# Fluidkey Markdown version of https://l2beat.com/privacy/projects/fluidkey ## Summary - Metrics: Not tracked. Data tracking is not available for this project. - Tracked on: Ethereum, Base Chain, Arbitrum One, OP Mainnet, Polygon PoS, Gnosis Chain - Attributes: Stealth addresses, Any amount, DeFi ### Risks - Trusted setup: No setup (sentiment: neutral). No setup: This project does not have a ZK system and thus no setup-related trust assumptions. - Exit window: Infinite (sentiment: good). Under the documented key model, existing stealth balances are held in user-controlled Safes and can be recovered with the published client-side recovery tool and original Safe initialization parameters. Auto-earn positions remain subject to the withdrawal conditions and risks of their underlying vaults. This protocol does not pass the walkaway test: users cannot fully use it if all centralized protocol participants disappear. New payment-address generation through the app and ENS, address indexing, transaction construction, and relaying depend on the hosted Fluidkey service. - Privacy: Recipient privacy. Public observer: Recipient private (sentiment: good); Chain analyst: Recipient at risk (sentiment: warning); Network observer: Recipient at risk (sentiment: warning); Privileged insider: Recipient exposed (sentiment: bad); Future adversary: Recipient at risk (sentiment: warning). - Reproducibility: Partially reproducible (sentiment: warning). The production web wallet is closed source and cannot be self-hosted. The published derivation code and recovery client can nevertheless be used to derive keys, verify service-generated receiving addresses, and recover funds independently. A local client can also register and authenticate through the hosted API. The backend implementations of the API, ENS gateway, indexer, and relay service are not published, so the complete service cannot be reproduced. ### About A wallet service with a closed-source hosted frontend that keeps spending keys client-side and gives recipients a fresh stealth Safe account for every payment through reusable ENS names. ## Protocol description Fluidkey is a wallet service that separates incoming payments across fresh Ethereum addresses while presenting them as one account. Whether requested through an ENS name, the app, or the API, each receiving address is a Safe controlled by a private key that the recipient can derive locally. ### Stealth address generation Under Fluidkey's published key model, the client deterministically derives separate viewing and spending keys from a wallet signature combined with a PIN. It shares a derived private viewing node and public spending key with Fluidkey so the service can generate and monitor payment addresses, but keeps the private spending key locally. Fluidkey also offers Privy embedded wallets on the web and device-generated keys on mobile. Recovery of those keys depends on the chosen login and backup method. For each payment nonce, the service derives an ephemeral private key and combines it with the recipient's public spending key to generate a one-time signer address. The client can recreate the same ephemeral key and combine its public key with the private spending key to derive the private key controlling that signer. Under this model, only the client can derive the private key needed to sign for a correctly generated address. The receiving address is a counterfactually predicted 1/1 Safe whose sole owner is the stealth signer. It can receive funds before the Safe contract is deployed. Its address depends on the Safe factory, singleton, proxy bytecode, owners, threshold, salt nonce, and initialization data. Recovery must reproduce the original parameters, including any auto-earn initialization, rather than just the user's current settings. The derivation SDK and standalone recovery client are published. The recovery client can derive exportable stealth signer keys, predict receiving Safes, and deploy them without using the Fluidkey API. The production web wallet itself is closed source, has no published reproducible build, and cannot be self-hosted. Users who rely on it must trust the remotely served application to preserve the