# Overview

QSafe Quantum-Secure Crypto Wallet is a secure, multi-chain wallet that supports Quranium Chain, a blockchain that combines EVM compatibility with quantum-securecryptography.&#x20;

Key features:

* **SLHDSA Signatures:** Quranium chain uses post-quantum secure digital signatures. SLHDSA (Stateless Hash-Based Digital Signature) is a **NIST-standardized post-quantum cryptographic algorithm** that secures transactions on Quranium Chain. Unlike traditional ECDSA (used by Ethereum or Bitcoin), SLH-DSA relies on hash functions instead of elliptic curves, making it resistant to quantum attacks. When you send **QRN coins** on Quranium Chain, your transaction is signed using SLHDSA, ensuring quantum-safe validation.
* **ML-KEM Encryption:** ML-KEM (Module Lattice-Based Key Encapsulation Mechanism) is a **post-quantum encryption standard** used to secure your wallet backups. It ensures your recovery phrase and private keys remain safe even if quantum computers become mainstream.
* **Cross-Chain Support:** QSafe manages all chains from one wallet, with distinct security profiles for each network. And different address derivation methods for all the networks, ensuring compatibility with Quranium network, EVM networks, Bitcoin and Solana.
* **User-Friendly Interface:** The wallet features an intuitive interface for both beginners and advanced users, offering easy access to essential functionalities like sending & receiving of QRN Coins.

### Getting Started

Follow these steps to set up your wallet, secure your assets, and start using the Quranium Chain.

**1. Installation**

**Supported Platforms**:

* **Desktop**: Windows, macOS, Linux (Chrome/Firefox extension)

**Steps**:

1. Visit the [QSafe Wallet](https://chromewebstore.google.com/detail/opnnmgopaggjpapnoknbphfpjfadbddc?utm_source=item-share-cb).
2. Download the extension for your browser or OS.
3. Follow the installation prompts.

**2. Create a New Wallet**

**Step 1: Generate a Recovery Phrase**

* On the welcome screen, click **Create a New Wallet**.
* Write down the **12/24-word recovery phrase** and store it offline.
  * ⚠️ **Never share this phrase** – it controls access to your SLH-DSA and ML-KEM keys.

**Step 2: Set a Password**

* Create a strong password to encrypt your wallet locally.
* This password is required to unlock the wallet and sign transactions.

**3. Enable Quranium Chain (QL1EVM)**

QSafe Wallet automatically creates a Quranium account with quantum-safe keys:

* **SLH-DSA Key**: Used for signing transactions.
* **ML-KEM Key**: Used for encrypting backups.

**To Add More Quranium Accounts**:

1. Go to **Settings → Networks → Quranium Chain**.
2. Click **Add Account** – new keys are derived from your recovery phrase.

**4. Send Your First Transaction**

**On Quranium Chain**:

1. Click **Send** from the dashboard.
2. Enter the recipient’s Quranium address (`0x...`).
3. Specify the amount and gas fees.
4. Confirm and send.

**5. Restore a Wallet**

**From Recovery Phrase**:

1. Open QSafe Wallet and click **Import Wallet**.
2. Enter your 12/24-word phrase.
3. Set a new password.


# FAQs

Find answers to common questions about QSafe Wallet and its quantum-resistant features.

1. **What is QSafe Wallet?**\
   QSafe Wallet is a next-generation cryptocurrency wallet that combines **EVM compatibility** with **post-quantum cryptography** . It supports multiple blockchains including Quranium Chain (a quantum-safe EVM chain), Ethereum, Polygon, Bitcoin, Solana, and more.
2. **Is QSafe Wallet open-source?**\
   Yes, QSafe Wallet is built using open-source libraries and tools. The core components are publicly available for review and auditing.
3. **Can I use QSafe Wallet on mobile devices?**\
   Currently, it’s available as a browser extension. Mobile app support is under development.
4. **Does QSafe Wallet store any of my data on servers?**\
   No. QSafe Wallet is **non-custodial** , meaning all private keys, mnemonics, and encrypted data remain on your device. No user data is stored on remote servers.
5. **Who developed QSafe Wallet?**\
   QSafe Wallet was developed by Quranium product team.
6. **Can I use QSafe Wallet without internet access?**\
   You can view balances and manage accounts offline, but sending transactions or interacting with DApps requires an internet connection.
7. **What operating systems does QSafe Wallet support?**\
   It works on **Windows, macOS, and Linux** , and integrates with major browsers like Chrome and Firefox.
8. **How do I contact QSafe Wallet support?**\
   You can reach out via the official website, GitHub repository, Discord server, or community forums.
9. **Is QSafe Wallet free to use?**\
   Yes, the wallet is free. However, you may incur network fees (gas) when transacting on supported blockchains.
10. **Can I run QSafe Wallet in a private browser mode?**\
    Yes, but note that local storage (e.g., session tokens) will be cleared when the window closes.
11. **What makes QSafe Wallet quantum-safe?**\
    It uses **SLHDSA** for signing and **ML-KEM** for encryption — both NIST-standardized post-quantum algorithms that protect against future threats from quantum computing.
12. **What is SLHDSA and how is it used?**\
    SLHDSA (Stateless Hash-Based Digital Signature Algorithm) is used for signing transactions on **Quranium Chain** . Unlike ECDSA, it doesn’t rely on elliptic curves but on hash functions, making it resistant to quantum attacks.
13. **What is ML-KEM and how does it work?**\
    ML-KEM (Module Lattice-Based Key Encapsulation Mechanism) is used to encrypt backups and sensitive data. It combines lattice-based cryptography with symmetric encryption for hybrid security.
14. **Are my private keys ever exposed to the internet?**\
    No. Your private keys never leave your device unless explicitly exported. They are only used in memory during signing operations.
15. **Can I export my ML-KEM private key?**\
    Yes, but only manually and at your own risk. Always store exported keys securely.
16. **Why is post-quantum security important now?**\
    Although quantum computers aren't widely available yet, they could one day break traditional cryptographic algorithms like ECDSA and RSA. Using post-quantum methods ensures long-term safety.
17. **Can I verify that my backup is encrypted with ML-KEM?**\
    Yes. Encrypted backups are stored in a JSON format containing a **capsule** , **symmetric ciphertext** , and **nonce** , all generated using ML-KEM.
18. **What happens if I lose my password?**\
    If you lose your password and don’t have a recovery phrase or ML-KEM key, you will not be able to unlock your wallet or decrypt your mnemonic.
19. **Is there a way to test quantum-resistant features?**\
    Yes, you can interact with **Quranium Testnet** or simulate transactions in dev environments to test SLH-DSA and ML-KEM functionality.
20. **Do I need to understand quantum physics to use QSafe Wallet?**\
    No. You just need to follow standard wallet best practices (e.g., securing your mnemonic, keeping backups safe). The post-quantum features operate behind the scenes.
21. **How do I back up my wallet?**\
    Go to **Settings > Backup & Restore** , select the account, confirm your password, and save the encrypted file securely.
22. **Where are backups stored?**\
    Encrypted backups are stored locally or uploaded to cloud services. The wallet itself does not store them.
23. **Can I restore from a backup without the password?**\
    No. The backup is encrypted using a password-derived key. Without the correct password, decryption fails.
24. **What should I do if I forget my password?**\
    Unfortunately, you’ll lose access to your wallet and backups unless you remember the password or have a written copy of your mnemonic.
25. **How often should I back up my wallet?**\
    Back up your wallet whenever you create a new account or change your password.
26. **Can I import a backup into another wallet?**\
    No. Backups are specific to QSafe Wallet and cannot be imported into other wallets due to their post-quantum encryption structure.
27. **What does a backup contain?**\
    A backup contains:

* Encrypted mnemonic
* Account metadata
* Public keys
* Derivation paths

28. **Can I recover just one account from a backup?**\
    Yes. You can selectively restore individual accounts using the backup system.
29. **What happens if my backup file gets corrupted?**\
    Try restoring from another backup. If none exist, you'll need to use your mnemonic to recreate the wallet.
30. **Can I share my backup with someone else?**\
    Only if you fully trust them. Anyone with the backup and password can access your funds.
31. **How do I send crypto using QSafe Wallet?**\
    Click "Send", enter the recipient address, amount, and confirm the transaction using your password or hardware wallet.
32. **What networks are supported for transactions?**\
    QSafe Wallet supports:

* Quranium Chain (SLHDSA)
* Ethereum, Polygon, BSC, etc. (ECDSA)
* Bitcoin
* Solana
* Polkadot (Substrate)

33. **Why do I get an error when trying to send on EVM chains?**\
    This usually occurs when using an SLHDSA account on an EVM chain. Ensure you're using an ECDSA-based account for Ethereum-compatible networks.
34. **What is gas and why do I need it?**\
    Gas is the fee paid to miners or validators to process your transaction on a blockchain. On EVM chains, it's paid in ETH or the native token.
35. **Can I set custom gas prices?**\
    Yes. Use the gas price slider (`Economy/Fast/Fastest`) or manually adjust values in advanced settings.
36. **What is a nonce?**\
    A nonce is a counter used to prevent double-spending. Each transaction must have a unique nonce.
37. **What happens if a transaction fails?**\
    The transaction is recorded as failed in your activity log. Gas fees are still charged because resources were used.
38. **Can I cancel a pending transaction?**\
    No, once submitted to the network, a transaction cannot be canceled. You can try replacing it with a higher gas price.
39. **How do I check transaction status?**\
    View your transaction in the Activity tab. Click the transaction hash to see details on the respective blockchain explorer.
40. **Why did my transaction take so long to confirm?**\
    Low gas price or network congestion can delay confirmation. Try increasing the gas price next time.
41. **Can I swap tokens inside QSafe Wallet?**\
    Yes, QSafe Wallet has an integrated swap interface that connects to decentralized exchanges (DEXs).
42. **Which DEXs does QSafe Wallet integrate with?**\
    It currently integrates with Uniswap, SushiSwap, QuickSwap, and others across supported chains.
43. **Can I use QSafe Wallet with MetaMask-supported DApps?**\
    Yes. QSafe Wallet provides a compatible Ethereum provider object that most DApps recognize.
44. **Why am I seeing a slippage warning?**\
    Slippage is the difference between the expected and actual price of a trade. A high slippage means the price moved significantly during execution.
45. **What is the minimum swap amount?**\
    Minimum amounts vary depending on the token and exchange. Check the DApp interface for details.
46. **Can I approve unlimited token spending?**\
    Yes, but we recommend setting a finite allowance to reduce risk.
47. **Why does a DApp ask for access to my wallet?**\
    DApps request permission to read your balance and sign transactions. Never grant access to untrusted apps.
48. **Can I revoke permissions for a DApp?**\
    Yes, go to **Settings > Connected Sites** and click “Revoke” next to the DApp name.
49. **Why is my approval still active after closing the app?**\
    Approvals are stored on-chain. You must manually revoke them to remove access.
50. **Can I use QSafe Wallet with yield aggregators or DeFi protocols?**\
    Yes, as long as the protocol is deployed on a supported chain and uses standard interfaces (ERC-20, ERC-721, etc.).
51. **How does QSafe Wallet generate private keys for Quranium Chain?**\
    Private keys are derived from the mnemonic using BIP-39 entropy and hashed via SHAKE256 to produce deterministic SLHDSA key pairs.
52. **What signing algorithm is used for Quranium Chain transactions?**\
    SLHDSA (Stateless Hash-Based Digital Signature Algorithm), a NIST-standardized post-quantum signature scheme.
53. **How is the public key derived in QSafe Wallet?**\
    For SLHDSA, the public key is generated during key generation and stored as a hex string. It's used to derive the wallet address.
54. **What hashing function is used in SLHDSA signing?**\
    SHAKE256, an extendable-output function (XOF) from the SHA-3 family.
55. **How is the transaction hash computed before signing?**\
    Keccak-256 is used to hash the transaction data before signing it with the SLHDSA private key.
56. **Can I sign raw transaction data manually using QSafe Wallet?**\
    Yes, advanced users can input RLP-encoded transaction data and sign it directly using the `signRaw` method.
57. **What format does the signed transaction return in?**\
    The signed transaction is returned in RLP-encoded format, prefixed with `0x`.
58. **Does QSafe Wallet support EIP-1559 for gas estimation?**\
    Yes, it fully supports EIP-1559 for networks that use fee market transactions (e.g., Ethereum, Optimism).
59. **What libraries are used for cryptographic operations in QSafe Wallet?**

