The Glass Forest: Hunting for Broken Signatures in 3.76 Billion Signatures

by stutxo

I scanned every signature ever confirmed on the Bitcoin blockchain, 3.76 billion of them from 1.41 billion transactions, and found 475 proven cases of nonce reuse that leaked private keys. Expanding the search through transitive and cross-key analysis brought the total to 3,207 recoverable keys, every one verified against its on-chain public key. No private keys are stored anywhere, and every affected address was empty at the snapshot. Every claim below links to its on-chain evidence.

Verified nonce-reuse findings
475
Affected addresses
432
Spent after exposure
2,354.29 BTC
Up for grabs right now
15,285 sats
Proven keys incl. cross-key census
3,207

Snapshot: block 962,942, 2026-08-17 20:19 UTC. Explorer links show current state.

“Spent after exposure” is value that moved after the key became publicly computable; not proof of theft.

Every interesting finding, with numbers and evidence links.

Headline stats

The wallet that never noticed

One nonce, 2.55 million signatures

Brainwallets

Timestamp keys

Small scalars

Vanity nonces

Keys posted as public data

Stranger corners

The Android bug's footprint

What held up

So were the coins stolen?

The hunters

The chain as a message board (anyone-can-spend, unspent, 15,285 sats total at block 963,084)

The canon (history of exposed keys, with links)

2012: 12 addresses 2012 2013: 2 addresses 2013 2014: 52 addresses 2014 52 2015: 5 addresses 2015 2016: 3 addresses 2016 2017: 292 addresses 2017 292 2018: 3 addresses 2018 2019: 3 addresses 2019 2020: 10 addresses 2020 2021: 6 addresses 2021 2022: 12 addresses 2022 2023: 3 addresses 2023 2024: 4 addresses 2024 2025: 5 addresses 2025 2026: 7 addresses 2026 7
Last activity of the 419 affected addresses with observed history, by year (square-root scale). The 2026 bar is not zero.

Affected addresses

475 verified findings across 432 addresses. Search, filter, or select a heading to sort.

Download CSV
432 affected addresses
Loading findings from findings.csv…

Other findings

Every affected key below was empty at the snapshot.

CheckResult
Small-scalar keys370 distinct keys with d ≤ 224, including the 2015 puzzle keys. Example: d = 1 at 1EHNa6Q4Jz2uvNExL497mE43ikXhwF6kZm.
Timestamp keys26 funded addresses whose private keys equal Unix timestamps from 2009–2029. Example: 14xTHSRP6vbJv3xcXih2EnHYYCopR5ghJJ, a date in February 2009, weeks after Bitcoin launched. A March 2010 date, 137ZSN8hYxMRqwSJErvyTnu3jsh5LLwMGa, received 7.21 BTC.
Brainwallets6,367 addresses from 6,439 passwords in a 14.34-million-word dictionary. Yes, someone really used sha256("password"). Also funded: sha256("correct horse battery staple") and sha256("satoshi nakamoto").
Keys embedded as data5,095 distinct private keys found in OP_RETURNs, test strings, and puzzle material. Example: this transaction embeds sha256("") as a key, and it controls a funded address.
Replayable signatures71,749 SIGHASH_SINGLE signatures signed the constant z = 1 and can be replayed against another UTXO of the same key. Example: 15iwPhxErFDyQTJew81ok9hCbQNhyWuXq1 (7 such signatures).
Shared fixed nonce2,552,742 signatures used the constant nonce k = (n−1)/2 (r = 0000…3b78ce…), a July-2015 dust-sweep trick: the short DER encoding saved fees. Full census: 1,956 distinct private keys recovered and verified, including 1,034 keys that signed only once. Because k is a known constant, a single such signature is enough to expose the key. Evidence: an early cluster transaction and a November 2024 puzzle transaction.
Cross-key nonce joinEvery signature's r was matched against the x-coordinate of all 135.7 million signing keys with two or more signatures, plus a filtered pass over the rest (keys sign with another key's private scalar as nonce). Together with transitive nonce propagation this raises the verified total to 3,207 private keys; the 1,721 net-new keys held 0 BTC across 11,906 checked address variants. Example: this 2020 spend used a 2015-compromised key's private scalar as its nonce.
Single-signature leaks287 signatures from at least 46 keys used k = 1 (e.g. 1KonZ9DA1eW4rW6eKzjhw2yTjjvXEDTKia); 336 used |k| ≤ 224; one used k = d (block 450,655).
Taproot / SchnorrNo same-key nonce reuse. Two R values repeated across different signing keys; neither exposed a key. No key-path k = d across 352 million outputs.
Deep per-key attacksIn a 2,000,000-key sample of the 135.7 million keys with 2+ signatures, 24 more keys fell without any plain reuse: 13 had signed twice with one identical nonce, 7 had nonces differing by exactly 1, and 4 had nonces short enough (|k| < 2128) to fall to a lattice (HNP) attack.
Burned by designThe private key d = 1 is, not coincidentally, the BIP-173 specification's example bech32 address. It was still receiving dust the week of the snapshot; watcher bots sweep every deposit within minutes.
Still happeningThe newest spend from a proven-compromised key (15EmxXfWmD4UemererBjUVYjK4brjfGWPg) confirmed on 2026-06-19, eight weeks before the snapshot. The oldest date to 2012.
The wallet that never noticedThe largest spent-after-exposure case looks like an owner who never knew. 1BMzWp77j7x3GKDYNbCP3df7YG3UEw1vVE signed two inputs of one 2013-02-12 transaction with the same nonce, exposing its key to anyone, then simply kept operating: 533.82 BTC spent four days later, about 1,930.26 BTC over the following weeks, 6,622.25 BTC across its lifetime. No grab ever came; the activity before and after the leak is one continuous pattern. It was last seen spending 9,749 sats in December 2025.

