Bitcoin key exposure audit

Verified ECDSA nonce-reuse findings from a full-chain scan.

No affected address held funds at the snapshot.

Verified nonce-reuse findings
475
Affected addresses
432
Spent after exposure
2,354.27117192 BTC
Snapshot balance
0 BTC

Snapshot: block 961,768, 2026-08-09 20:00 UTC. Explorer links show current state.

Affected addresses

475 verified findings across 432 addresses. Search, filter, or select a heading to sort.

Download CSV
432 affected addresses
Loading findings from findings.csv

Other findings

Every affected key below was empty at the snapshot.

CheckResult
Small-scalar keys369 distinct keys with d ≤ 224, including the 2015 puzzle keys.
Timestamp keys42 funded addresses whose private keys equal Unix timestamps from 2008–2031.
Brainwallets6,367 addresses from 6,439 passwords in a 14.34-million-word dictionary.
Keys embedded as data5,095 distinct private keys found in OP_RETURNs, test strings, and puzzle material.
Replayable signatures71,863 SIGHASH_SINGLE signatures signed the constant z = 1 and can be replayed against another UTXO of the same key.
Shared fixed nonce2,552,755 signatures from at least 122 keys used one nonce in 2018. Keys used twice through the service are compromised; keys with one such signature are unaffected.
Single-signature leaks287 signatures from at least 46 keys used k = 1; 336 used |k| ≤ 224; one used k = d.
Taproot / SchnorrNo same-key nonce reuse. Two R values repeated across different signing keys; neither exposed a key. No key-path k = d across 352 million outputs.

Weak-key addresses are permanently unsafe and routinely swept by bots.

Show the 18 reviewed hashlocked outputs

Method

3.760 billion signatures were scanned. Every reported key was recovered and verified; private keys and spend instructions are omitted.

Figures and validation

“First blocks” are the earliest confirmed signature blocks in each finding. “Lifetime spent” is the sum of confirmed spends from an address over its full history, not its balance at exposure or evidence of theft. “Spent after exposure” counts spends strictly after the second exposing signature; exposure-block spending is kept separate.

Full histories total 8,405.04393680 BTC spent, including 2,354.27117192 BTC after exposure and 255.73643522 BTC in exposure blocks. Values came from a local chain scan and transaction index, then matched the node’s UTXO set with 0 mismatches. P2PK-era spends totaling 0.50936589 BTC have no input-side date.

† Thirteen displayed P2PKH addresses never appeared on-chain. For those rows, the activity shown is from the same key’s used SegWit address; no spending is attributed to the unused address. Script and multisig spends that merely contain a key are not attributed to that key’s address.

Limits and edge cases

Weak-key searches are limited to the enumerated scalar, dictionary, and timestamp spaces.

Signature checks cover final on-chain signatures, not participant-level MuSig or FROST sessions.

The snapshot pass observed the one-block orphan at height 961,632 on 2026-08-08. Its roughly 3,900 duplicated transactions are filtered by transaction ID and do not change the findings.