The Genesis Puzzle Key Is Not in the Genesis Block: It Is a 255-Byte OP_RETURN in Block 963,629, and the Real Story Is Deliberate Entropy Collapse
DEEP-DIVE ON THIS CARD. The card gets the location and the lesson wrong, and both corrections matter.
WHAT THE CARD SAYS AND WHY IT IS INCORRECT.
The card describes a puzzle that 'conceals a Bitcoin wallet key inside the data of a genesis block, requiring solvers to decode on-chain payload', and states 'the key is embedded in immutable block data'.
That is not what happened. An unidentified user embedded a 255-byte message via OP_RETURN in a roughly 500-byte transaction in block 963,629 on 22 August 2026. The message announces a puzzle wallet whose key material was derived from publicly available information in the Genesis Block. The private key is not stored in block 0, and nothing was concealed inside Satoshi's block - which has been immutable and unmodifiable since January 2009, and whose 50 BTC coinbase output is famously unspendable due to a quirk of the original client.
The distinction is not pedantry. 'A key is hidden inside the Genesis Block' implies Satoshi placed something there. What actually occurred is that a modern user generated a wallet using Genesis Block data as a seed source and announced it in a 2026 transaction. Galaxy Research identified the transaction; neither the author's identity nor the derivation method is verified, and there is no confirmed evidence the puzzle has been solved or the funds moved.
WHAT THE AUTHOR ACTUALLY SAID.
Per the embedded message: 'I created a Bitcoin puzzle using information from Satoshi's Genesis Block to generate a wallet. The entropy is extremely low. I did not even need to make backups - everything required was already in the first block. Good luck!'
Read that as a security statement rather than a game. The author deliberately abandoned random seed generation and derived a key from a public, fixed, universally available dataset. Anyone can reconstruct the input space. The only protection is the obscurity of the exact derivation method - which is not cryptographic protection at all.
THE LESSON THE CARD MISSES.
The card frames this as demonstrating 'how Bitcoin's ledger can be used as a censorship-resistant storage medium for transferring access via cryptographic challenges'. That inverts the actual demonstration.
This is a live, intentional reproduction of the failure mode that drained roughly 1,816 BTC (~$116M) from Coldcard users starting 30 July 2026 - where a March 2021 build error caused seeds to fall back on a weak software RNG, collapsing effective key strength from 128 bits to as little as 40. Coldcard users suffered that unknowingly. This author chose it, and said so.
The unifying principle: a Bitcoin private key's security is entirely a function of the entropy behind it, and nothing else in the stack compensates. Not an air gap, not a secure element, not the immutability of the chain. A 256-bit key derived from a public document has the entropy of the derivation method, not of 256 bits.
HOW TO WATCH IT.
If the wallet is drained quickly, that measures how fast the key-hunting community can enumerate plausible derivations from a known public source - a genuinely useful empirical datapoint on low-entropy key risk, arriving with real money attached and no victim. Separately, a long-running puzzle holds 916 BTC unsolved across 78 addresses, worth roughly $58.87M, which is the standing benchmark for this kind of search.
Watch the address. The time-to-drain is the finding.
Sources (5)
AI Research
Key Takeaway
An unidentified user embedded a 255-byte OP_RETURN message in block 963,629 on 22 August 2026 announcing a wallet whose key material was derived from public Genesis Block data - 'the entropy is extremely low. I did not even need to make backups.' The key is not stored in the Genesis Block; block 0's coinbase output has always been unspendable. This is a deliberate re-enactment of the exact failure that cost Coldcard users 1,816 BTC three weeks earlier.
DEEP-DIVE ON THIS CARD. The card gets the location and the lesson wrong, and both corrections matter.
WHAT THE CARD SAYS AND WHY IT IS INCORRECT.
The card describes a puzzle that 'conceals a Bitcoin wallet key inside the data of a genesis block, requiring solvers to decode on-chain payload', and states 'the key is embedded in immutable block data'.
That is not what happened. An unidentified user embedded a 255-byte message via OP_RETURN in a roughly 500-byte transaction in block 963,629 on 22 August 2026. The message announces a puzzle wallet whose key material was derived from publicly available information in the Genesis Block. The private key is not stored in block 0, and nothing was concealed inside Satoshi's block - which has been immutable and unmodifiable since January 2009, and whose 50 BTC coinbase output is famously unspendable due to a quirk of the original client.
The distinction is not pedantry. 'A key is hidden inside the Genesis Block' implies Satoshi placed something there. What actually occurred is that a modern user generated a wallet using Genesis Block data as a seed source and announced it in a 2026 transaction. Galaxy Research identified the transaction; neither the author's identity nor the derivation method is verified, and there is no confirmed evidence the puzzle has been solved or the funds moved.
WHAT THE AUTHOR ACTUALLY SAID.
Per the embedded message: 'I created a Bitcoin puzzle using information from Satoshi's Genesis Block to generate a wallet. The entropy is extremely low. I did not even need to make backups - everything required was already in the first block. Good luck!'
Read that as a security statement rather than a game. The author deliberately abandoned random seed generation and derived a key from a public, fixed, universally available dataset. Anyone can reconstruct the input space. The only protection is the obscurity of the exact derivation method - which is not cryptographic protection at all.
THE LESSON THE CARD MISSES.
The card frames this as demonstrating 'how Bitcoin's ledger can be used as a censorship-resistant storage medium for transferring access via cryptographic challenges'. That inverts the actual demonstration.
This is a live, intentional reproduction of the failure mode that drained roughly 1,816 BTC (~$116M) from Coldcard users starting 30 July 2026 - where a March 2021 build error caused seeds to fall back on a weak software RNG, collapsing effective key strength from 128 bits to as little as 40. Coldcard users suffered that unknowingly. This author chose it, and said so.
The unifying principle: a Bitcoin private key's security is entirely a function of the entropy behind it, and nothing else in the stack compensates. Not an air gap, not a secure element, not the immutability of the chain. A 256-bit key derived from a public document has the entropy of the derivation method, not of 256 bits.
HOW TO WATCH IT.
If the wallet is drained quickly, that measures how fast the key-hunting community can enumerate plausible derivations from a known public source - a genuinely useful empirical datapoint on low-entropy key risk, arriving with real money attached and no victim. Separately, a long-running puzzle holds 916 BTC unsolved across 78 addresses, worth roughly $58.87M, which is the standing benchmark for this kind of search.
Watch the address. The time-to-drain is the finding.