Quantus mainnet · ReversibleTransfers pallet · verified against upstream source 2026-09-29
Send it like it matters
Quantus is the chain where a transfer can be un-sent. Attach a delay window, and the sender can cancel before the coins move. Verify any address with the real upstream checkphrase algorithm. Learn the high-security account system — the one-way vault with a guardian. Nothing here moves real funds: the transfer lab is a clearly-labeled simulation, the verifier runs the actual algorithm.
🔏 Checkphrase Verifier
Paste any address and this page derives its human checkphrase with the actual upstream algorithm — PBKDF2-HMAC-SHA256, 40,000 iterations, salt "human-readable-checksum", five 11-bit words from the 2,048-word list — validated byte-for-byte against all 1,171 upstream test vectors. 100% client-side; your address never leaves this tab.
Deriving…
Tip: an address doesn't need to be yours — try any qz… address from the Block Explorer or Address Toolkit.
Five friendly words, cryptographically bound to the address. Read them to the recipient — if they don't match their address, stop.
One character of the address was changed (highlighted). The checkphrase is completely different — that's the point. Attackers generate lookalike addresses hoping you won't notice; the phrase makes the swap obvious.
How the algorithm works (and the 50k vs 40k footnote)
- The address string is UTF-8 encoded and fed to PBKDF2-HMAC-SHA256 with salt
"human-readable-checksum"and 40,000 iterations, producing a 7-byte key. - The first 55 bits of that key are split into five 11-bit indices (211 = 2,048) into the curated positive wordlist.
- The 40k-iteration KDF is what makes rainbow tables ~50,000× more expensive than a plain hash — an attacker can't cheaply grind vanity phrases.
- Footnote: the upstream safety deep-dive describes a 50,000-iteration KDF as the design parameter; the shipped reference implementation and all 1,171 test vectors use 40,000. This tool follows the implementation, and its output matches the test vectors exactly.
⏳ Reversible Transfer Lab Simulation
This is an interactive simulation of the ReversibleTransfers::schedule_transfer_with_delay flow — no real QTC moves. Pick an amount and a delay window, watch the scheduled transfer ride the countdown, then cancel it (like a fat-fingered send) or let it execute. The right rail shows what each step means on mainnet.
Schedule a transfer
Demo clock: 1 second = 1 block, so you can watch a full window in a coffee break. Real wall-clock times are shown in the rail.
Live transfer
Fill in the form and schedule your first reversible transfer.
qzk…On mainnet, each step means
schedule_transfer_with_delay- Sender calls with
dest,amount, anddelay(blocks or ms). Funds move into the pallet's escrow hold — not yet credited to the recipient. Atx_idis emitted in the block's events. - In-block → scheduled
- Wallets show a countdown; the recipient sees an incoming-but-not-final transfer. Cancellation is a second extrinsic:
cancel(tx_id). - Cancel (sender)
- For a one-time transfer the sender cancels free: the full held amount returns — no reversal fee, only the cancel extrinsic's network fee.
- Delay expires
- The Scheduler pallet auto-executes the transfer to the recipient. Uses
transfer_allow_deathso it can't get stuck. - Your chosen delay
- 7,200 blocks ≈ 24 h on mainnet (12 s blocks). Below the 2-block runtime minimum is rejected by the chain.
🔐 High-Security Accounts
Reversibility as a lifestyle: opt an account into high-security mode and every outgoing transfer carries a mandatory delay — plus a guardian who can cancel suspicious transfers or sweep the whole account. The catch that matters: it's one-way. Once enabled, the account can never send ordinary transfers again.
⚠️ One-way door
Enabling high-security is permanent. The runtime whitelist then rejects everything except schedule_transfer, cancel, recover_funds, and batch_all of those (≤ 16 calls, no nesting). No governance, no treasury, no tipping.
👁 Mandatory delay
The delay you choose at enrollment applies to all outgoing transfers — one-time schedule_transfer_with_delay calls are rejected for enrolled accounts. Plan the window like a safe's time lock.
🛡 Guardian power
A named guardian (hardware wallet, multisig, or trusted third party) can cancel any pending transfer during the window — and can call recover_funds to seize every pending hold plus the free balance. Choose it like a recovery key.
🔥 1% burn on guardian reversals
When a guardian reverses funds, a 1% volume fee is burned (the remaining 99% goes to the guardian, not back to the sender). Sender-cancelled one-time transfers pay no reversal fee. The burn makes guardian seizure expensive to abuse.
📏 Quotas & caps
Max 16 signed extrinsics per rolling 24 h window; batch_all ≤ 16 leaves; high-security signers cannot tip. Size and fee caps are enforced by the signed extension.
🔗 Daisy-chain guardians
A guardian can itself be a high-security account with its own guardian — layered hierarchies where each layer has superior permissions. Upstream recommends a multisig guardian: a single-key HS guardian shares the 16/day quota and can be locked out of cancel for a day.
schedule_transferSources: User Safety Features deep-dive · pallet-reversible-transfers source (verified 2026-09-29).
📚 Call Reference
The ReversibleTransfers pallet's dispatchables, straight from chain/pallets/reversible-transfers/src/lib.rs (indices included for anyone decoding extrinsics).
| Call | Index | Parameters | Who | Notes |
|---|---|---|---|---|
schedule_transfer_with_delay | 4 | dest, amount, delay (blocks or ms) | Any non-HS account | One-time reversible transfer. Delay ≥ 2 blocks. Rejected for high-security accounts. |
schedule_transfer | 3 | dest, amount | High-security accounts | Uses the enrollment delay. Default at enrollment: 7,200 blocks (24 h). |
cancel | 1 | tx_id | Sender, or guardian for HS | Sender-cancelled one-time transfers return the full amount — no reversal fee. Guardian cancels burn 1%. |
execute_transfer | 2 | tx_id | Pallet only | Dispatched automatically by the Scheduler pallet when the delay expires. Users never call this. |
recover_funds | 7 | account | Guardian | Emergency sweep: cancels all pending holds (1% fee) and moves the free balance to the guardian. Repeatable. HS status stays. |