No single key holds the treasury
Derive the exact on-chain address of a Quantus multisig from its signers —
the real blake2b-256(py/mltsg ‖ signers ‖ threshold ‖ nonce) derivation,
straight from Quantus-Network/chain. Price every fee from runtime constants,
build byte-exact unsigned payloads for the pallet's seven dispatchables, and track
proposals through approval and execution. This page never sees a private key.
01 Vault factory
Add signer addresses. The chain sorts them byte-wise before hashing, so input order never changes the vault address — the nonce does, giving you unlimited fresh vaults from the same member set.
02 Cost engine
Every figure below is a runtime constant from
runtime/src/configs/mod.rs — no estimates, no rounding games.
| Cost | Amount | Fate |
|---|---|---|
| Vault creation | 0.03 QTC | burned |
| Proposal base fee | 0.05 QTC | burned |
| Proposal deposit | 0.01 QTC | returned |
| Per-signer step | +1% of base × N | burned |
Proposal fee formula (from the pallet source):
base + Permill(1%).mul_floor(base × N). The deposit comes back on execute
or cancel; the fees never do. Normal extrinsic length fees apply on top.
03 Call builder
Build the exact inner call, then the exact unsigned payloads for the pallet's
dispatchables. Sign them with quantus-cli or your wallet — nothing here signs.
04 Proposal board
Track proposals against the real lifecycle — Active → Approved → executed, with expiry blocks and the blake2b-256 call fingerprint. This board lives only in your browser (localStorage); it is not chain state. Verify everything on the block explorer.
05 Security brief
🔒 Vaults are permanent
There is no dissolve or close extrinsic — by design, to kill griefing games around
dust balances. Fund a vault only when you intend to keep it. "Closing" a vault means
sweeping it out with transfer_all and walking away.
✍️ Approvals bind to the bytes
approve forces each signer to resubmit the proposal's inner call, and the
pallet rejects it unless it is byte-equal to the stored payload. A signer always
sees exactly what they are approving — the signature covers the call, not an opaque id.
💰 Fees are the spam filter
0.03 QTC burns on creation, ~0.05 QTC burns per proposal, 0.01 QTC reserved per proposal
until cleanup. Approving is cheap; proposing is priced. Runaway proposals expire —
anyone can then remove_expired, and the proposer reclaims deposits in bulk
with claim_deposits.
⏳ Expiry has a ceiling
Proposals live at most 100,800 blocks — about 14 days at 12-second blocks. Pick a window that outlasts your slowest signer but doesn't park deposits forever. Expired proposals can never execute.
🛡️ High-security vaults exist
A vault address can opt into high-security mode, where the pallet enforces a call whitelist — only pre-approved call types may be proposed. Check a vault's mode before proposing anything exotic.
🎲 Nonce = unlimited vaults
Same signers, same threshold, different nonce → different address. Use the nonce to mint fresh vaults per project, per quarter, per counterparty — no address reuse, no collisions, ever.
All claims read from Quantus-Network/chain @ 2026-09-30 —
pallets/multisig/src/lib.rs, runtime/src/configs/mod.rs,
runtime/src/lib.rs. If the pallet changes upstream, re-verify here first.