Every run breaks a bigger key.
Press start. Your browser will crack a real key, then a bigger one, then a bigger one, and publish the proof each time. Bitcoin keys are 256 bits. Watch how fast the wall goes up.
The Quantum Room
Where the flies live: a hall of rigs and racks you can walk through in 3D, with the colony's log running beside it.
Runs
Each run: the public key is shown first, then the search starts. When the private key is found, the page checks that key × G equals the public key. Nothing here is simulated.
| # | bits | public key | hops | time | hops/s | private key | check |
|---|---|---|---|---|---|---|---|
| No runs yet. | |||||||
The ladder
Expected work for the best known attack (Pollard's kangaroo) is about 2bits/2 hops. Every 2 extra bits doubles it. Rows marked measured happened in this browser. Everything else is arithmetic from published speeds, not a claim.
| bits | expected hops | this browser | one RTX 4090 | record rig (135-bit solve) | status |
|---|
Speeds: this browser = measured live. RTX 4090 = 14.5 GH/s (RCKangaroo, published). Record rig = whatever solved the 135-bit puzzle in about 5 months (reported July 2026), calibrated from that result to ≈32 TH/s, so its 135 row reads 5 months by construction. Quantum hardware's public record: a 15-bit key (Project Eleven Q-Day Prize, April 2026).
The board
Outside numbers this meter is measured against. We are not hunting any of these. They are the scoreboard, quoted with their source.
| item | value | what it means | quoted through |
|---|---|---|---|
| Bitcoin key size | 256 bits | The wall. 2128 hops with the known attack. | secp256k1 |
| Puzzle #71 | 7.1 BTC · unsolved | Next prize in the 2015 puzzle challenge. No public key exposed, so brute force only: ~25,000 GPU-years. | btcpuzzle.info · 2026-10 |
| Puzzle #135 | 13.5 BTC · solved | Current record: reported ~5 months of GPU work, July 2026. | Bitcoin-Puzzle-Info · 2026-07-28 |
| Puzzles unsolved | ~916 BTC | Still sitting in the challenge wallets. | bitcoin.com · 2026-08 |
| BTC on exposed keys | 7,110,382 BTC | Coins whose public key is already on chain (≈ $581B). Drake's "bunker mode" is about these. | Project Eleven risq list · 2026-10-09 |
| Quantum record | 15 bits | Largest elliptic-curve key broken on quantum hardware for a public prize. | Project Eleven Q-Day Prize · 2026-04 |
Report
Written from this session's real runs. Copy it, post it.
No runs yet. Start the climb and the report writes itself.
Method
A private key is a number. The public key is that number times a fixed point G on a curve. Going forward is easy; going back is the hard problem that protects every Bitcoin and Ethereum wallet.
Kangaroo is the best known way back when you know the key lives in a range. Two herds of "kangaroos" hop along the curve, one from a known position, one from the public key. When they land on the same spot, the distance between their starting points is the key. It costs about the square root of the range: 2bits/2 hops.
This page makes a random key in a chosen range, shows you the public key before searching, runs kangaroo in a web worker, and then checks the answer by multiplying it back. The ladder scales the measured speed to published GPU speeds. The arithmetic is simple; the sizes are what matter.
What this shows
- Real cost of the known attack at every size, measured where we can and computed where we can't.
- That each 2 bits doubles the work, which is why 256 is not "a bit more" than 128.
- Proof for every run: anyone can multiply the private key by G and compare.
What this does not show
- Nothing about whether AI will find a new shortcut. This measures the attack we have.
- We never touch anyone's wallet. Every key here is ours, made seconds earlier.
- We are not hunting the puzzle wallets. On this page they are a scoreboard.