Skip to main content
0xio implements industry-standard cryptographic algorithms to ensure the highest level of security for your assets.

Signing Algorithm

Ed25519 (Twisted Edwards Curve)
  • High-speed signature generation and verification
  • 256-bit security level
  • Implemented via TweetNaCl.js for browser compatibility
  • Resistant to side-channel attacks

Hashing

  • SHA-256: Primary hashing algorithm for address generation
  • HMAC-SHA512: Used in key derivation processes

Symmetric Encryption

AES-256-GCM for local vault protection
  • Authenticated encryption: guarantees both confidentiality and integrity
  • Protects your private keys at rest on the device
  • The vault key is derived from your password with PBKDF2-HMAC-SHA256
  • In the extension the vault is sealed under a random vault key, which is stored only wrapped by the key derived from your password. While unlocked, the session holds that vault key, never your password, and changing the password re-wraps the vault key without touching the vault
The PBKDF2 iteration count is tuned per platform to balance security against device performance:

Key Derivation

Mnemonic Standard

BIP-39 recovery phrases (English wordlist)
  • 0xio generates 12-word phrases (128-bit entropy)
  • Imports of longer phrases (e.g. 24-word, 256-bit) are also accepted
  • Dictionary: the 2048-word official BIP-39 English wordlist

Seed Generation

PBKDF2-HMAC-SHA512 with 2048 iterations
  • Converts the mnemonic to a 64-byte cryptographic seed
  • Salt: the string mnemonic plus an optional passphrase (per BIP-39)

Master Root Key Derivation

All 0xio platforms (extension, mobile, desktop) use the same canonical key derivation:
  • No HD path: Octra uses the master root key directly; there is no BIP-44 derivation path
  • Deterministic: The same seed phrase always produces the same master key
  • Cross-platform: Importing the same seed phrase produces the same address on all 0xio products (extension, mobile, desktop)
  • Secure: HMAC-SHA512 provides cryptographic strength; the first 32 bytes become the Ed25519 seed (the next 32 bytes form the chain code)

Address Format

0xio generates Octra addresses through a multi-step process:
1

Generate Ed25519 Public Key

Derive the 32-byte public key from the private key using Ed25519
2

Hash Public Key

Compute the SHA-256 hash of the raw public key bytes
3

Base58 Encoding

Encode the 32-byte hash using Base58 (Bitcoin alphabet)
4

Add Prefix

Prefix with oct for Octra Network identification
Result: A 47-character string (oct + 44 Base58 characters). During generation, 0xio “grinds” (regenerating any key whose encoded hash is shorter than 44 characters), so every address is exactly 47 characters.

Security Architecture

Privacy First: 0xio implements zero telemetry. We never collect IP addresses, wallet addresses, or usage data.

Privacy Cryptography (PVAC)

Octra’s private balances are powered by PVAC, an additively-homomorphic encryption scheme. All PVAC cryptography runs locally on your device through pvac-rs, a purpose-built Rust library built on the curve25519-dalek Ristretto255 group.

Core Operations

  1. FHE Encrypt/Decrypt: Additively-homomorphic encryption of token amounts, so ciphertexts can be added and subtracted on-chain (ct_add / ct_sub) without ever decrypting
  2. Range Proofs: Bulletproofs-style zero-knowledge proofs (64-bit) that an encrypted amount is non-negative and within bounds, without revealing the value
  3. Pedersen Commitments: Binding commitments to amounts using Ristretto255 points, used for transaction integrity
  4. Bound & Zero Proofs: Used when decrypting and when validating balance updates to prove a ciphertext encrypts zero (or a bounded value)
  5. Stealth Transfers: An X25519 ECDH shared secret derives a per-output stealth tag and claim keys, so private sends are unlinkable and the recipient scans for outputs addressed to them

Stealth Transfer Detail

A stealth transfer derives its routing and claim material entirely from an ECDH shared secret:
  • Shared secret: SHA-256(X25519(sender_ephemeral_sk, recipient_view_pub))
  • Stealth tag: first 16 bytes of SHA-256(shared_secret ‖ "OCTRA_STEALTH_TAG_V1"), which the recipient looks for when scanning on-chain outputs
  • Amount: encrypted to the recipient with AES-256-GCM keyed by the shared secret
  • Claim keys: further domain-separated SHA-256 derivations bind the claim to the recipient’s address

pvac-rs

The pvac-rs library compiles to multiple targets to run natively on each platform: Range-proof generation time varies widely by platform, from seconds on native desktop builds to over a minute on mobile. Key dependencies: curve25519-dalek (Ristretto255 group arithmetic and scalars) and sha2 / sha3 for hashing. The browser/mobile JavaScript layer separately uses @noble/hashes and tweetnacl.