Bitcoin Forum
July 28, 2026, 06:51:42 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 [26]
  Print  
Author Topic: Solving ECDLP with Kangaroos: Part 1 + 2 + RCKangaroo  (Read 20085 times)
This is a self-moderated topic. If you do not want to be moderated by the person who started this topic, create a new topic. (28 posts by 6+ users deleted.)
kTimesG
Sr. Member
****
Offline

Activity: 910
Merit: 256


View Profile
July 12, 2026, 08:55:17 PM
 #501

You are mixing Pollard Kangaroo and Gaudry-Schost. What you describe would only work for GS or SOTA/SOTA+ (or more generically on methods relaying on birthday attack analysis) but not Pollard Kangaroo. It doesn't matter how many points you compute "at once" in Pollard Kangaroo, because distance between tame and wild, wouldn't change. Or in other words, it doesn't matter if tame catches wild (or wild catches tame) on the plus side going forward, or on the minus side going backwards, both are perfect mirror of each others and for methods that start at one location and never "restart" (i.e. PK) this wouldn't work.

You are missing the fact that in PK all walks go in a single direction.

Hence, only the points are mirrored, not the walks.This means that once you hit one of two points with the same X, the next point is different depending on whether the current point was on the left or right side.

So once you have a DP collision, you have two distances, not one, because the DP might have been on one of two sides, hence different distances to the respective base point (two offsets to the tame base, and two offsets to the public key and the symmetric one).

Maybe actually implement this and see for yourself? You don't have to believe me, I am simply stating facts.

lleoha
Newbie
*
Offline

Activity: 9
Merit: 1


View Profile
July 12, 2026, 10:04:58 PM
 #502

You are missing the fact that in PK all walks go in a single direction.
I am very aware of that.

Maybe actually implement this and see for yourself? You don't have to believe me, I am simply stating facts.
Already did that, more than one time.
https://github.com/lleoha/kangaroo-lab (experiments to compare K with what papers say)
https://github.com/lleoha/coin-cracker (CUDA "mirrorless" SOTAv2, gives k=1.6 but it processes more points/s than RCKangaroo, there's also some math behind SOTAv2's "k").
kTimesG
Sr. Member
****
Offline

Activity: 910
Merit: 256


View Profile
July 12, 2026, 10:23:43 PM
 #503

I am very aware of that.

Great then. You continue to confuse secp256k1 with a generic group. Here's your fallacy:

Quote
The leading constant should not depend on whether the group is this additive group, an elliptic-curve group, or another cyclic group of comparable order

because the exact opposite is true: the constant depends on whether the group has special properties.

PK 1.71 is for generic groups, not for groups with equivalence classes. But you should know better what you're looking for, after all. EOF

verybitcoinwow
Newbie
*
Offline

Activity: 3
Merit: 0


View Profile
July 20, 2026, 10:01:42 PM
 #504

Question from a newbie: Did RC have the public keys for puzzles #120, #125, and #130?
nc50lc
Legendary
*
Offline

Activity: 3220
Merit: 8936


Self-proclaimed Genius


View Profile
July 21, 2026, 04:50:38 AM
Last edit: July 21, 2026, 06:33:16 AM by nc50lc
 #505

Question from a newbie: Did RC have the public keys for puzzles #120, #125, and #130?
Those pubKeys are already available to public ever since the puzzle owner revealed those divisible-by-five puzzle ranges.

For clarification,
It's not directly posted, the owner just sent and spent 1000sat UTXO to those, by doing so, he reveled the pubKeys.
(then sent more bitcoins back to the same addresses)

Those pubKeys can be seen in this "transaction" that spent those: 17e4e323cfbc68d7f0071cad09364e8193eedf8fefbcbd8a21b4b65717a4b3d3
Click "Details+" and look for each address' pubKey next to the signature.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
verybitcoinwow
Newbie
*
Offline

Activity: 3
Merit: 0


View Profile
July 21, 2026, 07:02:46 PM
 #506

Question from a newbie: Did RC have the public keys for puzzles #120, #125, and #130?
Those pubKeys are already available to public ever since the puzzle owner revealed those divisible-by-five puzzle ranges.

For clarification,
It's not directly posted, the owner just sent and spent 1000sat UTXO to those, by doing so, he reveled the pubKeys.
(then sent more bitcoins back to the same addresses)

Those pubKeys can be seen in this "transaction" that spent those: 17e4e323cfbc68d7f0071cad09364e8193eedf8fefbcbd8a21b4b65717a4b3d3
Click "Details+" and look for each address' pubKey next to the signature.

Thanks. That explains it
JDScreesh
Member
**
Online Online

Activity: 73
Merit: 27


View Profile
Today at 08:35:20 AM
 #507

Hello there!

Congratulations RetiredCoder for solve the puzzle # 135.

 Smiley

For donations: BTC - bc1q9v9s9jtunr58pykwx77dpwzdupmfdn0x8jyt06 or 145u2ppTJhkXq11xnbBM5JgkQdgV9o1V42
For donations: LTC - LaAHGMjisi2NFMfHJpMywKm8ALzmivdRaq
RetiredCoder (OP)
Full Member
***
Offline

Activity: 172
Merit: 182


No pain, no gain!


View Profile WWW
Today at 08:39:40 AM
Merited by viljy (5), kTimesG (5)
 #508

Thanks.
Yeah, finally I solved #135, it took about 5 months on 200GPUs.
It was... long. I quit, officially. Happy solving #140 without me.
To help you with this, today I will update RCKangaroo with complete sources for ASM turbo kernels.
I will also publish pk for #135 but later, not right now, when I have some time I will think up another mini-puzzle for that.

