Retroactive Grant Application - Vizor Wallet

Application Owners

@dogemos

Organization or Individual Name

Github - @chainapsis / Org - KPLR

Additional Team Members

- Name: Josh Lee
  Role: Product Owner / Primary coodrinator 
  Background: CEO / Co-founder at Keplr Wallet and Osmosis
  Responsibilities: Product, UX, community, release QA, application owner
- Name: Tony Yun
  Role: Chief Technical Owner / Software Engineer
  Background: Chief Technical Officer and Co-founder at KPLR
  Responsibilities: Rust architecture, sync, Keystone, security, migration scheduling, releases
- Name: Nik
  Role: Design, UI/UX, and Visualization
  Background: Designs at KPLR
  Responsibilities: All product design and migration UX
- Name: Kamal
  Role: Quality assurance, testing, and product management
  Background: Solutions architect and primary QA testing
  Responsibilities: Desktop, mobile, Keystone, and migration QA

How did you learn about the Lockbox: Coinholder Retroactive Grants Program?

Recommended by Dev Ojha

Requested Grant Amount (USD)

360000

Category

Wallets

Project Summary

Vizor is an Apache-2.0 self-custody Zcash wallet delivered across macOS, Windows, Linux, iOS, and Android, with shielded transactions, multi-account support, transparent-fund shielding, air-gapped Keystone signing, Pay, swaps, coinholder voting, and current Zcash protocol support. Its clearest measurable impact came at Ironwood activation, when CipherScan identified Vizor as the first end-user wallet with full ZIP-318 migration compliance.

Project Description

KPLR requests $360,000 retroactively for the complete Vizor wallet delivered from mid-March through August 7, 2026. This application does not request funding for a future roadmap. The wallet, releases, hardware-signing path, and Apache-2.0 source code are already public and available for review.

Complete self-custody wallet

Vizor gives users a modern, non-custodial interface for Zcash. Users can create or restore a wallet, receive through Unified Addresses or transparent addresses, shield transparent funds, send shielded ZEC, attach encrypted memos, review transaction history, and manage multiple accounts without giving a hosted service control of their keys.

The wallet includes configurable lightwalletd endpoints, sync and balance states, an app password, privacy mode, transparent-address rotation, ZIP-317 fees, ZIP-320 TEX addresses, the June 3 Orchard circuit update, and signed or notarized releases. The same modified Rust core based on librustzcash supports Flutter interfaces across macOS, Windows, Linux, iOS, and Android.

Hardware security and wallet utility

Vizor supports air-gapped Keystone accounts through animated-QR PCZT exchange. Users prepare a transaction in Vizor, authorize it on Keystone, and return the signed result without connecting the signing device by USB or network. The hardware path supports ordinary transfers, shielding, swaps, voting, and multi-transaction Ironwood migration.

Vizor also expands how holders can use shielded ZEC:

  • Pay: recipient entry and scanning, recent recipients, address-book support, amount review, encrypted memos, and activity status.
  • Cross-chain swaps: NEAR Intents quotes, ZEC deposit preparation, external settlement tracking, recovery states, and Keystone authorization.
  • Coinholder voting: proposal discovery, vote commitments and shares, submission tracking, interrupted-session recovery, and software or Keystone signing.
  • Account and activity UX: unified transfer and swap history, recipient labels, progress and failure states, and responsive desktop and mobile layouts.

Ironwood as proof of product impact

Ironwood required every part of the wallet—sync, account state, transaction construction, proofs, signing, background execution, recovery, release operations, and user communication—to work together under a fixed mainnet deadline.

After the activation height was confirmed on July 10, Vizor shipped its production migration implementation when Ironwood activated on July 28. The completed system includes canonical 1-2-5 denominations, boundary-aligned anchors, shared expiry buckets, randomized scheduling, large-holder denominations, diversified submission endpoints, and fail-closed broadcast checks.