Weak-key addresses are permanently unsafe and routinely swept by bots.

Show the 18 reviewed hashlocked outputs

FAQ

Is my wallet affected?

Almost certainly not. Every key here was exposed by broken signing software that reused randomness. Bitcoin Core, Electrum, hardware wallets, and mainstream mobile wallets derive nonces deterministically (RFC 6979 for ECDSA, BIP340 for Schnorr) and do not have this failure. The scan covered the entire chain; every affected address is listed in the table above. The cross-key census adds 1,721 further proven keys; all were empty, so they are not listed individually.

What is nonce reuse?

An ECDSA signature uses a one-time secret k. Signing two messages with the same key and the same k lets anyone compute the private key from the two signatures. Each finding here was proven that way: the key was recovered from the public signatures and checked against the on-chain public key.

What is the cross-key census?

Classic nonce-reuse detection compares a key's own signatures with each other. The census instead compared every signature's nonce fingerprint r against the public point of every key with two or more signatures ever seen on chain (135.7 million), extended to single-signature keys in a filtered pass: if they match, that signature's supposedly random nonce was actually another key's private scalar, so when that key is known, one signature is enough to expose the signer. Counting every such case chain-wide (a census, not a sample), together with transitive propagation, raised the verified total from 475 findings to 3,207 keys.

Were the coins stolen?

Unknown, and unknowable from chain data. 2,354 BTC moved out of affected addresses after their keys became publicly computable. Some of that was certainly owners spending as usual: the largest single case, about 1,930 BTC from one 2013 wallet, shows every sign of being the owner continuing as normal (see the wallet that never noticed). Watcher bots do sweep known-broken keys within minutes of any deposit. What can be said: every affected address was empty at the snapshot.

Who takes the money?

Mostly automated watchers. Once a key is publicly computable (a weak brainwallet, a reused nonce, d = 1), bots monitor its addresses around the clock. The moment a deposit confirms, a bot broadcasts a spend; when several bots compete, they outbid each other's fees until the miner takes most of it. Deposit to gone: typically minutes. That is why every affected address here reads zero, and why sending "just a little, to test" to a listed address donates it to the fastest bot.

Does this include the Coldcard data?

Not yet. The July 2026 Coldcard entropy flaw exposed keys at generation time, before any signature existed, so it needs a different analysis than this signature-level audit. That work is in progress and will be added in a future update; this incident report reconstructs the flaw in detail. If your seed was generated on affected Coldcard firmware, migrate it according to Coinkite's official advisory: the dice-entropy exception may apply, and a firmware update alone does not repair an existing seed.

My address is listed. What should I do?

Treat the key as public knowledge: never send funds to it again. Anything sent to a listed address can be taken by anyone. Move any remaining funds to a freshly generated wallet.

Method

3.760 billion signatures were scanned. Every reported key was recovered and verified; private keys and spend instructions are omitted.

Figures and validation

“First blocks” are the earliest confirmed signature blocks in each finding. “Lifetime spent” is the sum of confirmed spends from an address over its full history, not its balance at exposure or evidence of theft. “Spent after exposure” counts spends strictly after the second exposing signature; exposure-block spending is kept separate.

Full histories total 8,405.04393680 BTC spent, including 2,354.28513476 BTC after exposure and 255.73643522 BTC in exposure blocks. Values came from a local chain scan and transaction index, then matched the node’s UTXO set with 0 mismatches. P2PK-era spends totaling 0.50936589 BTC have no input-side date.

† 13 displayed P2PKH addresses never appeared on-chain. For those rows, the activity shown is from the same key’s used SegWit address; no spending is attributed to the unused address. Script and multisig spends that merely contain a key are not attributed to that key’s address.

Limits and edge cases

Weak-key searches are limited to the enumerated scalar, dictionary, and timestamp spaces.

Signature checks cover final on-chain signatures, not participant-level MuSig or FROST sessions.

The snapshot pass observed the one-block orphan at height 961,632 on 2026-08-08. Its roughly 3,900 duplicated transactions are filtered by transaction ID and do not change the findings.