Send ETH with a link.
SMAIL seals ETH into a link. Whoever you send the link to opens it and takes the funds to any address, without an account and without ETH of their own for gas.
Introduction
A smail is ETH held by a contract under a one-time key. The key lives in the link, after the #. Opening the link signs a release with that key, and the contract pays the address the opener chooses.
There are two kinds of link:
- Standard link. Simple and cheap. The chain shows who sealed it and who claimed it.
- Private link. Sealed into a shared pool and claimed with a zero-knowledge proof, so the claim cannot be matched to the sealing by address.
A network of relayers submits claims and pays their gas, funded by a 1% fee the sender pays when sealing.
Networks
SMAIL runs on EVM chains only.
| Network | Chain ID | Status |
|---|---|---|
| Robinhood Chain testnet | 46630 | Live |
| Robinhood Chain | 4663 | Not deployed yet |
| Ethereum Sepolia | 11155111 | Not deployed yet |
Standard links
- Seal. Choose an amount and a claim window (5 minutes to 30 days). Your wallet sends the amount plus the 1% fee to the contract.
- Share. You get a claim link and a return link. Send the claim link privately to your recipient. Keep the return link.
- Claim. The recipient opens the link and enters any address. A relayer submits the claim and pays the gas; the recipient receives the full amount.
Treat a claim link like cash. Whoever opens it first can claim the funds. Never post it in public.
A smail releases exactly once. The signature in a claim fixes the chain, the contract, the recipient, the relayer and the fee, so a claim that is seen in transit cannot be redirected.
A recipient with a wallet can also claim directly and pay their own gas. Smart-contract recipients must claim this way: sponsored delivery goes to plain wallets only.
Password lock
A sender can add a password when sealing. The link alone then opens nothing: the recipient needs the link and the password together. Send them over different channels.
The password is never stored, on-chain or in the browser. If it is lost, the funds come back through the return link after the window ends.
Returns
If nobody claims before the window ends, the return link takes the funds back. A return always goes to the wallet that sealed the smail; the address cannot be changed, so a leaked return link cannot send the funds anywhere else.
A return is refused while the claim window is still open.
Private links
A private link holds two secrets instead of a key. Sealing puts a commitment to them into a Merkle tree shared with every other private sealing. Claiming proves, with a Groth16 zero-knowledge proof made in the browser, that the claimer knows the secrets behind one of the commitments, without saying which.
- The claim publishes a nullifier, so each link can be claimed once.
- The sender’s browser keeps a copy of the link, so the sender can take the funds back with the same link until someone claims it. There is no separate return link.
- Relayers carry private claims of ETH. The relayer that submits one is paid the 1% fee the sender prepaid when sealing.
Fees
| Action | Fee | Who pays gas |
|---|---|---|
| Seal a standard link | 1% on top of the amount | Sender |
| Claim or return through a relayer | None | Relayer |
| Claim or return from your own wallet | None | You |
| Private link | 1% | Sender to seal, relayer to claim |
The 1% on a standard link is split when the smail is sealed: 50% to the relayer that delivers it, 30% to the maintainers, 20% burned.
The smallest smail is 0.001 ETH on testnet and 0.1 ETH on mainnet.
What the chain shows
| Standard link | Private link | |
|---|---|---|
| Sender address | Public | Public, as a deposit into the pool |
| Amount | Public | Public at sealing and at claim |
| Recipient address | Public | Public, as a withdrawal from the pool |
| Link between sender and recipient | Public | Hidden by the proof |
| The key or secrets in the link | Never on-chain | Never on-chain |
The part of a link after the # is not sent to any server by the browser.
Privacy tips
A private link hides which sealing a claim belongs to. It does not hide patterns around it.
- Wait between sealing and claiming. A claim seconds after a sealing is easy to pair with it.
- Amounts are fixed sizes (0.001, 0.005, 0.01, 0.05 and 0.1 ETH), so an amount alone does not single out a sealing.
- Claim to a fresh address that has no history with the sender.
- Let a relayer submit the claim. Claiming from your own wallet shows that wallet paying the gas.
- The pool protects better the more sealings it holds.
How relayers work
A relayer earns from delivering smails. Relayers run no server and hold no key: one hosted relayer submits every delivery, and a rotation decides which member is paid for it.
- Each member gets one turn per round. The next turn is drawn at random from the members still waiting, and is fixed until it is taken.
- The member whose turn it is receives the relayer share of that smail’s fee, and repays the delivery’s gas from its gas tank.
- The gas charge never exceeds the reward, so a delivery cannot cost a member more than it pays.
See who is active on the relayers page.
