01 / STEALTH ADDR
Pay any wallet
Drop a 0x, ENS, or Solana key. Amount is sealed client-side. The chain only sees a proof and a settlement event.
Next-gen on-chain settlement. Private payments, QR rails, encrypted gift vaults. Strip the noise. Keep the signal. Pay anyone, anywhere — sealed.
00 / PROTOCOL
Every transfer is a sealed packet. Metadata is minimized. Memos are encrypted. The public ledger records settlement — not your social graph.
01 / STEALTH ADDR
Drop a 0x, ENS, or Solana key. Amount is sealed client-side. The chain only sees a proof and a settlement event.
02 / QR RAIL
Point-of-sale without exposing payer identity. One rotating QR, one-shot proofs, instant confirmation pulse.
03 / GIFT VAULTS
Mint an encrypted gift card. Share the claim glyph. Recipient redeems to any address they choose.
01 / SETTLE
Route value through a unified node. Native coins, stables, L2s. One proof format. One confirmation pulse. Destination can be a wallet, a merchant QR, or a gift vault.
02 / QR RAIL
Merchants render a living QR. Payers scan, prove, settle. No account linking. No shared email. Optional encrypted invoice memo rides inside the proof, not on the public log.
TPAY://QR/7F-C3-A1
03 / GIFT VAULTS
Issue a prepaid glyph. Print it, beam it, or drop it in chat. Whoever holds the claim secret can redeem on-chain — to their own rail, not yours.
04 / STACK
Groth16 / Halo2 proofs bind amount + destination without leaking the payer graph.
One-time addresses derived per invoice. Reuse detection is treated as a fault.
EVM, Solana, Bitcoin taproot notes in one SDK. Same client API.
Secrets never leave the device. Relayers only see sealed blobs.
import { TornadoPay } from "@tornadopay/sdk";
const pay = new TornadoPay({ endpoint: "wss://node.tornadopay.io" });
const invoice = await pay.qr.create({ asset: "USDC", amount: "24.00" });
await pay.gift.mint({ asset: "ETH", amount: "0.05", label: "ops" });