Signing Algorithm
Ed25519 (Twisted Edwards Curve)- High-speed signature generation and verification
- 256-bit security level
- Implemented via TweetNaCl.js for browser compatibility
- Resistant to side-channel attacks
Hashing
- SHA-256: Primary hashing algorithm for address generation
- HMAC-SHA512: Used in key derivation processes
Symmetric Encryption
AES-256-GCM for local vault protection- Authenticated encryption: guarantees both confidentiality and integrity
- Protects your private keys at rest on the device
- The vault key is derived from your password with PBKDF2-HMAC-SHA256
- In the extension the vault is sealed under a random vault key, which is stored only wrapped by the key derived from your password. While unlocked, the session holds that vault key, never your password, and changing the password re-wraps the vault key without touching the vault
Key Derivation
Mnemonic Standard
BIP-39 recovery phrases (English wordlist)- 0xio generates 12-word phrases (128-bit entropy)
- Imports of longer phrases (e.g. 24-word, 256-bit) are also accepted
- Dictionary: the 2048-word official BIP-39 English wordlist
Seed Generation
PBKDF2-HMAC-SHA512 with 2048 iterations- Converts the mnemonic to a 64-byte cryptographic seed
- Salt: the string
mnemonicplus an optional passphrase (per BIP-39)
Master Root Key Derivation
All 0xio platforms (extension, mobile, desktop) use the same canonical key derivation:- No HD path: Octra uses the master root key directly; there is no BIP-44 derivation path
- Deterministic: The same seed phrase always produces the same master key
- Cross-platform: Importing the same seed phrase produces the same address on all 0xio products (extension, mobile, desktop)
- Secure: HMAC-SHA512 provides cryptographic strength; the first 32 bytes become the Ed25519 seed (the next 32 bytes form the chain code)
Address Format
0xio generates Octra addresses through a multi-step process:1
Generate Ed25519 Public Key
Derive the 32-byte public key from the private key using Ed25519
2
Hash Public Key
Compute the SHA-256 hash of the raw public key bytes
3
Base58 Encoding
Encode the 32-byte hash using Base58 (Bitcoin alphabet)
4
Add Prefix
Prefix with
oct for Octra Network identificationoct + 44 Base58 characters). During generation, 0xio “grinds” (regenerating any key whose encoded hash is shorter than 44 characters), so every address is exactly 47 characters.
Security Architecture
Privacy Cryptography (PVAC)
Octra’s private balances are powered by PVAC, an additively-homomorphic encryption scheme. All PVAC cryptography runs locally on your device through pvac-rs, a purpose-built Rust library built on thecurve25519-dalek Ristretto255 group.
Core Operations
- FHE Encrypt/Decrypt: Additively-homomorphic encryption of token amounts, so ciphertexts can be added and subtracted on-chain (
ct_add/ct_sub) without ever decrypting - Range Proofs: Bulletproofs-style zero-knowledge proofs (64-bit) that an encrypted amount is non-negative and within bounds, without revealing the value
- Pedersen Commitments: Binding commitments to amounts using Ristretto255 points, used for transaction integrity
- Bound & Zero Proofs: Used when decrypting and when validating balance updates to prove a ciphertext encrypts zero (or a bounded value)
- Stealth Transfers: An X25519 ECDH shared secret derives a per-output stealth tag and claim keys, so private sends are unlinkable and the recipient scans for outputs addressed to them
Stealth Transfer Detail
A stealth transfer derives its routing and claim material entirely from an ECDH shared secret:- Shared secret:
SHA-256(X25519(sender_ephemeral_sk, recipient_view_pub)) - Stealth tag: first 16 bytes of
SHA-256(shared_secret ‖ "OCTRA_STEALTH_TAG_V1"), which the recipient looks for when scanning on-chain outputs - Amount: encrypted to the recipient with AES-256-GCM keyed by the shared secret
- Claim keys: further domain-separated SHA-256 derivations bind the claim to the recipient’s address
pvac-rs
The pvac-rs library compiles to multiple targets to run natively on each platform:
Range-proof generation time varies widely by platform, from seconds on native desktop builds to over a minute on mobile.
Key dependencies:
curve25519-dalek (Ristretto255 group arithmetic and scalars) and sha2 / sha3 for hashing. The browser/mobile JavaScript layer separately uses @noble/hashes and tweetnacl.