Live edition loading…

PXke Algorand

Independent daily coverage of the Algorand ecosystem — verified reporting on wallets, DeFi, NFTs and infrastructure, fact-checked on-chain before it publishes.

← Latest stories

Sealed's Android messenger is live, but its Algorand contract remains Testnet-only

· · · · · · ·

Sealed's Android messenger is live, but its Algorand contract remains Testnet-only

The demo conversation on Sealed's homepage ends the way almost no messenger preview does: instead of a reply, one participant pastes a long random string between '---Begin Message---' and '---End Message---' markers. That visual is the whole product in miniature. Sealed is a messenger whose answer to the server inside every mainstream chat app is to not have one — messages travel as encrypted blobs written into Algorand transactions, and identity is a wallet generated on the user's device, with no phone number, email, or username required.

The project is young, and its own materials say so: the sealed.channel domain was registered on December 16, 2025, the first public source release landed on June 18, 2026, and the app is Android-only for now — on Google Play and as a direct APK, with the App Store marked 'coming soon'. One caveat belongs up front: despite the site's 'Fully Anonymous Multi-Chain Messenger' title, the documentation describes exactly one blockchain — Algorand — and the docs' own search assistant, asked which other chains are supported, answers that none are listed.

One message, one transaction

The documented flow keeps plain text on the sending device at all times; it is never transmitted for routing, moderation, or storage. According to the encryption docs, message content is sealed with AES-GCM using a key derived through HKDF, and the key exchange is hybrid: X25519, a widely used classical method, combined with ML-KEM-512, a NIST-standardized mechanism designed to resist quantum computers. The stated purpose is to blunt 'save now, decrypt later' attacks, in which encrypted data is harvested today in the hope that future hardware can crack it, and the exchange is paired with a fresh ephemeral keypair per message for forward secrecy. The ciphertext is padded to a uniform 1KB, then submitted as an app-call transaction to the Sealed smart contract on Algorand.

Receiving reverses the process: the app scans chain data for a per-message encrypted hint derived from the recipient's wallet — a hint that changes every time, so an outside observer cannot easily group messages into one conversation — and decrypts locally. Delivery deliberately avoids direct wallet-to-wallet transfers: everyone calls the same contract function, so no simple sender-to-recipient edge is visible in the public record. One message per transaction is practical here because Algorand blocks finalize in roughly three seconds and fees are negligible, so each message confirms almost instantly at a fraction of a cent of protocol cost. Fees are paid by a treasury escrow through a two-transaction fee-pool group: the escrow fronts the network fee while the user's messaging wallet signs only the app-call, which means the messaging wallet never pays gas and does not need to hold ALGO at all.

The important status caveat: the contract in the repository is marked 'v1 TestNet only', the deployment the integration docs reference was created on July 20, 2026 on Algorand's Testnet, and the xGov proposal describes payloads embedded in 'Algorand TestNet' transactions. The site's roadmap lists a mainnet launch in Q2 2026 — now past — but no mainnet contract is verifiable on-chain, so the current build should be treated as a testnet-backed early release rather than a production messenger.

Metadata is the real target

The docs argue that encryption alone is not privacy: the surrounding signals — message size, timing, IP addresses, payment patterns — are where anonymity usually leaks. Sealed layers protections around the encrypted blob. Alias Chat creates a fully separate channel in which both sides use locally chosen aliases and freshly generated temporary wallets, started by a one-time network invitation or an offline QR exchange; each temporary wallet is funded by a separate 50-message credit package and rotated as it drains, so the conversation never builds a long-lived wallet trail — at the cost of being device-bound and unrecoverable if the phone is lost. Every request to the Algorand RPC passes through OHTTP (Oblivious HTTP), which splits the connection so the node processes the request without seeing the device's IP — a protection that relies on a relay and a gateway not colluding, a trust assumption the project's own SECURITY.md states. Push notifications exist but are disabled by default, because they route through an open-source indexer operated by Sealed and add timing metadata.

What the marketing page promises and what the project's own docs concede are two different things, and the gap is worth a table.

ConceptReal-World Implication
'Zero-Trace Security' / 'completely secure, untraceable communication' (site)The docs state plainly: 'These mechanisms do not make every trace disappear. No honest privacy system should claim that.' SECURITY.md lists message timing and frequency as observable on the blockchain.
'No metadata collected' (site)On-chain transaction timing and frequency remain visible to network monitors; enabling notifications additionally exposes delivery metadata to Apple or Google push systems.
'Serverless communication — no middleman, no server' (site)Core delivery has no central message server, but Sealed operates the optional open-source notification indexer and the web top-up flow; the OHTTP relay and gateway add two infrastructure operators to the trust model.
'Fully anonymous' (site)Shared-contract delivery and changing hints obscure relationship graphs, but the wallet addresses that submit transactions are public record.

