Not a hack — permission you granted. One approval, one “sign this message” popup, and a stranger can move your tokens whenever they choose. No gas. No transaction. Nothing to see in your activity feed until the balance is gone.
We show you every permission that is live right now — who holds it, what it can take, and the one call that cancels it.
It asks for no gas. It creates no transaction. Your wallet shows nothing pending, and revocation dashboards stay empty — because nothing has been approved yet. The signature is the approval, and it is redeemed later, on someone else's schedule.
By the time it appears on-chain, the tokens are gone. There is exactly one moment when this is preventable: before you click sign.
When wallets reuse nonces, leak partial key material through malformed signatures, or expose private keys via weak entropy sources — no existing tool flags it. The wallet looks "clean" on Chainalysis while the cryptographic foundation crumbles.
Contamination from ransomware, sanctioned entities, and mixer services spreads through UTXO chains and DeFi protocols. Traditional tools check known addresses. KeyExposureX maps the entire contamination lineage — including cross-chain propagation through bridges and wrapped assets.
Every wallet using exposed ECDSA public keys is theoretically vulnerable to Shor's algorithm. The post-quantum clock is ticking, yet no platform provides PQ readiness scoring. When quantum computing matures, billions in assets will have zero protection.
CERF™ is not a score. Scores imply a continuum, and the facts that matter here are decidable: either two signatures share a nonce — in which case the private key follows by algebra anyone can run — or they do not. Either a spender holds an unlimited allowance, or it does not. Averaging those into “73” destroys the only property worth reporting.
Findings also carry a position in the compromise lifecycle — material exposed, authority granted, key recoverable — so the answer is how far along this is and what time remains, rather than how risky it looks.
Pull every signature, output, and graph edge for the address. Multi-source RPC + indexer fan-out.
Run nonce-bias, entropy, R-value, taint-graph, and PQ-exposure detectors over the corpus.
Normalize, weight, and emit one 0–100 number plus a per-dimension breakdown. Sub-seconds.
Detects private key derivation vulnerabilities — ECDSA nonce reuse (k-value collisions that make the private key algebraically recoverable), brain wallet detection, weak entropy scanning, and cross-chain key correlation. Analyzes every signature the wallet ever produced.
"PlayStation 3 was hacked because Sony reused the same nonce. We scan your wallet's signatures for that exact vulnerability — in real time."
Analyzes transaction timing, spending velocity, output structure, and UTXO management for indicators of compromise. Catches automated draining, unauthorized access, and social-engineering signatures.
"When a 4-year-cold wallet suddenly broadcasts 47 outputs in 12 seconds — that's not the owner. That's a drainer."
Maps multi-hop contamination from ransomware wallets, OFAC-sanctioned addresses, mixers, and drainer contracts. Traces taint through UTXO chains, DeFi protocols, bridges, and wrapped assets — across chains.
"The address matches no direct sanctions hit. KeyExposureX screens it against Lazarus Group's 2024 Bybit drain."
Evaluates vulnerability to quantum attacks — Shor's algorithm against ECDSA, Grover's against hash schemes. Includes Harvest-Now-Decrypt-Later exposure window calculator and a concrete PQ migration engine with step-by-step paths to ML-DSA, SLH-DSA, and Taproot safety.
"Your public key has been exposed for 2,847 days. That's 2,847 days a nation-state has been collecting it for the day quantum arrives."
These are complements, not substitutes. Analytics platforms are excellent at the question they answer. A gasless Permit2 signature simply is not that question — nothing has reached the chain yet for them to analyse.
One platform. Seven modules. Each built to neutralize a specific cryptographic threat that every other security tool leaves wide open. All powered by the CERF™ scoring engine.
The world's first multi-dimensional cryptographic risk score. Four dimensions. ECDSA nonce reuse scanner. Brain wallet detection. PQ migration engine. Tamper-proof audit chain. One number that tells you the cryptographic truth —.
Pre-transaction firewall with address poisoning detection, CERF impact simulation, and tamper-proof audit chain. Shows you "after this send, your CERF drops from 72 to 41" before you sign.
24/7 portfolio surveillance. Rescans every 5 minutes. The moment a CERF score degrades or a new threat vector appears — you know first.
Real-time dust attack detection. Spots reconnaissance dusting, taint poisoning, and address probing campaigns before they compromise your UTXO set.
Maps your wallet's proximity to Lazarus Group, OFAC-sanctioned mixers, Pink Drainer, and the live OFAC sanctions list plus curated threat addresses. Screened against the live OFAC list and curated threat addresses on every check.
Autonomous threat response. When CERF crosses your threshold — quarantine, escalation, and compliance actions fire automatically. Rules you define, evaluated on every scan.
Tamper-proof, SHA-256 verified blockchain health certificates. Export as PDF. Present to auditors. Three types: Exposure Snapshot, Compliance Audit, PQ Readiness.
Here's what actually happens to teams that don't have pre-transaction cryptographic security. And what happens when they do.
Start free. Upgrade when you need enterprise-grade protection.
They answer a different question. Analytics platforms trace where funds came from — clustering, entity attribution, AML scoring — which is investigative work done after value has moved. KeyExposureX answers what can be taken from you next: the approvals and Permit2 grants that are live on your wallet right now, and what a signature request would authorise before you sign it. Nothing has reached the chain at that point, so it is outside what on-chain analytics can see. Most serious teams want both.
CERF (Cryptographic Exposure Risk Framework) is a 0–100 risk score computed across four dimensions: Key Exposure, Behavioral, Taint, and Post-Quantum. A score of 0 means minimal risk; 100 means critical. CERF is designed to be a regulatory-grade standard for cryptographic wallet safety.
KeyExposureX currently supports Bitcoin (BTC) and Ethereum (ETH) with full CERF scoring. Our architecture is chain-agnostic — additional chains including Solana, Polygon, and Avalanche are on the roadmap.
Quantum computers running Shor's algorithm could theoretically break ECDSA — the signature scheme used by Bitcoin and Ethereum. Any wallet whose public key has been exposed (by spending at least once) is vulnerable. KeyExposureX scores this vulnerability and provides phased migration plans to PQ-safe alternatives.
Yes. The Certification ($99/mo) and Enterprise plans include full API access. You can programmatically compute CERF scores, generate certificates, and query threat intelligence for any address.
Yes. The Starter plan is free forever and includes 1 CERF check per month, 5 SafeSend scans, and 1 health certificate. It's designed to let you explore the platform before committing.
Every Bitcoin and Ethereum address whose public key has been exposed will be vulnerable to Shor's algorithm the moment a cryptographically-relevant quantum computer comes online. KeyExposureX is the only platform scoring that exposure today.
Every day, drainer contracts and compromised wallets steal millions because security platforms only react after the transaction. KeyExposureX is the firewall that fires before the signature ever reaches the chain. Free to start. Built to scale.