Better privacy defaults for your users with stealth addresses | Devcon SEA
Devcon·Tue, Oct 7, 2025, 12:00 AM
Stealth addresses can be used to give users better privacy from payments to identity. In this workshop we will run through practical use cases of stealth addresses today and how they relate to different types of products. We will then have a short coding session where we will implement stealth addresses to generate private Safe signers from scratch. Speaker(s): Moritz Boullenger, Antonio Seveso Skill level: Intermediate Track: Cypherpunk & Privacy Keywords: Live Coding, Privacy, User Experience, stealth, address Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/
Transcript
good morning everyone uh thanks for coming and and thanks for your patience as well I'm morit and Antonio and I are the co-founders of fluid key um and today we'd like to talk to you about ways to give your users better privacy um with stealth addresses um this is mostly coming from the work we've done with fluid key over the past year also implementing this for our users um and uh we have first going to show you a little bit of the theory around stealth addresses and how it works bit of an explainer and then we're going to do a session where um we're actually going to live code an app that um will also generate steal addresses so you really understand also at a deeper level how this works and how you can implement this into your apps as well so that's the plan for today um so for the first 20 minutes I'll be talking a little bit about stealth addresses in general how they work why they're useful um and then I'll hand over to Antonio for the live coding part after that um along the way please feel free to also ask any questions I think it's going to be a a longer session so it's great to make it interactive and kind of also make it more of a discussion and and understand how you'd like to use steal addresses and so on and so forth if there's any specific questions around this great so with that let me start by also tell you a little bit a little bit more about wi self addresses are actually a pretty cool way to give your users privacy um the first part I want to talk to you also a little bit about how we got started um so we are pretty heavy ethereum and evm chain users and um maybe I can ask you also a question first who year has more than five different ethereum addresses that they own accounts okay two three pretty much everyone actually I think if uh yeah so so we have also tens of different accounts right and um one reason we have so many accounts is because if you have you know one address you tie all of your activity with anybody can see forever what you've done with this address um who paid you who you paid and how much money you have on this address and so on and so forth and so what most users do then is like they use their wallet and they just create different accounts for different use cases and so that's one reason to have many addresses and um that gets really difficult to manage and is also just not ideal because in the end you don't create a new address for every transaction you make you just created once in a while right and so you don't have much more privacy and you have a lot of you know headaches managing that and so that was kind of also our starting point in in exploring stealth addresses because with stealth addresses you can actually get much better privacy with a ux that's much easier to use um than uh having you know tons of different accounts across you know a normal wallet um so a few more questions to also getting to know you a little bit better just to show off hands um who yeah has heard of self addresses before okay so half of the room I would say um who here has used a product that uses self addresses before okay that's great then uh today you will at least get to see a product that uses telf addresses we'll build it together um and then the third question is um we is working on a product that would benefit from better privacy okay okay good amount of of people in the room as well great then um let me start by telling you a little bit about how stealth addresses actually work I'll start by showing you um how this works in practice with fluid key just to illustrate this very easily and then I'll also talk a little bit about the you know Tech behind the scenes um so with with fluid key specifically the way this works is every user has an ens so this is my ens over year moritz. F.E um and usually when you have an ens like that what happens is every time someone puts it in their wallet and resolves it the same address gets returned right and um in this case it's very different because every time you know you resolve this ens you basically get a new address and so you see here 0x 78 B8 if I refresh the page sorry all right if I refresh the page what you'll see is that um the 0x 78 will be gone and there's a new address here 0x7f E9 and so every time somebody puts this U you know ens in their wallet um or an ether scan or anywhere a new address is generated and that address is fully self- custodial only I can you know spend the funds that are received through that address and um but this address can be generated by Third parties and so I don't need to be on the other side of somebody having to send me money um to you know create that address in real time I can just have this in the service with fluid key for example and then this address is automatically generated by fluid key without fluid key being able to touch your funds in anyway and so that's the the power of self addresses because otherwise you could say I can just use my you know metamask or any other wallet and just generate these HD wallet addresses where you can create more and more addresses but here the cool thing with self addresses is anybody can generate these addresses on your behalf without being able to touch the funds that go into these addresses um and on the other side then you know inside of fluid key for example you see all of your balances in one place so here for example this is my total balance in in in this account um but then if I go on chain and look at for example this one uh usdc payment what you'll see on uh on Bas scan in this case is that sorry I might have to zoom in a bit um yes you see that this address only holds $1 right and so I could have $100,000 in this account you wouldn't know by just sending me money into this uh into this address and into this enss and so that's kind of at a very high level how steal addresses work and and the benefit of of using steal addresses um any questions so far maybe already at this kind of high level yes I addresses uh if I want to withdraw my phones from a set of stal or set of addresses yeah I should uh provide end transactions yeah so the way it works is that these telf addresses let me um let me switch back to that tab actually um these telf addresses are actually um counterfactual smart accounts so the moment you want to withdraw money it's actually a smart account that is a safe smart account that is deployed at this address and what that helps you to do is that you can do gas sponsorship for example so say you receive usdc in an address um otherwise you'd have to like fund that address then with eth and then you know that would dox you because you'd have to send that E from one of your other addresses and so on and so forth um and with smart accounts the other thing is that you can batch transactions so in fluid key basically every time you send money out um the the way it works is that we are Computing the generic most privacy preserving path for it right so say you received $10 $100 and $100,000 in the past and you want to send $90 out that would come from the $100 address because that would just tie one address to that outgoing payment and so so that's one thing and then on the other side um you can also label addresses and then basically decide oh I just want to you know pay out this payment from this specific label so you can also have full control still over which funds you disclose to wh whomever you're paying does that make sense awesome any other questions then let me continue um yes get back in here great so basically as I mentioned just before the the big unlock is that you can generate self- custodial accounts for your users um that aren't publicly linked