Key derivation
How the client turns one wallet signature into your spending and viewing keys, why it works that way, and what a leaked signature would allow.
You never back up a stealth key. Both private keys come from one signature of your normal wallet, so the same wallet always recreates them, on any device and any copy of the client.
One signature, two keys
Sign one fixed message. The client asks your wallet for a standard personal_sign (EIP-191) signature over a fixed text that names ephemeral and a version number. The text does not include a chain id, so the same keys work on every chain where the Announcer and registry live.
Split the signature. An Ethereum signature is 65 bytes: r (32 bytes), s (32 bytes) and v (1 byte).
Hash each half into a key.
p_spend = keccak256(r) mod n
p_view = keccak256(s) mod n
This is the same construction the ScopeLift stealth-address SDK uses, so the keys are interoperable with tools built on it.
Publish the public halves. P_spend and P_view form your meta-address. The private keys stay in the browser's memory for the session and are never sent anywhere.
The exact message
Version 1 of the text, signed with personal_sign. It never changes, because changing one character changes every key.
ephemeral stealth keys v1
Sign this message to create your private receiving keys.
It does not move funds or approve anything.
Anyone who has this signature can find and spend payments to you.
Only sign it on ephemeral.money or a copy of the client you run yourself.If a page asks you to sign this text anywhere else, it is trying to take your payments.
Determinism check
The scheme only works if your wallet produces the same signature every time for the same message. Wallets that use deterministic ECDSA (RFC 6979) do; some smart-contract and MPC wallets do not. At setup the client asks for the signature twice and compares. If the two differ, it stops before creating keys, because keys you cannot recreate are keys you will lose.
What a leaked signature allows
Treat the signature like a private key
Anyone who obtains this one signature can compute both of your keys: they can find every payment to you and spend all of them. Only sign the ephemeral message on the official site or a copy of the client you run yourself. The message text says so, so that a phishing page that asks for it is easier to spot.
Why not a random key?
A random key would have to be backed up, and lost backups lose funds. Deriving from the wallet means one secret to protect instead of two. The trade-off is that whoever controls your wallet also controls your stealth keys. For most people that is the right trade; if it is not for you, use a dedicated wallet just for receiving.
Rotation
To rotate keys, sign a new version of the message and publish the new meta-address. Payments already made to the old keys stay findable with the old keys, so the client keeps both until you have moved those funds.