On February 3, 2026, Mybucks.online launched the Wallet Cracking Challenge on the HackenProof platform — a time-limited security challenge designed to test the resilience of its wallet architecture.
Unlike most programs on the platform, which focus on identifying vulnerabilities in applications or smart contracts, this challenge invited researchers to attempt something more specific: gain access to a target wallet generated by the Mybucks.online system.
By opening the challenge to the HackenProof community, Mybucks.online engaged ethical hackers from around the world to analyze the wallet’s key-generation mechanism and explore potential attack paths.
Challenge Setup
The Wallet Cracking Challenge invited researchers to attempt access to a target wallet generated using the Mybucks.online key derivation system. The objective was straightforward: recover the correct credentials and unlock the funds stored in the wallet.
The target wallet was generated locally on app.mybucks.online using a combination of Scrypt and Keccak-256 to derive the private key from two user-defined inputs: a Passphrase and a PIN.
Target wallet address
0x590C70693Bd5ca256cb3a5c65d8Fa28dc58E7FE6
Network
Polygon
The total bounty pool for the challenge was $1,000 USDT and 100 POL, with a $1,100 reward allocated for a critical outcome — successfully recovering the credentials and gaining access to the wallet.
To make brute-force attempts non-trivial, the credentials were generated with the following complexity:
Passphrase
- Length: 12
- Charset: a–z, A–Z, 0–9, !@#$%^&*
PIN
- Length: 6
- Charset: 0–9
Participants had 30 days to analyze the architecture, test potential attack paths, and attempt to recover the credentials.
Community Engagement
Over the course of the 30-day challenge, the HackenProof community actively engaged with the target wallet and its key generation logic.
In total:
- 19 hackers participated in the challenge
- 28 reports were submitted
- 11,386 scope reviews were recorded
Researchers explored different approaches to analyzing the wallet’s architecture, from evaluating the cryptographic design to assessing potential brute-force strategies and implementation-level weaknesses.
The challenge generated consistent activity throughout its duration, demonstrating how time-limited security events can mobilize the hacker community around a very specific technical target.
Challenge Results
After the challenge concluded, the Mybucks.online team withdrew the funds from the target wallet and disclosed the credentials used to generate it. The wallet itself was created by the HackenProof team, and access to the credentials was restricted to HackenProof during the challenge. Publishing the credentials allows anyone to independently reproduce the wallet and verify the challenge setup.
The wallet was generated using the following inputs:
Passphrase
3xFbsYA9V*FP
PIN
225588
Using these credentials, the same private key can be derived through the Mybucks.online key generation process, corresponding to the original challenge wallet.
Mybucks.online team received several constructive reports and architectural reviews from the ethical hacker community. To implement these insights and further harden the security of Mybucks.online, they have released a March 2026 Security Update.
To stay updated on future announcements and initiatives from Mybucks.online, follow the project on X and Telegram.
Why Challenges Like This Matter
While most programs on HackenProof follow the traditional bug bounty format, the Wallet Cracking Challenge shows how the platform can also support time-limited security challenges focused on a specific technical objective.
Formats like this allow projects to stress-test a particular component of their architecture, engage the hacker community around a clearly defined problem, and gain additional confidence in the resilience of their systems.
For teams building in Web3, challenges of this kind can complement traditional security approaches such as audits and ongoing bug bounty programs. By opening a focused target to a global community of researchers, projects can observe how independent hackers analyze the system and attempt to approach it from different angles.
If you’re building a Web3 product and want to test your infrastructure in a similar way, you can launch your own security program through HackenProof bug bounty programs.



