BUNKER MODECRYPTOGRAPHIC DEFENSE NETWORK
$BUNKER
RESEARCH NOTES · V1

Key exposure, measured honestly.

What Bunker Mode checks, how the numbers are produced, and where the limits are. Short on purpose.

01 The problem

Ethereum accounts are secured by ECDSA over the secp256k1 curve. A private key produces a public key; the public key is hashed with keccak256 and the last 20 bytes become the address.

Every transaction an account sends carries a signature (r, s and a recovery bit). From a signature and the signed message anyone can recover the public key. That is how nodes verify senders without the key being sent separately.

So after the first outgoing transaction, the full public key of that account is effectively public. Today this is fine: deriving a private key from a public key is not practical with any known attack. The long-term question is what happens to keys that are already public if that ever changes, for example through a large enough quantum computer running Shor’s algorithm, or an unexpected mathematical advance.

02 Why fresh addresses matter

An address that has never signed shows only a hash of its public key. Recovering a key from that requires breaking the hash as well, which is a much harder target. Receiving funds does not change this: incoming transfers are signed by the sender, not the recipient.

UNUSED KEYAddress visible · public key hidden
USED KEYSignature published · public key recoverable

That gives a simple hygiene rule: keep long-term holdings on addresses that rarely or never sign, and do your daily activity from separate wallets. Your everyday wallet signs often. Your bunker shouldn’t.

03 What Bunker Mode measures

  • Account type. eth_getCode separates externally owned accounts (one ECDSA key) from contracts. EOAs with an EIP-7702 delegation are still treated as ECDSA keys. For Safe multisigs the signers are listed so each can be scanned.
  • Signature exposure. An EOA’s nonce counts the transactions (and EIP-7702 authorisations) it has signed. Nonce 0 means no outgoing signature on-chain: SEALED. Nonce above 0 means the public key can be recovered: EXPOSED.
  • First and latest exposure. With an archive node, Bunker Mode searches historical nonces block by block to find the exact blocks where nonce 0 and the latest nonce were used, then reads those transactions.
  • Public-key recovery. From a located transaction Bunker Mode rebuilds the signing payload (legacy, EIP-155, EIP-2930, EIP-1559, EIP-4844 and EIP-7702 types), recovers the secp256k1 public key from (r, s, yParity), derives the address from it and only marks the key as recovered when that address matches. If it can’t, it says “Outgoing signature confirmed” and shows no key.
  • Tracked value. ETH and major tokens (USDC, USDT, DAI, WETH, stETH, wstETH, WBTC, cbBTC) priced with on-chain Chainlink feeds. Other tokens and NFTs are not counted.

All data is public chain data read through a server-side RPC provider. No wallet connection, no signatures, no keys. API keys never reach the browser.

04 The Bunker Score

A wallet-hygiene indicator from 0 to 100, based on key exposure, address activity and value held on an exposed key. It is not a probability of compromise and it is reported separately from the SEALED / EXPOSED status.

Start100
Public key revealed (any outgoing signature)−20
Signature volume: 5 × log₁₀(signatures + 1)up to −15
Exposure age: 2 × years since first signatureup to −10
Value on an exposed key: 2.5 × log₁₀(USD ÷ 1,000)up to −10
Sealed key: off-chain signatures can’t be ruled out−4
90–100SEALED75–89HARDENED50–74EXPOSED0–49HIGH EXPOSURE

Contract accounts are not scored (their exposure is their signers’). If exposure can’t be determined the result is UNVERIFIED and unscored. Unknown is never treated as safe.

05 What Bunker Mode does not claim

  • Bunker Mode does not claim that ECDSA is currently broken.
  • Bunker Mode does not predict when quantum or classical cryptanalytic breakthroughs will occur.
  • The Bunker Score is not a guarantee of security.
  • Experimental post-quantum systems should not secure significant funds without professional review.

Scanning an address does not protect it. Bunker Mode never moves funds and never asks for seed phrases or private keys.

06 Known limitations

  • Off-chain signatures. Sign-in messages, typed-data permits and other off-chain signatures can reveal a public key without touching the chain. No scanner can rule them out, so sealed results carry a small deduction and a note.
  • Other chains. The same key is often used on L2s and other EVM chains. A signature there exposes the key just the same. V1 reads Ethereum mainnet only.
  • Relayed signatures. A permit signed off-chain and submitted by someone else is on-chain but does not move the signer’s nonce.
  • Value coverage. Only the listed assets are priced; long-tail tokens and NFTs are ignored.

07 Future work

RESEARCHHash-based authorizationSmart accounts that require an additional hash-based approval (one-time keys under a Merkle root) next to the ECDSA signature.
RESEARCHKey rotationAssisted rotation: Bunker Mode prepares the transfers to a fresh key, you review and sign.
RESEARCHSmart accountsAccount-abstraction wallets where the authorization scheme can be upgraded without moving assets.
RESEARCHNative account abstractionFollowing Ethereum’s native AA work (EIP-8141-compatible designs) for validation beyond ECDSA.
RESEARCHBitcoin exposure analysisAddress-type aware exposure checks (P2PKH, P2WPKH, P2TR, reused addresses).

Experimental cryptography stays labelled as research until it is specified, implemented and professionally reviewed. It will not be presented as production security before then.