Hash your password locally
$ echo -n fredflinstone | shasum
95e47d937e105fa1cc84bfa476b10f091304c090 -
Then take the first five characters of the hash and invoke the API $ curl https://api.pwnedpasswords.com/range/95e47
...
D8F3BA8D3952AA8917C78295EE1122F675C:17
D910D224A8450006478ED28D2CE2D005343:10
D91C102088F1D91469B803235DB60903259:874
D937E105FA1CC84BFA476B10F091304C090:290
D96BF2796784C142392D8B46AEF68B991D0:4
D98009835A90E46EFFD43AC3E5C6BD1C14B:5
And there we have it -- my password is compromised (the suffix D937...)Easy enough to script this up with minimal information leakage. All you're sending is 20 bits; that's not enough to do anything malicious even if your password is compromised.