Social escrow guide
If a coin was launched for your X, GitHub, Telegram, Farcaster or Discord account, the fees are waiting in an escrow that only you, the account owner, can claim. Background: social-account escrows.
Social-account beneficiaries are not available at launch. No attestors are registered on the
mainnet FeeVault (attestorThreshold = 0) and the attestor service is not running, so binding
reverts and nobody can claim an escrow yet. The launch app shows social-account beneficiaries as
"coming soon". Fees already credited to an escrow id stay in the vault, but that is not a
guarantee you can claim them later:
- An escrow can only ever be bound if its handle commitment used a real
attestorSaltfrom the attestor salt service, which is not running. Do not create social-account escrows through the SDK or the contracts directly until it is. - If the escrow has a fallback recipient, its fallback clock keeps running while nothing can be
bound. Once its fallback delay has passed (at least 180 days after the escrow was registered or
first credited), anyone can call
sweepToFallbackand send the whole balance to the fallback recipient. After that the account owner can no longer claim it.
This guide describes the flow as it will work once attestors are live.
Anyone can launch a coin "for" you without asking. A coin's escrow does not mean you endorse it, and you are under no obligation to claim or promote it.
How the creator named your account
The creator either typed your account's numeric user ID (free) or had an attestor look up your handle for a small x402 payment ($0.03 USDT on BNB Smart Chain, same price on X, GitHub and Farcaster). Either way the escrow commits to your numeric ID, so renaming your handle does not affect it. The lookup payment shows on chain that the creator's wallet paid for a handle-based escrow; it does not name the platform or your handle.
What you need
- Access to the platform account (you will log in with it). For Farcaster: the Farcaster app on your phone, signed in to the account (it signs with the account's custody or auth address).
- A device you trust. Tor Browser is recommended.
- Time: binding includes a waiting period (the timelock) of 1 to 30 days, set by the protocol.
Bind your account
- Open the bind portal and pick the platform.
- A fresh stealth key is generated in your browser. It will control the escrow. Save the claim kit it shows you now.
- Log in once per attestor. The portal sends you to each of the k attestors in turn, and you
approve a read-only login each time. Each login is tied to your new key on the attestor's
side (the key and escrow ids are sent in a request body, never in a URL), so nobody can reuse
it for a different key.
- X: OAuth 2.0 with minimal read scopes; the token is revoked right after your user id is read.
- GitHub: a GitHub OAuth app.
- Telegram: the Telegram login widget.
- Discord: "Sign in with Discord" (OAuth 2.0 with PKCE). The attestor asks only for the
identifyscope, reads your permanent user id (not your username) and revokes the token right away. - Farcaster: "Sign in with Farcaster". Each attestor shows a QR code (or an "Open in Farcaster" link on the phone). Scan it, check that the request is for this site, and approve. Your Farcaster app signs a one-time message that names that attestor's request, so the signature cannot be reused for another key. The attestor checks on Optimism that the signer controls your fid (custody address or an auth address). The request passes through the Farcaster relay, which sees your fid.
- Submit the bind. The portal picks one signature deadline, collects every attestor's
signature for it, and a relayer calls
proposeBind. You pay nothing. Escrow coins are not prefetched in the background, so the web host does not learn which escrows you own. - Wait for the timelock. The portal shows a countdown. During this time attestors or the guardian can veto a bind they believe is fraudulent.
- Finalize. After the countdown, anyone (normally the relayer) calls
finalizeBind. The escrow is now controlled by your key.
From here on, follow the beneficiary guide: consolidate, shield to Railgun, register shield templates, and ping now and then.
A Farcaster escrow is tied to your fid, not your username. If the fid is transferred, or recovered to another address by its recovery address, the new controller can bind the escrow. Bind soon after a coin is launched for you, keep your recovery address safe, and if your fid is taken over, contest the bind during the timelock (below).
Lost your key?
If you lose the stealth key after binding, bind again with the same platform account:
- the waiting period is twice as long;
- if someone else holds the old key, they can cancel the rebind with a signed
CancelBind, and the dispute must be resolved by the attestors and guardian; - when the rebind is finalized, any shield templates registered with the old key are discarded.
If someone else tries to bind your account
If your account was hijacked and someone starts a bind, you have the timelock to react:
- Recover your platform account.
- Log in to the bind portal again. It shows that a bind to another key is pending. That may be your own bind from an earlier visit (the portal makes a fresh key on each visit), so it asks you first. If you confirm, it contests that one escrow: each attestor revokes its other attestations for it and, where vetoes are enabled, vetoes the pending bind. Escrows are contested one at a time, so a contest never publicly groups your escrows together.
- Contact the attestors and the guardian through the channels listed in the app.
A veto never moves funds. It only clears the pending bind, and it keeps any fallback sweep closed for at least twice the bind delay, so you have time to bind again.
What the attestors know
Each attestor can decrypt the launch hint on its own (hints are not threshold-encrypted), so every one of them knows which account an escrow is for, and each sees your login. They never hold your key and cannot claim on their own: a bind needs k of them, and it is public and vetoable during the timelock.