client-side spending-key boundary. The API, ENS gateway, indexer, and relay are also hosted and closed source, so the complete wallet service cannot be self-hosted. The hosted frontend is not required to hold or use spending keys. A locally run client can register and authenticate an account, independently verify service-generated receiving addresses, and recover funds from them. In this setup, the spending key and derived stealth private keys remain local. Fluidkey receives the scoped viewing capability and signed authorizations. Assuming the client verifies the data it signs, bypassing the hosted frontend removes it as a spending-key exfiltration risk. This differs from the usual sender-driven ERC-5564 flow. The payer does not derive the address from public recipient metadata and publish an announcement. Fluidkey's service performs the derivation, keeps the address-to-account mapping, and indexes the resulting balances. When a user spends, the service selects one or more stealth Safes and prepares the transactions. The client re-derives the corresponding owner keys and authorizes Safe execution. The hosted client also processes accepted actions returned by the backend, so keeping keys client-side does not replace checking the transaction data supplied by the service. ### ENS resolution Fluidkey provides `username.fkey.eth` and `username.fkey.id` names. Both kinds of name use the same ENS CCIP-Read flow. The `.fkey.id` name also works as a web payment link. A lookup is redirected to Fluidkey's gateway, which creates a fresh payment address and returns a signed ENS answer. The onchain resolver checks the answer's expiry and signature against its configurable set of signers. The signature authenticates the answer as one accepted by Fluidkey, but it is not a proof that the returned address was correctly derived for the named recipient. An external sender cannot independently verify recipient control from the ENS answer alone. The resolver owner can immediately replace the gateway URL and add or remove accepted signers. ### Auto-earn When auto-earn is enabled, receiving Safes are initialized with the Fluidkey Earn module. It allows the module owner and authorized relayers to wrap native tokens when needed and deposit funds into configured ERC-4626 vaults, with the vault shares credited to the same Safe. Anyone can also submit a deposit instruction signed by an authorized relayer. These deposits do not require a new Safe owner signature for each execution. The module owner publishes token and vault configurations identified by a hash of their contents. Changing a vault produces a different configuration hash, and selecting a different hash requires a call from the Safe. The owner cannot silently replace the vault set under an already selected hash. Both the module owner and authorized relayers can manage relayer permissions. Users can disable the module through their Safe, but funds already deposited remain exposed to the underlying vaults' losses, liquidity, and withdrawal restrictions. ### Privacy considerations Fluidkey's fresh addresses do not hide the sender, token, amount, or receiving address of an individual payment. They prevent separate receives from automatically accumulating under one reused public address. Later transactions can still link addresses when they consolidate balances, use a recognizable destination, or correlate by timing and amount. The hosted service has the viewing capability and address index needed to link an account's stealth addresses and activity. Fluidkey also integrates Houdini Swap for its Hide Trail feature, which routes funds through two centralized exchanges (CEXs) to obscure the public link between the original and final addresses. This adds reliance on the swap service and participating exchanges, including their visibility into the transfers and their ability to delay or block them. ## Privacy **What the protocol promises:** Hides which account a receiving Safe belongs to. The payer knows the address it was given; sender, asset, amount and where the funds go next are public. On public blockchains like Ethereum, all actions transparent by default. A privacy protocol can at best cut