Key takeaways
- The Bitcoin puzzle is a single 2015 transaction that funded 256 addresses, each holding a private key inside a known, fixed numeric range.
- Each puzzle is exactly twice as hard as the one before it, because puzzle #N hides its key between 2 to the power of N minus 1 and 2 to the power of N.
- Puzzles whose public keys were exposed in 2019 can be attacked with Pollard's kangaroo algorithm, which is why high-numbered #130 fell before brute-force-only #71.
- The remaining unexposed puzzles like #71 need true brute force over a 2^70 range, which is impractical for almost everyone.
- Only study the public challenge addresses: pointing these methods at anyone else's wallet is theft and, in practice, infeasible anyway.
The Bitcoin puzzle is a single 2015 transaction that locked a pile of BTC into 256 addresses, each holding a private key inside a known, escalating numeric range. It was built as an open cryptography challenge, not a scam or a prediction, and anyone who finds a key in the right range can claim the coins sitting at that address.
That setup makes the Bitcoin puzzle one of the cleanest ways to learn how Bitcoin keys actually work. You can watch real money move as real cryptography gets tested, with no marketing and no hype in the way. This guide walks through the history, the math behind the key ranges, which puzzles are already solved, and an honest look at the odds on the rest.

What the 2015 Bitcoin puzzle transaction is
On 15 January 2015, an anonymous creator broadcast a Bitcoin transaction that funded 256 separate addresses at once. Each address became puzzle #1, #2, #3, and so on, up through #256. The design rule is simple and strict: the private key for puzzle #N lives somewhere in the range from 2 to the power of (N minus 1) up to 2 to the power of N.
Puzzle #1 therefore has its key in the range 1 to 1, a single value. Puzzle #2 sits between 2 and 3. Puzzle #10 hides in a range of 512 possible keys. By the time you reach puzzle #70, the range holds more than a billion billion possibilities. Every step up the ladder doubles the search space, so each puzzle is exactly twice as hard as the one before it.
The amounts followed a clean pattern too. The reward for each address scales with its number, so higher puzzles carry more BTC. Early on the whole set held roughly 32.9 BTC, and later top-ups pushed the total prize pool toward around 1,000 BTC across the active addresses. You can read the full transaction and solve history in the community-maintained Bitcoin puzzle info repository, which tracks every address and its status.
Why the ranges matter
The key ranges are the whole point. In normal Bitcoin use, a private key is a random 256-bit number, so guessing one is hopeless by design. The puzzle deliberately shrinks the search space for the low addresses down to something a laptop can sweep in seconds, then grows it step by step until it reaches sizes no machine on Earth can brute force. It is a difficulty dial you can see and measure, which is exactly what makes it a teaching tool.
Which puzzles are solved, and which are not
The low puzzles went almost immediately. Anyone who understood the range rule could sweep puzzles #1 through the low numbers in minutes, because the search space was tiny. As of 2026, every puzzle from #1 through #70 has been solved, and so has every fifth puzzle up through #130.
A few solves stand out:
- Puzzle #66 was claimed on 15 September 2024, releasing 6.6 BTC. According to the Hacker News discussion of the solve, the winning transaction was front-run in the mempool, meaning a watcher spotted the reveal and rushed a competing claim.
- Puzzle #130 fell on 23 September 2024 for 13 BTC, despite its range being astronomically larger than #66.
- Puzzle #67 was solved on 21 February 2025, and puzzle #68 on 7 April 2025, with later solvers routing around the public mempool to avoid getting front-run.
That raises an obvious question. How did puzzle #130, with a key range around 2 to the power of 129, get solved before puzzle #71, which is vastly smaller? The answer is not luck. It is a quiet change the creator made in 2019.
The 2019 public-key exposure
In May 2019, small transactions were sent out of the higher puzzle addresses, including #70 and every fifth address above it. Spending from an address reveals its public key on the blockchain, and that single fact changes the math completely.
When only the address is known, an attacker has to brute force the entire range, checking candidate keys one by one. When the public key is also known, a different and far faster method becomes available.
The math and the honest odds
Two families of attack apply here, and the gap between them is enormous.
Brute force applies when only the address is published. For puzzle #71, that means searching a range of size 2 to the power of 70, roughly 10 to the power of 21 candidate keys. Even at billions of keys per second, sweeping a space that large is impractical for almost anyone, which is why #71 remains unsolved while flashier high-numbered puzzles have fallen.
Pollard's kangaroo algorithm applies when the public key is known. It solves the underlying elliptic curve discrete logarithm in roughly the square root of the range size. For puzzle #130, that turns an impossible 2 to the power of 129 search into roughly 2 to the power of 65 operations. The same Hacker News thread on the #130 solve describes that scale of work as achievable in a few months with a few hundred GPUs. Demanding, expensive, but not impossible.