* `@noble/post-quantum/slh-dsa` for post-quantum signatures
* `@noble/post-quantum/ml-kem` for encryption
* `ethereumjs/tx` for EVM transaction handling

60. **How is the SLHDSA signature length validated?**\
    The wallet checks if the signature buffer length is exactly 49,856 bytes, which is required by SLH-DSA-128.
61. **Is there a fallback mechanism for failed signature validation?**\
    No. Invalid signatures throw an error to prevent malformed or malicious transactions from being submitted.
62. **How is the ML-KEM public key used in backups?**\
    It’s used to encapsulate a shared secret, which is then used to encrypt the symmetric payload using XSalsa20-Poly1305.
63. **What happens if I lose my ML-KEM private key?**\
    You won’t be able to decrypt any encrypted backups or sensitive data stored in the wallet.
64. **Are ML-KEM and SLHDSA interchangeable in QSafe Wallet?**\
    No. SLHDSA is used for signing transactions, while ML-KEM is used only for backup encryption.
65. **Can I export both SLHDSA and ML-KEM keys together?**\
    Yes, but they must be exported separately and stored securely.
66. **How does QSafe Wallet handle multi-chain account derivation?**\
    Each chain uses its own derivation path (BIP-44 compliant), ensuring deterministic account generation across chains.
67. **What happens when you switch between networks in the wallet?**\
    The wallet loads the correct signer (ECDSA or SLHDSA) and network-specific RPC endpoints.
68. **Can I use the same mnemonic for multiple wallets?**\
    Yes, but each wallet may derive accounts differently based on their derivation paths and signing algorithms.
69. **How are transaction nonces handled in QSafe Wallet?**\
    Nonces are fetched from the latest block and incremented automatically per transaction.
70. **Is nonce manipulation possible in QSafe Wallet?**\
    Advanced users can manually override the nonce value in developer mode.
71. **How is the gas limit estimated for a transaction?**\
    Using `web3.eth.estimateGas()` for most EVM-compatible chains. Overrides are allowed for manual tuning.
72. **Why do some transactions fail even with high gas limits?**\
    Gas estimation is not always accurate due to dynamic contract behavior or reentrancy issues.
73. **Can I set custom gas price values?**\
    Yes, the wallet allows setting custom maxFeePerGas and maxPriorityFeePerGas values.
74. **How is the final signed transaction broadcasted?**\
    Using `eth_sendRawTransaction` over HTTP-RPC to the selected network node.
75. **Can I monitor pending transactions inside the wallet?**\
    Yes, all sent transactions appear in the Activity tab until confirmed or failed.
76. **What tools are available for transaction debugging?**\
    The wallet logs raw transaction data, signature lengths, and error messages for troubleshooting.
77. **How does the wallet handle failed transaction receipts?**\
    Failed transactions are marked as "Failed" in the activity log, and the user is alerted.
78. **Is replay protection built into the wallet?**\
    Yes, each transaction has a unique nonce, preventing accidental replays.
79. **How is the wallet integrated with blockchain explorers?**\
    After a successful transaction, the wallet provides a link to the corresponding explorer page.
80. **Can I view the serialized transaction before sending?**\
    Yes, in developer mode, the full RLP-serialized transaction is visible for inspection.
81. **What role does the recovery ID play in ECDSA signing?**\
    The recovery ID (`v`) determines which public key corresponds to the private key used for signing.
82. **Why is the y-parity field important in EVM transactions?**\
    It ensures the correct public key is recovered from the signature and must be either 0 or 1.
83. **Can I use SLHDSA signatures on EVM chains?**\
    No. EVM nodes expect ECDSA signatures. Using SLHDSA results in rejection with errors like "invalid y-parity".
84. **How does the wallet distinguish between ECDSA and SLHDSA accounts?**\
    Each account stores metadata indicating its signing type (`signerType`), used to select the appropriate signer.
85. **What happens if I try to send ETH using an SLHDSA account?**\
    The transaction will fail because the Ethereum node cannot validate the SLHDSA signature.
86. **Can I convert an ECDSA account to an SLHDSA account?**\
    No. These are separate derivation paths and signing mechanisms. You must create a new account.
87. **How are transaction hashes verified after submission?**\
    The wallet polls the network for the transaction receipt and displays the result once received.
88. **Is there a way to simulate transactions without broadcasting them?**\
    Yes, using the “Preview” feature, the wallet shows expected outcomes without submitting to the network.
89. **What happens if a transaction is dropped from the mempool?**\
    It appears as "Failed" in the activity log, and the user must resend with higher fees.
90. **How are transaction confirmations tracked?**\
    By polling the network at regular intervals and updating status in the UI.
91. **Can I cancel a pending transaction?**\
    No, but you can replace it by resubmitting with a higher gas price.
92. **What is the purpose of the session token in QSafe Wallet?**\
    It keeps the wallet unlocked temporarily during transaction signing without requiring repeated password entry.
93. **How long is the session token valid?**\
    Typically 5 minutes, after which the wallet auto-locks for security.
94. **Is there a timeout for transaction signing?**\
    Yes. If signing takes too long (e.g., due to slow hardware), the process aborts to avoid hanging.
95. **How does the wallet ensure cross-chain compatibility?**\
    By abstracting signing logic behind a unified interface and allowing network-specific overrides.
96. **Can I reuse a signed transaction across different networks?**\
    No. Each network has a unique chainId, making transactions incompatible across chains.
97. **What is the difference between legacy and EIP-1559 transactions?**\
    Legacy uses a single gasPrice, while EIP-1559 separates baseFee and tip (priority fee).
98. **How does QSafe Wallet handle chain upgrades like London or Cancun?**\
    By dynamically detecting the network and applying the correct transaction format and gas rules.
99. **Can I manually specify the chainId for a transaction?**\
    Yes, in advanced settings, users can override the default chainId for testing or custom networks.
100. **How does the wallet handle multisig or contract interactions?**\
     It treats them like standard transactions, showing decoded ABI data where available.
101. **Why am I getting 'insufficient funds for gas \* price + value' even with balance?**\
     This usually occurs when using an SLH-DSA account on an EVM chain. Ensure you're using an ECDSA-based account.
102. **What causes a 'nonce too low' error?**\
     Trying to reuse a nonce that has already been mined.
103. **What does 'replacement transaction underpriced' mean?**\
     You tried to replace a pending transaction, but the new one doesn't pay enough gas.
104. **Why does my transaction say 'out of gas'?**\
     The provided gas limit was insufficient to complete execution, often due to complex smart contract logic.
105. **What is a 'reverted' transaction?**\
     A transaction that failed during execution, often due to a contract condition or invalid call data.
106. **How do I fix 'intrinsic gas too low' errors?**\
     Increase the gas limit slightly above the minimum required for the transaction.
107. **What is the 'baseFeePerGas' and why does it matter?**\
     It's the minimum gas price set by the network. Transactions below this are rejected.
108. **Why did my swap fail with 'slippage too high' warning?**\
     The price moved more than your slippage tolerance allowed during execution.
109. **How do I debug a failed DApp interaction?**\
     Check the transaction receipt for revert reasons or decode the contract logs.
110. **What is a 'contract execution reverted' error?**\
     The called contract threw an exception, often due to invalid parameters or insufficient permissions.
111. **Why do some transactions get stuck in 'Pending' state?**\
     Low gas prices cause miners to ignore the transaction; increase gas price to speed it up.
112. **How do I force-cancel a stuck transaction?**\
     Send a 0-value transaction with the same nonce and higher gas price to overwrite it.
113. **What is a 'transaction underpriced' error?**\
     Your transaction gas price is too low compared to current network conditions.
114. **Why does the wallet sometimes show 'Invalid to address'?**\
     The recipient address may be invalid or improperly formatted (e.g., missing '0x').
115. **What is a 'non-contract account called' error?**\
     Occurs when trying to interact with an externally owned account (EOA) as if it were a contract.
116. **Why does my token transfer show 'Approve' instead of 'Transfer'?**\
     Some tokens require approval before transferring, especially ERC-20 tokens.
117. **What is the 'max priority fee too low' error?**\
     Your transaction's tip is below the network’s minimum required for inclusion.
118. **Why does my transaction keep failing with 'Reverted' on Polygon?**\
     Polygon uses fast-finality, so invalid contracts or approvals trigger immediate reverts.
119. **What should I do if I accidentally sent funds to the wrong network?**\
     Use a cross-chain bridge if supported. Otherwise, contact the receiving chain’s support team.
120. **Why does the wallet show 'Not enough POL to pay the network fee'?**\
     You’re using a POL-based network (e.g., Polygon), and your POL balance is too low to cover gas.
121. **What is the difference between 'Economy', 'Fast', and 'Fastest' gas options?**

* Economy: Low fees, slower confirmation
* Fast: Balanced fees
* Fastest: Highest fees, fastest mining

