silentpayments.net
Kill the bitcoin address
A · Reach
| A1 | BTCPay Server integration: invoice footer generator, WooCommerce pay by name, and upstream PRs adding payment-name support to BTCPay's own Invoices and Point of Sale apps, same plugin architecture, one upstream project | M |
| A2 | NIP-05 on the same names, both directions: the name proves nostr identity (NIP-05), and a claim linked to an npub pushes the resolved payment info into that user's kind-0 profile, so nostr clients show "pay this person" natively | M |
B · Product
| B1 | Own-domain page: a form that hands you the exact DNS TXT record to paste into your own domain, so a name lives at you@yourdomain.com instead of you@silentpayments.net. We publish nothing; the record only exists wherever you paste it | S |
| B2 | Name transfer and key rotation | L |
| B3 | Takedown path | S |
| B4 | Site copy, remaining pages | S |
C · Trust and verification
| C1 | One public page: uptime for every service we run (node, Fulcrum, Frigate, silentpayments.net), a self-check anyone can run (DNS, the log recomputed independently, the checkpoints), and the growth stats (names claimed, log entries) with the same verify link on every number: trust, ops and growth stats in one place instead of three separate builds nobody finds | L |
| C2 | Per-name signed events | M |
| C3 | Audit | M |
| C4 | Disclose wallet defects found | S |
| C5 | Write BIP-353 security considerations | M |
| C6 | BIP-353 conformance suite | L |
| C7 | Co-signed changes, opt-in for key-owned names, building on C2's per-name signed events: the name's own Nostr key must sign off before a DNS record change takes effect, so an unauthorized change is blocked, not just logged | L |
| C8 | Live integrity feed: publish every log entry as its own Nostr event, not just the 6-hourly head checkpoint, so a client can alert in real time | M |
| C9 | Encrypted DM alerts (NIP-44): if a name holder has linked an npub, DM them the moment their record changes | S |
| C10 | Checkpoint the live DNS state, not just our own log: a separate process independently resolves every name and publishes that as its own signed Nostr event, so a stolen Cloudflare token editing DNS directly, bypassing the app entirely, still gets caught | L |
| C11 | Public NIP-51 watch-lists: anyone, not just the name holder, can publish "I'm watching this name" and get notified on any divergence, so a customer or a journalist can monitor a name the same way its owner can | S |
D · Public infrastructure
| D1 | Second IPv4 | S |
| D2 | Clearnet Frigate scanning server | L |
| D3 | Tweak-server shape beside it | L |
| D4 | Redundancy | M |
| D5 | Fulcrum on clearnet | S |
| D6 | Alerting | S |
| D7 | Operating policy published | S |
| D8 | Cloudflare Pro at 150 names | S |
E · Hardware
| E1 | Silent payment receiving on SeedSigner, a world first: no hardware wallet anywhere can do this yet | XL |
| E2 | Airgapped scan handoff | L |
| E3 | Read SeedSigner #769 | S |
| E4 | Same on ShieldSigner | M |
| E5 | Reference implementation and test vectors | M |
| E6 | Update wallet matrix | S |
F · Research
| F1 | Publish negative results | S |
| F2 | Scanning appliance | L |
| F3 | Explore a Cashu nutzap bridge (NIP-61): can a Nostr nutzap settle into a claimed name's Lightning path, receiving without an LNURL server | S |
G · Unjudged
| G1 | Organisation names | M |
| G2 | One-click via DNS providers: automate B1's manual TXT-record paste through major DNS providers' own APIs (Cloudflare, Namecheap), for the non-technical domain owners who never get past "what's a TXT record" | M |
| G3 | Paid tier: a one-time fee for names under N characters, price scaling with shortness, the anti-squat mechanism that makes short names viable. Paid by Lightning invoice at claim time, NWC for one-tap, no account or email | M |
| G4 | Alarm as a standalone service, not bundled into the StartOS client: the real monitor H2 promises, watching any name and not just ours, without needing a payment key to run it | M |
| G5 | Shorter domain | S |
| G6 | Self-host / white-label: let others run their own instance. Requires open-sourcing services/silentpayments/ itself, not just the StartOS client package | L |
| G7 | Companion wallet or browser extension that resolves these names end-to-end, instead of waiting on third-party wallets to adopt BIP-353 | L |
I · Growth and network effects
| I1 | Viral loop: every /card and widget.js embed carries a "claim your own name free" link, so every payment shown becomes a recruitment moment, not just a transaction | S |
| I2 | A tiny open SDK wrapping /api/check, /api/claim and /api/resolve, so a third-party developer can integrate in minutes without reading the API docs from scratch | S |
| I3 | Get listed in curated bitcoin-ecosystem directories: being listed transfers the curator's existing trust, cheaper than building trust from scratch each time. Two concrete targets: Sparrow's hardcoded server list (earned by running a good clearnet Frigate server, D2) and the Umbrel App Store (a second self-hosted distribution channel beside Start9's Community registry) | M |
H · Outside this workspace
| H1 | Cheap private receiving. Make scanning your own payments cheap enough that a wallet turns it on by default, instead of an expert setting. | XXL |
| H2 | Name transparency. Certificate Transparency applied to payment names, so trusting the operator is provable rather than assumed. | XXL |