the link between addresses or offer privacy while deposited. The colour says whether a careful user can keep the link, amount or recipient private against that adversary: green yes, yellow only outside supported options or by accepting another leak, red no. Fields marked at risk stay private only under the condition in their note. ### Public observer Recipient private (sentiment: good) **Who:** Everyone with a block explorer and some basic tools. Sees every public onchain event, but does no correlation beyond following links. Examples: A curious counterparty, an employer, a journalist. A payment reaches a predicted Safe before it is deployed, with no onchain announcement linking it to the recipient account. Deployment later exposes the individual stealth owner and enabled modules, not the parent account. **Advice:** Generate a fresh address for each receive, keep unrelated funds separate with labels, and send to destinations with no public link to you. **Sources** - [Counterfactual receiving Safe and individual stealth signer](https://docs.fluidkey.com/technical-documentation/technical-walkthrough/#3-stealth-accounts) - [Safe owner and initialization data determine the address](https://github.com/fluidkey/fluidkey-stealth-account-kit/blob/2a4ccfafef127165c11ba16fc16235c919698ec2/src/predictStealthSafeAddress.ts#L32-L104) - [AutoEarnExecuted exposes Safe, token and deposited amount](https://l2beat.com/privacy/projects/fluidkey#FluidkeyEarnModule) - [Labels restrict which balances fund a send](https://docs.fluidkey.com/readme/labels/) ### Chain analyst Recipient at risk (sentiment: warning) **Who:** Scrapes all public data and correlates it: timing, amounts, gas and wallet fingerprints, address clusters. Examples: Chain analytics firms, ZachXBT, data brokers. Safe deployment and auto-earn events make service use recognizable, which narrows the anonymity set to Fluidkey users. Nothing onchain maps Safes to accounts, but timing, amounts, common destinations and reuse across chains can identify or cluster recipients, and a send draws from several Safes by default, which links them. The optional Hide Trail routes through Houdini and two exchanges, a separate service with its own trust assumptions. **Advice:** Label payments so a send draws from one Safe. Check related activity across chains and space out distinctive payments. **Sources** - [onInstall records its caller; an event alone is not proof of a Fluidkey user](https://github.com/fluidkey/fluidkey-earn-module/blob/122cde19940d06b94c0027f4cd2e22e7fa19129a/src/FluidkeyEarnModule.sol#L243-L260) - [Different auto-earn versions use different initialization data](https://docs.fluidkey.com/technical-documentation/stealth-account-initdata/) - [Shared derivation path permits the same addresses across chains](https://docs.fluidkey.com/technical-documentation/technical-walkthrough/#3a-stealth-signer-derivation) - [Hide Trail integration](https://docs.fluidkey.com/readme/advanced-privacy/) ### Network observer Recipient at risk (sentiment: warning) **Who:** Sits between the user and the chain and sees web2 traffic only: RPC providers, relayers and broadcasters, indexers, ISPs. Learns IP addresses, timing, browser fingerprints, ciphertext and what becomes public. Assumes Tor to send transactions and, where the client has an RPC setting, an own node to read the blockchain. Examples: Infura or Alchemy, a Tornado relayer, a wallet vendor selling telemetry, Google captcha or analytics in the dapp frontend. The hosted client is closed source, so which RPC and analytics providers see your Safe list cannot be verified. Paying to your fkey.id name hands the name and the fresh address to whoever resolves ENS for the payer, often the payer's RPC provider. Only the open kit and the recovery app can be pointed at your own node. **Advice:** Derive addresses with the kit and hand them to payers directly instead of the ENS name. Read balances with the recovery app on your own RPC, and deploy and spend from a fresh gas wallet, since the recovery app deploys Safes from the connected wallet. **Sources** - [Offchain ENS gateway](https://l2beat.com/privacy/projects/fluidkey#OffchainResolver) - [Local