This is a well-known attack. The discoverer was sophisticated enough to brute force, but not enough to know about this risk :)
This is a well-known attack. The discoverer was sophisticated enough to brute force, but not enough to know about this risk :)
I believe the correlation is the other way around... at least once you get past some early local maxima near "people who don't understand how money can be in a computer."
P.S.: To digress (rant) a bit: The linchpin is whether your system needs to allow anybody to create and control any number of new participant-nodes at any time. That fundamental requirement is actually very rare, and it's also the root causing a cascading tree of workarounds, compromises, inefficiencies, and risks.
The only reason we're still talking about BTC is bag-holders. It's vastly technologically inferior on every metric.
Talking about BTC's failures as if they exemplify cryptocurrency is just like attacking solar panels on the basis of whale oil's flaws.
The next release of Nano (the original and best imo*) manages spam to the point where fee-less sub-second transactions can be maintained even while under a directed spam attack.
If you want to learn more there's plenty of documentation:
Overview: https://docs.nano.org/what-is-nano/overview/
More technical docs: https://docs.nano.org/#
* - I love how it was distributed, and the team are extremely focused on making it work at a "commercial grade" as opposed to working up hype.
The point stands - BTC's limitations mean nothing to the potential of digital currency as a whole. Cryptocurrency has been proven not to need fees or mining, and yet people love to attack it on that basis. Anything to feel superior I guess.
Even taking your example coin, they’re making it production-grade, for what? How many people seriously use it? What is the real plan to adoption? Or is it just another fun tech project.
Why am I doing basic research for you?
These aren't "pie in the sky" "claims", they are statements of fact that can be verified by trying it out yourself. I already linked the docs if you want to know how it works, what the upcoming milestones are, what work has already been done, etc.
One example of a great use case is Nano-gpt(.com), where you can try the latest AI models straight away and pay by the question. The bottleneck here is your imagination.
Regarding nano-gpt, that’s already a solved problem. Literally all API platforms support pay-as-you-go credits. I went to your link, and I loved the irony of them asking for a 0.10$ minimum deposit - note the complete lack of crypto rates. That is par for the course for crypto apps, nobody cares what the coin conversion is - it’s just a gimmick.
TBF, that particular data-point tends to have a "damned if you do, damned if you don't" extrapolation, ex:
1. "If sellers only care about what regular currency it can be turned into, that means it has failed as a currency because it's just an intermediate payment scheme."
2. "If sellers don't care about what regular currency it can become, that probably means it has failed as a currency because it's really just a speculative-bubble asset."
The Raiblocks and BitGrail hack sealed it's death.
And this isn't about personal beliefs, market cap, market share, etc. The conversational point was that it's technically vastly superior to BTC, which it undeniably is. On market cap, adoption and hype, BTC wins hands down, for now, but there's no reason at all for that to always be the case.
People here love dunking on cryptocurrency for the slow times and the mining and the hacks (like this post) - yet none of that is a necessary characteristic of cryptocurrency.
Btw, Nano is very much alive. V27 is coming out soon making major improvements, regardless of like, your opinion man.
The FranciscoTheBomber admin of BitGrail should have served prison time over the entire thing. He got off basically with zero consequences.
Nano will never be in the top 100 of crypto projects ever again. That's just a fact.
Do I need to paste the definitions of fact, vs prediction, prophecy, belief and opinion in here?
I remember hearing similar pronouncements presented as 'ironclad fact' after Mt. Gox, and after the DAO hack, and even during the Bitcoin Cash debate. The field is more full to the brim of people presenting opinions as fact than I would ever have believed. Even if you were someone I'd heard of and respected, a known expert; if you claimed your opinion in this space as fact I would yawn and put my respect for you down a notch.
And, the discussion wasn't about market cap, top 100, or anything like that - just verifiable technical characteristics.
The scam talked about in this thread wouldn't work in Nano, because Nano doesn't require mining or fees. Many other coins have the same characteristics, Nano was an example. I would bet that any other example would have been just as triggering to people.
Note that this issue doesn't exist with puzzle numbers that are multiple of 5, because these addresses have their public key already known. So everyone is on a level playing field. The multiple of 5 have been solved up to #125: https://privatekeys.pw/puzzles/bitcoin-puzzle-tx
That one is even easier to steal because it doesn't even require a digital signature and there are tons of bots out there inspecting live transactions and if they don't require a signature they just create a new transaction with an increased fee and their own address as recipient.
