HACKROCKS CTF — Tracing a Suspicious Bitcoin Payment

by yesi | Sep 2, 2026 | Threat Detection | 0 comments

After completing Josh Madakor’s Cybersecurity course, and my internshipt at Log(N)Pacific, I decided I didn't want to simply add another certificate to my résumé and move on. I wanted to put what I learned into practice. While continuing my search for an opportunity to begin my career in cybersecurity, I've been using my time to work through hands-on labs, CTFs, and security challenges that allow me to apply what I've learned in a practical environment. One of the challenges I recently completed was a beginner CTF on HACKROCKS, which challenged me to think beyond simply finding an answer and instead approach the problem like an investigator. See the Scenario below

"Our investigation team has discovered that some senior officials of a certain Olympic Committee have received significant bribes in the past, specifically in 2012. Unfortunately, we do not know much more; we only have the following Image for you to start your investigation, which is somehow related to the recipient of the payment.

Regarding the amount of the payment, we only know that it must be significantly higher than the rest of the payments received that year.

Can you help us bring the guilty parties to justice?" https://hackrocks.com/challenges/start/corrupt-committee

This was very much different from what I learned in Josh's Madakor Cyber Range Cybersecurity course. This is isn't about KQL queries, Nessus Vulnerabilty, Azure, Rules or Alerts.

Investigation Objective

The challenge provided two important clues:

  • The supplied image was somehow related to the recipient.
  • The suspicious payment occurred in 2012 and was significantly larger than the recipient's other payments that year.

The goal was therefore to determine:

Who sent the suspicious payment?

Step 1 — Examining the Image

I began by treating the image as an evidence artifact rather than simply viewing it as a picture.

One of the first things I looked for was information embedded within the image.

The image contained a QR code, which appeared to be associated with a cryptocurrency address.

After decoding the QR code, I obtained a Bitcoin address: 1BWaryNxvEdkzRMZ6L4y2bgvBwhRyFTHQ2

Step 2 — Pivoting to Blockchain Data

Rather than attempting to identify the recipient directly, I used the Bitcoin address as an investigative pivot.

The objective was to determine:

a. Bit Conin Address
b. Unsually large payment 2012 Transactions
c. Transaction input
d. Sender

By going to https://blockchain.com entering the BTC Address I was able to decode the

From the above image you will immediately think you have found two different Bitcoin addresses. What is happening you are seeing the same address on two diferent blockchains. BTC (Bitcoin) and BCH (Bitcoin Cash).

Why does the same address appear twice?

Bitcoin Cash (BCH) was created as a fork of Bitcoin in 2017. Because of the way the two networks were created, addresses that existed on Bitcoin could also have corresponding addresses on the Bitcoin Cash chain.

So the website is basically saying:

"I found this address on the Bitcoin blockchain and I found a corresponding address on the Bitcoin Cash blockchain."

Which one should you investigate for this CTF?

BTC — the orange Bitcoin result.

The challenge specifically tells you the payment occurred in 2012.

That's an important clue because Bitcoin Cash didn't exist in 2012. Bitcoin Cash was created years later

Do keep this in mind Bitcoin Cash was not created until 2017; Therefore, you should focus on BTC blockchain becuase the

Step 3 — Identifying the Significant Payment

The challenge specifically stated that the payment was significantly larger than the other payments received during that year.

This gave me an important filtering criterion.

Rather than treating every transaction equally, I looked for the transaction that stood out because of its value.

The suspicious transaction involved:challenge specified that the suspicious payment occurred in 2012.

Step 4 — Identifying the Sender

The next step was to examine the input side of the transaction.

In a Bitcoin transaction, the output identifies where funds were sent, while the input provides information about the previous transaction/output from which the funds originated.

The transaction showed the originating address as: 1Ce1DeJf6HHHKPBKH63qC7kzP6m2a3rDrr

This became the primary identifier associated with the sender of the suspicious payment.

What I Learned

Although this was categorized as a beginner CTF, I found the investigation useful because it demonstrated an important cybersecurity concept:

A small piece of information can become an investigative pivot.

The image itself didn't immediately provide the answer.

Instead, I had to recognize that the QR code could contain useful information, extract the Bitcoin address, pivot to blockchain data, establish the relevant timeframe, identify the anomalous transaction, and then investigate the transaction's origin.

This is similar to the mindset used in OSINT and digital investigations:

Don't just look at the evidence — determine what you can pivot from it.

Skills Demonstrated

For your portfolio, I would list the skills like this:

Technical Skills

  • OSINT investigation
  • Digital investigation methodology
  • Cryptocurrency/blockchain analysis
  • QR-code analysis
  • Transaction analysis
  • Evidence correlation
  • Investigative pivoting
  • Critical thinking
  • Technical documentation

Conclusion

The investigation began with a single image and very little contextual information.

By extracting the information contained within the image and using it as an investigative pivot, I was able to trace the relevant Bitcoin activity back to the originating address.

This challenge reinforced the importance of following evidence logically rather than making assumptions about where the investigation will lead.