|
Title: R,S,Z , K nonce and public key Signature samples Post by: krashfire on June 22, 2024, 11:47:33 AM Saw some comments of users looking for R,S,Z Signatures and public key sample for research purposes.
So i created a script where you can have a little more details than you need. Its a simple script so you can do your various research that you wish on ECDSA Secp256k1 signatures. you can download it here. https://github.com/KrashKrash/ecdsa-rsz-signature Code:
just a little more info for you who are just starting out to do the research, some call it z, some call it message(hash) some just call it h. but it means the same thing. message or m = the original message H(m) or h or z = the hash of the message H(m), h or z depending on who you talk to, is the hash of the message. same meaning. I just want to have this information out here so you don't waste your time thinking what is h and what is z. Good luck on your research. Title: Re: R,S,Z , K nonce and public key Signature samples Post by: Kpot87 on June 22, 2024, 05:50:33 PM Offtop, how if your twist attack?
Title: Re: R,S,Z , K nonce and public key Signature samples Post by: krashfire on June 23, 2024, 01:29:59 AM Offtop, how if your twist attack? thats done. awhile ago. Title: Re: R,S,Z , K nonce and public key Signature samples Post by: jacky19790729 on June 24, 2024, 10:21:41 AM I have been learning about ECDSA ( r s z, public key ,private key ) for about 2 months
# 130 Although only 1 rsz is known , but 1000 rsz can be produced using the public key, the nonce K value will be 240~256 bits 50% - nonce is 256 bit 25% - nonce is 254 bit 25% - nonce is 253~240 bit However, more than 64 rsz must be leaked at the same time to leak more than 12 bits to use lattice-attack # 130 Public Key ( Fix 2024/06/25 ) 0x633cbe3ec02b9401c5effa144c5b4d22f87940259634858fc7e59b1c09937852, 0xb078a17cc1558a9a4fa0b406f194c9a2b71d9a61424b533ceefe27408b3191e3 Address: 1Fo65aKq8s8iquMt6weF1rku1moWVEd5Ua I create some rsz as #130 , these are address "1Fo65aKq8s8iquMt6weF1rku1moWVEd5Ua" and the public keys are #130 public key Code: # 130 rsz 1 Title: Re: R,S,Z , K nonce and public key Signature samples Post by: krashfire on June 25, 2024, 06:11:27 AM I have been learning about ECDSA ( r s z, public key ,private key ) for about 2 months # 130 Although only one rsz is know , but 1000 rsz can be produced using the public key, the nonce K value will be 240~256 bits 50% - nonce is 256 bit 25% - nonce is 254 bit 25% - nonce is 253~240 bit However, more than 64 rsz must be leaked at the same time to leak more than 12 bits to use lattice-attack # 130 Public Key 0x8629507d9eef1748ec67ca2c4ab641fa0951d7f0bb0cf226f1c0f465a4e29404, 0x2237204a53021490adfec9f0b3f0732f5024181d50fde2dcfc7a428c992b8d70 create #130 rsz Code: # 130 rsz 1 would you mind sharing your code on how you leak the RSZ and how you create more sample for the given public key. thank you Title: Re: R,S,Z , K nonce and public key Signature samples Post by: jacky19790729 on June 25, 2024, 07:48:48 AM would you mind sharing your code on how you leak the RSZ and how you create more sample for the given public key. thank you https://bitcointalk.org/index.php?topic=5394249.100 (https://bitcointalk.org/index.php?topic=5394249.100) read it ....... garlonicon share his source code Even if I have 100,000 puzzle #130 r , s, z I still can't use lattice-attack crack ....Because the generated rsz and k values are unknown.... I used my private key and public key to see nonce K value ... From the probability, more than 50% is a 256-bit nonce K value ~~ It must be 252 bit or less bit ...... Unless you can know from these 100,000 rsz which nonce k bits are less than 252 bit , and select 88 group for lattice attack... This probability is lower than guessing any Bitcoin private key :'( :'( N = 0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEBAAEDCE6AF48A03BBFD25E8CD0364141 if N <= 252 bit , we can use #130 public key to produce 70 ~ 100 fake rsz , and ECDSA will broken ~~~ Now, ECDSA is still safe Title: Re: R,S,Z , K nonce and public key Signature samples Post by: JohnnyTX on June 25, 2024, 02:15:25 PM Hi there!
