ARK Easter Egg Hunt 2019 — Solutions

biz_network
9 min readApr 21, 2019

The hunt is over! Congratulations to everybody that was able to solve a puzzle and claim their prize and we’d like to express our gratitude to fun, jarunik, goose, Mike, ark.business, cam’s yellow jacket, echo, and pieface for donating to this year’s prize pool. This year’s hunt was 10x bigger and better than last year’s and we couldn’t have done it without the generous support from the ARK community. We hope you had fun and we’ll see you again next year.

— biz_network, rising_sun

And now for the solutions to this year’s puzzles

20 ARK

April showers:

bringmayflowers

ARK Core v2.1: Hello…

typescript

Ark doesn’t give dates…

arkgivesquarters

bzzt… bzzt…

pumpit

Fix’s lisk address

10664503299117383959L

http://oldliskforum.liskpoland.pl/forum.lisk.io/viewtopic6e24.html?f=6&t=162

This old Liskforum post from Travis where he mentioned donating ARK to Fix has two transactions. One of the transactions’ recipient addresses was the solution.

The bull, the bear, and…

thecrab

Bull markets go up. Bear markets go down. Crab markets go sideways.

Aloha, from this Michigan native

matthewcox

Cofounder Matthew Cox, aka Grexx, moved back to his native Michigan from Hawaii to work on Ark full time.

ARK Logic is…

flexiblescalablesimple

From the whitepaper https://ark.io/Whitepaper.pdf

Just like the animals boarding, ARK has two

whitepapers

I’m not a lawyer but he is

rayalva

Ray Alva is a bar-certified lawyer and Delegate Echo

How much Travis donated to Fix

1840927835lisk

The total of the two transactions in Travis’s Liskforum post above with the decimal removed.

The birth of axi

2014c6d55fd1a07cc36ce60339f766430c67d29bbcf680fe553ed55b4a5cab92

Transaction ID of axi registering his delegate.

This coffee drinking redditor’s birthday, express in unix!

1400716800

Jarunik’s Reddit birthday: May 22, 2014

50 ARK

The temperamental leader of the rising sun

williammoody

Capt. of the Rising Sun pirate ship. https://en.wikipedia.org/wiki/William_Moody_(pirate)

Sam put on his Ray-bans and Classic Yellow Jacket to meet the Founder of the GYM Pirates and conduct Business but got sent on a wild Goose chase in Switzerland.

piefaceechobizclassiccamsyellowjacketmikefunrisingsunarkbusinessgoosejarunik

All the donators/contributors in the order they are mentioned in the hint.

A new ARKangel has arrived

michelkraaijeveld

“Michael” is one of the archangels in Roman Catholicism and “Michel” is a new addition to the ARK Team.

Please click my referral link :(

heythanksitmeansalot

Click the Ledger affiliate link on https://classicdelegate.biz/faucet

The sleepy engineer’s bio

wearethemusicmakersthedreamersofdreams

https://twitter.com/sleepdefic1t

sleepdefic1t’s twitter bio “We are the music makers, the dreamers of dreams…”

Prof Decimus’s video ID

4vDczHgWH60

https://www.youtube.com/watch?v=4vDczHgWH60

The death of axi

cddbfc659bac3843724530b7b8add8f7663924768cf5fa6ec17730e4475a8e2c

Transaction ID of axi publishing his delegate passphrase onto the blockchain.

It’s Christmas with Sam’s Escrow!

AVUdzoVh5yRqg3ph9iytpAJnnHiZXx4R5u

The address of Pieface’s Christmas price prediction ARK address

75 ARK

Welcome bros

ravelouarky

Ravelou and Arky are delegates and Fix’s brothers. He greeted them with “welcome bro” when they joined slack

The Gold, Silver, and Bronze builders of the Ark

faustbriankristjankalexbarnsley

The top 3 contributors to Ark Core https://github.com/ArkEcosystem/core/graphs/contributors

The pilot has the lock. The shoemaker is the key.

thevideobossandnodelord

The lock (encrypted text) is in the pilot, aka the first video CYJ ever uploaded. The decryption key is the Shoemaker, Ryan Schoonmaker of CYJ: “ryanschoonmaker” https://www.camsyellowjacket.com/

