Three ways out of the vault — all under your control
The hot key starts a withdrawal. The destination is locked into the contract, the coins queue for the delay you chose — presets from 6 hours to 14 days, or any window from 1 hour to 90 days. The covenant simply has no spend path that releases them early.
While the delay runs, the alarm key (kept apart — on paper, elsewhere) sends everything back to the vault in one move. A thief with the hot key gets nothing.
The window passed without a cancel — so it was you. The coins are delivered strictly to the address locked at the start — automatically, if auto-complete is on (recommended). The covenant accepts no other destination.
Set up once — hold a serious sum calmly, at home or on the road
Your phone is taken — or you're forced to send coins. The thief starts a withdrawal, but the coins are still in the vault for hours. One move with the alarm key (kept apart — at home, on paper) and everything comes back. At home or travelling, the money never leaves instantly.
Malware, a phishing site or a leaked seed phrase — the attacker still can't drain the vault instantly. You get an alert, cancel the withdrawal and calmly move the coins to a fresh vault.
You want your KAS to reach your family if something happens to you. Set a periodic check-in — say, once a month. If you stop checking in, after your chosen term the coins open to your heir — the right and the timer live on-chain. Our watcher then delivers them automatically as a service (no key, no software needed) — or anyone can execute the same delivery manually with the open recovery tools. How inheritance works ↓
Pasted the wrong address? Changed your mind? While the window is open, the withdrawal can be cancelled and the coins return to the vault. A mistake stops being irreversible.
Your company keeps KAS in a shared vault: every withdrawal is visible in advance and runs with a delay. A hacked employee laptop can't walk away with the treasury — the founder's alarm key stops the withdrawal.
Name your own second address as the heir. Lose the hot key — just stop checking in: after the period, the coins come back to you through the inheritance path. In a plain wallet a lost key means lost coins; here you have a road back.
Your coins reach your family — without handing anyone your keys
Inheritance is a separate, optional covenant path — leave it off and the vault is a pure anti-theft safe.
What runs where — and what we can never touch
From your browser to the BlockDAG
The server relays transactions and watches the chain — it never sees a key and can't sign anything. Advanced flows (vault migration, offline tools) live in Docs.
The vault is free. Pay only if you want us watching
Creating the vault, withdrawals, cancels, check-ins, inheritance — every on-chain operation costs nothing beyond the Kaspa network fee (fractions of a KAS).
A Telegram alert the moment anything happens to your vault, plus check-in reminders. The vault works without the subscription too — but without alerts you'll learn about someone else's withdrawal later than you'd like.
Verify the model, then use the product
Kaspa Forge is designed to be understood, not trusted blindly. Start with the security model, then follow the covenant mechanics into the product you need.
Fair questions
Do you hold my coins?
No. Keys are generated and live only in your browser; the vault rules are a Kaspa on-chain script. We physically can't move your funds — and can't help withdraw them if you lose both keys.
What if your site disappears?
The vault is an on-chain contract — it doesn't need us to exist. The recovery guide and the open-source vaultctl tool let you do everything from a terminal against any Kaspa node.
What does it cost?
On-chain operations are free forever — you pay only the Kaspa network fee (fractions of a KAS). Telegram monitoring is 100 KAS/year, first 30 days free.
Do I have to stay online for the vault to work?
No. The rules are enforced by the blockchain itself. Our watcher handles the conveniences — auto-completing withdrawals and delivering inheritance. And if we ever vanish, every step can be done by hand or with vaultctl.
How often do I have to check in for inheritance?
There's no separate schedule — the inheritance period you chose at creation is the deadline. Every check-in resets the timer to zero, so check in at least once within each period (picked 12 months — show up more often than once a year). Cancelling a withdrawal resets the timer too. With the alerts subscription, Telegram reminds you once ~80% of the period has passed; without it, watch the timer in the vault panel yourself.
What if a thief gets both keys?
Then the window won't save you — that's why keeping the keys apart is the foundation. The hot key lives where you use it; the alarm key belongs on paper in a different place. A thief with just the hot key gets nothing.
How is this different from a hardware wallet?
A hardware wallet protects the key, but a signed transaction is final. Kaspa Safe protects the coins themselves: even with a stolen key, every withdrawal waits out your delay and can be cancelled. The two work great together.
How tested is it?
The contract is unaudited but passed our full on-chain cycle plus adversarial attacks on our test range. Non-custodial — use amounts you're comfortable trusting to code.
Which network?
Kaspa mainnet, Toccata covenants (active since June 30, 2026). No tokens, no bridges — plain KAS in a covenant script.