Receiving
How the client finds payments to you, what it shows, and how to move them safely.
Find your payments
Under Your payments, pick how far back to look (7, 30 or 90 days, or everything) and press Find my payments. The client reads every ERC-5564 announcement on the network and tests each one on your device:
- the one-byte view tag rules out 255 of 256 strangers' payments cheaply;
- for the rest, it derives the address the payment would go to and compares.
Nobody learns which announcements are yours. Announcements come from Blockscout's public API by default, or from your own RPC endpoint (eth_getLogs) if you choose it in Settings.
What you see
For each payment: the one-time address, when it arrived, the amount the sender announced, and the current balance. Token payments show the token and its balance.
Move a payment
Press Withdraw, enter a destination, and the client sends the whole ETH balance minus a network-standard fee, signed in the tab with that payment's own key. Before it does, it runs the checks from our leak study:
| Check | What the client does |
|---|---|
| H1 the wallet your keys come from | Blocks it |
| H2 the address that paid you | Warns |
| H3 another of your stealth addresses, or a destination another payment already went to | Warns |
| H4 custom fee | Never offered: fees follow the network |
| H5 token payment with no ETH for gas | Blocks: never fund it from a wallet linked to you |
| Received less than an hour ago | Warns: waiting makes timing harder to pair |
Warnings need a tick before the button unlocks. The fee is reserved at its maximum, so a tiny remainder can stay on the payment address. Token payments are withdrawn the same way: the token first, paying gas from the payment's own ETH, then the leftover ETH, both to the destination you enter.
More on why each check exists: Withdraw without leaking.