pull down to refresh

P2SH and P2WSH outputs don't show their spending conditions on chain. The output only commits to a hash of the script. The script itself shows up later, when someone spends the coins.

Most of those scripts check a signature. But a script doesn't have to. You can lock coins with "the input must equal 5", "wait 144 blocks", or even just OP_TRUE. Anyone who knows or guesses one of those scripts can spend the coins. No key needed.

So I wondered: are there coins sitting behind scripts like that, waiting for someone to guess the script?

Step 1: learn from history

Guessing blindly is hopeless, so I started with what people have actually done. I ran my own node and walked every block from genesis to height 968,880. That's about 1.45 billion transactions and 3.5 billion inputs. For every P2SH and P2WSH spend, I pulled out the revealed script and threw away anything containing a signature opcode.

That removed about 329 million spends. About 314,000 spends were left, using roughly 205,000 distinct scripts.

What was left was mostly boring:

  • About 99% were "push some random bytes, drop them, return true." That's an anyone-can-spend output with a nonce, so every address is unique. Someone has done this hundreds of thousands of times. My guess is a service or protocol making throwaway addresses, but I don't know which.
  • Hundreds of SHA1 hash puzzles. None of them still holds funds.
  • A few timelocks, like 144 OP_CSV OP_DROP OP_TRUE, which was used 42 times.
  • Small arithmetic puzzles, such as "give me two numbers whose sum is X and whose difference is Y".
  • A few real puzzles, which I'll get to.

Step 2: build a dictionary and check the UTXO set

Next I built a dictionary from those findings:

  • Every script I'd seen, under all three wrappers (P2SH, P2WSH, and P2SH-P2WSH), since people sometimes reuse a script with a different wrapper.
  • "Equals some small value" scripts.
  • Hashes of small inputs.
  • Input-size checks.
  • Simple arithmetic targets.
  • Timelocks close to the ones people actually used.
  • Every one- and two-byte version of the "push, drop, true" pattern.

That came to about 860,000 candidate scripts. I hashed each one into an address and asked my own electrs server whether it still holds coins.

What's still out there

1,979 sats at bc1qz5vs9dnge32mrj8da6wl0f9ukeuvhr2p7zn9l3g2rrrrxukzerqqq68mmw.
The script is 010887, which means <0x08> OP_EQUAL. To spend it, you just provide the byte 8. The catch is that the script pushes the 8 with an explicit one-byte push instead of OP_8. That's valid by consensus, but it breaks Core's minimal-push relay rule, so normal nodes won't relay the spend. You'd need a miner willing to take a nonstandard transaction directly.

888 sats at 3LZqWsZdvwsrVsmtq2SV6YkyTfUciBrL7E.
This one is fun. The script starts with the text * PoW PUZZLE * Find the secret bits. Then it runs 40 rounds where you choose whether to apply SHA256, with HASH160 applied between rounds, and compares the result to a fixed digest. Brute force means about 2^39 combinations.

But the same script was also used as plain legacy P2SH and spent twice, at blocks 600,143 and 924,213. Those spends put the 40 secret bits on chain. Someone also funded the nested SegWit version of the same script at block 600,140, and that output was never touched. I replayed the published bits offline, and they hit the target. So this one is solved, just unclaimed. The witness is around 300 bytes, so fees will eat a good chunk of it.

Honorable mention: Peter Todd's 2013 collision bounties.
About 0.59 BTC is still sitting in the RIPEMD160, HASH160, SHA256, and HASH256 collision bounties. They're signature-free, but you need two different inputs with the same hash. That takes roughly 2^80 to 2^128 hash operations, so they're "free" only in theory. The SHA1 bounty was claimed in 2017 after SHAttered, and the trivial ABS bounty was claimed long ago.

What I didn't find

  • No funded timelock-only scripts.
  • No "equals 1, 2, 3, a, b, c" scripts beyond the 8 above.
  • No small arithmetic puzzles with money left in them.

Altogether, the spendable "free money" comes to 2,867 sats, and part of it can't be relayed normally. Either people are careful, or these outputs get swept fast.

Caveats

  • The filter is strict. I excluded any script with a signature opcode, even in a branch that can never run. So this isn't every possible signature-free script.
  • The dictionary is finite. Finding nothing in it doesn't prove nothing exists.
  • Anyone can take the payout. These scripts have no signature, so nothing ties the spend to your output. Whoever broadcasts a solution is basically handing it to any miner who wants to redirect the payout.
  • Nothing was spent. I didn't broadcast any spends. The last batch of about 230,000 candidates was still running when I wrote this.

Still, it was a fun way to spend a few days of CPU: mainnet has a small museum of strange scripts, and a couple of them still hold coins.