Deriving a stealth address
The recipient publishes a meta-address made of a spending public key K and a viewing public key V. A sender picks a random r, publishes R = r·G, and computes the shared secret s = hash(r·V). The stealth address is the address of K + s·G.
The recipient computes the same s = hash(v·R) with the viewing key, and the stealth private key is k + s.
View tags
The first byte of s is included in the announcement metadata, so a scanner can reject most announcements with one hash instead of a full elliptic-curve check.
The announcement
event Announcement( uint256 indexed schemeId, // 1 = secp256k1 address indexed stealthAddress, address indexed caller, bytes ephemeralPubKey, // R bytes metadata // view tag, ... );
