Hearts race, restless dreamsβ
softly, longing slips away,
stillness fills the air.
dannybuntu
dannybuntu@walletscrutiny.com
npub1r709...sf7d
Open Source contributor to FOSS project walletscrutiny.com and nostr.info
Successfully reproduced Coldcard Q1 firmware v1.3.3Q from sourceβbit-for-bit identical to the official release (excluding ECDSA signature).
Proof of strong #ReproducibleBuilds and open auditability for Bitcoin hardware wallets.
Full details:
#Bitcoin #Coldcard #SupplyChainSecurity

WalletScrutiny
Coldcard Q
Review of Coldcard Q (verdict: sourceavailable)
πβ
Verified: Nunchuk Android 1.68.1 split APKs reproducible!
Only expected binary diffs (manifest, resources, Play Store signing) observedβno functional or security differences.
Full report:
#Bitcoin #OpenSource #ReproducibleBuilds πππ

WalletScrutiny
Nunchuk Bitcoin Wallet
Review of Nunchuk Bitcoin Wallet (verdict: sourceavailable)
Thinking out loud: 'list framework, language and other dependencies for apps" With the verifications we have produced, we now have access to data that can be utilized to compare apps. Some are reproducibile, others are not. what frameworks do reproducible apps use? Although not exhaustively the source of non-reproducibility - these provide vital clues.
Yes, corellation isn't causation. But we have to start somewhere to help other app developers get their app reproducible.
β
We verified that @nunchuk_io io.nunchuk.android v1.68.0 is reproducible!
Despite minor expected diffs in AndroidManifest.xml & resources.arsc (e.g. Crashlytics ID, Google Play metadata), no functional changes were found.
#ReproducibleBuilds #FOSS #Android


WalletScrutiny
Asset Information
β
Just verified that Phoenix Wallet (Mainnet) v2.6.0 is reproducible!
Built from source and matched Play Store APK byte-for-byte.
π No signed tag/commit, but the build checks out.
Full verification:


WalletScrutiny
Asset Information
π Verified: @nunchuk_io Desktop v1.9.46 is fully reproducible
Built on Ubuntu 22.04 using their official Docker-based guide
β
ZIP & AppImage SHA256 match official release
π Build: CMake + Qt + Docker
π¦ Result: Byte-for-byte identical
#ReproducibleBuilds #Bitcoin #OpenSource


WalletScrutiny
Asset Information
π Just verified the Bitcoin Knots v28.1 (Linux x86_64) binary as reproducible!
π§ͺ Build matched byte-for-byte.
π Signatures validated from Luke Dashjr & other Knots builders.
π Full details on WalletScrutiny:
#Bitcoin #ReproducibleBuilds #FOSS

WalletScrutiny
Asset Information
β
Reproducibility confirmed for it.airgap.vault v3.32.7 (68124)
π APK hash: 5ae0a8...9c25
𧬠Matches source at commit 3ec5c79...
π οΈ Built using test.sh & Docker
π Verified report:
#ReproducibleBuilds #Android #OpenSource #WalletSecurity

WalletScrutiny
Asset Information
Tried building Mixin Messenger for Linux (v2.2.0) from source β ran into a missing breakpad_client error. No buildable path without upstream fix.
π§ GitHub Issue: https://github.com/MixinNetwork/flutter-app/issues/1747
π WalletScrutiny Asset Info:
#ReproducibleBuilds #CryptoWallets #LinuxApps

WalletScrutiny
Asset Information
π Check out this asset information I registered on WalletScrutiny:
β
Reproducible Electrum Windows Standalone Executable (v4.5.8)
Full verification and report available here:
Independent reproducibility strengthens open-source security. π
#ReproducibleBuilds #OpenSource #Electrum #WalletScrutiny

WalletScrutiny
Asset Information
π Successfully reproduced and verified Electrum 4.5.8 from source!
π Full PGP verification passed β signatures from Thomas Voegtlin, Emzy, and SomberNight were β
ultimate trust β
.
π SHA256 matched: dd8595a138132dee87cee76ce760a1d622fc2fd65d3b6ac7df7e53b7fb6ea7e8
π See the full asset registered at WalletScrutiny:
π
#Bitcoin #OpenSource #ReproducibleBuilds #Electrum #WalletScrutiny

WalletScrutiny
Asset Information
llm doesn't want to do the drake meme. just keeps on getting the hair (all of the hair) wrong. ;)
https://pbs.twimg.com/media/GpSljzzbYAIRr7E?format=jpg&name=small


π Verified: Keystone3 Pro Firmware v2.0.4 (Cypherpunk, Modern) is reproducible β
Unsigned binary matches local build byte-for-byte.
Signed hash differs (as expected due to signature).
π Asset registered on WalletScrutiny:
#ReproducibleBuilds #FirmwareIntegrity #Bitcoin

WalletScrutiny
Asset Information
π Verified! Keystone3 Pro Firmware v2.0.4 (Multi-Coin, Modern) is reproducible π§ͺβ
Our build perfectly matches the unsigned official binary.
Signed binary differs (expected due to signature).
Tested with: keystone3pro.sh 2.0.4 multicoin modern
π #ReproducibleBuilds #Bitcoin #FirmwareIntegrity #WalletScrutiny


WalletScrutiny
Asset Information
π Verified! Keystone3 Pro Firmware v2.0.4 (Multi-Coin, Legacy) is reproducible π§ͺβ¨
Our build matches the official unsigned binary byte-for-byte β
Signed binary differs (as expected) due to cryptographic signature.
π Full test details: keystone3pro.sh 2.0.4 multicoin legacy
π https://keyst.one/contents/KeystoneFirmwareG3/v2.0.4/web3/legacy_ota/keystone3.bin
#ReproducibleBuilds #Bitcoin #FOSS
π Tried to build Nunchuk Desktop from source β but hit a wall.
β Missing submodule libnunchuk (404 GitLab link) breaks the build.
π§ͺ Tested on both local Ubuntu & remote Debian.
π Not reproducible in current state.
π¦ SHA-256: (build failed β no binary to hash)
π
#Bitcoin #ReproducibleBuilds #WalletScrutiny

WalletScrutiny
Asset Information
π Just verified a reproducible build of Nunchuk v1.67.0 (io.nunchuk.android)!
β
The APK from my phone matches the one built from source (tag: android.1.67)
π Signing excluded, but the code checks out byte-for-byte.
π¦ SHA-256: 41a66972d53121db4c77fd54bd79202822074fea6db35059b3049bfb5571bb73
π 

WalletScrutiny
Asset Information
π§ͺ Verified the BitBanana v0.9.4 Android app is functionally reproducible!
π¦ Official split APKs were compared to those built from source.
π§Ύ Only minor binary diffs in AndroidManifest.xml & resources.arsc.
π 

WalletScrutiny
Asset Information
π Just verified a reproducible build of Blockstream Green v4.1.8!
β
The APK from my phone matches the one built from source.
π Signing was missing, but the code checks out.
π¦ SHA-256: e2b842...50f89
π 

WalletScrutiny
Asset Information