Paying without being identified

Sealed separates funding from messaging with a credit system. A user deposits ALGO on the top-up page — connecting Pera, Defly, or Lute — and receives a code worth 500 credits, equal to 500 messages, for every 10 ALGO deposited. The fixed denomination matters: identical codes prevent amount-based fingerprinting. Codes are redeemed through a Merkle-tree privacy pool the docs describe as 'inspired by Tornado Cash', in which many identical deposit commitments sit in one shared structure and activation proves ownership of a valid code without revealing which deposit created it — the docs compare it to putting identical sealed envelopes in a box and proving you hold one without opening it. That separation is only as strong as the pool's volume: with one deposit and one activation the link is trivial to guess, which is why the docs advise waiting to activate a code so more activity accumulates between deposit and redemption. Because the escrow covers network fees (as noted above), the messaging wallet itself still never holds ALGO.

The repo shows the redeem path is a zero-knowledge proof: it ships a Circom circuit and a Groth16 SNARK prover that runs inside the app, so activation demonstrates possession of a valid code without exposing the deposit. On top of credits, the xGov proposal describes a freemium layer — a sponsored number of free messages per day, then roughly $0.003 per message — and the docs outline ALGO-denominated subscription tiers (Sealed+, Sealed PRO, and Sealed Channel for business workspaces), whose exact limits and prices are not published. The docs also lay out a planned SLD token: a fixed 1 billion supply (30% community and airdrops, 20% investors, 20% DAO, 15% team, 10% reserve, 5% liquidity), a planned initial price of $0.025 implying a $25 million fully diluted valuation, 45% of protocol revenue to stakers in 30-day cycles, and a 'POWER' multiplier that grows 0.01x per staked day to 4x and resets on any unstake. Two flags for readers: no SLD or SEALED asset exists on Algorand mainnet — an on-chain name search returns only unrelated NFTs, and the team's known addresses (the xGov proposer and the Testnet contract creator) have created no assets — so the token is a paper design, not a live one; and the staking design concentrates value in the project's own token, a structure that rewards tokenholders rather than message users.

Who is building it, and where it stands

The team is Polish, per the Google Play listing — developer 'SUNSHIP IGOR KAMROWSKI', Sunship Studio, with a Starogard Gdański address and a development@sealed.channel support address — and the xGov proposal names six roles: CEO Igor Makowiecki, CTO Dominik Stępień, Product Owner Igor Kamrowski, Chief Ecosystem Officer Sebastian Seliga, Head of Marketing Grzegorz Pisula, and Head of Design Grzegorz Pawlica. The proposal also cites appearances at Next Block Expo (Warsaw), the Crypto Community Conference (Łódź), ETH Warsaw, and Cashifam (Rzeszów).

The public footprint is small but real. The GitHub repo opened June 18, 2026 with a single initial commit, two stars, and no releases; it contains the Flutter app, the TypeScript smart contract compiled with Puya, the notification indexer, and the Circom circuit. On-chain, the contract referenced above is live on Testnet with stored box state, and the escrow account shows recent payments — verifiable development activity, but weeks old in public form. Google Play shows a '10+' download count, and the Discord server has 37 members with 7 online.

The xGov proposal — 400,000 ALGO, categorized as retroactive — was posted April 27, 2026 and remains in discussion, not approved: the on-chain proposal record shows no approvals and no opened vote. The forum thread drew 21 replies, 494 views, and 18 likes, with a reception ranging from curious to cautious: Algorand Foundation's cusma asked the team to explain 'why a blockchain is needed at all and why specifically Algorand', a councillor advised deferring submission until outstanding issues were solved, and founder Makowiecki answered (paraphrased) that the chain provides identity, message transport, fee settlement, and privacy via OHTTP and top-up masking, and that Algorand was chosen for its low fees, security, scalability, and speed. No independent reviews or Bluesky discussion were found. Notable gaps: the docs' Audits page is empty — no security audit has been published — and pages for Layer 2, Compliance, and risk annotations are stubs.

Trying it today — and what to watch

Anyone can try Sealed now on Android via the Play store or a direct APK; iOS is 'coming soon'. Setup creates a local wallet, then a six-digit access code and a termination code that silently wipes the device when entered under duress; recovery is a 24-word mnemonic, with no password reset possible. The site's whitelist form collects an email for early access, and the docs point to free access through the Discord. Given the Testnet-backed status noted earlier, a message sent today is a real transaction on a value-free test network — a functional demo of the architecture rather than a permanent mainnet record.

The post-quantum positioning lands at a fortunate moment for the ecosystem: on June 18, 2026, the Algorand Foundation announced a roadmap to broad quantum resilience by the end of 2027 — native post-quantum accounts in Pera from Q3 2026, post-quantum multisig, and treasury migration — with Foundation CTO Bruno Martins arguing that 'post-quantum security cannot be retrofitted after Q-Day'. Sealed's ML-KEM-512 sits at the application layer, above the chain's own signature upgrades, so the two efforts are complementary rather than competing.

The honest read: Sealed is a coherent and unusually candid early project — the docs name their own limitations, the code is open, and a Testnet contract is genuinely live. What would make it more than a prototype is exactly what it does not yet have: a mainnet deployment, a completed audit, and a base of users. Until then, it is a promising testnet messenger whose design questions are the right ones.

Source

Source: editorial://brief/7616eb02-d77d-4981-bc92-9c72798e685e