One passkey. Unlinkable on-chain identities. Every app gets its own USDG account and ID on Arbitrum; each approval is a ZK proof made in the browser, so nothing on-chain links them.



VeraKey is Hide-My-Email for wallets: one passkey, unlinkable on-chain identities on Arbitrum.
The problem: cross-app wallets turn one passkey into one global ID. Every passkey smart account we inspected stores or emits the passkey's public key on-chain, so every app a person uses can be tied to the same key.
What VeraKey does: every app gets its own USDG account and ID behind a single passkey, with payments, sign-in and recovery built in. Each approval is a zero-knowledge proof (Noir, UltraHonk) made in the browser, in about 2 seconds on desktop Chrome. The chain learns that the passkey approved exactly this action, but never sees the passkey's public key or signature: the account stores a per-app nullifier instead, so nothing on-chain links a person's accounts. Unlinkable, not anonymous: amounts and recipients stay public, and USDG's issuer can still freeze any account.
What is built, and where it runs:
• Per-app smart accounts in Rust on Arbitrum Stylus: per-payment and daily caps, a cap on first payments to new recipients, an instant freeze, timelocked changes, a guardian nobody can see, and optionally the browser's payment sheet. Deployed on Arbitrum Sepolia.
• Gasless USDG payments through a relayer that can only submit what the passkey approved and takes a capped fee. Live on Arbitrum Sepolia at verakey.xyz: after the 29 September redeploy, the integration kit's end-to-end test (headless Chrome, a virtual passkey) signed a player in through the live popup and paid 1 USDG (tx 0xa7e1…25c5). The first USDG payment on Arbitrum Sepolia, approved with a passkey on an iPhone, was on an earlier deployment (tx 0x81c5…f797). Also tested end to end with real proofs on a local Arbitrum Nitro devnode.
• Sign in with VeraKey, live on Arbitrum Sepolia: any https site signs people in through VeraKey's popup, gets its own ID for each person, and verifies a proof of every sign-in on its server.
• Disclosures: prove to an auditor that two accounts share a passkey, without revealing the key. The verifier is deployed on Arbitrum Sepolia.
• An ERC-7579 validator module for modular smart accounts such as Kernel and Nexus, tested with real proofs and deployed on Arbitrum Sepolia. It is the root validator of a ZeroDev Kernel v3.3 account there: built with ZeroDev's SDK and @verakey/sdk/kernel, its first user operation deployed it and paid 1 USDG with a passkey proof (tx 0x0f61…2fc3).
• @verakey/sdk 0.2.3 on npm, with an integration kit that adds Sign in with VeraKey and USDG payments to a React site with a Node server in about ten lines, with sessions that signing out revokes everywhere. It also keeps one passkey on one identity in a browser: if a password manager returns a different PRF secret through another route, such as a phone's QR code, VeraKey refuses the unlock instead of opening other accounts. Documentation at verakey.xyz/docs, and the app at verakey.xyz.
Security: two internal Nemesis audits. The first, of the contracts, found 1 high, 1 medium and 4 low-severity issues; the second, on 29 September, covered the whole system (contracts, relayer, SDK, popup) and found 2 medium and 4 low. All are fixed, each with a regression test, and the contracts were redeployed. The circuits and contracts have not had an independent audit, so VeraKey is testnet only.
Everything in the repository was built during the Buildathon (see the public git history at github.com/nnovida/veraKey):
• Two Noir circuits, one for WebAuthn P-256 approvals and one for consent-to-link disclosures, with UltraHonk verifiers. Moving to bb 5.2.0's optimized verifier cut a payment from 4.17M to 1.07M gas; packed storage and cached programs then brought it to 1.02M.
• The Stylus account and factory in Rust, the relayer, and the ERC-7579 validator module in Solidity.
• The web app, a 31-page documentation site, Sign in with VeraKey (popup and SDK), and @verakey/sdk on npm (0.2.3: a React and server integration kit with revocable sessions, a ZeroDev Kernel plugin, and a guard that keeps one passkey on one identity).
• 87 end-to-end tests with real proofs on a Nitro devnode, 138 SDK unit tests, and two internal audits, of the contracts and of the whole system, whose 12 findings are all fixed and redeployed to Arbitrum Sepolia.
Before the Buildathon: only the first version of the landing page and its Vite/Express scaffold. Our earlier repo adiitsuu-ui/arbitrum-nexus is a separate project with no shared files.
Not raised; self-funded so far. We are applying for an Arbitrum grant to take VeraKey to Arbitrum One: an independent audit of the circuits and contracts, proving on phones, and developer access so other apps can run VeraKey accounts.