I've solved #120, #125, #130, #135. How: https://github.com/RetiredC
Torin Keepler
Newbie
*
Offline

Activity: 46
Merit: 0


View Profile
Today at 09:38:45 AM
 #509

Thanks.
Yeah, finally I solved #135, it took about 5 months on 200GPUs.

Congratulations on your determined and systematic approach, which has led you to yet another victory!

I have a question: which jump tables did you use for the main step and for escaping loops?

Did you use jump tables from the ranges of previous puzzles, taking advantage of the existing database, or did you start all over again?

Thank you very much, and once again, please accept my sincere congratulations!
RetiredCoder (OP)
Full Member
***
Offline

Activity: 172
Merit: 182


No pain, no gain!


View Profile WWW
Today at 10:07:50 AM
 #510

RCKangaroo v4.0:
https://github.com/RetiredC/RCKangaroo

I managed to exclude inverse calculation from main loop and applied Montgomery trick three times in total, so I call it "Triple Montgomery trick"  Cheesy
That was fun!

I have a question: which jump tables did you use for the main step and for escaping loops?
Did you use jump tables from the ranges of previous puzzles, taking advantage of the existing database, or did you start all over again?

I had reasons not to use old databases, so I used fresh jump tables.

I've solved #120, #125, #130, #135. How: https://github.com/RetiredC
citramonb
Newbie
*
Offline

Activity: 6
Merit: 0


View Profile
Today at 10:33:32 AM
 #511

Thanks.
Yeah, finally I solved #135, it took about 5 months on 200GPUs.
It was... long. I quit, officially. Happy solving #140 without me.
To help you with this, today I will update RCKangaroo with complete sources for ASM turbo kernels.
I will also publish pk for #135 but later, not right now, when I have some time I will think up another mini-puzzle for that.

Congratulations! You’ve made history—no one will ever be able to replicate what you’ve achieved! You wrote the software and gave it away for free, yet you still outclassed everyone; pools with 20, 30, 50, 100, or even more members failed to do what you did—you beat them all to the punch once again. Congratulations! It was a pleasure watching your journey. 👏🏼🤝🏼
b0dre
Jr. Member
*
Offline

Activity: 62
Merit: 1


View Profile
Today at 11:32:13 AM
 #512

RCKangaroo v4.0:
https://github.com/RetiredC/RCKangaroo

I managed to exclude inverse calculation from main loop and applied Montgomery trick three times in total, so I call it "Triple Montgomery trick"  Cheesy
That was fun!

I have a question: which jump tables did you use for the main step and for escaping loops?
Did you use jump tables from the ranges of previous puzzles, taking advantage of the existing database, or did you start all over again?

I had reasons not to use old databases, so I used fresh jump tables.

Congratulations legendary.

"fresh jump tables" every try or how?
kTimesG
Sr. Member
****
Offline

Activity: 910
Merit: 256


View Profile
Today at 11:55:12 AM
 #513

Thanks.
Yeah, finally I solved #135, it took about 5 months on 200GPUs.
It was... long. I quit, officially. Happy solving #140 without me.

CongSats! So did you even make a profit off #135? Your post's sentiment inclines a bit toward some frustration. Don't worry, your code will be dissected to blood and stand as the basis of future optimizations until the dawn of secp256k1.

RetiredCoder (OP)
Full Member
***
Offline

Activity: 172
Merit: 182


No pain, no gain!


View Profile WWW
Today at 01:43:13 PM
Last edit: Today at 01:53:24 PM by RetiredCoder
 #514

"fresh jump tables" every try or how?

It means I used own set of jumps for #135, not from previous puzzles.

So did you even make a profit off #135? Your post's sentiment inclines a bit toward some frustration.

Sure I got profit, but I won't do it again, no fun anymore, it was too boring to pay bills for five months  Grin

Don't worry, your code will be dissected to blood and stand as the basis of future optimizations until the dawn of secp256k1.

Yeah, feel free to improve it by x10!   Cheesy

The range closest to the actual key is here. Is this correct
...

Please keep all magic predictions/circles/etc away from this thread, you have a whole separate 680-pages thread for this!  Grin

I've solved #120, #125, #130, #135. How: https://github.com/RetiredC
crytoestudo
Newbie
*
Online Online

Activity: 40
Merit: 0


View Profile
Today at 04:11:48 PM
 #515

Congrats, bro—you're a total legend. Could you tell us which GPU models they are?
Thanks.
Yeah, finally I solved #135, it took about 5 months on 200GPUs.
It was... long. I quit, officially. Happy solving #140 without me.
To help you with this, today I will update RCKangaroo with complete sources for ASM turbo kernels.
I will also publish pk for #135 but later, not right now, when I have some time I will think up another mini-puzzle for that.
damiankopacz87
Newbie
*
Offline

Activity: 17
Merit: 0


View Profile
Today at 04:41:47 PM
 #516

5 months instead of AT LEAST 20 expected? Did You search at smaller ranges, eg. 1024 x 124bit ranges? Random choice or one by one?
If You are leaving quest, are You willing to give DP base You used to community? Apes together strong Wink

Best Regards
Damian
toshisa_toshisa
Brand new
*
Online Online

Activity: 0
Merit: 0


View Profile
Today at 06:51:36 PM
 #517

Congratulations on solving Bitcoin Puzzle 135! That's an incredible achievement and a testament to your skill, patience, and dedication.

I have to admit, seeing your success is bittersweet for me. I've spent so much money, countless hours, and an enormous amount of effort chasing these puzzles, hoping one day I'd solve one myself. After hearing the news, I honestly feel pretty hopeless.

Still, you earned this, and I sincerely congratulate you. Enjoy the moment—you've accomplished something that many of us have been chasing for a long time. Wishing you all the best, and thanks for showing what's possible.
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 [26]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!