to your users and you can generate as many as you want without them needing to do anything once they're set up so that's basically um the the power you get from from stealth addresses and uh how you can also provide your users with better privacy because then in your product one user doesn't need to be one address but can be you know many different addresses basically and can um can yeah basically in the end then have much more privacy from that so also just to illustrate that again I think right now the status quo is if you have a normal wallet pretty much all of your transactions coming in and out to the same address and um everybody being able to see your balance what you're doing and so on and so forth and now in in this new model um you have lots of different addresses they're not publicly linked to your ens so somebody looking at ether scan would know that this is an address that was generated by your ens before um and all of these addresses are also not tied together so each of these addresses is its own kind of like small uh account that just holds one asset and and isn't tied to any of the other addresses in any way now I want to talk also a little bit about you know the cryptography behind it so this is pseudo maath right like not not going into exactly how the elliptic curve cryptography works but just explaining at a very high level as well what's happening so you get a better intuition for it so um when I receive money from you know from someone that wants to pay me um what's happening is that there's uh three elements here um every user that wants to use telf addresses needs to generate what's called a US a meta public key that public key can be basically um you know put on chain anybody can know about it if you know about that public key you you can't know the stealth addresses just from that so that's basically the you know openly shared parts that that anybody can um can have access to and then the second part is that you multipli this by a secret um and so this is elliptic curve multiplications right these are not normal multiplications and um you know that secret is basically what allows you to generate a steal address and only if you know the secret can you know the steal address and can you know that that steal address is you know connected to the user who has this specific public key so so that secret is is pretty important here because that's what um allows you to have the Privacy as well um and you have you can have an infinite amount of Secrets and so you can have an infinite amount of Steal addresses on the other side right now the question then becomes okay so now I generated steal address for uh for Antonio for example and I sent him money how does Antonio know that uh a stealth address was generated and that he received money on that self address right and so there there's a few different ways to do it there's an ERC ERC 5564 um that allows you to basically announce these transactions on chain in an encrypted way where only Antonio with his viewing key is able to um decode these transactions and see that these funds are actually you know meant for him um another way in which self addresses were actually you know created and thought of is that you can also use a trusted third party to basically index These funds on your behalf and so what that means is that um you know you don't have to you know scan the blockchain for like hundreds of transactions to see if any of of those is related to you but you can have like a trusted third party that basically does that on your behalf and tells you hey you know year there were funds basically um that um that were received in one of of the addresses related to you um and then the final part and this is also how fluid key works is that um this secret can be can be pseudo randomly generated and in this case if it's pseudo randomly generated um you can basically just replay all of this tal addresses because you you know how the secret is s randomly you know generated and then you can replay all of the Steal addresses um that were generated one by one and check if there are funds on it so that's another you know way to to think about it and that's why on fluid key you know if fluid key disappears tomorrow you can always recover your funds because these addresses are PSE sudo randomly generated based on you know your private keys and as long as you have access to your private Keys you can recover all of these addresses without any any third party awesome then the second part is when you want to send money out of this telf address how do you because this is a this is an address this is a public key so it's just a public address you can't really access the funds from from this um but then when you send them money out um there's another set of uh of keys here you have the user meta private Keys which are basically the the private Keys related to the public key keys here and if you multiply those by the same secret you basically get access to the stealth address private keys and so what's really important is that the user meta private Keys should always stay only with the user and uh never you know be shared with anyone because that's what makes uh this whole system self- custodial and and uh basically allows the user to have full control of of of their funds uh only um and then yeah the secret is is the same secret as this secret so if you you multiply these two things together you get access to the the private key and from that you can spend the funds uh of this uh of this address that's at it at a very high level any any questions around around this all right then let me talk about one more um one more topic which is um the difference of privacy you get with stealth addresses versus other systems right so um with stealth addresses you get something that's called unlinkability um and what that means is that you can generate generate addresses that are not related to your public address and are not related to each other so they're not tied together on chain in any way um but you don't B you don't break traceability so you can still follow the funds basically right so um money that was sent to that to a steal address you can still see where that money came from initially and where it came from and so on and so forth um and so the advantages of self addresses is that they're they're really fast to produce you can you know do that uh elliptic curve cryptography I was showing to you before fully offchain takes milliseconds so you know there's you can generate them in real time when this ens I showed before is um you know returning a new address that address is generated in real time basically while uh the ens is queried um the other thing is that these are just normal ethereum addresses and what that means is that they're compatible with you know every counterparty and every contract on public evm chains that means you can send me money from your metamask account from any other account and my counterparty doesn't need to know that I'm using fluid key for this to work right I can use fluid key and just receive uh payments with better privacy without the other person having to do anything specific um on their end and I think that's really important because most other privacy systems basically require you to have both parties in kind of more of a shielded pool environment where you can then trade um with each other and here you don't need to to have that um the downside obviously again is that it doesn't break traceability I would say it's um it's a downside in one way in another way a lot of the the users that use fluid key for example um like this property because it's much easier to also disclose where your funds came from and so if you want to off-ramp them or you know kind of disclose what you yeah how you obtain the funds it's pretty easy to show because you can show that you have access to this address and you can show where the funds came from so there's not the risk of you mixing funds with a third you know party that uh did something illegal or anything like that because all of these addresses are fully self- custodial and only your addresses and you're never mixing those funds with anybody else and so that's um I guess the the plus side of of this property um on the other side untraceability so meaning that you can break um the the path your