The Glass Forest: Hunting for Broken Signatures in 3.76 Billion Signatures
I scanned every signature ever confirmed on the Bitcoin blockchain, 3.76 billion of them from 1.41 billion transactions, and found 475 proven cases of nonce reuse that leaked private keys. Expanding the search through transitive and cross-key analysis brought the total to 3,207 recoverable keys, every one verified against its on-chain public key. No private keys are stored anywhere, and every affected address was empty at the snapshot. Every claim below links to its on-chain evidence.
- Verified nonce-reuse findings
- 475
- Affected addresses
- 432
- Spent after exposure
- 2,354.29 BTC
- Up for grabs right now
- 15,285 sats
- Proven keys incl. cross-key census
- 3,207
Every interesting finding, with numbers and evidence links.
Headline stats
- Scanned 3,759,607,584 signature records from 1,412,921,348 transactions (760 GB, ~30 min on 32 cores, local Bitcoin Core node: block files + txindex)
- 475 verified nonce-reuse findings across 432 addresses
- 3,207 keys total: 1,486 from same-key + transitive nonce analysis, plus 1,721 net-new from the cross-key census
- 2,354.28513476 BTC spent after exposure; 255.73643522 BTC more inside exposure blocks; 8,405.04393680 BTC lifetime
- 0 BTC in any affected address at snapshot (block 962,942, 2026-08-17)
- ~85% of the 475 keys leaked in 2012–2015; the newest leaked in 2026
- Every key recovered in memory and verified d·G == pubkey; no private keys stored anywhere; balances matched the node's UTXO set with zero mismatches
The wallet that never noticed
- Address: 1BMzWp77j7x3GKDYNbCP3df7YG3UEw1vVE
- Exposed 2013-02-12 (block 220,772): two inputs of one transaction signed with the same nonce (identical r, different s) — key computable by anyone from that block on
- 533.82 BTC spent four days later; ~1,930.26 BTC moved post-exposure; 6,622.25 BTC lifetime; last seen spending 9,749 sats in December 2025
- Balance curve: 619.40 BTC peak (2013-01-20) → 131.18 (exposure day) → 42.71 (+1 month) → 0.00 (May 2013)
- Accounts for 82% of the audit's 2,354 BTC spent-after-exposure total
- The exposing transaction was publicly dissected on bitcointalk in January 2015 (Evil-Knievel cites it by txid as the same-r/different-s example)
One nonce, 2.55 million signatures
- Constant nonce k = (n−1)/2; signature fingerprint r starts
0000…3b78ce… - July 2015 dust-sweep trick: exceptionally short DER encoding saved fees; known constant, so one signature exposes the key
- 2,552,742 signatures → 1,956 distinct private keys recovered and verified; 1,034 of them signed only once
- Only 237 of the 1,956 were already proven by earlier passes; the census found the other 1,719
- Evidence: an early cluster transaction, a November 2024 puzzle transaction
- Publicly documented since 2015: the most repeated r value on the blockchain
Brainwallets
- 14.34-million-word dictionary → 6,439 passwords hit → 6,367 funded addresses
sha256("password")— fundedsha256("correct horse battery staple")— fundedsha256("satoshi nakamoto")— funded
Timestamp keys
- 26 funded addresses whose private keys are Unix timestamps (2009–2029)
- February 2009, weeks after launch: 14xTHSRP6vbJv3xcXih2EnHYYCopR5ghJJ
- March 2010, received 7.21 BTC: 137ZSN8hYxMRqwSJErvyTnu3jsh5LLwMGa
- Future dates: September 2026, August 2027, June 2029, September 2029
- Holidays: New Year's Day 2022, Christmas Day 2023
Small scalars
- 370 distinct keys with d ≤ 2^24, including the 2015 puzzle keys
- d = 1 backs both
1EHNa6Q4Jz2uvNExL497mE43ikXhwF6kZmand the BIP-173 example bech32 address — still dusted and swept the week of the snapshot - keys.lol enumerates every possible private key as an infinite book
Vanity nonces
Keys posted as public data
- 5,095 distinct private keys embedded in the chain as data, each matching a public key used on chain (OP_RETURNs, test strings, puzzle material)
