Browser-based ECDSA demo on secp256k1 and P-256 — sign/verify, live nonce reuse attack with full private key recovery (the PS3 hack, real math), RFC 6979 deterministic nonces verified against test vectors. The signature algorithm behind TLS, Bitcoin, Ethereum, SSH, and WebAuthn. No backends. No simulated math.
MITTypeScriptbitcoincryptographydigital-signaturesecdsaethereumnonce-reusep256rfc-6979
systemslibrarian.github.io/crypto-lab-ecdsa-forge