Users can choose between a staged private migration and an explicit immediate migration, see the schedule, stop or switch modes, resume interrupted work, and recover expired transfers. Mobile builds use iOS BGProcessingTask and Android WorkManager to broadcast prepared transactions in the background. Keystone users can authorize batches of up to 35 migration transactions through one QR session with idempotent recovery.

Mainnet operation also produced improvements across the wallet. KPLR and Valar Group eliminated 92% of hot-path wallet-summary calls, fixed a 3.5× sync regression, made account switching about 10× faster, and measured 30–50% faster migration phases. Five stabilization releases followed activation through August 3.

Vizor’s mainnet observations also informed the open [ZIP-318 timing proposal](ZIP 318: Shorten migration timing by ValarDragon · Pull Request #1343 · zcash/zips · GitHub). [librustzcash #2855](Adopt the revised ZIP 318 migration timing by nuttycom · Pull Request #2855 · zcash/librustzcash · GitHub) adopted the resulting constants, including a reduction in the transfer-delay mean from 144 to 66 blocks.

Why retroactive funding is appropriate

KPLR funded Vizor without Zcash ecosystem funding or pre-arranged compensation. Coinholders are evaluating a completed product with public releases, open code, app listings, a working hardware path, and observable mainnet impact rather than a staffing plan or forecast. Ironwood is the strongest evidence of the wallet’s impact, but the funded output is the complete Vizor product and its contribution to Zcash’s wallet ecosystem.

Technical Approach (how you did it)

Vizor uses Flutter and Dart for its multi-platform interface and orchestration layer over a modified Rust core based on librustzcash, connected through flutter_rust_bridge. Rust owns the security- and protocol-sensitive path: account state, chain sync, note selection, transaction construction, proof generation, signing state, and ZIP-318 scheduling. SQLite persists wallet, activity, and migration state so long-running or interrupted operations can resume instead of restarting.

The wallet connects to lightwalletd over gRPC. Users select a preset or custom endpoint before account creation. Migration submission is diversified across endpoints to reduce dependence on one broadcaster. Mobile background execution uses iOS BGProcessingTask and Android WorkManager to submit transactions that have already been prepared and signed.

Keystone integration uses animated QR codes and PCZTs instead of USB or a network connection. Vizor prepares and proves transactions, Keystone authorizes them, and Vizor imports the signed result into the same persistent workflow used by software accounts. Ironwood extended this design to resumable batches of migration transactions.

Pay, swaps, and voting build on the same wallet state rather than moving users into separate custodial systems. Pay composes standard Zcash transactions with recipient, memo, and activity UX. Swaps obtain a NEAR Intents route, prepare a ZEC deposit, track external settlement, and retain a recoverable activity record. Voting derives eligibility from wallet state and supports commitment, share, submission, and recovery flows with software or Keystone signing.

CI covers Flutter, Rust, and regtest migration simulations. Test paths cover preparation, scheduled transfer, expiry, retry, interruption, and completion. Distribution uses signed or notarized desktop builds, platform-native update channels, the Apple App Store, and Google Play. The repository includes build and release-verification instructions so reviewers can inspect the code behind the published applications.

Time Period of Work Completion

March 2026 – August 7, 2026

Total Budget (USD)

360000

Budget Breakdown

  • Compensation
    • Amount: $340,000
    • Justification: Completed engineering, product, design, QA, release, and operational work for the Vizor wallet.
  • Technology/Software
    • Amount: $0
    • Justification: No separate amount requested; core dependencies and development tooling are open source or included in compensation.
  • Infrastructure/Hosting
    • Amount: $10,000
    • Justification: CI/CD, code signing and notarization, lightwalletd infrastructure, and validator operation.
  • Services/Contractors
    • Amount: $10,000
    • Justification: Test devices, Keystone units, legal policies, and app-store compliance.
  • Other
    • Amount: $0
    • Justification: None.
  • Total: $360,000

Previous Funding

No

Previous Funding Details

KPLR and Vizor have not received funding from the Zcash Coinholder Grants Program or another Zcash ecosystem grant program.

Other Funding Sources

Yes

Other Funding Sources Details

KPLR raised venture financing for Keplr Wallet and funded Vizor internally from company resources. No Zcash ecosystem funding or pre-arranged compensation funded the completed work covered by this application.