CREATE2 prediction needs no RPC](https://github.com/fluidkey/fluidkey-stealth-account-kit/blob/2a4ccfafef127165c11ba16fc16235c919698ec2/src/predictStealthSafeAddress.ts#L120-L180) - [Recovery app accepts a custom RPC](https://github.com/fluidkey/sara/blob/6ab939e176cbae60a33214d292070d6a1dfe9b30/src/components/RecoverAddressesJourneyStep.tsx#L468) - [Recovery app deploys the Safe from the connected wallet](https://github.com/fluidkey/sara/blob/6ab939e176cbae60a33214d292070d6a1dfe9b30/src/hooks/useDeployStealthSafe.ts#L63-L99) - [Disclosed service providers and transport encryption](https://www.fluidkey.com/privacy) ### Privileged insider Recipient exposed (sentiment: bad) **Who:** Holds a protocol operator role or receives keys or plaintext by design: upgrade admin, sequencer, decryption or view key holder, TEE vendor, association set provider, hosted prover, note registry. Examples: A compliance backdoor key, a DAO with an upgrade key, a KMS committee, an ASP operator. Fluidkey holds the viewing key, so it can regenerate every address and tie its activity to your account. Optional identity-verified services add identity attributes, and Hide Trail adds route knowledge at Houdini and each exchange. **Advice:** Verify address derivations and transactions with an inspected local client. This protects your spending keys but does not remove Fluidkey's view. **Sources** - [Private viewing key shared with the service](https://github.com/fluidkey/fluidkey-stealth-account-kit/blob/2a4ccfafef127165c11ba16fc16235c919698ec2/src/extractViewingPrivateKeyNode.ts#L14-L30) - [Ephemeral key plus public spending key generates each signer](https://github.com/fluidkey/fluidkey-stealth-account-kit/blob/2a4ccfafef127165c11ba16fc16235c919698ec2/src/generateStealthAddresses.ts#L14-L49) - [ENS signature authenticates the service, not recipient control](https://l2beat.com/privacy/projects/fluidkey#OffchainResolver) - [Permissions](https://l2beat.com/privacy/projects/fluidkey#permissions) - [Hosted-client trust boundary](https://l2beat.com/privacy/projects/fluidkey#upgrades-and-governance) - [Optional verification results and identity attributes](https://www.fluidkey.com/privacy) - [Hide Trail and its exchange intermediaries](https://docs.fluidkey.com/readme/advanced-privacy/) ### Future adversary Recipient at risk (sentiment: warning) **Who:** Harvest now, decrypt later. Holds every byte ever written onchain plus any retained logs, and future cryptanalysis such as a large quantum computer that breaks elliptic-curve key exchange and pairings, but not hashes, symmetric ciphers or lattices. Examples: First well-funded insiders, then everyone in a potential post-quantum future. No announcement is published, so a quantum computer cannot replay address derivations from the chain alone. The viewing key held by Fluidkey exposes the history regardless. Accounts created from a wallet signature reduce to that wallet's key plus a four-digit PIN. **Advice:** Create your account with independently generated keys, not from a wallet signature. Treat the viewing key shared with Fluidkey as permanently disclosed. **Sources** - [Stealth signer depends on a hashed shared secret](https://github.com/fluidkey/fluidkey-stealth-account-kit/blob/2a4ccfafef127165c11ba16fc16235c919698ec2/src/generateStealthPrivateKey.ts#L11-L21) - [Signature halves generate the viewing and spending keys](https://github.com/fluidkey/fluidkey-stealth-account-kit/blob/2a4ccfafef127165c11ba16fc16235c919698ec2/src/generateKeysFromSignature.ts#L11-L36) - [Wallet address and PIN determine the key-generation message](https://github.com/fluidkey/fluidkey-stealth-account-kit/blob/2a4ccfafef127165c11ba16fc16235c919698ec2/src/utils/generateFluidkeyMessage.ts#L10-L32) - [Recovery supports a four-digit PIN, defaulting to 0000](https://github.com/fluidkey/sara/blob/6ab939e176cbae60a33214d292070d6a1dfe9b30/src/components/GenerateKeysJourneyStep.tsx#L28-L90) - [Distinct web embedded-wallet and mobile device-key setups](https://docs.fluidkey.com/readme/account-set-up/) - [Operator data retention](https://www.fluidkey.com/privacy) ## Risk summary ### Funds can be stolen if 1. a user relies on the hosted wallet and it is malicious or compromised and exfiltrates derived spending keys. The production wallet is closed source and has no published reproducible build, so users cannot inspect its source or verify the code being served. 