Privacy
ordinals / runes.
Send an inscription or a rune balance to someone's sp1 wallet. The sats land in a one-time taproot output that only they can find, so the collection stays off the public map of who owns what.
Carries the ordinal (sat #) or the rune balance
Pays network fees and postage
Decode sp1q… into the recipient's scan key B_scan and spend key B_spend.
ecdh = a · B_scan, where a is the sum of the sender's input private keys and the input hash.
P = B_spend + hash(ecdh ‖ 0) · G. Output 0 pays P2TR(P) with the inscription sats, or the rune edict points at it.
Unisat or Xverse signs all inputs. The chain sees an ordinary taproot transfer.
Fresh key derived from the recipient's sp1 address. Nothing on chain links it to them.
Edict: move the rune balance to output 0. Only for runes.
Back to the sender's payment wallet
Their private wallet scans block tweaks with the scan key and recognises output 0 without ever revealing the key to a server.
The inscribed sat travels at offset 0 of output 0. Coin selection never spends inscription UTXOs as fees.
No address reuse, no on-chain hint of the sp1 wallet. Explorers see a fresh bc1p… output like any other taproot spend.
- bech32m, version 0, scan key ‖ spend key (66 bytes)
- Shared like a domain name; reusable forever
- Never appears on chain
- P = B_spend + hash(ecdh ‖ k)·G, unique per payment
- Holds the inscription or rune balance
- Only the recipient can recognise or spend it
- Your Unisat or Xverse account (P2WPKH or P2TR)
- Public alias target behind your sp1 wallet today
- Funds fees, receives change
- Derived from one wallet signature at m/352'
- Scans block tweaks to find one-time outputs
- Spends them with the tweaked spend key
Privacy ordinals and runes
Phase 2 unlocks the private wallet: scanning, inscription-aware coin selection, and sending ordinals or runes to any sp1 wallet. The wallet page already derives your keys; the rest follows.