It looks like you all are crazy for nonces and signatures, so I have some special values for you ;) Code: r=0x678afdb0fe5548271967f1a67130b7105cd6a828e03909a67962e0ea1f61deb6 Title: Re: R,S,Z , K nonce and public key Signature samples Post by: jacky19790729 on June 25, 2024, 04:01:32 PM Hi there! It looks like you all are crazy for nonces and signatures, so I have some special values for you ;) Btw. I think that those who do serious research of this topic do not need your script, but all contributions are welcome, of course. the same r value , we can recovery private key ........ but we are interested in recovering the private key of #puzzle 130 from a large set of r s z and public key ... But we need to know the bits of k , from every set of r s z ......... if anyone can know the bits of k from every r s z and public key , all bitcoin address that leaks the public key can recovery private key Of course, currently only 252 bit k can be recovery by the lattice attack. https://githubhelp.com/bitlogik/lattice-attack/issues/2 (https://githubhelp.com/bitlogik/lattice-attack/issues/2) The authors of the lattice-attack mentioned that they were also unable to crack more than k > 252 bits~~~ For the topic "down to 2 bits", note that we never found a private key using our LatticeAttack software below 4 know bits, hence the restriction put in place that prevent the user to run it with lower than 4 bits. But we never performed long running time. Using higher RECOVERY_SEQUENCE "effort" block size, combined with a loop "-l" can be a way to recover key with 3 or even 2 bits. That would just require long running times (several hours), and no guarantee of result. Title: Re: R,S,Z , K nonce and public key Signature samples Post by: JohnnyTX on June 25, 2024, 05:55:44 PM the same r value , we can recovery private key ........ These are not as easy as you may think.but we are interested in recovering the private key of #puzzle 130 from a large set of r s z and public key ... But we need to know the bits of k , from every set of r s z ......... Well, then I have two more for you, but this public key doesn't point to the puzzle #130 it seems... # Public Key 0x8629507d9eef1748ec67ca2c4ab641fa0951d7f0bb0cf226f1c0f465a4e29404, 0x2237204a53021490adfec9f0b3f0732f5024181d50fde2dcfc7a428c992b8d70 Code: # rsz 1 Title: Re: R,S,Z , K nonce and public key Signature samples Post by: jacky19790729 on June 25, 2024, 06:56:02 PM Well, then I have two more for you, but this public key doesn't point to the puzzle #130 it seems... # Public Key 0x8629507d9eef1748ec67ca2c4ab641fa0951d7f0bb0cf226f1c0f465a4e29404, 0x2237204a53021490adfec9f0b3f0732f5024181d50fde2dcfc7a428c992b8d70 I had edit my post ~~ fix it #130 public key 0x633cbe3ec02b9401c5effa144c5b4d22f87940259634858fc7e59b1c09937852, 0xb078a17cc1558a9a4fa0b406f194c9a2b71d9a61424b533ceefe27408b3191e3 and Provide 5 sets of my own generated rsz for #130 # 130 rsz 1 r=0x56a37728d3036203ba57a2399ba282351b55e7b7a2660080a510732f373f18f8 s=0x6bf0c1501792f3184866f56a82b69ad17cb169105ed85350ca30f3e2070e032e z=0x0042fe8868fbfa3d16b603af849bb81a35d6292651ab36a23af4c427d4265bf9 # 130 rsz 2 r=0x84812aade108ee63f12098f31e0819b36fcd4a4433fdbd29dbc8d94082e1a822 s=0xa7da5a2552d02a4551a23381fe4bcca9f1108d66cb0137712d9325d2a1fe4b4a z=0x50825e90bcae246a62602d3719d895da1108545b3c09527ed1dbf599034cf0a2 # 130 rsz 3 r=0x1567a88d2dc54158afc135433f5bd7cb673a73ecd978626504fa7a972fc88eb0 s=0x0340b27310b89895c166c839b5a27fd6de1a271a8765de608c07e96539827850 z=0x503f919c88920407436211529abf8f8d2459d8aec963181dbaf822e20f162d0e # 130 rsz 4 r=0x3facca914bf602c454b2e1332e4bd9db3482cdc648bc9f79328fed36de7babca s=0xfe9797f9323c74e8b5d91937c4ea704f0a73e3aae536d8f051e7c77214a4a5a9 z=0xdde32a1d171f66168bc88211c5bbd1f0de2bc8aa504b70af8591f7619b6a3632 # 130 rsz 5 r=0x63444d8aa42965428ea68fa74976fe38772ba59e6e1b4f8682e6f6178ee4c1e9 s=0x33f53e75c58b289d094932407c4f1eac3156a0029c9a33f257485a0c3b5b497d z=0xfe4573a2009e9f7985f8f366949757f001aaccc81da635ea3868c1d70b9a2e04 1Fo65aKq8s8iquMt6weF1rku1moWVEd5Ua Title: Re: R,S,Z , K nonce and public key Signature samples Post by: jacky19790729 on June 25, 2024, 07:00:33 PM Code: # rsz 1 sorry......I can't recovery private key for this 2 rsz my result: k1 = 0 k2 = 1 Recovered Bitcoin public key: 028629507d9eef1748ec67ca2c4ab641fa0951d7f0bb0cf226f1c0f465a4e29404 Bitcoin Address: 1Ln1NYjtCamBG2UZDTKcHqcaNLP8TUrKFe Recovered Bitcoin public key: 0395c632a7af384a67104afd5b6a4a5d882e782d232519c59084f0744d08093876 Bitcoin Address: 1P5TaCC8ZQohntb3NwRXQE5zFzB2De2Dvz show your private key .. ?? Title: Re: R,S,Z , K nonce and public key Signature samples Post by: COBRAS on June 25, 2024, 08:39:34 PM Code: # rsz 1 sorry......I can't recovery private key for this 2 rsz my result: k1 = 0 k2 = 1 Recovered Bitcoin public key: 028629507d9eef1748ec67ca2c4ab641fa0951d7f0bb0cf226f1c0f465a4e29404 Bitcoin Address: 1Ln1NYjtCamBG2UZDTKcHqcaNLP8TUrKFe Recovered Bitcoin public key: 0395c632a7af384a67104afd5b6a4a5d882e782d232519c59084f0744d08093876 Bitcoin Address: 1P5TaCC8ZQohntb3NwRXQE5zFzB2De2Dvz show your private key .. ?? You try bruteforce 02d7232c0eed9a80a6e53d74b57d80cd892816b46c69157f8e543ee76dc21f8410 ? Title: Re: R,S,Z , K nonce and public key Signature samples Post by: jacky19790729 on June 25, 2024, 09:14:59 PM Code: # rsz 1 no....bruteforce nonce k , that is impossible It's seem use 1 rsz convert to 2 rsz even know that k2 = k1 + 1 I still can't recovery private key Title: Re: R,S,Z , K nonce and public key Signature samples Post by: jacky19790729 on June 25, 2024, 09:56:31 PM Code: # rsz 1 Code: N = 0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEBAAEDCE6AF48A03BBFD25E8CD0364141 output: HA: e809a06f968e72e232e96f55e26f809d22d922681acca6904f12c4ba1b53018d r1 = 0xd7232c0eed9a80a6e53d74b57d80cd892816b46c69157f8e543ee76dc21f8410 s1 = 0xe6665792427b98ebd93cd43f694e03383c84af34b00e5f471c5cec5a24541808 z1 = 0xc3479c8d5591597a4b12018ccacd0215528e584aa18125d63fac5c0c0c92588b r2= 0xd7232c0eed9a80a6e53d74b57d80cd892816b46c69157f8e543ee76dc21f8410 s2= 0xe6665792427b98ebd93cd43f694e03383c84af34b00e5f471c5cec5a24541808 z2= 0xc3479c8d5591597a4b12018ccacd0215528e584aa18125d63fac5c0c0c92588b r1 = r2 , s1 = s2 , z1 = z2 .......Your 2 rsz are from the same rsz :'( :'( :'( Title: Re: R,S,Z , K nonce and public key Signature samples Post by: JohnnyTX on July 29, 2024, 12:22:10 PM Public Key 0x40f08294791bb07e908196847f79ad162ba0dff28eb312b1669ee2c8a72f7bfb, 0x28c29cc6ec6f2ddf9f54f32da1ea727de71c2ef168528475f5233ba28c06c4a8
