The drain doesn't look like a transaction. It looks like a message.

Someone May Already Have
Permission To Empty Your Wallet.

Not a hack — permission you granted. One approval, one “sign this message” popup, and a stranger can move your tokens whenever they choose. No gas. No transaction. Nothing to see in your activity feed until the balance is gone.

We show you every permission that is live right now — who holds it, what it can take, and the one call that cancels it.

Try:
See How CERF™ Works →
● LIVE SCAN 7 Threat Vectors
CERF™ Analysis — Live
BTC 1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa
74
CERF
Key Exposure82
Behavioral65
Taint71
Post-Quantum78
⚠ ECDSA nonce bias detected — potential key recovery vector
2-hop proximity to OFAC-sanctioned mixer cluster
Public key exposed — vulnerable to Shor's algorithm (quantum)
CERF™ Engine v3.0 Threats Indexed 14.2M+ Avg Decision Time 187ms OFAC Mixers Tracked 2,400+ Drainer Contracts 1,000+ Chains Supported BTC · ETH · SOL · BASE · ARB · POLY Post-Quantum Ready Shor + Grover CERF™ Engine v3.0 Threats Indexed 14.2M+ Avg Decision Time 187ms OFAC Mixers Tracked 2,400+ Drainer Contracts 1,000+ Chains Supported BTC · ETH · SOL · BASE · ARB · POLY Post-Quantum Ready Shor + Grover
PURPOSE-BUILT FOR
DeFi Protocols
Exchanges & Custodians
Compliance Teams
Wallet Providers
Forensic Investigators
⚖️ Institutional Treasury
LIVE · SINCE JAN 1, 2026
$0
stolen from crypto wallets while this page has been open.
Behavioral analytics didn't see it coming.
"

Every other security platform tells you
the money was stolen.
We tell you it's about to be.

— The KeyExposureX Manifesto
seconds
Pre-Tx Decision Time
4D
CERF™ Risk Dimensions
10
Failure Modes Scanned
PQ
Migration Engine + HNDL
The Blind Spot

The Popup That Empties
Wallets Says “Sign This Message”

It asks for no gas. It creates no transaction. Your wallet shows nothing pending, and revocation dashboards stay empty — because nothing has been approved yet. The signature is the approval, and it is redeemed later, on someone else's schedule.

By the time it appears on-chain, the tokens are gone. There is exactly one moment when this is preventable: before you click sign.

What your wallet shows you
Signature request
Uniswap Permit2
PermitSingle   token: 0xa0b8…eb48
amount: 1461501637330902918203684832716283019655932542975
What KeyExposureX shows you
DO NOT SIGN
Signing this lets 0xbadc0ffe… move ALL of your USDC, with no expiry — including USDC you receive in future.

Key Exposure Goes Undetected

When wallets reuse nonces, leak partial key material through malformed signatures, or expose private keys via weak entropy sources — no existing tool flags it. The wallet looks "clean" on Chainalysis while the cryptographic foundation crumbles.

Taint Propagation Is Invisible

Contamination from ransomware, sanctioned entities, and mixer services spreads through UTXO chains and DeFi protocols. Traditional tools check known addresses. KeyExposureX maps the entire contamination lineage — including cross-chain propagation through bridges and wrapped assets.

Quantum Threat Is Ignored

Every wallet using exposed ECDSA public keys is theoretically vulnerable to Shor's algorithm. The post-quantum clock is ticking, yet no platform provides PQ readiness scoring. When quantum computing matures, billions in assets will have zero protection.

Traditional Analytics
  • Transaction pattern matching only
  • Known-address blacklists (reactive)
  • Behavioral heuristics & AML flags
  • No cryptographic analysis whatsoever
  • No signature or entropy inspection
  • Zero post-quantum assessment
  • No cross-chain exposure lineage
  • Detects threats after compromise
VS
KeyExposureX CERF™
  • Deep cryptographic state analysis
  • Key exposure & nonce anomaly detection
  • Signature entropy scoring
  • Multi-hop taint propagation mapping
  • Post-quantum vulnerability scoring
  • Cross-chain exposure lineage tracking
  • Compliance-grade health certificates
  • Proactive — identifies risk before exploits
CERF™ · Cryptographic Exposure Risk Framework

One Number.
Total Wallet Truth.