122. **Why does the gas cost keep fluctuating?**\
     Gas prices depend on network congestion and base fee changes (especially on EIP-1559 chains).
123. **What is a 'failed' transaction in the activity log?**\
     It means the transaction was submitted but rejected by the network.
124. **Can I recover gas fees from a failed transaction?**\
     No. Gas is paid regardless of success because resources were used to process the transaction.
125. **What is the 'Transaction Not Found' error?**\
     The transaction hasn’t been mined yet or was dropped from the mempool.
126. **Why does the wallet say 'Invalid decimals for \[token]'?**\
     The entered amount exceeds the token’s decimal precision (e.g., 18 for ETH).
127. **What does 'User rejected transaction' mean?**\
     You canceled the transaction before signing.
128. **How do I check transaction details after submission?**\
     Click the transaction hash in the Activity tab to open it on the relevant blockchain explorer.
129. **What is the 'Insufficient allowance' error?**\
     The DApp doesn’t have permission to spend the token you're trying to send.
130. **Why is my approval still active after closing the app?**\
     Approvals are stored on-chain. You must manually revoke them to remove access.
131. **How do I revoke token allowances?**\
     Use the Revoke feature in the DApp Permissions section.
132. **What is a 'Bad instruction' error?**\
     Usually caused by invalid bytecode execution or corrupted contract calls.
133. **What is 'Execution reverted without reason'?**\
     The contract threw an error without providing a revert message.
134. **Why do I see 'Only external accounts may initiate transactions'?**\
     You tried to send a transaction from a contract account, which isn’t allowed.
135. **What does 'Exceeds block gas limit' mean?**\
     The gas limit you set is higher than what the current block can accept.
136. **What is a 'Transaction with the same hash was already imported'?**\
     You attempted to resubmit a transaction that's already in the mempool.
137. **Why does the wallet warn about 'High Slippage'?**\
     To alert you that the trade price could move significantly before execution.
138. **What is a 'Missing revert data' error?**\
     The transaction failed, but no revert reason was included in the response.
139. **What is a 'Transaction already in the pool' error?**\
     The transaction has already been submitted and is waiting to be mined.
140. **What is 'Too many requests' when connecting to a provider?**\
     You’ve exceeded the rate limit of the RPC provider.
141. **Why does the wallet sometimes show 'Unknown Error'?**\
     If the provider returns an unhandled error, the wallet falls back to a generic message.
142. **What is 'Out of bounds' in transaction data?**\
     The encoded calldata contains out-of-range values.
143. **What does 'Call failed' mean?**\
     An internal call within the transaction failed, typically due to contract logic.
144. **Why does the wallet show 'Invalid chain ID'?**\
     You’re trying to send a transaction to a network with a mismatched chain ID.
145. **What is 'Transaction timed out'?**\
     The transaction wasn’t mined within the expected time window.
146. **Why does the wallet sometimes freeze during signing?**\
     Large computations (like SLH-DSA signing) can take time and block the UI thread.
147. **What is a 'Dust attack' warning?**\
     Someone sent a tiny amount of tokens to your wallet to identify your address.
148. **Why do I get 'Signer not found' when trying to sign?**\
     The wallet couldn't find the correct signing method for the selected network.
149. **What is 'Data too large' in transaction data?**\
     The calldata size exceeds the maximum allowed by the network.
150. **Why does the wallet show 'Could not estimate gas'?**\
     The transaction would likely fail, so the network refuses to provide an estimate.
151. **How does QSafe Wallet protect against phishing attacks?**\
     It warns users when interacting with unknown or suspicious domains.
152. **What is a secure way to store backups?**\
     Store them in offline storage (e.g., USB drive, cold storage) and encrypt them with a strong password.
153. **Can I use biometric authentication for signing?**\
     Yes, on supported devices, you can enable fingerprint or facial recognition for signing.
154. **How often should I rotate my private keys?**\
     Never unless necessary — rotating increases risk. Use strong backups instead.
155. **What is the safest way to verify an address?**\
     Use checksum addresses (EIP-55) and double-check the last few characters.
156. **How does QSafe Wallet prevent brute-force attacks?**\
     Encrypted backups use PBKDF2 with high iteration counts to slow down attackers.
157. **What happens if someone gets my public key?**\
     Nothing — the public key is safe to share and cannot be used to derive the private key.
158. **What is a zero-day vulnerability and how does QSafe Wallet mitigate it?**\
     Zero-days are unknown exploits. QSafe Wallet mitigates risk through code audits and prompt updates.
159. **Can I import a compromised mnemonic into QSafe Wallet?**\
     Technically yes, but it's not recommended. Always assume compromised mnemonics are unsafe.
160. **What is a side-channel attack and how is it prevented?**\
     Side-channel attacks exploit timing or memory leaks. QSafe Wallet uses constant-time signing functions.
161. **How does the wallet handle memory cleanup?**\
     Sensitive data is cleared from memory after signing or locking the wallet.
162. **What is a cold wallet and how is it different?**\
     A cold wallet is never connected to the internet, unlike QSafe Wallet, which is hot.
163. **Can I use QSafe Wallet on public Wi-Fi?**\
     Yes, but avoid logging in or approving transactions on insecure networks.
164. **How does QSafe Wallet detect fake RPCs?**\
     It validates known network identifiers and blocks unrecognized ones.
165. **What is a rogue DApp and how can it harm me?**\
     A rogue DApp may request excessive permissions or execute malicious code.
166. **How do I know if a DApp is trustworthy?**\
     Stick to well-known DApps with open-source code and verified contracts.
167. **What is a replay attack and how is it prevented?**\
     A replay attack resubmits a valid transaction. QSafe Wallet prevents this by incrementing nonces.
168. **What is a front-running attack and how can I avoid it?**\
     Front-running is when bots copy your transaction. Avoid sending high-value transactions in public pools.
169. **How does QSafe Wallet prevent unauthorized access?**\
     It uses local encryption and requires password entry for every unlock or sign operation.
170. **Can I lock the wallet remotely?**\
     Not currently, but future versions may allow remote locking via linked accounts.
171. **What is the purpose of the mnemonic phrase?**\
     It acts as a seed for generating all your keys deterministically.
172. **What should I do if I suspect a breach?**\
     Immediately stop using the wallet and move funds to a new account.
173. **How do I know if a transaction was tampered with?**\
     Compare the signed hash with the one on the blockchain explorer.
174. **What is a hardware wallet and how does it improve security?**\
     A hardware wallet stores private keys offline, protecting them from software-based attacks.
175. **What is a social engineering scam and how to avoid it?**\
     Scammers trick users into sharing secrets. Never give your mnemonic to anyone.
176. **How does QSafe Wallet handle firmware updates?**\
     Updates are signed and verified before installation to prevent malicious code injection.
177. **What is a honeypot and how do I avoid it?**\
     Honeypots trap users into giving away control. Only interact with audited contracts.
178. **What is a phishing site and how can I spot one?**\
     Phishing sites mimic real interfaces. Always verify URLs and SSL certificates.
179. **How does the wallet prevent clipboard hijacking?**\
     It includes a verification step before sending to copied addresses.
180. **What is a MEV bot and how does it affect me?**\
     MEV bots extract value from your transactions. Avoid using them unless necessary.
181. **What is a flash loan attack and how is it related to DApps?**\
     Flash loans let attackers borrow and repay in one transaction. Be cautious when interacting with lending platforms.
182. **What is a Sybil attack and how does it impact my wallet?**\
     Sybil attacks involve fake identities. QSafe Wallet isn't vulnerable to this directly.
183. **How does QSafe Wallet protect against malware?**\
     It avoids storing private keys in plain text and clears memory after use.
184. **What is a seed vault and how does it work?**\
     A seed vault is a secure location for storing mnemonics. QSafe Wallet doesn’t store seeds directly.
185. **What is a 51% attack and how does it affect me?**\
     A 51% attack allows attackers to reverse transactions. QSafe Wallet assumes the network is honest.
186. **What is a reentrancy attack and how does it affect DApps?**\
     Reentrancy lets contracts recursively call other contracts. QSafe Wallet doesn’t execute contract calls.
187. **What is a sandwich attack and how can I avoid it?**\
     Sandwich attacks manipulate trades. Use trusted DEXs and avoid high-slippage swaps.
188. **How does QSafe Wallet protect against keylogging?**\
     It encourages using hardware wallets and clearing session tokens after use.
189. **What is a quantum attack and how is QSafe Wallet prepared?**\
     Quantum computers could break ECDSA. QSafe Wallet uses post-quantum algorithms to stay ahead.
190. **What is a downgrade attack and how is it prevented?**\
     Downgrade attacks trick clients into using older, weaker protocols. QSafe Wallet enforces modern standards.
191. **What is a man-in-the-middle attack and how is it prevented?**\
     MITM attacks intercept communication. QSafe Wallet uses HTTPS and secure signing methods.
192. **What is a dusting attack and how do I respond?**\
     Attackers send tiny amounts to track wallets. QSafe Wallet alerts users about unusual small transfers.
193. **What is a rug pull and how do I avoid it?**\
     Rug pulls occur when developers abandon projects. Only interact with audited and community-trusted DApps.
194. **How does the wallet handle phishing attempts via DApps?**\
     It verifies domain names and warns users before granting permissions.
195. **What is a spoofed transaction and how to detect it?**\
     Spoofed transactions mimic real ones. Always verify the transaction hash and sender.
196. **What is a honeypot DApp and how do I avoid it?**\
     Honeypot DApps trap users into giving up control. Stick to known, trusted DApps.
197. **How does QSafe Wallet handle insecure RPC connections?**\
     It validates known RPCs and warns users when connecting to unknown ones.
198. **What is a whale attack and how do I avoid it?**\
     Whales can manipulate prices. Avoid trading on illiquid markets.
199. **How does QSafe Wallet protect against supply chain attacks?**\
     All dependencies are pinned and checked for integrity using subresource integrity (SRI).
200. **What is a dependency confusion attack and how is it avoided?**\
     QSafe Wallet uses strict package-lock files and avoids ambiguous dependency names.


# Account Creation in Wallet

### 1. **Mnemonic Setup**

When you first create a wallet, the system generates a **12-word or 24-word recovery phrase** , following the **BIP-39 standard** .

#### Why Mnemonics Matter:

* Acts as the **root of trust** for your wallet.
* Deterministically generates all keys (signing + encryption).
* Must be stored securely — it’s the only way to recover your wallet if lost.

### 2. **Key Generation**

Two distinct key pairs are derived from the mnemonic:

#### SLHDSA Keys (Signing)

* **Algorithm**: NIST-standardized post-quantum signature scheme.
* **Used for**: Signing transactions on **Quranium Chain** .
* **How It Works**:
  * The mnemonic is converted into entropy using `mnemonicToEntropy`.
  * This entropy is processed with **SHAKE256** (an extendable-output function from SHA-3 family) to produce a 96-byte seed.
  * The seed is fed into `slh.slh_dsa_shake_256f.keygen` to generate the **SLH-DSA key pair** .

#### ML-KEM Keys (Encryption)

* **Algorithm**: Lattice-based post-quantum encryption scheme.
* **Used for**: Securely encrypting backups, messages, and sensitive data.
* **How It Works**:
  * The same mnemonic is used to derive a **seed** via BIP-39 (`mnemonicToSeed`).
  * A 64-byte seed is generated using **SHAKE256** .
  * The seed is passed to `ml_kem768.keygen`, which produces an ML-KEM public/private key pair.

3. Address Derivation:

* Once the **SLHDSA public key** is generated, it is used to derive a blockchain address compatible with Quranium Chain.&#x20;
* Relevant code for generating signing key pair and address :

```typescript
  async generate(mnemonic: string, derivationPath?: string): Promise<KeyPair> {
    const entropy = Buffer.from(mnemonicToEntropy(mnemonic), "hex");
    const seed96 = shake256.create({ dkLen: 96 }).update(entropy).digest();
    const keys = slh.slh_dsa_shake_256f.keygen(seed96);
    const originalPublicKey = Buffer.from(keys.publicKey);
    const strippedPubKey = originalPublicKey.subarray(1);
    const publicKeyHash = keccak256(strippedPubKey);
    const addressBytes = publicKeyHash.slice(-20);
    const address = bufferToHex(addressBytes);

    return {
      address: address.toLowerCase(),
      privateKey: bufferToHex(keys.secretKey),
      publicKey: bufferToHex(originalPublicKey),
    };
  }
```

<mark style="color:red;">**Unique Feature:**</mark>  Each account has separate keys for signing (SLHDSA) and encryption (ML-KEM).


