Bitcoin key exposure audit
Verified ECDSA nonce-reuse findings from a full-chain scan.
No affected address held funds at the snapshot.
- Verified nonce-reuse findings
- 475
- Affected addresses
- 432
- Spent after exposure
- 2,354.27117192 BTC
- Snapshot balance
- 0 BTC
Affected addresses
475 verified findings across 432 addresses. Search, filter, or select a heading to sort.
Loading findings from findings.csv… | ||||
Other findings
Every affected key below was empty at the snapshot.
| Check | Result |
|---|---|
| Small-scalar keys | 369 distinct keys with d ≤ 224, including the 2015 puzzle keys. |
| Timestamp keys | 42 funded addresses whose private keys equal Unix timestamps from 2008–2031. |
| Brainwallets | 6,367 addresses from 6,439 passwords in a 14.34-million-word dictionary. |
| Keys embedded as data | 5,095 distinct private keys found in OP_RETURNs, test strings, and puzzle material. |
| Replayable signatures | 71,863 SIGHASH_SINGLE signatures signed the constant z = 1 and can be replayed against another UTXO of the same key. |
| Shared fixed nonce | 2,552,755 signatures from at least 122 keys used one nonce in 2018. Keys used twice through the service are compromised; keys with one such signature are unaffected. |
| Single-signature leaks | 287 signatures from at least 46 keys used k = 1; 336 used |k| ≤ 224; one used k = d. |
| Taproot / Schnorr | No same-key nonce reuse. Two R values repeated across different signing keys; neither exposed a key. No key-path k = d across 352 million outputs. |
Weak-key addresses are permanently unsafe and routinely swept by bots.
Related, but not spendable
- 3-of-5 multisig · 17.23643265 BTC:
31oSGBBNrpCiENH3XMZpiP6GTC4tad4bMyheld this amount across 881 UTXOs. One participating key was exposed at the empty address19zqrJ8K9LLQJzv5do4Di9GrWi7fAjCwcy; spending still requires three signatures. Evidence: transaction 1 and transaction 2. - 18 hashlocked outputs · 859,986 sats: their preimages are public, but every reviewed spend path also requires a signature from a key not identified as compromised.
Show the 18 reviewed hashlocked outputs
3NRAEf2uBHo3U9FtjRivmARnmEsnHx5g7G: 250,000 sats36LgN86RKg2a3H9qR3uk3e3TGNGSq5qHBy: 125,000 sats33qmZ6GZb3GktwvRxp6NZLrNRxNhHzaUHu: 125,000 sats3KG4noM8vVc2aNhBTKNtPBrzbFpGiLiSMP: 125,000 satsbc1qqurjzctxl6t0askcskan9rktfqau2sawh6783u9hphzsxe4ymyjqqgjxsl: 97,399 sats3MLWfbLWCKeLWd9eYDwWPhJTir2gET6LQt: 20,000 satsbc1q5lpu6d2h05puxf3gpdg62ecrpxwvra47huw45uc2wql5rmj3malqgfy4ru: 10,000 satsbc1q8xjlevt2npv7f7ls4p2muwwlxawn60vr47zknxp24r94cye6gz5s3qpe6k: 10,000 satsbc1qngqmycntvnuux6s7dn846y4chyfwx3qsxs5phhp8p4zu6hae6wxq9r0q4c: 10,000 satsbc1qm3jx72qj5kpx3y2u24357z36r74t7u7w895gtq5g6tg4u84gx58qufh4dj: 8,000 satsbc1qqmtt7rjtxnnt8v3uynvpudleuztqs92tqcf3wu543hnujejy8yqs3yhadk: 6,000 satsbc1q7xulzwyp069y0evvtaceg4xenssa46s2zdaw73pw0n730ay2gj2qwype87: 5,700 satsbc1q58dldrda5jldlcdzschl25getp2al50npfsvh3ry9nr62ufraj3suq4cq4: 4,098 satsbc1qy5qrshgtu5ff2mk72xzlw8m77xphq87f5ug9fnur5ua3a8nkmyqqyfjh5n: 3,968 satsbc1qygzz54sw0qgyxkx8yh602ksve0swuvvq4ymwfg4yzvc46xchq8ss2syvwp: 3,221 satsbc1q00cqk3djf22wfpfqa08e47hj8qpugr56g6ap2860ncamp749530q7ag5ph: 1,000 satsbc1qj5t8q9vppwztcxk4m6h0ur0kjkh6ls6fn96actlepgqm075yw92s2jc759: 600 sats75bb6417afc7500a6389201a67bfc2428a1241170a214bbf6833a389191036fe, output 0: 55,000 sats
Method
3.760 billion signatures were scanned. Every reported key was recovered and verified; private keys and spend instructions are omitted.
Figures and validation
“First blocks” are the earliest confirmed signature blocks in each finding. “Lifetime spent” is the sum of confirmed spends from an address over its full history, not its balance at exposure or evidence of theft. “Spent after exposure” counts spends strictly after the second exposing signature; exposure-block spending is kept separate.
Full histories total 8,405.04393680 BTC spent, including 2,354.27117192 BTC after exposure and 255.73643522 BTC in exposure blocks. Values came from a local chain scan and transaction index, then matched the node’s UTXO set with 0 mismatches. P2PK-era spends totaling 0.50936589 BTC have no input-side date.
† Thirteen displayed P2PKH addresses never appeared on-chain. For those rows, the activity shown is from the same key’s used SegWit address; no spending is attributed to the unused address. Script and multisig spends that merely contain a key are not attributed to that key’s address.
Limits and edge cases
Weak-key searches are limited to the enumerated scalar, dictionary, and timestamp spaces.
Signature checks cover final on-chain signatures, not participant-level MuSig or FROST sessions.
The snapshot pass observed the one-block orphan at height 961,632 on 2026-08-08. Its roughly 3,900 duplicated transactions are filtered by transaction ID and do not change the findings.