Three facts explain the entire project. None of them require you to trust anybody, including us.
01
Someone hid keys on purpose
In January 2015, a person known as saatoshi_rising funded 160 Bitcoin addresses in one
transaction. The private key of puzzle #1 sat in a 1-bit range, #2 in a 2-bit range, and every
step after that doubled. Puzzles up to #70 have all been cracked. In April 2023 the creator
multiplied the remaining prizes by ten, which is why #140 now holds 14 BTC. Those coins have
never moved.
02
Five of them leaked the shape of the answer
An address is only a hash of a public key, so normally you learn nothing from it. But in May 2019
the creator spent 1,000 satoshis out of #140, #145, #150, #155 and #160, and a spend publishes
the public key. With that key in hand the hunt stops being a guessing game and becomes a
computation: about the square root of the range instead of the whole range.
03
Compute is the only input
There is no product here and nothing to believe in. Trading fees land in one public wallet, that
wallet buys GPU hours, and those hours walk a keyspace. If a key falls out, the Bitcoin is real
and the transaction is visible to everyone at the same moment. If it doesn't, the wallet still
shows exactly where every dollar went.
02 / THE ENGINEHASH RESEARCH DIVISION +
Fee engine
Fees in, keyspace out.
Five steps. Every one of them is something an outsider can check, which is the only reason to lay it out like this.
Trades happen
The HASH/BTC pair will launch on Solana. Its trading fees are intended to fund the project's compute.
Fees pool in public
Fees will settle in a public Solana treasury. The address will be published with launch details.
Fees become GPU hours
The balance is spent on rented compute, priced in GPU-hours. Nothing is manufactured; hardware is bought at market rate.
Compute takes a slice
Each worker gets a slice of the target's interval and walks it with Kangaroo, or hashes it blind on the targets that never leaked a key.
A collision ends it
Two herds land on the same point, the private key drops out of the difference, and the coins move on Bitcoin in front of everybody.
Follow the evidence. Puzzle addresses can be checked against a public Bitcoin node. Fleet readings retain their source timestamps. Hash's Solana treasury and HASH/BTC market details will be published at launch.
03 / COMPUTEHASH RESEARCH DIVISION +
Compute telemetry
Inside the compute.
Every generated wallet is checked against a 100M+ entry Bloom filter containing funded addresses, including all unsolved BTC Puzzle wallets. Recovered BTC is intended to be converted to SOL on Solana to fund additional GPUs and buybacks for the HASH/BTC pair. The readings below preserve the source project's public hardware data.
Loading source telemetry
Fleet throughput0
GPUs online0
Wallets generated per second0reported across the source fleet
Fleet throughput
No rig has reported yet. Rows appear here within seconds of an agent starting on a box.
04 / TARGET ARCHIVEHASH RESEARCH DIVISION +
The board
77 unsolved targets.
Every tile is a live Bitcoin address. Open one for its exact key range, the attack it allows, and a
balance check straight from a public node. Source snapshot 2026-09-22; check an address for its current balance.
Orange tiles leaked a public key in 2019 and can be attacked with Kangaroo. Everything else has to be
brute-forced, which is why the bounty on a tile tells you almost nothing about how hard it is.
05 / THE MATHEMATICSHASH RESEARCH DIVISION +
Why only five
Hunting versus computing.
A scaled illustration of Pollard's Kangaroo: two deterministic walks share a path when they reach the same point. This is an explainer, not a live key search.
Pollard's Kangaroo · scaled interval0 hops
SHARED HOP RULE / TWO STARTING POINTS
tame herd, known start wild herd, starts on the target stored distinguished pointstatus: herds walking
A blind puzzle leaves you one move: pick a key, hash it, compare it to the address, repeat.
#71 hides its key somewhere in 270 candidates, so you expect to try about
590 billion billion of them before one matches.
A puzzle with an exposed public key gives you geometry instead. Kangaroo releases two herds onto
the interval, and the length of every hop is decided by wherever that kangaroo currently stands.
The moment one herd lands on a point the other already visited, both follow the identical path
forever, and the gap between where they started is the private key. The work collapses to roughly
the square root of the interval.
#135 fell exactly this way in July 2026, after the solver known as RetiredCoder spent about five
months on 200 GPUs. #140 is the next rung on the same ladder, and it is where Hash starts.
#71 · blind
5.9 × 1020
hashes expected. 270 range, no public key, no shortcut of any kind.
#140 · computable
9.6 × 1020
hops expected. A range 269 times larger, for 1.6× the work.
