Bitcoin Forum
August 21, 2026, 08:53:04 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685 686 687 688 [689] 690 »
  Print  
Author Topic: Bitcoin puzzle transaction ~32 BTC prize to who solves it  (Read 405715 times)
PHA_.07
Newbie
*
Offline

Activity: 20
Merit: 0


View Profile
August 19, 2026, 05:58:48 PM
 #13761

I don't use methods, from the cycada, I don't need to prove anything. I have internal standards higher than Cicada
--- PART 1 / 4 ---
⠀⠀⠁⣂⠀⠀⠀⡱⢍⡁⠯⣍⢌⢖⣾⠮⢜⢕⣝⣗⠙⠣⠞⢆⣎⣩⡳⢌⢐⠻⢱⠦⡪⣓⣲⣽⠲⠭⣡⠌⡮⡽⣬⠉⣃⢭⣘⢗⡳⣆⠊⡡⢂⣾⢵⡹⣠⠾⡄⢾⢋⢓⠅⣴
⠐⢕⠞⠏⡲⡥⡛⣭⡏⡰⡈⠳⣿⣮⣝⡶⠈⢷⢇⣨⠗⠴⡴⡦⡹⡘⠝⣔⠺⢓⡃⢮⠘⡾⡕⢌⡴⡨⡿⡌⢁⢽⡃⡄⠪⣢⣿⡃⠨⢱⡅⡛⢉⢀⡑⢃⢲⢬⠂⡘⣭⢽⢠⡋
⡔⣑⣸⢻⠣⡱⡻⢋⢾⢁⡁⣶⠶⠧⣼⢽⢘⢐⡟⣛⣖⢐⣎⣮⠣⠅⢻⢀⡞⠲⡒⡔⣰⠁⡤⣸⡏⣷⠆⠜⡣⣼⣴⢓⢏⠭⡮⢳⣚⡺⡶⢨⣦⡽⢏⢊⠃⢖⢇⢼⣝⣮⡔⣶
⣚⢯⢶⡁⢹⠁⢋⠿
--- PART 2 / 4 ---
⢅⡘⣕⡧⣖⠷⡎⠌⠗⡒⠏⣧⣅⣸⡁⠨⡘⡅⡙⢟⠮⣿⡑⣘⡵⠽⢋⠃⡺⠿⠠⣊⢃⣡⢉⡹⢴⢔⢄⡰⢢⠱⡻⣦⠥⣬⠅⠜⠇⣹⢄⡜⣨⠶⠙⡗⠱⠰⡥⡇⢶⣟⣇⡧
⣶⣔⠎⠛⣳⡡⡊⣅⢖⢾⠶⢚⢀⡁⣄⡙⡞⡻⢧⡤⢌⢶⡰⡡⠂⣶⢈⢯⠘⣽⢯⢺⡤⡝⡖⣑⢐⣶⡋⡗⣀⣤⢎⢵⢋⠣⠂⡴⠞⠶⡃⡪⣧⠧⣝⡆⠠⣲⡖⠿⠓⣸⣱⣟
⢧⡢⢘⢦⡊⡇⣈⢀⠻⠞⢿⣼⢅⣋⢆⢄⣟⡃⡌⣲⠏⢬⣴⠦⠮⢗⡝⣎⡈⢽⡟⣷⢋⠨⡾⣗⣴⡩⠵⡵⠶⣰⡜⣲⡥⢌⢈⢵⢣⠗⠌⡈⡸⠭⡉⡏⢌⣐⠣⠼⠢⢉⡍⠩
⣣⢟⡦⠮⠰⡧⠃⣚
--- PART 3 / 4 ---
⡍⠄⠀⠒⡃⡿⢆⢥⣷⠥⡶⡴⣜⠏⣫⢵⣬⣴⣴⡳⡪⣩⣧⣾⢴⢸⠯⠎⡗⠏⣿⣢⢚⣻⣞⡻⢠⢦⠽⣨⣸⣩⢲⠭⢺⢻⢐⡮⢎⢺⢋⣷⢯⠕⠺⡋⢎⡚⠀⠀⠼⡐⣒⡲
⢚⠦⠸⢾⡚⡪⡤⢻⠱⠬⠩⢽⢀⡙⠂⠏⠪⠨⢩⠅⣼⠨⡃⠊⢩⠑⠲⢳⠒⡦⣴⢤⠅⠦⡆⢪⡩⢿⠒⡞⢫⣙⢧⣉⡄⢶⠯⢙⠂⣌⣻⣓⡌⢎⠡⢥⢺⢚⢐⢶⡟⢮⠞⣔
⠥⣲⡇⣱⣖⢍⣩⠑⡐⡺⢒⠄⣓⣝⡫⢺⣵⣥⢉⠑⡴⢓⡉⣹⢒⡰⣾⣣⠣⡨⢅⣨⠈⢓⡨⡩⠅⢨⡫⣯⡠⠑⡻⡬⢿⣜⢭⣚⣏⣦⡽⢪⢰⠽⢷⠼⣀⠢⣬⠇⠠⢇⣱⢟
⠄⡽⠜⠱⡭⡵⡧⠀
--- PART 4 / 4 ---
⠴⣑⠠⡣⢔⢗⡙⠓⣬⣶⡊⡌⣫⠖⡁⣀⢼⢩⢰⡣⣁⠁⠟⡰⢗⢌⣭⣊⠗⠼⡏⡋⠇⢫⢅⠆⣼⢦⡿⢍⠪⡬⡎⠮⣲⢰⡲⣐⠙⠀⣚⢍⣁⢇⣗⡚⡞⡔⠾⢙⣱⡱⢼⣩
⢿⡇⡽⣿⡕⣜⢦⢷⠫⣪⢉⢼⢲⣃⣹⣣⠔⣑⡪⢤⣻⢮
If you are so good at cryptography that you use only the prop method. Rough then this is your problem buy 1000k GPU and do a brute-force password, on v71

