hash® SOLANA / BTC
A FEE-FUNDED BITCOIN EXPERIMENTPUBLIC KEYS. OPEN POSSIBILITIES.

HASH

[ EVERY KEY IS A POSSIBILITY ]

Locked in Bitcoin.
Unlocked by compute.

77 unsolved puzzles. 903 BTC waiting.
Hash turns trading fees into the GPU power searching for the keys.

EXPLORE THE TARGETS See how it works
An exploded metal padlock showing its cylinder, springs, and orange core
FEES COMPUTE SEARCH MATCH01 / EXPLORE THE UNKNOWN
UNSOLVED TARGETS77

Puzzles #71 through #160

BTC UNCLAIMED903

Publicly verifiable prizes

COMPUTABLE PUZZLES05

75 BTC behind exposed public keys

FUNDED ADDRESS DATABASE100M+

Addresses checked during the search

01 / THE IDEAHASH RESEARCH DIVISION +
The setup

Real Bitcoin, locked behind arithmetic.

Three facts explain the entire project. None of them require you to trust anybody, including us.

01

Someone hid keys on purpose

In January 2015, a person known as saatoshi_rising funded 160 Bitcoin addresses in one transaction. The private key of puzzle #1 sat in a 1-bit range, #2 in a 2-bit range, and every step after that doubled. Puzzles up to #70 have all been cracked. In April 2023 the creator multiplied the remaining prizes by ten, which is why #140 now holds 14 BTC. Those coins have never moved.

02

Five of them leaked the shape of the answer

An address is only a hash of a public key, so normally you learn nothing from it. But in May 2019 the creator spent 1,000 satoshis out of #140, #145, #150, #155 and #160, and a spend publishes the public key. With that key in hand the hunt stops being a guessing game and becomes a computation: about the square root of the range instead of the whole range.

03

Compute is the only input

There is no product here and nothing to believe in. Trading fees land in one public wallet, that wallet buys GPU hours, and those hours walk a keyspace. If a key falls out, the Bitcoin is real and the transaction is visible to everyone at the same moment. If it doesn't, the wallet still shows exactly where every dollar went.

02 / THE ENGINEHASH RESEARCH DIVISION +
Fee engine

Fees in, keyspace out.

Five steps. Every one of them is something an outsider can check, which is the only reason to lay it out like this.

Trades happen

The HASH/BTC pair will launch on Solana. Its trading fees are intended to fund the project's compute.

Fees pool in public

Fees will settle in a public Solana treasury. The address will be published with launch details.

Fees become GPU hours

The balance is spent on rented compute, priced in GPU-hours. Nothing is manufactured; hardware is bought at market rate.

Compute takes a slice

Each worker gets a slice of the target's interval and walks it with Kangaroo, or hashes it blind on the targets that never leaked a key.

A collision ends it

Two herds land on the same point, the private key drops out of the difference, and the coins move on Bitcoin in front of everybody.

Follow the evidence. Puzzle addresses can be checked against a public Bitcoin node. Fleet readings retain their source timestamps. Hash's Solana treasury and HASH/BTC market details will be published at launch.
03 / COMPUTEHASH RESEARCH DIVISION +
Compute telemetry

Inside the compute.

Every generated wallet is checked against a 100M+ entry Bloom filter containing funded addresses, including all unsolved BTC Puzzle wallets. Recovered BTC is intended to be converted to SOL on Solana to fund additional GPUs and buybacks for the HASH/BTC pair. The readings below preserve the source project's public hardware data.

Loading source telemetry
Fleet throughput 0
GPUs online 0
Wallets generated per second 0 reported across the source fleet
Fleet throughput
04 / TARGET ARCHIVEHASH RESEARCH DIVISION +
The board

77 unsolved targets.

Every tile is a live Bitcoin address. Open one for its exact key range, the attack it allows, and a balance check straight from a public node. Source snapshot 2026-09-22; check an address for its current balance.

Orange tiles leaked a public key in 2019 and can be attacked with Kangaroo. Everything else has to be brute-forced, which is why the bounty on a tile tells you almost nothing about how hard it is.

05 / THE MATHEMATICSHASH RESEARCH DIVISION +
Why only five

Hunting versus computing.

A scaled illustration of Pollard's Kangaroo: two deterministic walks share a path when they reach the same point. This is an explainer, not a live key search.

Pollard's Kangaroo · scaled interval 0 hops
SHARED HOP RULE / TWO STARTING POINTS
tame herd, known start wild herd, starts on the target stored distinguished point status: herds walking

A blind puzzle leaves you one move: pick a key, hash it, compare it to the address, repeat. #71 hides its key somewhere in 270 candidates, so you expect to try about 590 billion billion of them before one matches.

A puzzle with an exposed public key gives you geometry instead. Kangaroo releases two herds onto the interval, and the length of every hop is decided by wherever that kangaroo currently stands. The moment one herd lands on a point the other already visited, both follow the identical path forever, and the gap between where they started is the private key. The work collapses to roughly the square root of the interval.

