You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
Go to file
cathugger a6e53b0997
fixup release script
9 months ago
contrib fixup release script 9 months ago
ed25519 cleanup some remaining dead refs 10 months ago
.editorconfig various things 2 years ago
.gitattributes .gitattributes: make sure *.h *.c are detected as C 4 years ago
.gitignore a bit of calcest and some other stuff 1 year ago
COPYING.txt README & COPYING 6 years ago some cleanups & make depend 10 months ago
OPTIMISATION.txt adjust OPTIMISATION.txt for current stuff 3 years ago edit readme a bit more 10 months ago add amd64-{51-30k,64-24k} from SUPERCOP, now use autoconf 6 years ago
base16.h improvements all over the place 6 years ago
base16_from.c some more explicitness 5 years ago
base32.h harden pseudo-YAML validation 5 years ago
base32_from.c some more explicitness 5 years ago
base32_to.c improvements all over the place 6 years ago
base64.h split worker off 4 years ago
base64_from.c stronger base64 validation 5 years ago
base64_to.c optional functionality for writing results to the single file and extracting specific keys from it 5 years ago
calcest.c more stuff 10 months ago
common.h rawyaml mode 3 years ago some cleanups & make depend 10 months ago
cpucount.c glibc isn't limited to linux 4 years ago
cpucount.h explicit void declaration, remove unused arg. thanks ccomp 5 years ago
filters.h explicit void params declarations, add warnings to keep it correct 4 years ago fix intfilter expansion logic 2 years ago various things 2 years ago whatever i implemented it anyway 2 years ago split worker off 4 years ago
hex.h add numwords functionality 5 years ago
ifilter_bitsum.h fix compilation err in non-intfilter cases 2 years ago
ioutil.c fix syncwritefile on windows 9 months ago
ioutil.h make checkpoint stuff actually proper 1 year ago
keccak.c explicit void declaration, remove unused arg. thanks ccomp 5 years ago
keccak.h explicit void declaration, remove unused arg. thanks ccomp 5 years ago
likely.h some fixes and optimizations 6 years ago
main.c more :> 11 months ago
test_base16.c delet trailing whitespace 5 years ago
test_base32.c delet trailing whitespace 5 years ago
test_base64.c cleanups, make clang happy 4 years ago
test_ed25519.c rebase on newer SUPERCOP, use PIE, some other stuff 11 months ago
testutil.h small cleanup, makefile preparation for calcdiff 3 years ago
types.h more flexible intfilter config 5 years ago
vec.c some vec tweaks 6 years ago
vec.h small fixup, implement deduplication support 5 years ago
worker.c more :> 11 months ago
worker.h more :> 11 months ago more :> 11 months ago more :> 11 months ago more :> 11 months ago more :> 11 months ago more :> 11 months ago more :> 11 months ago
yaml.c rawyaml mode 3 years ago
yaml.h rawyaml mode 3 years ago

mkp224o - vanity address generator for ed25519 onion services

This tool generates vanity ed25519 (hidden service version 3, formely known as proposal 224) onion addresses.


  • C99 compatible compiler (gcc and clang should work)
  • libsodium (including headers)
  • GNU make
  • GNU autoconf (to generate configure script, needed only if not using release tarball)
  • UNIX-like platform (currently tested in Linux and OpenBSD, but should also build under cygwin and msys2).

For debian-like linux distros, this should be enough to prepare for building:

apt install gcc libsodium-dev make autoconf


./ to generate configure script, if it's not there already.

./configure to generate makefile; in *BSD platforms you probably want to use ./configure CPPFLAGS="-I/usr/local/include" LDFLAGS="-L/usr/local/lib".

On AMD64 platforms, you probably also want to pass something like --enable-amd64-51-30k to configure script for faster key generation; run ./configure --help to see all available options.

Finally, make to start building (gmake in *BSD platforms).


Generator needs one or more filters to work.

It makes directory with secret/public keys and hostname for each discovered service. By default root is current directory, but that can be overridden with -d switch.

Use -s switch to enable printing of statistics, which may be useful when benchmarking different ed25519 implementations on your machine.

Use -h switch to obtain all available options.

I highly recommend reading OPTIMISATION.txt for performance-related tips.

FAQ and other useful info

  • How do I generate address?

    Once compiled, run it like ./mkp224o neko, and it will try creating keys for onions starting with "neko" in this example; use ./mkp224o -d nekokeys neko to not litter current directory and put all discovered keys in directory named "nekokeys".

  • How do I make tor use generated keys?

    Copy key folder (though technically only hs_ed25519_secret_key is required) to where you want your service keys to reside:

    sudo cp -r neko54as6d54....onion /var/lib/tor/nekosvc

    You may need to adjust ownership and permissions:

    sudo chown -R tor: /var/lib/tor/nekosvc
    sudo chmod -R u+rwX,og-rwx /var/lib/tor/nekosvc

    Then edit torrc and add new service with that folder.
    After reload/restart tor should pick it up.

  • Generate addresses with 1-2 and 7-9 digits?

    Onion addresses use base32 encoding which does not include 0,1,8,9 numbers.
    So no, that's not possible to generate these, and mkp224o tries to detect invalid filters containing them early on.

  • How long is it going to take?

    Because of probablistic nature of brute force key generation, and varience of hardware it's going to run on, it's hard to make promisses about how long it's going to take, especially when the most of users want just a few keys.
    See this issue for very valuable discussion about this.
    If your machine is powerful enough, 6 character prefix shouldn't take more than few tens of minutes, if using batch mode (read OPTIMISATION.txt) 7 characters can take hours to days.
    No promisses though, it depends on pure luck.

  • Will this work with onionbalance?

    It appears that onionbalance supports loading usual hs_ed25519_secret_key key so it should work.

To the extent possible under law, the author(s) have dedicated all copyright and related and neighboring rights to this software to the public domain worldwide. This software is distributed without any warranty. You should have received a copy of the CC0 Public Domain Dedication along with this software. If not, see CC0.

  • keccak.c is based on Keccak-more-compact.c
  • ed25519/{ref10,amd64-51-30k,amd64-64-24k} are adopted from SUPERCOP
  • ed25519/ed25519-donna adopted from ed25519-donna
  • Idea used in worker_fast() is stolen from horse25519
  • base64 routines and initial YAML processing work contributed by Alexander Khristoforov (heios at protonmail dot com)
  • Passphrase-based generation code and idea used in worker_batch() contributed by foobar2019