06 / THE RECORDHASH RESEARCH DIVISION +
Track record
Eleven years of this puzzle.
Nothing about the puzzle is speculative. It has a transaction history, a body of solvers, and a frontier that keeps moving.
160 addresses funded in a single transaction, each private key placed in a range twice the size of the one before it.
The creator sweeps addresses #161–#256 back into the lower ones, raising every remaining prize.
The event this project depends on. 1,000 satoshis are spent out of #65, #70 and every fifth address up to #160. Each spend publishes that address's public key, which turned #140, #145, #150, #155 and #160 into computable targets.
Every unsolved prize is multiplied by ten. #140 becomes 14 BTC, #160 becomes 16 BTC.
#66 falls. The winning transaction is broadcast into the public mempool and most of the 6.6 BTC is replaced out from under the solver before it confirms, which is why every later solve was mined privately.
#67, #68 and #69 fall within ten weeks of each other, all three mined out of band.
#135 falls to RetiredCoder, the highest puzzle ever solved, using Kangaroo on its exposed public key.
"Finally I solved #135, it took about 5 months on 200 GPUs. It was… long. I quit, officially. Happy solving #140 without me."
#140 is the lowest unsolved target with an exposed public key. 77 puzzles remain, holding 903 BTC between them.
Dates, addresses and balances on this page were taken from
privatekeys.pw ↗
and can be re-checked against any Bitcoin node. Timeline and puzzle counts preserve the source site's September 22, 2026 snapshot.
07 / THE TREASURYHASH RESEARCH DIVISION +
Transparency
One wallet. Watch it.
One public Solana treasury will collect trading fees and pay for compute. Its address will be announced with the launch. The puzzle prizes stay on Bitcoin.
Project wallet
Fees arrive here. Compute is paid for from here. Both directions are on-chain.
SOLANA TREASURYAddress to be announcedPublished at launch
NetworkSolana
Trading pairHASH / BTC
MarketTo be announced
RoleCollects fees · pays for compute
First targetPuzzle #140, 14 BTC
Token
What this wallet is not
It does not hold a puzzle prize and it never will. A recovered key spends on Bitcoin,
not here, so if #140 is ever solved, the proof appears at
1QKBaU6WAeycb3DbKbLBkX7vJiaS8r42Xo
within seconds, on the most public ledger there is. You will not need this website to tell you.
Hash is an experiment. It does not promise a solve, a payout, or a schedule. The bounties are a
public race that anybody can win at any moment, including people who have never heard of this project.
Target changes and anything spent out of this wallet get posted on
@hashcracked on X ↗
08 / QUESTIONSHASH RESEARCH DIVISION +
Questions
The obvious objections.
Answered directly, including the ones without a comfortable answer.
Isn't taking these coins just theft?+
No. The creator built the puzzle as a public measurement of how much cracking power the world has, said
so on BitcoinTalk at the time, and has topped the prizes up twice since. The keys are meant to be found, and
whoever finds one spends it. It has been an open race with published rules for eleven years. This invitation applies to the published puzzles, not to ordinary wallets.
Why start at #140 instead of the cheaper-looking #71?+
Because #140 leaked its public key and #71 did not. In work terms they are almost the same target,
roughly 1021 operations each, but #140 pays 14 BTC instead of 7.1, and its work can be
split cleanly across rented machines. #71 stays on the board; it is simply worse value for the same
electricity.
What happens if somebody else solves it first?+
The tile turns, the hardware moves to the next target, and the board carries on. There are 77 of them
holding 903 BTC, and the five computable ones alone hold 75 BTC. This is the reason the project is not
named after a single puzzle.
Be honest, what are the odds?+
A hundred GPUs pointed at #140 would expect to spend decades. Ten thousand would expect months. That
gap is the entire argument for funding this with a fee stream instead of a fixed budget: the only lever
that matters is how much compute is running, and fees compound.
It is also why nobody should treat a solve as scheduled. Expected work is an estimate, not a deadline.
Every target on the board carries the exact figure, and luck moves a real run in both directions.
Why Solana?+
Hash will launch on Solana with a BTC-paired market. Trading fees are intended to fund the compute. The project wallet will be published there, so
the flow from trading activity to compute spending can be followed by anyone without a dashboard, an API
key, or our permission.
Can I contribute hardware?+
Not yet, in the sense that there is no pool to point a machine at. What already exists is the reporting
side of it: every rig the project runs publishes its own readings to the fleet panel above, so outside
hardware can be added the day the work-splitting side is ready without asking anybody to take a number on
trust. Changes get announced on
@hashcracked on X ↗.