Code: r1 = 0x7029db68c1420fe2d41c1fd7b86ea0739bc8e6d0a7c58f754b93e5ff6c8040 Interesting, right? Title: Re: R,S,Z , K nonce and public key Signature samples Post by: jacky19790729 on July 29, 2024, 06:04:13 PM Hi there! It looks like you all are crazy for nonces and signatures, so I have some special values for you ;) Code: r=0x678afdb0fe5548271967f1a67130b7105cd6a828e03909a67962e0ea1f61deb6 Recovered Bitcoin public key: 023e42b3151f310f5f417f11b4c32d8360b22109dcc6432339243332b56cd596de Bitcoin Address: 1ak61eAXk4bxNbovZuqh4f1PxBaf1VUBV r=0x678afdb0fe5548271967f1a67130b7105cd6a828e03909a67962e0ea1f61deb6 s=0x24c8a42e8fe11d670633fa66ebedb1672c71a517a30cbbaa9e14f2d5a15a3783 z=0xe0f6c07e19eb2dfa2e0c3586a2a9f4b225dba10c353fc354baa2dabcc9d42051 --- Recovered Bitcoin public key: 03c79fa242694e3148c8d50e667010e0c221f6004d108692c5040ff139595ed081 Bitcoin Address: 1GLKrFmj8eUsHS7s91PTMh2L6rPtF1RzNj r=0x678afdb0fe5548271967f1a67130b7105cd6a828e03909a67962e0ea1f61deb6 s=0x768a0e3b0cfb3c8d9b7899f59f480555176ef25eefa1e96d3ac575ba4ffe85fd z=0x48ef5d298a862b6f74338ebb5281f5212d8221a2fd8cce827be72779bffd25dd --- Recovered Bitcoin public key: 03c03657988e2baf31a1a1061a87fa3da20f166dc8a22c02658f6d325dec722d84 Bitcoin Address: 17aj9BWZyDTqr6UnK7LScoCHdsbFRT6LZG r=0x678afdb0fe5548271967f1a67130b7105cd6a828e03909a67962e0ea1f61deb6 s=0xd17c5ed9fb37692cd152f381c4a3f16a896f96d26100310fe818d6963c402b25 z=0x1e6a32d38fb096d19ad46186c6299f82b7bfd5a92d0d3b17142e8ff18b75e358 I can't understand special values Title: Re: R,S,Z , K nonce and public key Signature samples Post by: jacky19790729 on July 29, 2024, 06:10:21 PM Public Key 0x40f08294791bb07e908196847f79ad162ba0dff28eb312b1669ee2c8a72f7bfb, 0x28c29cc6ec6f2ddf9f54f32da1ea727de71c2ef168528475f5233ba28c06c4a8 Code: r1 = 0x7029db68c1420fe2d41c1fd7b86ea0739bc8e6d0a7c58f754b93e5ff6c8040 Interesting, right? Recovered Bitcoin public key: 0240f08294791bb07e908196847f79ad162ba0dff28eb312b1669ee2c8a72f7bfb Bitcoin Address: 1AaEnbgVCKmG7RM8KYxjiQ2xaqn4NmyA7a r1 = 0x7029db68c1420fe2d41c1fd7b86ea0739bc8e6d0a7c58f754b93e5ff6c8040 s1 = 0xdbe4b484c838fce2aa65d85901f94f6fad6ad5f604d805c30ce05c58371c6991 z1 = 0x9cabe7317b243f04a211a282035b96caa14d646dc32ba0e326f52d43cef07d8c why z2 will be Private key for Puzzle #130 ?? Title: Re: R,S,Z , K nonce and public key Signature samples Post by: JohnnyTX on July 29, 2024, 07:19:09 PM I can't understand special values Which values? All values are special ;-) First 3 signatures use Satoshi private key #1 as a nonce, but signed real messages (not random). Nobody noticed? The fourth signature signs again real message, and with the same key also a private key of Puzzle #130 as input, there is no "why", that's an intention. Code: s2 = 0x352b52b52b52b52b52b52b52b52b52b4e7c1db2bf914fdd54560dc7fb517156e Title: Re: R,S,Z , K nonce and public key Signature samples Post by: garlonicon on July 30, 2024, 12:48:24 PM Quote Code: s2 = 0x352b52b52b52b52b52b52b52b52b52b4e7c1db2bf914fdd54560dc7fb517156e Title: Re: R,S,Z , K nonce and public key Signature samples Post by: JohnnyTX on July 30, 2024, 01:16:53 PM It is just an inversion of 0x82, nothing special. Well, thanks, I was too hasty this time.Title: Re: R,S,Z , K nonce and public key Signature samples Post by: COBRAS on August 03, 2024, 12:47:23 AM Lattice for rs and pub
https://bitcointalk.org/index.php?topic=5504929.0 Title: Re: R,S,Z , K nonce and public key Signature samples Post by: JDScreesh on September 23, 2024, 07:59:24 AM Hi there.
