Imagine you run a nightclub with two stamps — one visible under the regular black light at the door, one that only glows under a special UV frequency kept in the back office. Guests can check the visible stamp themselves, but if someone tries to fake or scrub it, the discrepancy between the two stamps tells your bouncer exactly what happened. That is the core mechanism: split one watermarking key into a public half anyone can verify and a private half that catches forgery and targeted removal. The committed claim is straightforward: you can release a watermark detector publicly without meaningfully helping attackers remove the watermark, because uninformed paraphrase attacks already strip watermarks at comparable rates with lower quality cost. Giving an attacker the public detector only helps at very small edit budgets — a few token swaps — where the attacker could barely degrade the text anyway. At realistic edit levels, blind rephrasing already does the job. The public detector is not the liability providers fear it is. The method builds on existing green-list watermarking (specifically the Kirchenbauer et al. family), splitting the pseudorandom key that biases token generation into two independent sub-keys. One sub-key drives a publicly detectable signal; the other drives a private signal only the provider can read. An informed attacker with access to the public detector can surgically strip the public signal while preserving text quality — but this surgery creates a statistical imbalance between the public and private scores that itself becomes a forensic fingerprint. The paper introduces a formal two-stage statistical test: first check the full-key watermark, then check for imbalance between the public and private sub-signals. The experimental evaluation covers both removal attacks (paraphrase, token substitution, word-level editing) and forgery attacks (planting a fake watermark on unwatermarked text). The key finding on removal: at small edit budgets (roughly 5-15% of tokens changed), access to the public detector does improve removal slightly over blind paraphrase. But at budgets above ~20%, the advantage vanishes because brute-force paraphrase already removes the signal. Forgery is the real new surface — a public detector lets attackers forge watermarks on arbitrary text — but the private pipeline catches this because the private sub-key signal will be absent. Integrity-wise, the evaluation uses standard LLM watermarking benchmarks (C4 dataset, OPT and Llama model families) and compares against the uninformed-attacker baseline directly, which is the honest comparison. The threat model is carefully tiered — token-level scores, aggregated scores, and binary verdict — which is more granular than most watermarking papers bother with. The main limitation the authors acknowledge: the split-key approach halves the effective watermark strength per channel, requiring longer text spans for reliable detection. The practical implication is pointed: if you are an LLM provider holding your watermark detector private for fear of attack, this paper argues you are paying a transparency cost for security you do not actually gain. The uninformed attacker is already nearly as effective. Releasing half the key enables third-party auditing, interoperability between providers, and public accountability — all without surrendering your forensic backstop. The obvious next experiment is scaling to production-grade models (GPT-4-class, 70B+ parameters) and real-world paraphrase engines rather than controlled substitutions. The authors almost certainly did not run this because of compute cost and API access restrictions, not because they expect it to fail — the mechanism is architecture-agnostic.