OffcurveScan a wallet

Research notesv1

Key exposure on Solana, measured honestly.

What Offcurve checks, how the numbers are produced, and where the limits are. Short on purpose.

01The problem

Most blockchains secure accounts with elliptic-curve signatures. A private key produces a public key, and the security of the account rests on one assumption: that nobody can work backwards from the public key to the private one.

Today that assumption holds. The long-term question is what happens to public keys that are already known if it ever stops holding, whether through a large enough quantum computer running Shor's algorithm or an unexpected mathematical advance. A key that was never published is a harder target than one that was.

02Why Solana is different

On Ethereum and Bitcoin an address is a hash of a public key. Until the account signs something, only the hash is visible, so an address that has never signed keeps its key hidden. Much wallet-hygiene advice is built on that property.

Solana uses Ed25519, and a Solana address is the public key itself: the 32 bytes of the key, base58-encoded. There is no hash in between. Every keypair wallet on Solana has had its public key exposed since the moment its address was first shared. There is no sealed state to preserve, and a wallet that has never signed is no better hidden than one that signs every minute.

That changes the useful question. It is no longer “has this key surfaced?” but “how much depends on this one key, and does it have to?”

03Off-curve addresses

Roughly half of all 32-byte strings are valid Ed25519 points. The rest are not on the curve, and no private key can exist for them. Solana programs use this deliberately: a program derived address is sha256(seeds ‖ bump ‖ program id ‖ "ProgramDerivedAddress"), with the bump lowered from 255 until the result is not a curve point. Only the deriving program can sign for it.

Funds at an off-curve address cannot be moved by learning a key, because none exists. They move when the program's rules are satisfied. A multisig vault is the common case: the vault is off the curve, and the program releases funds when enough member keys approve.

This relocates trust; it does not remove it. A multisig vault is as strong as its member keys, its threshold and the program's code, and its members are ordinary on-curve wallets. What it removes is a single key as the only thing standing between an attacker and everything.

04What a scan measures

  • Curve. The address is decoded to 32 bytes and decompressed as an Ed25519 point, the same test the runtime applies. The implementation is checked against @solana/web3.js in the test suite.
  • Account type. getAccountInfo gives the owning program. System-owned and on curve is a keypair wallet. System-owned and off curve is a program-controlled vault. Token accounts, mints, stake accounts and programs are identified and not scored.
  • Activity. getSignaturesForAddress lists every transaction that mentions the address, up to the 4,000 most recent. That includes incoming transfers and dust, so up to sixteen transactions spread evenly across that history are fetched in full to see how often the address was actually a signer, and the signature count is scaled by that share.
  • Age. The block time of the oldest transaction found. If the history is longer than what was read, the age is reported as a lower bound.
  • Value. SOL, stake accounts whose withdraw authority is the address, and SPL and Token-2022 balances that have a market price. NFTs and unpriced tokens are counted separately and excluded from value.
  • Delegations. Token accounts with a delegate and a non-zero delegated amount. A delegate can move that amount without any further signature from the owner, which makes this the one measure here that maps to losses happening today.

Everything is public chain data read through a server-side RPC. No wallet connection, no signatures, no keys. .sol names are resolved by reading the Name Service account directly.

05The Curve Score

A hygiene indicator for keypair wallets. It starts at 100 and subtracts. Because every keypair's public key is public by construction, the first deduction always applies and no keypair can score above 80.

DeductionUp to
On-curve keyThe address is the public key. Fixed.−20
Signing activity5 × log₁₀(signatures + 1)−15
Key age2 × years since first seen−10
Value behind the key2.5 × log₁₀(USD ÷ 1,000)−10
Live token delegations5 per delegation−15
  • 70–80 Cold. A quiet key: little signing, nothing delegated.
  • 55–69 Warm. Normal for a wallet in regular use.
  • 40–54 Hot. A busy key holding real value.
  • 0–39 Overexposed. Old, busy, valuable and delegated. Split it up.

The logarithms are deliberate: the difference between 10 and 100 signatures matters more than the difference between 10,000 and 10,090. Off-curve and program-owned accounts are not scored. Unknown is never treated as safe: if prices are unavailable, value is left out and the result says so.

06What we do not claim

  • Offcurve does not claim that Ed25519 is broken or close to it.
  • It does not predict when quantum or classical cryptanalysis will advance.
  • The Curve Score is not a guarantee of security or a probability of compromise.
  • Off the curve does not mean quantum-safe. A vault controlled by on-curve signers inherits their exposure.
  • Scanning an address does not protect it. Offcurve never holds keys or funds and never asks for a seed phrase; its vault tools only prepare transactions for you to sign in your own wallet.
  • A vault made here is a standard Squads multisig. Offcurve has no special access to it and cannot recover it if its member keys are lost.

07Known limitations

  • Sampling. Signature counts for busy wallets are estimates from at most sixteen sampled transactions, and often eight on a public RPC. That is a coarse estimate, and the result always says how many of the sample were signed.
  • History depth. Only the 4,000 most recent transactions are read, so very active wallets get a lower-bound age.
  • Vault provenance. Given a Squads multisig address, the scan lists its members and threshold and reads its vault. Given only a vault address, it can say the address is program-controlled, but the chain does not record which multisig derived it.
  • Other authorities. Stake authority, token mint and freeze authorities, program upgrade authorities and close authorities also hang off keys. Only stake withdraw authority is counted today.
  • Value coverage. Tokens without a liquid market price, NFTs, LP positions and funds deposited in protocols are not counted.
  • Names. A wrapped (tokenized) .sol name resolves to its escrow, not to the person holding it.

08Future work

  • Vault discovery. Find every multisig a wallet is a member of from chain data, instead of relying on the address being saved.
  • Vault configuration. Changing members and thresholds from here. Today that is done in the Squads app.
  • Hash-based vaults. A program that releases funds on a hash-based one-time signature rather than an Ed25519 one would not rest on elliptic-curve assumptions at all. Proofs of concept exist on Solana. They are experimental.
  • Authority audits. Extend the scan to every authority a key holds, not only balances.

Experimental cryptography stays labelled as research until it is specified, implemented and professionally reviewed. It will not be presented as production security before then.

Scan a wallet