Only paste an address. Never enter a seed phrase or private key here, or on any site that asks for one.
What "exposed" means
Every Bitcoin address is controlled by a private key. The matching public key can be derived from the private key, but not the other way around, at least not with any computer that exists today.
Most address types don't put the public key on-chain. They publish only a hash of it. The public key is revealed when you spend from the address, because the network needs it to check your signature. Taproot addresses are different: the public key is the address.
A large enough quantum computer running Shor's algorithm could, in principle, work out a private key from a public key. That machine doesn't exist yet, and no one knows when it will. But coins sitting behind an exposed key would be the first ones in reach.
| Address type | Public key on-chain? | Starts with |
|---|---|---|
| Legacy (P2PKH) | After the first spend | 1 |
| Native SegWit (P2WPKH) | After the first spend | bc1q |
| Script hash (P2SH / P2WSH) | After the first spend (in the script) | 3, long bc1q |
| Taproot (P2TR) | Always, in the address itself | bc1p |
| Pay-to-pubkey (P2PK) | Always (mostly early coins, no address format) | n/a |
Questions
Can someone steal my coins today because my key is exposed?
No. Exposed public keys are normal. Most bitcoin ever spent has revealed one. The elliptic-curve cryptography behind Bitcoin is not broken. This check is about long-term risk, not something you need to rush to fix tonight.
My key is exposed and the address still has funds. What should I do?
When it's convenient, send the funds to a brand-new address from your own wallet, one that has never received or spent before. Most modern wallets make a fresh address for every receive. After that, don't send anything back to the old address.
Why is Taproot always flagged?
A Taproot address encodes a (tweaked) public key directly, so the key is visible as soon as anyone sees the address. Taproot has other real benefits. This is just one trade-off to know about. Bitcoin developers are discussing post-quantum upgrades (for example BIP-360), and if adopted they'd give everyone a migration path.
My key isn't exposed. Am I fully safe?
From this specific risk, you're in the best position you can be. Keep it that way: don't reuse addresses, and keep your seed phrase offline. The far more common ways people lose bitcoin are phishing, fake wallet apps, and "recovery" scams.
What happens to the address I paste?
Your browser sends it straight to the public mempool.space API to read its on-chain history. This site has no server and stores nothing. If you'd rather not link your IP to an address, use a VPN or Tor, or run your own node.