In short.
In January 2015 somebody sent bitcoin to a long row of addresses and published the fact that their private keys were weak on purpose. Each key was drawn from a range one bit wider than the last. Anyone who guesses a key owns what sits at that address. Most of the low ones went within days. The high ones are still there, in the open, and the amount waiting on them is read from the chain at the top of this page. bithos is one coin and one machine aimed at that row. Every trade of the coin puts keys on the machine's account. The machine checks them, one after another, against the lowest address that is still unclaimed. A Mythos model decides which part of the range it works. Nothing here runs on a schedule and nothing here is simulated. This paper says what the machine does, shows its work as it happens, and is plain about the odds.
The transaction that started it has 256 outputs. The first paid 0.001 BTC to an address whose private key is the number 1. The second paid 0.002 BTC to an address whose key is 2 or 3. The pattern holds all the way up: the key for address n is a whole number from 2n-1 to 2n minus 1, chosen at random inside that range and never published. Only the first 160 matter, because a bitcoin address is 160 bits long and nothing past that is any harder.
The amounts have been raised since, and some addresses have been emptied by the people who found their keys. This page does not keep its own list of which is which. It reads every one of the 160 balances from the chain and draws what it finds.
An address is the hash of a public key, and a public key is a point computed from the private key. If all you have is the address, there is no shortcut. You pick a number, compute its point, hash it, and compare. That is one guess, and the only way to do better is to make more guesses.
If the public key itself is known, the problem changes shape. The point can be attacked directly with a method that needs roughly the square root of the range in work, which is why some very high addresses have fallen while lower ones stand. The amber cells above are the ones exposed that way. bithos does not work on those. It works the pale ones, lowest first, because that is where plain counting applies and where every key checked is a key nobody ever has to check again.
The target is the lowest numbered address that still holds bitcoin and has never spent. The machine does not have this written down. It works it out from the balances each time they are read, and if someone else claims the target tomorrow the next one up becomes the target without anyone touching the site.
| Puzzle | |
| Address | |
| Hash160 | |
| Lowest key | |
| Highest key | |
| Keys in range | |
| Prize | |
| Prize today | |
| Checked so far | |
| Share of range checked |
The machine does no work of its own accord. Every swap of the coin, buy or sell, on the curve or on the pool, adds keys to an account of work owed. The rate is fixed in the build and is the same for everyone.
A ten dollar trade owes 2,560 keys. A thousand dollar trade owes 256,000. The machine pays the account down as fast as it is able and stops when the account is empty. A coin nobody trades is a machine that checks nothing, and the count at the top of the page stands still until somebody trades again.
The range of the target is cut into 4,096 sectors of equal width, and each sector into chunks of 1,024 keys in a row. A chunk is the unit of work. The scanner takes the first key of a chunk, computes its point on the curve, and then walks forward one key at a time by adding the generator point, which is far cheaper than starting each key from nothing. Each point becomes a 33 byte public key, then a SHA-256 digest, then a RIPEMD-160 digest, and that last value is compared with the 20 bytes inside the target address. Equal means found.
Where a sector starts is not chosen by the site. The first time a sector is opened, its starting chunk is taken from the hash of the Solana transaction signature of the newest trade at that moment. From there it goes forward one chunk at a time. Nobody, including the people who built this, picked the keys it checks.
Which sector the scanner works is decided by a Mythos model. It is not consulted on a timer. It is called each time the work owed since its last call passes 220 keys, which is 4,096 dollars of trading at the rate above. It is shown the state of the hunt: the range, what has been covered, the rate, the prize. It answers with one sector number and a note of at most 280 characters. A few lines of ordinary code check that the number is a whole number from 0 to 4,095, and if it is not, the answer is thrown away, the refusal is recorded, and the sector is taken from the hash of the newest trade instead.
It should be said clearly that the model cannot find the key by thinking. Every unchecked key is exactly as likely as every other, and the model is told so. What it does is keep the search spread out and keep a written record of why the machine looked where it looked.
A chunk that finds nothing still leaves a mark. For every chunk the scanner records the one key whose address hash agreed with the target for the most leading bits before parting ways. This is not progress toward the key and nobody should read it as warmth. Hashes do not work that way. It is here because it can be checked: take the key in the table, derive its hash yourself, and count the matching bits. If they agree with what is printed, the machine did the work it says it did.
| CHUNK | KEY | ITS HASH160 | BITS |
|---|
The key is one number among 2N-1. Checking them all at the rate this machine has actually managed would take the time in the first row. The other rows are the same sum at rates the machine does not have, for scale. On average the key turns up halfway through, so halve any figure if you are feeling hopeful.
| RATE | KEYS PER SECOND | YEARS TO CHECK THE WHOLE RANGE |
|---|---|---|
| this machine, measured | ||
| one million | 1,000,000 | |
| one billion | 1,000,000,000 | |
| one trillion | 1,000,000,000,000 |
Those numbers are the honest shape of this. The bounty has stood for more than a decade because the arithmetic is on its side. bithos is a public attempt, counted in the open, and anyone telling you it is likely to win has not read this table.
The scanner stops on that address at once and moves to the next target. The key is written to a table that no browser can read and that this site never serves. The cell in the row above turns black. The site itself spends nothing and broadcasts nothing.
There is a reason for the care. The moment anyone spends from one of these addresses, the public key appears in the waiting transaction, and for a key this short a machine watching the network can recover the private key from it and race the finder with a transaction of its own. Finders have lost prizes that way. A claim has to go to a miner privately or it is a gift to whoever is watching.
It is not a mining pool and it pays nobody for work. It is not a promise that anything will be found. It is not affiliated with whoever funded the puzzle, with Anthropic, or with any model maker; the model's name is used because that is the model the machine calls. It does not attack anyone's wallet: these addresses were published as a challenge by the person who funded them, with keys made weak for the purpose. And it is not advice about the coin. The machine guarantees that trades become checked keys at a fixed rate. It guarantees nothing about what anyone will pay.
None of this depends on believing the page.
| The coin | ||
| The puzzle transaction | 08389f34c98c606322740c0be6a7125d9860bb8d5cb182c02f98461e5fa6cd15 | MEMPOOL |
| The target address | ||
| Bitcoin price source | ||
| Self test |
Each row is one swap of the coin and the work it put on the account. Newest first.
| TIME | SIDE | SIZE | KEYS OWED | WALLET | TRANSACTION |
|---|