- One transaction embeds
sha256("")as a key; it controls a funded address
Stranger corners
- Oldest exposure in the audit:
1A8TY7dxURcsRtPBs7fP6bDVzAgpgP4962reused a nonce in block 121,481 (May 2, 2011), 20 months before the attack's first public write-up; same key still spending in April 2026, 0.77 BTC since the leak - Unluckiest week:
1BTrViTDXhWrdw5ErBWSyP5LdzYmeuDTr2leaked 8 times in 11 days in March 2016, 7 of them inside six hours; 160.27 BTC moved after exposure - Undocumented burst: 13 findings first exposed across 2022 and early 2023, 11 of them packed into the same weeks of August–September 2022
- 71,749 legacy SIGHASH_SINGLE signatures commit to the constant z = 1 and are replayable against another compatible UTXO of the same key; one address has 7
- 287 signatures from at least 46 keys used k = 1 (example); one signature used k = d, its own private key as the nonce, in block 450,655
- Cross-key join: every signature's r matched against all 135.7 million signing keys with 2+ signatures, plus a filtered pass over the rest; one 2020 spend used a 2015-compromised key's private scalar as its nonce
- Deep sample: in 2,000,000 keys, 24 more fell outside the primary grouping — 13 repeated-nonce cases, 7 with nonces differing by exactly 1, 4 by a lattice (HNP) attack
The Android bug's footprint
- 9 of the 475 findings first exposed in the four weeks around the 2013-08-11 Android SecureRandom alert
- 17HHdLh4oXncuTejALwC6fgArVqPUxh2Sr — exposed August 6, five days before the alert
- 1HgRa96fuHCde6Rie4nwhaz1hZR694X4wj — exposed September 4, three weeks after
What held up
- Taproot/Schnorr: zero same-key nonce reuse, zero key-path k = d across 352 million outputs
- Mainstream wallets with deterministic nonces (RFC 6979 for ECDSA, BIP340 for Schnorr) appear nowhere in the findings
- Chain-wide scans found zero signatures with k = s, zero with k = r, zero nonce-chaining relations, zero nonces derived from block hashes or merkle roots (5.7 million candidates, orphan blocks included)
So were the coins stolen?
- Unknown from chain data; the 2,354.29 BTC is value in motion while keys were public, not proof of theft
- 17.23643265 BTC in a 3-of-5 multisig (881 UTXOs): one participating key leaked at the empty address
19zqrJ8K9LLQJzv5do4Di9GrWi7fAjCwcy; spending still needs three signatures. Evidence: transaction 1, transaction 2 - 18 hashlocked outputs, 859,986 sats: preimages public, but every reviewed spend path still needs an uncompromised signature
The hunters
- Puzzle #66 (September 2024): solver broadcast the 6.6 BTC claim; a bot replaced the unconfirmed transaction with a higher-fee copy and took 5.94 BTC. The next prize solver skipped the public mempool entirely
- The "bus × 12" seed (August 12, 2026):
bc1qqhx2nydhdw5qhruslhwf74hdjq88lh662m8xy2, provably derived from the seed phrase "bus" × 12 (BIP-84 index 1). Four deposits totaling 1.771 BTC in one block; every sweep confirmed in that block paid 100% of the money as miner fees. Even a 546-sat dusting two days later was swept. Sources: @ottosch_, @narcelio - The BIP-173 example address (d = 1) still receives dust every week; bots sweep deposits within minutes
- The smallest post-exposure spend in the audit is a single satoshi
The chain as a message board (anyone-can-spend, unspent, 15,285 sats total at block 963,084)
- The PortlandHODL open letter (one April 2026 transaction, seven 21-sat outputs):
- "PortlandHODL here -> MARA: I resign effectively when this TX is mined."
- "Gratitude is extended to Fred Thiel and Mike."
- "Slipstream is freedom and censorship resistance."
- "Slipstream should be shuttered, nobody with competence to maintain remains."
- "The flame of innovation burns bright in my soul and a hunger for success remains"
- "Listening to Linkin Park, reminiscing all that has transpired during the last 2 years. A lot."
- "Praise the Lord and may Christ guide me."
