Shared custody · pallet 19 · byte-exact

No single key holds the treasury

Derive the exact on-chain address of a Quantus multisig from its signers — the real blake2b-256(py/mltsg ‖ signers ‖ threshold ‖ nonce) derivation, straight from Quantus-Network/chain. Price every fee from runtime constants, build byte-exact unsigned payloads for the pallet's seven dispatchables, and track proposals through approval and execution. This page never sees a private key.

PalletMultisig · index 19
Derivationblake2b-256 · sorted signers
Create fee0.03 QTC burned
Proposal deposit0.01 QTC · refunded

01 Vault factory

Add signer addresses. The chain sorts them byte-wise before hashing, so input order never changes the vault address — the nonce does, giving you unlimited fresh vaults from the same member set.

Paste 2–100 addresses. Each is checksum-verified as you type.
2
1 — any one signerN — unanimous
Your vault address appears here once the signers validate.

02 Cost engine

Every figure below is a runtime constant from runtime/src/configs/mod.rs — no estimates, no rounding games.

CostAmountFate
Vault creation0.03 QTCburned
Proposal base fee0.05 QTCburned
Proposal deposit0.01 QTCreturned
Per-signer step+1% of base × Nburned

Proposal fee formula (from the pallet source): base + Permill(1%).mul_floor(base × N). The deposit comes back on execute or cancel; the fees never do. Normal extrinsic length fees apply on top.

03 Call builder

Build the exact inner call, then the exact unsigned payloads for the pallet's dispatchables. Sign them with quantus-cli or your wallet — nothing here signs.

Payloads appear here — inner call, propose, approve, execute, cancel.

04 Proposal board

Track proposals against the real lifecycle — Active → Approved → executed, with expiry blocks and the blake2b-256 call fingerprint. This board lives only in your browser (localStorage); it is not chain state. Verify everything on the block explorer.

05 Security brief

🔒 Vaults are permanent

There is no dissolve or close extrinsic — by design, to kill griefing games around dust balances. Fund a vault only when you intend to keep it. "Closing" a vault means sweeping it out with transfer_all and walking away.

✍️ Approvals bind to the bytes

approve forces each signer to resubmit the proposal's inner call, and the pallet rejects it unless it is byte-equal to the stored payload. A signer always sees exactly what they are approving — the signature covers the call, not an opaque id.

💰 Fees are the spam filter

0.03 QTC burns on creation, ~0.05 QTC burns per proposal, 0.01 QTC reserved per proposal until cleanup. Approving is cheap; proposing is priced. Runaway proposals expire — anyone can then remove_expired, and the proposer reclaims deposits in bulk with claim_deposits.

⏳ Expiry has a ceiling

Proposals live at most 100,800 blocks — about 14 days at 12-second blocks. Pick a window that outlasts your slowest signer but doesn't park deposits forever. Expired proposals can never execute.

🛡️ High-security vaults exist

A vault address can opt into high-security mode, where the pallet enforces a call whitelist — only pre-approved call types may be proposed. Check a vault's mode before proposing anything exotic.

🎲 Nonce = unlimited vaults

Same signers, same threshold, different nonce → different address. Use the nonce to mint fresh vaults per project, per quarter, per counterparty — no address reuse, no collisions, ever.

All claims read from Quantus-Network/chain @ 2026-09-30 — pallets/multisig/src/lib.rs, runtime/src/configs/mod.rs, runtime/src/lib.rs. If the pallet changes upstream, re-verify here first.