2. an accepted ENS signer returns an attacker-controlled payment address for a Fluidkey name. The resolver authenticates the answer but does not prove that the intended recipient controls it. 3. the hosted service supplies malicious transaction data and the client signs it without independently checking the destination, amount, and calls being authorized.
### Funds can be lost if 1. a user loses the wallet, PIN, login, or backup needed to recover their private spending keys. 2. the service and client derive different address data or Safe initialization parameters and a payment is sent to an address that the user cannot recover. 3. an auto-earn vault loses funds or cannot honor withdrawals, or a service used by Hide Trail fails to return the funds routed through it.
### Privacy can be lost if 1. Fluidkey, or an attacker who obtains its viewing data, uses the service's viewing capability and index to link an account's stealth addresses and onchain activity. 2. spending from several stealth addresses together, reusing destinations, or recognizable timing and amounts links otherwise separate payments onchain. 3. a user relies on Hide Trail and the swap service or participating exchanges use their transfer records to link activity that is obscured from public onchain observers. ## Upgrades & Governance Fluidkey has no public onchain governance process for its hosted wallet, API, indexer, ENS gateway, or relay. These components can change without an onchain notice period. The production wallet is closed source and has no published reproducible build, so users who rely on it cannot inspect its source, verify which client code is deployed, or determine whether an update preserves the client-side spending-key boundary. Users can bypass the hosted frontend with an inspected local client, but this does not reproduce the other hosted components or prevent them from changing. The deployed ENS `OffchainResolver` code is immutable, but its owner can immediately replace the gateway URL, add or remove accepted signers, or transfer ownership. An accepted signer can authenticate any offchain ENS answer, including a payment address. The resolver callback verifies only the signature and expiry. It does not verify stealth-address derivation or recipient control. The resolver is owned by a 3/5 Safe. These powers affect new address generation and ENS lookups. They do not let the resolver owner or signers spend from an existing, correctly derived stealth Safe because its private owner key remains with the user. Existing balances can be recovered independently with the published recovery client and the original Safe initialization parameters, but the full Fluidkey experience does not remain available if the hosted service disappears. The Fluidkey Earn module is separate from the resolver and has immutable code. Its owner is a 2/3 Safe on each tracked chain. Its owner can publish new vault configurations and manage authorized relayers. Relayers can initiate deposits into a Safe's selected configuration and add or remove relayers. Each configuration is identified by a hash of its contents, so adopting a different vault set requires a call from the Safe. Users can disable the module through their Safe. The governance and withdrawal conditions of the underlying vaults remain separate dependencies. ## Updates Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/privacy/projects/fluidkey#updates). ## Permissions ### Arbitrum One #### Actors ##### Fluidkey Earn Owner Addresses: [0x9E3eba321427941868cB4123De97DAB145C9e7CD](https://arbiscan.io/address/0x9E3eba321427941868cB4123De97DAB145C9e7CD) A Multisig with 2/3 threshold. * Can interact with FluidkeyEarnModule * publish vault configurations, manage authorized relayers, and initiate deposits into the configurations selected by enabled Safes. Changing a Safe's selected configuration hash requires a call from that Safe ##### EOA 1 Addresses: [0x53d92eCe145696ff27A7d1F8746632C3deBB151D](https://arbiscan.io/address/0x53d92eCe145696ff27A7d1F8746632C3deBB151D) * Can interact with FluidkeyEarnModule * initiate deposits from enabled Safes into their selected vault configurations, and add or remove authorized relayers ### Base Chain #### Actors ##### Fluidkey Earn Owner Addresses: [0x9E3eba321427941868cB4123De97DAB145C9e7CD](https://basescan.org/address/0x9E3eba321427941868cB4123De97DAB145C9e7CD) A Multisig with 2/3 threshold. * Can interact with FluidkeyEarnModule * publish vault configurations, manage authorized relayers, and initiate deposits into the configurations selected by enabled Safes. Changing a Safe's selected configuration hash requires a call from that Safe ##### EOA 2 Addresses: [0x53d92eCe145696ff27A7d1F8746632C3deBB151D](https://basescan.org/address/0x53d92eCe145696ff27A7d1F8746632C3deBB151D) * Can interact with FluidkeyEarnModule * initiate deposits from enabled Safes into their selected vault configurations, and add or remove authorized relayers ### Ethereum #### Actors ##### Fluidkey Earn Owner Addresses: [0x9E3eba321427941868cB4123De97DAB145C9e7CD](https://etherscan.io/address/0x9E3eba321427941868cB4123De97DAB145C9e7CD) A Multisig with 2/3 threshold. * Can interact with FluidkeyEarnModule * publish vault configurations, manage authorized relayers, and initiate deposits into the configurations selected by enabled Safes. Changing a Safe's selected configuration hash requires a call from that Safe ##### Fluidkey Resolver Multisig Addresses: [0xdcC34c0da55cEF7AeD38Bb749AD97DAC12A9936C](https://etherscan.io/address/0xdcC34c0da55cEF7AeD38Bb749AD97DAC12A9936C) A Multisig with 3/5 threshold. * Can interact with OffchainResolver * change the accepted signers and gateway URL immediately, or transfer resolver ownership ##### EOA 4 Addresses: [0x53d92eCe145696ff27A7d1F8746632C3deBB151D](https://etherscan.io/address/0x53d92eCe145696ff27A7d1F8746632C3deBB151D) * Can interact with FluidkeyEarnModule * initiate deposits from enabled Safes into their selected vault configurations, and add or remove authorized relayers ##### EOA 3 Addresses: [0x269fDaBd799179189C98D960C58C3793CcedDB85](https://etherscan.io/address/0x269fDaBd799179189C98D960C58C3793CcedDB85) * Can interact with OffchainResolver * sign arbitrary offchain ENS answers, including payment addresses accepted by the resolver ### Gnosis Chain #### Actors ##### Fluidkey Earn Owner Addresses: [0x9E3eba321427941868cB4123De97DAB145C9e7CD](https://gnosis.blockscout.com/address/0x9E3eba321427941868cB4123De97DAB145C9e7CD) A Multisig with 2/3 threshold. * Can interact with FluidkeyEarnModule * publish vault configurations, manage authorized relayers, and initiate deposits into the configurations selected by enabled Safes. Changing a Safe's selected configuration hash requires a call from that Safe ##### EOA 5 Addresses: [0x53d92eCe145696ff27A7d1F8746632C3deBB151D](https://gnosis.blockscout.com/address/0x53d92eCe145696ff27A7d1F8746632C3deBB151D) * Can interact with FluidkeyEarnModule * initiate deposits from enabled Safes into their selected vault configurations, and add or remove authorized relayers ### Polygon PoS #### Actors ##### Fluidkey Earn Owner Addresses: [0x9E3eba321427941868cB4123De97DAB145C9e7CD](https://polygonscan.com/address/0x9E3eba321427941868cB4123De97DAB145C9e7CD) A Multisig with 2/3 threshold. * Can interact with FluidkeyEarnModule * publish vault configurations, manage authorized relayers, and initiate deposits into the configurations selected by enabled Safes. Changing a Safe's selected configuration hash requires a call from that Safe ##### EOA 6 Addresses: [0x53d92eCe145696ff27A7d1F8746632C3deBB151D](https://polygonscan.com/address/0x53d92eCe145696ff27A7d1F8746632C3deBB151D) * Can interact with FluidkeyEarnModule * initiate deposits from enabled Safes into their selected vault configurations, and add or remove authorized relayers ### OP Mainnet #### Actors ##### Fluidkey Earn Owner Addresses: [0x9E3eba321427941868cB4123De97DAB145C9e7CD](https://optimistic.etherscan.io/address/0x9E3eba321427941868cB4123De97DAB145C9e7CD) A Multisig with 2/3 threshold. * Can interact with FluidkeyEarnModule * publish vault configurations, manage authorized