean energy that would have been used for more useful purposes, as shown by the article I linked.
You can do actual useful stuff with electricity no matter where it came from, like smelting aluminium, training AI models or desalinating water. Wasting it on mining bitcoin is literally the last thing we should be doing with spare energy.
If that spare energy doesn’t have a use yet, negative pricing will find one… but allowing that use to be “computing mathematical puzzles to support a deregulated financial instrument whose chief uses are illicit transactions and speculative investment” is just absurd and we should regulate this away.
the canaries that are left are worth several million of USD combined, if there's any incremental progress towards cracking them, that's a strong incentive not to leave the money on the table.
if someone comes up with a full crack sponteously, then yeah the canaries won't protect you, or anything else for that matter.
You'd just need to download the 6,505,548 TB list of keys and re-derive the public key for each to check that they're valid; unfortunately it would take in the ballpark of a kiloyear of compute time assuming you have 3x RTX 3090s.
>> First output: take random number from 2^0 upto 2^1-1, use it as private key >> Second output: take random number from 2^1 upto 2^2-1, use it as private key >> Third output: take random number from 2^2 upto 2^3-1, use it as private key
To me it sounds like that wallet #10 has a range from 2^9 to 2^10 - 1 - so you don't actually need to check previous bits. But somehow it seems like everyone is crawling through the whole range of possible private key. Doesn't make sense, does it? Am I missing something?
With each puzzle, you know that the top bit is 1, and nothing else. Every bit below that is unknown, and you need to go through the whole range of n-1 bits. Puzzle #10 has 9 bits to guess, because it's between 10_0000_0000 and 11_1111_1111. Puzzle #66 has 65 bits to guess. If someone says 66 unknown bits they've misspoken.
>> Puzzle #10 has 9 bits to guess, because it's between 10_0000_0000 and 11_1111_1111
means that I don't have to start at 0000 0000 0000 ... everytime, I can actually start at 2^5 and look up to 2^6 - 1, for example for the 6th address.
I thought cracking anything to steal bitcoin was impossible due to the keys sizes involved? Is this possible because a portion of the key is already available so there is less to crack?
Which key is known? The public or private? Another comment said the “now known public” but then also said the private key can now be recovered by cracking it? Two keys need to be cracked?
What kind computing power is needed to crack both keys and how long?
Thanks. Sorry, I’m an idiot when it comes to bitcoin.
This would normally be computationally intractable but these keys are much smaller than normal, with most of their leading digits intentionally zeroed out to make it easier to 'steal' the funds from the corresponding wallet. If anyone knows who set this up, or why, they aren't talking.
In the process of creating the transaction to claim the prize, the winner must generate a corresponding public key based on some sort of hash of the private key and wallet address. I don't know how they can tell when they've succeeded; hopefully someone else can clarify/correct this point. But once they do succeed, the transaction is then posted in public to allow miners to add it to the blockchain.
Unfortunately, due to mathematical witchfuckery, knowledge of both the private key and a valid public key makes it possible to solve the puzzle as if the already-shortened private key had half the number of bits. In that case, finding the wallet address might take only a minute or two on a standard GPU rather than the months of time on a whole warehouse full of them that the original winner had to spend.
Knowing this, people who are bad and who should feel bad set up bots to watch for the prize-claiming transactions. The bots are designed to recompute the source wallet address independently and front-run the winner's transaction by resubmitting it for the benefit of the thief, using a higher reward to incentivize miners to prioritize their transaction over their original one. Bitcoin blocks are mined about every 20 minutes, so on average the thief has about 10 minutes to create an overriding transaction once the original transaction is posted. Sucks to be the winner who expended so much effort to claim the prize, as they are now out about $400K. Nothing left but a huge electric bill.
https://bitcointalk.org/index.php?topic=1305887.0
Someone, back in the 2015, created this puzzle when BTC was cheap. He/she posted a couple of public keys (Wallet Addresses):
https://bitcointalk.org/index.php?topic=5218972.0
Though, I don't understand the actual task. It's a couple of transactions and one have to "guess" (aka bruteforce) the private key to a known public key. There's an increasing level of complexity, which makes it harder, the higher you get in this list.
Would appreciate any more details.
https://www.blockchain.com/explorer/transactions/btc/12f34b5...
Bitcoin was not cheap in 2023, this is someone with $50m to spare!
IANAL, etc.
What puzzles create something of value when they're solved today? A puzzle is typically a thing you do for fun and entertainment, not something you try to solve for the purpose of creating value.
I guess you're thinking more about logic/mathematical puzzles and alike? Would make sense in that case, but that's not the only type of puzzle.