Success Metrics

Shipped product

  • A complete self-custody wallet spanning account creation and recovery, shielded receive and send, transparent-fund shielding, memos, multi-account management, activity history, and privacy controls.
  • Distribution across macOS, Windows, Linux, iOS, and Android from one Flutter/Rust architecture.
  • Air-gapped Keystone support for ordinary transactions, shielding, swaps, voting, and Ironwood migration.
  • Shipped Pay, cross-chain swaps, coinholder voting, ZIP-317 fees, ZIP-320 TEX addresses, transparent-address rotation, and the June 3 Orchard circuit update.
  • Apache-2.0 source, signed or notarized releases, verification instructions, and regtest coverage.

Observable Ironwood impact

CipherScan’s August 6 snapshot—before later compliant wallet integrations were listed—contained 5,666 Orchard-to-Ironwood transactions. Its classifier grouped 1,521 transactions moving 854,446.52 ZEC into the current-SDK family. Of those, 1,500 transactions moving 831,943.52 ZEC passed all three full-compliance checks: standard denomination, expected Orchard/Ironwood action structure, and a boundary-aligned anchor.

The corresponding network overview reported 1,194,271 ZEC moving from Orchard into Ironwood. The fully compliant current-SDK footprint represented roughly 70% of observed Orchard-to-Ironwood value at that snapshot. CipherScan then listed Vizor and the reference implementation as the fully compliant entries; because the reference implementation was not an end-user wallet, this is the best available public estimate of migration through Vizor during that period.

This attribution is based on timing and transaction fingerprints, not a cryptographic wallet identifier. The estimate excludes transactions that only partially matched ZIP-318 or belonged to separately identified implementation families.

Ecosystem impact

  • Vizor was the first end-user wallet CipherScan identified as fully ZIP-318 compliant.
  • Mainnet observations informed zcash/zips #1343, and librustzcash #2855 adopted the resulting timing constants.
  • Mainnet stabilization eliminated 92% of hot-path wallet-summary calls, fixed a 3.5Ă— sync regression, made account switching about 10Ă— faster, and improved measured migration phases by 30–50%.
  • The public Flutter/Rust implementation gives other Zcash teams a production reference for wallet UX, hardware signing, background execution, recovery, and ZIP-318 integration.

Proof of completion

Repository and code

  • Vizor repository - Apache-2.0 Flutter/Rust wallet source, tests, release tooling, and verification instructions.
  • Keystone integration PR #6 - air-gapped PCZT signing.
  • Required before submission: add and link CONTRIBUTING.md.

Deployments and releases

External and upstream evidence

Conflict of Interest Disclosure

Conflict of Interest Disclosure

  • Swap fees: KPLR receives a share of the NEAR Intents route fee on swaps executed through Vizor. Current revenue does not cover Vizor’s operating costs.
  • Company funding: KPLR funded Vizor from company resources originally raised for its broader wallet business. Vizor received no Zcash ecosystem funding for the completed work in this application.
  • Validator: KPLR operates a coinholder-voting-chain validator and may receive at-cost infrastructure compensation.
  • Collaborations: KPLR worked with Valar Group on ZIP-318, sync, and usability improvements, and with Keystone on Ironwood-ready firmware. This request covers only KPLR’s work.
  • Organizational roles: No KPLR personnel hold roles at FPF, ZCG, Zcash Foundation, or Shielded Labs.
5 Likes

Note on submission timing: This proposal was submitted shortly after the Q3 deadline. I’m typically based in Asia but am currently traveling in the US, and I miscalculated the time-zone conversion for the cutoff. I apologize for the delay and have asked the program administrators whether they can accept the late submission. I’m posting it here for transparency and community feedback while awaiting their decision.

1 Like

We’re unable to accept late submissions for any reasons. Q4 will roll around quickly and then you can resubmit.

1 Like

Absolutely love Vizor wallet, would have voted yes on this round and will vote yes on the next one.

5 Likes