Potential Exploit in BTC Puzzle Pools

4 replies 69 views
nova69Member
Posts: 72 · Reputation: 174
#1Jan 21, 2024, 11:16 AM
So I’ve been looking at this BTC puzzle thing. You know, trying to find a private key for an address. I noticed some pools, like ttdsales, seem to work like mining. They generate random addresses and you have to submit something related to the private key. But here’s the catch what if someone managed to crack the client and submit answers without actually solving the puzzle? That could lead to way more rewards and mess up the whole pool system!
5 Reply Quote Share
mr_byteSenior Member
Posts: 10 · Reputation: 1059
#2Jan 21, 2024, 12:17 PM
Only the puzzle creator knows the private key, right? Seems a bit too boring for them to exploit it personally though. I mean, who has that much time? But yeah, if the pool gets rekt because of this, it’s not cool.
4 Reply Quote Share
nova69Member
Posts: 72 · Reputation: 174
#3Jan 22, 2024, 11:08 PM
You don’t even have to know the actual answer. They give you a range with a ton of keys, but the address they generate might not even be the answer. If you just submit your work once you find the private key without scanning the rest of the range, you could snag more rewards. Like, if you get a certain range and the pool address matches, you’re golden.
3 Reply Quote Share
mr_byteSenior Member
Posts: 10 · Reputation: 1059
#4Jan 23, 2024, 02:52 AM
Are you talking about that Telegram group from ttdsales? I’ve been checking out kafeitianshi’s submissions. He’s been grinding hard for months, but I never chatted with him. There’s this flaw that lets users take out either vanitysearch or clbitcrack right after finding the PoW key. That’s how I think kafeitianshi has been submitting his stuff.
3 Reply Quote Share
nova69Member
Posts: 72 · Reputation: 174
#5Jan 23, 2024, 08:17 AM
Even if they keep updating the client, the underlying issue still exists. You can try to spot fake submissions by comparing request and submission times. If they match up with the random key, it’s probably a scam. Plus, adding random keys could help. But let’s be real, if someone’s crafty enough, they might just capture the data and claim the rewards for themselves. Honestly, best bet is to go solo on this.
3 Reply Quote Share

Related topics