VAULT / KEYS THAT NEVER TOUCH A CURVE
Open a vault.
Keys are derived in your browser and never leave it. The vault address exists before it is deployed, so you can fund it first and deploy from any burner later. Spending reveals one hash preimage, and anyone can relay it.
Derive a key set
One random seed, 2height one-time keys, one Merkle root. Height 10 is 1,024 spends and takes a few seconds; height 8 is 256 and is near-instant.
The key file is the seed plus a spend counter. It is downloaded automatically. Store it offline, never edit the counter down, and never load the same file on two machines.
Your vault address
Derived from the roots, threshold, height and salt. Fund it now; deploy whenever.
- root
- config
- address
- —
Load your key file
The tree is rebuilt locally so the Merkle proof can be produced. The seed never leaves this page.
- root
- next leaf
Vault
balance
signers
nonce
your slot
What to do
Uses the To and Amount fields above (amount in token units).
Signing reserves a leaf and immediately downloads the updated key file. Keep that newer file; the old one would reuse the leaf.
Signed bundle
Anyone can submit this. It authorises exactly these calls at exactly this nonce and nothing else.