your tokens took so say say somebody sends you usdc and you want to you know make sure that uh nobody can know who sent this usdc that's what's called untraceability and that is enabled by systems like privacy pools like tornado cache for example as well um and I think there the downsides versus self addresses is that it's much slower right so you have to move your funds into this shielded protocol and it'll take um you know multiple hours for you to basically be able to take them out safely with uh you know privacy because otherwise if you just you know move them in and out at the next second you basically don't gain anything because you can tie those you know those movements together so usually you have to leave them in a system like like rail gun as well for at least 3 hours and uh and so that's like also a little bit of a slower slower thing um the second thing is that it's a you have a limited set of operations you can do within a private Y pool right so you can maybe send money to others but they also need to be part of of that uh you know system and then you can do in in systems like rail gun for example you can do swaps and a few other things but you can't interact with every you know contract on an evm chain just like um you would do with a normal address and so that's another um you know downside there the plus side is that it breaks traceability so um that's uh that's the the really big plus side on on that side and and so what we think you know is kind of the ultimate uh privacy stack in in the future is that you you kind of combine these two things together and have something where um you have stealth addresses where you can you know receive payments day-to-day very easily um without your counterparty having to do anything on on their end um and you know you can just interact with any contract through that but then if you want to break traceability on your end say you receive a million dollars and then you want to you know spend on the other side smaller amounts with that you receive your million dollars into a self address pass it through a privacy pool on the other side you can send that to many different self addresses of say $10,000 each and then um you can spend from those self addresses and just interact on chain with those addresses as well and so you get that um you know break in in in tracing um but also benefit from having addresses that are just compatible with any contract and and anything on chain and so so yeah that's kind of where we're seeing things going but uh there's a lot of work I think on both side both both on stealth addresses and privacy pools still to be done to make this super user friendly and and so we're really um also focused on on that um any questions on this part then the final uh point I want to make before I hand over to Antonio is talking also a little bit about the ux problems to solve still with stealth addresses um two specifically one is Key Management so um the way steal addresses work is that you have uh they're basically EAS right and then you can have an EA that controls a smart account so you have basically one out of one safe for example with an EA that is a stealth address um the problem with that is that if you have thousands of different addresses with those keys if you want to rotate those keys for example you'd have to do thousand onchain transactions to rotate those keys so that's not really practical and you also have the issue then that um you know if you rotate the same keys at the same time over a thousand addresses you can link all of those addresses together and so on and so forth um and there we're really excited about what's happening with key store rollups um the idea with key store rollups in a in a really um quick explanation is that you decouple the smart accounts from the keys themselves so the keys are stored in a key store rollup or a smart contract basically where you have a slot for every user so the user user a says um you know these are my keys and then every time you deploy a smart contract a smart account you basically point to that slot in the in the key store and by doing that um you can just rotate the keys in this one key store slot and they automatically rotate your keys on all smart accounts that that are pointing to that um to do that privately obviously you can't just point directly to that slot obviously otherwise it would tie everything together so you need to have ZK proof signatures and so on and so um you know there are like proof of Concepts around this but this is all still in pretty much in beta and so this is something that um I think we'll see a lot of uh improvements around as well in the the coming months um the second issue is around dap interactions so say you have all these steal addresses in fluid key for example and you connect to Unis swap right and then you want to um you know swap some of your funds how do you do it without having to move all of your funds to one address because when you you connect to uniswap for example you have to connect with one specific address and uniswap would look on chain the balance of this address right and so you need to have enough balance on that address to be able to make the swap right now and and that's a huge you know problem because then you have to move funds before even making the Swap and so on and so forth um with ERC 5792 um wallets can basically communicate to daps what uh properties the the user already has so the wallet can just say fluid key can just say in this case for example hey um you know this user has $100,000 we're not telling you where these $100,000 are but they're year they're 100,000 usdc somewhere and uh just assume that that's true and then prepare the transaction for us and then at the moment of the signature and the transaction being executed that's when we then in that transaction also move the funds to the address but the user doesn't have to move funds before executing any transactions or Interac with any deps and so that's I think also a big ux um Improvement we need to still uh work on and and that's being worked on um with ERC 5792 that's it from my side any questions before I hand over to Antonio for the more practical part yes this one uh yes this one um do did I correctly understand that this popky and priv priv ke yeah is the same that extended public K and extended uh private K in bip uh 32 HD wallets yeah so so the no the key is a bit different it dep so there's different ways to to kind of do it and I think Antonio will show you concretely how it looks for example with fluid key um usually with self addresses you have a viewing key and a spending key and so um you kind of have like two keys actually um and the the spending key is there to um allow the user have uh access to the funds and then uh the public key is there to to you know multiply by the secret but um but yes you're correct that in the end these are just like ethereum public and private keys so it's the yeah it's it's kind of similar in the in the sense that you know they're yeah they're the same kind of private keys and public Keys it's okay uh so the function that uh returns me st's private key yeah is uh multiplication uh extended private Key by secret yeah and if I want to get uh steals public key uh the function is the same uh is this priv uh private key stes private key much to stes public key yeah yes so the private key and the public key are connected together exactly they're like one set of keys in a way right it's like the same way when you know you have your normal ethereum account you have like a public key and public address and then you have your private keys that can control that yes but in uh bip uh 32 yeah uh this function uh functions is not the same not uh multiplication in uh first yeah uh not the same that multiplication second it's more complex yeah I think we for sure it is more complex so again this is like a simplification just to explain at a very high level you know get an intuition for it Antonio will I think show you the code exactly how it works um and maybe then you can uh ask questions if it's uh yeah unclear awesome any other questions good then yeah let me hand over to Antonio for the the second part of the session over to you thank you morit for the uh intro and hi everyone I'm Antonio I work as a CTO at flute key and uh