The private receive layer for Ethereum
Every payment lands on a new address.
One public address turns your income, your balance and every payer into public record. With ephemeral, each payment gets its own one-time address that only you can find and spend from. Built on ERC-5564, the open standard any wallet can implement.
The client is in beta. Partners and early testers get it first, then everyone.
§1 · The problem
Your address is a public bank statement.
Share one address and you share everything that ever reaches it. Switch the view: the same five payments, received both ways.
Example payments, for illustration. The first stealth address is the real one from the worked example in §3.
§2 · Why now
Ethereum's builders want to break the one-address norm. The receive side is still open.
In May 2026 Vitalik Buterin called a single global address “a norm we have to break”, backing Kohaku’s new address for every app.
A new address per app
Wallet-level privacy, such as Kohaku.
A trail nobody can follow
Shielded pools, such as Privacy Pools and Railgun.
A new address per payment
ephemeral, on ERC-5564. Pools hide the trail; ephemeral hides where it lands.
ephemeral is independent. It is not affiliated with the Ethereum Foundation or with any project named here.
§3 · The protocol
Real keys. Real math. Check every line.
No interaction between sender and receiver, and no server in the middle. Below: one payment computed with demo keys, values you can reproduce in a few lines of TypeScript.
- 01
You publish one meta-address
Two public keys, spend and view, derived in your browser from one wallet signature.
Chain sees: this address accepts stealth payments.
- 02
The sender derives a one-time address
A random key and your viewing key give a shared secret only the two of you can compute.
Chain sees: nothing yet.
- 03
Funds land with an announcement
One transaction pays the new address and publishes the sender’s public key and a one-byte view tag.
Chain sees: a payment to an address that never existed before.
- 04
Your client finds it, locally
The view tag rejects 255 of 256 announcements that are not yours before any further math.
Chain sees: nothing. Scanning never leaves your device.
- 05
Only you can spend it
Its private key is your spending key plus the shared secret. Nobody else holds your spending key.
Chain sees: a transfer out of an address with no link to you.
import { secp256k1 } from '@noble/curves/secp256k1'
import { keccak256, hexToBytes } from 'viem'
import { publicKeyToAddress } from 'viem/accounts'
const s = secp256k1.getSharedSecret(p_e, P_view, true) // p_e · P_view
const s_h = keccak256(s)
const tag = s_h.slice(0, 4) // view tag: 0xc1
const P = secp256k1.ProjectivePoint.fromHex(P_spend)
.add(secp256k1.ProjectivePoint.fromPrivateKey(hexToBytes(s_h)))
publicKeyToAddress(`0x${P.toHex(false)}`) // 0xF236…52F4The derivation step by step, with the proof that only the receiver can spend: Docs › Stealth address math
§4 · Research
4 in 10 stealth payments on Ethereum were traced to their owner.
We re-ran the method of Kovács & Seres (2023) on every Umbra and ERC-5564 payment ever made on Ethereum, to block 26,127,110. The cryptography holds. The leaks come from what wallets do next.
n = 782, 7,415, 8,039, 4,078, 3,820 and 883 withdrawn addresses. Aggregate counts only: no address, cluster or link is published.
§5 · Safe by default
Five habits give a stealth payment away. Our client is designed to close each one.
| LEAK | WHAT GIVES YOU AWAY | PLANNED CLIENT DEFAULT |
|---|---|---|
| H1 · registrant reuse | Withdrawing to the address that registered your keys. Behind 9,709 traced withdrawals. | Never offered as a destination. Typing it in shows a hard warning. |
| H2 · round trip | Sending funds back to the address that paid you. | A warning before you sign when the destination is the payer. |
| H3 · collector | Sweeping many stealth addresses into one wallet. 45.68% of single withdrawals. | No sweep-all. Each payment moves on its own path, at its own time. |
| H4 · fee fingerprint | A custom priority fee that repeats across withdrawals. | Fees follow the network’s standard values. |
| H5 · gas funding | Funding a token-only stealth address with gas from your main wallet. | Never funded from a linked wallet. Sponsored gas is on the roadmap. |
§6 · Private names · planned
One name. A fresh address on every lookup.
