Where the recoverian sends its OTP, masked server-side; null when no
contact is bound (or recovery is not configured at all). current is
true when the bound contact matches the current token's claims; false
means a stale binding the user should update while they still control
the old contact (rebinding requires an OTP sent there).
A recovery blob is stored — the wallet can be recovered onto a new device.
Read-only view of the account's recovery setup (WO 2026/003995).
enrolledreflects the stored ciphertext blob (same lookup ashasStoredRecovery);contactis the recoverian's OTP delivery binding. The contact is pre-masked by the recoverian — this surface never carries the plain address, so Layer 1 may read it.