|
kTimesG
|
 |
July 12, 2026, 08:55:17 PM |
|
You are mixing Pollard Kangaroo and Gaudry-Schost. What you describe would only work for GS or SOTA/SOTA+ (or more generically on methods relaying on birthday attack analysis) but not Pollard Kangaroo. It doesn't matter how many points you compute "at once" in Pollard Kangaroo, because distance between tame and wild, wouldn't change. Or in other words, it doesn't matter if tame catches wild (or wild catches tame) on the plus side going forward, or on the minus side going backwards, both are perfect mirror of each others and for methods that start at one location and never "restart" (i.e. PK) this wouldn't work. You are missing the fact that in PK all walks go in a single direction. Hence, only the points are mirrored, not the walks.This means that once you hit one of two points with the same X, the next point is different depending on whether the current point was on the left or right side. So once you have a DP collision, you have two distances, not one, because the DP might have been on one of two sides, hence different distances to the respective base point (two offsets to the tame base, and two offsets to the public key and the symmetric one). Maybe actually implement this and see for yourself? You don't have to believe me, I am simply stating facts.
|
|
|
|
lleoha
Newbie

Activity: 9
Merit: 1
|
 |
July 12, 2026, 10:04:58 PM |
|
You are missing the fact that in PK all walks go in a single direction.
I am very aware of that. Maybe actually implement this and see for yourself? You don't have to believe me, I am simply stating facts.
Already did that, more than one time. https://github.com/lleoha/kangaroo-lab (experiments to compare K with what papers say) https://github.com/lleoha/coin-cracker (CUDA "mirrorless" SOTAv2, gives k=1.6 but it processes more points/s than RCKangaroo, there's also some math behind SOTAv2's "k").
|
|
|
|
|
|
kTimesG
|
 |
July 12, 2026, 10:23:43 PM |
|
I am very aware of that. Great then. You continue to confuse secp256k1 with a generic group. Here's your fallacy: The leading constant should not depend on whether the group is this additive group, an elliptic-curve group, or another cyclic group of comparable order because the exact opposite is true: the constant depends on whether the group has special properties. PK 1.71 is for generic groups, not for groups with equivalence classes. But you should know better what you're looking for, after all. EOF
|
|
|
|
verybitcoinwow
Newbie

Activity: 3
Merit: 0
|
 |
July 20, 2026, 10:01:42 PM |
|
Question from a newbie: Did RC have the public keys for puzzles #120, #125, and #130?
|
|
|
|
|
nc50lc
Legendary

Activity: 3220
Merit: 8936
Self-proclaimed Genius
|
 |
July 21, 2026, 04:50:38 AM Last edit: July 21, 2026, 06:33:16 AM by nc50lc |
|
Question from a newbie: Did RC have the public keys for puzzles #120, #125, and #130?
Those pubKeys are already available to public ever since the puzzle owner revealed those divisible-by-five puzzle ranges. For clarification, It's not directly posted, the owner just sent and spent 1000sat UTXO to those, by doing so, he reveled the pubKeys. ( then sent more bitcoins back to the same addresses) Those pubKeys can be seen in this " transaction" that spent those: 17e4e323cfbc68d7f0071cad09364e8193eedf8fefbcbd8a21b4b65717a4b3d3Click " Details+" and look for each address' pubKey next to the signature.
|
|
|
|
verybitcoinwow
Newbie

Activity: 3
Merit: 0
|
 |
July 21, 2026, 07:02:46 PM |
|
Question from a newbie: Did RC have the public keys for puzzles #120, #125, and #130?
Those pubKeys are already available to public ever since the puzzle owner revealed those divisible-by-five puzzle ranges. For clarification, It's not directly posted, the owner just sent and spent 1000sat UTXO to those, by doing so, he reveled the pubKeys. ( then sent more bitcoins back to the same addresses) Those pubKeys can be seen in this " transaction" that spent those: 17e4e323cfbc68d7f0071cad09364e8193eedf8fefbcbd8a21b4b65717a4b3d3Click " Details+" and look for each address' pubKey next to the signature. Thanks. That explains it
|
|
|
|
|
JDScreesh
Member


Activity: 73
Merit: 27
|
 |
Today at 08:35:20 AM |
|
Hello there! Congratulations RetiredCoder for solve the puzzle # 135. 
|
For donations: BTC - bc1q9v9s9jtunr58pykwx77dpwzdupmfdn0x8jyt06 or 145u2ppTJhkXq11xnbBM5JgkQdgV9o1V42 For donations: LTC - LaAHGMjisi2NFMfHJpMywKm8ALzmivdRaq
|
|
|
RetiredCoder (OP)
Full Member
 

Activity: 172
Merit: 186
No pain, no gain!
|
Thanks. Yeah, finally I solved #135, it took about 5 months on 200GPUs. It was... long. I quit, officially. Happy solving #140 without me. To help you with this, today I will update RCKangaroo with complete sources for ASM turbo kernels. I will also publish pk for #135 but later, not right now, when I have some time I will think up another mini-puzzle for that.
|
|
|
|
Torin Keepler
Newbie

Activity: 46
Merit: 0
|
 |
Today at 09:38:45 AM |
|
Thanks. Yeah, finally I solved #135, it took about 5 months on 200GPUs.
Congratulations on your determined and systematic approach, which has led you to yet another victory! I have a question: which jump tables did you use for the main step and for escaping loops? Did you use jump tables from the ranges of previous puzzles, taking advantage of the existing database, or did you start all over again? Thank you very much, and once again, please accept my sincere congratulations!
|
|
|
|
|
RetiredCoder (OP)
Full Member
 