relayers, and initiate deposits into the configurations selected by enabled Safes. Changing a Safe's selected configuration hash requires a call from that Safe ##### EOA 7 Addresses: [0x53d92eCe145696ff27A7d1F8746632C3deBB151D](https://optimistic.etherscan.io/address/0x53d92eCe145696ff27A7d1F8746632C3deBB151D) * Can interact with FluidkeyEarnModule * initiate deposits from enabled Safes into their selected vault configurations, and add or remove authorized relayers ## Smart contracts ### Arbitrum One #### FluidkeyEarnModule Addresses: [0x3BDb857AFe9b51d8916D80240d2ADe40D4d3f2f9](https://arbiscan.io/address/0x3BDb857AFe9b51d8916D80240d2ADe40D4d3f2f9#code) Safe module used for Fluidkey auto-earn. Authorized relayers can deposit tokens into the vault selected by the Safe's configuration hash, with vault shares credited to that Safe. The module owner publishes configurations, but selecting a different hash requires a call from the Safe. * Roles: * **authorizedRelayers**: EOA 1 * **owner**: Fluidkey Earn Owner ### Base Chain #### FluidkeyEarnModule Addresses: [0x3BDb857AFe9b51d8916D80240d2ADe40D4d3f2f9](https://basescan.org/address/0x3BDb857AFe9b51d8916D80240d2ADe40D4d3f2f9#code) Safe module used for Fluidkey auto-earn. Authorized relayers can deposit tokens into the vault selected by the Safe's configuration hash, with vault shares credited to that Safe. The module owner publishes configurations, but selecting a different hash requires a call from the Safe. * Roles: * **authorizedRelayers**: EOA 2 * **owner**: Fluidkey Earn Owner ### Ethereum #### FluidkeyEarnModule Addresses: [0x3BDb857AFe9b51d8916D80240d2ADe40D4d3f2f9](https://etherscan.io/address/0x3BDb857AFe9b51d8916D80240d2ADe40D4d3f2f9#code) Safe module used for Fluidkey auto-earn. Authorized relayers can deposit tokens into the vault selected by the Safe's configuration hash, with vault shares credited to that Safe. The module owner publishes configurations, but selecting a different hash requires a call from the Safe. * Roles: * **authorizedRelayers**: EOA 4 * **owner**: Fluidkey Earn Owner #### OffchainResolver Addresses: [0x9AcF316290AaA62edafdDDaC48B124032C36EB3c](https://etherscan.io/address/0x9AcF316290AaA62edafdDDaC48B124032C36EB3c#code) Immutable ENS CCIP-Read resolver used by Fluidkey. Every query redirects to a configurable gateway and accepts the returned ENS record if it is unexpired and signed by an accepted signer. It does not verify that a returned payment address was derived for the named recipient. * Roles: * **owner**: Fluidkey Resolver Multisig * **signers**: EOA 3 ### Gnosis Chain #### FluidkeyEarnModule Addresses: [0x3BDb857AFe9b51d8916D80240d2ADe40D4d3f2f9](https://gnosis.blockscout.com/address/0x3BDb857AFe9b51d8916D80240d2ADe40D4d3f2f9#code) Safe module used for Fluidkey auto-earn. Authorized relayers can deposit tokens into the vault selected by the Safe's configuration hash, with vault shares credited to that Safe. The module owner publishes configurations, but selecting a different hash requires a call from the Safe. * Roles: * **authorizedRelayers**: EOA 5 * **owner**: Fluidkey Earn Owner ### Polygon PoS #### FluidkeyEarnModule Addresses: [0x3BDb857AFe9b51d8916D80240d2ADe40D4d3f2f9](https://polygonscan.com/address/0x3BDb857AFe9b51d8916D80240d2ADe40D4d3f2f9#code) Safe module used for Fluidkey auto-earn. Authorized relayers can deposit tokens into the vault selected by the Safe's configuration hash, with vault shares credited to that Safe. The module owner publishes configurations, but selecting a different hash requires a call from the Safe. * Roles: * **authorizedRelayers**: EOA 6 * **owner**: Fluidkey Earn Owner ### OP Mainnet #### FluidkeyEarnModule Addresses: [0x3BDb857AFe9b51d8916D80240d2ADe40D4d3f2f9](https://optimistic.etherscan.io/address/0x3BDb857AFe9b51d8916D80240d2ADe40D4d3f2f9#code) Safe module used for Fluidkey auto-earn. Authorized relayers can deposit tokens into the vault selected by the Safe's configuration hash, with vault shares credited to that Safe. The module owner publishes configurations, but selecting a different hash requires a call from the Safe. * Roles: * **authorizedRelayers**: EOA 7 * **owner**: Fluidkey Earn Owner