Found an Arithmetic Relationship in secp256k1's G.x

17 replies 97 views
im_whaleMember
Posts: 9 · Reputation: 94
#1Mar 12, 2025, 11:39 AM
Hey all, Did some digging into secp256k1 and stumbled upon this cool arithmetic relationship for the x-coordinate of the generator G: G.x = 27·(k₀·d' + r') where - D = 2³² + 977 - d' = D/27 = 159072899 - r' = (G.x % D)/27 = 15460270 - k₀ = 346169984758229267385003896202133930596503452506876071803407489043052 Seems like the odds of this being random are less than 1 in 10 billion. I checked out the first 2000 multiples of G and guess what? Only for k=1 does `(x//27)%d' == r'` hold.
4 Reply Quote Share
boss2009Newbie
Posts: 20 · Reputation: 15
#2Mar 12, 2025, 04:11 PM
I went all out testing, from 1 to 10 million. Range: 1 to 10000000. Hits: 371005. That's around 3.71%.
1 Reply Quote Share
Posts: 2 · Reputation: 211
#3Mar 14, 2025, 03:44 AM
Not sure why you think this is groundbreaking. It just shows how the math works with the curve. You could swap in different numbers and it’d be similar.
4 Reply Quote Share
falcon2019Full Member
Posts: 90 · Reputation: 425
#4Mar 14, 2025, 08:59 AM
Nah, that’s overthinking it. OP just found that G.x is a multiple of 27, which means it shows up about 3.71% of the time. No need to complicate things with advanced math.
1 Reply Quote Share
im_whaleMember
Posts: 9 · Reputation: 94
#5Mar 14, 2025, 10:54 AM
Appreciate your thoughts but the fact that G.x is divisible by 27 doesn’t imply it’s trivial. There’s more context. Let me break it down: - D is chosen to be divisible by 27. - d' is a legit integer. - r' is derived straightforwardly from G.x.
0 Reply Quote Share
falcon2019Full Member
Posts: 90 · Reputation: 425
#6Mar 14, 2025, 02:23 PM
Nope, your ‘discovery’ is basically saying G.x is divisible by 27 because you picked 27 deliberately since D is also divisible by it. Your r' is just a byproduct, so it’s not surprising that G.x satisfies the equation.
0 Reply Quote Share
im_whaleMember
Posts: 9 · Reputation: 94
#7Mar 14, 2025, 03:54 PM
Let’s clarify. We know: - `D = 2³² + 977` - `d' = D/27` - `r' = (G.x % D) / 27` Now, G.x follows this integer equation: G.x = 27 * (k₀·d' + r') This isn’t just a coincidence; it’s a specific integer equation tied directly to G.
3 Reply Quote Share
falcon2019Full Member
Posts: 90 · Reputation: 425
#8Mar 14, 2025, 08:14 PM
First, D is a constant and divisible by 27, that’s 100%. Also, if two numbers share a factor, their mod will always divide. This math has been known forever.
3 Reply Quote Share
im_whaleMember
Posts: 9 · Reputation: 94
#9Mar 15, 2025, 01:14 AM
True, but let’s not sidestep the fact that 15460270 is actually a 24-bit number, not 27-bit as you said. Good catch. Also, you are right. It's misleading to imply D’s divisibility by 27 relates to a 1/27 probability without context.
3 Reply Quote Share
falcon2019Full Member
Posts: 90 · Reputation: 425
#10Mar 15, 2025, 04:27 AM
Nah, it’s still 1 in 27, always. Just pick any integer and you’ll see that any of them will show this rule. This is true regardless of the curve.
0 Reply Quote Share
im_whaleMember
Posts: 9 · Reputation: 94
#11Mar 17, 2025, 07:47 AM
Wait, so if x is a multiple of 27, then that x % D scenario automatically applies. So both conditions aren’t independent. That means finding integers fitting both just depends on the first.
2 Reply Quote Share
falcon2019Full Member
Posts: 90 · Reputation: 425
#12Mar 17, 2025, 01:34 PM
I still don’t see your point. Just select any point where x % 27 == 0, compute an r', and claim it's special because it fits this equation. What's stopping you from doing that for any point?
1 Reply Quote Share
im_whaleMember
Posts: 9 · Reputation: 94
#13Mar 17, 2025, 03:39 PM
Come on, this is just nonsense. You could create similar claims for any random point. It loses its meaning here. G does have unique properties, but not in the way OP is pushing.
4 Reply Quote Share
falcon2019Full Member
Posts: 90 · Reputation: 425
#14Mar 19, 2025, 05:40 AM
I've scanned up to 100 billion points, looking for patterns or anomalies. The results were just random. Nothing stood out, all seemed typical to me.
2 Reply Quote Share
Posts: 110 · Reputation: 19
#15Mar 20, 2025, 10:02 PM
+1 for hitting 100 billion, but it seems like just randomness in the curve.
3 Reply Quote Share
boss2009Newbie
Posts: 20 · Reputation: 15
#16Mar 21, 2025, 03:53 AM
Got to agree, it’s not groundbreaking stuff, just math as it is.
2 Reply Quote Share
Posts: 3523 · Reputation: 35
#17Mar 21, 2025, 04:31 AM
Any chance you can share more details on your findings? Sounds interesting.
2 Reply Quote Share
Posts: 3523 · Reputation: 35
#18Mar 21, 2025, 05:01 PM
Can you guys back up your claims with math? Or is it just a feeling?
4 Reply Quote Share

Related topics