- A July 2026 transaction with 88 outputs ends in a 4,096-sat output whose entire locking script is the text "Money money money"; its OP_RETURN reads "You owe me money"
- "A pagar las deudas!" and one more bare-push output (21 sats each)
- 11,173 bare OP_TRUE outputs: 11,000 holding one satoshi each and 173 empty; every bigger one was already swept long ago
The canon (history of exposed keys, with links)
- Dec 2010: fail0verflow shows Sony signed PS3 software with a constant "random" number, recovering its root key — the 27C3 "Epic Fail" talk
- Jan 2013: Nils Schneider publishes the first public Bitcoin key recovery from reused nonces (archived copy); his example key signed 76 times with the same nonce —
1BFhrfTTZP3Nw4BNy4eX4KFLsn9ZeijcMm, his example transaction - Aug 2013: Android SecureRandom collides nonces chain-wide — bitcoin.org alert
- Dec 2014: blockchain.info's RNG breaks for hours; white-hat johoe sweeps hundreds of BTC and returns it — his thread, Finance Magnates
- 2015: the 1,000 BTC puzzle (announcement, funding transaction); #135 fell in July 2026, 13.5 BTC to a solver with 200 GPUs
- 2015: Castellucci's DEF CON talk, Cracking Cryptocurrency Brainwallets
- 2016: The Bitcoin Brain Drain counts 884 live brainwallets and documents the competing "drainer" bots
- 2018: Bitcoin Core adopts low-r signature grinding (PR 13666) — the 2015 trick done safely, fresh nonce each try
- 2019: Breitner and Heninger compute hundreds of keys from biased nonces (Biased Nonce Sense); ISE's Ethercombing finds the "Blockchain Bandit" (paper)
- 2023: Milk Sad's broken
bx seed(CVE-2023-39910, address lookup); Randstorm's weak browser wallets (Unciphered) - 2024: Dark Skippy, seed exfiltration inside signatures (disclosure); never seen in the wild
- 2025: a known linear relation between two nonces is enough to recover the key in closed form (Gilchrist et al., ePrint 2025/705); this audit's sample found 7 keys whose nonces differed by exactly 1
- 2026: the Coldcard entropy flaw — seeds leaked at generation time for five years (incident report, official advisory); the coordinated sweep is itself on-chain: 517 drain transactions and 134.9 BTC of dormant coins in block 960,185
Affected addresses
475 verified findings across 432 addresses. Search, filter, or select a heading to sort.
Loading findings from findings.csv… | ||||
Other findings
Every affected key below was empty at the snapshot.
| Check | Result |
|---|---|
| Small-scalar keys | 370 distinct keys with d ≤ 224, including the 2015 puzzle keys. Example: d = 1 at 1EHNa6Q4Jz2uvNExL497mE43ikXhwF6kZm. |
| Timestamp keys | 26 funded addresses whose private keys equal Unix timestamps from 2009–2029. Example: 14xTHSRP6vbJv3xcXih2EnHYYCopR5ghJJ, a date in February 2009, weeks after Bitcoin launched. A March 2010 date, 137ZSN8hYxMRqwSJErvyTnu3jsh5LLwMGa, received 7.21 BTC. |
| Brainwallets | 6,367 addresses from 6,439 passwords in a 14.34-million-word dictionary. Yes, someone really used sha256("password"). Also funded: sha256("correct horse battery staple") and sha256("satoshi nakamoto"). |
| Keys embedded as data | 5,095 distinct private keys found in OP_RETURNs, test strings, and puzzle material. Example: this transaction embeds sha256("") as a key, and it controls a funded address. |
| Replayable signatures | 71,749 SIGHASH_SINGLE signatures signed the constant z = 1 and can be replayed against another UTXO of the same key. Example: 15iwPhxErFDyQTJew81ok9hCbQNhyWuXq1 (7 such signatures). |
| Shared fixed nonce | 2,552,742 signatures used the constant nonce k = (n−1)/2 (r = 0000…3b78ce…), a July-2015 dust-sweep trick: the short DER encoding saved fees. Full census: 1,956 distinct private keys recovered and verified, including 1,034 keys that signed only once. Because k is a known constant, a single such signature is enough to expose the key. Evidence: an early cluster transaction and a November 2024 puzzle transaction. |
