Search key, WIF, mnemonic across 18 chains CtrlK

BIP32 Nonce Reuse Across Paths → Master Key

k = ((z₁−z₂) + r(IL₁−IL₂)) / (s₁−s₂) → d_par = d_child − IL

newest for the address (exactly this many are scanned; a single TXID fetches just that one transaction)
Balance 0 BTC
Received 0 BTC
TX 0
Instructions:
1. Paste the master xpub in the XPUB box, and a child address/TXID in the main box.
2. Signatures are scanned for a reused nonce (equal r) across two child paths; both child keys and then the master key are recovered.
Educational / read-only tool. Transaction data is fetched live from public block-explorer APIs (blockstream.info, with blockchain.info as a fallback). R-reuse recovery only succeeds on wallets that already leaked their key on-chain through a faulty signer — it demonstrates why ECDSA nonce reuse is catastrophic. Never enter keys for wallets you use.