frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: I built a low-level crypto lib that adds passwords to wallet mnemonics

3•mscikdf•1h ago
TL;DR: Today’s mnemonics are bare assets with no cryptographic protection. I built a low low-level crypto lib that adds passwords to wallet mnemonics, so leaking your mnemonic no longer leaks your assets.

In the first half of 2025, more than $1.7B in crypto assets were stolen, and roughly 70% of those incidents involved mnemonic-compromise pathways. The core problem is structural. I built MSCIKDF to directly solve this. Here is the playground: https://github.com/mscikdf/mscikdf-playground

MSCIKDF is a core lib that introduces passphrase-sealed mnemonics, built-in multichain, and rotatable secrets at the cryptographic layer. It ensures that:

- The seed is never stored on disk, and never kept in memory (apps/browser extensions)—it only exists for ~20 microseconds during signing or verification.

- A mnemonic and its passphrase can be rotated unlimited times without changing any addresses and without migrating assets.

- One mnemonic supports essentially all chains at cryptographic level.

- The algorithm is pluggable, allowing smooth PQC upgrades in the future while keeping the same mnemonic and the same addresses.

- it supports UNICODE (Chinese / Japanese / Korean / Arabic / Emoji) as passphrases.

Why these properties are possible?

Under the hood, MSCIKDF was designed around:

- Single-root → multi-context isolation (each chain, wallet, device, agent, or application gets a mathematically isolated stream).

- Zero-persistence secret handling (the derived seed is never kept in long-term memory or disk).

- Rotatable passphrase sealing, allowing unlimited secret rotation with stable public identities.

- Curve-agnostic, multi-algorithm derivation, supporting both signatures and encryption (Ed25519, X25519, Secp256k1, sr25519, ECDSA, etc.).

- PQC compatibility, meaning post-quantum KDF modules can be plugged in without breaking identities or requiring wallet migrations.

In short: MSCIKDF turns mnemonics from “bare private keys” into cryptographically protected, renewable, multi-curve cryptographic identity roots.

Comments

mscikdf•1h ago
Happy to answer any questions about the design, threat model, or the KDF internals. The implementation is pure Rust and the playground repo includes test vectors if anyone wants to experiment.

Just to clarify: this is not a wallet or an app. It's a low-level cryptographic library that changes how mnemonics work at the KDF layer.

Shuffle – Game Mode as Experiment Engine

1•gok2•1m ago•0 comments

Grim Fandango film inspirations [pdf]

https://drive.google.com/file/d/1uIofz6_WeSYI3-6SEHT0vqFplb1wfLSW/view
1•Rant423•1m ago•0 comments

Tell HN: It should be okay to use AI for code and papers

1•nis0s•4m ago•0 comments

Show HN: Readit – Portable, dynamic context for AI Agents

https://readit.md/
1•zeerg•5m ago•1 comments

CSS has become too powerful. Here's the solution

https://youtu.be/VsLGfo-e-wc
1•whitep4nth3r•5m ago•0 comments

Pakistan says rooftop solar output to exceed grid demand in some hubs next year

https://www.reuters.com/sustainability/boards-policy-regulation/pakistan-says-rooftop-solar-outpu...
1•toomuchtodo•5m ago•1 comments

NLnet announces funding for 45 more open-source digital infrastructure projects

https://nlnet.nl/news/2025/20251127-45-NGI0-CommonsFund.html
1•pimterry•6m ago•0 comments

Show HN: In The Office Tracker – Track your RTO requirements automatically

https://intheofficetracker.com
1•jryan49•6m ago•0 comments

Greggit – Google but it's only the Reddit results

https://greggit.com
1•goncharom•7m ago•0 comments

Ask HN: What Are You Thankful For?

3•nerdsniper•8m ago•0 comments

10 years of writing a blog nobody reads

https://flowtwo.io/post/on-10-years-of-writing-a-blog-nobody-reads
1•thejoeflow•8m ago•0 comments

The VanDersarl Blériot: a 1911 airplane homebuilt by teenage brothers

https://www.historynet.com/vandersarl-bleriot/
1•ForHackernews•9m ago•0 comments

Thank You Hacker News – To Everyone – It Is the Most Fun Place on the Internet

1•Brajeshwar•9m ago•0 comments

Google Agent Garden

https://console.cloud.google.com/vertex-ai/agents/agent-garden
1•Brajeshwar•10m ago•0 comments

Sharing Your Work Is Like Lifting with Your Legs

https://devonzuegel.com/writing-for-an-audience-is-like-lifting-with-your-legs
1•todsacerdoti•11m ago•0 comments

Show HN: An open-source, air-gapped threat detector for Active Directory

https://github.com/Saeros-Security/Saeros
1•saeros•11m ago•0 comments

Lifetime access to AI-for-evil WormGPT 4 costs just $220

https://www.theregister.com/2025/11/25/wormgpt_4_evil_ai_lifetime_cost_220_dollars/
2•vintagedave•12m ago•0 comments

It's Been a Very Hard Year

https://bell.bz/its-been-a-very-hard-year/
3•tobr•12m ago•0 comments

In Memoriam: Web mascots 404 but not forgotten

https://archive.org/details/in-memoriam-web-mascots
3•ChrisArchitect•13m ago•1 comments

Has China pulled the plug on largest particle collider?

https://www.scmp.com/news/china/science/article/3331618/chinas-god-particle-quest-over-worlds-lar...
1•elashri•13m ago•0 comments

YouChoose: Feed Your Head, Choose Your Algorithm

https://youchoose.ai/
1•thunderbong•16m ago•0 comments

Stirling V2

https://www.stirling.com/blog/introducing-v2
1•Tomte•17m ago•0 comments

Show HN: GemGuard – a security auditing tool for Linux and Windows

https://github.com/AlvaroHoux/gem-guard
1•Alvaro_Houx•19m ago•0 comments

Future Colliders Comparative Evaluation – Working Group Report

https://arxiv.org/abs/2511.20417
1•elashri•20m ago•0 comments

Tested OpenAI's prompt caching across models. Found undocumented behavior

1•harsharanga•22m ago•0 comments

Ingredient in diet sodas, ice cream and chewing gum now linked to liver disease

https://www.dailymail.co.uk/health/article-15328493/Ingredient-diet-sodas-ice-cream-chewing-gum-l...
1•Bender•23m ago•1 comments

Slipknot-gauged mechanical transmission and robotic operation

https://www.nature.com/articles/s41586-025-09673-w
1•bookofjoe•23m ago•0 comments

Dollar Radio Station – 1926 experimental private ship-to-shore radio network

https://www.dollaradiopacifica.com
1•supportengineer•24m ago•0 comments

OpenAI User Data Exposed in Mixpanel Hack

https://www.securityweek.com/openai-user-data-exposed-in-mixpanel-hack/
1•Bender•25m ago•1 comments

RFK Jr.'s new CDC deputy director prefers "natural immunity" over vaccines

https://arstechnica.com/health/2025/11/rfk-jr-s-new-cdc-deputy-director-prefers-natural-immunity-...
5•Bender•25m ago•1 comments