CloakPay

The first crypto wallet where the merchant never sees your address. Pay anyone. Reveal nothing.

CloakPay

Created At

ETHGlobal Cannes 2026

Winner of

WalletConnect

WalletConnect - Best use of WalletConnect Pay 1st place

Project Description

CloakPay is a passkey-native crypto wallet for real-world payments that hides the sender's identity at the point of sale. Using stealth address derivation and the Unlink protocol, every payment is routed through a privacy pool — breaking the on-chain link between the sender's wallet and the merchant. The merchant receives funds from an ephemeral one-time address, with zero knowledge of who actually paid. Built on ERC-4337 smart accounts with Face ID onboarding, CloakPay also supports crypto subscriptions via ERC-7715 spend permissions — letting merchants pull recurring payments within user-defined limits, non-custodially. Integrated with WalletConnect Pay Terminal for seamless POS checkout.

How it's Made

We started with a simple observation: every crypto payment leaks your entire financial history to the merchant. Your wallet address is your bank statement — open to anyone, forever. The fix wasn't obvious. Stealth addresses (ERC-5564) hide the receiver. Nobody had flipped this for the sender. So we did.

The Privacy Layer

  • User deposits into the Unlink protocol — a ZK-powered privacy pool that severs the on-chain link between depositor and withdrawal
  • We derive a one-time ephemeral sender address from the user's master spending key using a DKSAP scheme
  • The merchant at the WalletConnect Pay Terminal receives funds from this ephemeral address — with zero ability to trace it back to the real wallet
  • The user holds a viewing key to privately reconstruct their own history anytime

Passkey Onboarding

  • Built on WebAuthn and ERC-4337 smart accounts
  • No seed phrase, no browser extension
  • Face ID in 30 seconds — first-time crypto users can actually use this

Subscription Layer

  • ERC-7715 spend permissions enforced onchain by our smart wallet's permission manager
  • Merchants pull recurring payments automatically within user-defined limits
  • Fully non-custodial, no signature required each time
  • Private AND recurring — nobody else has both

Stack Unlink SDK · WalletConnect Pay · ERC-4337 · ERC-7715 · DKSAP · Base

background image mobile

Join the mailing list

Get the latest news and updates