Upgrade your wallet to 2-of-2 multisig for $0
and execute with hardware-grade security, forever — the first Proof-of-Intent security protocol across EVM & Solana.
Safe
Squads
GoPlus Security
Blockaid
Turnkey
Solana
Ethereum
Base
Arbitrum
BSC
Hyperliquid
RobinhoodNail your assets to your wallet. Nail your wallet to your device.
Connect Existing Wallet
Link your native EVM or Solana address in one click. Maintain your existing wallet identity and balance; no asset migration, no contract deployments, and no new seed phrases required.
Bind Hardware Device
Pair your device using WebAuthn passkeys. Local authentication leverages your device’s Secure Element to generate an un-phishable, hardware-backed cryptographic device key isolated on-chip.
Enforce On-Chain Multisig
Transact with guaranteed 2-of-2 security. On-chain contracts automatically validate dual signatures before execution; enforced via EIP-7702 Account Abstraction on EVM networks and Squads PDAs on Solana.
The Co-Signing Pipeline
How the firewall intercepts, sanitizes, and signs transactions in milliseconds.
01 | Intent Initiation
The user constructs the transaction. The primary local private key signs the initial payload intent.
02 | Payload Sanitization
The Nail Firewall intercepts the raw payload. It executes rate limiting, payload sanitization, mainnet simulation, and verifies against address and router whitelists.
03 | Out-of-Band Authorization
If the payload passes all simulation checks, the firewall triggers an out-of-band WebAuthn request to the user's hardware Secure Enclave for explicit biometric approval.
04 | The Co-Sign (Key 2)
Upon hardware authorization, the firewall applies Key 2. If any prior security check fails, the transaction is dropped at the firewall level before the co-signing key ever touches the payload.
05 | On-Chain Execution
The fully signed 2-of-2 transaction is broadcast. Protocol-level multisig logic is strictly enforced via EIP-7702 Account Abstraction on EVM networks and Squads PDAs on Solana.
Every movement of funds requires two independent signatures: your private key and your device-bound passkey. An attacker who compromises your private key still cannot move assets without physical control of your device.
Nail Protocol allows you to provision multiple hardware backups to eliminate single points of failure. You can bind secondary mobile devices, external security modules like YubiKeys, or standard cold wallets (such as Ledger or Trezor) as authorized recovery co-signers. Your security layer remains strictly tied to physical hardware, never exposed to vulnerable cloud syncs.
Yes. While FaceID and TouchID offer a frictionless experience, the WebAuthn protocol fully supports PIN-backed hardware enclaves, Windows Hello, and external USB security modules. As long as the device features a secure hardware enclave to generate the cryptographic signature, it can act as your firewall.
No. This is the core technical breakthrough of the protocol. By leveraging EIP-7702 on EVM networks and Squads PDAs on Solana, Nail upgrades your existing Externally Owned Account (EOA) in place. Your wallet address remains exactly the same, and your balances stay untouched.
Never. Nail is strictly a non-custodial execution layer. We cannot access your primary private key, your biometric enclave, or your assets. The protocol merely provides the on-chain architecture that enforces the 2-of-2 requirement. We cannot move your funds, and we cannot freeze your wallet.
Traditional multisigs require you to deploy a separate vault contract and manually transfer your assets into it. Nail eliminates this friction entirely. On EVM networks, Nail utilizes EIP-7702, which allows your existing wallet to "borrow" smart contract logic without changing its identity. On Solana, Nail leverages Smart Accounts and Program-Controlled Delegation to update the ownership authority of your existing account structure. Across both chains, your assets never move and your address remains exactly the same. Once upgraded, your existing address is secured by a second co-signer encrypted (by Turnkey) behind a security firewall. This second signature is only released when you physically authenticate using your device's Secure Element, rendering stolen private keys useless without physical Proof-of-Intent.