3.4 Scalability; Rail 34

taoodiecphochgtthtmatltsrehmateeusaeeedateehiyustnoreinskucldennetebtnhkotatralcsoepdditsyioiarlsmaotyeendrelopnrsnrnaoueewlcndssoeepeiunoedtgctrnuoebeeontdrsnodwsnyhecumnlyngfshnfelpeowecgronitttsaoareodissphmaustisrthutfpoerotetsinnoceqeioesnsuulmnerhploarolulbbomateggalcneeerlhnpeiusnevalhnnllgyesistfobhteecdkapicuiidkivoeielwivchaecusefesesmnbcgponnohagmstyrgnseiueenugcogmanneddrentamhlecarnkiteiiianeeqisowttlumaictornslnamvunatokabsrtlhuasmmassaeinnkrrnatoibalniaactennrudrtoelofoaioehnrshcdoeruohwoamrnnnsctyknartymtswytuciesesdossuituhleoettesszpaytesnostnoeennteonlyernbhryilelosnrtehnseyldedseosausideetsreeehchthntylththcuertoaaihctrgogeuriecicobsewnssrtuneiaitoeamdoamhcvosersnruahchwyctoenoetorrenetiertaheoaeafksrsinekodsaeadigivrlielnapwsduknnekvip

Run Section 3.4 of the Whitepaper through a Railfence cipher with key = 34

A bit late for Christmas but I hear Santa has some left over booty

keepthechangeyoufilthyanimal

A rising_sun December blog post has this clue and an invite link to the biz_network discord

Join the discord and you’ll see this image in the channel announcing the Easter egg hunt.

This image has a zip embedded into it. Unzip the image to get:

Find the Greek. Become the Greek. Sign your profile.

30450221009f59a79872e3415058a63d8d5cebad8656dec1430f5aea6327f32cf36e891ad502202884235c827ba4a5a5fc1fdf2cf1bb17b37d92f100a6ebd841695b7fa16a860f

“The Greek” refers to the puzzle from last year where egg hunters had to bruteforce the two missing words on the “Pascha” account. Take that passphrase and sign Pascha’s profile. The solution is the signature.

Search the scrolls of the pirate to find the ancient long nosed devourer

arkwillmakeeveryonerich

One of rising_sun’s bounty submissions is an image of an Aardvark on Noah’s ark. It was edited with a speech bubble:

Like last year’s puzzle, googling “DABMBSG” will lead to a /biz/ thread with the following posts:

The numbers reference words in the v2 whitepaper and are in the post are in the format [PageNumber] [LineNumber]:[WordNumber]. Looking up the numbers will give you the solution.

Pokechain’s ICO. Combine the 2.

e430a2e0e209e9d1eeaa02a5db5db6f77e8b1c1e2cabb11258ab50104087b1c3c1dbcdf769260d66bf97a5fc3bf2ef5823400145a281db907adbbe55de51aa37

The transaction IDs where fun/alessio printed 20M dARK and took over devnet with Pokemon delegates.

The pirate’s red feather is a herring. Look closer and use the title.

nothingcanbesaidtobecertainexceptdeathandtaxes

An image in a rising_sun blog post contains an image of delegate goose’s logo with a link to a corrupted version of that same image.

Open the image up in a hex editor and go to where the corruption begins to find the text medium:ark.dpos.tax embedded into the image data. The solution is the title of goose’s blogpost announcing ark.dpos.tax.

130 ARK

Dr. Krypto. I’m CIA. Look in the passages, were the 12 words part of your plan?

betweenlightthatpossibletheyusedfieldunknownknowaboutthisthey

Take the solved passages from the CIA’s Kryptos puzzles and cross-reference it with the BIP39 dictionary, which ARK passphrases are generated from. Use the first 12 results.

Publicly present the Classic Sun Digest!

0d54d11251bf9c972e1dcfac748fe88c0684ad58766987e26e272fb3cc56ac8f

“Digest” is another word for a hash. The solution is the digest (SHA256 hash) of biz_classic and rising_sun’s public keys.