| Cross-key nonce join | Every signature's r was matched against the x-coordinate of all 135.7 million signing keys with two or more signatures, plus a filtered pass over the rest (keys sign with another key's private scalar as nonce). Together with transitive nonce propagation this raises the verified total to 3,207 private keys; the 1,721 net-new keys held 0 BTC across 11,906 checked address variants. Example: this 2020 spend used a 2015-compromised key's private scalar as its nonce. |
| Single-signature leaks | 287 signatures from at least 46 keys used k = 1 (e.g. 1KonZ9DA1eW4rW6eKzjhw2yTjjvXEDTKia); 336 used |k| ≤ 224; one used k = d (block 450,655). |
| Taproot / Schnorr | No same-key nonce reuse. Two R values repeated across different signing keys; neither exposed a key. No key-path k = d across 352 million outputs. |
| Deep per-key attacks | In a 2,000,000-key sample of the 135.7 million keys with 2+ signatures, 24 more keys fell without any plain reuse: 13 had signed twice with one identical nonce, 7 had nonces differing by exactly 1, and 4 had nonces short enough (|k| < 2128) to fall to a lattice (HNP) attack. |
| Burned by design | The private key d = 1 is, not coincidentally, the BIP-173 specification's example bech32 address. It was still receiving dust the week of the snapshot; watcher bots sweep every deposit within minutes. |
| Still happening | The newest spend from a proven-compromised key (15EmxXfWmD4UemererBjUVYjK4brjfGWPg) confirmed on 2026-06-19, eight weeks before the snapshot. The oldest date to 2012. |
| The wallet that never noticed | The largest spent-after-exposure case looks like an owner who never knew. 1BMzWp77j7x3GKDYNbCP3df7YG3UEw1vVE signed two inputs of one 2013-02-12 transaction with the same nonce, exposing its key to anyone, then simply kept operating: 533.82 BTC spent four days later, about 1,930.26 BTC over the following weeks, 6,622.25 BTC across its lifetime. No grab ever came; the activity before and after the leak is one continuous pattern. It was last seen spending 9,749 sats in December 2025. |
Weak-key addresses are permanently unsafe and routinely swept by bots.
Related, but not spendable
- 3-of-5 multisig · 17.23643265 BTC:
31oSGBBNrpCiENH3XMZpiP6GTC4tad4bMyheld this amount across 881 UTXOs. One participating key was exposed at the empty address19zqrJ8K9LLQJzv5do4Di9GrWi7fAjCwcy; spending still requires three signatures. Evidence: transaction 1 and transaction 2. - 18 hashlocked outputs · 859,986 sats: their preimages are public, but every reviewed spend path also requires a signature from a key not identified as compromised.
Show the 18 reviewed hashlocked outputs
3NRAEf2uBHo3U9FtjRivmARnmEsnHx5g7G: 250,000 sats36LgN86RKg2a3H9qR3uk3e3TGNGSq5qHBy: 125,000 sats33qmZ6GZb3GktwvRxp6NZLrNRxNhHzaUHu: 125,000 sats3KG4noM8vVc2aNhBTKNtPBrzbFpGiLiSMP: 125,000 satsbc1qqurjzctxl6t0askcskan9rktfqau2sawh6783u9hphzsxe4ymyjqqgjxsl: 97,399 sats3MLWfbLWCKeLWd9eYDwWPhJTir2gET6LQt: 20,000 satsbc1q5lpu6d2h05puxf3gpdg62ecrpxwvra47huw45uc2wql5rmj3malqgfy4ru: 10,000 satsbc1q8xjlevt2npv7f7ls4p2muwwlxawn60vr47zknxp24r94cye6gz5s3qpe6k: 10,000 satsbc1qngqmycntvnuux6s7dn846y4chyfwx3qsxs5phhp8p4zu6hae6wxq9r0q4c: 10,000 satsbc1qm3jx72qj5kpx3y2u24357z36r74t7u7w895gtq5g6tg4u84gx58qufh4dj: 8,000 satsbc1qqmtt7rjtxnnt8v3uynvpudleuztqs92tqcf3wu543hnujejy8yqs3yhadk: 6,000 satsbc1q7xulzwyp069y0evvtaceg4xenssa46s2zdaw73pw0n730ay2gj2qwype87: 5,700 satsbc1q58dldrda5jldlcdzschl25getp2al50npfsvh3ry9nr62ufraj3suq4cq4: 4,098 satsbc1qy5qrshgtu5ff2mk72xzlw8m77xphq87f5ug9fnur5ua3a8nkmyqqyfjh5n: 3,968 satsbc1qygzz54sw0qgyxkx8yh602ksve0swuvvq4ymwfg4yzvc46xchq8ss2syvwp: 3,221 satsbc1q00cqk3djf22wfpfqa08e47hj8qpugr56g6ap2860ncamp749530q7ag5ph: 1,000 satsbc1qj5t8q9vppwztcxk4m6h0ur0kjkh6ls6fn96actlepgqm075yw92s2jc759: 600 sats75bb6417afc7500a6389201a67bfc2428a1241170a214bbf6833a389191036fe, output 0: 55,000 sats
FAQ
Is my wallet affected?