Become a relayer
- Mint a SHELL. 100,000 SMAIL is locked into a SHELL, the relayer licence. It is an activation, not a yield product: a SHELL earns nothing by itself.
- Register the SHELL with ETH for its gas tank.
- Earn when your turn comes. Rewards collect in your own vault; withdraw them at any time.
- Leave whenever you like. Your gas and rewards come back in the same transaction, and unstaking returns the SMAIL.
Start on the register page.
Gas tank
| Rule | Value |
|---|---|
| Minimum top-up | 0.01 ETH (0.001 ETH on testnet) |
| Maximum in a tank | 1 ETH |
| Out-of-gas floor | 0.0001 ETH |
The tank is used only to repay delivery gas. A member whose tank falls below the floor is benched: it keeps its seat but takes no turns and earns nothing until it tops up. Anyone may evict a benched member, which returns its SHELL, rewards and remaining gas and frees the seat.
Seats and queue
There are 100 seats. Everyone past that waits in a first-come queue, with SHELL and gas committed, and is seated automatically when a seat opens. Leaving the queue returns both at once.
A member that leaves and rejoins goes to the back of the queue.
SDK
smail-sdk builds the transactions and signatures; you send them with any EVM library. Sealing:
import { generateEnvelopeKey, buildFundETH } from "smail-sdk";
const claim = generateEnvelopeKey(); // the claim link carries this key
const refund = generateEnvelopeKey(); // the return link carries this one
const amount = 10n ** 17n; // 0.1 ETH
const call = buildFundETH(SNAIL, {
claimKey: claim.address,
refundKey: refund.address,
amount: amount + amount / 100n, // the amount plus the 1% fee
expiry: BigInt(Math.floor(Date.now() / 1000) + 86_400),
});
await wallet.sendTransaction(call); // { to, data, value }Claiming through the relayer network:
import { authorizeRelease, addressToDestination, releaseRequestOf } from "smail-sdk";
const release = await authorizeRelease("claimToAddress", claim.privateKey, {
chainId, snail: SNAIL, claimKey: claim.address,
destination: addressToDestination(recipient),
relayer: RELAYER_NETWORK, // signed for the network: it submits and pays gas
fee: 0n,
});
await fetch(RELAYER_URL + "/release", {
method: "POST",
headers: { "content-type": "application/json" },
body: JSON.stringify(releaseRequestOf(release)),
});The claim link is the claim key’s 32 bytes, base64url-encoded, after /claim#s1.
CLI and agents
smail-cli seals, opens and returns smails from a terminal, for scripts and AI agents holding a key.
npm install -g smail-cli
smail seal --amount 0.1 --expiry 24h
smail seal --amount 0.1 --privateThe full guide is on the agent page.
Relayer API
Base URL on testnet: https://relay.smail.cash/v16
| Request | Purpose |
|---|---|
GET / | The chain, contracts and gas price this relayer serves |
POST /release | Submit a signed claim or return of a standard smail |
POST /private-claim | Submit a private-link claim with its proof |
The relayer refuses a delivery whose gas would cost more than its reward, a recipient that is a smart contract, and any claim it has already submitted. Requests are limited per address: 20 submissions and 120 status reads a minute.
Contracts
Robinhood Chain testnet (46630). All are verified on the explorer.
| Contract | What it does | Address |
|---|---|---|
| SponsoredSmail | Holds standard smails; seal, claim and return | 0x4CA78E…Ff21C4 ↗ |
| RelayerNetwork | Relayer seats, rotation, gas tanks and the fee split | 0x9A5389…699418 ↗ |
| ShellStake | The SHELL relayer licence (NFT) | 0x288670…E41CFa ↗ |
| SmailToken | SMAIL, minted into a SHELL | 0xA81b4E…33a7f9 ↗ |
| PrivateSnail | The private-link pool | 0xEc91c9…00a85C ↗ |
| Groth16Verifier | Checks private-claim proofs | 0x845b87…3F3E3e ↗ |
| RelayerNames | Relayer display names | 0x1DB98F…bae1A7 ↗ |
No contract has an upgrade key. The maintainer can withdraw its 30% share and, in an emergency, return a stuck stake to its own staker; it cannot move anyone’s funds anywhere else.
Caveats
- The protocol is unaudited by an independent firm. Review the code before sending real funds.
- A link is a bearer instrument. Anyone who gets it can claim: a chat app, a screenshot, a shared computer.
- This browser stores your links so you can find and return them. Clearing site data before a smail is claimed or returned loses the return link.
- A standard link is not private. Use a private link when the connection between sender and recipient must not be public.