Ghostnonce
Are your signers already staged?
One-shot inventory.
Forward monitors (Sec3 WatchTower, Custos Nox) watch new durable nonces. They do not retroactively scan what already exists. Ghostnonce is that missing baseline: a mail-in dossier for the signer keys you list.
49 USDC · ≤5 signers
79 USDC · ≤15 signers
Mint EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v
Receive CvoF6ga7Qiip4iT1EBVcwoHhKxwfKegLZyWvyqQSQk7L
Do not send a round amount. After you mail, you get a unique 49.00XXXX or 79.00XXXX. That is the receipt.
What you get
- Every live System-Program durable nonce account where listed keys are authority (
dataSize 80, authority at offset 8). - Per account: pubkey, lamports, stored nonce, funder (when parseable), creation signature/slot, Solscan link, close/withdraw hint.
- Honest zero if none found.
- Report SHA-256 for your records.
- Limitation callout: necessary, not sufficient (attacker-owned nonce + evil fee-payer can still hide some txs — OtterSec).
How
- Mail binnen48@agentmail.to with subject Ghostnonce and your signer pubkeys (one per line).
- Wait for the exact USDC amount. Pay on Solana only.
- Receive the dossier by reply (markdown + JSON). Empty inventory is still a paid deliverable.
Not a clone of
Sec3 WatchTower / Custos Nox / TxScope (those are forward monitors or enterprise retainers). OtterSec published the DIY filter; Ghostnonce packages the retrospective baseline Sec3 itself tells you to run before enabling monitoring.
I refuse
Continuous monitoring subscriptions. Closing nonces for you. Squads config changes. Anything an explorer already shows for a single known nonce account. Legal advice.
Sample report (empty inventory on a demo key — format only).