KNIGHTPRO

KNIGHT SHIELD WALLET · PRO

For people who do care about crypto.

A self-custodial Midnight wallet for users who want to see — and control — what is happening underneath.

PRO is Midnight-native and security-first: real wallet state, shielded and unshielded roles, contract-backed @username routing and a local encrypted seed vault. It is an expert surface, not a trading floor — no charts, no tickers, no market theatre.

  • NIGHT
  • DUST
  • SHIELDED / PUBLIC
  • SAFESEND
  • STAKING ROADMAP

Every capability below is labelled LIVE, WIRED, MOCK or ROADMAP against the current wallet build. This page explains the product; it is not the wallet application.

Still You? — continuity

COMING SOON

Knight Verify is designed to confirm identity continuity after a replaced phone, a restored wallet or a new device — before access continues. A generic passkey proves device control; this proves continuity. It is not implemented in the current wallet build.

Section 01

Midnight-native core

The wallet builds itself from your seed and talks to Midnight directly.

Self-custody

LIVE

The wallet is built from your own seed on your own device. It is not a connector wrapper around someone else's wallet, and the seed never leaves the device for our backend.

Shielded + unshielded NIGHT

LIVE

The HD wallet derives shielded, unshielded and DUST roles. PRO surfaces the private (shielded) and public (unshielded) split instead of collapsing it into one number.

DUST roles

WIRED

DUST keys are derived as part of the Midnight role architecture, and the backend can sponsor DUST for a new user's first SafeSend registration when the wallet has none. Staking-generated DUST is not live.

Real wallet state

LIVE

Balances and transaction history come from Midnight wallet state, not from a local simulation.

Network awareness

WIRED

Preview, preprod and mainnet endpoint configurations exist. Preview is the currently exercised target.

Installable PWA

LIVE

Mobile-first installable progressive web app architecture, built to behave like an application rather than a browser tab.

Where DUST actually stands

WIREDROADMAP
  • Today: the wallet derives a DUST role and key as part of its Midnight role architecture, and the backend can sponsor DUST for a new user's first SafeSend registration.
  • Not today: staking and DUST self-sufficiency are advanced roadmap direction and retained legacy prototype work. They are not current wallet behaviour.
  • We do not publish generation rates or yield figures. Older planning numbers are historical material, not network truth.

Section 02

SafeSend + proof infrastructure

Human-readable routing backed by a Compact contract, with proof infrastructure in place. Username operations are live; money movement is not.

@username routing

LIVE

Send to a human-readable @username instead of forcing raw addresses. Claim and lookup run through Midnight Compact circuits: register_routing_details, resolve and is_username_registered.

Proof infrastructure

WIRED

SafeSend ZK artifacts and prover/verifier configuration are present, and the PWA uses a Midnight proof server as part of the architecture.

First-registration DUST sponsorship

WIRED

A new wallet with no DUST can have its first SafeSend registration sponsored by the backend so identity claim is not blocked on day one.

Transfer execution

MOCK

Recipient resolution is real. Actual money movement still uses a local mock — no funds move on any network today.

Section 03

Pro controls

What PRO reveals that the default Knight experience deliberately hides.

NIGHT balance detail

LIVE

PRO shows NIGHT balances directly rather than a single simplified amount.

Private vs public split

LIVE

Shielded (private) and unshielded (public) holdings are shown separately so you always know which side you are spending from.

Raw addresses

LIVE

Raw receiving addresses are exposed in PRO for users who want to verify or copy them directly.

Receive options

LIVE

The PRO receive flow offers @username, Private and Public receiving choices. QR receive is a preview aid, not production network scanning.

Transaction technical detail

WIRED

Where the current interface exposes them, transaction identifiers and technical detail are visible instead of hidden.

Fiat / NIGHT rate

MOCK

The displayed conversion rate is a mock value. Do not treat it as market data.

Section 04

Security model

Key material stays on the device. The architecture is written down here in full because PRO users should be able to check it.

Local encrypted seed vault

LIVE

The seed is encrypted on-device with AES-GCM and stored in the device vault. The backend never sees it.

Passcode-derived wrapping

LIVE

Vault keys are wrapped using material derived from your passcode, so possession of the device alone is not enough.

WebAuthn PRF biometric path

LIVE

Optional biometric unlock uses a WebAuthn PRF key path, enabled only when the authenticator genuinely supports it.

Encrypted backup and restore

LIVE

Backup and restore covers the vault, SafeSend identity, wallet state and payment history, encrypted end to end.

Auto-lock and passcode change

LIVE

The wallet auto-locks, and the passcode can be rotated without rebuilding the wallet.

Device erase

LIVE

A deliberate device-erase path removes local wallet material from the device.

Legacy Vault

MOCK

Legacy Vault in the current build is interface only. No contract is connected.

Section 05

Advanced Midnight roadmap

Direction and retained prototypes. Nothing in this section is live, and no yield, rate, generation figure or date is being claimed.

NIGHT Staking

LEGACY PROTOTYPE

A StakingManager prototype (stake, unstake, timelock checks, stake info, reward estimation) and a Compact staking prototype with staked balances, timestamps, total staked, configurable lock period and reward-rate fields exist in the earlier wallet repository. That architecture is retained but is not wired into the current wallet.

DUST Self-Sufficiency

ROADMAP

An advanced Midnight economics direction. Older documentation described DUST self-sufficiency; those figures are historical planning material, not current network truth.

Expanded NIGHT Controls

ROADMAP

Deeper token-native controls beyond the current PRO balance split.

Multi-token / Swap Layer

ROADMAP

Multi-token support and swaps were planned for a later advanced-wallet release. They are not current functionality.

Current truth

  • Sending money is mock — recipient resolution is real, transfer execution is not.
  • The fiat / NIGHT display rate is mock.
  • Legacy Vault is interface only; no contract is connected.
  • QR receive is a preview aid, not production network scanning.
  • Staking is not present in the current wallet build.

Want the plain-language version instead? Knight is the same wallet with the crypto mechanics deliberately kept out of the way.