Why solve your puzzle with no reward when the btc puzzles hold Bitcoin? If you have the solution, take the puzzles?

Also I found these pubkeys, were they known before?

p150: 03137807790ea7dc6e97901c2bc87411f45ed74a5629315c4e4b03a0a102250c49

p155: 035cd1854cae45391ca4ec428cc7e6c7d9984424b954209a8eea197b9e364c05f6

p160: 02e0a8b039282faf6fe0fd769cfbc4b6b4cf8758ba68220eac420e32b91ddfa673

Thats what i was getting at, cicada 3301 just wants others to waste there time for his nonsense while he tries to solve the 71 ect.  no body cares about your passphrase for your braille nonsense, this forum is about Bitcoin puzzle transaction not your little privates issues.

Why did you decide that people’s tasks can’t be completed in the background while they themselves are busy with other things?

I guess this person is trying to say he can do both, then cicada 3301  and eggsylacer can go make there own braille thread then!  No reason was given as to why this relates to, Bitcoin puzzle transaction ~32 BTC prize to who solves it , and doesn’t belong here.
Virtuose
Jr. Member
*
Offline

Activity: 67
Merit: 1


View Profile
August 19, 2026, 06:04:57 PM
 #13762

the task is solved, the formulas are ready, the pre-check is ready, I take 903k BTC. You looked in the wrong place, but I will say thank you very much for opening 1-70, 65-135. I will finish off and slowly, open all wallets. I think in a week, but it's just a lot of additional projects. Thank you all very much, and no, I won't publish. formulas. In institutes, such mathematics is not taught.

Lol, we’ve got a real clown here. In a month, three months, even six months, we’ll still see the funds sitting on all the remaining addresses.

I’ve seen tons of guys like you come through here acting all cocky. In the end, they just make complete fools of themselves and delete their alt accounts so they don’t have to show their real face, just another guy desperate for attention and validation. :p (Activity: 3  Cheesy)
cicada 3301
Newbie
*
Offline

Activity: 8
Merit: 0


View Profile
August 19, 2026, 06:40:24 PM
 #13763

Haha, I love annoying people. Yeah, I’ve figured everything out — the formulas are fully ready, I’ve gathered everything, all that’s left is to pick it up, but I’m too lazy. An explanation for idiots — here it is… wallets. And how you’ll think about it is your problem. The second given problem is the translation from cosmology. Formally, you need an intellect like cicada 3301, or like mine. Essentially, it’s an addition to OTO. That’s why I say you’re idiots obsessed with money. You're dumb as a rock.
Virtuose
Jr. Member
*
Offline

Activity: 67
Merit: 1


View Profile
August 19, 2026, 06:52:48 PM
 #13764

Haha, I love annoying people. Yeah, I’ve figured everything out — the formulas are fully ready, I’ve gathered everything, all that’s left is to pick it up, but I’m too lazy. An explanation for idiots — here it is… wallets. And how you’ll think about it is your problem. The second given problem is the translation from cosmology. Formally, you need an intellect like cicada 3301, or like mine. Essentially, it’s an addition to OTO. That’s why I say you’re idiots obsessed with money. You're dumb as a rock.

