keyexposed

FreeRead-onlyRuns in your browser

Is your public key exposed?

If elliptic-curve signatures ever break, the coins at risk are the ones whose public key is already on-chain. A fresh address that has never signed shows only a hash. Paste an address to see which kind you hold.

We will never ask for your seed phrase or private key. Anyone who does is a scammer.

Public addresses only. No wallet connect, no signatures, ever. Your browser asks public blockchain nodes directly; nothing is stored on our side and there are no analytics.

One per line, up to 25. Bitcoin, Ethereum and EVM chains, Solana.

Try:

Why people are checking this week

Two of Ethereum's best-known researchers, 7 October 2026.

"If it's not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea. If it's easy for you, do it. But be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined."

"Don't rush. While I believe there is cause for action a rushed migration would do more harm than good. Don't panic either. Moving assets to protected addresses is a simple, preventative step which does not require new cryptography or new wallets."

This is a precaution for a scenario that may or may not arrive soon. No practical break of Bitcoin or Ethereum signatures has been shown publicly. Nothing on this page is financial advice.

How we decide

The rules the checker applies, per chain. Everything is read from public data.

Bitcoin

Taprootbc1p…
Exposed
By design. A Taproot address encodes a (tweaked) public key, so it is visible as soon as the address is shared, spent or not.
Pay-to-public-key2009 to 2010 coins
Exposed
The output is the raw public key. Most early mined coins, including the genesis block reward, sit this way.
Legacy, SegWit, script1… bc1q… 3…
Until the address spends. The first spend reveals the key (or the script and its keys). Coins left there, or sent there later, sit behind a known key.

Ethereum and EVM chains

Account that has sentnonce > 0
Exposed
Any transaction signature reveals the key. The same key controls the address on every EVM chain, so one transaction anywhere exposes it everywhere. We check Ethereum, Base, BNB Chain, Arbitrum, Optimism, Polygon, Avalanche, Linea, Scroll, Gnosis, Unichain, Blast, Mantle and Sonic.
Account that never sentnonce = 0
Only the address (the last 20 bytes of a hash of the key) is on-chain, unless you signed something someone else submitted: Safe approvals, token permits, gasless swaps or smart-wallet operations put your signature on-chain too. Receiving reveals nothing.
Smart contract walletSafe and others
Depends
A contract has no key of its own. What matters is its owner keys. Owners who approved Safe transactions have signatures on-chain, so treat them as exposed.

Solana

Wallet accounts
Exposed
A Solana wallet address is the Ed25519 public key itself (Ed25519 is elliptic-curve too). A fresh Solana address does not help. Program-derived accounts, such as Squads vaults, have no key; their owners' keys matter.

If your key is exposed

Calm, in this order. Nothing here needs new software.

  1. Don't rush

    A rushed move to a mistyped or poisoned address is a far more likely loss than a curve break this month. Pick a quiet moment.

  2. Create a brand-new address

    Bitcoin: a fresh Native SegWit receive address (bc1q…) that has never been used. Ethereum: a new account that has never sent a transaction. Both can come from the seed phrase you already have.

  3. Send a small test first

    Move a small amount, confirm it arrives, then move the rest.

  4. Verify the address on your hardware wallet screen

    Clipboard malware and look-alike addresses swap the destination on your computer. Compare every character on the device itself.

  5. Keep it receive-only

    Treat the new address as a vault that only receives. When you do spend from it, move what's left to another fresh address in the same step.

What this can't tell you

"Hidden" means your key is not on-chain. It does not mean safe.

  • Signatures you give to others count too. Wallet logins and NFT listings reveal your key to whoever received them. Safe approvals, token permits and gasless swaps can end up on-chain inside someone else's transaction, which this check can't see.
  • We check 14 EVM networks. A transaction on any other EVM chain also exposes the key.
  • Anyone you have given your xpub to (an accounting app, a watch-only wallet) can derive every key in that account, hidden or not.
  • Early pay-to-public-key coins do not always show up under a 1… address in explorers. Project Eleven's risq list tracks these in depth.
  • Coins on an exchange sit behind the exchange's keys, not yours. Ask them.
  • Balances are native coins only. Tokens are not counted. USD values are approximate and skipped for coins without a reliable price feed.
  • Your seed phrase hygiene matters far more today than any of this.

What happens to your addresses

Short version: nothing on our side.

This page is static files. When you press check, your browser asks public infrastructure directly: PublicNode for EVM chains and Solana, with Base, BNB Chain, Arbitrum and Optimism public RPCs, dRPC and 1RPC as fallbacks; mempool.space (Blockstream as fallback) for Bitcoin; and Coinbase's public price feed. Those providers see the lookup, as they would from any wallet or block explorer, and if you check several addresses at once they can see they came from the same IP. For sensitive addresses, check one at a time or use a VPN or Tor. Our server never sees your addresses.

No accounts, no cookies, no analytics, nothing stored on our side (only your light or dark preference stays in your own browser). A Content Security Policy locks the page to exactly those endpoints. If something you paste looks like a seed phrase or private key, the page clears it before anything is sent.

Further reading