CERF™ is not a score. Scores imply a continuum, and the facts that matter here are decidable: either two signatures share a nonce — in which case the private key follows by algebra anyone can run — or they do not. Either a spender holds an unlimited allowance, or it does not. Averaging those into “73” destroys the only property worth reporting.

PROVEN Mathematics guarantees it. The derivation is shown, so you can check the claim instead of trusting it.
STRUCTURAL The system's design guarantees it. An unlimited allowance means the holder can move your balance — that is what an allowance is.
OBSERVED A recorded fact from an authoritative source, such as the live OFAC sanctions list.
UNCHECKED The check could not run. We say so. It is never reported as clean.

Findings also carry a position in the compromise lifecycle — material exposed, authority granted, key recoverable — so the answer is how far along this is and what time remains, rather than how risky it looks.

STAGE 01

Acquisition

Pull every signature, output, and graph edge for the address. Multi-source RPC + indexer fan-out.

STAGE 02

Cryptographic Analysis

Run nonce-bias, entropy, R-value, taint-graph, and PQ-exposure detectors over the corpus.

STAGE 03

Weighted CERF Score

Normalize, weight, and emit one 0–100 number plus a per-dimension breakdown. Sub-seconds.

01
Proven & structural

Key Exposure Analysis

Detects private key derivation vulnerabilities — ECDSA nonce reuse (k-value collisions that make the private key algebraically recoverable), brain wallet detection, weak entropy scanning, and cross-chain key correlation. Analyzes every signature the wallet ever produced.

"PlayStation 3 was hacked because Sony reused the same nonce. We scan your wallet's signatures for that exact vulnerability — in real time."
Detection ECDSA r-value dedup · brain wallet DB · weak entropy scan · nonce collision proof
Nonce Reuse Scanner Brain Wallet Detection Entropy Analysis Key Recovery Proof
02
Observed

Behavioral Pattern Scoring

Analyzes transaction timing, spending velocity, output structure, and UTXO management for indicators of compromise. Catches automated draining, unauthorized access, and social-engineering signatures.

"When a 4-year-cold wallet suddenly broadcasts 47 outputs in 12 seconds — that's not the owner. That's a drainer."
Detection Velocity anomalies · output entropy · sweep pattern fingerprints
Timing Analysis Spend Patterns UTXO Behavior Anomaly Detection
03
Observed

Taint & Contamination Mapping

Maps multi-hop contamination from ransomware wallets, OFAC-sanctioned addresses, mixers, and drainer contracts. Traces taint through UTXO chains, DeFi protocols, bridges, and wrapped assets — across chains.

"The address matches no direct sanctions hit. KeyExposureX screens it against Lazarus Group's 2024 Bybit drain."
Detection Graph-walk proximity · OFAC index · cross-chain bridge taint
Proximity Scoring Lineage Tracking Cross-Chain Taint OFAC Mapping
04
Structural

Post-Quantum Readiness

Evaluates vulnerability to quantum attacks — Shor's algorithm against ECDSA, Grover's against hash schemes. Includes Harvest-Now-Decrypt-Later exposure window calculator and a concrete PQ migration engine with step-by-step paths to ML-DSA, SLH-DSA, and Taproot safety.

"Your public key has been exposed for 2,847 days. That's 2,847 days a nation-state has been collecting it for the day quantum arrives."
Detection HNDL window calculator · PQ migration engine · Shor-class scoring · BIP-360 readiness
HNDL Calculator Migration Engine Shor's Vulnerability PQ Migration Path
Two different questions
Blockchain analytics
Where did this money come from?
Traces funds backwards through the chain
Clusters addresses to entities and services
Scores counterparties for AML and compliance
Answers after value has moved
Built for investigators and compliance desks
vs
KeyExposureX
What can be taken from me next?
Every live approval and Permit2 grant, with the revoke call
Decodes a signature request before you sign it
Live OFAC sanctions screening, refreshed daily
ECDSA nonce reuse and signature forensics
Keys reused across address forms and across chains
Answers before value moves

These are complements, not substitutes. Analytics platforms are excellent at the question they answer. A gasless Permit2 signature simply is not that question — nothing has reached the chain yet for them to analyse.

