Blind credits / from your wallet
Blind credits,
kept on your device.
- 1
One-time key
- 2
Pay
- 3
Credit
- 4
Mint credits
- 5
Keep them
- 6
Wipe the key
1 · Make a one-time key and choose how to pay
The key is made in this tab, needs no account and never leaves it. It receives your payment, the page turns the credit into blind credits, and then the key is switched off and wiped.
USDG
USDG on Robinhood Chain is credited one for one, with no haircut, then turned into credits of the same value.
$Verify
Paying in $Verify is considered for after the token launch. Not available.
Your credits
None yet. Credits bought here stay in this browser and can be saved to a file you keep.
What is linkable, and what is not
Can be linked to you
- The payment. Sending USDG is a public transfer on Robinhood Chain. Anyone, the router included, can see that your wallet paid, how much, and to which one-time key.
- The purchase. The router records that the one-time key bought credits: how many and in which sizes. Put together, “this wallet bought N credits” is on record.
- Your network address and timing. Buying over the open internet shows the router your IP address, and spending right after buying links the two by time. Waiting and using an onion route both help.
Cannot be linked to you
- Which prompts the credits paid for. The router signs each credit blind: it never sees the credit it signs. When one is spent, the router can tell it is genuine and unspent, but not which purchase or wallet it came from. The call is logged against a hash of the credit, with no key, account or wallet, and its receipt says the same.
What credits do not hide
- The text of a request. On every lane the router reads a request in memory to route it, and that includes calls paid with credits. Credits hide who pays, not what is sent.
- Your address while spending, unless you use Tor. Spend credits through an onion address to keep your network address from the router. Calls on one circuit can be linked to each other.
- Unused value. A credit pays for one call up to its value; the rest is not returned. Credits expire on the date shown with them, and a lost credit cannot be replaced, because nobody keeps a record of who holds them.
Spending them
The unlinkable lane is not served yet, so credits cannot be spent anywhere today. When it opens, a credit goes in the Authorization header as BlindCredit credit=<credit>, with the lane named in X-VR-Lane: unlinkable.