# Quranium Chain Transaction Signing

* **How It Works:**

1. Transaction Creation:

* Users input recipient address, amount, and gas fees.
* The wallet converts values to hexadecimal and fetches dynamic gas prices from the Quranium node.

2. SLHDSA Signing:

* A 49,856-byte signature is generated using the SLH-DSA algorithm.
* The user’s public key is appended to the signature for Quranium-specific verification.

3. Transaction Structure:

* Quranium uses a RLP encoding with 7 fields (nonce, gas price, gas limit, to-address, value, data, and signature+publicKey).

```typescript
const finalTxFields = [
  hexTxData.nonce,      // Nonce (transaction count)
  hexTxData.gasPrice,   // Gas price in Wei
  hexTxData.gas,        // Gas limit
  hexTxData.to,         // Recipient address
  hexTxData.value,      // Amount in Wei
  hexTxData.data,       // Transaction data (empty for transfers)
  sig                   // Signature + Public Key
];

const rawTx = '0x' + rlp.encode(finalTxFields).toString('hex');
```

This structure ensures compatibility with Quranium nodes.

4. Broadcasting:

* The signed transaction is sent to the Quranium network for processing.

```typescript
const response = await axios.post('http://20.19.88.188:8545', {
  jsonrpc: '2.0',
  method: 'eth_sendRawTransaction',
  params: [rawTx], // Raw signed transaction
  id: 1,
});
```

* **Code Flow Summary**

1. **User Input → Transaction Data**:
   * **`addressTo`**, **`amount`**, **`gasFee`** → **`hexTxData`**.
2. **Signing**:
   * **`hexTxData`** → RLP encode + Keccak-256 → **`msgHash`** → SLHDSA signature.
3. **Final Transaction**:
   * **`signature + publicKey`** → RLP encode → **`rawTx`**.
4. **Broadcast**:
   * **`eth_sendRawTransaction`** → Quranium node.


# ML-KEM Encryption for Backups

<mark style="color:red;">**Backup Encryption Workflow (ML-KEM)**</mark>

#### **Step 1: Data Preparation**

* **Input**: Wallet data (accounts, keys, metadata) is serialized into a JSON string.
* **Hashing**: A SHA-256 hash of the JSON string is generated for integrity checks.
* **Serialization**: Data is converted to a **`Buffer`** for encryption.

#### **Step 2: ML-KEM Encryption**

* **Key Encapsulation**:
  * The recipient’s **ML-KEM public key** (stored in **`account.encryptionPublicKey`**) generates a shared secret.
  * ML-KEM’s **`encapsulate()`** function creates:
    * **Ciphertext**: Encapsulated shared secret (sent to the server).
    * **Shared Secret**: Used for symmetric encryption.
* **Symmetric Encryption**:
  * The shared secret encrypts the backup data using **XSalsa20** (or **AES-256**) for efficiency.
  * Result: A hybrid ciphertext (**`encryptedPayload`**) containing both ML-KEM ciphertext and symmetrically encrypted data.

#### **Step 3: Signature Generation (SLH-DSA)**

* **Hashing the Payload**:
  * The encrypted payload is hashed using Keccak-256 to create a fixed-size digest.
* **SLH-DSA Signing**:
  * The hash is signed using the user’s **SLH-DSA private key** (derived from their mnemonic).
  * Produces a **49,856-byte signature** for tamper-proof verification.

#### **Step 4: Cloud Storage**

* **Payload Structure**:

  ```json
  {
    "signature": "0x...", // 49,856-byte SLH-DSA signature
    "payload": "0x..."    // ML-KEM ciphertext + symmetrically encrypted data
  }
  ```
* **Server-Side Handling**:

  * Backups are stored under the user’s public key (**`account.publicKey`**).
  * The server uses SHA-256 to hash the public key for secure storage.

<mark style="color:red;">**Backup Verification:**</mark>

The server performs **security checks** before allowing access:

#### **Check 1: SLH-DSA Signature Validation**

* **Message Reconstruction**:
  * The server generates valid messages based on timestamps (e.g., **`pubkey-GET-BACKUPS-2023-09-01`**).

```tsx
const legitMessages = [  
  `${pubkey}-GET-BACKUPS-${ymdnow}`,  
  `${pubkey}-GET-BACKUPS-${ymdlb}`, // Lower bound timestamp  
  `${pubkey}-GET-BACKUPS-${ymdub}`, // Upper bound timestamp  
];  
```

* **Signature Verification**:

  * The server uses the user’s **SLH-DSA public key** to verify the signature against all possible messages.
  * Ensures the request is recent and untampered.

  ```tsx
  const valid = slh.slh_dsa_shake_256f.verify(  
    pubkeyBytes,  
    messageBuffer,  
    signature  
  );  
  ```

#### **Check 2: Ownership Proof**

* Ownership is verified through SLH-DSA signature. Since ML-KEM and SLH-DSA keys are derived from the same mnemonic, validating SLH-DSA signatures proves control over the ML-KEM private key.

```typescript
// Verify SLH-DSA signature to prove ownership of ML-KEM key
let provenOwnership = false;
for (const message of legitMessages) {
  const valid = slh.slh_dsa_shake_256f.verify(
    pubkeyBytes, // SLH-DSA public key (derived from same mnemonic as ML-KEM key)
    Buffer.from(message, "utf8"),
    byteStringToBytes(signature)
  );
  if (valid) {
    provenOwnership = true;
    break;
  }
}
if (!provenOwnership) {
  throw new HttpError(HttpStatus.BadRequest, ERROR_MESSAGE.INVALID_SIGNATURE);
}
```

<mark style="color:red;">**Backup Retrieval & Decryption**</mark>

#### **Step 1: Fetching the Backup**

* Users request backups via their public key and a timestamped signature.

  ```tsx
  const backup = await getBackup(userId);
  ```

#### **Step 2: ML-KEM Decryption**

* **Key Decapsulation**:

  * The user’s **ML-KEM private key** decrypts the ciphertext to recover the shared secret.

  ```tsx
  const sharedSecret = ml_kem.decapsulate(ciphertext, privateKey);
  ```
* **Symmetric Decryption**:
  * The shared secret decrypts the symmetrically encrypted data.

#### **Step 3: Data Reconstruction**

* The decrypted **`Buffer`** is parsed back into JSON.
* Accounts are reinitialized in the wallet.

  ```tsx
  const decryptedBackup: BackupData = JSON.parse(decryptedData.toString());
  ```


# Backup and Recovery

### 1. **Automatic Backups**

Backups are created automatically when accounts or settings are modified. These backups are **encrypted locally using ML-KEM before being uploaded** to a remote server.

#### Why ML-KEM?

* **NIST-standardized lattice-based algorithm** .
* Resistant to attacks from both classical and quantum computers.
* Used to securely encrypt sensitive data like account records and recovery information.

***

#### Encryption Flow: ML-KEM + XSalsa20-Poly1305

The wallet uses a **hybrid encryption model** :

1. A **shared secret** is generated using ML-KEM.
2. The actual data is encrypted using **XSalsa20-Poly1305** , a symmetric cipher.
3. The shared secret is then encapsulated using the recipient's **ML-KEM public key** .

```typescript
{
  "capsule": "0x...",          // ML-KEM ciphertext (encapsulated shared secret)
  "symmetricCiphertext": "0x...",  // XSalsa20-Poly1305 encrypted payload
  "nonce": "0x..."             // Random nonce used for symmetric encryption
}
```

```typescript
async encryptBackup(backupBuffer: Buffer, encryptionPublicKey: string): Promise<string> {
  const recipientPubKeyBuffer = hexToBuffer(encryptionPublicKey);

  // Step 1: Generate shared secret using ML-KEM encapsulation
  const { cipherText: capsule, sharedSecret } = ml_kem768.encapsulate(recipientPubKeyBuffer);

  // Step 2: Generate random nonce for symmetric encryption
  const nonce = crypto.randomBytes(24); // 24-byte nonce for XSalsa20

  // Step 3: Encrypt payload using XSalsa20-Poly1305
  const symmetricCiphertext = secretbox(backupBuffer, nonce, sharedSecret);

  // Step 4: Return structured JSON blob
  return JSON.stringify({
    capsule: bufferToHex(capsule),
    symmetricCiphertext: bufferToHex(symmetricCiphertext),
    nonce: bufferToHex(nonce),
  });
}
```

#### Uploading the Backup

After encryption, the backup is signed using **SLH-DSA** to ensure authenticity before upload.

```typescript
const signatureHex = await kr.sign(messageBuffer, {
  basePath: QL1evmNetworks.ql1evm.basePath,
  signerType: SignerType.slh_dsaevm,
  pathIndex: 0,
  walletType: WalletType.mnemonic,
});
```

The backup and signature are sent via an authenticated API call:

```typescript
await fetch(`${BACKUP_URL}backups/${account.publicKey}/users/${state.userId}`, {
  method: 'POST',
  headers: HEADERS,
  body: JSON.stringify({
    signature: signatureHex,
    payload: bufferToHex(Buffer.from(encryptedPayload)),
  }),
});
```

### 2. **Manual Recovery**

There are two main ways to restore a wallet:

***

#### Option A: **Recovery via Mnemonic Phrase (12/24 Words)**

**Process:**

1. User enters their **12/24-word mnemonic** during recovery.
2. The wallet regenerates:
   * **SLH-DSA signing keypair** (for Quranium Chain).
   * **ML-KEM encryption keypair** (for decrypting backups).
3. All accounts are re-created deterministically based on derivation paths.

```typescript
const entropy = Buffer.from(mnemonicToEntropy(mnemonic), "hex");
const seed96 = shake256.create({ dkLen: 96 }).update(entropy).digest();
const keys = slh.slh_dsa_shake_256f.keygen(seed96);
```

#### Option B: **Restore from Cloud Backup**

Use this option if you want to restore specific encrypted backups (e.g., saved settings or additional accounts).

**Requirements:**

* **ML-KEM Private Key** : Either regenerated from the mnemonic or exported earlier.
* **Encrypted Backup File** : Must contain the `capsule`, `symmetricCiphertext`, and `nonce`.

**Decryption Steps:**

1. Use the **ML-KEM private key** to extract the shared secret from the capsule.
2. Decrypt the symmetric ciphertext using the shared secret and nonce.

```typescript
async decryptBackup(encryptedMessageStr: string, encryptionKeypair: KeyPair): Promise<string> {
  const encryptedData = JSON.parse(encryptedMessageStr);
  const capsule = hexToBuffer(encryptedData.capsule);
  const symmetricCiphertext = hexToBuffer(encryptedData.symmetricCiphertext);
  const nonce = hexToBuffer(encryptedData.nonce);

  // Step 1: Decapsulate shared secret using ML-KEM
  const sharedSecret = ml_kem768.decapsulate(capsule, hexToBuffer(encryptionKeypair.privateKey));

  // Step 2: Decrypt symmetric data
  const decrypted = secretbox.open(symmetricCiphertext, nonce, sharedSecret);

  return bufferToHex(Buffer.from(decrypted));
}
```


# Onboarding

### Introduction

QSafe Wallet offers users a seamless and secure onboarding experience through a browser extension. Once installed, users are guided step-by-step through either creating a new wallet or restoring an existing one, with user-friendly interfaces and essential security checks.<br>

### Getting Started: Wallet Installation & Launch

After installing the QSafe Wallet extension and launching it, users are redirected to the **Onboarding Page**, where they are greeted with a simple interface containing two options:

1. **Create a New Wallet**
2. **Restore Existing Wallet**

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FKuZ415fpa3SX2beJSbrY%2Fimage.png?alt=media&amp;token=36c7cf8f-2250-4258-81b7-53fb594987fd" alt=""><figcaption></figcaption></figure>

**(i) Creating a New Wallet**

#### Step 1: Create a Password

* The first step is to **create a strong password** for protecting the wallet.
* This password is essential for accessing the wallet locally.
* ⚠️ **Important:** This password **cannot be recovered**. Users are advised to store it securely.