A telegram from biz

happypepe45360

The blinking underscore on https://classicdelegate.biz/ was modified to blink in morse code. The morse code message is HAPPY BIRTHDAY TO ME. If you open the browser console you’ll also see I was born on the 29th of June :).If you change your system clock to June 29th and refresh, you'll trigger the following image:

The adjective is “happy”

The proper noun is “Pepe”

The ‘x’ in the balloons mean to multiply the numbers on Pepe’s hat which is “45360”

Hey, listen! *drip drip drip*

chocolateeggsinjaruniksvault

The drips are a clue to check the biz_classic faucet. If you click open the faucet settings you’ll see a new alert sound was added called “With your eyes.” If you click “(Listen)” it’ll download an audio file.

The clue “Listen with your eyes” means to visualize the audio file. Viewing the spectrogram of the audio will reveal the following image:

The image has encrypted text on top and the clue “Dot the dimensions” under an ARK logo and Jarunik’s website. If you go on arkcoin.net, you’ll see an identical ARK logo. Find the dot product of the dimensions of that image ([1,6,0] • [1,6,0]) to get the number 37.

Shift the first letter of the encrypted text by 3 and do the same for every other letter. Then, shift the remaining letters by 7 to get the solution.

Losers are winners so go have some fun

moonatemyeggs

Lose all three of fun/Alessio’s games on https://www.arkfun.io/. After the third loss, the following image of Moon wearing a VR headset in a Starbucks will appear:

If you look really closely at his headset or adjust the hue/contrast, you’ll see login credentials. Log in to https://classicdelegate.biz with those credentials and look at the faucet rolls of that account.

The roll numbers are within the range of the alphabet in ASCII and converting them to letters will yield: “kmolnbwhudkcw”

The roll amounts look like binary and converting them to letters will yield: “wacynuatshqio”

The two strings are of the same length which commonly corresponds with a type of cipher known as a One-Time Pad. Doing a simple XOR on the two will produce the solution: moonatemyeggs.

ALoneDZHzW3waJzJH5D8kyPbUoAVzsMTq7 is sad and needs a hug from A cutie :(

Bruteforce an ARK address that begins with “Acutie” (not case sensitive) and send a transaction to ALoneDZHzW3waJzJH5D8kyPbUoAVzsMTq7 with “hug” in the smartbridge field. That will trigger a transaction to be sent from Alone to the sender with the 130 ARK prize.

WOW! Exciting new chatroom for High IQ Investors only! JOIN NOW FOR FREE MONEY!!! — The Adminstrator

raindropsdroptopsplayingmatch3icantstop

A new delegate was registered 2 days before this puzzle was released called “high_iq_investors.” That delegate sent a transaction with a link to the following image:

Unzipping the image will reveal the following files:

The README contains the text

Fear not, Egghunter. This JAR is safe. Run it in a sandbox or VM to be sure or decompile using https://github.com/deathmarine/Luyten

and ArkChat.jar is a login with a simple chat program

The README telling the reader to decompile the JAR was a hint. Inside the JAR is a variable forgotPw = false;that is never set to anything else despite the “Forgot password” checkbox in the UI. Someone reading the decompiled code will also see that the “Password” input field is also never used unless forgotPw was set to true as well. And how it is used is that another set of socket connections are opened where the password and username gets sent to the server if forgotPw == true. The relevant code snippet can be seen here.

The JAR also contains a plaintext resource file that contains the following data with some peculiar looking string next to “reset”:

title:Ark Chat 2.3
version:2.3.0
ip:104.167.101.189
port:5191
welcomeMessage:*~*~Welcome to Ark Chat!~*~*
loginWidth:300
loginHeight:150
chatWidth:500
chatHeight:400
reset:YzSkmM1bVC0EieyCD8WdX06PACnSZkErjJRnuqzOgxNPdinYdvXTlMsh0dLbE9d2

The code and config file references to someone forgetting their password and something that needs to be “reset” would suggest that a password reset needs to be done. But whose? The clue refers to “The Administrator” so try that.

First, recompile the JAR with forgotPw set to true. Then, logging in using the username “admin” will reveal the following message:

“imhavingsomuchFUN” is the key to the encrypted string labeled “reset” in the config file above.

Decrypting the text will give you “www.youtube.com/watch?v=_XAa0NWhEyg

Now, simply log back in using the username admin with the password www.youtube.com/watch?v=_XAa0NWhEyg to be presented with the solution.

--

--