Is your wallet AGI- and quantum-ready?

Check if your address is in bunker mode: its public key has never been revealed, so breaking the cryptography behind signatures isn't enough to take your funds.

Only the address is needed. Never enter a recovery phrase or private key, here or anywhere else.

Why bunker mode, and why now

Ethereum researcher Justin Drake has warned that ECDSA, the signature scheme that protects Bitcoin and Ethereum, could be broken before quantum computers arrive, possibly within months. In that scenario, recovering a private key from a public key could take about a week on hardware anyone can buy, such as a large GPU cluster.

Among his reasons:

  • AI is speeding up mathematical research.
  • Elliptic curves have structure that attacks can exploit.
  • Fast quantum algorithms have sometimes led to fast classical ones.
  • A government that finds a break might keep it quiet.

His answer is bunker mode: keep funds at addresses whose public key is still hidden behind a hash. Whether a break comes from AI-assisted maths or a quantum computer, the attacker then has nothing to work on.

  • Large holders, such as exchanges, brokers and stablecoin issuers, should move most funds to addresses that have never signed.
  • After any signature, move what's left to a new address. It can come from the same seed.
  • Frequent signers, like oracles and rollup security councils, should rotate keys after every signature or add a hash-based signature such as SPHINCS+.
  • Don't panic or rush: wallets under 50 BTC have cover, since the roughly 20,000 exposed 50-BTC addresses from Bitcoin's early days would be attacked first.
  • In the long run, the answer is purely hash-based cryptography, and Ethereum's roadmap toward it should speed up.
Read Justin Drake's post on X

What the checker looks at

Three questions, answered from public blockchain data. No keys are involved.

  1. Has it ever sent a transaction?Its outgoing transaction count (nonce) must be 0 on Ethereum, Base, Arbitrum One, Optimism, Polygon PoS, BNB Smart Chain and Avalanche C-Chain. This also catches EIP-7702 delegations, because they raise the nonce too.
  2. Is there code at the address?There must be none: no EIP-7702 delegation attached, and no smart contract.
  3. Has it signed an approval while the nonce is still 0?An approval with this address as owner means it signed an off-chain permit (EIP-2612 or Permit2) that someone else submitted. The public key has leaked even though the address never sent a transaction.

What no checker can see: off-chain signatures such as Sign-In with Ethereum or signed messages, which go to a website and never reach the blockchain.

A bunker needs two things

The public key is never revealed

The address has never signed anything. This is what the checker verifies, and a website can help you with it.

The private key never touches the internet

No website can give you this: a key made in a browser tab has been on an online device. That's why there's no live generator here.

How to set up a bunker wallet

Serious amounts: use a hardware wallet

A hardware wallet creates the key on the device and never lets it out, so it covers both properties. Buy one directly from the manufacturer (for example Trezor, Ledger, Keystone or GridPlus), set it up with a new recovery phrase and receive funds on an address that has never signed. Each time you send from an address, move what's left to the next one.

Or: our offline generator

One self-contained HTML file that you download, check and open on a computer with no network connection. It creates a recovery phrase and its first five addresses, and shows nothing else.

  • Security policy blocks every network request
  • No outside scripts, styles, fonts or images
  • No analytics or tracking
  • Shows only the phrase and addresses, never a key
  • Unminified: read every line in a text editor
  • Reproducible build with a published checksum
Download generatorbunker-wallet-generator.html · version 1.0.0 · 164 KB

SHA-256 checksum

5291be7ee52550c49c451b2c73acede01772be961e9ac204f12f22bf32feda10

Check it before you open the file. The output must match exactly.

# macOS or Linux
shasum -a 256 bunker-wallet-generator.html

# Windows (Command Prompt or PowerShell)
certutil -hashfile bunker-wallet-generator.html SHA256

Also published as bunker-wallet-generator.html.sha256.

  1. Download the file and check its SHA-256 checksum.
  2. Copy it to an offline computer, or start a live USB system with networking turned off.
  3. Open it in a browser, generate a wallet and write the recovery phrase on paper. Don't photograph or print it.
  4. Note the addresses, press Clear and close the browser.
  5. Check address #0 here from any online device: it should show as bunker-ready. Then send funds to it.
How the file is built

The file bundles audited, open-source libraries with esbuild 0.21.5, unminified. Rebuilding from the source with the pinned versions below (yarn build:bunker-generator) produces a byte-identical file with the same checksum.