today I want to try to show you in practice how statuses work to do that uh uh let me uh um show you the structure of this project you get a screenshot of how it looks like at the beginning of the slides in the end uh will be react app a very simple app we run on Local Host uh there will be also a deployed version of it uh at the end I will show you uh what this app does that app will manage and create St addresses locally and then through wallet connect we will try to connect to the safe uh app web UI and we will deploy a safe controlled by one or you can even play around so even more of the St address you generated and this basically allows you to have different saves controlled by different addresses so apparently they seems completely disconnected users but under the hood all will be controlled by the same user and the same master key now we will get familiar even more with the names of of the different parts that compose St taces what this allow you to do then of course is then through wallet connect maybe connect this safe to any dap as Mor mentioned before these are regular St addresses so connect to any up and do literally whatever you want controlled by your uh your stal safe so this is uh the the goal of today the couple of notes on the implementation details and this is where I want to like step in St addresses are uh in some parts are also Concepts and this is what matters most for me to give you today is that there are some parts like the elliptic multiplication that these are mathematical constraints so we cannot change how those thing works otherwise SES won't work anymore but to get there there are some steps that are conventions but not like conven itions that you know someone imposed with an ERC or whatever there are irc's okay but there are you know parts that can be interpreted or done based on what are the needs of what we want to do and these are the implementation the tests for the demo of today first of all we use the way that like fluid keywords assault addresses are Pudo randomly generated this means that uh uh if you have the viewing private key and then we'll enter more in this details you will be able to regenerate those addresses okay it's a private key it will stay with you but that's how you will be able to regenerate in a way that if a third party disappears you will be able to regenerate those addresses always the same way we will use the viewing key so now let's start getting familiar with these names when a user want to generate set addresses on convention it's two keys one is called the viewing key the other one is called the spending key together they are the meta key so we get familiar with names why they are separate why there are two we will see it later but it brings a lot of practical advantages when you want to self-control funds but let someone else generate still addresses on your behalf as I mentioned these addresses can be easily recreated in the future uh we don't need to emit a nonchain event because everything will be run locally and this is meant for trusted third party or personal project think about you know you want someone to set up with this example you want someone to set up saves on your behalf safes that only you can control but you don't want to be there every time to tell them oh this is my address this is my address and you don't even want to send him a list of pregenerated address that you can control it's enough to share the viewing key with that trusted third party that trusted third party will generate the saes for you and then whenever you want you will be able to move money out no one will be able to do that unless you uh this private sorry viewing key should be kept confidential I mean you can share with trusty party if you share with anyone anyone will be able to compute your addresses that's it their part to simplify this um uh Workshop we have used the stt account kit it's a SDK uh JavaScript SDK that we coded it has been audited back this June and uh we will go also in the code of this kit but this will allow you to create an app generating and controlling St Tes within really a few lines of code and that's what we will do in this Workshop we will have three goals for this Workshop that are the three main phases that also Mor show before in the um slide where he was showing how stes work first goal will be generate the metaal keys of the user so the spending and the viewing goal number one goal number two generate one or more St address goal number three will be generate the private key to control those St addresses I on purpose to separate phase two and three to show you that it's possible possible to generate a address without knowing its private key then generate the private key to control that address knowing the spending private key I know it's quite a lot of uh of things so we will tackle one by one and we will go into that so now let's go to code and uh I will leave this for you so the way it works I have created this uh GitHub repository it's under flute key SL dc7 St address uh I will leave your time if if you want to uh to clone it this repository has uh uh a main branch and three branches called stage one stage two and stage three I I've done Ive set up it in this way because we will start coding from stage one so if you want to code along with me just clone stage one but if for any reason you messed up you you you lost a p you have an error or whatever once they move to stage two that's when we will create the the address it's enough for you to pull the stage to branch and you will be up to that point and in the end at the end of the session we will be at the main one so the main one is the final version we're going to code to that today you don't need to understand how react works you just need uh and there are instructions on this uh R so let me go here this is the repository you will just need to clone and uh run yarn install and then yarn start to have the app going and we will add code just in one file so just let make me sure that I am on stage one perfect so I'm stage one and this is okay now we need to zoom in and how was that that works like this no I even zoom out okay much better I would say can you read it or you want bigger okay if you if you don't see something just raise your hands and you want bigger sure okay I think that could be better um in general if you need to ask questions or if you miss no a part just stop me and I I I don't want to lose anyone uh on the path towards the the goal of this session as I was saying a second ago I will uh I already run yarn install or npm install whatever it's the best for your laptop and now now I will uh launch the application with a with a start command yes sure don't worry so the repository is gab.com SL uh no sorry that's the wrong one gab.com fluid key slash dc7 St address let me go back to the slide so you can see bigger don't worry perfect let me meanwhile go back here so I have uh uh just hit start let me also open the console that just will help us going through what we are what we are doing so again I just clone uh the repository yarn install yarn start and you will have a fully functional rea application that technically if you get there in a website you will say oh okay just generate a master key if you click that it says oh generate metast stel keys not implemented yet and that's the first task we need to go through now this is a demo application okay so I have a remove some parts that in a regular application you will have there the most practical and hopeful one will be to have a connect wallet button like uh if you want to connect your metam mask in into this to simplify that part and now avoid a lot of problems so my metam Mask doesn't connect and so on we will generate a private key right here and from that private key that's like if it's your wallet private key we will generate The Meta keys and I show you how to do that again this is is a demo application if you want after the session to propose a PR and have a proper connect button feel free to do the code is open source and you can do whatever you want okay so let's start coding this first part and let's go into our project and the project there is a uh I'm sorry this part I can zoom but there's a source folder SRC folder inside there is an helper folder that has a file that's called St address.
