Devnet

Reach your confidential balances without Sotto

Sotto derives your confidential keys the standard way: your wallet signs the message solana-conf-bal/v1 and the keys come from that signature. The Solana command line tool spl-token derives the same keys from the same wallet. We checked this with spl-token-cli 5.6.1: it configures the same encryption key, and our key decrypts the balance it records. So if your wallet stops signing that message in Sotto, or Sotto is not available, you can still move your confidential balance back to a public balance. A small script from Sotto's source code tells you the exact amount.

What you need

  • The Solana command line tools: solana, solana-keygen and spl-token.
  • Node.js 24 and pnpm, to run Sotto's recovery script. It is part of Sotto's source code (github.com/anilkaracay/sotto), which Sotto publishes at its public launch.
  • Your wallet's recovery phrase, or its private key exported from the wallet.
  • A little SOL in the wallet for transaction fees.

Do this on your own computer. Never type your recovery phrase or private key into a website, and never share them. Sotto will never ask for them.

1. Create a keypair file for your wallet

From the recovery phrase, which the tool asks you to type:

solana-keygen recover 'prompt://?key=0/0' --outfile wallet.json

This recovers the account at the derivation path m/44'/501'/0'/0'. If you exported the private key from your wallet instead, pass it in place of 'prompt://?key=0/0'; it then stays in your shell history, so clear the history afterwards.

2. Check that it is your wallet

solana-keygen pubkey wallet.json

This must print your wallet address. If it prints another address, stop: the file is a different account of your recovery phrase, and you can export the account's private key from your wallet instead.

3. Point the tools at your wallet and the network

solana config set --keypair wallet.json --url devnet

4. Move pending tokens into your available balance

spl-token apply-pending-balance AhJfP4JJBaHWRtXRiaScZUC7SMm4RqUPSb3g9H5RT8Bd

5. Find the exact amount

In a copy of Sotto's source code, after pnpm install:

node scripts/recover-balance.ts --keypair wallet.json --mint AhJfP4JJBaHWRtXRiaScZUC7SMm4RqUPSb3g9H5RT8Bd --url devnet

The script derives your keys on your computer, the same keys Sotto and spl-token derive, reads your token account, and prints the available and pending balances with the exact command for the next step. It sends nothing: no transaction, and your keys stay on your computer. If it still shows a pending balance, repeat step 4 first.

6. Move the confidential balance to your public balance

spl-token withdraw-confidential-tokens AhJfP4JJBaHWRtXRiaScZUC7SMm4RqUPSb3g9H5RT8Bd <amount>

Use the command the script printed: it has the exact amount, in whole tokens. The keyword ALL is not supported for this command in spl-token-cli 5.6.1.

After recovery

The tokens are now a public wUSDC balance of your wallet, which any Solana wallet can send. During the devnet beta they are test tokens. wUSDC on devnet is wrapped by Sotto's test deployment of Token Wrap, which the standard spl-token-wrap tool cannot address. To unwrap it to devnet USDC, build the tool for that deployment from Sotto's source code (it needs Rust with cargo 1.98.1), create a USDC account if you have none, and unwrap:

scripts/build-token-wrap.sh --cli
spl-token create-account 4zMMC9srt5Ri5X14GAgXhaHii3GnPAEERYPJgZJDncDU
.cache/token-wrap/cli/target/release/spl-token-wrap unwrap <wUSDC token account> <USDC token account> <amount in base units>

The wUSDC token account is the one the script printed. Unwrap amounts are in base units: 1 wUSDC is 1000000.

Back to Sotto