Lmao, cosmology, Cicada 3301, OTO… you’re throwing random mysterious-sounding words around because apparently saying wallets was supposed to prove you solved secp256k1. 😂

You know… actual elliptic-curve cryptanalysis. Not cosmology > wallets > Cicada 3301 > trust me bro.

That’s always the funny part with self-proclaimed geniuses: somehow they’ve defeated a 256-bit elliptic-curve problem in their head, but explaining one concrete technical detail is where the magic suddenly stops working.  Tongue

Here’s an actual fact for you: people who make genuine breakthroughs usually don’t need to announce that they’re geniuses beforehand. Recognition tends to come after the work proves itself, not before.

GL

cicada 3301
Newbie
*
Offline

Activity: 8
Merit: 0


View Profile
August 19, 2026, 06:53:49 PM
 #13765

My nickname within the group is “Architect.”
Virtuose
Jr. Member
*
Offline

Activity: 67
Merit: 1


View Profile
August 19, 2026, 06:55:51 PM
 #13766

My nickname within the group is “Architect.”

Perfect. Now all that’s missing is an actual building. So far we’ve only seen the blueprint for an ego. 😂
PHA_.07
Newbie
*
Offline

Activity: 20
Merit: 0


View Profile
August 19, 2026, 07:35:43 PM
 #13767

Haha, I love annoying people. Yeah, I’ve figured everything out — the formulas are fully ready, I’ve gathered everything, all that’s left is to pick it up, but I’m too lazy. An explanation for idiots — here it is… wallets. And how you’ll think about it is your problem. The second given problem is the translation from cosmology. Formally, you need an intellect like cicada 3301, or like mine. Essentially, it’s an addition to OTO. That’s why I say you’re idiots obsessed with money. You're dumb as a rock.

His formulas are ready to go, estimation time for first puzzle 1354 years!
analyticnomad
Newbie
*
Online Online

Activity: 108
Merit: 0


View Profile
August 19, 2026, 08:15:13 PM
 #13768

Haha, I love annoying people. Yeah, I’ve figured everything out — the formulas are fully ready, I’ve gathered everything, all that’s left is to pick it up, but I’m too lazy. An explanation for idiots — here it is… wallets. And how you’ll think about it is your problem. The second given problem is the translation from cosmology. Formally, you need an intellect like cicada 3301, or like mine. Essentially, it’s an addition to OTO. That’s why I say you’re idiots obsessed with money. You're dumb as a rock.

Hey guys, he took the time and energy to "solve" it but is just too damn lazy to move the funds. Give him a break! Solving secp256k1 is exhausting!
Virtuose
Jr. Member
*
Offline

Activity: 67
Merit: 1


View Profile
August 19, 2026, 11:08:20 PM
 #13769

A Critical Analysis of the Green-Tao Theorem (2004): Fundamental Mathematical Flaws and Their Role in the AI Veracity Crisis

Author: cicada 3301 architect

Date: August 2026

Abstract
Bla bla bla

It took you 3 hours to get AI to spit this out? 😭

You didn’t debunk Green-Tao. You just glued together fake-sounding math jargon, LLM hallucinations, crypto hacks and stock crashes and called it a paper.

Peak AI slop pretending to be mathematics. 😂
cicada 3301
Newbie
*
Offline

Activity: 8
Merit: 0


View Profile
August 19, 2026, 11:09:15 PM
 #13770

And now, guess what I’m going to do with 903k BTC — I’ll answer right away: I’m going to dump them on the market. I want to destroy the global economy. The reason for this is the total deception, in everything. We’ve known about this for a long time. The time has come.
Virtuose
Jr. Member
*
Offline

Activity: 67
Merit: 1


View Profile
August 19, 2026, 11:11:56 PM
 #13771

And now, guess what I’m going to do with 903k BTC — I’ll answer right away: I’m going to dump them on the market. I want to destroy the global economy. The reason for this is the total deception, in everything. We’ve known about this for a long time. The time has come.

