Elliptic Curve Visualizer illustration

Elliptic Curve Visualizer

Makes elliptic-curve cryptography visible. Over the real numbers, plot y² = x³ + ax + b, click two points and watch the chord-and-tangent rule: the line through P and Q meets the curve in a third point, whose reflection is P + Q; animate the multiples P, 2P, 3P… hopping along the curve. Then switch to a finite field F_p and see what the math actually computes with: a cloud of lattice points where the same addition law still works, multiples of a point jump around unpredictably, and a toy Diffie-Hellman panel shows Alice’s aP and Bob’s bP landing on the same shared secret abP computed two different ways.

Runs 100% in your browser — simulations are computed locally on your device.

Notes

  • The smooth real-number picture is intuition only — real cryptography works over a finite field, where the "curve" is a scatter of points and there is no notion of "close". The addition formulas are identical.
  • Security rests on the discrete logarithm problem: computing nP from n and P is fast (double-and-add), but recovering n from P and nP has no known shortcut — on a 256-bit curve the best attacks need about 2¹²⁸ steps.
  • The points of the curve form a group; the order of a point (how many multiples until it cycles back to infinity) always divides the group size — Lagrange’s theorem, visible here on small curves.
  • The toy ECDH uses a curve small enough to break by brute force in microseconds. Real curves like P-256 or Curve25519 use primes hundreds of bits long — same construction, astronomically bigger group.
  • Runs 100% in your browser — keys and data never leave your device.