mrb
Discussion thread here: https://bitcointalk.org/index.php?topic=1306983.msg64526037#...

Bitcoin puzzles are private keys with just a few unknown bits so that anyone can bruteforce them to collect a reward. Puzzle 66 contained 66 unknown bits and had 6.6 BTC deposited into it by the initial puzzle creator. The private key was 0x000000000000000000000000000000000000000000000002832ed74f2b5e35ee or 256 bits with mostly zeroes but 66 random ones.

The next Bitcoin puzzle, #67, has 67 unknown bits, and contains 6.7 BTC up for grabs: https://www.blockchain.com/explorer/addresses/btc/1BY8GQbnue...

The previous puzzle by order of difficulty was #64 (not #65, because see below) and was solved on 9/9/2022, so about 2 years ago. In other words, it took about 2 years of compute time to run the 2^66 bruteforcing task.

Puzzles that are multiple of 5 (#65 or #70) are special: they have twice more entropy. So that private key #65 doesn't have 65-bit of entropy but 130-bit of entropy. And the creator of the puzzle intentionally published their public key on the blockchain. When you know the public key, brutetforcing the n-bit private key only requires 2^(n/2) work. So puzzle #65 with a 130-bit key actually require bruteforcing up to only 2^65 keys.

gzer0
Whoever solved it left a rather intriguing, albeit slightly mocking, message:

  TX input:
  Code:
  1FuckUmT5yBAvozf6gT8GRQVbJ7iBDUnrH

  TX outputs:
  Code:
  1Jvv4yWkE9MhbuwGU66666666669sugEF 0.00000001
  1YouAreSoDumbLoL666666666667K5aR4 0.00000002
  1WhatWereUThinking6666666662wkqq1 0.00000003
  1YouDeserveNothing6666666665sbbBC 0.00000004
  1YouEpicFaiLure66666666666688GSDA 0.00000005
  1BitchAssLoser66666666666669dBUVg 0.00000006
  1AndEveryoneELse666666666669Vnc8C 0.00000007
  1ThisisALosingGame6666666667HAZdf 0.00000008
  1JustGetAReaLJob666666666665vGKVD 0.00000009
  1YoureWastingTimeAndMoney664CVExC 0.00000010
  1AndCausingCLimateChange6666HK8Qc 0.00000011
  13zb1hQbWVsc2S7ZTZnP2G4undNNpdh5so 0.00000012
  1Jvv4yWkE9MhbuwGUoqFYzDjRVQHaLWuJd 0.00000013
  1FK5PjPNARQmg94n2cNHTo9417kWfXUDBQ 0.00002125
arcanemachiner
Looks like the coins were stolen by a bot:

> https://bitcointalk.org/index.php?topic=1306983.msg64535839#...

I'm not super familiar with the concept (and I'm too lazy to look into it TBH), but I think the would-be winner posted the private key before enough (any?) blocks were mined, and the thief posted a transaction with a bigger fee, and the thief's transaction was in the block that got mined.

thundergolfer
We had fraudsters using modal.com compute to solve this challenge. It's not traditional mining software so it didn't initially get flagged, but we've updated our detection to catch it now[1].

1. https://modal.com/blog/catching-cryptominers

cj
Interesting: Reading the first page of the bitcointalk forum, the puzzle originated from this wallet, which has an incredible amount of volume going through it. 10,000+ transactions and over a million BTC sent/received.

https://www.blockchain.com/explorer/addresses/btc/173ujrhEVG...

gizmo385
Is there something unique or special about the private keys that are guessed? This seems like an incredibly wasteful allocation of compute (which wouldn’t be surprising given that it’s bitcoin but still)
rboyd
probably discussed in the bitcointalk thread, but how do we know it's not just the creator of the puzzle reclaiming his own bitcoin?
y42
What I don't understand, hopefully someone is still reading it here: The hint says this:

>> First output: take random number from 2^0 upto 2^1-1, use it as private key >> Second output: take random number from 2^1 upto 2^2-1, use it as private key >> Third output: take random number from 2^2 upto 2^3-1, use it as private key

To me it sounds like that wallet #10 has a range from 2^9 to 2^10 - 1 - so you don't actually need to check previous bits. But somehow it seems like everyone is crawling through the whole range of possible private key. Doesn't make sense, does it? Am I missing something?

mrb
Another good resource on these puzzles: https://privatekeys.pw/puzzles/bitcoin-puzzle-tx
iJohnDoe
Can someone EILI5?

I thought cracking anything to steal bitcoin was impossible due to the keys sizes involved? Is this possible because a portion of the key is already available so there is less to crack?

Which key is known? The public or private? Another comment said the “now known public” but then also said the private key can now be recovered by cracking it? Two keys need to be cracked?

What kind computing power is needed to crack both keys and how long?

Thanks. Sorry, I’m an idiot when it comes to bitcoin.

wodenokoto
That’s not a trivial price. Who finance these puzzles?
odyssey7
What category of taxable income would this be in the US?
DreadPriateRob
my assumption is the only way you will be able to stop any bot from double spend attack is to multisig the puzzle address when its solved so any transaction there forth would need your main wallets or any wallet that you set up to need its signature or signature(s) if using multiple before any transactions are made but you will need to be quick about it maybe even setting up your own script or bot to do so i find it wild that the solver didn't think that someone could swoop in and take the reward i multisig all my addresses for that very reason and yes i know a lot about mutisig it's impossible to use a double spend attack with that set up
ivanjermakov
Who is paying to the puzzle solvers?
unapapa
[dead]
dmikke
[dead]
Andrewkimberly
[dead]
Blackgamer
[dead]
frolovairinaa
[flagged]
VICTORIAARCHIE
[flagged]
venck
[flagged]
imrankhanjoya
[flagged]
VICTORIAARCHIE
[flagged]
totallyunknown
This is just sick.
Meganet
So while this is going on https://www.youtube.com/watch?v=Vl6VhCAeEfQ (ted talk)

a lot of people created co2 to take part in a btc lottery and the winner was now randomly found.

I hate crypto :|

Dwedit
Do they have a buyer for that $400k? If not, it's not worth $400K.