Application Owners
Organization or Individual Name
Github - @chainapsis / Org - KPLR
Additional Team Members
- Name: Josh Lee
Role: Product Owner / Primary coodrinator
Background: CEO / Co-founder at Keplr Wallet and Osmosis
Responsibilities: Product, UX, community, release QA, application owner
- Name: Tony Yun
Role: Chief Technical Owner / Software Engineer
Background: Chief Technical Officer and Co-founder at KPLR
Responsibilities: Rust architecture, sync, Keystone, security, migration scheduling, releases
- Name: Nik
Role: Design, UI/UX, and Visualization
Background: Designs at KPLR
Responsibilities: All product design and migration UX
- Name: Kamal
Role: Quality assurance, testing, and product management
Background: Solutions architect and primary QA testing
Responsibilities: Desktop, mobile, Keystone, and migration QA
How did you learn about the Lockbox: Coinholder Retroactive Grants Program?
Recommended by Dev Ojha
Requested Grant Amount (USD)
360000
Category
Wallets
Project Summary
Vizor is an Apache-2.0 self-custody Zcash wallet delivered across macOS, Windows, Linux, iOS, and Android, with shielded transactions, multi-account support, transparent-fund shielding, air-gapped Keystone signing, Pay, swaps, coinholder voting, and current Zcash protocol support. Its clearest measurable impact came at Ironwood activation, when CipherScan identified Vizor as the first end-user wallet with full ZIP-318 migration compliance.
Project Description
KPLR requests $360,000 retroactively for the complete Vizor wallet delivered from mid-March through August 7, 2026. This application does not request funding for a future roadmap. The wallet, releases, hardware-signing path, and Apache-2.0 source code are already public and available for review.
Complete self-custody wallet
Vizor gives users a modern, non-custodial interface for Zcash. Users can create or restore a wallet, receive through Unified Addresses or transparent addresses, shield transparent funds, send shielded ZEC, attach encrypted memos, review transaction history, and manage multiple accounts without giving a hosted service control of their keys.
The wallet includes configurable lightwalletd endpoints, sync and balance states, an app password, privacy mode, transparent-address rotation, ZIP-317 fees, ZIP-320 TEX addresses, the June 3 Orchard circuit update, and signed or notarized releases. The same modified Rust core based on librustzcash supports Flutter interfaces across macOS, Windows, Linux, iOS, and Android.
Hardware security and wallet utility
Vizor supports air-gapped Keystone accounts through animated-QR PCZT exchange. Users prepare a transaction in Vizor, authorize it on Keystone, and return the signed result without connecting the signing device by USB or network. The hardware path supports ordinary transfers, shielding, swaps, voting, and multi-transaction Ironwood migration.
Vizor also expands how holders can use shielded ZEC:
- Pay: recipient entry and scanning, recent recipients, address-book support, amount review, encrypted memos, and activity status.
- Cross-chain swaps: NEAR Intents quotes, ZEC deposit preparation, external settlement tracking, recovery states, and Keystone authorization.
- Coinholder voting: proposal discovery, vote commitments and shares, submission tracking, interrupted-session recovery, and software or Keystone signing.
- Account and activity UX: unified transfer and swap history, recipient labels, progress and failure states, and responsive desktop and mobile layouts.
Ironwood as proof of product impact
Ironwood required every part of the wallet—sync, account state, transaction construction, proofs, signing, background execution, recovery, release operations, and user communication—to work together under a fixed mainnet deadline.
After the activation height was confirmed on July 10, Vizor shipped its production migration implementation when Ironwood activated on July 28. The completed system includes canonical 1-2-5 denominations, boundary-aligned anchors, shared expiry buckets, randomized scheduling, large-holder denominations, diversified submission endpoints, and fail-closed broadcast checks.
Users can choose between a staged private migration and an explicit immediate migration, see the schedule, stop or switch modes, resume interrupted work, and recover expired transfers. Mobile builds use iOS BGProcessingTask and Android WorkManager to broadcast prepared transactions in the background. Keystone users can authorize batches of up to 35 migration transactions through one QR session with idempotent recovery.
