#110
SolvedKey exposedThe private key to this puzzle is public and the balance has been swept. Everything below was re-derived with secp256k1 and confirmed to match the address — never take a copied value on trust.
0x2000000000000000000000000000 ~ 0x3fffffffffffffffffffffffffff
2^109 = 6.5×10^32
0.00000000 BTC · 11 tx
snapshot from 2026-08-23
0309976ba5570966bf889196b7fdf5a0f9a1e9ab340556ec29f8bb60599616167d
Exposed on 31 May 2019, when the creator withdrew 1,000 satoshis from this address. This is the value BSGS and Kangaroo take as input.
00000000000000000000000000000000000035c0d7234df7deb0f20cf7062444
The balance is zero. This value is useful for verification and learning only — import it into a wallet and you will find nothing there.
How to actually run this puzzle
The public key is known, so the discrete logarithm is solved directly. The work drops from 2^109 to around 2^54.5.
git clone https://github.com/JeanLucPons/Kangaroo cd Kangaroo make gpu=1 ccap=86 # ccap is your GPU's compute capability (4090=89, 3090=86, 1060=61) # On Windows open VC_CUDA102/Kangaroo.sln in Visual Studio. macOS and AMD are not supported.
cat > in110.txt <<'EOF' 2000000000000000000000000000 3FFFFFFFFFFFFFFFFFFFFFFFFFFF 0309976BA5570966BF889196B7FDF5A0F9A1E9AB340556EC29F8BB60599616167D EOF
./kangaroo -t 8 -gpu -gpuId 0 -w save110.work -wi 300 -o found-110.txt in110.txt
- Order matters in the input file — range start, range end, public key. Get it wrong and it finds nothing.
- -d is the distinguished-point bit count. Leave it out and it picks one; only touch it when distributing.
- -w and -wi save progress every five minutes. On a job that runs for days this is not optional.
- To combine machines use -s (server) / -c (client) mode. It is more efficient than splitting the range.
CPU only. Handles both addresses and public keys, and is the easiest to install — good for learning and for checking your setup.
Address brute force. The de facto standard for puzzles with no public key, and the only one that runs on AMD.
The public key is known, so brute-forcing addresses is a waste. Kangaroo needs 2^54.5 operations where BitCrack runs 2^109.
This one is already solved. The commands above are for learning — knowing the answer makes it a good way to confirm your tool actually works.