Skip to main content

Beneficiary guide

Someone launched a coin and gave you a claim link, or asked you for a payout code, or you launched one yourself. This guide explains how to receive the fees without ever using a public wallet or holding BNB for gas.

Best: give the creator a payout code (your own key)​

If a creator asks where to send the fees before they launch, generate the key yourself, so the creator never holds it:

  1. Open https://zkpad.family/receive and choose Generate my key. The key is created in your browser.
  2. Save your receive kit (download it, or copy the zkkey1.… receive key into a password manager) and tick the confirmation box. It is the only copy.
  3. Send the creator your payout code (zkpay1.…). It contains only a hash of your key and the network, never the key, so any channel is fine.
  4. After the launch, the creator sends you a launch receipt link (…/receive#zkrcpt1.…). It carries the token, your key hash and the fallback they chose, and no key.
  5. Open the receipt link and load your receive kit. The portal opens your account: claim, consolidate and shield as described below. No rotation is needed, because nobody else ever had your key. Your first action registers the account.

Codes are checksummed and versioned: a mistyped or truncated code, a code for another network, or a receipt made for a different payout code is rejected with an explanation.

Use a fresh payout code per launch if you do not want your launches to be linkable to each other once you claim (registering an account reveals its key's address).

If the creator already launched with a claim link, read on.

Keep the claim kit safe​

Your claim link looks like this:

https://zkpad.family/claim#v1.<long-string>
  • Anyone with this link can claim your funds. Treat it like cash or a seed phrase.
  • The secret is in the part after #. Browsers do not send that part to the web server, and the claim page decodes it locally.
  • Do not post it, screenshot it into cloud photo backups, or paste it into chat apps that are not end-to-end encrypted.
  • Open it promptly. The person who made the link holds the same key until the portal rotates it (see below), and before that whoever acts first wins.
  • Beware of phishing: the real claim portal never asks you to send the link anywhere, to connect a wallet that holds funds, or to pay anything up front.

Open the claim portal​

Open the link. The portal:

  1. decodes the key in your browser;
  2. downloads the whole list of beneficiary balances and nonces (the fetch-everything endpoint) and picks out yours locally, so no server or public RPC learns which account you are looking at;
  3. shows your balance per asset and your account status.

Do not paste your claim link or key into the site's search boxes; they clear it instead of searching, but other sites may not.

For better network privacy, open the portal through Tor Browser or a trusted VPN.

Rotate your key​

The creator generated the key in your claim link, so they hold it too. The portal rotates it for you, before anything else: the creator's copy then cannot claim, consolidate, register templates or ping, and cannot see what you do next.

  1. The first time you open a claim link whose key still controls the account, the portal shows Secure this claim link first. It has already generated a new key in your browser and shows it as a new claim kit.
  2. Save the new kit (download, copy or store it encrypted) and tick I saved the NEW claim kit. Until you do, every action is blocked.
  3. Then either choose Rotate now, or just go ahead with your first action (a claim, a consolidation, templates or a ping). Either way, the old key signs a RotateOwner message and the new key signs everything after it, in one relayed transaction. The relayer fee is paid from the vault balance; you never need BNB. With Rotate now you pay one extra relayer fee.
  4. From then on, only the new kit works. The link you opened is useless.
  5. Any unused shield templates are discarded (the old key authorised them). Register new ones with the new kit if you want the creator to be able to shield for you.

If the portal says This claim link was already used, the account's key was already rotated away from the link. If you did it yourself (on another device, say), open your newest claim kit. If you did not, someone else holding the link (the creator, or anyone they shared it with) got there first and may have claimed: contact the creator. The portal tells this from the public account index it already downloads; it makes no extra request about your account.

If the portal notes that the link's key already signed actions, check the activity: the creator's fallback registration signs one ping, anything else was done by someone holding the link.

A rotation also needs a balance to pay the relayer fee from. If the account has received nothing yet, there is nothing to claim either; open the link again once fees arrive.