Mainnet operation also produced improvements across the wallet. KPLR and Valar Group eliminated 92% of hot-path wallet-summary calls, fixed a 3.5× sync regression, made account switching about 10× faster, and measured 30–50% faster migration phases. Five stabilization releases followed activation through August 3.
Vizor’s mainnet observations also informed the open [ZIP-318 timing proposal](ZIP 318: Shorten migration timing by ValarDragon · Pull Request #1343 · zcash/zips · GitHub). [librustzcash #2855](Adopt the revised ZIP 318 migration timing by nuttycom · Pull Request #2855 · zcash/librustzcash · GitHub) adopted the resulting constants, including a reduction in the transfer-delay mean from 144 to 66 blocks.
Why retroactive funding is appropriate
KPLR funded Vizor without Zcash ecosystem funding or pre-arranged compensation. Coinholders are evaluating a completed product with public releases, open code, app listings, a working hardware path, and observable mainnet impact rather than a staffing plan or forecast. Ironwood is the strongest evidence of the wallet’s impact, but the funded output is the complete Vizor product and its contribution to Zcash’s wallet ecosystem.
Technical Approach (how you did it)
Vizor uses Flutter and Dart for its multi-platform interface and orchestration layer over a modified Rust core based on librustzcash, connected through flutter_rust_bridge. Rust owns the security- and protocol-sensitive path: account state, chain sync, note selection, transaction construction, proof generation, signing state, and ZIP-318 scheduling. SQLite persists wallet, activity, and migration state so long-running or interrupted operations can resume instead of restarting.
The wallet connects to lightwalletd over gRPC. Users select a preset or custom endpoint before account creation. Migration submission is diversified across endpoints to reduce dependence on one broadcaster. Mobile background execution uses iOS BGProcessingTask and Android WorkManager to submit transactions that have already been prepared and signed.
Keystone integration uses animated QR codes and PCZTs instead of USB or a network connection. Vizor prepares and proves transactions, Keystone authorizes them, and Vizor imports the signed result into the same persistent workflow used by software accounts. Ironwood extended this design to resumable batches of migration transactions.
Pay, swaps, and voting build on the same wallet state rather than moving users into separate custodial systems. Pay composes standard Zcash transactions with recipient, memo, and activity UX. Swaps obtain a NEAR Intents route, prepare a ZEC deposit, track external settlement, and retain a recoverable activity record. Voting derives eligibility from wallet state and supports commitment, share, submission, and recovery flows with software or Keystone signing.
CI covers Flutter, Rust, and regtest migration simulations. Test paths cover preparation, scheduled transfer, expiry, retry, interruption, and completion. Distribution uses signed or notarized desktop builds, platform-native update channels, the Apple App Store, and Google Play. The repository includes build and release-verification instructions so reviewers can inspect the code behind the published applications.
Time Period of Work Completion
March 2026 – August 7, 2026
Total Budget (USD)
360000
Budget Breakdown
- Compensation
- Amount: $340,000
- Justification: Completed engineering, product, design, QA, release, and operational work for the Vizor wallet.
- Technology/Software
- Amount: $0
- Justification: No separate amount requested; core dependencies and development tooling are open source or included in compensation.
- Infrastructure/Hosting
- Amount: $10,000
- Justification: CI/CD, code signing and notarization, lightwalletd infrastructure, and validator operation.
- Services/Contractors
- Amount: $10,000
- Justification: Test devices, Keystone units, legal policies, and app-store compliance.
- Other
- Amount: $0
- Justification: None.
- Total: $360,000
Previous Funding
No
Previous Funding Details
KPLR and Vizor have not received funding from the Zcash Coinholder Grants Program or another Zcash ecosystem grant program.
Other Funding Sources
Yes
Other Funding Sources Details
KPLR raised venture financing for Keplr Wallet and funded Vizor internally from company resources. No Zcash ecosystem funding or pre-arranged compensation funded the completed work covered by this application.
