Recovery · the paper is the key

Your twenty-four words
bring it all back.

The words you wrote down are not a backup of your key. They are the key. Type them into any of the three tools below and the same four addresses come back, on Sui, Ethereum, Solana and Bitcoin.

We hold nothing that can do this for you. That is why it still works on a machine that has never heard of us.

Three ways back, in order

Pick the one that fits the machine in front of you

All three run the same derivation and land on the same addresses. The first is the easiest. The second needs nothing from us at all.

  1. In this browserone.ie/w/restore

    Type the twenty-four words and the same four addresses come back in this tab. It needs you signed in to a ONE account, because it records the restored addresses there. The words themselves are never sent. This is the quickest way, and the only one of the three that runs on a page we serve.

    Restore in the browser
  2. Offline, on any machinenpx @oneie/recover

    Words in, four addresses and a signer out, with no ONE server in the path. It was tested with the network blocked. Add --rpc sui=<url> to read a balance from a node you choose; there is no default node and ours is refused. The package also carries a single-file page, dist/page.html, that you can copy to a USB stick and open on a machine that has never been online.

    npx -y @oneie/recover
  3. From the ONE command linenpx oneie key recover

    The same derivation in the ONE CLI. key recover rebuilds the key from its words, key public prints the public identity and the four addresses, and key verify checks that identity against what the server holds without sending the key. The words come from a hidden prompt or stdin, never from the command line, so they stay out of your shell history.

    npx oneie key recover

Before you type your words

Check the offline page is the one we published

A page that asks for your words should be checked, not trusted. This is the SHA-256 of dist/page.html in @oneie/recover 0.1.0. Run the three lines below on your own machine and compare. A different hash means a different file: do not type your words into it.

sha256 · dist/page.html · @oneie/recover 0.1.0

8b160c5026c71a5170d4278aab463ecbecdf13a2774e8468a7deeba08d39826e

npm pack @oneie/recover@0.1.0
tar xzf oneie-recover-0.1.0.tgz
shasum -a 256 package/dist/page.html

On Windows: certutil -hashfile page.html SHA256. The page also seals itself: its Content-Security-Policy names the hash of its own code, so a browser refuses to run a copy with one byte changed, and it loads nothing from the network except a balance node you type in yourself.

The boundary

What ONE can and cannot do

We hold nothing that opens it

The key is made on your device and never sent to us. There is no copy here to hand back, and no support queue that can restore you.

Lost key and lost paper

If the device and the twenty-four words are both gone, nobody can recover the key. Not us, not anyone. That is the same property that stops anyone else taking it.

Anyone with the words

Whoever holds the paper holds the key. We cannot freeze it or reverse what they do with it. Keep the paper apart from the device.

Other wallets, said out loud

They are BIP-39 words, and a key made at one.ie today is not one another wallet can open. Typed into other software, the same words produce addresses that look valid, hold nothing and are not yours. Recover with one of the three tools above. The offline tool prints two address sets, labelled v1 and v2, because keys made under the older and the newer derivation land on different addresses. Check which set holds your money before you send anything.

How the key is made and kept: one.ie/key. Your keys and where each copy rests: one.ie/keys. The tools are free under the ONE License. One obligation in return: keep the ONE mark and the link to one.ie in whatever you deploy.