A signature proves you hold a private key without ever showing it. Every signature needs a fresh secret nonce k. Reuse k just once across two messages and your private key drops out by schoolbook algebra. It is the bug that unlocked the PlayStation 3 and has drained real wallets.
The signatures below are made with this key. The attack never sees it, yet it recovers it exactly.
Each signature is s = k⁻¹(z + r·d). The nonce k is the only secret hiding d. Two signatures with the betray that they share k: two equations, two unknowns, solved.
A signature is bound to one exact message. Change a single character and verification fails immediately. You can't lift a signature onto different terms.
Because r comes only from k·G, two signatures sharing a nonce share their r. That repeat is the visible fingerprint of the fatal mistake.
The recovered d matches the private key in the side panel to the last digit, computed only from public signature data.