Checked on every phone
Your phone checks each payment against the vault’s own keys: recipients, amounts, change and fee. If anything’s off, it won’t sign.

Now on testnet
One private vault for your team. Nothing moves until enough of you approve.
How it works
Anyone in the vault drafts a payment. Nothing moves yet.

Each phone checks the payment on its own. One tap to approve.

Once enough of you approve, it goes. On-chain, it looks like any payment.

Features
Your phone checks each payment against the vault’s own keys: recipients, amounts, change and fee. If anything’s off, it won’t sign.

The phones sign together as one. To the chain it’s an ordinary shielded payment, like this real one from our testnet trial.
Security
Testnet only, for now. Zafe hasn’t been audited yet. Don’t use real funds.
The key is split across your phones and never put together, not even to sign.
Phones talk through a relay that sees who and when. Never amounts, addresses or keys.
Compare
| Feature | Zafe | On-chain multisig | Single-key wallet |
|---|---|---|---|
| Several people must approve | Yes | Yes | No |
| Balances and payments stay private | Yes | No | If shielded |
| Looks like an ordinary payment | Yes | No | Yes |
It’s on testnet and not yet audited. Everything is open source. Don’t use real funds yet.
Yes, just not on-chain. Each phone holds a key share (FROST), and enough shares make one ordinary signature.
Who messages whom, and when. Never amounts, addresses or keys. It can’t sign or move funds.
The vault keeps working while enough members have theirs, and the share comes back from its encrypted backup. Lose too many, and the funds are gone for good.
Not yet. Make a new vault and move the funds.
Android. iPhone later.
More in the spec.