TS again I don't know why it's losing the zoom perfect this is the only file we will we are going to uh edit and this file has three function one for each step the first function is called generate metast keys and at the moment you see there's an alert that's the alert we just saw in the code okay if if you scroll down there is a second function that generates salt address that's the second function second stage of the uh workshop and then the third one that's the eval St address private key and that's a thir third stage once we get down to this point we will be able to have a to deploy a safe and control the safe with the address we are generating I have set a lot of to-dos that will guide us through what we have to do and if you don't mind I would like to start with the first step so let's see how to generate The Meta stall Keys as I mentioned uh for this demo I have uh you know simulated I don't want to connect an external wallet just to simplify but on average what you will mostly commonly do to generate the St addresses is ask the user to connect a buet and generate a s uh and sign a message the signature is a deterministic signature this way is a nice way to ask a user a unique string the signature that only his private key can generate and uh you know that it's tied to the user Master private key without asking the private key to the user the wallet private key okay because if you go on a website and the first thing you ask a user is can you please pass here your private key of your wallet that's like will be targeted as a scam website your application so you cannot do that here what we have done to simplify we just uh generate the private key here you will see that key appearing here and uh uh we will uh think about a message in this case I put hello defon 7 this is the message that must be always the same to always obtain the same signature from the user if we change this message the signature changing and those the metast keys under the hood will change so let's keep it static we will then input to this function a private key a wallet private key and we will return the spending and the viewing private key the first part out of these three internal steps two of three will be very simple VM function so let me go to the first one I will just create an account by calling the function private key to account and passing the master private key receive as input of this function let me go a little bit okay so the this function is a master private key and this a generate an account this is exactly as having a metamask account connected Okay so nothing more than that into that this is again a VM function and the second one I want obtain a signature and I have to use the await uh it's an await yes account dot okay sign Messa but this is wrong and we have to pass the message to authenticate and that's s like this and again if this account represent a metamask wallet connected through wagi for example this is exactly how you have to do just require message and there is a wait because the user will have to click and approve the signature and now we have obtained a signature that's everything that's the last part not related to St addresses from now on will be only St address related functions and uh we will use the first function from the St account kit so we need to let's read the comment use St account kit to derive meta stall keys from the signature think it's time to go back into our St account kit Let Me Maybe still Zoom a little bit more that's it I don't know how to close this honestly let me see if I can no more than but it's fine if you go into our St account kit or you clone it in the source folder there there will be a series on function to simplify we put one function per file that's easier also to read each one will be used at a certain stage of our of our Workshop what we will need now is generate keys from signature just quickly show you what it does basically this function takes a signature and Returns the spending and the viewing private key how does it how it does very simple take the signature split by two each part of the signature is used as a initiator to generate a key and then Returns the two keys you don't have to write all this code you just need to go here and says uh generate uh Keys from signature and you pass the signature and then of course we need to store that an function and then we need to return keys. spending private key and keys. viewing private key okay this we you start seeing the utility of the Steal account kit you don't have to know all that part this specifically part is a convention it's not a a must to do for St addresses in your H you want to generate the viewing and spending proper key independently with your algor algorithm that's fine okay it's not something that you have to do this is a the easiest way so that a user can connect this wallet generate a signature and make sure that even if your front end disappear is always able to generate a signature and then following a simple program being able to uh generate the keys let me also put here a console.log of key of keys and let's see if it works now let me um just clear cache go back to console clear it refresh the page so before we were here and when we were clicking the button we were getting an error now let's click the same button and we got keys okay and as you can see this is a uh if you go in the react code it will generate a random private key of course if I copy it I clear the cache and I passed this key inside here again the metaal keys generated that we can see here will always be the same so this 0x d8 BC as a spending and 0x 8944 a be as a viewing private key that will always be the same if this changes all the St tablet are going to change okay so that's the first part stage one completed if you didn't follow along you can uh pull stage two of the gab RPO and you will be exactly at this point like I am now we are ready to go into the most interesting I would say part of the uh of the process that's generating the St address that's also the one that requires a little bit more of steps and in our react application would be just okay generate your first account if I click uh this application allows me know to add also a nickname whatever you want and if I hit had now I got a message generating St addresses not implemented yet and this is what we will do in the stage two of this uh Workshop a console and go here so let's start by removing this alert and as you can see this generate St address has two input parameters that are set by the react application and needs to return two things so sorry three input parameters the first one is the viewing private key the second one is the spending public key and the third one is a numeric nuns first thing you notice there is only the spending public key because it's a public key I can share with anyone and this is what guarantees me that my funds are self- custodial to generate a Ste address you just need the spending public key not the spending private key and this is the the first important part the second part is the nons the NS is a number can be any number up to two power 256 okay so like large amount of number for Simplicity in this demo application we will rotate from zero on so we'll pass the nons zero 1 two the changes of this nons will change the the generated St address so once we have stat like once you have the meta St Keys then it just enough to increase the nons and every time I will generate a St address that's completely uncorrelated to each other and even if you know that two address are controlled by the same private key let's say I generate three address of you out of these three or any address I am not able to recreate the controlling public or private key what this function returns this function Returns the St address and the Emeral private key and now we asking what's an eal private key in the high level slide uh we had before in a mod session at a certain point there was the no the public or private key multiplied by a secret that secret is obtained from a mathematical operation we will see from a ephemeral private key this private key can be generated by who generates the address generate the address to that and then can can throw away the private key and just keep the public key this I don't go into too much details at the moment just consider that you need also this private key but it's a random generated private key at the moment or P Rand generated if you want to recreate them consistently and this is what we will see now also here three steps all three related to St addresses and this we go back into what I I consider convention not a mandatory mathematical operation you have to do for St addresses when we uh decided to know how to set up fluid key we thought that sharing a viewing key even if it's a private one let's say another way sharing a private key whatever it is it's all always a bad attitude you you don't you never have to share private key but as as a trusted third party I need a viewing private key to generate Sal addresses on your behalf so how how do do how did we end up solving this uh problem we ask user to share with us a bip32 node of the viewing private key see uh in a simple way you have a viewing private key the one I we console.log in the browser before and from that viewing private key you are generating a sub private key that you share with us following a a standard that's the bip32 why you say why that why this extra complication because the day you don't trust me anymore if you have shared with me your viewing uh key derived from the master key you