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FcTBsHBpUvFEuQNby6yJP%2Fimage.png?alt=media&amp;token=7775ed7a-0345-42f5-a0b3-18ee8a6ee491" alt=""><figcaption></figcaption></figure>

#### Step 2: Confirm the Password

* Users must **re-enter the password** to confirm it was typed correctly and remembered.
* This validation ensures the user is aware of the exact password used.

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FSTQTqNWgozCP2BbC7y36%2Fimage.png?alt=media&amp;token=f04339e4-6077-44af-948c-7b815eefb151" alt=""><figcaption></figcaption></figure>

#### Step 3: Mnemonic Phrase Generation

* Upon successful password creation, a **12-word mnemonic phrase** is generated.
* This is a **critical security component** for recovering the wallet in the future.
* Users are instructed to **save this phrase offline**, preferably in a secure, physical location.

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FDzWOkRShSDvhFcWPtk4N%2Fimage.png?alt=media&amp;token=2f5a70e1-e21f-4569-a18e-771946c75845" alt=""><figcaption></figcaption></figure>

#### Step 4: Mnemonic Phrase Verification

* To ensure the user has **securely stored the phrase**, a short quiz is conducted.
* Example:\
  *"Which of the following is the 9th word of your secret phrase?"*\
  Options: `Supply`, `Wire`, `Local`, `Silent`
* The user must **correctly answer** to proceed.

**Once all four steps are completed successfully**, the user is granted full access to the QSafe Wallet and its features.

### (ii) Restore an Existing Wallet

If the user has previously created a wallet and wants to restore it:

#### Step 1: Choose "Restore Existing Wallet"

* On the onboarding screen, the user selects the second option to begin the recovery process.

#### Step 2: Enter Secret Recovery Phrase

* The user is redirected to a screen with a text area.
* They must enter the **12-word mnemonic phrase** from their previous wallet setup.

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FyX8YYYnPTyxaSnLYYFXf%2Fimage.png?alt=media&amp;token=4db14237-e6c2-4616-8d63-7b0668355b0d" alt=""><figcaption></figcaption></figure>

#### Step 3: Create a New Password

* After successfully entering the phrase, the user must **set a new password** for the restored wallet.
* This password is specific to the current device/browser instance.

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2Fglab8ngPhGD5C4Kuypu0%2Fimage.png?alt=media&amp;token=274cbba7-66bd-447d-9eb2-e1717af1f91b" alt=""><figcaption></figcaption></figure>

#### Step 4: Confirm the Password

* The new password is re-entered to ensure correctness and awareness.

**Upon completing these steps**, the wallet is restored successfully, and all previously associated data (accounts, balances, activity) becomes accessible again.

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FXbhjGfnrdDDpgqunjMx3%2Fimage.png?alt=media&amp;token=840ceadd-b4f1-4411-91dd-410f8f848e29" alt=""><figcaption></figcaption></figure>

Important Notes

* The **12-word mnemonic phrase is the only way to recover the wallet**. QSafe does not store it, and it should never be shared with anyone.
* The **password only protects local access** and **cannot be recovered** if forgotten. Use secure methods to store both the password and mnemonic phrase.
* Screenshots corresponding to each step in both processes should be referenced for visual clarity (as indicated in the source text).


# Activity Section

QSafe Wallet provides a separate section for users to keep track of all the account activities, including sending, receiving tokens, contract interactions, and much more.

The image below shows the seamless, user-friendly UI for activity section functionality.

* **Address** (e.g., `0xffD5...B27`).
* **Timestamp** (e.g., "19 hours ago").
* **Status** (e.g., "Received", "Failed").
* **Amount** (e.g., `-0.0001 POL`, `$0.00022`).

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FCJAryKG3JpzGYB3y0bYd%2Fimage.png?alt=media&amp;token=5b80976d-d70c-4a87-be8e-3d71f5db343f" alt=""><figcaption></figcaption></figure>

***

#### Activity Log

This section reflects real-time account activity and transaction history.

**Key Activity Types:**

* **Received Transactions**
  * Shows incoming token amounts (e.g., `0.001 POL`)
  * Displays sender address (e.g., `0xffD5...c06B27`)
  * Timestamp of the transaction (e.g., *19 hours ago*)
  * Token value in USD (e.g., `$0.000216`)
* **Failed Transactions**
  * Clearly marked as **Failed**
  * Shows attempted amount (e.g., `-0.0001 POL`)
  * Same address, timestamp, and token equivalent in USD

***


# Add Account

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FXTpPjcEr1SwyOdU4Rd1J%2Fimage.png?alt=media&amp;token=bdbadf54-b26e-40c9-84a8-81a3d0123247" alt="" width="563"><figcaption></figcaption></figure>

QSafe provides primarily 3 ways to create/import your account.

* **Add account** – create a new wallet account.
* **Add hardware wallet account** – connect a device like Ledger or Trezor.
* **Import account from another wallet** – restore an account using a private key or recovery phrase.

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FnMzA0TIbRWSuEUD5rYdd%2Fimage.png?alt=media&amp;token=f74671bf-9236-4a35-9b32-280e530505ba" alt="" width="563"><figcaption></figcaption></figure>

This is the account creation modal for the **Polygon** network, Since Polygon is the currently selected network in the left pane, the wallet only allows adding a **Polygon-compatible** account at this moment, Since **Polygon** is the **currently selected network** . You can enter a custom name for the new account, and the "Add account" button becomes active once the name field is filled. To add an account for a **different** network, simply switch to another network from the left sidebar, and the modal will update accordingly to reflect that network's requirements.

**Key points:**

* Modal is specific to the currently selected network (e.g., Polygon).
* Allows adding only **currently selected network** accounts at this stage.
* You can enter a **custom name** for the new account.
* **"Add account"** button is enabled once the name field is not empty.
* To add an account on another network:
  * Switch to a different network from the **left sidebar**.
  * The modal will update based on that network's **compatibility and rules**.

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FdfnOO2vXy8uTLQUQtGnc%2Fimage.png?alt=media&amp;token=37cdb682-bbd0-4ead-8d3b-a6c5c45da5f9" alt="" width="555"><figcaption></figcaption></figure>

This is the **"Import account**" modal, allowing users to bring in **existing accounts** using either a **Keystore file** or a **private key**. The modal clearly warns that imported accounts won't be linked to the user's **Secret Recovery Phrase**, meaning they can only be restored in the future using the **same Keystore file or private key**. This ensures users understand the importance of securely storing these credentials.

**Key points:**

* Enables importing accounts via:
  * **Keystore file**
  * **Private key**
* Imported accounts are **not associated** with the Secret Recovery Phrase.
* To restore these accounts later, users must retain:
  * The **original Keystore file**, or
  * The **exact private key**
* Emphasizes the need for **secure backup and storage** of credentials.

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FsMdwPGmReUIkfl9AcfBJ%2Fimage.png?alt=media&amp;token=7cee5b67-f710-42b0-8c0c-5ffa4889e675" alt="" width="563"><figcaption></figcaption></figure>

This screen allows the user to add a **hardware wallet** account. It presents two supported hardware wallet options: **Ledger** and **Trezor**. The user can select their preferred device to connect and manage their accounts securely through the **physical wallet**, ensuring enhanced security for transactions and private key storage.

**Key points:**

* Lets users connect a **hardware wallet** for added security.
* **Supported devices**:
  * **Ledger**
  * **Trezor**
* Helps manage accounts while keeping **private keys offline**.
* Enhances protection against phishing, malware, and keyloggers.
* Ideal for users seeking **secure transaction signing** and **cold storage** options.


# Multichain

### Custom Network Configuration — Multi-Chain Support in QSafe Wallet

QSafe Wallet is built to be **multi-chain compatible**, offering seamless management of digital assets across a variety of blockchain ecosystems through a single intuitive interface. Whether users want to interact with **Quranium (QRN)**, **Bitcoin (BTC)**, **Solana (SOL)**, or **EVM-compatible networks** (such as Ethereum, Binance Smart Chain, Polygon, Avalanche, Fantom, etc.), QSafe provides full flexibility.

#### Add a Custom Network

In addition to the default supported networks, QSafe allows users to manually add **custom blockchain networks** by entering the required configuration details. This feature is especially useful for developers or advanced users interacting with less common or private blockchain environments.

Below is an explanation of each field in the **“Custom Network”** :

**🛠️ Fields Explained:**

1. **New RPC URL**\
   This is the URL of the **Remote Procedure Call (RPC)** endpoint for the blockchain network.\
   *Example:* `https://mainnet.infura.io/v3/YOUR-PROJECT-ID`\
   This allows the wallet to interact with the blockchain (fetch balances, send transactions, etc.).
2. **Network Name**\
   The display name for the network in the wallet.\
   *Example:* `My Custom Chain`
3. **Chain ID**\
   A unique identifier for the blockchain network.\
   *Example:* `1` for Ethereum Mainnet, `56` for BSC, `137` for Polygon.\
   Important for preventing replay attacks across chains.
4. **Currency Symbol**\
   The symbol of the native currency used on the network.\
   &#x20;*Example:* `ETH`, `BNB`, `MATIC`, etc.\
   This is shown next to balances and used in transaction amounts.
5. **Block Explorer URL (Optional)**\
   A link to the block explorer for the network, allowing users to view transactions and blocks directly from the wallet.\
   *Example:* `https://etherscan.io`\
   Optional but enhances usability.
6. **Add Network Button**\
   Once all mandatory fields are filled correctly, the **“Add network”** button becomes active. Clicking it adds the custom chain to the wallet for immediate use.

***

#### Seamless Switching Between Networks

Once added, the **Custom Network** appears in the network selector. Users can easily switch between networks. Each chain has:

* Its own account structure
* Individual balances
* Independent transaction history
* Separate dApp interaction contexts

QSafe makes **multi-chain asset management** simple and secure with a consistent user experience across all chains.

***

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FSdNy2sLN052umk5VBvZ0%2Fimage.png?alt=media&amp;token=6e65bfef-716b-419b-915d-4bd068c8ce15" alt=""><figcaption></figcaption></figure>


# Sending Transaction

* QSafe allows users to send tokens from one address to another by providing the to address, gas fees, and token address as inputs.

**Dashboard Page:**

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FT6CDNX70ws1A9zYgCa3m%2Fimage.png?alt=media&amp;token=cfc92eac-f6b3-4b32-b3dc-dc6bff33ba36" alt=""><figcaption></figcaption></figure>

**Send Page:**

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FKDD8RiZ0FXzZzEMUVJRw%2Fimage.png?alt=media&amp;token=f8bd7cdb-4ada-40a8-be13-c17ed52d4e76" alt=""><figcaption></figcaption></figure>

* After the components receive all the user-based inputs and are validated then the signing object is created and sent to the Quranium RPC for validation.