From "I debunked Green–Tao" to "I own 903k BTC and I’m going to destroy the global economy." 😭

At this point, forget the AI prompts, maybe genuinely consider getting some help. This isn’t sounding intimidating, just deeply embarrassing.  Lips sealed
fairmuffin
Newbie
*
Offline

Activity: 32
Merit: 0


View Profile
August 19, 2026, 11:20:33 PM
 #13772

I am laughing at how the thread became, a lot of trolling and it ressembles a d*** measuring contest. Is anyone ever going to bring forth some serious theories instead of posting that they found something without ever telling what it was? It's giving too much cold war vibes (ya know, when everyone used to "fake" and indirectly threaten the enemy by pretending to be on the moon or whatever lol).

So far, I liked zahid888's theory, detailed and with some examples. I would have loved to see everyone contribute their findings, rather than just come here posting stressing us all out that a weirdo may unlock all those keys (plz donate if you do Grin )
Virtuose
Jr. Member
*
Offline

Activity: 67
Merit: 1


View Profile
August 19, 2026, 11:33:15 PM
 #13773

I am laughing at how the thread became, a lot of trolling and it ressembles a d*** measuring contest. Is anyone ever going to bring forth some serious theories instead of posting that they found something without ever telling what it was? It's giving too much cold war vibes (ya know, when everyone used to "fake" and indirectly threaten the enemy by pretending to be on the moon or whatever lol).

So far, I liked zahid888's theory, detailed and with some examples. I would have loved to see everyone contribute their findings, rather than just come here posting stressing us all out that a weirdo may unlock all those keys (plz donate if you do Grin )

Fair point. I’d also rather see actual theories, evidence and reasoning than endless "I found it" posts.

But sometimes things need to be put back in their place too. I don’t like disorder, especially when nonsense starts taking over the thread.
analyticnomad
Newbie
*
Online Online

Activity: 108
Merit: 0


View Profile
August 19, 2026, 11:40:07 PM
 #13774

And now, guess what I’m going to do with 903k BTC — I’ll answer right away: I’m going to dump them on the market. I want to destroy the global economy. The reason for this is the total deception, in everything. We’ve known about this for a long time. The time has come.

It's not even 903K bitcoin. You do know what "k" means, right? Of course you do. You broke entropy.
detechs
Newbie
*
Online Online

Activity: 42
Merit: 0


View Profile WWW
August 20, 2026, 01:46:43 AM
 #13775

I am laughing at how the thread became, a lot of trolling and it ressembles a d*** measuring contest. Is anyone ever going to bring forth some serious theories instead of posting that they found something without ever telling what it was? It's giving too much cold war vibes (ya know, when everyone used to "fake" and indirectly threaten the enemy by pretending to be on the moon or whatever lol).

So far, I liked zahid888's theory, detailed and with some examples. I would have loved to see everyone contribute their findings, rather than just come here posting stressing us all out that a weirdo may unlock all those keys (plz donate if you do Grin )

secp256k1. an analysis anyone can check

every claim was proven from raw chain data or from the curve arithmetic itself, or is in the one clearly labelled section of published theorems.


1. the curve

bitcoin signs with

y^2 = x^3 + 7 mod p

p = 2^256 - 2^32 - 977

the group order n is prime:

n = 0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEBAAEDCE6AF48A03BBFD25E8CD0364141

the generator:

Gx = 0x79BE667EF9DCBBAC55A06295CE870B07029BFCDB2DCE28D959F2815B16F81798
Gy = 0x483ADA7726A3C4655DA4FBFC0E1108A8FD17B448A68554199C47D08FFB10D4B8


2. the structure checks

every check here is mechanical. the constants are given in full so anyone can run them.

2.1 G lies on the curve. substitute Gx and Gy into y^2 = x^3 + 7 mod p. holds.

2.2 the 2G control. 2G is widely published:

2Gx = 0xC6047F9441ED7D6D3045406E95C07CD85C778E4B8CEF3CA7ABAC09B95C709EE5
2Gy = 0x1AE168FEA63DC339A3C58419466CEAEEF7F632653266D0E1236431A950CFE52A

recomputing 2G from G with any correct group law implementation must land on exactly this point. this is the control that catches broken code.

