Paper wallet for Hush, which you can use with no internet access while wearing a tinfoil hat inside of a Faraday cage.
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

83 lines
4.3 KiB

# hushpaperwallet
hushpaperwallet is a paper wallet generator that can run completely offline.
You can run it on an air-gapped computer to generate your shielded z-addresses, which will allow you to keep your keys completely offline.
5 years ago
5 years ago
*Example:*
![screenshot](hushpaperwallet.png?raw=true)
5 years ago
5 years ago
# Download
hushpaperwallet is available as pre-built binaries from our [release page](https://github.com/MyHush/hushpaperwallet/releases). Download the zip file for your platform, extract it and run the `./hushpaperwallet` binary.
5 years ago
# Generating wallets
To generate a Hush paper wallet, simply run `./hushpaperwallet`
5 years ago
You'll be asked to type some random characters that will add entropy to the random number generator. Run with `--help` to see all options
## Saving as PDFs
To generate a Hush paper wallet and save it as a PDF, run
`./hushpaperwallet -z 3 --format pdf hushpaper-output.pdf`
5 years ago
This will generate 3 shielded z-addresses and their corresponding private keys, and save them in a PDF file called `hushpaper-output.pdf`
5 years ago
5 years ago
## Vanity Addresses
You can generate a "vanity address" (that is, an address starting with a given prefix) by specifying a `--vanity` argument with the prefix you want.
Note that generating vanity addresses with a prefix longer than 4-5 characters is computationally expensive. You can run it on multiple CPUs on your computer by specifying the `--threads` option.
5 years ago
# Compiling from Source
hushpaperwallet is built with rust. To compile from source, you [install Rust](https://www.rust-lang.org/tools/install). Basically, you need to:
5 years ago
```
curl https://sh.rustup.rs -sSf | sh
```
Checkout the hushpaperwallet repository and build the CLI
5 years ago
```
git clone https://github.com/MyHush/hushpaperwallet.git
cd hushpaperwallet/cli
5 years ago
cargo build --release
```
5 years ago
The binary is available in the `target/release` folder.
5 years ago
5 years ago
## Ensuring Security
When generating paper wallets that will store large amounts of crypto, please take special care to ensure the keys are generated and kept completely offline.
1. `hushpaperwallet` supports ARMv8 (Raspberry Pi 3+). You can put one in a Faraday cage along with a printer, and print out the PDFs securely.
2. Please ensure you supply random entropy when you run `hushpaperwallet`. Your entropy is mixed in with system-provided entropy to generate keys
5 years ago
3. If you can, run with `unshare`, which will disable all network interfaces to a process, providing you with an additional layer of safety. (See next section)
4. After you've generated the keys, you can tear off the Address potion of the wallet and take it to your online computer/phone to send the address funds. Please always keep the private key offline.
5. When you're ready to spend the cold storage keys, import the private key into a full node, then don't re-use the key again.
### Run without network
If you are running a newish version of Linux, you can be doubly sure that the process is not contacting the network by running hushpaperwallet without the network namespace.
5 years ago
```
sudo unshare -n ./target/release/hushpaperwallet
5 years ago
```
`unshare -n` runs the process without a network interface which means you can be sure that your data is not being sent across the network.
5 years ago
## Help options
```
USAGE:
hushpaperwallet [FLAGS] [OPTIONS] [output]
5 years ago
FLAGS:
-h, --help Prints help information
-n, --nohd Don't reuse HD keys. Normally, hushpaperwallet will use the same HD key to derive multiple
5 years ago
addresses. This flag will use a new seed for each address
5 years ago
--testnet Generate Testnet addresses
5 years ago
-V, --version Prints version information
OPTIONS:
5 years ago
-e, --entropy <entropy> Provide additional entropy to the random number generator. Any random string,
containing 32-64 characters
5 years ago
-f, --format <FORMAT> What format to generate the output in [default: json] [possible values: pdf, json]
5 years ago
-t, --taddrs <t_addresses> Numbe rof T addresses to generate [default: 0]
5 years ago
--threads <threads> Number of threads to use for the vanity address generator. Set this to the number of
CPUs you have [default: 1]
--vanity <vanity> Generate a vanity address with the given prefix
5 years ago
-z, --zaddrs <z_addresses> Number of Z addresses (Sapling) to generate [default: 1]
ARGS:
<output> Name of output file.
```