the internet: “paste your private key here to see if it’s taken”
Is anybody using this private key?
— answered without revealing it.
Your key is hashed and blinded in this browser tab. The server only ever receives a random-looking point and proves (a DLEQ proof, RFC 9497) that it answered honestly. It never learns your key — or even its hash.
stays in this tab ✓
SHA-256 fingerprint, computed locally — never transmitted.
sent to the server →
A blinded curve point. Unlinkable to your key without the secret blind.