Search key, WIF, mnemonic across 18 chains
CtrlK
Truncated Nonce
Nonce k = prefix·2^l + u with u < 2^l (only l random low bits). With enough signatures the key is recovered by an LLL lattice reduction.
newest for the address (1 to 100,000 supported \u2014 a single TXID fetches just that one transaction; larger counts take longer to fetch and analyze)
Balance
0 BTC
Received
0 BTC
TX
0
Instructions:\n1. Enter a Bitcoin TXID (64 hex) or an address.\n2. Signatures are tested across several truncated-nonce lengths (l random low bits).\n3. When enough signatures exist, the LLL reduction recovers the key.
Educational / read-only tool. Transaction data is fetched live from public block-explorer
APIs (blockstream.info, with blockchain.info as a fallback). R-reuse recovery only succeeds
on wallets that already leaked their key on-chain through a faulty signer — it demonstrates why ECDSA
nonce reuse is catastrophic. Never enter keys for wallets you use.