So the honest odds break down like this:
- The low puzzles are long gone. There is nothing left to win there.
- The remaining exposed-key puzzles, such as #135, are theoretically crackable with kangaroo methods, but only for people willing to run serious GPU fleets for months.
- The remaining brute-force-only puzzles, like #71, sit behind search spaces that make a home-computer solve a lottery ticket with worse odds than most lotteries.
No amount of clever software changes those exponents. A square-root speedup is huge, and it is still not enough to make a 2 to the power of 70 brute force casual. Anyone promising an easy puzzle win is selling something.
Ethics and safety: only the challenge addresses
The methods above work on the puzzle addresses precisely because the creator chose keys inside small, known ranges on purpose. That is the entire reason they are solvable at all.
A normal Bitcoin wallet uses a full-entropy 256-bit key. Pointing kangaroo or brute-force tools at a stranger's address does two things: it will not work, because the key is not confined to a tiny range, and it is attempted theft. Study the public challenge addresses that were set up to be studied, and leave every other wallet alone. If you want to understand how key reuse or an exposed public key affects a real wallet, you can read about that safely without touching anyone's funds.
The safe way to explore any of this is to read addresses, not to attack them. A good on-chain explorer lets you inspect an address history, see when a public key was exposed by an outgoing spend, and understand the difference between a watched address and a controlled one.
Explore the puzzle addresses safely with QbyteLab
If the puzzle transaction has you curious about how Bitcoin keys and addresses really behave, the right next step is to inspect them directly rather than to attack anything. The Bitcoin Research Tool by QbyteLab is built for exactly that kind of study. It pairs an on-chain explorer with detailed address dossiers, an offline HEX, WIF, and address converter, and key-space analysis with real speed metrics, so you can see the math at work instead of taking anyone's word for it.
Nothing in the app custodies funds or touches private wallets. It is a research toolkit for reading the blockchain honestly. The Bitcoin Research Tool is live on the App Store and Google Play, with a one-time $9.99 Premium upgrade and no subscriptions. Download it, open a puzzle address, and watch the key-space math line up with everything in this guide.
Frequently asked questions
What is the Bitcoin puzzle?
It is a 2015 Bitcoin transaction that funded 256 addresses whose private keys sit in predictable, escalating numeric ranges. The creator left the funds as an open cryptography challenge.
Is solving a Bitcoin puzzle legal?
Claiming a public challenge address the creator set up for this purpose is widely treated as fair game. Applying the same math to someone else's wallet is theft, and the key spaces involved make it infeasible regardless.
Why was puzzle #130 solved before puzzle #71?
Puzzle #130's public key was exposed in 2019, so solvers used Pollard's kangaroo algorithm to cut the work to roughly 2^65. Puzzle #71 has no exposed public key, so it still requires brute force over its full 2^70 range.
Can I crack a high Bitcoin puzzle on a home PC?
Not realistically. The low puzzles were solved years ago. The remaining ones need either an exposed public key plus serious GPU time or brute force across ranges too large for consumer hardware.

Leave a Reply