One of the 160 puzzle addresses created in 2015 to show how hard it is to guess a Bitcoin private key. This one still stands, with 15.5001 BTC (about $1,012,452) waiting for whoever finds the key.
1AoeP37TmHdFh8uN72fu9AqgtLrUwcv2wJThe private key of this address is a number between 2154 and 2155, which is 2.3 × 1046 possible keys. In hex, the range looks like this:
4000000000000000000000000000000000000007fffffffffffffffffffffffffffffffffffffffffffffffFor scale: one modern GPU checking about a billion keys per second would need about 1030 years to sweep this entire range.
The creator deliberately revealed the public key of this address. That changes the math completely: with a known public key, Pollard's kangaroo algorithm cuts the search to roughly the square root of the range, and a future quantum computer running Shor's algorithm could derive the private key outright. This is exactly why puzzles like this one act as an early warning system, a quantum canary for Bitcoin.
035cd1854cae45391ca4ec428cc7e6c7d9984424b954209a8eea197b9e364c05f6This demo samples random keys inside the exact range of this puzzle, right in your browser. Every candidate is real, but at JavaScript speed the odds of landing on the key are astronomically small. It exists to give you a feel for the scale, not to win the prize. Dedicated GPU tools scan roughly a thousand times faster, and the full table on the home page explains what to do in the absurdly lucky case that a search actually hits.
In 2015, an anonymous user created 160 Bitcoin addresses and funded them with about 1000 BTC in total. Each address hides its private key in a range that doubles with every puzzle number: puzzle 1 uses a 1 bit range, puzzle 160 a 160 bit range. Puzzle 155 sits at the 155 bit mark, so its key is one of 2.3 × 1046 candidates.
Nobody has claimed this prize yet, but this puzzle is special: its public key is out in the open. Kangaroo style solvers can attack it with square root effort, and a sufficiently capable quantum computer could break it outright with Shor's algorithm. If this puzzle and its exposed key neighbors all fall within a short window, that is the clearest public signal available that practical quantum attacks on Bitcoin have arrived.
The whole series is best understood as a public experiment, not a hacking contest. These coins were placed on purpose to be found, and the solved and unsolved puzzles together map the exact frontier of what today's hardware can do against Bitcoin's cryptography. Guessing the key of a normal wallet remains astronomically out of reach: a real 256 bit key has a keyspace about 1029 times larger than even puzzle 160. Read more about the math and the quantum angle in the FAQ on the main page.