Docs menu

YONDER docs

What is private, what is public

YONDER keeps one thing out of sight: where your piece lands. Your buy, your mint and every token amount stay public on Robinhood Chain, the same as any transaction, and this page says plainly which part is which. There is no account and no email. You bring a wallet, and your own keys do the rest.

Status

At a glance

WhatPublic or privateWhy
Your buyPublicAn ordinary swap from the pool. Anyone can read it, like every buy.
The mint transactionPublicYour own wallet sends the mint and pays the network fee, so the sender is visible.
The announcementPublicThe canonical ERC-5564 Announcer logs the stealth address, an ephemeral public key, a one-byte view tag, and which collection and token this is. No buyer address and no amount.
Which stealth address is yoursPrivateTo anyone reading only the announcements, it is a fresh address with no history. Only your view key can recognise it.
Your spending key and view keyPrivateDerived in your browser from one wallet signature. Never sent anywhere and never stored.
Your identityNever collectedNo account, no email, no name. Just your wallet and your keys.
Token amounts and balancesPublicEvery ERC-20 amount and balance is visible on chain, including tokens you make private.

How a stealth address works

YONDER uses ERC-5564, the Ethereum standard for stealth addresses, with scheme 1: secp256k1, the same curve your wallet already uses.

  1. One signature makes two keys. You sign the message Yonder stealth keys v1 | chain <chainId> | account <your wallet, lowercase> once. Your browser turns that signature into a spending key and a viewing key. The signature and both keys stay in page memory, and they are cleared when you switch account, switch chain or disconnect.
  2. A fresh ephemeral key for every delivery. For each piece, the browser picks a new random ephemeral private key. Its compressed 33-byte public key is the only part that gets published.
  3. A shared secret only you can rebuild. An ECDH exchange between the ephemeral key and your viewing key gives a shared point. Keccak256 of that point gives a shared number, and its first byte is the view tag.
  4. A brand new address. The stealth address comes from your spending public key plus that shared number. Its private key is your spending key plus the shared number, which only you can compute.

The Announcer, already live on Robinhood Chain

The canonical ERC-5564 Announcer is a shared, standard contract, not a YONDER contract. Its address is 0x55649E01B5Df198D18D95b5cc5051630cfD45564. A read-only check on Robinhood Chain (chain id 4663) on 2026-09-27, at block 74000789, found 709 bytes of deployed code there. When your piece mints, the collection calls this Announcer with scheme id 1, the stealth address, the ephemeral public key and 57 bytes of metadata: the view tag, the mint selector, the collection address and the token id.

The EIP-712 claim

Before a piece can mint, the server reads your buy back from the chain and checks it. Only then does it sign an EIP-712 MintAuthorization under the Yonder Collection version 1 domain. That typed signature names the buyer, the buy reference, the amount, a deadline, and the stealth address, ephemeral public key and view tag. It binds the buy and the stealth destination together, so the authorisation cannot be pointed at a different address. The contract allows one piece per wallet and one per buy, and your own wallet sends the mint.

What leaves your browser during a claim is the public part: the buy's transaction hash, the new stealth address, its ephemeral public key and its view tag. Your keys and the signature that made them never leave.

What an observer sees

Someone watching only the Announcer sees a new stealth address, an ephemeral key, a view tag and a token id. From the announcements alone they cannot tell whose piece it is. Someone reading the whole chain sees more: your buy, then a mint transaction sent from the same wallet, which lands the piece at that stealth address.

The honest limit

Limit

Because your own wallet sends the mint, a careful observer can link the buying wallet to the stealth address. The same is true when you send tokens from your main wallet to a stealth address, or top up a stealth address with gas from your main wallet.

Stealth addresses reduce address reuse. They are not a mixer, and they do not hide amounts. A private relay that closes the linking gap is in development. Relayer gas funding is not part of the current release.

What YONDER never asks for

No account, no email, no name and no password. Connecting a wallet reads your address. Building your stealth keys takes one signature, which stays in your browser. If you lose access to your wallet, there is no reset link to fall back on, because there is nothing to reset: your keys come from your wallet and nowhere else.