ephemeral

Trust model

Every party that touches a payment, what it learns, and what it cannot do. Including us.

Status: the client beta opens to partners and early testers first. The name gateway is planned; its rows describe the design.

A privacy tool is only as honest as its list of who can see what. This page names every party involved in receiving and spending with ephemeral.

Summary

PartySeesCannot see or do
Anyone on-chainSender, amount, time, the one-time address, the announcement, every later move from itThat the address is yours, unless you link it
The senderThe one address they paidYour other payments or your balance
Your RPC providerYour IP and the addresses your client queriesYour keys
The name gateway nextWhich addresses it issued for your name, and the IP of the lookupYour keys or existing funds. If compromised, it could misdirect new payments to a name
A viewing-key holderEvery payment to you and its amountSpend anything
The ephemeral teamNothing from your client. As operator of the name gateway: the addresses issued for your nameYour keys; we cannot move funds
YouEverything, with your keysNothing is hidden from you

The chain

Everything on Ethereum is public forever. A stealth payment shows the sender, the amount, the time and a brand-new address. What it does not show is the link between that address and you. That link exists only in the shared secret, which takes your viewing key or the sender's one-time key to compute. See Stealth address math.

The sender

The sender knows the address they paid, because they computed it. They cannot compute any other stealth address of yours, and they cannot spend from the one they paid.

Your RPC provider

To scan, your client downloads announcements. That reveals that you use stealth payments, but not which announcements are yours: the check happens on your device. Reading balances and sending withdrawals does reveal the addresses involved, together with your IP. If that matters to you, use your own node or a private RPC.

The name gateway

A private name resolves through an ENS offchain resolver (EIP-3668). The gateway behind it computes a fresh stealth address from your public meta-address for each lookup and publishes the announcement, since a sender with an ordinary wallet will not. It therefore knows which addresses it issued for your name, and the IP of each lookup. We run this gateway. It never holds a private key and cannot move funds that already landed. If it were compromised, it could hand out an address it controls for new payments to a name; the defences are on Private names. A sender who wants zero trust can pay your raw meta-address instead.

The viewing key

Anyone with your viewing key can find every payment to you. That is by design: it is how you give an accountant read-only access. It can never move funds. If it leaks, publish a new meta-address and future payments use new keys.

The ephemeral team

We run no server that holds keys, no pool, and no contract in the payment path. We cannot see the payments your client finds, and we cannot freeze or move any payment. The one exception to what we see is the name gateway above. If we disappear, your payments stay yours: any ERC-5564 client with your keys can find and spend them.

What you trust

  • The cryptography of secp256k1 and keccak256.
  • Your device and your wallet.
  • That the client you run is the published one. Once its source is published, verify it or run it yourself.

On this page