Activity: 172
Merit: 186
No pain, no gain!
|
 |
Today at 10:07:50 AM |
|
RCKangaroo v4.0: https://github.com/RetiredC/RCKangarooI managed to exclude inverse calculation from main loop and applied Montgomery trick three times in total, so I call it "Triple Montgomery trick"  That was fun! I have a question: which jump tables did you use for the main step and for escaping loops? Did you use jump tables from the ranges of previous puzzles, taking advantage of the existing database, or did you start all over again?
I had reasons not to use old databases, so I used fresh jump tables.
|
|
|
|
citramonb
Newbie

Activity: 6
Merit: 0
|
 |
Today at 10:33:32 AM |
|
Thanks. Yeah, finally I solved #135, it took about 5 months on 200GPUs. It was... long. I quit, officially. Happy solving #140 without me. To help you with this, today I will update RCKangaroo with complete sources for ASM turbo kernels. I will also publish pk for #135 but later, not right now, when I have some time I will think up another mini-puzzle for that.
Congratulations! You’ve made history—no one will ever be able to replicate what you’ve achieved! You wrote the software and gave it away for free, yet you still outclassed everyone; pools with 20, 30, 50, 100, or even more members failed to do what you did—you beat them all to the punch once again. Congratulations! It was a pleasure watching your journey. 👏🏼🤝🏼
|
|
|
|
|
b0dre
Jr. Member

Activity: 62
Merit: 1
|
 |
Today at 11:32:13 AM |
|
RCKangaroo v4.0: https://github.com/RetiredC/RCKangarooI managed to exclude inverse calculation from main loop and applied Montgomery trick three times in total, so I call it "Triple Montgomery trick"  That was fun! I have a question: which jump tables did you use for the main step and for escaping loops? Did you use jump tables from the ranges of previous puzzles, taking advantage of the existing database, or did you start all over again?
I had reasons not to use old databases, so I used fresh jump tables. Congratulations legendary. "fresh jump tables" every try or how?
|
|
|
|
|
|
kTimesG
|
 |
Today at 11:55:12 AM |
|
Thanks. Yeah, finally I solved #135, it took about 5 months on 200GPUs. It was... long. I quit, officially. Happy solving #140 without me.
CongSats! So did you even make a profit off #135? Your post's sentiment inclines a bit toward some frustration. Don't worry, your code will be dissected to blood and stand as the basis of future optimizations until the dawn of secp256k1.
|
|
|
|
RetiredCoder (OP)
Full Member
 

Activity: 172
Merit: 186
No pain, no gain!
|
 |
Today at 01:43:13 PM Last edit: Today at 01:53:24 PM by RetiredCoder |
|
"fresh jump tables" every try or how?
It means I used own set of jumps for #135, not from previous puzzles. So did you even make a profit off #135? Your post's sentiment inclines a bit toward some frustration.
Sure I got profit, but I won't do it again, no fun anymore, it was too boring to pay bills for five months  Don't worry, your code will be dissected to blood and stand as the basis of future optimizations until the dawn of secp256k1.
Yeah, feel free to improve it by x10!  The range closest to the actual key is here. Is this correct ...
Please keep all magic predictions/circles/etc away from this thread, you have a whole separate 680-pages thread for this! 
|
|
|
|
crytoestudo
Newbie

Activity: 42
Merit: 0
|
 |
Today at 04:11:48 PM |
|
Congrats, bro—you're a total legend. Could you tell us which GPU models they are?Thanks. Yeah, finally I solved #135, it took about 5 months on 200GPUs. It was... long. I quit, officially. Happy solving #140 without me. To help you with this, today I will update RCKangaroo with complete sources for ASM turbo kernels. I will also publish pk for #135 but later, not right now, when I have some time I will think up another mini-puzzle for that.
|
|
|
|
|
damiankopacz87
Newbie
Online
Activity: 17
Merit: 0
|
 |
Today at 04:41:47 PM |
|
5 months instead of AT LEAST 20 expected? Did You search at smaller ranges, eg. 1024 x 124bit ranges? Random choice or one by one? If You are leaving quest, are You willing to give DP base You used to community? Apes together strong  Best Regards Damian
|
|
|
|
|
toshisa_toshisa
Newbie
Online
Activity: 1
Merit: 0
|
 |
Today at 07:31:07 PM |
|
Congratulations again on solving Puzzle #135. It was an impressive technical achievement, and your dedication is undeniable. That said, I have mixed feelings after reading that it took around **200 GPUs running for 5 months**. For many of us, that's simply impossible. Most enthusiasts have one GPU, maybe two if they're lucky. Competing against hundreds of GPUs makes these puzzles feel less like a test of skill and more like a contest of who has access to the biggest hardware budget.I know the rules never promised an equal playing field, and you earned your success. But it's hard not to feel discouraged when the resources required are far beyond the reach of the average participant. It makes the challenge seem increasingly inaccessible to anyone without substantial computing power. I hope future community challenges can find ways to reward creativity, optimization, and efficiency—not just raw hardware scale—so more people have a realistic chance to compete. Congratulations again, and one small favor if you have a few minutes. I've been building a Bitcoin Puzzle research web app and I'm getting close to publishing it. Since you've spent years optimizing this field, I'd really value your feedback. If you have time, could you please take a quick look and let me know what you think could be improved before I publish it? https://btc-puzzle-solver-search-lab.ai.studio/Any advice or criticism would be greatly appreciated. Thanks, and congratulations once again on your achievement.
|
|
|
|
|
Denis_Hitov
Newbie
Online
Activity: 50
Merit: 0
|
 |
Today at 07:35:33 PM |
|
Thanks. Yeah, finally I solved #135, it took about 5 months on 200GPUs.
Congratulations on solving puzzle #135! You're a genius! Would you like to create your own puzzle with a 1 Bitcoin prize for someone less successful than you?
|
|
|
|
|
|