Check if your address is in bunker mode: its public key has never been revealed, so breaking the cryptography behind signatures isn't enough to take your funds.
Only the address is needed. Never enter a recovery phrase or private key, here or anywhere else.
Ethereum researcher Justin Drake has warned that ECDSA, the signature scheme that protects Bitcoin and Ethereum, could be broken before quantum computers arrive, possibly within months. In that scenario, recovering a private key from a public key could take about a week on hardware anyone can buy, such as a large GPU cluster.
Among his reasons:
His answer is bunker mode: keep funds at addresses whose public key is still hidden behind a hash. Whether a break comes from AI-assisted maths or a quantum computer, the attacker then has nothing to work on.
Three questions, answered from public blockchain data. No keys are involved.
What no checker can see: off-chain signatures such as Sign-In with Ethereum or signed messages, which go to a website and never reach the blockchain.
The public key is never revealed
The address has never signed anything. This is what the checker verifies, and a website can help you with it.
The private key never touches the internet
No website can give you this: a key made in a browser tab has been on an online device. That's why there's no live generator here.
A hardware wallet creates the key on the device and never lets it out, so it covers both properties. Buy one directly from the manufacturer (for example Trezor, Ledger, Keystone or GridPlus), set it up with a new recovery phrase and receive funds on an address that has never signed. Each time you send from an address, move what's left to the next one.
One self-contained HTML file that you download, check and open on a computer with no network connection. It creates a recovery phrase and its first five addresses, and shows nothing else.
SHA-256 checksum
5291be7ee52550c49c451b2c73acede01772be961e9ac204f12f22bf32feda10Check it before you open the file. The output must match exactly.
# macOS or Linux
shasum -a 256 bunker-wallet-generator.html
# Windows (Command Prompt or PowerShell)
certutil -hashfile bunker-wallet-generator.html SHA256Also published as bunker-wallet-generator.html.sha256.
The file bundles audited, open-source libraries with esbuild 0.21.5, unminified. Rebuilding from the source with the pinned versions below (yarn build:bunker-generator) produces a byte-identical file with the same checksum.
Its Content-Security-Policy allows only its own inline script and styles, by hash, and nothing else:
default-src 'none'; script-src 'sha256-+iMl+GrbSruEKqGvynd5rqO113ChsYrZ4i2oN+akUa8='; style-src 'sha256-fqntiKVupv1TBLB556DynIOkzbJS9nRW1dGketm8sVE='; connect-src 'none'; img-src 'none'; form-action 'none'; base-uri 'none'Sending, approving or signing a message reveals the public key. Move what's left to the next address from the same phrase (#1, #2 and so on): each one has its own key pair, so it's a fresh bunker until it signs.
An address whose public key has never been revealed, controlled by a private key that has never been on an internet-connected device. On Ethereum and Bitcoin an address is a hash of the public key, so until the address signs something, an attacker would have to break the hash as well as the signature scheme to take its funds.
Anyone can recover the signer’s public key from a signature. Once an address sends a transaction or signs an approval or a message, its public key is effectively public. That’s harmless today, but if ECDSA, the signature scheme behind Ethereum and Bitcoin, is broken, the private key could be computed from it.
No. Receiving doesn’t need a signature, so an address that has only received funds keeps its public key hidden, as long as it hasn’t signed approvals, permits or messages.
One private key controls the same address on Ethereum, Base, Arbitrum One, Optimism, Polygon PoS, BNB Smart Chain and Avalanche C-Chain and every other EVM network. A transaction on any of them reveals the public key for all of them.
EIP-7702, live on Ethereum since the Pectra upgrade in May 2025, lets a regular address delegate to smart contract code by signing an authorization. That signature reveals the public key, raises the address’s nonce and leaves a delegation marker as its code, so the checker catches it both ways.
Off-chain signatures, such as Sign-In with Ethereum, signed messages and off-chain orders, go straight to a website or app and never touch the blockchain. They reveal the public key to whoever receives them, but no public data shows they happened. If you’ve signed one with an address, treat it as exposed.
The checker covers Ethereum and EVM networks only. On Bitcoin, legacy (1…) and native SegWit (bc1q…) addresses hide the public key until you spend from them, so an address that has never spent is in bunker mode. Taproot (bc1p…) addresses contain the public key itself, so they’re exposed from the start, and so are the earliest pay-to-public-key coins, including those attributed to Satoshi.
A contract account has no key of its own: its owners’ keys control it. It’s only as safe as those keys, so check each owner address. An owner that has signed a Safe transaction has revealed its public key, even if someone else submitted the transaction.
Justin Drake’s advice is not to panic or rush. Large holders and anyone who signs often should act first. He notes that wallets under 50 BTC have cover, since the roughly 20,000 early Bitcoin addresses with 50 BTC each and exposed keys would be attacked first. The move itself is signed by the old address, which is fine as long as you move everything you want to protect.
Yes. Each address from a recovery phrase has its own key pair, so the next one (#1, #2 and so on) is a fresh bunker until it signs. Drake notes the new address can come from the same seed.
A bunker also needs a private key that has never been on an internet-connected device, and a key made in a web page has been on one by definition. That’s why the generator is a file you download, check and open on an offline computer.