have to sh you have to change the master key and those changing also the spending key and all the others you have you need to go through each of those and change a controlling key if you have shared with me a sub a private key derived for your viewing private key the day you don't trust me anymore you just need to start generating still addresses with another sub viewing private key and the spending key stays the same so I as a trusted third party know all your addresses up to that moment but I don't know anymore your addresses from that moment on while you keep controlling also the next addresses with the same spending key this just to say that in a couple of lines of code we will generate this sub uh viewing private key we will call a viewing private key node and we will use the node number zero of course we are just generating now we use number zero the day you don't trust a thrusted to party anymore it's enough to put this as one and you will start generating other St addresses control all by the same private key but the other party won't be able to know that are your addresses those first step is use stt account kit to extract the specific node from the viewing private key required for generating the fmal key so what I just said we are going to do with a with a one simple function that we take from the steal account kit and uh if you look at the list of function uh it's called extract viewing private key node and as you can see we are just using this is I don't I don't I'm not going to details but it's a standard bip32 the purpose is 5564 uh we use this number because it reflects the ERC around St addresses nothing special around that and the no is the number we just said 0 1 2 every time you change the node the derived viewing private key completely changes so this function accept two parameters the private View King a the node and returns a a a node the hdq is a node so if we go here and uh just say con viewing private key node as you can see it already knows what I what I need to do and uh yep and this is the uh the implementation so basically I am extracting VI impro key node passing the view in private key that's an input on the function and the current uh node number the number zero we can pass this node numberb as a parameter of this function yes of course but it's usually it's something that you change really once in a while so for the demo is fine to have in the code finally we have the viewing private key we will use to generate all the St addresses from we can go to this next step and here we have to use St account kit to generate an emial private key using the extracted viewing key node and the provided nons so we will use this just generated key to generate this fmr private key that's basically what forms the secret that you just show before okay we need this one to generate the secret when in the slide before we were putting secret we were hiding this intermediate passage that's needed at code level to do that let's go back in our uh St account kit and the function that will need to use it's the longest one actually but uh um generate FM private key that's it this function accept four parameters actually two are mutual optional the first one is the viewing private key node that's the one we just generated okay see it as a view private key but in a way that if I want to rotate it I don't have to change my master key the N is the one that we passed know the 0o 1 2 3 4 that every time we change change the still tles generated so this change quite often this is why we put as an input of the the function and then the chain ID that's why you can generate still is specific for a specific chain here we will pass chain ID zero that what does it mean it's an address that you in your mind can use on any chain not on just specific chain okay why this is done because sometimes you want to know Force some addresses from a logical point of view it's not like from a practical or mathematical point of view to work only on a specific chain because you will deploy a smart contract controlled by T Ste account that's available only on one chain okay and that's an easier way for you to generate St addresses that are for you connected to a specific chain again this is a concept not a mandatory uh mathematical constraint uh the the non should to get different St addresses so the question is like I have a nouns can just change that for different chains if you think you want one address for one chain works the moment that you might have two addresses for the same chain um you might start you might not not remembering that the approach we do for example at fluid key we have always chain zero and we deploy saves because we have saves through the canonical Factory that that generate the same address the same smart account address across all the chains so we don't have this problem and also it's an advantage because if by mistake I send money to the wrong chain I know how to recover that that that amount of money okay the CH is never uh I will see um reviewing with the current you can choose anyone that's you you like absolutely absolutely instead of you can choose two power 256 one and it's Stone again absolutely again this is a concept not a mathematical constraint so whatever you want so uh let me go here I put this and then let me don't ah my bad and okay these are type parameters so uh the viewing private key node is the one we have above the nons is the one passed to the function and the um chain ID we said we're going to put zero and this returns uh Emeral private key uh feel free to go through a code the idea is that uh we also do here Bap 32 that just to to stay in the standard uh we I added a lot of explanation around what it does I don't want to Deep dive as I think it will remove the focus from what we are doing now and finally so that I can finally see the Ste address being generated we will use the stealth account kit to generate St addresses using the spending public key and the generated emal private key if you go to this St account kit you can there's a function generate St addresses that accept uh an array of spending public Keys we set up an array because you can generate multiple uh addresses in one shot and the uh Emeral private key so this is the function uh technically might have picked this up the problem is that this needs to be an array and probably uh misses an S here perfect and now we can can return the St address generated and the okay uh like this because return to type one and then theate key I could have also technically returned the F public key now that's just more to keep those connected to each other as I've generated those t taes now with the setup of okay I have the viewing private key I extract the node I generate the fmr private key so basically I generate the secret let's see in this way and from the secret I generate the St address if we want to go into how this function work this is what probably you were mentioning before you will see that to obtain the St address in the function I do an elliptic multiplication between the spending public key point and the hash of the share secret the share secret is an hash uh the ash of the share secret comes for the share secret and the share secret comes from the eal private key and the spending public key okay again uh these are the advantages of using the Sal account kit you don't have to remember all the steps uh in memory just use a function but that just to prove you that there's elliptic cryptography under under the hood now I'm confident that if we go here and we click generate your first account and we add the account appears now if you add another account another one appears and if you have the third one a third one appears all are different this has nons zero nons one nons two if we look on them on CH uh we will use base chain just for Simplicity it's an empty address there's nothing on it it has no connection to each other it's also empty because we have just generated them no but uh that's to prove you the power of this tool now we can uh go to the start doing the fun part and uh try to deploy a save controlled by one of these to do this we will need to uh wallet connect to the safe UI and we using wallet connect so please fing across that it works I have set up this here let's see amazing now what else you want strange because I pretty sure I added this uh AP maybe my bad uh didn't update the the code one oh strange it's here why does he complain Mor idea po pretty strange but uh let me see seems to go now I don't know why uh but it's done it's 954 because yesterday we had this same issue but 95 for f it's it's right here so if I continue with that let me deploy this on base of course as you can see I have connected a specific St address 954 F that's the first one in the list I want it to be deployed on safe one out of one it's fine and uh just pay now luckily safe allows of sponsored deployment so that's it I don't have to approve any transaction and in a few second the safe will be deployed on chain and we will have address connected to that let's just give a second that it deploys and then we will move actual money on it we'll move a few cents of it and then the last part will be try to move them out and we will need to create the private key for that this is the safe generated it has an address F7 A1 blah blah blah uh let me um switch to basos wallet connect so that's all here all done perfect now I have the address and I will send money to this uh to this address to do that I will use uh my fluid key account just because it is uh it is faster let me send like 0.