Puzzle 130 was solved, but I don't know which script or technique was used ??? Anyway, gratz to the solver :) Title: Re: R,S,Z , K nonce and public key Signature samples Post by: Kpot87 on September 25, 2024, 12:52:40 PM Quote Code: s2 = 0x352b52b52b52b52b52b52b52b52b52b4e7c1db2bf914fdd54560dc7fb517156e thank you! Title: Re: R,S,Z , K nonce and public key Signature samples Post by: garlonicon on September 25, 2024, 01:57:24 PM Quote can you share more numbers Just use inversion, and get some ECC calculator:Code: 1/2=0x7fffffffffffffffffffffffffffffff5d576e7357a4501ddfe92f46681b20a1 Title: Re: R,S,Z , K nonce and public key Signature samples Post by: Sergey Magalyas on October 09, 2024, 06:52:04 AM I have been learning about ECDSA ( r s z, public key ,private key ) for about 2 months # 130 Although only one rsz is know , but 1000 rsz can be produced using the public key, the nonce K value will be 240~256 bits would you mind sharing your code on how you leak the RSZ and how you create more sample for the given public key. thank you Friend, give me a code that allows you to create 1000 rsz using a public key. Title: Re: R,S,Z , K nonce and public key Signature samples Post by: JohnnyTX on December 15, 2024, 08:32:00 PM Code: r2 = 0xdfb77cd83e2251dc96caad4c45cf98fcf76b8c24aa349c2dbba548029571331f Code: z2 = 0x33e7665705359f04f28b88cf897c603c9 Code: r = 0xdb30127de06f6c9d04e4ebc9cdefb93433a37be972db697b21c22724f6cf69d2 Title: Re: R,S,Z , K nonce and public key Signature samples Post by: COBRAS on December 15, 2024, 09:21:13 PM Code: r2 = 0xdfb77cd83e2251dc96caad4c45cf98fcf76b8c24aa349c2dbba548029571331f Code: z2 = 0x33e7665705359f04f28b88cf897c603c9 Code: r = 0xdb30127de06f6c9d04e4ebc9cdefb93433a37be972db697b21c22724f6cf69d2 Hi, can you multiply or add r to number and edit s,z after , so what signatures will be valid ? Title: Re: R,S,Z , K nonce and public key Signature samples Post by: abdullahsoliman on December 15, 2024, 10:49:37 PM Code: r2 = 0xdfb77cd83e2251dc96caad4c45cf98fcf76b8c24aa349c2dbba548029571331f Code: z2 = 0x33e7665705359f04f28b88cf897c603c9 Code: r = 0xdb30127de06f6c9d04e4ebc9cdefb93433a37be972db697b21c22724f6cf69d2 Hi, can you multiply or add r to number and edit s,z after , so what signatures will be valid ? the question is how RetiredCoder makes this valuable and connected "r1_1 = 02de97092bfb7c02148a827b4f8b62db1e189a739c77815799df5e6fb35ae88a1f r2_1 = 02838db77b981db321faf527a830461cfda01aed50d85c345a7b0a8f4e5e4fd3fc delta = 031e283a9ebc4c50b0a93f27d411e69d0a97aad2a6d4ae26f5725f8b55fb5176f5 delta _k = 0xfffffffffffffffffffffffffffffffebaaedce6af487e246f4eac90b714b3bd N- delta _k = 0x22175083b1fc19218d84 r1_2= 03de97092bfb7c02148a827b4f8b62db1e189a739c77815799df5e6fb35ae88a1f r2_2= 03838db77b981db321faf527a830461cfda01aed50d85c345a7b0a8f4e5e4fd3fc delta = 021e283a9ebc4c50b0a93f27d411e69d0a97aad2a6d4ae26f5725f8b55fb5176f5 delta _k = 0x22175083b1fc19218d84 PK = 33e7665705359f04f28b88cf897c603c9" I wasted maybe 48 hours coding :D, Then, one out of the community claimed the puzzle and didn`t show up. ;D where are you? ::) Title: Re: R,S,Z , K nonce and public key Signature samples Post by: Lolo54 on December 16, 2024, 01:15:01 AM Intriguing all the same, this RetiredCoder his way of writing, of composing his posts and some facts intrigue me (1 example post de JohnnyTX 29/07/24) I'm probably wrong but satoshi_rider= RetiredCoder=satoshi why not 🤔?! I don't understand the meaning of some of his messages including the one in the signature of #130 involving a famous quote from Jules Verne?? nor why this one….nor even how it was a clue if not a message or rather an implied clue free to everyone to appreciate its significance. Why is it he who gives the explanation then the privkey on how to achieve it and not the solver…. strange brief
