Search key, WIF, mnemonic across 18 chains CtrlK

Schnorr Nonce Reuse

Two BIP-340 Schnorr signatures (same key, same R, different messages) → d = (s1 − s2)/(e1 − e2) mod n.

newest for the address (1 to 100,000 supported \u2014 a single TXID fetches just that one transaction; larger counts take longer to fetch and analyze)
Balance 0 BTC
Received 0 BTC
TX 0
Instructions:\n1. Enter a Bitcoin TXID (64 hex) or an address.\n2. Every input\u2019s ECDSA signature (R, S, Z) is extracted and shown; R-reuse pairs recover the private key.\n3. Note: on-chain signatures here are ECDSA (legacy/segwit). BIP-340 Taproot Schnorr signature extraction (BIP-341 sighash) is not wired yet \u2014 the ECDSA R-reuse recovery below is fully working.
Educational / read-only tool. Transaction data is fetched live from public block-explorer APIs (blockstream.info, with blockchain.info as a fallback). R-reuse recovery only succeeds on wallets that already leaked their key on-chain through a faulty signer — it demonstrates why ECDSA nonce reuse is catastrophic. Never enter keys for wallets you use.