๐ก Can you brute-force a TON private key?
โซ๏ธ Getgems developer Ivan Nedzvetsky decided to test how often TON developers cut corners when generating private keys. The idea came from a case involving cold Bitcoin wallets, where predictable key generation made it possible to recover private keys and steal tens of millions of dollars.
โซ๏ธ The problem is that a private key is supposed to be generated from random data. But technically, a developer can take a shortcut: hash a word with SHA-256 and derive a private key from the result. The wallet will still work normally, but a key like that can potentially be brute-forced using common password lists.
โซ๏ธ Ivan wanted to see whether anyone had actually done this in practice. Using TON Analytics, he pulled data for roughly 190 million addresses and 50 million public keys, then started brute-forcing candidate values. His search included 56 million common passwords from SecLists, 134 million Unix timestamps starting from 2022, and another 10 million plain numbers.
โซ๏ธ The result was actually pretty reassuring: out of hundreds of millions of candidates, he found just two addresses. One key had been derived from the word storm, while the other came from the string 1.3. And as it turned out, Ivan himself had created the second wallet at some point. Both were used only once and are empty today.
โซ๏ธ If you want the technical details, check out the developerโs channel โ he broke down how the experiment worked and what else could still be tested. And if youโre planning to do some key hunting yourself, better move fast before GRAM gets sent all the way to zero
@thedailyton
๐ก Can you brute-force a TON private key? โซ๏ธ Getgems developer Ivan Nedzvetsky decided to test how oft
The Daily TON | News
@thedailytonYour daily dose of TON news. _________________________ Contact us: @dailytonsupport_bot Twitter: twitter.com/the_daily_ton
258,878 ืื ืืืื
ืคืชื ืืืืืจื 