metaspace
Concepts / Recovery words

Concepts

Recovery words

The twelve words are the seed. Everything that can open the vault is derived from them.

The seed

The twelve words are the seed. They are generated in the browser when the vault is created, shown once, and never stored or sent anywhere. At withdrawal they are typed in, used to derive the current one-time key and the next commitment, and discarded.

What is derived from it

Every one-time key the vault will ever use comes from the seed: one set of 34 chain secrets per rotation. Writing nn for the vault’s rotation count and KDF\mathrm{KDF} for the client’s derivation function,

xi(n)=KDF(seed, n, i),i=1,…,34.x^{(n)}_i = \mathrm{KDF}(\mathit{seed},\, n,\, i), \qquad i = 1, \ldots, 34.
The derivation is deterministic, so the key for the next state is always computable before the key for the current state is revealed.

The commitment for state nn is the hash of those secrets’ chain endpoints, as defined in The lock. A client that holds the seed can therefore recompute any past or future commitment, which is what makes the seed sufficient for recovery.

There is no other path

A seed is the only recovery path. There is no admin, no social recovery, no timelock escape and no close_vault. A vault whose commitment nobody holds the preimage for is indistinguishable, on chain, from one whose owner is away, and an instruction that could retire the first could steal from the second.