Wallets & Key Management
Manage keypairs, HD derivation, and signing flows in Rust wallets and validators without leaking secrets.
Search across all documentation pages
Manage keypairs, HD derivation, and signing flows in Rust wallets and validators without leaking secrets.
use ed25519_dalek::SigningKey;
use rand::rngs::OsRng;
struct KeyStore {
signing: SigningKey,
}
impl KeyStore {
fn generate() -> Self {
Self {
signing: SigningKey::generate(&mut OsRng),
}
}
fn sign(&self, msg: &[u8]) -> ed25519_dalek::Signature {
use ed25519_dalek::Signer;
self.signing.sign(msg)
}
}When to reach for this:
HD-style path documentation with explicit derivation crate boundary:
use ed25519_dalek::SigningKey;
use bip39::{Language, Mnemonic, Seed};
use rand::rngs::OsRng;
fn derive_from_mnemonic(words: &str, path: &str) -> anyhow::Result<SigningKey> {
let mnemonic = Mnemonic::parse_in(Language::English, words)?;
let seed = Seed::new(&mnemonic, "");
// Use chain-specific SLIP-0010 or ed25519 derivation crate for `path`
let _ = (seed.as_bytes(), path);
Ok(SigningKey::generate(&mut OsRng)) // placeholder: swap for real derive
}What this demonstrates:
Result instead of panics in wallet UXm/44'/501'/0'/0' map accounts per chain (Solana 501).| Tier | Location | Use |
|---|---|---|
| Hot | App memory | Bots, small balances |
| Warm | Encrypted disk | Daily ops with limits |
| Cold | Hardware/offline | Treasury, upgrade authority |
| Alternative | Use When | Don't Use When |
|---|---|---|
| Browser extension wallet | Consumer dApp UX | Headless server signing |
| Fireblocks/Copper custody | Institutional scale | Self-custody product |
| Turnkey API wallets | Hosted signing SLA | Full on-prem requirement |
| Paper wallet | Cold storage drill | Frequent signing needs |
HSM or cloud KMS with IAM policy; hot keys only hold limited daily float.
Coin type in path selects curve/chain - look up SLIP-0044 registry for your network.
On-chain authority transfer instruction, dual-run period, then revoke old key permissions.
Squads, Gnosis Safe (EVM), or native multisig programs - pick per chain capabilities.
Devnet keys in env vars excluded from prod builds via compile-time cfg flags.
scrypt + AES from Ethereum keystore format or age-encrypted files for CLI wallets.
Separate consensus and commission accounts; never reuse browser extension seed.
Ephemeral keys only; production signing should never run in shared CI runners.
Log pubkey, instruction type, and simulation result - never signature preimage secrets.
See Applied Cryptography for algorithms.
Stack versions: This page was written for Rust 1.97.0 (edition 2024), Tokio 1.x, Axum 0.8, serde 1.0, sqlx 0.8, clap 4, and Polars 0.46+.
Reviewed by Chris St. John·Last updated Jul 16, 2026