  • @scure/bip39@2.4.0sha512-82dxFbZUYboyOf0AXiydsQrFQ5Q4h9mX+O2UkE91ROYmsc0BKMGZLwDmy96Jpa2+vrtoxomjUhy1RPIgH/r2nA==
  • @scure/bip32@2.4.0sha512-i3DS0CptAocyvqE4n3SUkpzeQK4vJMFwWLofTwRiiKo2aWojBOfyMCgfKw9HVpO6fSY5AK86sHS/Uzn8kK9Few==
  • @scure/base@2.4.0sha512-thZ1TuJwFwBblOhgsjDKvvGirBxNp+wSvY/DR6tJBJOTDhdAAcHJ8Vbr2eFnqaxeca4+t0i9KBf+uHYGWwZORg==
  • @noble/curves@2.4.0sha512-P4/62zrgfH33CneE3Dn4WhJVA22YUU0eR51wKIan4NVRvwsA0YnPTwWGpNbpuacSujmSFLvyzpyuR30+fbq2Ew==
  • @noble/hashes@2.4.0sha512-X5XaVWZIBCT7HHZGm5I7ZQXDwLG+bGXuSrMQAW+7Zvl87h1kmc1ZB1VSRJcpUfoUrGQp4Fkoxm5kZ+Ms+aW+eA==

Its Content-Security-Policy allows only its own inline script and styles, by hash, and nothing else:

default-src 'none'; script-src 'sha256-+iMl+GrbSruEKqGvynd5rqO113ChsYrZ4i2oN+akUa8='; style-src 'sha256-fqntiKVupv1TBLB556DynIOkzbJS9nRW1dGketm8sVE='; connect-src 'none'; img-src 'none'; form-action 'none'; base-uri 'none'

After every signature, move on

Sending, approving or signing a message reveals the public key. Move what's left to the next address from the same phrase (#1, #2 and so on): each one has its own key pair, so it's a fresh bunker until it signs.

How your data is processed

  • Only an address. We never ask for a recovery phrase, private key or signature. If you paste something that looks like one, the page clears it and sends nothing.
  • Sent privately to our server. The address travels in the body of an encrypted request, not in the URL, so it stays out of your browser history and link previews.
  • Checked against public nodes. Our server asks public blockchain nodes (PublicNode and each network's official endpoint) for the address's transaction count and code on 7 networks, and for approval events on Ethereum. The node operators see these requests coming from our server, not from you.
  • Nothing stored. We don't save the address or the result, link them to you or cache them. To stop abuse, the server counts checks per IP address in memory for one minute.
  • Standard site analytics. Like the rest of moai.cash, this page uses Google Analytics and Vercel Analytics to count visits. They don't receive the address you check. See our privacy policy.

FAQ

What is a bunker wallet?

An address whose public key has never been revealed, controlled by a private key that has never been on an internet-connected device. On Ethereum and Bitcoin an address is a hash of the public key, so until the address signs something, an attacker would have to break the hash as well as the signature scheme to take its funds.

Why does sending a transaction reveal my public key?

Anyone can recover the signer’s public key from a signature. Once an address sends a transaction or signs an approval or a message, its public key is effectively public. That’s harmless today, but if ECDSA, the signature scheme behind Ethereum and Bitcoin, is broken, the private key could be computed from it.

I’ve only received funds. Is my address exposed?

No. Receiving doesn’t need a signature, so an address that has only received funds keeps its public key hidden, as long as it hasn’t signed approvals, permits or messages.

Why do you check several networks?

One private key controls the same address on Ethereum, Base, Arbitrum One, Optimism, Polygon PoS, BNB Smart Chain and Avalanche C-Chain and every other EVM network. A transaction on any of them reveals the public key for all of them.

What is EIP-7702, and why does it count?

EIP-7702, live on Ethereum since the Pectra upgrade in May 2025, lets a regular address delegate to smart contract code by signing an authorization. That signature reveals the public key, raises the address’s nonce and leaves a delegation marker as its code, so the checker catches it both ways.

Why can’t the checker see Sign-In with Ethereum?

Off-chain signatures, such as Sign-In with Ethereum, signed messages and off-chain orders, go straight to a website or app and never touch the blockchain. They reveal the public key to whoever receives them, but no public data shows they happened. If you’ve signed one with an address, treat it as exposed.

Does this work for Bitcoin addresses?

The checker covers Ethereum and EVM networks only. On Bitcoin, legacy (1…) and native SegWit (bc1q…) addresses hide the public key until you spend from them, so an address that has never spent is in bunker mode. Taproot (bc1p…) addresses contain the public key itself, so they’re exposed from the start, and so are the earliest pay-to-public-key coins, including those attributed to Satoshi.

What about smart contract wallets like Safe?

A contract account has no key of its own: its owners’ keys control it. It’s only as safe as those keys, so check each owner address. An owner that has signed a Safe transaction has revealed its public key, even if someone else submitted the transaction.

Should I move my funds right away?

Justin Drake’s advice is not to panic or rush. Large holders and anyone who signs often should act first. He notes that wallets under 50 BTC have cover, since the roughly 20,000 early Bitcoin addresses with 50 BTC each and exposed keys would be attacked first. The move itself is signed by the old address, which is fine as long as you move everything you want to protect.

Can the new address come from the same recovery phrase?

Yes. Each address from a recovery phrase has its own key pair, so the next one (#1, #2 and so on) is a fresh bunker until it signs. Drake notes the new address can come from the same seed.

Why isn’t there a wallet generator on this page?

A bunker also needs a private key that has never been on an internet-connected device, and a key made in a web page has been on one by definition. That’s why the generator is a file you download, check and open on an offline computer.