Bitcoin
Bitcoin is a proof of work cryptocurrency.
This article covers some specific aspects of the Bitcoin protocol.
My Bitcoin Address is: 1HDp1gU3rgrRNKqrKorz8uWCpHUNdyGqXm
Overview
Bitcoin is a decentralized protocol that operates in an untrusted peer to peer environment while still being a reliable method to exchange credits (bitcoins) between people.
For detailed information, read the Bitcoin paper or one of the many sites out there.
Hashes & Encoding
You will see hashes as part of the Bitcoin protocol everywhere.
Types of Hashes
Here are a few common hashes you will encounter.
40 character long / 160-bit value
37f332f68db77bd9d7edd4969571ad671cf9dd3b
Generated using RIPEMD-160
64 character long / 256-bit value
600FFE422B4E00731A59557A5CCA46CC183944191006324A447BDB2D98D4B408
Generated using SHA256 of any number of rounds. This is typically seen as a transaction ID. The private key of an address also uses a 256-bit value.
130 character long
0450863AD64A87AE8A2FE83C1AF1A8403CB53F53E486D8511DAD8A04887E5B23522CD470243453A299FA9E77237716103ABC11A1DF38855ED6F2EE187E9C582BA6
The private key of an address
Hash160 (Transactions)
Transaction numbers are represented using Hash160 of the public key. That is:
TransactionID = Hash160 = RIPEMD160(SHA256(PubKey))
It is outputted as a 160-bit value in hex (64 characters long). For example:
49123c475ef78814414f1318eff0a349bcbafd182d8b3e110684152ee0e44081
Hash
Hashes in Bitcoin are done using two rounds of SHA256.
Hash = SHA256(SHA256(X))
Base58Check
Base58Check is used to generate Bitcoin addresses.
Address / Keys
A Bitcoin address is a 160-bit hash of theh ECDSA public/private keypair.
Generating An Address
- Take a 160-bit value as the private key.
- Generate a public key with it
- Hash = SHA256(PublicKey)
- Hash160 = RIPEMD160(Hash)
- Address = Base58Check(Hash160)
Where Base58Check takes a Hash160 hash value:
- BaseAddress = 00 + RIPEMD160(Hash160)
- Check = SHA256(SHA256(BaseAddress))
- FinalAddress = BaseAddress + (first 4 bytes of Check)
- Address = Base58CheckEncode(FinalAddress)
See Also: https://en.bitcoin.it/wiki/Technical_background_of_version_1_Bitcoin_addresses
Brain Wallets
A brain wallet allows for the generation of the public/private key pair using a passphrase. It is accomplished by:
- Converting a pass phrase into a private key
- PrivateKey = SHA256(PassPhrase)
- Generate a public key using the private key
- PublicKey = privateToPublic(PrivateKey)
- Generate the bitcoin address
- Hash = SHA256(PublicKey)
- Hash160 = RIPEMD160(Hash) (used by transactions)
- Address = Base58Check(Hash160)
The publickey can either be uncompressed or compressed. A compressed public key is simply a truncated key where the missing parts can be recomputed.
Attack
Ryan Castellucci did a talk on Defcon 23 on cracking brain wallets using his program called Brainflayer.
The basic idea is to extract all unique addresses in the bitcoin system. Dump the addresses into a bloom filter for almost constant time search, then use Brainflayer to bruteforce check on a word list that matches a specific address hash.
That is:
- get all Bitcoin Addresses as Hash160 > hashes.hex
- hex2blf hashes.hex hashes.blf
- brainflayer -b hashes.blf -i phraselist.txt
- or cat password.txt | brainflayer -b hashes.blf