Search key, WIF, mnemonic across 18 chains CtrlK

R = 0 / S = 0 Signature Forgery

verify: x(u₁G + u₂Q) ≡ r — drop r≠0 and any (0, s) passes

newest for the address (exactly this many are scanned; a single TXID fetches just that one transaction)
Balance 0 BTC
Received 0 BTC
TX 0
Instructions:
1. Paste a Bitcoin TXID or address (its real signatures are loaded), OR just click Analyze to forge on the sample pubkey.
2. A signature with r = 0 is constructed and run through a correct verifier and a broken one — you see which check rejects it.
Educational / read-only tool. Transaction data is fetched live from public block-explorer APIs (blockstream.info, with blockchain.info as a fallback). R-reuse recovery only succeeds on wallets that already leaked their key on-chain through a faulty signer — it demonstrates why ECDSA nonce reuse is catastrophic. Never enter keys for wallets you use.