Title: Re: R,S,Z , K nonce and public key Signature samples Post by: lavina888 on February 04, 2025, 02:37:31 PM Hi there! It looks like you all are crazy for nonces and signatures, so I have some special values for you ;) Code: r=0x678afdb0fe5548271967f1a67130b7105cd6a828e03909a67962e0ea1f61deb6 nonce found, but in theory knowing this value - it is possible to restore the private key from each address: x = (s*k-m)/r, but this is not true at all. for all three signatures it is impossible to restore the correct keys to the addresses. Title: Re: R,S,Z , K nonce and public key Signature samples Post by: COBRAS on February 05, 2025, 01:59:23 AM Hi there! It looks like you all are crazy for nonces and signatures, so I have some special values for you ;) Code: r=0x678afdb0fe5548271967f1a67130b7105cd6a828e03909a67962e0ea1f61deb6 nonce found, but in theory knowing this value - it is possible to restore the private key from each address: x = (s*k-m)/r, but this is not true at all. for all three signatures it is impossible to restore the correct keys to the addresses. publick keys different, because it not posible find privkey for adress. Title: Re: R,S,Z , K nonce and public key Signature samples Post by: coolmib on June 28, 2025, 09:29:00 AM sorry......I can't recovery private key for this 2 rsz my result: k1 = 0 k2 = 1 Recovered Bitcoin public key: 028629507d9eef1748ec67ca2c4ab641fa0951d7f0bb0cf226f1c0f465a4e29404 Bitcoin Address: 1Ln1NYjtCamBG2UZDTKcHqcaNLP8TUrKFe Recovered Bitcoin public key: 0395c632a7af384a67104afd5b6a4a5d882e782d232519c59084f0744d08093876 Bitcoin Address: 1P5TaCC8ZQohntb3NwRXQE5zFzB2De2Dvz show your private key .. ?? both msg sign from the same pubkey : ( 0x8629507d9eef1748ec67ca2c4ab641fa0951d7f0bb0cf226f1c0f465a4e29404 , 0x2237204a53021490adfec9f0b3f0732f5024181d50fde2dcfc7a428c992b8d70 ) r2 = r1 + G Signatures are valid ✅ Nonces follow k2 = k1 + 1 ✅ Public key is valid and known ✅ Algebraic recovery fails due to zero denominator ❌ Lattice attack returns zero polynomial or errors ❌ Interesting.. ;) nonce found, but in theory knowing this value - it is possible to restore the private key from each address: x = (s*k-m)/r, but this is not true at all. for all three signatures it is impossible to restore the correct keys to the addresses. If the nonce is found, it means you already have access to the genesis wallet, why bother with recovering another private key ;)Title: Re: R,S,Z , K nonce and public key Signature samples Post by: nlitsme on June 30, 2025, 10:53:38 AM the signatures posted by JonnyTX ( https://bitcointalk.org/index.php?topic=5500713.msg64254396#msg64254396 ) have the interesting property that r/s = (0xdeadbeef << 224) + i
you can easily generate more such signatures by calculating: s = r / (c+i) z = a random 256 bit number Pubkey = (R*s-G*z)/r where c = the above (0xdeadbeef << 224) constant, and r = genesis-pubkey.x and R = genesis-pubkey. then the signatures posted by jacky19790729 ( https://bitcointalk.org/index.php?topic=5500713.msg64255481#msg64255481 ) have the property that both r/s and z/r are less than sqrt(n), where n is the curve grouporder. you can generate more such signatures like this: a = a random 128 bit number b = another random 128 bit number R = (G*b+Pubkey)*a r = R.xcoord s = r/a z = r*b in the above: lowercase letters indicate scalars in GF[n], uppercase letters indicate points on secp256k1 Title: Re: R,S,Z , K nonce and public key Signature samples Post by: JimsR on July 01, 2025, 05:20:09 PM Code: r2 = 0xdfb77cd83e2251dc96caad4c45cf98fcf76b8c24aa349c2dbba548029571331f Code: z2 = 0x33e7665705359f04f28b88cf897c603c9 Code: r = 0xdb30127de06f6c9d04e4ebc9cdefb93433a37be972db697b21c22724f6cf69d2 Hi Many thanks for your insight, can you show please how to find R for every puzzle with known public key?? or there is any clue?? Title: Re: R,S,Z , K nonce and public key Signature samples Post by: ActiveC on August 16, 2025, 12:26:18 AM Hi there! It looks like you all are crazy for nonces and signatures, so I have some special values for you ;) Code: r=0x678afdb0fe5548271967f1a67130b7105cd6a828e03909a67962e0ea1f61deb6 You are right JohnnyTX, almost anybody can do this :) Code:
Opinions are welcome! Title: Re: R,S,Z , K nonce and public key Signature samples Post by: AtemAudit on September 07, 2025, 06:00:04 PM Hi there! It looks like you all are crazy for nonces and signatures, so I have some special values for you ;) Code: r=0x678afdb0fe5548271967f1a67130b7105cd6a828e03909a67962e0ea1f61deb6 You are right JohnnyTX, almost anybody can do this :) Code:
