NEEDLESPACE
The 160/#150

#150

UnsolvedKey exposed15 BTC

Still unsolved. But its public key is exposed, so it yields to Pollard's Kangaroo rather than brute force. The work required falls from 2149 to its square root, around 274.5.

Address

1MUJSJYtGPVGkBCTqGspnxyHahpt5Te8jy

mempool.space
Key range (hex)

0x20000000000000000000000000000000000000 ~ 0x3fffffffffffffffffffffffffffffffffffff

Interval size

2^149 = 7.1×10^44

Balance

15.00001600 BTC · 7 tx

snapshot from 2026-08-23

Public key (compressed)

03137807790ea7dc6e97901c2bc87411f45ed74a5629315c4e4b03a0a102250c49

Exposed on 31 May 2019, when the creator withdrew 1,000 satoshis from this address. This is the value BSGS and Kangaroo take as input.

Method of attack
Pollard's Kangaroo
work ≈ 2.7×10^22 (2^74.5)
Browser (JS, 1 thread)the search tool on this site4.7×10^10 years — 3.4× the age of the universe
CPU · keyhunt, 8 threads1.1×10^8 years
CPU · keyhunt, 16 threads52,906,707 years
GTX 10604,232,537 years
RTX 30701,058,134 years
RTX 3090564,338 years
RTX 4090338,603 years
RTX 5090211,627 years
RTX 4090 × 1033,860 years
RTX 4090 × 1003,386 years
RTX 4090 × 1,000the scale of a large pool339 years
All approximate. Implementation, clocks and target count move these by multiples, so read the order of magnitude and nothing finer. The calculator lets you put your own rate in.
Finding it is not the same as keeping it

A transaction moving puzzle funds carries the public key and the signature. The moment it reaches the mempool, bots take the same coins with a higher fee. That is exactly how #66 and #69 were lost. How to prevent it

Doing it

How to actually run this puzzle

Recommended: Kangaroo (GPU)

The public key is known, so the discrete logarithm is solved directly. The work drops from 2^149 to around 2^74.5.

0. Build (Linux · CUDA)
git clone https://github.com/JeanLucPons/Kangaroo
cd Kangaroo
make gpu=1 ccap=86   # ccap is your GPU's compute capability (4090=89, 3090=86, 1060=61)
# On Windows open VC_CUDA102/Kangaroo.sln in Visual Studio. macOS and AMD are not supported.
1. Input file — three lines: range start, range end, public key
cat > in150.txt <<'EOF'
20000000000000000000000000000000000000
3FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
03137807790EA7DC6E97901C2BC87411F45ED74A5629315C4E4B03A0A102250C49
EOF
2. Run
./kangaroo -t 8 -gpu -gpuId 0 -w save150.work -wi 300 -o found-150.txt in150.txt
Watch out for
  • Order matters in the input file — range start, range end, public key. Get it wrong and it finds nothing.
  • -d is the distinguished-point bit count. Leave it out and it picks one; only touch it when distributing.
  • -w and -wi save progress every five minutes. On a job that runs for days this is not optional.
  • To combine machines use -s (server) / -c (client) mode. It is more efficient than splitting the range.
Other options

CPU only. Handles both addresses and public keys, and is the easiest to install — good for learning and for checking your setup.

Address brute force. The de facto standard for puzzles with no public key, and the only one that runs on AMD.

BitCracknot usable

The public key is known, so brute-forcing addresses is a waste. Kangaroo needs 2^74.5 operations where BitCrack runs 2^149.

A reality check

On a single RTX 4090 this takes 338,603 years. That is not “eventually”; in most cases it means “no”. Doing it anyway means accumulating GPUs or joining a pool.