2.3 the order. n times G is the point at infinity, and n passes 24 rounds of miller rabin. n is prime and G is not the identity, so the order of G is exactly n.

2.4 the full group order. hase's bound says the trace t = p + 1 - #E satisfies |t| <= 2 sqrt(p). here t = p + 1 - n = 432420386565659656852420866390673177327, inside the bound. n lies in the hase interval and 2n does not, so the only multiple of n in the interval is n itself. the number of points on the curve is exactly n, and the cofactor h = 1. this follows from 2.3 alone, it is not a quoted fact. an extra confirmation: n times each of five random points is the point at infinity, which is exactly what a full group of order n predicts.

2.5 the group law. associativity and inverse spot checks hold on random scalars.

2.6 the endomorphism. secp256k1 has j = 0, so it carries the extra structure most curves do not have. two constants:

lambda = 0x5363AD4CC05C30E0A5261C028812645A122E22EA20816678DF02967C1B23BD72
beta   = 0x7AE96A2B657C07106E64479EAC3434E99CF0497512F58995C1396C28719501EE

lambda^2 + lambda + 1 = 0 mod n. beta^2 + beta + 1 = 0 mod p. lambda times G equals (beta Gx, Gy), and the same holds on random points. this is the glv split that fast implementations use.

beta is derivable, not memorized. p = 3 mod 4, so sqrt(-3) mod p = (-3)^((p+1)/4), and the cube roots of unity are (-1 +/- sqrt(-3))/2. both roots pass the identity check, the generator check picks the right one. anyone can recompute beta from scratch this way and get the value above. two further confirmations: beta cubed is 1 mod p and beta is not 1 itself, so beta is a genuine cube root of unity. and the identity lambda times P equals (beta x, y) holds on a random point, not only on the generator.

2.7 the twist. the quadratic twist has order 2p + 2 - n, which factors as

3^2 * 13^2 * 3319 * 22639 * R

where R passes 12 rounds of miller rabin. the cofactor is 114286177161 and the rest is a giant probable prime. attacks that need small twist cofactors are dead. the twist order was computed two independent ways, 2p + 2 - n and p + 1 + t, and the two agree.

2.8 the embedding degree. the mov and frey ruck attacks need n to divide p^k - 1 for small k. such a k must divide n - 1. here

n - 1 = 2^6 * 3 * 149 * 631 * C

where C = 6414488540731361226607730496888035255996436684289152125202372832747357 is composite with no prime factor below 10^6. the union of every k from 1 to 200 and every divisor of n - 1 built from the small factors, 241 values in total, was tested. none satisfies p^k = 1 mod n. any valid k is therefore at least 10^6. a pairing into a field of extension degree a million is not an attack. this is a proven bound, not the exact embedding degree.

2.9 the costs. pollard rho costs sqrt(pi n / 2) = about 2^128.3 group operations. baby step giant step needs 2^128 memory. pollard kangaroo is expected to cost about 2 sqrt(W) for a range of width W.


3. attacks that do not apply

the ones proven dead by the checks above:

smart's anomalous curve attack. needs the group order to equal p. section 2.4 proved the order is n, not p.

mov and frey ruck. need a small embedding degree. the bound in 2.8 closes them.

invalid curve and twist attacks. the curve has cofactor 1 and the twist's cofactor is the giant prime product in 2.7. points that do not satisfy y^2 = x^3 + 7 must be rejected before any scalar multiplication, and then nothing is left for these attacks.

the ones listed for completeness, published theorems with published proofs, not re-derived here:

index calculus. no subexponential algorithm exists for generic elliptic curves over prime fields.

weil descent and the ghs family. these need composite extension fields. this curve is over a prime field.