Edit: nevermind, I got confused with P2SH: https://learnmeabitcoin.com/technical/script/p2sh/ pretty sure you can't unlock outputs with a hashed script unless the creator of those outputs did it ahead of time.
I'd be curious to know if it is possible at all to "securely" send the funds of these puzzles or if there is some hard limit that requires the pubkey to be published with the transaction.
So anybody that has sent a transaction can have their private key cracked just from their public address? How is this considered secure? That's absurd...
So this would not be possible with a normal Bitcoin transaction with regular entropy.
mrb describes it better: https://news.ycombinator.com/item?id=41547443
Even if it's 70 years from now before we have the compute to do that, the wallets will be worth so much by then that whoever does that will end up with a level of money that is high enough to menace and threaten entire countries if they are malicious.
Why doesn't Bitcoin require keys to get longer over time? Require 256 bit now but require 65536 bit in 20 years to make any transaction?
To answer your question that change in bitcoin can happen at any point in time with a protocol update. It would probably won’t even require a hard fork, a soft fork would suffice.
Huh? Ask someone in 1950 if we would ever achieve petaflops on a desktop-sized PC. Yet here we are with H100's. About 10 decimal orders of magnitude faster than the state of the art in 1950.
Quantum computing will also happen, and I think 70 years is more than a realistic time frame.
No other transactions are subject to this weakness, and it's this puzzle which proves that.
Look up MEV
It's essentially MitM all the way down.
even the private mempool can attempt a double-spend with a larger fee, get one transaction ahead, then try to maintain an edge long enough to be the "longest branch" for consensus - the 51% attack only needs 33% in reality, much less when your the private mempool that can take advantage of the birthday paradox to jump two blocks ahead.
you have to literally mine your own coin with the reward transaction included.
of course, zpk+ would solve this issue entirely.
Alice and Bob wouldn't ever doubt each other again.
The attack itself can't be mitigated because there's the incentive to try to force the blockchain with your own theft block because your fee is much higher for what appears to be the same transaction. But this attack, like you said, is only feasible for this niche domain of low entropy private keys.
What specifically are you calling "so easy"?
If we're talking about "2^(n/2)", I don't see the problem. Why shouldn't it be that?
https://en.wikipedia.org/wiki/Pollard%27s_rho_algorithm_for_...
Here is a trivial one:
In advance, make a table of all the pubkeys xG for secret key s = (0,2^33].
When you get a target key T, compute T - (2^33)xG for x = (0,2^33] and look up the result in the table.
When you get a hit, you've found the private key for T it's (2^33)x + s.
Of course, this is a trivialized example, many optimizations are possible and you can specialize any generic DL solver to work in a known range.
Work thought it, I think it'll be more informative than me simply repeating myself further. If you're still confused, ask specific questions and I'll be glad to answer.
Given only a random public key, is it possible to quickly recognize when its corresponding private key has weak entropy?
No, but it is possible to quickly recognise that it matches a published puzzle address, which is derived from the public key. And the amount held by that address is public knowlege (it's on the blockchain).
If someone knows that a given address has a huge sum of money, they can create a bot to monitor that particular address, overriding any transactions to his own address?
Would that be possible???
The purpose of the puzzle is to find the private key given only 75% of it.
Let’s imagine that takes 1 year to brute force the last 25%. But if you have the public key as well, it only takes 1 minute.
As soon as the coins were sent, the private key was known since it inherently revealed the public key.
- Send some money to an address, which would temporarily stop accepting money from anywhere else. The fee gives the sender the exclusive right to solve the puzzle for, say, 15 blocks.
- After that transaction is validated, a second transaction (which now cannot be forged by bots) can be sent through.
I am pretty sure you could do something like this on Ethereum but I don't know if the BTC protocol would allow this. I also know very little about the guts of the respective VMs in general.
I wish HN eliminated downvotes without posting associated feedback
I stand by my point: pay peanuts, get monkeys.
If you don't take extra measures to ensure the safe reception of the reward, don't be surprised your security gauge turns out sticky.
but are not the public keys anyway available on block chain? that means literally every thing can be brute forced?