connecting…
Each spark is a real address from the latest Solana block.
Solanakey exposure scanner
Your addressis yourpublic key.
On Solana nothing hides a wallet's key. Scan any address to see how much sits behind it, how long it has been in use, and who else is allowed to move its tokens.
No wallet connection. Never asks for a seed phrase or private key.
Start herewhat you actually do
Check your wallet. Fix what is open. Lock away your savings.
For anyone holding more on Solana than they would be comfortable losing to one stolen key. Three steps, about five minutes, and you stay in control of your own wallet the whole time.
- 1
Check
Paste your wallet address. In a couple of seconds you see how much money sits behind that one key, how long it has been in use, and whether any app is still allowed to move your tokens.
Free. No wallet connection.
Scan a wallet - 2
Fix
Apps you approved months ago can often still move your tokens. Connect your wallet and switch those permissions off in one click.
Costs a tiny network fee.
Revoke permissions - 3
Lock away
Create a vault that needs two of your own devices to approve anything, then move your savings into it. If you ever think your wallet is compromised, sweep everything there in one go.
About 0.003 SOL to set up. You hold all the keys.
Create a vault
01The difference
Elsewhere an address hides the key. Here it is the key.
An Ethereum address is a hash of a public key, and the key only surfaces once the account signs. A Solana address is the key itself: 32 bytes, written in base58. There is no unused, hidden state to preserve.
Ethereum
hash in between0x…
A one-way hash. Nothing of the key is readable from the address, and the key stays unpublished until the account signs.
Solana
nothing in between…
Hover any byte: it is in the address, in the same position. The key is public the moment the address is.
Is that dangerous today? No.
Deriving a private key from an Ed25519 public key is not practical with any known technique. But it means the usual advice, “keep savings on an address that has never signed”, buys nothing here. What matters on Solana is how much one key controls, how exposed that key is to day-to-day use, and whether the value needs to sit behind a single key at all.
02Off the curve
Half of all possible addresses have no key at all.
Only about half of all 32-byte strings are points on the curve. The rest cannot have a private key, and Solana programs use exactly those as addresses only code can sign for. Watch it happen.
0 random 32-byte strings tested in your browser
Bump search · the real derivation
sha256(seed ‖ bump ‖ program ‖ marker)A hash lands on the curve about half the time, so the program lowers the bump until one does not. This seed took 2 tries.
What that buys you, and what it does not
Associated token accounts, multisig vaults and protocol treasuries all live at off-curve addresses. Funds there cannot be taken by learning a key, because there is no key to learn. They move only when the owning program's rules are met: two of three signers, a time lock, a spending limit.
It is not a force field. A multisig vault is exactly as strong as its member keys, its threshold and its program. Each member is an ordinary on-curve wallet, and each one can be scanned here.
The point is to stop one key being the whole story.
03The scan
Five things, read from public chain data.
Paste an address. Offcurve reads the chain through a server-side RPC and reports what it finds. Nothing is connected, signed or moved.
- 01
Curve
Is the address a valid Ed25519 key, or is it off the curve and owned by a program?
- 02
Signatures
How often the key has actually signed, sampled from across its transaction history.
- 03
Age
How long the same key has been in use, from the first transaction we can find.
- 04
Value
SOL, staked SOL and priced tokens that this one key can move.
- 05
Delegations
Token accounts where someone else is approved to move your balance.
Example wallets · synthetic, scored by the real rules
Quiet saver
Funded once, signed three times, left alone.
Daily driver
Swaps, mints and claims, with two approvals left open.
Old whale
Everything behind one key since 2021, approvals included.
Multisig vault
Off the curve. No private key to find.
04The model
One key to spend. No key to save.
Keep a wallet for activity and keep long-term value somewhere a single key cannot reach. Sweep from the first to the second.
Signer
On curveYour everyday wallet. It signs swaps, mints and approvals, and it will pick up delegations along the way.
- Controlled by
- one private key
- Signs
- constantly
- Should hold
- working capital
Vault
Off curveA program-controlled address. It receives. It releases funds only when its rules are met.
- Controlled by
- a program's rules
- Signs
- never, it has no key
- Should hold
- long-term assets
Set it up now.
Revoke old delegations, create a multisig vault with keys you control, and sweep SOL and tokens into it. You sign every transaction in your own wallet. Rehearse on devnet first.
05Method
How the Curve Score works.
A transparent hygiene indicator for keypair wallets. It starts at 100 and subtracts. Because every Solana keypair has a public key by construction, none can score above 80.
| Deduction | Up to |
|---|---|
| On-curve keyThe address is the public key. Fixed. | −20 |
| Signing activity5 × log₁₀(signatures + 1) | −15 |
| Key age2 × years since first seen | −10 |
| Value behind the key2.5 × log₁₀(USD ÷ 1,000) | −10 |
| Live token delegations5 per delegation | −15 |
Cold
A quiet key: little signing, nothing delegated.
Warm
Normal for a wallet in regular use.
Hot
A busy key holding real value.
Overexposed
Old, busy, valuable and delegated. Split it up.
The hatched stretch from 80 to 100 is unreachable for any keypair. Off-curve addresses and program-owned accounts are not scored: their exposure is their program's and their signers'. Anything the scan cannot determine is reported as unknown and never counted as safe.
What Offcurve does not claim
- Ed25519 is not broken, and nothing here says it is.
- Nobody can predict when a quantum computer or a mathematical advance will change that. We do not try.
- The Curve Score is not a guarantee, a rating of you, or a probability of loss.
- Off the curve does not mean safe. It means the rules belong to a program instead of a key.
- Scanning an address does not protect it. Only you moving funds does.
06Roadmap
Beyond a single curve.
The scanner and the vault tools are live. Everything past them is research, and stays labelled as research until it has been specified, implemented and independently reviewed.
Live
Shipping- On-curve and off-curve classification
- Signature sampling and key age
- Value behind a key: SOL, stake, priced tokens
- Live token delegation detection
- Curve Score and a plain-language plan
- One-click delegation revokes
- Multisig vault creation, sweeps and member-approved withdrawals
Research
Not deployed- Finding every vault a wallet belongs to, from chain data
- Changing a vault's members and threshold from here
- Hash-based vaults using one-time signatures
- Tracking Solana's own post-quantum proposals
- Stake and token authority audits
A vault whose authorization is a hash-based signature would not depend on elliptic curves at all. Proofs of concept exist. None should hold significant funds without professional review.
Ecosystem
$OFFCURVE
The token behind Offcurve. The scanner is free, needs no wallet and works the same whether or not you hold it. Nothing on this site is financial advice.
When $OFFCURVE exists, its address will appear here and nowhere else first. Treat any address claiming to be it before then as unrelated.