Devnet prototype · two phones, one escrow
Alice locks SOL in escrow, signs a voucher with no internet, Bob settles it later. Replay-protected. Self-custody. Real devnet transactions — not a mock.
How it works
Bluetooth in this demo is simulated in-browser. Signing and settle are real.
Alice locks SOL into a PDA. Funds stay hers until a signed voucher is settled.
No RPC. The phone still holds the escrow key and can sign locally.
An 84-byte message names payee, amount, and nonce. Ed25519, not a transaction.
Bob (or any relayer) submits verify + settle. Receipt PDA blocks replay.
After expiry, leftover SOL and rent return to Alice.
Architecture
The program never sees Bluetooth. It only sees an Ed25519 verify ix, then settle.
escrow ← ["escrow", authority, seed]
receipt ← ["receipt", escrow, nonce] — init makes replay fail.
MORAescrow 32nonce 8payee 32amount 8
Signer must be escrow.authority. Payee is in the bytes, not a settle signer.
Ix 0: Ed25519 native (self-contained). Ix 1: settle reads instructions sysvar, checks previous ix.
BT bus is BroadcastChannel. Hash chain lives in localStorage. Neither is in the program.
(authority, seed). Real create_escrow."MORA" | escrow | nonce | payee | amount, Ed25519 locally. No RPC.settle. Receipt PDA makes the nonce unreplayable.close_escrow returns rent + remainder.