I live in Thailand. Today I bought two government lottery tickets for ~200 baht — and spent the evening doing math instead of dreaming. Result: I’m done buying tickets. I’d rather run a lottery where tickets are free and the jackpot is ~903 BTC.
The Ticket
| Lottery | Ticket | Odds |
|---|---|---|
| Thai lottery | ~100฿ | 1 in 10^6 |
| Powerball | $2 | 1 in 2.9×10^8 |
| Bitcoin Puzzle seed lottery | 0฿ | 1 in 2^128 ≈ 3.4×10^38 |
My odds are the worst on the list. But the tickets are free, the odds are honest, and the math behind them is beautiful.
What Is This
The Bitcoin Puzzle Transaction: 2015, an anonymous user funds 256 addresses. Each address #N has its private key inside [2^(N-1), 2^N). Higher N = more bits = harder. #1 is 1 bit. #160 is 160 bits.
83 solved. ~903 BTC still sitting there.
Everyone asks: how to crack it?
Wrong question. I asked: how was it created? Then rebuilt the entire pipeline from scratch. Zero dependencies. Every stage verified against real data.
The Pipeline
seed phrase (12/24 BIP39 words)
│ PBKDF2-HMAC-SHA512, 2048 iterations
▼
512-bit seed
│ HMAC-SHA512(key = "Bitcoin seed")
▼
master key + chain code ← BIP32
│ CKD: 256 consecutive child keys
▼
bit erasure: key #N → [2^(N-1), 2^N)
│ K = k × G on secp256k1
▼
P2PKH "1..." addresses
Validation
- All 83 solved keys → k×G → Hash160 → Base58Check: 83/83 match
- BIP32 vs official spec test vectors: 17/17
- secp256k1: 1×G equals the canonical generator
The Finding
All 83 keys have exactly N bits.
Zeroing top bits would push half the keys out of range — joint probability of the observed outcome: 2^-83. The creator didn’t erase bits. He forced them:
k = 2**(n-1) | (child_key % 2**(n-1)) # "force" mode
Corollary: puzzle #1’s address is identical for any seed phrase. The key is always 1.
The Seed Lottery
Back to the tickets. My lottery:
- Ticket price: 0฿
- Ticket = creator’s phrase: 1 in 2^128
- Full space at 66 tickets/sec: 1.7×10^19 ages of the universe
- Memory O(1): a 2 MB Bloom filter instead of a set of all phrases. RSS ~23 MB flat.
The phrase will be found by a leak, not by math.
Run It
python3 puzzle_generator.py # self-test + difficulty ladder
./lotto_daemon.sh start nice # seed lottery in background
./lotto_daemon.sh hits # jackpots (spoiler: none)
Links
- Source code: github.com/temaprint/BitcoinPuzzle