Bitcoin, built from nothing. No crypto libraries, no magic. The secp256k1 curve, the hashes, the signatures, the proof of work, the network, all rebuilt by hand and turned into things you can touch. Nineteen interactive windows onto how a chain of numbers becomes money nobody can forge.
secp256k1's group law, made geometric. Your private key is a number; your public key is a point on a curve.
Open →Watch a 256-bit secret become an address through SHA-256, RIPEMD-160 and Base58Check. Flip a bit, see the avalanche.
Open →Sign a message, verify it, then reuse one nonce across two signatures and watch the private key fall out.
Open →Grind a nonce until the hash clears the target, link blocks together, then tamper with one and break the chain.
Open →Nodes gossip, forks appear and an attacker rewrites a "confirmed" payment.
Open →Build, sign and broadcast a genuine transaction to the Bitcoin testnet.
Open →Step through Bitcoin's tiny programming language: P2PKH, multisig, hash locks, timelocks.
Open →One seed phrase unfolds into a whole tree of addresses.
Open →Three keys, one address, a 2-of-3 rule. Lose a key and your coins are safe; lose a thief's, and so are they.
Open →A block fingerprints every transaction in 32 bytes. Prove one is included with a handful of hashes, no full block needed.
Open →Bitcoin's cleaner signature: keys that add, one joint signature for many owners and the tweak behind every bc1p… address.
Open →Three cosigners, one key, one 64-byte signature. The two-round ceremony that makes a multisig vault invisible, with a witness 4× smaller.
Open →Pay off-chain thousands of times, trustlessly. Publish a revoked state and the revocation key lets your counterparty take everything.
Open →One payment hops Alice→Bob→Carol with no direct channel. A single preimage settles the whole path; decreasing timelocks keep the middle honest.
Open →Any t of n key-holders sign: 2 of 3, and any one alone can't. One Schnorr signature, the group secret never assembled.
Open →Route a payment with point-locks, not hash-locks. A Schnorr adaptor signature per hop; completing it reveals the secret and settles the path, privately.
Open →Re-skin FROST to BIP-340: any 2 of 3 officers key-path spend a bc1p vault with one signature, indistinguishable on-chain from a lone wallet.
Open →Force-close with a payment in flight: the HTLC-timeout / HTLC-success transactions (byte-for-byte BOLT-3), whose output is itself delayed and revocable: the penalty, one level down.
Open →Delete the trusted dealer. Each participant contributes a secret only they know; the group key is the sum, never assembled, yet any 2 of 3 still sign. Distributed key generation, from scratch.
Open →