Seven Weapons

Every Attack Vector Has a
Dedicated Kill Switch.

One platform. Seven modules. Each built to neutralize a specific cryptographic threat that every other security tool leaves wide open. All powered by the CERF™ scoring engine.

Core Engine

CERF™ v3 Scoring Engine

The world's first multi-dimensional cryptographic risk score. Four dimensions. ECDSA nonce reuse scanner. Brain wallet detection. PQ migration engine. Tamper-proof audit chain. One number that tells you the cryptographic truth —.

4DRisk Dimensions
8New Scanners
v3Engine Version
Kills: drainer transfers, poisoned addresses, tainted receives

SafeSend™ v3

Pre-transaction firewall with address poisoning detection, CERF impact simulation, and tamper-proof audit chain. Shows you "after this send, your CERF drops from 72 to 41" before you sign.

6Layer
10FM
APDetect
Kills: silent key degradation, CERF drift

WatchDog™

24/7 portfolio surveillance. Rescans every 5 minutes. The moment a CERF score degrades or a new threat vector appears — you know first.

Kills: dust attacks, taint poisoning, recon probes

DustShield™

Real-time dust attack detection. Spots reconnaissance dusting, taint poisoning, and address probing campaigns before they compromise your UTXO set.

Enterprise
Kills: hidden mixer/sanctioned entity exposure

PBTI-X™ Threat Intel

Maps your wallet's proximity to Lazarus Group, OFAC-sanctioned mixers, Pink Drainer, and the live OFAC sanctions list plus curated threat addresses. Screened against the live OFAC list and curated threat addresses on every check.

Enterprise
Kills: delayed response to critical threats

AutoShield-X™

Autonomous threat response. When CERF crosses your threshold — quarantine, escalation, and compliance actions fire automatically. Rules you define, evaluated on every scan.

Enterprise
Kills: regulatory gaps, audit uncertainty

CertiTrust-X™

Tamper-proof, SHA-256 verified blockchain health certificates. Export as PDF. Present to auditors. Three types: Exposure Snapshot, Compliance Audit, PQ Readiness.

Real Scenarios. Real Threats Blocked.

Without KeyExposureX, You're Flying Blind.

Here's what actually happens to teams that don't have pre-transaction cryptographic security. And what happens when they do.

Exchange · Deposit Desk

$4.2M deposit from a wallet with exposed ECDSA keys

Without KX Deposit accepted. Wallet drained 6 hours later. Exchange is liable for commingled tainted funds.
With KX SafeSend flags CERF 84 (Critical). Deposit blocked. Exchange avoids $4.2M liability.
DeFi Protocol · Liquidity Pool

$800K liquidity deposit 2 hops from Tornado Cash

Without KX Funds accepted. OFAC subpoena arrives 3 months later. Protocol tagged as mixer-adjacent.
With KX PBTI-X detects 2-hop Tornado proximity. CERF taint score: 91. Deposit rejected automatically.
Compliance · Quarterly Audit

Auditor asks: "Are your wallets quantum-safe?"

Without KX No answer. No data. Three-week scramble to produce a manual assessment that's already stale.
With KX CertiTrust-X generates PQ Readiness Certificate in 30 seconds. SHA-256 verified. PDF exported. Done.
Forensics · Incident Response

Ransomware payment traced to your cold storage

Without KX A destination that passes a direct sanctions check can still hold an unlimited approval to a known drainer.
With KX Standing authority is enumerated before you send, and the destination is screened against the live OFAC list.
Individual · P2P OTC Trade

Stranger sends 3 BTC from a nonce-reuse wallet

Without KX Trade accepted. Private key was already extractable via nonce bias. Wallet drained within 48 hours.
With KX SafeSend catches ECDSA nonce bias. Key Exposure score: 89. Trade refused. Assets safe.
⚖️ Fund · $200M AUM Portfolio

Portfolio wallet's CERF drifts from 22 to 67 overnight

Without KX No monitoring. Score degradation is invisible. By morning, the wallet is 1 hop from a sanctioned mixer cluster.
With KX WatchDog catches drift at CERF 45. AutoShield quarantines. Compliance notified. Zero loss.
Pricing

Cryptographic Security
at Every Scale

Start free. Upgrade when you need enterprise-grade protection.

