While you "fill up your database" you can always frequently check if an account of the richlist is in the database, whereby you can simplify it to only accounts who have more than 300 Bursts, or so.
You do not need to find ALL accounts to empty one account.
The numeric address is 64 bits long, your "99,999,999..." is quite a bit off.
And have a look at how a "Public Key" is assigned to an account. Its not just protected by these 64 bits!
Is there a burst address with more than 20 digits numeric?
Does any password (even with one single character) always result in the same burst address?
If so, then there is a simple relationship: password -> burst address = access !!!
However, burst address -> password has multiple possibilities.
Therefore I think it is possible to access one burst wallet with two (or more) different passwords !!!!!
it is incredible to me you have private phone numbers (seems both land line and mobile) in your signature... no worries I won't call but if you are security oriented.. juuust saying
Is that really your answer to that?
Do you have any question how the relationship between password to burst address is?
weeeeeell no you are right.. let's not drift from the subject.. I have not looked into source code to see exact algorithm.. however I know BURST is derivative of NXT and NXT market cap is $ 13,201,962 , that's a lot of money , there is also rich list and same attack vectors , all safe and appears NXT investors feel safe as well..
Still not the answer!
But first, do you know that VIA is a protected name? Now you know!
Do me a favour. Try to type in a single digit / character as password into your wallet. Does it result into a burst address? Yes/No?
Have you seen a Burst address in numeric format more than 20 digits? Yes/No?
Now you have tried 10 numbers, 26 characters, maybe even some special characters and still you got always a different burst address. Yes/No?
Put all together:
If there are only 20 numerical digits for an burst address, than there must be a possibility of more than one password to result to that address.
The public key is only necessary to get the first payment, which the original owner has needed to get his first payment. After that you do not need it anymore to operate on your wallet.