Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
boha — Crypto bounties, puzzles and challenges data library | Kitploit
工具/GitHubGitHub/oritwoen/boha
CryptographyCTFPapers & ResearchLearning & EducationCurated Resources
GitHuboritwoen/boha

boha

Crypto bounties, puzzles and challenges data library

查看仓库
1662156分钟前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
内容在请求的语言中不可用。显示英文版本。

@agntn/puzzles

npm version npm downloads license Ask DeepWiki

Public crypto puzzles and bounties, as typed records. You ask for a puzzle, you get its address, its key material and what happened on chain.

Why?

Every puzzle thread has the same three things: the addresses, the prizes, and who solved what. Every scanner and tracker re-types them from the thread, slightly differently each time. So they live here once, as code. A puzzle is a TypeScript record. The type checker reads it before a test does. The CLI, the MCP server and the Pi and OMP extensions read one registry.

Docs, one page per puzzle and a live playground: puzzles.agntn.dev.

[!WARNING] Pre-1.0. The API, the CLI flags and the data model can still move. Pin an exact version if you build on it.

✨ Features

  • 🧾 Data as code. One PuzzleSpec literal per puzzle, built by a factory for its chain. No JSON, no build step.
  • 🕳️ Absent means absent. A puzzle without a solver or a prize has no such key. Nothing serializes as null.
  • 🔑 Key material in every shape. Hex, WIF, a BIP38 payload, a seed phrase, secret shares, or just a bit width. One builder.
  • 💤 Lazy registry. Importing the package loads no records. get("b1000/71") imports one collection module.
  • ✅ Verification is a value. A published key derives the address or it doesn't. Nothing throws for a bad record.
  • 💰 Live balances. puzzle.balance() through @agntn/explorers. Base units as bigint, API keys redacted from errors.
  • 🤖 Twelve agent tools. One executor behind MCP, Pi and OMP. Same answer everywhere.
  • 🌐 Runs anywhere. Neutral ESM on the Fetch API. Node, browsers, edge workers.

📦 Install

pnpm add @agntn/puzzles

Node.js 26 or newer for the CLI.

🚀 First call

npx @agntn/puzzles stats

That prints the total, one count per status and how many puzzles have a known public key. No key, no config, no network. The records ship inside the package. The bare puzzles below is pnpm exec puzzles after a local pnpm add, or just puzzles after pnpm add -g @agntn/puzzles.

puzzles show hash-collision/sha256
hash-collision/sha256	unsolved	0.277343 BTC	35Snmmy3uhaer2gTboc81ayCip4m9DT4ko
chain: bitcoin  address kind: p2sh
hash160: 292fb39df7cd619a396069383928e6bfb74ebec5
redeem script: 6e879169a87ca887 (hash 292fb39df7cd619a396069383928e6bfb74ebec5)
public key: unknown
private key: unknown
started: 2013-09-13 05:59:09
transactions: 1
	funding	2013-09-13 05:59:09	0.1 BTC	397f12ee15f8a3d2ab25c0f6bb7d3c64d2038ca056af10dd8251b98ae0f076b0
explorer: https://blockstream.info/address/35Snmmy3uhaer2gTboc81ayCip4m9DT4ko
source: https://bitcointalk.org/index.php?topic=293382.0

Commands

CommandWhat it prints
puzzles statsTotals and status counts. --json adds the prize sums
puzzles collectionsOne row per collection: key, counts, author
puzzles authors [key]One row per author, or one author's record with its sourced facts
puzzles solvers [key]One row per named solver, or one solver's record: every solve, profiles and sourced facts
puzzles show <id>One puzzle's record: key material, transactions, hints and links. --json for the data
puzzles hints <id>The collection's hints, the puzzle's own, then its hint files. --json for both
puzzles stages <id>The stages of a multi-stage puzzle with their pages, files and published answers. --json for the list
puzzles list [collection]One puzzle per line. --address, --chain, --status and --with-pubkey narrow it, --limit and --offset page it
puzzles verify [id]A published key against its address. --all for every puzzle, exit 1 on a mismatch
puzzles balance [id]The live balance. The list filters check a whole set, one row each. --api-key, or one variable per chain
puzzles exportThe whole dataset with its data_version
puzzles mcpThe MCP server over stdio

--json is the same serializer everywhere, bigint as strings and absent fields left out. The flags and exit codes are in the CLI guide.

🧠 Library

import { get, stats, verify } from "@agntn/puzzles";
import { b1000 } from "@agntn/puzzles/collections/b1000";

const puzzle = await get("b1000/71"); // loads the b1000 collection, nothing else
puzzle?.address().value; // "1PWo3JeB9jrGwfHDNpdGK54CRas7fsVzXU"
puzzle?.keyRange(); // [2n ** 70n, 2n ** 71n - 1n]

(await verify(b1000.require(1))).verified; // true, key 1 derives its address
(await stats()).unsolved; // how many are still waiting for a key
(await b1000.require(71).balance()).totalUnits(); // 7.10190014 when I ran it, mempool.space decides

That's most of it, really. A collection is its own entry and everything on it is synchronous. The views that span collections await a load. Errors descend from PuzzlesError, balances have their own family under BalanceError. The rest is in the guides: records, registry, lookups, verification, balances.

🗺️ Collections

下载工具