BITHOS
Mythos, pointed at the oldest unclaimed bounty in bitcoin.
THE COIN
BITCOIN
PRICE
HOLDERS
24H VOLUME
TRADES SEEN
KEYS OWED
KEYS CHECKED
PRIZE IN SIGHT

In short.

In January 2015 somebody sent bitcoin to a long row of addresses and published the fact that their private keys were weak on purpose. Each key was drawn from a range one bit wider than the last. Anyone who guesses a key owns what sits at that address. Most of the low ones went within days. The high ones are still there, in the open, and the amount waiting on them is read from the chain at the top of this page. bithos is one coin and one machine aimed at that row. Every trade of the coin puts keys on the machine's account. The machine checks them, one after another, against the lowest address that is still unclaimed. A Mythos model decides which part of the range it works. Nothing here runs on a schedule and nothing here is simulated. This paper says what the machine does, shows its work as it happens, and is plain about the odds.


The bounty

The transaction that started it has 256 outputs. The first paid 0.001 BTC to an address whose private key is the number 1. The second paid 0.002 BTC to an address whose key is 2 or 3. The pattern holds all the way up: the key for address n is a whole number from 2n-1 to 2n minus 1, chosen at random inside that range and never published. Only the first 160 matter, because a bitcoin address is 160 bits long and nothing past that is any harder.

The amounts have been raised since, and some addresses have been emptied by the people who found their keys. This page does not keep its own list of which is which. It reads every one of the 160 balances from the chain and draws what it finds.

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160
CLAIMEDOPEN, ADDRESS ONLYOPEN, PUBLIC KEY KNOWNTHE TARGETFOUND HERE
All 160 addresses in order, colored by what the chain says about each one right now. Grey has been emptied. Pale is open with nothing known but the address. Amber is open and has spent once, which put its public key on the chain.
OPEN ADDRESSES
CLAIMED
BITCOIN STILL WAITING
WORTH TODAY

Two kinds of open address

An address is the hash of a public key, and a public key is a point computed from the private key. If all you have is the address, there is no shortcut. You pick a number, compute its point, hash it, and compare. That is one guess, and the only way to do better is to make more guesses.

If the public key itself is known, the problem changes shape. The point can be attacked directly with a method that needs roughly the square root of the range in work, which is why some very high addresses have fallen while lower ones stand. The amber cells above are the ones exposed that way. bithos does not work on those. It works the pale ones, lowest first, because that is where plain counting applies and where every key checked is a key nobody ever has to check again.

The target

The target is the lowest numbered address that still holds bitcoin and has never spent. The machine does not have this written down. It works it out from the balances each time they are read, and if someone else claims the target tomorrow the next one up becomes the target without anyone touching the site.

Puzzle
Address
Hash160
Lowest key
Highest key
Keys in range
Prize
Prize today
Checked so far
Share of range checked

Why trades

The machine does no work of its own accord. Every swap of the coin, buy or sell, on the curve or on the pool, adds keys to an account of work owed. The rate is fixed in the build and is the same for everyone.

owed = floor( usd × 256 )

A ten dollar trade owes 2,560 keys. A thousand dollar trade owes 256,000. The machine pays the account down as fast as it is able and stops when the account is empty. A coin nobody trades is a machine that checks nothing, and the count at the top of the page stands still until somebody trades again.

The scanner

The range of the target is cut into 4,096 sectors of equal width, and each sector into chunks of 1,024 keys in a row. A chunk is the unit of work. The scanner takes the first key of a chunk, computes its point on the curve, and then walks forward one key at a time by adding the generator point, which is far cheaper than starting each key from nothing. Each point becomes a 33 byte public key, then a SHA-256 digest, then a RIPEMD-160 digest, and that last value is compared with the 20 bytes inside the target address. Equal means found.

Where a sector starts is not chosen by the site. The first time a sector is opened, its starting chunk is taken from the hash of the Solana transaction signature of the newest trade at that moment. From there it goes forward one chunk at a time. Nobody, including the people who built this, picked the keys it checks.

The whole range of the target, left to right. Each mark is a sector the scanner has opened, darker with more chunks done. The black mark is the sector it is working now.
SECTORS OPENED
CHUNKS DONE
KEYS PER SECOND
WORKING SECTOR

The director

Which sector the scanner works is decided by a Mythos model. It is not consulted on a timer. It is called each time the work owed since its last call passes 220 keys, which is 4,096 dollars of trading at the rate above. It is shown the state of the hunt: the range, what has been covered, the rate, the prize. It answers with one sector number and a note of at most 280 characters. A few lines of ordinary code check that the number is a whole number from 0 to 4,095, and if it is not, the answer is thrown away, the refusal is recorded, and the sector is taken from the hash of the newest trade instead.

It should be said clearly that the model cannot find the key by thinking. Every unchecked key is exactly as likely as every other, and the model is told so. What it does is keep the search spread out and keep a written record of why the machine looked where it looked.

LATEST NOTE

The nearest miss

A chunk that finds nothing still leaves a mark. For every chunk the scanner records the one key whose address hash agreed with the target for the most leading bits before parting ways. This is not progress toward the key and nobody should read it as warmth. Hashes do not work that way. It is here because it can be checked: take the key in the table, derive its hash yourself, and count the matching bits. If they agree with what is printed, the machine did the work it says it did.

CHUNKKEYITS HASH160BITS

The odds, stated plainly

The key is one number among 2N-1. Checking them all at the rate this machine has actually managed would take the time in the first row. The other rows are the same sum at rates the machine does not have, for scale. On average the key turns up halfway through, so halve any figure if you are feeling hopeful.

RATEKEYS PER SECONDYEARS TO CHECK THE WHOLE RANGE
this machine, measured
one million1,000,000
one billion1,000,000,000
one trillion1,000,000,000,000

Those numbers are the honest shape of this. The bounty has stood for more than a decade because the arithmetic is on its side. bithos is a public attempt, counted in the open, and anyone telling you it is likely to win has not read this table.

If the key is found

The scanner stops on that address at once and moves to the next target. The key is written to a table that no browser can read and that this site never serves. The cell in the row above turns black. The site itself spends nothing and broadcasts nothing.

There is a reason for the care. The moment anyone spends from one of these addresses, the public key appears in the waiting transaction, and for a key this short a machine watching the network can recover the private key from it and race the finder with a transaction of its own. Finders have lost prizes that way. A claim has to go to a miner privately or it is a gift to whoever is watching.

What bithos is not

It is not a mining pool and it pays nobody for work. It is not a promise that anything will be found. It is not affiliated with whoever funded the puzzle, with Anthropic, or with any model maker; the model's name is used because that is the model the machine calls. It does not attack anyone's wallet: these addresses were published as a challenge by the person who funded them, with keys made weak for the purpose. And it is not advice about the coin. The machine guarantees that trades become checked keys at a fixed rate. It guarantees nothing about what anyone will pay.

On the public record

None of this depends on believing the page.

The coin
The puzzle transaction08389f34c98c606322740c0be6a7125d9860bb8d5cb182c02f98461e5fa6cd15MEMPOOL
The target address
Bitcoin price source
Self test

Every trade

Each row is one swap of the coin and the work it put on the account. Newest first.

TIMESIDESIZEKEYS OWEDWALLETTRANSACTION