01 what's that three cents yes of uh worth of it and uh this is the F7 A1 double check F7 A1 perfect send pin as you as you were mentioned before uh fluid key no releas the transaction for you under the hood this money is coming from a St address a St safe okay that's a I'm just using that to simplify the process okay so money is being sent yeah so the the safe I deployed here I basically told the safe UI this is the signer and it was one of the stealth addresses I generated trust me I have the private key CU I connected through wallet connect then safe deploy the safe because we on base they sponsor the transaction it's it's gasless they pay the gas for for us coinbase is sponsoring the gas and uh that's it we have a safe control with a one out of one signature from this St address what we would have to do is generate a private key to move this money out if we go to the assets we have just received three cents worth of e now and they safe now if I want to move money back let's send this money back to my account but you know we have still addresses so back to another address of myself and say okay I want to empty it send it all out if I go next it works I mean if it's the saf UI uh it's just simulating and say okay wonderful execute it now one execute if I go back here it throws me an error it says evaluating Sal outs private key not implemented I cannot you know do the transaction for you and uh uh if I go back you know there is a user rejected signature there's an error so we have to fix this error and we should be able to move money out and uh complete the workshop this is the easy part of that because we Rec the hard part we have already done the easy part is just one function and you can pull stage three if you want or that's the last part we have have and we have to go to the evaluate St address private key so let me remove the alert and then need to use the stal account kit to generate the St private sending key using the provided spending private key and the fal public key so here is where I need the spending private key and that's the only time you have seen me using that and the fmr public key spend one minute explaining why I need the public key here but it's also a logical way of doing that you never have to share a private key so if I'm in a scenario where I want to generate the St address for you for example I don't share the secret because if I just share the secret everyone will be able to see a secret and everyone will be able to to to do the computation understand who is owning that address I share I generate an FM private key that allows me to generate the secret then I share with you the public Epal public key that you can use to generate the same secret too it's a a lot of tical multiplication but this allows a uh a trustless environment where there's no risk of encrypting stuff on chain because if you encrypt something on chain today is encrypted who knows in 10 years if that same stuff is still encrypted someone can broke that encryption on on chain so this is literally one line of code uh with one function let me go here for the last time and the Ste account kit and get a function that's called generate St private key and if you enter and you see how it is it's very short you input the spending private key and the feral public key the same input we had in our uh function we recompute the share secret of course the output of this computation is the same of the one we do when we generate the address but this time we multiply the spending private key with the ephemeral public key if you remember before to generate the secret we multiplied the spending public key with Epal private key right so all the piece are coming together and I am able to regenerate the secret hash it exactly like we were doing before and doing a slightly different litic multiplication that's not like proper multiplication because we have like then to limit for the end of the curve and get the private key from here we have the private key and if we input to to see if that works to see we get here uh maybe got it yep perfect and that's it but we'll leave it the code for here uh for sure it's not like this it's like this because it returns a type parameter so I have just called the generate St key the function I just show you runs under the hood and returns me the private key that I return to control the transaction and for example how this code works the private key is generated only at the time of the transaction I don't keep store key that I don't want to store and after is thrown away now if we go back to our safe wallet and I ask again to execute the transaction and I go back here technically finger crossed like before yes it works forget about the error the error just react we have received a signature request from metamask yes he made a mask good night from uh safe this is the uh body of the transaction if I approve I'm using the St address private key just generated to confir a transaction and if we go back here H try again maybe was timeout something like that let's see okay T okay of course it's the beauty of the okay somehow the connection with wet connector broke I have no idea why so that's why it wasn't working because wet connect was no more connected now it says it's connected let's try last time so this this is where I want to send the money I want to send it all next prep transaction otherwise I will reset the connection with wet connect let's see if it works okay let's approve no there is something it doesn't like so I know what to do disconnect refresh request to connect again with wet connect regenerate the connection amazing it's connected 095 perfect try to execute again one last time let approve perfect and now it worked this is why I was asking you to keep finger crossed with Willet connect so uh if you notice we are sending money back to the account that sent me actually we are sending money back to another address that send money but controlled by the same owner and this is the power of St addresses if you look on chain you will see money coming from A to B and B to C and you have no idea if a and b are the same owner and see a different one or like in our case A and C are the same owner and B was just a middle where we went send money through as you can see we just receive 0.001 eth that like 3 cents and if I look at that on basan I will be able to see that you know it was sent to this address that has just uh three cents of worth of e while in my wallet I have $5 you can do a lot more I'm not doing that now I'm want to like leave some space for the questions you can for example example wallet connect safe UI to uniswap and control it add another signer generate a two out of two signer by for example here in the settings add another signer and this signer you know can be another Ste of the one you generated and you say why doing that I have no idea but maybe you want you know to to show you have one out of 20 for some reason and I'm adding a second signer uh to that and so on I'll go back to the slide but there's time for questions and that was my main concern is leaving a like a 15 minutes to discuss and go on um you can find the final version of this demo app on dc7 fluid key.com