- Add an attested, checksummed `x86_64-unknown-linux-musl` release archive so Linux and Windows WSL users can download and verify keyRX without first compiling its Rust dependency tree. Keep native Windows unsupported until its owner-only file guarantees exist, and keep macOS on the source-build path until signed and notarized native archives can be tested honestly. - Make first-run guidance lead with the prebuilt archive and give source builders one complete official-rustup, Rust 1.85+, Cargo `PATH`, and `cargo install --locked` path. The official prebuilt now points `--update` users back to
After a successful default grind, print the exact copy-ready keyrx show command for every Markdown record just written. The command carries the full managed path, realized address casing, duplicate .02 / .03 suffixes, and the EVM directory without revealing seeds or private keys. A successful explicit --out FILE grind keeps its established completion-line form; any grind that later fails persistence or custody now withholds every completion command.
Save every default grind hit as its own mode-0600 Markdown recovery record. Uppercase field headings put each address, path, seed, and key on the following line; Solana records include the base58 and JSON forms, while EVM records carry only the 0x private key. - Name each record after both the requested pattern and the exact casing that actually matched: --ends-with coined --ignore-case can produce coined.ic.coiNED.md. A repeated exact result is created without overwrite as .02.md, .03.md, and so on. Prefix and combined-edge searches preserve their realized address text the same wa
Make an interrupted automatic release resume through the normal tag-only workflow. Inert drafts are found across every authenticated release page, and discovery, upload, publication and final verification remain bound to one numeric GitHub Release identity. - Pin every Cargo publish and yank operation to crates.io, then retire one normal predecessor plus one interrupted predecessor only after the new crate and immutable release are independently revalidated. - Add behavior-driven controls for pagination, duplicate draft producers, empty-draft races, upload-response identity and digest checks
Restore the normal one-tag release path: a protected version tag, short-lived crates.io OIDC credential, and one sequential run now publish the crate and immutable GitHub Release without a repository-administration token, temporary branch admission, or manual recovery dispatch. - Restore keyrx.sol beside the authoritative Solana address on keyrx.tech, in both desktop and mobile layouts. - Make the concurrent benchmark custody test prove the refusal path from its output and diagnostic instead of depending on wall-clock timing.
Match output and grind coordination are fail-closed: private files are opened without following links, must be caller-owned and single-link, concurrent grinds cannot share a target, exact match counts are reserved before a record is written, bounded files cannot grow beyond the read limit, and invalid zero-work requests are refused. - Secret-bearing values have shorter lifetimes and are zeroized more consistently. verify now returns a failing process status when either chain's self-test fails. Existing EVM records refuse scalar zero before address derivation. - Benchmark caches are bound t
keyrx --help introduces itself as the keyRX CLI too (its summary line was the one place that still said only what it does, not which product it is). Completes 0.4.10. No behaviour change.
The product names itself keyRX CLI wherever it introduces itself: the page title and cards of keyrx.tech, the README, and the crate description (the start screen already read keyRX | CLI). Two products share the keyRX name now, and this is the one with no token; saying CLI every time keeps that sentence true without a footnote. No behaviour change.
The donate panel names the Solana wallet as keyrx.sol only. 0.4.8 printed keyrx.sol · keyrx.sns and called them two spellings of one domain; .sns is not a spelling of anything, so it is gone from the CLI and the site. The addresses are unchanged.
The donate panel names the wallets as well as printing them: keyrx.sol · keyrx.sns (one on-chain domain, two spellings) under the Solana address, keyrx.eth · keyrx.base.eth · keyrx.hoodfi.eth under the EVM address (ENS, Basename, Robinhood Chain), each resolving to the address shown; the address stays the thing to read. The site says the same. The two addresses are now the wallets those names resolve to: Solana 2pSgpgA6TqdynuAdVpFEZbyVRrKi5oTyvxGL9gjKEYRX, EVM 0x036CC610fb2883DB9504dD172FA94fEe89900000; the previous Gi2z…KEYRX and 0x34F0…00000 are retired, so a name and the address u
Every GitHub Release now carries the .crate packaged from the tag, its Sigstore provenance bundle (keyrx- .crate.sigstore.json; check with gh attestation verify keyrx- .crate --owner keyrx) and the CycloneDX SBOM. Robinhood Chain is named among the EVM chains on the start screen, in --help, the README and the site (the same address works there; keyrx networks has its values). No change to grinding, matching or files.
keyrx networks: the first framed row read "network nameRobinhood Chain" - a key one character wider than the key column ran into its value. The key is name; the bare line below the frame still says "network name". Nothing else changes.