Anyone can pay name.ephmrl.eth from any wallet that resolves ENS names, even one that knows nothing about stealth addresses. An ENS offchain resolver (EIP-3668) answers each lookup with a new address only you can spend from.
What you trust: the gateway issues each address and publishes its announcement, so it knows which addresses belong to your name. It holds no keys and cannot move funds. Example addresses.
§7 · The receive layer
Every wallet, payroll run, invoice and agent needs a place to get paid.
ephemeral is building that place: an app, private names and a library other wallets can embed. Built on open standards, so it is a layer, not a walled garden.
fig. 3 · The Announcer and the registry sit at the same address on all five chains, so the same keys receive on every one of them.
New · Uniswap v4
The privacy layer for Uniswap v4.
Hooks are turning tokens into products. Every buy, payout and reward in them still lands on a public address. ephemeral adds the missing piece: any v4 token can be bought, paid or paid out to a one-time address that only the receiver can find, with the gas for the next step already there.
Stealth Buy.
Buy on any v4 pool and the token goes straight to a fresh stealth address. The router announces it under ERC-5564, so the receiver's wallet finds it, and sends a little ETH along for gas.
Pay in any token.
A pay link where the payer sends ETH and the receiver gets the token they chose, on a one-time address. Every payment becomes a buy.
Built into hooks.
Private payouts in one call: NFT rewards, buybacks and airdrops land on one-time addresses. And our immutable anti-sniper hook, private buys included, as an open launch kit for other projects.
What it does not hide: the buyer's address is the sender of the transaction. It protects the receiver. How Stealth Buy works →
§8 · How we build
Six rules we hold ourselves to.
Standards, not silos.
Same Announcer, same registry as every ERC-5564 wallet. Your payments work without us.
No custody, no admin keys.
Keys never leave your device. Nothing we run can move your funds.
Measure, then claim.
Every research number on this site can be reproduced with our open-source scanner.
State the limits.
What is public, who sees what, and what we cannot protect, in writing.
Ship upstream.
Fixes go to the shared SDK and the ERC thread, not only into our app.
A credible exit.
Payments that landed stay yours: any ERC-5564 client with your keys can find and spend them, with or without us.
§9 · Trust model
Who sees what. Including us.
| PARTY | SEES | CANNOT SEE OR DO |
|---|---|---|
| Anyone on-chain | Sender, amount, time, the one-time address, the announcement | That the address is yours |
| The sender | The one address they paid | Your other payments or your balance |
| Your RPC provider | Your IP and the addresses your client asks about | Your keys. Use your own node if this matters. |
| The name gateway (planned) | Which addresses it issued for your name, and the lookup IP | Your keys or funds that landed. If compromised, it could misdirect new payments to a name. |
| The ephemeral team | Nothing from your client. As gateway operator: the addresses issued for your name | Your keys. We cannot move funds. |
| You | Every payment to you, with your viewing key | Nothing is hidden from you |
§10 · Roadmap
Eight phases toward an Ethereum where no address is reused.
Phases run in parallel and update as things ship. We publish status, not dates.
Is this a mixer?
No. Nothing is pooled and nobody else’s funds touch yours. Each payment goes straight from the sender to a new address that belongs only to you.
Can ephemeral see my payments?
Not through the client: your viewing key never leaves your device. If you use a private name (planned), our gateway knows which addresses it issued for your name. Paying your meta-address directly avoids that.
Does it work with other stealth wallets?
With any wallet that implements ERC-5564: same standard, same Announcer, same registry, so payments work both ways. Umbra predates the standard and uses its own contracts; our research covers it, the client does not use it.
Can I show my income to an accountant?
Yes, by design. Your viewing key gives read-only access to all incoming payments and can never move funds. Exporting it from the client is planned.
What if I lose my device?
Sign the same message with the same wallet and your keys, payments and balances come back. If you lose the wallet itself, nobody can restore them.
Who builds ephemeral?
An independent team led by Sirius, building on Ethereum since 2016. Code, research and numbers are public, so you can judge the work rather than the names.