Success Metrics
Shipped product
- A complete self-custody wallet spanning account creation and recovery, shielded receive and send, transparent-fund shielding, memos, multi-account management, activity history, and privacy controls.
- Distribution across macOS, Windows, Linux, iOS, and Android from one Flutter/Rust architecture.
- Air-gapped Keystone support for ordinary transactions, shielding, swaps, voting, and Ironwood migration.
- Shipped Pay, cross-chain swaps, coinholder voting, ZIP-317 fees, ZIP-320 TEX addresses, transparent-address rotation, and the June 3 Orchard circuit update.
- Apache-2.0 source, signed or notarized releases, verification instructions, and regtest coverage.
Observable Ironwood impact
CipherScan’s August 6 snapshot—before later compliant wallet integrations were listed—contained 5,666 Orchard-to-Ironwood transactions. Its classifier grouped 1,521 transactions moving 854,446.52 ZEC into the current-SDK family. Of those, 1,500 transactions moving 831,943.52 ZEC passed all three full-compliance checks: standard denomination, expected Orchard/Ironwood action structure, and a boundary-aligned anchor.
The corresponding network overview reported 1,194,271 ZEC moving from Orchard into Ironwood. The fully compliant current-SDK footprint represented roughly 70% of observed Orchard-to-Ironwood value at that snapshot. CipherScan then listed Vizor and the reference implementation as the fully compliant entries; because the reference implementation was not an end-user wallet, this is the best available public estimate of migration through Vizor during that period.
This attribution is based on timing and transaction fingerprints, not a cryptographic wallet identifier. The estimate excludes transactions that only partially matched ZIP-318 or belonged to separately identified implementation families.
Ecosystem impact
- Vizor was the first end-user wallet CipherScan identified as fully ZIP-318 compliant.
- Mainnet observations informed zcash/zips #1343, and librustzcash #2855 adopted the resulting timing constants.
- Mainnet stabilization eliminated 92% of hot-path wallet-summary calls, fixed a 3.5× sync regression, made account switching about 10× faster, and improved measured migration phases by 30–50%.
- The public Flutter/Rust implementation gives other Zcash teams a production reference for wallet UX, hardware signing, background execution, recovery, and ZIP-318 integration.
Proof of completion
Repository and code
- Vizor repository - Apache-2.0 Flutter/Rust wallet source, tests, release tooling, and verification instructions.
- Keystone integration PR #6 - air-gapped PCZT signing.
- Required before submission: add and link
CONTRIBUTING.md.
Deployments and releases
- Desktop activation release v0.0.39 — Ironwood activation release.
- Vizor releases — published desktop releases and stabilization history.
- Vizor on the Apple App Store — production iOS listing.
- Vizor on Google Play — production Android listing.
External and upstream evidence
- CipherScan Ironwood tracker — migration totals, transaction analysis, and wallet-readiness classification.
- CipherScan migration privacy dataset — transaction-family and full-compliance data.
- CipherScan migration overview — Orchard inflow and network totals.
- ZIP-318 timing proposal — credits Vizor’s measurements and recommendations.
- librustzcash #2855 — adoption of the resulting timing constants.
Conflict of Interest Disclosure
Conflict of Interest Disclosure
- Swap fees: KPLR receives a share of the NEAR Intents route fee on swaps executed through Vizor. Current revenue does not cover Vizor’s operating costs.
- Company funding: KPLR funded Vizor from company resources originally raised for its broader wallet business. Vizor received no Zcash ecosystem funding for the completed work in this application.
- Validator: KPLR operates a coinholder-voting-chain validator and may receive at-cost infrastructure compensation.
- Collaborations: KPLR worked with Valar Group on ZIP-318, sync, and usability improvements, and with Keystone on Ironwood-ready firmware. This request covers only KPLR’s work.
- Organizational roles: No KPLR personnel hold roles at FPF, ZCG, Zcash Foundation, or Shielded Labs.