4. the attacks that work. implementation attacks on ecdsa

an ecdsa signature is (r, s) with

s = k^-1 (z + r d) mod n

where z is the message hash, d the private key, k the nonce. the curve itself is sound. every practical break is an implementation break.


nonce reuse. pure algebra

two signatures with the same k:

k = (z1 - z2) (s1 - s2)^-1 mod n
d = r^-1 (s k - z) mod n

both lines follow directly from the signature equation by subtraction. any wallet that ever repeated a nonce was drained. as a check of the algebra itself: a signature was built from the equation with a known key and nonce, and the two recovery lines returned the exact key and the exact nonce. the equations work in both directions.


biased nonces. found on chain, re-verified from raw data

two deterministic nonce formulas were found in real bitcoin signatures:

formula A:  k = (z >> 128) << 128
formula B:  k = n - ((z >> 128) << 128)

the nonce is the message hash with its bottom 128 bits zeroed, or n minus that. one family, two signs.

the odds. a random nonce having its bottom 128 bits all zero is 2^-128 per signature. seeing the pattern at all is not chance.

the proof, self-contained. for each of the four signatures below: take the raw transaction from the chain, compute the sighash z, recover r and s, assume the formula k, compute

d = r^-1 (s k - z) mod n

and derive the public key from d. the public key must equal the public key pushed in the signature. no key list involved. all four pass:

tx f4cac758926977b6d4970c5f59d1f59589ae6400c6a2318fef1c476bf32c5089  (2016-04-09)  formula A  recovered d = 7
tx bd4051685a68576e09a652980e3cd076443bff10bee52d46dc08227f8df49185  (2017-09-30)  formula B  recovered d = 21
tx 4fd371b373c8f27a96d88c846d81d3b6d98adb4b964ae0b719a0d3a2d792a6b3  (2017-10-31)  formula A  recovered d = 8
tx 4b553150b8c8789cb68059f3dab3862987e9982a0b24472450d641aff5aea3c1  (2017-11-15)  formula B  recovered d = 7

7, 21 and 8 are the published private keys of puzzle 3, puzzle 5 and puzzle 4. the signatures that spend those addresses were made with nonces generated by the two formulas. the key record was cross checked against two independent sources, the puzzle listing and the solved keys table, and all three agree. and in each of the four transactions the spent output's script commits to the same public key that the signature pushes, so the signature, the script, and the recovered key all point the same way.

the control that the method is sound. each of the four signatures also verifies normally against its pushed public key. a wrong sighash computation would fail verification, so the z values are proven correct before any formula is tried.

one full example. the first signature:

z = 0x9190c9b03e94af91480227eeb9c7378a1ade4d86d0e2bea19502c19bb014ddb1
k = 0x9190c9b03e94af91480227eeb9c7378a00000000000000000000000000000000

the top half of k is the top half of z, byte for byte, and the bottom 128 bits are zero. formula B's signature has k's bottom 128 bits equal to n's bottom 128 bits, 0xbaaedce6af48a03bbfd25e8cd0364141, byte for byte.

the honest limits. why the tool was built this way is unknown. no attribution is made and none should be inferred from the arithmetic. this report claims exactly these four signatures and nothing beyond them.


the standing requirement

proper implementations derive k deterministically from the key and the message, rfc6979, or from a good random source. every one of the breaks above came from a wallet that did neither.


5. measured kangaroo behaviour

a fresh pollard kangaroo was written and run on this machine on 2026-08-20, standard python, one core. jump table of 102 hash derived values, mean sqrt(W)/2, distinguished points are x coordinates with the low 8 bits zero, tame starts at the upper bound, wild at the public key. five known keys:

p24: 4216 steps, K = 0.73
p28: 11090 steps, K = 0.48
p32: 72312 steps, K = 0.78
p36: 706589 steps, K = 1.91
p40: 280775 steps, K = 0.19

K = steps / (2 sqrt(W)), the standard normalization. K wobbles 0.19 to 1.91 run to run. single run noise, not signal. the walk is fully deterministic, and rerunning it reproduces the exact step counts above.

the measured rate. 7200 point additions per second, one core, pure python, on the machine this was run on. faster machines change the constant, not the exponent.

the wall, stated with the measured numbers. puzzle 140's range is [2^139, 2^140). kangaroo cost is about 2 sqrt(2^139) = 2^70.5 point additions = about 1.67e21 additions. at this machine's 7200 additions per second that is 2.3e17 seconds, about 7.4e9 years on one core. p140 is a fleet problem or a structure problem. it is not a one machine problem.


what this means for the puzzles

puzzle 71. an address commits ripemd160(sha256(pubkey)). reversing that is a 160 bit preimage problem, and elliptic curve cryptanalysis does not reach it. the key comes from a spend or from the key itself.