just in case you want to play a little bit around and make sure also to check the repository uh I will also add the link to repository on this page now it's currently missing and uh one last slide if you want to learn more around the St address or you want to start building please uh scan this QR code we have put together a series of uh links and useful links to um learn more about that and there's also a link to our Ste account kit the SDK we just used there's also a telegram group specific for St addresses there like nice discussion going on if you want to be added just uh send a message on telegram to moris fluid key and we will be super happy to add you to that uh telegram account group with this they open to questions but thank you so much for your attention on behalf of Mo and myself thank you [Applause] there's a question there behind you yeah uh for me it's still not clear how the each key relates to each other like can we somehow explain it maybe with math or with simple slide if you have uh I understand that you need to arrive to the stealth private key and public key and the path to go there should be like through different Keys could you please explain math behind it like um at the beginning just to just to understand because we show one SL the receive and send did you see that I watched it on why YouTube so maybe so that wasn't what wasn't clear from that slide maybe or like how let me go yes better with the mic exactly perfect okay yeah here we go so yeah basically the the whole point of stealth addresses right like again otherwise you could also if if you want to generate new address for yourself you don't need self addresses because you can just use like an HD you know path to like create a new address every time right and and that's controlled by the same private key the whole power of Steal addresses is that you can share a public key with um you know anyone you want and then they can share um a an address they can create an address on your behalf that they know only you can basically control right so in the case of what we built just now one one example is for example say you're getting added to lots of different multi sigs right and you don't want your main address to be added to it but you also don't want to generate like lots of different addresses yourself and your metamask you just want to share you know basically your your your meta public key and anybody adding you to a safe can basically just generate a new address on your behalf add you to that multisig and you'll have full control and basically access to to to also control that that's again at a maybe high level so is there like what you like yeah maybe you can explain better what you're not yeah like you shared with them a public Emeral key and how they can generate additional address for you is it or do what do you should I think yeah it would be better if you explain the specific math of multiplication of elliptic curve equations if you have because it will be more clear sure so I think we can go to our repo maybe and uh show you that the public one uh start from the generate St address this one a little bit more awesome do you want to do you want to run through it actually y so uh this uh why I I don't I would just point with this so um this line here still public key is spending public key multiply by the share secret okay this line here is on the slide this line here okay to get to this one we need to generate this uh secret the secret here um forgetting about like generating a random one like how we implemented here uh which generate a a point to do litic mulation you need to generate a point way doesn't work from a um sorry here we generate the hash okay from the secret so that we have a fixed length over that okay and then uh the multiplication happens from the point on the curve of the spending public key with the ash of the share secret now there's this share secret still like up in the air the share secret ear comes from the ephemeral private Key multipli by the spending public key you might say hey but where is the viewing key and all this steps the viewing key is used to generate Emeral priv key in our case so the F prod key is somehow derived from the viewing key Rec compute the same sequence only if you in this case only if you have the viewing private key and so if I want you to compute the address for me I share with you my viewing private key a node of it okay you then generate the FM private key and then the spending public key is public so I can even publish on chain it's not a problem and then from here you arrive to generate the Ste address again there are even other methods to do that but the idea is that only the spending public Keys is here and this s secret needs to be generated in a way that depends on the use case in our use case for example you want a way that is PUD random generated for the use case and this is why use the viewing private key to generate this FM private key and uh do you remember that we use the non 0 1 2 3 4 for the different addresses a different nons will generate a different F private key and this is why the secret changes and this is why the final address changes it's like a butterfly effect uh from uh from the nons when it comes instead to the to the other way around it's quite easier because we have already the FM uh key generated okay so like you generate the private key you also have a public key of this fmal and then when we go to generate uh still private key that's the function you already have the fal public key you have the spending private key and that's uh you you compute the same if you if you take this share secret and the other one done the other way they're exactly the same and this is something that you cannot change this is a mathematical constraint this is how electric modification like basically uh works with a share secret then you hash it and then the operation is slightly different because we are working with private Keys here not public keys but and you can think is the same is Li multiplication with a module that limits its size uh on on on the Cure otherwise you can have values that goes out of the max available for a private key okay but you need to store somewhere ifal public key right in the storage so in our case since it's UMO random generated we can always recreate and this is also why we were returning from the St uh generate St address this is why here we were returning ah sorry my bad uh I got it so you this FAL public key array you generate using HD f for the pretty exactly but then but then with ERC 5564 for example the public key you could you could put that on chain and then only if you have the private uh spending key you can then also like regenerate as address and and see that it's your address basically so yeah there's there's definitely different ways to go about that that part as well and this is the part I was speaking before about based on your use case you can adapt one or choose another or you even find a third path that we haven't explored yet uh and do that okay okay thank you got it you're welcome awesome yes thank you everyone if you need more questions we
Automatic transcript — names and jargon may be misspelled.