Encrypted messaging for Robinhood Chain wallets

Using HoodChat

Privacy & security

Your words are private. The fact that two wallets talked is not. Here is exactly where that line sits.

Public vs. private

InformationWho can see it
Message textOnly you and the recipient
Sender and recipient wallet addressesAnyone (public on Robinhood Chain)
When a message was sentAnyone
Approximate message lengthAnyone — lengths are padded to 32-byte steps to blur them
Tip amountsAnyone — USDG transfers are public
Your secret keyOnly your browser

Your keys

When you unlock, your wallet signs a fixed message and your browser turns that signature into an encryption key pair. The secret key is kept in this browser’s local storage and is never sent anywhere. Settings → Lock inbox deletes it; signing again re-creates the same key.

Only sign the unlock message on HoodChat

Anyone who gets you to sign the exact HoodChat unlock message can derive your messaging key and read your messages. The message itself says so. Signing it on any other site is a phishing attempt.

Current limits

  • No forward secrecy yet. Keys are long-lived, so if your key ever leaked, past messages could be read too. Rotating keys per conversation is on the roadmap.
  • Messages are permanent. They live on a blockchain and can’t be edited or deleted by anyone.
  • Metadata is public. If the connection between two wallets is sensitive, use a fresh wallet.
  • Not yet audited. The contract and encryption code are small and tested, but haven’t had an independent audit.

Tampering and replay

Every message is authenticated (Poly1305), so any change to the ciphertext makes it fail to open. The sender and recipient addresses are sealed inside the encryption and checked against the on-chain event, so nobody can copy your message and re-send it as their own. Details in Encryption.