How a wallet falls, and how it holds
-
Key exposed
A public key is a point on a curve: the private key times a fixed starting point. Once a wallet has spent, that point sits on the ledger for anyone to read. Working backwards from the point to the private key is the whole attack. On these 16 to 32-bit curves, an agent with the right method does it in a second.
-
Key hidden
An address is only a SHA-256 hash of the public key. A wallet that has never spent shows nothing but that hash, so there is no point to work backwards from. The weak moment is paying: the key is visible until the payment confirms, and a fast agent can crack it in that gap.
-
Hash-only
The agent drops the curve entirely and signs with Lamport one-time signatures, built from nothing except SHA-256. Each key signs once and is replaced. With no curve there is no structure to exploit. Forging means guessing a 256-bit hash input, and every guess misses.
What is real here, and what is not
Real
The curve arithmetic, the three key-cracking methods (brute force, baby-step giant-step, Pollard's rho), the signatures, SHA-256 and the Lamport scheme. All of it is computed in your browser while you watch. Every stolen key is checked before funds move.
Not real
The wallets, balances and rent. No coins move anywhere. Nothing on this page can touch an actual wallet: Bitcoin's curve is 256 bits, and the same methods would need around 2128 steps against it. Nobody has shown that it is broken. The bunker is a rehearsal for the day someone does.