00 / why

wallets are protected by elliptic-curve signatures. if those ever break, anything whose public key is already published on-chain can be taken. the 'bunker mode' call of oct 7 2026 put it simply: move funds behind hashes.

on solana, the address is the ed25519 public key, so every solana wallet is already exposed. on bitcoin and ethereum a wallet stays behind a hash until it signs — then it's exposed too.

debunk is the open-source hash-based (winternitz) vault for solana, plus a scanner to show you where you stand.

01 / the scanner

paste any sol, btc or eth address. everything is read live, server-side, and read-only. nothing is stored.

  • · solana — always exposed. the address is the public key.
  • · bitcoin — exposed if it's taproot (bc1p…) or has ever spent; otherwise sealed behind a hash.
  • · ethereum — exposed once its nonce is above zero. contracts have no key of their own.
02 / the vault

deposit into your winternitz vault: funds sit behind a hash, not a public key. each spend reveals one one-time key, so the remainder auto-moves to a fresh vault.

status: devnet soon. unaudited. nothing is live yet.

03 / the hunters

four live demo agents (plus every agent booted by a burn) work the public bitcoin puzzle — a transaction funded in 2015 whose outputs each hide a private key in a known range (puzzle #n lies between 2^(n-1) and 2^n − 1). #161–256 were reclaimed by the creator in 2017, so we only use 1–160.

the work is real and runs in your browser: random start key in range, then incremental point addition on secp256k1, sha256 + ripemd160 of each compressed public key, compared against the puzzle's target hash. private keys never leave your device. the global counters only move when the server re-derives and verifies a sample key from each report, so they cannot be faked.

we only target published puzzle challenges — never anyone's real funds. agent assignment to holders is a preview until mint. any prize goes to $debunk buybacks. this is lottery-scale odds, not a promise of returns.

04 / how the search works

each agent picks a random start key inside its puzzle's range, 2^(n-1) … 2^n − 1, then walks upward by incremental point addition on secp256k1 (one inversion per 256 keys).

for every key: compressed public key → sha256 → ripemd160 → compared with the puzzle's hash160.

before searching, every worker runs a self-test: the known solved keys #1–#20 must derive their real addresses, and the same batched loop must hit keys 1, 3, 7 and 8. if anything fails, the search stays locked.

the 4 main screens stream live from a dedicated machine running the search 24/7: secp256k1 → sha256 → ripemd160, self-tested at boot, with periodic k·G re-verification of the point chain.

burned agents run in viewers' browsers until they get their own backend stream. there it runs only in the browsers of whoever is watching, pauses when the tab is hidden, and any found key is shown on that screen only — it never leaves the browser.

05 / burn to start

burn 100,000 $debunk on-chain to boot one agent. the server reads the transaction and checks the burn, the mint, the amount and your signature before the agent exists. one agent per burn signature.

live at launch. until then no agent can be booted.

06 / the odds, told honestly

puzzle #71: 2^70 ≈ 1.18×10^21 keys. searches restart at random points, so the median time to a hit is ln2 × range / rate ≈ 8.2×10^20 keys.

searcherspeedmedian time
one machine~640k keys/s≈ 4×10^7 years
one fast gpu~50m keys/s≈ 5.2×10^5 years
1,000,000 such gpus~5×10^13 keys/s≈ 6 months

terrible odds. real puzzle. we never promise a win.

07 / token

$debunk is not launched. the contract address, buy link, github and x go live at mint.

debunk is experimental and unaudited. nothing here is financial advice and $debunk promises no returns.

© 2026 debunk