Using HoodChat
Privacy & security
Your words are private. The fact that two wallets talked is not. Here is exactly where that line sits.
Public vs. private
| Information | Who can see it |
|---|---|
| Message text | Only you and the recipient |
| Sender and recipient wallet addresses | Anyone (public on Robinhood Chain) |
| When a message was sent | Anyone |
| Approximate message length | Anyone — lengths are padded to 32-byte steps to blur them |
| Tip amounts | Anyone — USDG transfers are public |
| Your secret key | Only your browser |
Your keys
When you unlock, your wallet signs a fixed message and your browser turns that signature into an encryption key pair. The secret key is kept in this browser’s local storage and is never sent anywhere. Settings → Lock inbox deletes it; signing again re-creates the same key.
Only sign the unlock message on HoodChat
Anyone who gets you to sign the exact HoodChat unlock message can derive your messaging key and read your messages. The message itself says so. Signing it on any other site is a phishing attempt.
Current limits
- No forward secrecy yet. Keys are long-lived, so if your key ever leaked, past messages could be read too. Rotating keys per conversation is on the roadmap.
- Messages are permanent. They live on a blockchain and can’t be edited or deleted by anyone.
- Metadata is public. If the connection between two wallets is sensitive, use a fresh wallet.
- Not yet audited. The contract and encryption code are small and tested, but haven’t had an independent audit.
Tampering and replay
Every message is authenticated (Poly1305), so any change to the ciphertext makes it fail to open. The sender and recipient addresses are sealed inside the encryption and checked against the on-chain event, so nobody can copy your message and re-send it as their own. Details in Encryption.