Starter
Free
Explore the platform
  • 1 CERF check / month
  • 5 SafeSend scans
  • 1 health certificate
  • Basic DustShield monitoring
  • PBTI-X™ threat intel
  • AutoShield-X™
  • API access
Personal
$7/mo
For anyone holding their own keys
  • 50 CERF checks / month
  • Unlimited SafeSend scans
  • 10 certificates
  • Full DustShield + WatchDog
  • Basic PBTI-X™ access
  • AutoShield-X™
  • API access
Most Popular
Pro
$19/mo
For active traders and multi-wallet users
  • Unlimited CERF checks
  • Unlimited SafeSend scans
  • 50 certificates
  • Full PBTI-X™ threat intel
  • AutoShield-X™ basic playbooks
  • WatchDog priority scanning
  • API access
Certification
$99/mo
For funds, desks and compliance teams
  • Everything in Pro
  • Unlimited certificates
  • Full AutoShield-X™
  • API access (10K calls/mo)
  • Priority support
  • Audit-ready reports
  • Custom playbooks
Enterprise
Custom
For exchanges & institutions
  • Unlimited everything
  • Unlimited API access
  • Custom integrations
  • Dedicated account manager
  • SLA guarantee (99.9%)
  • On-premise deployment option
  • Custom certificate signing keys

Frequently Asked Questions

How is KeyExposureX different from Chainalysis or Elliptic?

They answer a different question. Analytics platforms trace where funds came from — clustering, entity attribution, AML scoring — which is investigative work done after value has moved. KeyExposureX answers what can be taken from you next: the approvals and Permit2 grants that are live on your wallet right now, and what a signature request would authorise before you sign it. Nothing has reached the chain at that point, so it is outside what on-chain analytics can see. Most serious teams want both.

What is a CERF score?

CERF (Cryptographic Exposure Risk Framework) is a 0–100 risk score computed across four dimensions: Key Exposure, Behavioral, Taint, and Post-Quantum. A score of 0 means minimal risk; 100 means critical. CERF is designed to be a regulatory-grade standard for cryptographic wallet safety.

What blockchains do you support?

KeyExposureX currently supports Bitcoin (BTC) and Ethereum (ETH) with full CERF scoring. Our architecture is chain-agnostic — additional chains including Solana, Polygon, and Avalanche are on the roadmap.

What does "post-quantum readiness" mean?

Quantum computers running Shor's algorithm could theoretically break ECDSA — the signature scheme used by Bitcoin and Ethereum. Any wallet whose public key has been exposed (by spending at least once) is vulnerable. KeyExposureX scores this vulnerability and provides phased migration plans to PQ-safe alternatives.

Can I integrate CERF into my own platform?

Yes. The Certification ($99/mo) and Enterprise plans include full API access. You can programmatically compute CERF scores, generate certificates, and query threat intelligence for any address.

Is there a free tier?

Yes. The Starter plan is free forever and includes 1 CERF check per month, 5 SafeSend scans, and 1 health certificate. It's designed to let you explore the platform before committing.

⚛︎ THE QUANTUM CLOCK · CRPC ETA

ECDSA dies in

0days

Every Bitcoin and Ethereum address whose public key has been exposed will be vulnerable to Shor's algorithm the moment a cryptographically-relevant quantum computer comes online. KeyExposureX is the only platform scoring that exposure today.

Shor's Algorithm Public Key Exposure Risk NIST PQC Migration Planning

One Bad Signature Ends Everything.
Don't Be the Next Headline.

Every day, drainer contracts and compromised wallets steal millions because security platforms only react after the transaction. KeyExposureX is the firewall that fires before the signature ever reaches the chain. Free to start. Built to scale.

No credit card required Free tier available API documentation included