The chain
can't name
the receiver.
$SEALED lands on a one‑time address only the receiver can find and spend. The sender and the amount stay public. The receiver doesn't.
A transfer names two people.
Every transfer on a public chain names the sender who signs it and the receiver whose address sits in the calldata for anyone to read, forever. $SEALED removes the second name.
A transfer names two people.
From, to, amount. All readable by anyone, forever.
The receiver publishes a meta‑address, once.
st:rh:0x02… registered on the ERC‑6538 Registry, tied to their normal wallet.
The sender seals it to a one‑time address.
Derived in your browser, right now, with the app's own code. It has never existed before and will never be used again.
The vault. Every box looks the same.
Every sealed send posts a notice to the ERC‑5564 announcer. The wall is public. It says nothing to anyone.
Only the receiver's key opens one.
The viewing key checks one byte per box, then the full match. The spending key moves the funds. Neither leaves the receiver's device.
What it hides. What it doesn't.
- the sender
- the amount
- the token
- the time
Sealed sends hide who receives. They do not hide who sends or how much. We say so here because a privacy tool that overclaims is worse than no privacy tool at all. If you need all three hidden, Deep shield takes you to a shielded pool that hides sender, receiver and amount together. We link to it. We do not pretend to replace it.
A z‑addr in one signature.
Sign the $SEALED key message once and your browser derives a viewing key and a spending key. Neither leaves the tab. Nothing is uploaded anywhere.
Sign one message.
Your shielded keys are derived from that signature and never leave your device.
Register your meta‑address.
One transaction to the ERC‑6538 Registry that already lives on Robinhood Chain.
Share it like an address.
Anyone can send to it. Only you can find what arrives. Sweep with your spending key to a fresh wallet.
Zcash invented the z‑addr.
Zcash built the original z‑addr: a public record where the receiver is a secret. $SEALED brings the same idea to Robinhood Chain as an ERC‑20, settled in USDG. Every send through the app works with $SEALED.
Deep shield
If you need the sender, the receiver and the amount all hidden, Deep shield sends you to a full shielded pool on Robinhood Chain. Sealed sends alone hide only the receiver. We do not pretend to replace a pool.
Three contracts. No owner. No fees.
SealedSend is a single contract with no owner, no fee switch and no upgrade path. It moves a token to a one‑time address, drips a little ETH so the receiver can sweep, and announces. That is all it can do.
The announcer and the registry are the canonical ERC‑5564 and ERC‑6538 singletons, deployed to the same address on every EVM chain through the deterministic factory, not copies of ours. SealedSend is deployed to Robinhood Chain and verified on Sourcify.
Questions
What does $SEALED actually hide?
The receiver. Your coins land on a one time address only the receiver can find and spend. The sender, the amount, the coin and the time stay public. We say so plainly, because a privacy tool that overclaims is worse than none.
Is my wallet exposed when someone pays me?
No. Payments never touch your normal wallet. Each one lands on a fresh address derived just for that transfer, which only your key can open. You sweep it to a wallet of your choice.
Do I need to set anything up?
Connect once. Your sealed inbox is created from a single signature and registered to your wallet, so from then on anyone can pay you by your normal wallet address. Keys are derived in your browser and never uploaded.
Can I send any coin?
Yes. Any standard ERC‑20 on Robinhood Chain, including Pons family coins. Paste the coin's contract address, then the recipient's wallet address or their z‑addr, and send.
What is a z-addr?
Your stealth meta‑address: a public string that lets anyone pay you without ever naming your wallet. You do not have to handle it, sending to a normal wallet address works too.
Where do my keys live?
Only in your browser tab, derived from one signature. Nothing is uploaded. Closing the tab forgets them; sign again to recreate the exact same keys. Only ever sign the $SEALED key message on sealedrh.fun.