Rotate again (Key tab, Rotate key) whenever you think your kit may have been exposed.

Consolidate into USDT​

If your balance is in several assets (WBNB, BTCB, the coin itself...), you can convert any of them into USDT, the asset used for private withdrawals.

  1. Choose Consolidate to USDT for an asset.
  2. The portal prices it from oracle quotes for one whole unit of every configured quote token (the same request for every visitor, so the RPC learns neither your balance nor which asset you hold) and computes a minimum output from your slippage setting.
  3. You sign a Consolidate message with that minOut and the relayer's fee claim. If the swap would return less, it fails. Whole-balance consolidations are signed in the vault's full-balance form, so a creator consolidation landing just before yours cannot make it fail.

The creator of the coin may also trigger consolidation for you, but only of the fees its own launch credited. Their trigger is bounded by an oracle price, and they can never choose where the funds go.

Withdraw​

Choose an asset, an amount and a destination.

This sends USDT into a private Railgun balance.

  1. Have a Railgun wallet (for example Railway) and your 0zk address.
  2. Paste the 0zk address. The portal builds the shield data in your browser.
  3. Sign the claim. The relayer submits it and takes its fee from the claimed USDT.
  4. Railgun deducts its 0.25% shield fee.
  5. Your Railgun wallet shows the funds as pending for about 1 hour (the PPOI standby). That is normal.

Tips: do not unshield the exact amount you just shielded, wait before moving funds, and split large amounts. See the anonymity-set caveats.

Direct to a fresh address​

Send any asset to any address. Use a brand-new address that has never been linked to you. WBNB can be delivered as native BNB.

The relayer fee​

The portal shows a quote from the relayer before you sign. The fee is paid in the asset you claim, so you never need BNB. Other actions (consolidate, rotate, ping, templates) pay the relayer the same way, with a small fee-only claim you sign alongside them. You can switch relayers, or submit the claim yourself from any address.

Withdrawing a whole balance signs the vault's full-balance amount, so it still goes through if the balance changed slightly before the relayer submitted it.

Pre-register shield templates​

Shield templates let the coin's creator consolidate and shield your fees for you, to your Railgun wallet, without you doing anything at that moment.

  1. Choose Pre-register Railgun shield templates.
  2. Enter your 0zk address and how many templates to create. The portal generates a fresh, single-use shield request for each one.
  3. Sign one RegisterShieldTemplates message (plus the relayer's fee claim). A relayer submits it.

Each template is used once. When they run out, creator-triggered consolidations leave USDT in the vault until you claim or register more.

To discard unused templates (for example after changing Railgun wallets), use Discard unused templates. Your claim key signs ClearShieldTemplates, but the relayer has no endpoint for it, so the transaction is sent from a wallet you connect, which then shows up publicly as its sender: use a fresh wallet with a little BNB. A rotation discards templates automatically and is relayed.

Stay active (inactivity and fallback)​

If the creator set a fallback recipient (for example a charity), your balance can be swept there after a long period with no activity from you: at least 180 days, possibly longer. The portal shows the fallback address and the date it becomes possible.

Any signed action counts as activity: a claim, a consolidation, a template registration, a rotation, or a Ping. A ping does nothing except reset the clock; its only cost is the relayer's small fee, taken from your balance. Fee deposits from trading and creator-triggered consolidations do not count.

If something goes wrong​

ProblemWhat to do
The relayer is down or refusesTry another relayer, or submit the signed transaction yourself from any address
Railgun refused a shieldThe funds return to your per-account shield proxy; anyone can call recredit to put them back in your vault balance. Then claim directly or try again.
You lost the claim linkIf you rotated and lost the new kit too, the funds cannot be recovered (except by the fallback). For social escrows, you can rebind.
Someone else has your linkOpen it and rotate immediately (the portal asks you to). Whoever rotates or claims first wins.
"This claim link was already used"Someone rotated the key away from the link. Open your newest kit, or contact the creator.