rob thijssen b454e4424f
Some checks are pending
ci / gate (push) Has started running
fix(wormhole): nullifiers never leave the client
The spent check for wormhole deposits looked each nullifier up in
Wormhole::UsedNullifiers by key. That map is Blake2_128Concat, so the key
is blake2_128(n) ‖ n and every request handed the node the nullifier
itself. An exit publishes its nullifier on chain, so whoever runs the
node could match a later exit to the connection that asked, and that
connection also asked for the wallet's ordinary balances. The accounts
page ran it automatically for every open wallet with a phrase, so 0.1.0
and 0.2.0 sent unspent nullifiers to our mainnet endpoint.

spent_among now does what quantus/extension does: it reads whole buckets
of the map (keys sharing the first byte of blake2_128(n)) with
state_getKeysPaged, the buckets it needs padded with random others to at
least 16 and asked in shuffled order, and decides membership in Rust. The
node learns which buckets were read, never which entry mattered. The per-
key lookup is gone. Tests pin the rule: the plan covers ours, pads to 16
without repeats and does not lead with ours; no request carries a
nullifier and each is the map's root plus one byte. Against mainnet, a
real used nullifier read from a bucket hashes to that bucket and the
bucket read reports it spent and a random one unspent.

doc/threat-model.md gains the wormhole section: nullifiers and the
wallet's leaves are never named to a node, and spending (#46, #47) must
not request the Merkle path for the spent leaf alone.

Closes #68

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014ftBXYuba8ARhQeF74oUgW
2026-09-16 21:00:32 +03:00
2026-09-16 19:22:38 +03:00

blackbeard wallet

A desktop wallet for post-quantum chains, Quantus first. Linux, Windows and macOS; installable on Fedora with dnf.

Shape

The wallet is a Rust cargo workspace with a Tauri shell and a React webview. That split is the security model, not a convenience: every key, signature, decoded transaction and amount lives on the Rust side, and the webview only renders what a Tauri command hands it. Nothing that could serialise a secret is reachable from JavaScript.

crates/
  wallet-entities/   domain types and the IPC wire protocol; exported to TypeScript
  wallet-core/       wallet logic and the ports it is written against
  wallet-data/       adapters behind those ports: keystore, cache, RPC, provider APIs
  wallet-app/        the Tauri binary; commands are one-line shims into core
ui/                  Vite + React + TypeScript webview

The ports in wallet-core are what make "any post-quantum chain" a profile rather than a rewrite:

  • KeyScheme turns a seed and a path into a signer. ML-DSA-65 and ML-DSA-87 now; whatever the next chain uses later.
  • ChainAdapter knows one chain: balances, building and submitting a transaction, watching it. The Substrate adapter is driven by runtime metadata plus a small per-chain profile (ss58 prefix, decimals, signature enum, transaction extensions, signing-context rule, coin type).
  • SwapProvider is a swap venue. NEAR Intents first.
  • FiatRamp builds a provider session through a relay on our infrastructure, which holds the provider secrets, and opens it in the system browser.

The wallet is post-quantum only. Classical chains appear only as transit legs of a swap or ramp; the wallet never derives a secp256k1 or ed25519 key.

Why these choices

Quantus signs extrinsics with ML-DSA, hashes public keys with Poseidon2 for the account id, and shields mining rewards behind a Plonky2 wormhole whose prover is minutes of native CPU. All of that exists as Rust crates and nothing else, so the core is Rust. Tauri is the house desktop convention (~/git/architecture/generic.md §4) and the only shell that packages rpm, deb, msi and dmg with a Rust-owned IPC boundary out of the box.

NEAR's post-quantum work (their MPC fork with threshold ML-DSA-87) is not yet able to sign a Quantus extrinsic, so the swap module is built and tested against chains NEAR Intents already lists, with Quantus as a registry entry that lights up when the bridge does.

Building

pnpm --dir ui install
cargo tauri dev --config crates/wallet-app/tauri.conf.json   # from crates/wallet-app: cargo tauri dev
cargo test --workspace                                        # also regenerates ui/src/api/generated

The CI gate is cargo fmt --check, cargo clippy -D warnings, cargo test, and the webview's typecheck, lint and build. Run them before claiming done.

Work

Work is filed before it is done. Epics carry the epic label and an external definition of done; their steps carry child, in dependency order, at https://git.lair.cafe/blackbeard/wallet/issues. A commit that finishes a child closes it (Closes #N); when an investigation contradicts an issue, the correction is a comment on the issue, dated, not a surprise in a diff.

Description
Desktop wallet for post-quantum chains, Quantus first: ML-DSA signing in Rust, Tauri shell, NEAR Intents swaps and fiat ramps via transit chains. Linux (rpm/deb), Windows and macOS.
Readme 2.6 MiB
v0.3.0 Latest
2026-09-18 07:02:22 +00:00
Languages
Rust 72.1%
TypeScript 23.7%
CSS 1.8%
Python 1.6%
Shell 0.5%
Other 0.3%