**Steps**:

1. **RLP Encoding**:

   Transaction fields (nonce, gas price, gas limit, etc.) are encoded using Recursive Length Prefix (RLP).
2. **Hashing**:

   The RLP-encoded transaction is hashed with Keccak-256 to create a digest.
3. **SLH-DSA Signing**:

   The digest is signed with the user’s **SLH-DSA private key** (derived from their mnemonic phrase).

   Generates a **49,856-byte signature** for quantum resistance.

* Quranium RPC provides the transaction hash as output, clarifying that the transaction is successful.

1. **Signature Validation**:
   * Node verifies the SLH-DSA signature against the sender’s public key.
2. **Transaction Execution**:
   * Checks gas, balance, and contract logic (if applicable).
3. **Confirmation**:
   * Returns a **transaction hash** (e.g., `0x4e3a...`) on success.
   * Triggers the success modal in the UI.

**Send Transaction**

The Send Transaction feature in QSafe Wallet allows users to transfer digital assets (cryptocurrencies) securely, quickly, and with full visibility into network costs. This interface ensures that even non-technical users can confidently perform blockchain transactions with minimal effort and maximum clarity.

## Purpose

The Send Transaction page enables you to:\
\- Choose which token (e.g., QRN, BTC, ETH, SOL) you want to send.\
\- Specify the recipient’s address.\
\- View real-time gas/network fees based on current blockchain conditions.\
\- Review and confirm the transaction details before executing it.\ <br>

## Detailed Breakdown of Form Fields

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top">Field Name</td><td valign="top">Description</td></tr><tr><td valign="top">From Address</td><td valign="top">Automatically populated with your active wallet address. This is the sender's public key.</td></tr><tr><td valign="top">To Address</td><td valign="top">The destination address where the token will be sent. You must paste or scan a valid wallet address.</td></tr><tr><td valign="top">Token</td><td valign="top">A dropdown menu showing the available tokens in your wallet, including the network they reside on.</td></tr><tr><td valign="top">Amount</td><td valign="top">The quantity of the selected token to be transferred. Includes a live USD equivalent preview.</td></tr><tr><td valign="top">Gas Fee</td><td valign="top">Estimated fee (in native blockchain token) to execute the transaction. Displayed dynamically.</td></tr></tbody></table>

## User Interface Walkthrough

Upon visiting the Send Transaction page, users are presented with a clean and intuitive interface structured to minimize mistakes and ensure clarity.\
\
The UI includes:\
1\. Address Fields: From Address (locked), To Address (editable, supports QR code scan)\
2\. Token Selection Dropdown: Lists available tokens with name, symbol, and balance\
3\. Amount Input: Includes real-time conversion to fiat currency\
4\. Estimated Gas Fee Display: Network fee and estimated time are shown dynamically\
5\. Confirmation Button: Clearly shows total deduction and only activates when inputs are valid

## Transaction Flow (Step-by-Step)

1\. Select Token\
2\. Enter Recipient Address\
3\. Input Amount\
4\. Review Gas Fee\
5\. Click “Send”\
6\. Get Confirmation\
7\. Track Progress

## Example Scenario

Suppose you want to send 0.01 QRN to a friend.\
\
**To Address:** 0x397E...EBA0B1\
**Token:** QRN\
**Amount:** 0.01\
**Gas Fee (est):** 0.000021 QRN\
**Network:** QSafe Chain\
**Estimated Confirmation Time:** 1–2 minutes\
Total Cost: \~0.010021 QRN\
\
After clicking Send, you’ll see a confirmation popup. You can copy the transaction hash and view it in the block explorer.\ <br>

## Best Practices & Notes

What You Should Do:

·        Always double-check the address.

·        Ensure enough balance to cover amount + gas.

·        Use the correct network for the selected token.

·        Save transaction hash for tracking.

### Warnings

If you enter the wrong recipient address, the tokens will be lost permanently. Blockchain transactions cannot be reversed.

## Related Features

• Receive Tokens — Allows users to generate QR codes or copy addresses for incoming transfers.

• Transaction History — Displays all previous sends with status (pending, confirmed, failed).

• Network Settings — Lets advanced users customize gas price or switch chains manually.


# Deposit Funds

After clicking the deposit button, users can see a popup to copy the associated address and an address QR.

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FD6o8NzvcZbc6E1uhS8yh%2Fimage.png?alt=media&amp;token=cb205f81-0f9e-4832-b7d3-0e0a5d932ce9" alt="" width="563"><figcaption></figcaption></figure>


# Swapping

QSafe Wallet’s swap feature simplifies decentralized token exchanges across multiple blockchains. Here's a breakdown of how it works, using the screenshots attached as examples:

***

**1. Swap Interface Overview**

The swap screen allows you to convert one cryptocurrency into another (e.g., **POL → USDC** on Polygon). Key components include:

* **Token Selection**:
  * **Input Token**: Select the token you want to spend (e.g., POL).
  * **Output Token**: Choose the token you want to receive (e.g., USDC).
* **Amount Input**:\
  Enter the quantity of the input token (e.g., `0.0001 POL`).
* **Network Selection**:\
  Specify the blockchain for the swap (e.g., Polygon).
* **Recipient Address**:\
  Optionally set a destination address for the received tokens.
* **Preview Button**:\
  Simulate the swap to view real-time rates, fees, and slippage.

***

**2. How It Works Under the Hood**

1. **Price Aggregation**:\
   Q Safe Wallet queries decentralized exchanges (DEXs) and aggregators to find the **best possible rate** for your swap. For example, in the screenshot, swapping `0.0001 POL` yields `0.000021 USDC`.
2. **Gas Fee Estimation**:\
   The wallet calculates the **network fee** (gas) required to execute the transaction.&#x20;
3. **Slippage & Risk Management**:
   * **Slippage Tolerance**: The maximum acceptable price change during execution (default 0.5%).
   * **Minimum Received**: Ensures you get at least the specified amount even if prices fluctuate.
4. **Security Checks**:
   * Validates if you have enough funds to cover both the swap amount **and gas fees** .
   * Alerts you if funds are insufficient (as shown in the error message).

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FJmH27zrvDGyBtVXDrY0L%2Fimage.png?alt=media&amp;token=ea965fc0-c659-42ec-8fd8-e66002ec0a68" alt=""><figcaption></figcaption></figure>

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FIDcemJuejcdSv4Ipyw0Y%2Fimage.png?alt=media&amp;token=587faf39-e589-4575-8005-c99afcfb2b8f" alt=""><figcaption></figcaption></figure>


# Quranium

Quranium Chain is a **post-quantum secure EVM-compatible blockchain** designed to protect against future threats from quantum computing. Below is a detailed breakdown of its supported features and key considerations:

***

### **1. Native Token Transfers (QRN)**

#### **What It Means**

Users can send and receive **QRN** , the native token of the Quranium Chain, just like ETH on Ethereum or MATIC on Polygon.

#### **How It Works**

* QRN is used for:
  * **Gas fees**: Paying transaction fees.
  * **Staking/delegation**: Participating in network security.
  * **Value transfer**: Sending funds between accounts.
* Transactions are signed using **SLHDSA** , a **post-quantum digital signature algorithm** .

#### **Why It Matters**

Unlike traditional blockchains that use ECDSA signatures (vulnerable to quantum attacks), Quranium ensures long-term security even if quantum computers become viable.

***

### **2. SLHDSA Signature Transactions**

#### **What Is SLHDSA?**

* **SLHDSA** stands for **Stateless Hash-Based Digital Signature Algorithm** .
* It is a **NIST-standardized post-quantum cryptographic scheme** , part of the SPHINCS+ family.
* Unlike ECDSA (used by Ethereum), it does not rely on elliptic curves but on hash functions, making it resistant to quantum attacks.

#### **How It’s Used**

* Every transaction on Quranium Chain is signed with an **SLHDSA private key** .
* The corresponding public key is used to derive the wallet address (similar to Ethereum-style Keccak-based addresses).
* This ensures all user actions (e.g., sending tokens, interacting with smart contracts) are **quantum-safe** .

#### **Implications**

* Wallets must support **SLHDSA signing logic** (like QSafe Wallet).
* Standard Ethereum wallets (e.g., MetaMask) cannot sign transactions unless they integrate post-quantum libraries.

<br>


# Bitcoin & Derivatives

QSafe Wallet provides robust support for **Bitcoin (BTC)** and its derivatives like **Litecoin (LTC)** and **Dogecoin (DOGE)**. This ensures users can securely manage their UTXO-based assets with ease, while benefiting from modern wallet features.

***

### Supported Chains

| Chain        | Symbol | Description                                                                  |
| ------------ | ------ | ---------------------------------------------------------------------------- |
| **Bitcoin**  | ₿ BTC  | The original decentralized cryptocurrency, secured by SHA-256 PoW consensus. |
| **Litecoin** | Ł LTC  | A "silver to Bitcoin’s gold" — faster block times and Scrypt-based mining.   |
| **Dogecoin** | Ð DOGE | Originally a meme coin, now widely used for microtransactions and tipping.   |

These chains are **UTXO-based**, meaning transactions are structured differently than EVM chains (e.g., Ethereum), and require specific handling for signing and address generation.


# EVM

EVM chains are blockchains that run the **Ethereum Virtual Machine**, allowing them to support Ethereum-style smart contracts and token standards. QSafe Wallet is designed to work seamlessly with all EVM-compatible chains, including mainnets like **Ethereum**, **Polygon**, **Binance Smart Chain**, and testnets like **Holesky** and **Sepolia**.

***

### **Core Compatibility Features**

#### **1. Ethereum-Style Addresses (0x...)**

* All EVM chains use **hexadecimal addresses starting with `0x`**, derived from the public key using **Keccak-256 hashing**.
* Example: `0x3de85289856f88b4a718e53bf9421B1D5cE7E58f`
* These addresses are compatible across all EVM chains — you can use the same wallet address on **Ethereum**, **Polygon**, **BSC**, etc.

#### **2. ERC-20 / ERC-721 / ERC-1155 Tokens**

Q Safe Wallet supports the most widely used token standards in the Ethereum ecosystem:

| Token Standard | Description                                                                                                      |
| -------------- | ---------------------------------------------------------------------------------------------------------------- |
| **ERC-20**     | Fungible tokens (e.g., DAI, USDT, LINK). Used for stablecoins, governance tokens, etc.                           |
| **ERC-721**    | Non-fungible tokens (NFTs), where each token is unique (e.g., CryptoPunks, Bored Apes).                          |
| **ERC-1155**   | Semi-fungible tokens, supporting both NFTs and fungible assets in one contract (used in games and marketplaces). |

**How It Works:**

* You can **send, receive, and view balances** of these tokens directly from the wallet interface.
* The wallet automatically detects known tokens or allows manual import via contract address.

#### **3. Testnets Are Fully Supported**

Q Safe Wallet supports major **EVM testnets like Sepolia, Holesky**, and **BNB Testnet** making it ideal for developers and testers.


# Solana

QSafe Wallet supports **Solana**, a high-performance blockchain known for its **speed, low fees, and scalability**. Below is a detailed breakdown of the key features mentioned:

***

### &#x20;1. **High-Speed Transactions (50k TPS)**

#### **What It Means**

* Solana is capable of processing up to **50,000 transactions per second (TPS)** — significantly faster than Ethereum.
* This makes it ideal for **high-frequency use cases** like DeFi, NFT marketplaces, gaming, and Web3 applications requiring fast finality.

