How it Works

Pacto runs on two decentralized networks at once. Your messages stay private. Your community’s rules settle where they can be enforced. One identity binds both sides — on-chain governance can evolve when the community outgrows its first captain — and gas sponsorship keeps crypto under the hood.

Cross-network identity

Binding Nostr and Ethereum

Two networks, two jobs

Nostr is a decentralized social network. Relays carry events; no single company owns the pipe. Pacto uses it for private communication — chats and groups that are hard to censor or silently read.

Ethereum is a public blockchain: an immutable shared ledger that can represent scarce things — votes, permissions, balances. Pacto uses it for governance and access control together, with finance as a first-class part of the same stack. Rules, who may act, and shared assets all settle on-chain — not buried in a company admin panel.

Two networks, complementary jobs: talk privately on Nostr; settle who may act, how decisions are made, and shared assets on Ethereum.

What are we governing?

A lot of “DAO” tooling is shareholder logic in a new jacket: token-weighted votes over a treasury, plutocracy with better UX. Finance matters — communities move money — but if that is all you can govern, you have only moved the boardroom onto a chain.

So the real question: what can we govern?

  • People — who belongs, who holds which roles, how authority changes.
  • The app — permissions in the client come from on-chain access control. Governance does not sit beside the product; it is embedded in it. The software landscape itself is governable.
  • Assets — treasuries and scarce resources under the same rules as the people who use them.

In the ordinary digital world, people organize on feudal land: centralized servers owned by corporations. Here the land is not held by a landlord. It is decentralized — and governed by the people who live on it. That is more than governing finance. It is governing the place where the organizing happens.

Two keys, one person

On Nostr you act with a Nostr key. On Ethereum you act with an Ethereum key. In the Pacto client both come from the same recovery phrase, so you hold one identity root — but each network still speaks its own language.

Alone, that is not enough for others to trust that “this chat identity” and “this on-chain actor” are the same person. That is what binding is for.

Each key signs the other

Signing means using a private key to produce a cryptographic proof — evidence that you control that key — without revealing the key itself.

In the client, your Nostr key signs a statement that you own a specific Ethereum key. Your Ethereum key signs a statement that you own that Nostr key. When each side vouches for the other, you get a cross-network identity: private communication on Nostr; governable people, app, and assets on Ethereum — one person across both.

Signing means proving control of a key with cryptography — not a password you type into a website. Each key vouching for the other ties the two networks to one person.

Leveraging Hats Protocol

Governance that can evolve

Pacto Gov models a community like a pirate ship: a Captain and a Crew. Read it as a startup too — founder and contributors. Early on, a clear leader helps the group move. That is intentional.

The problem with ordinary startups is that power structures harden. What worked at five people calcifies at fifty. As a company or community grows, it needs different structures at different times — but most orgs have no on-chain way to rewrite who is in charge.

Pacto’s answer is mutiny. When the community is ready for a takeover, the crew can mutiny the captain. Leadership is provisional by design. That is what “governance that can evolve” means: not a founder forever, and not a frozen org chart.

The two-party system

Captain and crew check each other. The captain picks the crew. Both captain and crew can make proposals; the crew votes by quorum on proposals and treasury. The captain can approve or veto. And the crew can mutiny the captain. All of that lives in one Hats tree.

A two-party system inside one Hats tree: crew and captain check each other. Mutiny is the escape hatch when entrenched leadership no longer fits.

One tree for people and protocol

Hats Protocol organizes roles as a tree. In Pacto you can see the entire on-chain governance protocol and the people inside the organization in the same place — Top hat, treasury, quartermaster, mutiny, captain, crew.

Hats Protocol treats both users and smart contracts as first-class citizens. A wearer can be a person (your bound Ethereum identity) or a module (Treasury Safe, Mutiny module, Quartermaster). Same tree. Same rules language.

Hats tree explorer showing Top hat with Treasury Safe, Treasury Authority, Quartermaster with Crew wearers, and Mutiny module above Captain and Squad Admin
The Hats tree surfaces roles, wearers, and modules together — people and smart contracts as first-class citizens in one on-chain org chart.

Mutiny is not limited to person-to-person handoffs. An EOA (externally owned account — a human-controlled wallet) can be replaced by another person, a multisig committee, or any other smart contract. The captain hat does not have to sit on a human. It can sit on whatever on-chain entity the crew chooses next.

EIP-7702 · embedded wallet

Gas sponsorship under the hood

Open Pacto, set a PIN, and you are in. Your Nostr key and your Ethereum key(s) are created locally and encrypted on your device — a cross-network embedded wallet. You do not need to understand seed phrases, gas markets, or browser extensions to start. The crypto is generated for you.

Next you claim a unique username. Under the hood that mints an NFT. That NFT is your gas-sponsorship passport: with it, eligible Pacto actions — including the contracts surfaced through Hats trees — can run without you holding ETH for gas.

Sponsorship has two layers. There is an app-wide pool for onboarding and protocol actions. And each squad can deploy its own squad sponsor so the community pays gas for its members. Both paths use Pacto’s custom EIP-7702 account implementation so the same embedded key can send sponsored UserOps.

An embedded cross-network wallet plus sponsorship means the user never has to buy ETH just to start. Crypto stays under the hood.

Why a gas pool is reasonable here: Pacto’s messaging rides Nostr — a decentralized relay network — not a company cloud. There is no Discord- or Slack-scale server bill to keep chats alive. Relays are broadcast infrastructure we do not have to rent like a conventional SaaS. That leaves room to fund on-chain gas so organizers can govern without a crypto shopping list first.

If the core team ever stops topping up the global pool, squads can still stand up their own sponsor from the app UI and keep members moving. Sponsorship is part of the product surface, not a hidden ops trick.

The point is simple: a governable app can still feel easy when you are completely crypto-naive — PIN in, keys local, username claimed, gas sponsored under the hood.

Next steps

Those are the core ideas. For setup and developer detail, use the GitHub docs. To try the app, download Pacto.

← Back to Pacto