THE UNSEEN
ARCHIVE PROTOCOL TOKENOMICS ROADMAP CLAIM DEAD DROP
BEING BUILT · OPEN SOURCE · NOT IN STORES · NOTHING TO DOWNLOAD
THE UNSEEN // PRODUCT DOCUMENT 0.1

DEAD DROP

An open-source wallet whose keys can stay offline. Sign on a quiet phone. Carry the packet by QR. The last device that is online broadcasts it. Being built. Not in stores.

NAME · DEAD DROP BUILDING OPEN SOURCE · MIT ANDROID GRAPHENEOS ROBINHOOD CHAIN FIRST

What it is

DEAD DROP is the wallet. It is not a Chrome extension and it does not connect to MetaMask. Maya’s keys live in the app, on a phone that can stay off the network.

THE UNSEEN is the Archive and the 1,111 AI KEYS. DEAD DROP is the courier. A Key is not a ticket into the app. ETH stays on chain in her address. We never hold her coins.

IT IS
  • An air-gapped signer for ETH
  • A QR courier for the signed hop
  • A last hop that may be another person
  • Open source (MIT)
  • Android and GrapheneOS
IT IS NOT
  • Bitkey — that is Bitcoin 2-of-3
  • Bitchat — that is Bluetooth chat
  • A shield or UNSEEN STATUS
  • A store listing today
  • iOS in v1
HONEST SCOPE
AirGap already does spare-phone + QR + a hot app for ETH. DEAD DROP is the same class. What we treat as the product: the hop can be Leo, the packet says it is not money yet, Robinhood gas is dust, the source is public.

Who uses it

Two jobs, so two kinds of people. Neither needs a Key.

ROLEWHOSEED?INTERNET?
SIGNER Maya — holds the ETH Yes, on the quiet phone Off while signing
HOP Leo, or Maya’s other phone Never On, to broadcast
PAYEE Whoever should receive the ETH No Not required

Two devices

The quiet phone never needs a tower to sign. The loud phone (or Leo) never needs the seed to publish.

Signer phone and hop phone Left: dark phone labelled SIGNER, radio off. Right: lighter phone labelled HOP, online. A QR sits between them. FIGURE 01 — ROLES RADIO OFF SIGN 0.05 ETH → LEO MAYA · SIGNER SIGNED PACKET ONLINE BROADCAST NO SEED LEO · HOP
FIG. 01 — Maya signs in the dark. Leo only carries the packet. The QR is the drop.

Example: Maya pays Leo 0.05 ETH

Maya is in a basement, radio off. She wants to send 0.05 ETH to Leo. Leo is upstairs with normal internet. She does not deposit ETH “into” DEAD DROP. The 0.05 already sits on chain in her address — she funded it earlier from an exchange or MetaMask, as a normal transfer to her.

Five steps from fund to paid FIGURE 02 — ONE SEND 01 FUND ETH → Maya her address 02 BUILD to · 0.05 nonce · gas cap 03 SIGN quiet phone not paid yet 04 CARRY QR to Leo seed stays 05 BROADCAST Leo is online NOW it pays
FIG. 02 — Until step 05, Leo should not treat 0.05 as received. Signed is not paid.
  1. Maya’s DEAD DROP already shows a balance (funded earlier).
  2. A send is built: to Leo, 0.05 ETH, fee cap.
  3. Maya signs. Still no internet on that phone. Chain has not moved.
  4. She shows a QR. Leo scans. He holds bytes, not a seed.
  5. Leo broadcasts. Now 0.05 ETH is his.
IF LEO IS ALSO OFFLINE
He keeps the QR. When he (or any hop holding it) is back online, he broadcasts the same signed bytes. He cannot change gas. If Robinhood fees are still under Maya’s cap, it lands. If not, DEAD DROP refuses a dead QR and Maya signs once more.

Gas on Robinhood Chain

A plain ETH send is about 21,000 gas whether Maya sends 0.05 or 10,000 ETH. On Robinhood that is dust — on the order of 0.00002 ETH, not a percent of the bag. Keeping 0.01 ETH extra for fees is enormous headroom.

Value and gas are two separate bills FIGURE 03 — TWO BILLS VALUE · WHAT LEO GETS 0.05 ETH GAS · PAID BY MAYA ~0.00002 ETH THE CHAIN DOES NOT SUBTRACT GAS FROM THE 0.05
FIG. 03 — If she wants Leo to receive exactly 0.05, she holds 0.05 plus dust for gas. “Send max” is the other option: Leo gets slightly less.

Packet states (v1)

Packet lifecycle FIGURE 04 — STATES UNSIGNED SIGNED CARRIED BROADCAST CONFIRMED TTL ON THE QR · REFUSE IF THE CAP IS DEAD · LEO CANNOT REWRITE GAS
FIG. 04 — v1: fat fee cap + time-to-live + refuse a stale QR. Fee ladder and intent-and-fill are later, not this document as live.
V1
Fat cap + TTL. Maya authorizes a high max fee. On Robinhood that is still cheap. The hop refuses a packet that will not land.
LATER
Fee ladder. Same nonce, three signed caps. Hop picks the cheapest that works. Still no new Maya scan.
LATER
Intent-and-fill. Maya signs “pay Leo 0.05, valid until…”. The hop wraps live gas. Needs a contract. Not v1.

Android and GrapheneOS

v1 is Android. GrapheneOS on a Pixel is the intended house for the signer: sideload the APK, deny network to the app (or keep the radio off). The hop can be stock Android with internet.

SURFACEV1NOTE
ANDROIDYesSigner and hop
GRAPHENEOSYesFirst-class for the quiet phone. Sideload. Not a GrapheneOS product — we run on it.
iOSNoNot v1
EXTENSIONNoDEAD DROP is the wallet, not a plugin

Open source

License: MIT. When the app exists, the repository is public. Reproducible Android builds. GrapheneOS install notes in the README.

Public: apps, QR format, TTL rules, how the hop broadcasts. Never in git: seeds, mint-proceeds keys, anything that can spend.

Funded from mint proceeds after sell-out (0.006 ETH × 1,111). Treasury 8% stays holder stock tokens. Tokenomics do not change. There is nothing to download today.