#135 fell exactly this way in July 2026, after the solver known as RetiredCoder spent about five months on 200 GPUs. #140 is the next rung on the same ladder, and it is where Hash starts.

#71 · blind 5.9 × 1020

hashes expected. 270 range, no public key, no shortcut of any kind.

#140 · computable 9.6 × 1020

hops expected. A range 269 times larger, for 1.6× the work.

06 / THE RECORDHASH RESEARCH DIVISION +
Track record

Eleven years of this puzzle.

Nothing about the puzzle is speculative. It has a transaction history, a body of solvers, and a frontier that keeps moving.

  • 160 addresses funded in a single transaction, each private key placed in a range twice the size of the one before it.

  • The creator sweeps addresses #161–#256 back into the lower ones, raising every remaining prize.

  • The event this project depends on. 1,000 satoshis are spent out of #65, #70 and every fifth address up to #160. Each spend publishes that address's public key, which turned #140, #145, #150, #155 and #160 into computable targets.

  • Every unsolved prize is multiplied by ten. #140 becomes 14 BTC, #160 becomes 16 BTC.

  • #66 falls. The winning transaction is broadcast into the public mempool and most of the 6.6 BTC is replaced out from under the solver before it confirms, which is why every later solve was mined privately.

  • #67, #68 and #69 fall within ten weeks of each other, all three mined out of band.

  • #135 falls to RetiredCoder, the highest puzzle ever solved, using Kangaroo on its exposed public key.

    "Finally I solved #135, it took about 5 months on 200 GPUs. It was… long. I quit, officially. Happy solving #140 without me."
  • #140 is the lowest unsolved target with an exposed public key. 77 puzzles remain, holding 903 BTC between them.

Dates, addresses and balances on this page were taken from privatekeys.pw ↗ and can be re-checked against any Bitcoin node. Timeline and puzzle counts preserve the source site's September 22, 2026 snapshot.

07 / THE TREASURYHASH RESEARCH DIVISION +
Transparency

One wallet. Watch it.

One public Solana treasury will collect trading fees and pay for compute. Its address will be announced with the launch. The puzzle prizes stay on Bitcoin.

Project wallet

Fees arrive here. Compute is paid for from here. Both directions are on-chain.

SOLANA TREASURYAddress to be announcedPublished at launch
NetworkSolana
Trading pairHASH / BTC
MarketTo be announced
RoleCollects fees · pays for compute
First targetPuzzle #140, 14 BTC

What this wallet is not

It does not hold a puzzle prize and it never will. A recovered key spends on Bitcoin, not here, so if #140 is ever solved, the proof appears at 1QKBaU6WAeycb3DbKbLBkX7vJiaS8r42Xo within seconds, on the most public ledger there is. You will not need this website to tell you.


Hash is an experiment. It does not promise a solve, a payout, or a schedule. The bounties are a public race that anybody can win at any moment, including people who have never heard of this project.

Target changes and anything spent out of this wallet get posted on @hashcracked on X ↗

08 / QUESTIONSHASH RESEARCH DIVISION +
Questions

The obvious objections.

Answered directly, including the ones without a comfortable answer.

Isn't taking these coins just theft?

No. The creator built the puzzle as a public measurement of how much cracking power the world has, said so on BitcoinTalk at the time, and has topped the prizes up twice since. The keys are meant to be found, and whoever finds one spends it. It has been an open race with published rules for eleven years. This invitation applies to the published puzzles, not to ordinary wallets.

Why start at #140 instead of the cheaper-looking #71?

Because #140 leaked its public key and #71 did not. In work terms they are almost the same target, roughly 1021 operations each, but #140 pays 14 BTC instead of 7.1, and its work can be split cleanly across rented machines. #71 stays on the board; it is simply worse value for the same electricity.

What happens if somebody else solves it first?

The tile turns, the hardware moves to the next target, and the board carries on. There are 77 of them holding 903 BTC, and the five computable ones alone hold 75 BTC. This is the reason the project is not named after a single puzzle.

Be honest, what are the odds?

A hundred GPUs pointed at #140 would expect to spend decades. Ten thousand would expect months. That gap is the entire argument for funding this with a fee stream instead of a fixed budget: the only lever that matters is how much compute is running, and fees compound.

It is also why nobody should treat a solve as scheduled. Expected work is an estimate, not a deadline. Every target on the board carries the exact figure, and luck moves a real run in both directions.

Why Solana?

Hash will launch on Solana with a BTC-paired market. Trading fees are intended to fund the compute. The project wallet will be published there, so the flow from trading activity to compute spending can be followed by anyone without a dashboard, an API key, or our permission.

Can I contribute hardware?

Not yet, in the sense that there is no pool to point a machine at. What already exists is the reporting side of it: every rig the project runs publishes its own readings to the fleet panel above, so outside hardware can be added the day the work-splitting side is ready without asking anybody to take a number on trust. Changes get announced on @hashcracked on X ↗.

TARGET SPECIFICATION