puzzle 140. the public key is on chain from a 2019 spend. confirmation: input 15 of that transaction pushes a public key, and the ripemd160 hash of that public key is exactly the published puzzle 140 target address. the attack is the kangaroo, and the wall is 2^70.5 point additions, measured above.

the curve checks in section 2 confirm the curve is exactly what its security assumes. the breaks in section 4 are wallet breaks.


how to check this yourself

one. take the constants from section 1 and a correct group law implementation. check G on curve, 2G, nG = infinity.

two. verify the hase argument: t = p + 1 - n is inside 2 sqrt(p), and n is the only multiple of itself in the hase interval.

three. derive beta as in 2.6 and check both identities and the generator relation.

four. trial divide 2p + 2 - n by small primes and miller rabin the remainder.

five. build the divisor set of n - 1 from 2, 3, 149, 631 and check p^k mod n for each.

six. for the nonce finding, fetch the four transactions, compute z from the sighash, verify each signature against its pushed public key, then assume each formula k and derive d = r^-1 (s k - z) mod n. the derived public keys match the pushed public keys. the recovered keys are 7, 21, 8, 7.
PHA_.07
Newbie
*
Offline

Activity: 20
Merit: 0


View Profile
August 20, 2026, 02:43:49 AM
 #13776

And now, guess what I’m going to do with 903k BTC — I’ll answer right away: I’m going to dump them on the market. I want to destroy the global economy. The reason for this is the total deception, in everything. We’ve known about this for a long time. The time has come.

Hey little kid cicada 3301,

903 bitcoin will do nothing
Strategy Inc. Mid-January 2026: Acquired roughly 22,305 BTC, Mid-April 2026: Purchased  34,164 BTC  ect ect ect.
When he finishes getting strc back up he will continue to buy 10+ times of what the BTC for the  puzzle could account for if all were solved even.
satashi_nokamato
Jr. Member
*
Offline

Activity: 70
Merit: 6

Originality of BTC is something else


View Profile
August 20, 2026, 03:46:16 AM
 #13777

Hello, please let this thread be for discussing and exchanging ideas.
Has anyone here ever tried to make use of other algos? Just for a starter like CSA (crow  search algo), HS (harmony search)? Imagine you could turn Generator point into music notes, then all other points as well, you would be able to determine whether you are adding G to a point or subtracting from it just by listening to the highs and lows of the generated notes when, i.e,  scrolling the sheets, right?  Universe is math, nature, music are all parts of the universe.

Why not learn from the nature and adapt, these algos could also be useful searching for addresses without public keys.

bc1qn55msljhk39mkq2xheswzj0kjtxyvgyzpdvcdk
daly8
Newbie
*
Offline

Activity: 2
Merit: 0


View Profile
August 20, 2026, 05:53:37 AM
 #13778

Hello, please let this thread be for discussing and exchanging ideas.
Has anyone here ever tried to make use of other algos? Just for a starter like CSA (crow  search algo), HS (harmony search)? Imagine you could turn Generator point into music notes, then all other points as well, you would be able to determine whether you are adding G to a point or subtracting from it just by listening to the highs and lows of the generated notes when, i.e,  scrolling the sheets, right?  Universe is math, nature, music are all parts of the universe.

Why not learn from the nature and adapt, these algos could also be useful searching for addresses without public keys.
Not. Waste of time. No matter how much the brain would like to believe in not just generated addresses without meaning.
PHA_.07
Newbie
*
Offline

Activity: 20
Merit: 0


View Profile
August 20, 2026, 06:27:41 AM
Last edit: August 20, 2026, 09:23:30 PM by Mr. Big
 #13779


Nice Info detechs, This matches for the lower keys but starting at puzzle 7 doesnt A and B change ?  Hmm  that is how on first few they were able to use the formula on the signatures.
cicada 3301
Newbie
*
Offline

Activity: 8
Merit: 0


View Profile
August 20, 2026, 07:32:38 AM
 #13780

"the top half of k is the top half of z, byte for byte, and the bottom 128 bits are zero. formula B's signature has k's bottom 128 bits equal to n's bottom 128 bits, " I already have this formula in my hands, I wrote it.
Pages: « 1 ... 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685 686 687 688 [689] 690 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!