#### **Why It Matters**

* Users experience near-instant transaction confirmations (typically under **2 seconds** ).
* Ideal for **real-time interactions**, such as bidding on NFTs or participating in decentralized exchanges.

***

### 2. **Low Fee Structure ($0.00025 Avg)**

#### **What It Means**

* The average cost to send a transaction on Solana is **$0.00025 USD**, making it one of the most affordable blockchains available.

#### **How It Works**

* Fees are paid in **SOL**, Solana’s native token.
* Transaction fees are calculated based on:
  * **Transaction complexity** (e.g., number of instructions).
  * **Network congestion** (rare due to high throughput).
* Unlike EVM chains, gas prices do not fluctuate dramatically.

#### **Use Cases Enabled by Low Fees**

* Microtransactions (e.g., tipping, content monetization).
* Frequent smart contract interactions (e.g., yield farming, staking).
* Scalable DApps with thousands of daily users.

***

### 3. **SPL Token Standard Support**

#### **What Is SPL?**

* **SPL** stands for **Solana Program Library**, and **SPL tokens** are the equivalent of **ERC-20 tokens** on Ethereum.
* They allow developers to create and manage **fungible tokens** on the Solana blockchain.

#### **Supported Features**

* Send and receive **SPL tokens** directly from the wallet interface.
* View balances of popular tokens like:
  * **USDC (SPL version)**
  * **Raydium (RAY)**
  * **Serum (SRM)**
  * Custom SPL tokens (e.g., DAO governance tokens)
* Approve token spending for decentralized apps (DApps).

#### **Token Interactions in Q Safe Wallet**

* You can:
  * **Send & receive** SPL tokens.
  * **Approve allowances** for DeFi protocols.
  * **View transaction history** including token transfers.

<br>


# Other Chains

QSafe Wallet supports a variety of **non-EVM, non-Bitcoin, and non-Solana chains**, including **Substrate-based networks** like **Polkadot** and **Kusama**, as well as niche or emerging blockchains with unique features.

#### Core Features Supported in Q Safe Wallet

**1. Cross-Chain Messaging (XCMP)**

* XCMP (Cross-Consensus Message Passing) enables secure communication between **Polkadot parachains**.

**2. Parachain Interoperability**

* Each **parachain** operates independently but shares security from the **Polkadot relay chain**.

### Supported Substrate Chains

| **Polkadot (Relay Chain)** | DOT  | The main Polkadot relay chain that secures all connected parachains.                           |
| -------------------------- | ---- | ---------------------------------------------------------------------------------------------- |
| **Kusama**                 | KSM  | Polkadot’s “canary network” — faster and riskier, used for testing before mainnet deployments. |
| **Westend**                | WND  | Polkadot testnet for development and testing.                                                  |
| **Acala**                  | ACA  | DeFi hub with stablecoins, staking derivatives, and DEX functionality.                         |
| **Karura**                 | KAR  | Kusama’s sister DeFi platform, supporting stablecoins and liquid staking.                      |
| **Moonbeam**               | GLMR | EVM-compatible smart contract chain on Polkadot.                                               |
| **Moonriver**              | MOVR | Kusama-based version of Moonbeam; more experimental.                                           |
| **Shiden Network**         | SDN  | Multi-chain dApp hub on Kusama, supporting EVM, WASM, and Layer2 contracts.                    |

### Special Case Chains

Some chains fall outside the usual categories and offer **unique use cases**, such as **testing, gaming, or domain-specific smart contracts**. These chains may have limited or read-only support depending on wallet maturity.

| **Kadena**              | Pact Smart Contracts    | Read-Only | Supports Pact language-based smart contracts (used by institutions and enterprises).   |
| ----------------------- | ----------------------- | --------- | -------------------------------------------------------------------------------------- |
| **Caga Ankara Testnet** | Testnet Debugging Tools | Full      | Experimental testnet for debugging and testing new features in the Quranium ecosystem. |
| **Vara Network**        | Gaming-Focused Economy  | Partial   | Built for game economies using Gear Protocol (WASM-based smart contracts).             |


# Secure Your Backup and Mnemonic

## Secure Your Backup and Mnemonic: Best Practices and Guidelines

### Introduction

Securing your backup and mnemonic is critical to protecting access to your digital assets. Losing your **12/24-word mnemonic** or **ML-KEM private key** means **permanent loss of access**, as backups are encrypted with a combination of ML-KEM (post-quantum encryption) and symmetric encryption. This guide outlines best practices, workflows, and common pitfalls to ensure your assets remain secure.

***

### Understanding Your Security Tools

#### ML-KEM (Post-Quantum Encryption)

* A quantum-resistant encryption algorithm used to protect your backup.
* Losing the ML-KEM private key renders backups irrecoverable.

#### Symmetric Encryption

* Used alongside ML-KEM for encrypting backups (e.g., AES-256).
* Requires a strong password to decrypt.

#### SLH-DSA Keys

* Used for digital signatures. Never share these keys, as they authenticate transactions.

#### Mnemonic Phrase

* A 12/24-word seed phrase that regenerates your wallet’s private keys.
* **It is the ultimate backup.** Losing it means losing access forever.

***

### Best Practices

#### 1. Store Your Mnemonic Offline

* **Write it down physically**: Use paper or fire/water-resistant metal (e.g., steel plates).
* **Multiple secure locations**: Store copies in a safe, bank deposit box, or with trusted parties.
* **Never store digitally**: Avoid photos, cloud notes, or text files.

#### 2. Encrypt Backups Securely

* **Use strong passwords**: Combine uppercase, lowercase, numbers, and symbols (e.g., `Nv7@qT!3xLp`).
* **Separate backups from mnemonics**: Never store encrypted backups and mnemonics together.
* **Use trusted cloud services**: Enable 2FA for cloud accounts storing backups.

#### 3. Test Recovery Periodically

* **Simulate recovery**: Restore your wallet using the mnemonic every 3–6 months.
* **Verify decryption**: Ensure backups can be decrypted with your password.

#### 4. Never Share Keys

* **Avoid phishing/scams**: Never share your mnemonic, ML-KEM key, or SLH-DSA keys via email, calls, or messages.
* **Beware of fake support**: Legitimate services will never ask for your keys.

***

### Step-by-Step Workflow

#### Exporting an Encrypted Backup

1. **Navigate to Settings**:\
   Go to **Settings > Backup & Restore** in your wallet/app.

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2Fo2yJVZP2q5G7Y34ZUK1N%2Fimage.png?alt=media&amp;token=b4d1f771-1802-4f52-8d36-d09c296fe277" alt="" width="360"><figcaption></figcaption></figure>

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2F990jAtdceVLDnKwlOTGh%2Fimage.png?alt=media&amp;token=1603893c-3beb-4ded-9e4a-80a3d62f2097" alt="" width="375"><figcaption></figcaption></figure>

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FtPqRtjpwwfEvF1YaQpUR%2Fimage.png?alt=media&amp;token=85bd5288-39d8-4016-9d43-5e1381d2e3c0" alt="" width="360"><figcaption></figcaption></figure>

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FYvSvtohZzQnCOCvPMUbw%2Fimage.png?alt=media&amp;token=897d4d03-d90b-4edc-ba83-e1ad35a9ce56" alt="" width="375"><figcaption></figcaption></figure>

1. **Export Backup**:
   * Select **Encrypt Backup** and set a strong password.
   * Save the encrypted file to a secure cloud service (e.g., Google Drive with 2FA).
2. **Verify Decryption**:
   * Immediately test decrypting the backup with your password.
   * Confirm all data (e.g., wallet addresses, balances) is intact.

#### Restoring from Backup (Testing)

1. **Initiate Restore**:\
   Use **Settings > Backup & Restore > Restore Backup**.
2. **Enter Password**:\
   Provide the password to decrypt the backup.
3. **Validate Recovery**:\
   Ensure restored wallet matches original (e.g., transaction history, balances).

***

### Common Mistakes to Avoid

&#x20;**Storing mnemonics digitally**: Even encrypted digital copies are vulnerable.\
&#x20;**Reusing passwords**: Use unique passwords for backups and accounts.\
&#x20;**Ignoring recovery tests**: Assume backups are corrupt until proven otherwise.\
&#x20;**Storing keys/mnemonics together**: A single breach could compromise both.

***

### Note :

Your mnemonic and ML-KEM private key are the gatekeepers to your assets. By following these practices—storing offline, encrypting backups, testing recovery, and guarding keys—you ensure resilience against loss or theft. **Security is your responsibility.** Stay proactive, stay safe.


# Validate Transaction Details Before Signing

### Introduction

Signing a transaction without validating its details can lead to **permanent loss of funds** or failed transactions. Errors like incorrect gas fees, mismatched recipient addresses, or misconfigured slippage settings are common and irreversible. This guide explains how to rigorously review transaction details before signing to protect your assets.

***

### Key Transaction Details to Validate

Before approving any transaction, verify the following:

1. **Gas Fees**: Network fees required to process the transaction.
2. **Recipient Address**: The destination wallet address (e.g., `0x...` for Ethereum).
3. **Slippage Tolerance**: Allowed price fluctuation for swaps (e.g., 1-3%).
4. **Transaction Data**: Hex payloads for smart contract interactions.
5. **Network Compatibility**: Ensure the address matches the chain (e.g., BSC vs. Ethereum).

***

### Best Practices

#### 1. Review Gas Fees

* **Use the Gas Fee Selector**: Adjust fees based on urgency:

| **Gas Tier** | **When to Use**                         | **Risk of Failure** |
| ------------ | --------------------------------------- | ------------------- |
| Economy      | Non-urgent transactions (e.g., staking) | High                |
| Fast         | Most transactions                       | Low                 |
| Fastest      | Time-sensitive trades                   | Very Low            |

* **Economy**: Slow but cheap (low-priority transactions).
* **Fast**: Balances speed and cost (recommended for most users).
* **Fastest**: High priority (time-sensitive trades).
* **Check Network Congestion**: Use tools like [Etherscan Gas Tracker](https://etherscan.io/gastracker) to estimate fees.

#### 2. Double-Check Recipient Addresses

* **Verify Character-by-Character**: Malware can alter copied addresses.
* **Common Address Formats**:**Common Address Formats**:

  | **Chain**      | **Address Format Example** |
  | -------------- | -------------------------- |
  | Ethereum (ETH) | `0x1f9090aaE28b8a3dC...`   |
  | Bitcoin (BTC)  | `bc1qxy2kgdygjrsqtz...`    |
  | BSC (BEP-20)   | `0x7423270d0c9...`         |

  * **Test with a small amount first** for unknown addresses.

#### 3. Use the "Preview Swap" Feature

* **Confirm Rates and Fees**: Ensure the expected output matches market rates.

* **Adjust Slippage**:

  * **Low volatility**: Set slippage to 1-2%.
  * **High volatility**: Use 3-5% to avoid failed swaps.

* Below is the preview swap page.

<figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2Fu5WP6tl0Qy4Y7yFZNnCh%2Fimage.png?alt=media&amp;token=b24aaff4-1bda-4f90-a818-808a45f921e0" alt=""><figcaption></figcaption></figure>

#### 4. Enable Advanced Mode (For Experts)

* **Inspect Transaction Data**: View raw hex payloads to detect malicious smart contracts.
* **Validate Contract Addresses**: Ensure you’re interacting with verified contracts (e.g., check Etherscan’s “Verified” badge).

***

### Step-by-Step Workflow

#### Before Signing a Transaction:

1. **Open Transaction Preview**: Review the summary screen.&#x20;
2. **Confirm Recipient Address**:
   * Manually type the first/last 4 characters of the address.
   * Use wallet features like **ENS domains** (e.g., `vitalik.eth`).
3. **Adjust Gas Fees**:
   * Select a gas tier (Economy/Fast/Fastest) based on urgency.
4. **Preview Swap Details**:
   * Check slippage, minimum received, and network fees.
5. **Enable Advanced Mode** (if needed):

   * Review raw data for suspicious function calls.

   <figure><img src="https://4227883243-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWQaf2furhOcVCSNbnqem%2Fuploads%2FVZbynTYPNQSLrbqcdWE1%2Fimage.png?alt=media&amp;token=7c958f4a-a1c7-4f37-b645-54d2d3e44268" alt=""><figcaption></figcaption></figure>

#### After Signing:

1. **Track Transaction Status**: Use block explorers (e.g., Etherscan) to monitor progress.
2. **Cancel/Replace Stuck Transactions**:
   * **Speed up**: Resubmit with higher gas.
   * **Cancel**: Send a $0 transaction with the same nonce and higher gas.

***

### Common Errors & Solutions

| **Error**              | **Cause**                                              | **Solution**                          |
| ---------------------- | ------------------------------------------------------ | ------------------------------------- |
| **Insufficient Funds** | Balance < (Amount + Gas Fees)                          | Deposit more funds or reduce amount.  |
| **Invalid Signature**  | Wrong signing algorithm (e.g., EdDSA instead of ECDSA) | Recheck wallet-network compatibility. |
| **Transaction Stuck**  | Gas too low for network congestion                     | Speed up or cancel/replace the tx.    |

#### Troubleshooting Failed Transactions:

* **"Insufficient Funds"**: Ensure your balance covers **amount + gas fees**.
* **"Invalid Signature"**: Confirm the wallet’s signing algorithm (e.g., ECDSA, EdDSA) matches the network.

***

### Note :

Validating transaction details is your last line of defense against irreversible errors. By rigorously checking gas fees, addresses, and swap settings—and leveraging tools like **Preview Swap** and **Advanced Mode**—you minimize risks and protect your assets. **Always assume mistakes are costly.** Stay vigilant, double-check, and never rush.

***


# Monitor Account Activity Across Chains

### Introduction

Monitoring transactions across chains (e.g., EVM, Quranium, Bitcoin) is critical for detecting unauthorized access, resolving disputes, and ensuring asset security. This guide explains how to audit activity, use monitoring tools, and respond to anomalies using structured workflows and best practices.

***

### Key Tools for Monitoring

| **Tool**                 | **Purpose**                                                                |
| ------------------------ | -------------------------------------------------------------------------- |
| **Activity Dashboard**   | Central hub to filter, track, and export transactions by chain.            |
| **Blockchain Explorers** | Verify on-chain details (e.g., Etherscan for Ethereum, Quranium Explorer). |
| **Alert Systems**        | Notify you of large transactions, new chain connections, or failed txs.    |

***

### Best Practices

#### 1. Use the Activity Dashboard

Filter and organize transactions efficiently:

| **Feature**          | **How to Use It**                                       |
| -------------------- | ------------------------------------------------------- |
| **Chain Filter**     | Isolate activity by chain (EVM, Quranium, Bitcoin).     |
| **Transaction Hash** | Click to open the transaction in a blockchain explorer. |

***

#### 2. Verify Transactions on Explorers

Cross-check critical details using chain-specific explorers:

| **Bitcoin**  | Input/output addresses, transaction fees.          |
| ------------ | -------------------------------------------------- |
| **EVM**      | Recipient address, gas fees, smart contract calls. |
| **Quranium** | Transaction finality and confirmation count.       |

***

#### 3. Configure Alerts

Customize notifications to stay informed:

| **Alert Type**            | **Recommended Threshold** | **Purpose**                        |
| ------------------------- | ------------------------- | ---------------------------------- |
| **Large Transactions**    | > $1,000                  | Detect unauthorized withdrawals.   |
| **New Chain Connections** | Any                       | Warn about new wallet links.       |
| **Failed Transactions**   | Any                       | Investigate gas or network issues. |

***

### Step-by-Step Workflow

#### How to Investigate Suspicious Activity

| **Step** | **Action**                    | **Details**                                                             |
| -------- | ----------------------------- | ----------------------------------------------------------------------- |
| 1        | **Filter by Chain**           | Use the Dashboard to isolate the chain with suspicious activity.        |
| 2        | **Review Transaction Hashes** | Check recipient addresses and smart contract interactions on explorers. |
| 3        | **Cross-Reference Addresses** | Match against your saved address book or known contracts.               |
| 4        | **Revoke Access**             | Disconnect suspicious dApps/contracts immediately.                      |

***

### Common Mistakes to Avoid

| **Mistake**                 | **Risk**                              | **Solution**                       |
| --------------------------- | ------------------------------------- | ---------------------------------- |
| Ignoring small transactions | Hackers test with tiny amounts first. | Investigate **all** transactions.  |
| Not auditing all chains     | Cross-chain breaches go undetected.   | Use the **Chain Filter** weekly.   |
| Stale dApp permissions      | Old approvals may still have access.  | Revoke unused permissions monthly. |

***

### Troubleshooting Unrecognized Activity

| **Issue**                 | **Action**                                                     |
| ------------------------- | -------------------------------------------------------------- |
| Unknown recipient address | Cross-check with your saved addresses or past transactions.    |
| Unfamiliar contract call  | Search the contract address on explorers to verify legitimacy. |
| Balance discrepancy       | Sync your wallet and check for pending transactions.           |

***

### Note :

Proactive monitoring across chains is essential to safeguard your assets. Use the **Activity Dashboard** to filter transactions, **blockchain explorers** to verify details, and **alerts** to stay ahead of threats. Regular audits and revoking unused permissions minimize risks. **A single oversight can lead to irreversible losses.**


# Safe Interaction with DApps

### Introduction

Interacting with decentralized applications (DApps) on **Quranium Chain** and **EVM-compatible networks** (e.g., Ethereum, Polygon) requires vigilance to protect your assets. Q Safe Wallet automates critical security features like post-quantum cryptography (SLH-DSA) for Quranium DApps and ECDSA for EVM chains—but **your proactive validation is key**. This guide explains how to use DApps securely while minimizing risks.

***

### Quranium Chain DApps: Post-Quantum Security

#### Key Features

Quranium Chain uses **SLH-DSA**, a quantum-resistant signing algorithm, to future-proof transactions. Q Safe Wallet ensures:

| **Feature**                     | **How It Works**                                                                                 | **User Action Required**                             |
| ------------------------------- | ------------------------------------------------------------------------------------------------ | ---------------------------------------------------- |
| **Automatic Network Detection** | Wallet switches to SLH-DSA signing when interacting with Quranium DApps.                         | Confirm the network is "Quranium" before proceeding. |
| **Signature Validation**        | All transactions are signed with your SLH-DSA private key (derived from your mnemonic).          | Keep your mnemonic offline and never share it.       |
| **Gas Fee Handling**            | Gas fees are paid in **QRN** (Quranium’s native token). Wallet checks balance before submitting. | Ensure sufficient QRN balance for transactions.      |

***

### EVM-Compatible DApps: Standard Security

#### Key Features

For EVM chains (Ethereum, Polygon, BSC), Q Safe Wallet uses **ECDSA** (secp256k1 curve) for signing.

| **Feature**                   | **How It Works**                                                               | **User Action Required**                                  |
| ----------------------------- | ------------------------------------------------------------------------------ | --------------------------------------------------------- |
| **Automatic Chain Detection** | Wallet detects EVM chains (e.g., Ethereum, Polygon) and uses ECDSA signing.    | Confirm the correct chain (e.g., “Ethereum Mainnet”).     |
| **Gas Fee Optimization**      | Supports dynamic gas tiers (Economy/Fast/Fastest) based on network congestion. | Select appropriate gas tier to avoid failed transactions. |
| **DApp Permissions**          | Manages token allowances (e.g., ERC-20 approvals) and lets you revoke access.  | Periodically revoke unused approvals.                     |

***

### Best Practices for All DApps

#### 1. Verify DApp Authenticity

* **Check URLs**: Ensure you’re on the official DApp website (e.g., `app.uniswap.org`, not `uniswaap.com`).
* **Audit Smart Contracts**: Use block explorers (Etherscan, Quranium Explorer) to confirm contracts are verified.

#### 2. Limit Token Approvals

* **Set Allowance Caps**: Approve only the amount needed for the transaction.

#### 3. Confirm Transaction Details

* **Recipient Addresses**: Match them to official DApp contracts or known addresses.
* **Slippage Tolerance**: Use conservative values (1-3%) to avoid front-running.

***

### Step-by-Step Workflow

#### Safe Quranium DApp Interaction

1. **Connect Q Safe Wallet**:
   * Ensure the DApp URL is correct.
   * Confirm the wallet switches to **Quranium Chain**.
2. **Review Transaction**:
   * Check gas fees in QRN and validate your balance.
   * Confirm SLH-DSA signing is active (look for "Quantum-Safe" badge).
3. **Sign and Monitor**:
   * Track the transaction.

#### Safe EVM DApp Interaction

1. **Connect Q Safe Wallet**:
   * Verify the DApp’s domain and chain (e.g., Ethereum Mainnet).
2. **Adjust Gas Fees**:
   * Select **Economy/Fast/Fastest** based on urgency.
3. **Set Allowances**:
   * Approve only the amount needed (e.g., 1 ETH, not unlimited).
4. **Sign and Track**:
   * Use Etherscan/Polygonscan to monitor progress.

***

### Common Risks & Mitigations

| **Risk**                      | **Mitigation**                                                          |
| ----------------------------- | ----------------------------------------------------------------------- |
| **Phishing DApps**            | Bookmark trusted DApps and avoid Google ads.                            |
| **Unlimited Token Approvals** | Revoke unused approvals monthly.                                        |
| **Mismatched Network**        | Double-check the chain (e.g., Quranium vs. Ethereum) before signing.    |
| **Malicious Contracts**       | Reject transactions with unrecognized payloads or unverified contracts. |

***

### Troubleshooting

#### Insufficient Gas Fees (Quranium)

* **Cause**: Low QRN balance.
* **Fix**: Acquire QRN from a supported exchange.

#### Pending EVM Transactions

* **Cause**: Gas too low for network congestion.
* **Fix**: Speed up the transaction with a higher gas tier.

#### Unrecognized Contract Interaction

* **Cause**: Compromised DApp or accidental approval.
* **Fix**: Revoke permissions immediately via Q Safe Wallet.

***

### Note :

Q Safe Wallet automates critical security measures, but **your attention to detail prevents disasters**. Always verify DApp URLs, limit token approvals, and confirm chain settings. Quantum-safe SLH-DSA (Quranium) and battle-tested ECDSA (EVM) protect your transactions—but vigilance is irreplaceable.

***