Almost certainly not. Every key here was exposed by broken signing software that reused randomness. Bitcoin Core, Electrum, hardware wallets, and mainstream mobile wallets derive nonces deterministically (RFC 6979 for ECDSA, BIP340 for Schnorr) and do not have this failure. The scan covered the entire chain; every affected address is listed in the table above. The cross-key census adds 1,721 further proven keys; all were empty, so they are not listed individually.
What is nonce reuse?
An ECDSA signature uses a one-time secret k. Signing two messages with the same
key and the same k lets anyone compute the private key from the two signatures.
Each finding here was proven that way: the key was recovered from the public signatures and
checked against the on-chain public key.
What is the cross-key census?
Classic nonce-reuse detection compares a key's own signatures with each other. The census
instead compared every signature's nonce fingerprint r against the public point
of every key with two or more signatures ever seen on chain (135.7 million), extended to
single-signature keys in a filtered pass: if they match, that signature's supposedly random
nonce was actually another key's private scalar, so when that key is known, one signature
is enough to expose the signer. Counting every such case chain-wide (a census, not a sample),
together with transitive propagation, raised the verified total from 475 findings to
3,207 keys.
Were the coins stolen?
Unknown, and unknowable from chain data. 2,354 BTC moved out of affected addresses after their keys became publicly computable. Some of that was certainly owners spending as usual: the largest single case, about 1,930 BTC from one 2013 wallet, shows every sign of being the owner continuing as normal (see the wallet that never noticed). Watcher bots do sweep known-broken keys within minutes of any deposit. What can be said: every affected address was empty at the snapshot.
Who takes the money?
Mostly automated watchers. Once a key is publicly computable (a weak brainwallet, a reused
nonce, d = 1), bots monitor its addresses around the clock. The moment a deposit
confirms, a bot broadcasts a spend; when several bots compete, they outbid each other's fees
until the miner takes most of it. Deposit to gone: typically minutes. That is why every
affected address here reads zero, and why sending "just a little, to test" to a listed
address donates it to the fastest bot.
Does this include the Coldcard data?
Not yet. The July 2026 Coldcard entropy flaw exposed keys at generation time, before any signature existed, so it needs a different analysis than this signature-level audit. That work is in progress and will be added in a future update; this incident report reconstructs the flaw in detail. If your seed was generated on affected Coldcard firmware, migrate it according to Coinkite's official advisory: the dice-entropy exception may apply, and a firmware update alone does not repair an existing seed.
My address is listed. What should I do?
Treat the key as public knowledge: never send funds to it again. Anything sent to a listed address can be taken by anyone. Move any remaining funds to a freshly generated wallet.
Method
3.760 billion signatures were scanned. Every reported key was recovered and verified; private keys and spend instructions are omitted.
Figures and validation
“First blocks” are the earliest confirmed signature blocks in each finding. “Lifetime spent” is the sum of confirmed spends from an address over its full history, not its balance at exposure or evidence of theft. “Spent after exposure” counts spends strictly after the second exposing signature; exposure-block spending is kept separate.
Full histories total 8,405.04393680 BTC spent, including 2,354.28513476 BTC after exposure and 255.73643522 BTC in exposure blocks. Values came from a local chain scan and transaction index, then matched the node’s UTXO set with 0 mismatches. P2PK-era spends totaling 0.50936589 BTC have no input-side date.
† 13 displayed P2PKH addresses never appeared on-chain. For those rows, the activity shown is from the same key’s used SegWit address; no spending is attributed to the unused address. Script and multisig spends that merely contain a key are not attributed to that key’s address.
Limits and edge cases
Weak-key searches are limited to the enumerated scalar, dictionary, and timestamp spaces.
Signature checks cover final on-chain signatures, not participant-level MuSig or FROST sessions.
The snapshot pass observed the one-block orphan at height 961,632 on 2026-08-08. Its roughly 3,900 duplicated transactions are filtered by transaction ID and do not change the findings.