Found an Arithmetic Relationship in secp256k1's G.x

17 replies 286 views
im_whaleMember
Posts: 9 · Reputation: 94
#1Mar 12, 2025, 11:39 AM
Hey all, Did some digging into secp256k1 and stumbled upon this cool arithmetic relationship for the x-coordinate of the generator G: G.x = 27·(k₀·d' + r') where - D = 2³² + 977 - d' = D/27 = 159072899 - r' = (G.x % D)/27 = 15460270 - k₀ = 346169984758229267385003896202133930596503452506876071803407489043052 Seems like the odds of this being random are less than 1 in 10 billion. I checked out the first 2000 multiples of G and guess what? Only for k=1 does `(x//27)%d' == r'` hold.
6 Reply Quote Share
boss2009Newbie
Posts: 20 · Reputation: 15
#2Mar 12, 2025, 04:11 PM
I went all out testing, from 1 to 10 million. Range: 1 to 10000000. Hits: 371005. That's around 3.71%.
4 Reply Quote Share
Posts: 2 · Reputation: 211
#3Mar 14, 2025, 03:44 AM
Not sure why you think this is groundbreaking. It just shows how the math works with the curve. You could swap in different numbers and it’d be similar.
10 Reply Quote Share
falcon2019Full Member
Posts: 93 · Reputation: 425
#4Mar 14, 2025, 08:59 AM
Nah, that’s overthinking it. OP just found that G.x is a multiple of 27, which means it shows up about 3.71% of the time. No need to complicate things with advanced math.
4 Reply Quote Share
im_whaleMember
Posts: 9 · Reputation: 94
#5Mar 14, 2025, 10:54 AM
Appreciate your thoughts but the fact that G.x is divisible by 27 doesn’t imply it’s trivial. There’s more context. Let me break it down: - D is chosen to be divisible by 27. - d' is a legit integer. - r' is derived straightforwardly from G.x.
7 Reply Quote Share
falcon2019Full Member
Posts: 93 · Reputation: 425
#6Mar 14, 2025, 02:23 PM
Nope, your ‘discovery’ is basically saying G.x is divisible by 27 because you picked 27 deliberately since D is also divisible by it. Your r' is just a byproduct, so it’s not surprising that G.x satisfies the equation.
5 Reply Quote Share
im_whaleMember
Posts: 9 · Reputation: 94
#7Mar 14, 2025, 03:54 PM
Let’s clarify. We know: - `D = 2³² + 977` - `d' = D/27` - `r' = (G.x % D) / 27` Now, G.x follows this integer equation: G.x = 27 * (k₀·d' + r') This isn’t just a coincidence; it’s a specific integer equation tied directly to G.
6 Reply Quote Share
falcon2019Full Member
Posts: 93 · Reputation: 425
#8Mar 14, 2025, 08:14 PM
First, D is a constant and divisible by 27, that’s 100%. Also, if two numbers share a factor, their mod will always divide. This math has been known forever.
6 Reply Quote Share
im_whaleMember
Posts: 9 · Reputation: 94
#9Mar 15, 2025, 01:14 AM
True, but let’s not sidestep the fact that 15460270 is actually a 24-bit number, not 27-bit as you said. Good catch. Also, you are right. It's misleading to imply D’s divisibility by 27 relates to a 1/27 probability without context.
4 Reply Quote Share
falcon2019Full Member
Posts: 93 · Reputation: 425
#10Mar 15, 2025, 04:27 AM
Nah, it’s still 1 in 27, always. Just pick any integer and you’ll see that any of them will show this rule. This is true regardless of the curve.
4 Reply Quote Share
im_whaleMember
Posts: 9 · Reputation: 94
#11Mar 17, 2025, 07:47 AM
Wait, so if x is a multiple of 27, then that x % D scenario automatically applies. So both conditions aren’t independent. That means finding integers fitting both just depends on the first.
4 Reply Quote Share
falcon2019Full Member
Posts: 93 · Reputation: 425
#12Mar 17, 2025, 01:34 PM
I still don’t see your point. Just select any point where x % 27 == 0, compute an r', and claim it's special because it fits this equation. What's stopping you from doing that for any point?
9 Reply Quote Share
im_whaleMember
Posts: 9 · Reputation: 94
#13Mar 17, 2025, 03:39 PM
Come on, this is just nonsense. You could create similar claims for any random point. It loses its meaning here. G does have unique properties, but not in the way OP is pushing.
10 Reply Quote Share
falcon2019Full Member
Posts: 93 · Reputation: 425
#14Mar 19, 2025, 05:40 AM
I've scanned up to 100 billion points, looking for patterns or anomalies. The results were just random. Nothing stood out, all seemed typical to me.
4 Reply Quote Share
Posts: 117 · Reputation: 19
#15Mar 20, 2025, 10:02 PM
+1 for hitting 100 billion, but it seems like just randomness in the curve.
9 Reply Quote Share
boss2009Newbie
Posts: 20 · Reputation: 15
#16Mar 21, 2025, 03:53 AM
Got to agree, it’s not groundbreaking stuff, just math as it is.
5 Reply Quote Share
Posts: 3546 · Reputation: 35
#17Mar 21, 2025, 04:31 AM
Any chance you can share more details on your findings? Sounds interesting.
8 Reply Quote Share
Posts: 3546 · Reputation: 35
#18Mar 21, 2025, 05:01 PM
Can you guys back up your claims with math? Or is it just a feeling?
8 Reply Quote Share

Related topics