I'm not into crypto and I do think Bitcoin is stupid and wasteful, but I don't find it "sick" or all what upsetting that this kind of puzzle exists, though I think some smart contract-based Ethereum puzzles could be much more interesting, demanding solutions to more interesting problems that don't directly relate to the blockchain itself. Imagine a smart contract with a pot anybody can pay into that pays out to whoever could crack a particular previously unsolvable problem. Basically a public bounty. The only downside is that it has to be a problem that can be validated algorithmically.
This was just a race to see who could burn the most CPU/GPU cycles the fastest.
Even when a real puzzle has a monetary reward for solving it, a big component of the reward is the solving itself. For this, the reward is just money.
Anyway, I don't agree that puzzles by definition have known answers, unless you want to nitpick and I just change my "puzzle" into "challenge".
But, as it happens, this one does: it offers economic incentive to develop more efficient attacks on elliptic curves. The curve Bitcoin uses isn't widely used outside of it, but that doesn't mean that an efficient attack on Secp256k1 wouldn't apply elsewhere.
Is this modest as positive externalities go? Probably yes. Could someone with a better attack on the curve just empty wallets? Not necessarily, and probably not: the point of the puzzle is that the entropy has been deliberately reduced to make it crackable with brute force, so, say someone worked out a factor of four improvement: that isn't going to get you into the Genesis Wallet, but it substantially lowers the price of claiming some of the puzzles.
Also, being a cryptographer and being a thief are unrelated professions. Some people might be inclined to both, but I would guess that most are not.
Bitcoin may be an inefficiency, but is it the? Most everyday things modern first-world people do are equivalent to burning oil and shredding trees for little to no reason. You just can’t see it as clearly as in PoW crypto.
a lot of people created co2 to take part in a btc lottery and the winner was now randomly found.
I hate crypto :|
I think it’s worth noting that bitcoin uses a fraction of the energy required to mine gold for example.
It’s also a driving force in renewables, by stabilising energy grids (mining can use the spare capacity during quiet periods and switch off during peak hours).
So I don’t think it’s as black and white as “bitcoin uses energy = bad”
In NYC they bought a Gas power plant only for bitcoin. In Texas they had to pay millions to bitcoin miners for them to shut down. In china they stole power from normal people left and right.
It also allows to sell local limited energy globally and pushing energy into the trading/gambling area. Instead of giving local people cheap energy, some bitcoin miner will try to get as much of that cheap energy possible. It also incentivives using bitcoin miners to use flare gas instead of doing something to actually capture and use it as it is a limited resource.
Nonetheless PoW is stupid. its the worst scenario we can come up with in a society with scare resources and a very limited co2 budget by now ( have you watched the TED talk? ). And at the end bitcoins PoW system even still stand on our existing PoW system. Someone stole your bitcoins? You go to the police... Without our existing PoS System, you would need to keep your bitcoin wallet and address always anonyme otherwise you would trust our law and order (part of our PoS system) and you could literaly only send bitcoins around and nothing else. (Smart contracts are also not scalable and not stable solution to this issue).
Btw. yes gold need energy to be mined but its a one time cost YOU HAVE TO DO to use this material. Bitcoin is a Waste Resource all the time to use. And Gold has real value in science, manufacturing and in styling/model/art. Nonetheless we need to get the co2 production of Gold down and Bitcoin we just don't need. The best solution is to get rid of bitcoin and keep reducing co2 production for gold.
And yes i do have a lot more arguments on why bitcoin is useless.
Liquidity of less than a million worth of BTC hasn't been a problem for a long time
It takes 3 seconds to look up the 24h volume for BTC and it is $9.6 Billion
https://news.ycombinator.com/newsguidelines.html
"Be kind. Don't be snarky. Converse curiously; don't cross-examine. Edit out swipes."
Plenty of banks will freeze your bank account instantly.
And good luck convincing them that you stumbled upon $400k by solving a puzzle - only takes one suspicious fraud/risk manager to conclude that there’s a higher chance of fraud than legitimacy.
(But you are right, no problem to find someone to pay you the market price. That’s a done deal in seconds)
2. Deposit bitcoin
3. Market order sell all
4. Withdraw USD
Step 2.6 Coinbase blocks your account citing "Suspicious activity"
Step 2.7 Sign up to three other exchanges, split the loot across them
Step 5 Argue with the bank about the source of funds
Step 6 Argue with tax agency that you'll fill out your taxes correctly
Taxing this is super simple, you just mark as "other" - akin to finding money on the ground.
Arguing with bank - which specific bank would cause problems here?
Then again, it may be serious trouble if you have serious issues explaining the source.