Opinions are welcome! I tried to ask how it was done but to no avail, the only opinion that I but also others have, some have already written it, is that you, JhonnyTX and saatoshi_rising are either the same person or anyway you are all connected to the puzzle, it is also curious that you are ActiveC and in the forum there is a solver of no less than 3 puzzles, called RetiredCoder or even RetiredC for friends ;). So my opinion is that it is impossible, at least without further help, you can tell that they are constructed ad hoc, with some special method but to know the private key of the puzzle 130 and 135 you have to already have the private keys and be sure they are right, so either you solved it or anyway you already knew them, so you already have those keys in hand. If you would like to explain to me in private how to solve for the z of 135 that would be interesting :(. Title: Re: R,S,Z , K nonce and public key Signature samples Post by: krashfire on September 08, 2025, 04:33:17 AM Hi there! It looks like you all are crazy for nonces and signatures, so I have some special values for you ;) Code: r=0x678afdb0fe5548271967f1a67130b7105cd6a828e03909a67962e0ea1f61deb6 You are right JohnnyTX, almost anybody can do this :) Code:
Opinions are welcome! I tried to ask how it was done but to no avail, the only opinion that I but also others have, some have already written it, is that you, JhonnyTX and saatoshi_rising are either the same person or anyway you are all connected to the puzzle, it is also curious that you are ActiveC and in the forum there is a solver of no less than 3 puzzles, called RetiredCoder or even RetiredC for friends ;). So my opinion is that it is impossible, at least without further help, you can tell that they are constructed ad hoc, with some special method but to know the private key of the puzzle 130 and 135 you have to already have the private keys and be sure they are right, so either you solved it or anyway you already knew them, so you already have those keys in hand. If you would like to explain to me in private how to solve for the z of 135 that would be interesting :(. Here, you can see how Z Signature is calculated. https://github.com/KrashKrash/public-key-signature-generator Title: Re: R,S,Z , K nonce and public key Signature samples Post by: AtemAudit on September 08, 2025, 08:40:30 AM Hi there! It looks like you all are crazy for nonces and signatures, so I have some special values for you ;) Code: r=0x678afdb0fe5548271967f1a67130b7105cd6a828e03909a67962e0ea1f61deb6 You are right JohnnyTX, almost anybody can do this :) Code:
Opinions are welcome! I tried to ask how it was done but to no avail, the only opinion that I but also others have, some have already written it, is that you, JhonnyTX and saatoshi_rising are either the same person or anyway you are all connected to the puzzle, it is also curious that you are ActiveC and in the forum there is a solver of no less than 3 puzzles, called RetiredCoder or even RetiredC for friends ;). So my opinion is that it is impossible, at least without further help, you can tell that they are constructed ad hoc, with some special method but to know the private key of the puzzle 130 and 135 you have to already have the private keys and be sure they are right, so either you solved it or anyway you already knew them, so you already have those keys in hand. If you would like to explain to me in private how to solve for the z of 135 that would be interesting :(. Here, you can see how Z Signature is calculated. https://github.com/KrashKrash/public-key-signature-generator Yes, you're right, but in the case of JhonnyTX, the Z value is not random. He doesn't sign a wallet generically because, in his case, at least for 130 and 135, he uses z and "assigns" it the value of the private key corresponding to puzzles 130 and 135. This means that he already knows the private keys for those puzzles or, most likely, for the entire puzzle. |