One of the 160 puzzle addresses created in 2015 to show how hard it is to guess a Bitcoin private key. This one still stands, with 15 BTC (about $979,756) waiting for whoever finds the key.
1MUJSJYtGPVGkBCTqGspnxyHahpt5Te8jyThe private key of this address is a number between 2149 and 2150, which is 7.1 × 1044 possible keys. In hex, the range looks like this:
200000000000000000000000000000000000003fffffffffffffffffffffffffffffffffffffffffffFor scale: one modern GPU checking about a billion keys per second would need about 1028 years to sweep this entire range.
The creator deliberately revealed the public key of this address. That changes the math completely: with a known public key, Pollard's kangaroo algorithm cuts the search to roughly the square root of the range, and a future quantum computer running Shor's algorithm could derive the private key outright. This is exactly why puzzles like this one act as an early warning system, a quantum canary for Bitcoin.
03137807790ea7dc6e97901c2bc87411f45ed74a5629315c4e4b03a0a102250c49This demo samples random keys inside the exact range of this puzzle, right in your browser. Every candidate is real, but at JavaScript speed the odds of landing on the key are astronomically small. It exists to give you a feel for the scale, not to win the prize. Dedicated GPU tools scan roughly a thousand times faster, and the full table on the home page explains what to do in the absurdly lucky case that a search actually hits.
In 2015, an anonymous user created 160 Bitcoin addresses and funded them with about 1000 BTC in total. Each address hides its private key in a range that doubles with every puzzle number: puzzle 1 uses a 1 bit range, puzzle 160 a 160 bit range. Puzzle 150 sits at the 150 bit mark, so its key is one of 7.1 × 1044 candidates.
Nobody has claimed this prize yet, but this puzzle is special: its public key is out in the open. Kangaroo style solvers can attack it with square root effort, and a sufficiently capable quantum computer could break it outright with Shor's algorithm. If this puzzle and its exposed key neighbors all fall within a short window, that is the clearest public signal available that practical quantum attacks on Bitcoin have arrived.
The whole series is best understood as a public experiment, not a hacking contest. These coins were placed on purpose to be found, and the solved and unsolved puzzles together map the exact frontier of what today's hardware can do against Bitcoin's cryptography. Guessing the key of a normal wallet remains astronomically out of reach: a real 256 bit key has a keyspace about 1029 times larger than even puzzle 160. Read more about the math and the quantum angle in the FAQ on the main page.