keyrx networks: the add-a-network steps for MetaMask and Rabby, and the five values a wallet's form asks for, for EVM chains it does not list by default - framed for reading, then each value bare on its own line for pasting (the rule the keys follow). First entry: Robinhood Chain (Ethereum L2, mainnet), RPC https://rpc.mainnet.chain.robinhood.com, chain ID 4663, ETH, Blockscout explorer; the chain id was checked against that RPC on 2026-08-21, and a test pins the table. The EVM panel, COMMANDS and A TYPICAL SESSION point at it; the site's EVM section carries the same block with click/tap
Import steps said plainly, on both chains: a fresh Phantom or MetaMask insists on a seed phrase first and only then offers a private-key import, so every place that says "import the key" now says "a wallet must exist first (any seed; it never sees this key), then the key import ADDS an account"; and the seed route says "import THIS seed as the wallet, then 'add account' N times: account N+1 is the one". MATCH panel, import hints, the EVM panel, THE 128, RECIPES, README and the site's WALLETS and EVM sections. No functional change.
A TYPICAL SESSION: every row is one line again. The --checksum example was the one command too long for the column and wrapped into a two-line row among one-line rows; it is gone from this panel (RECIPES carries the full --checksum command, and the EVM panel explains the flag). No functional change.
DONATE shows the EVM address: 0x34F08966E43Fb58C5112ae6dB8BbadC2bae00000, one address for every EVM chain, ground with --chain evm (a five-zero suffix, EIP-55 case as printed). The same string is in the site's DONATE panel with click-to-copy. Nothing else changes.
The full EVM pass on the start screen: COMMANDS names both chains and the per-chain bench; THE 128 says what a branch costs on secp256k1 and why --indices buys less there; WHAT A MATCH WRITES carries the EVM four-line block as rows; RECIPES gains EVM (key import) and EVM EIP-55 (--checksum); A TYPICAL SESSION gains bench --chain evm and show evm/dead --keys; verify and show help texts name both chains; estimate --chain evm without a bench says what its model is anchored to. DONATE gains an EVM address slot, empty until the ground wallet is set and shown only then; the ask rea
--chain evm: Ethereum and every EVM chain (Base, Arbitrum, Optimism, Polygon, BNB, Avalanche C-Chain: one key, all of them). The same idea as the Solana path, on secp256k1: one mnemonic pays PBKDF2 once, then the BIP44 tree m/44'/60'/0'/0/N is walked at one HMAC-SHA512 plus one scalar multiplication per candidate; the address is the last twenty bytes of keccak-256 over the public key, written in EIP-55 case. estimate, grind and bench take --chain evm; bench --chain evm measures its own rate and estimate reads it (a separate file, bench-evm.txt, because the two loops cos
Release hygiene, no change to the binary: from this release on, publishing yanks the release before it (and anything listed in ops/yank.txt: 0.3.0, 0.3.1, 0.3.2 go with this one), so a fresh cargo install keyrx can only land on the newest. A yank never deletes a version or breaks an existing install or lockfile; it only stops new installs of a superseded one. If you pinned an old version on purpose, keyrx --update brings you forward.
A TYPICAL SESSION: every row is one line again, command column then note, with at least one column of air before the border (indent 2, gutter 3). The three notes that were trimmed to fit say what they meant. No functional change.
A TYPICAL SESSION: three notes were a character or two past the frame and clipped (the room check counted the gutter wrong). Every note now ends inside the border. No functional change.
The start screen's A TYPICAL SESSION panel now shows the variations, each with a one-line note: verify · bench · estimate --count 10 · grind · --count 10 · --indices 8 for Phantom · --passphrase · --starts-with Key --ends-with RX · --ignore-case · show · show --keys · --update. The site's INSTALL panel gained the --passphrase line. No functional change.
grind --passphrase — a BIP39 passphrase (the "25th word"). Prompted on the terminal, hidden, typed twice; never read from a flag, a file or the environment; never stored, never printed. The grind derives every candidate from PBKDF2(mnemonic, "mnemonic" + passphrase), exactly as every wallet that takes one does. The match file gains one line under the seed — passphrase used - NOT stored: the seed alone will not reach this address; the keys will — the fact, never the passphrase; show marks such matches; the MATCH panel and the GRIND panel say so. Most browser wallets have no passphrase
keyrx estimate --count N — when you intend to grind N matches, the ODDS panel adds "time to all N matches": 50% / 90% / mean, each match an independent wait, so the mean is exactly N times the first match's and the spread narrows as N grows (Gamma quantiles, Wilson–Hilferty). The start screen's --count N entry says so and says all N land in the one file. The site's INSTALL panel shows keyrx grind --ends-with KEYRX --count 10 ten of them, one file.