Kilombino Bitcoin-Blake2b wallet
com.kilombino.pyblockwatch
ꓘɨℓσꬺƄɨP110ꓘɳσ[Ŧƨ] 𓅦丰 _@kilombino.com Bitcoin-Blake2b wallet for Android: watch any xpub across both forks, or a spending hot wallet with on-device dice-seed generation and biometric-gated signing.
First release: Sep 5, 2026, 18 total releases.
Most recent release: Sep 20, 2026.
Appears in 1 app stack.
0 sats / 0 zaps received in the past year.
Sats Received
Underlying data available via MCP: app_zaps, app_releases.
Zap Count
Underlying data available via MCP: app_zaps, app_releases.
Releases
- Sep 20, 2026 0.8.3Binds the signing chain to the send draft — a follow-up to 0.8.2 hardening the send flow. The chain a spend signs under is now fixed on the draft at prepare time, so switching chains between review and confirmation can no longer change which sighash the reviewed spend is signed with (unified on BLAKE2b, legacy on SHA-256). The coin picker tracks which chain its UTXOs came from and refuses coins from another chain. `TxBuilder` now takes the P2WPKH scriptPubKey and implied-P2PKH scriptCode from `Address.scriptPubKey`, so those byte layouts have one definition — byte-identical, the 142 unified vectors and the BIP-143 anchor are unchanged. Adopts the improvements from #2 (thanks @gsampathkumar). **Verify before installing** ``` signed APK SHA-256 a04afa6eb2b5a69671c2cc14f4209eded1e1f2ec326828d8d1d511be5ff500f6 unsigned SHA-256 1be0aaeab71c775f76d2461017b92003fe31525af14e40c8b00c15d05c84f273 certificate SHA-256 b8d7ad679fbfbe39f5640bce01d675347f52b27b7ae6f3731d2ad982c92ef135 (AppVerifier; unchanged since 0.1.0)
More…
``` Reproducible-build steps and the verification of this APK: [README-REPRODUCIBLE.md](https://github.com/Kilombino/pyblock-watch/blob/master/README-REPRODUCIBLE.md). - Sep 20, 2026 0.8.2Opt-in **unified sighash** on BLAKE2b spends — replay protection. A hot-wallet spend signed with `SIGHASH_ALL` produced the same message on both sides of the fork, so spending a pre-fork coin (one that existed before block 961,640, with a twin at the same address on the SHA-256 chain) let anyone rebroadcast the raw transaction on the SHA-256 chain and move the twin coin to the same destination. Spends to the BLAKE2b chain now opt into the unified sighash (`SIGHASH_UNIFIED`, hash-type byte `0x21`), whose message a node without the fork cannot reconstruct — so the signature does not verify there and cannot be replayed. A SHA-256 spend has no fork to validate the new message and stays legacy `SIGHASH_ALL`. The unified message also commits to every input's amount and scriptPubKey, closing CVE-2020-14199. The signing message follows `doc/unified-sighash.md` (Knots v29.4.1) and is checked byte-for-byte against all 142 script-type-0 and script-type-1 vectors from `unified_sighash.json`. Reported by @melvincarvalho in #1. **Verify before installing** ``` signed APK SHA-256 41d63876e1dcec6126a4d5819999bdafcddb580a0a89af2894400b1f807a9438
More…
unsigned SHA-256 c2cb689bfa3e2f5cdde1cdb0b5c99a5031572ce94ff64ccc53e074dd80e77ab1 certificate SHA-256 b8d7ad679fbfbe39f5640bce01d675347f52b27b7ae6f3731d2ad982c92ef135 (AppVerifier; unchanged since 0.1.0) ``` Reproducible-build instructions and the verification of this APK: see [README-REPRODUCIBLE.md](https://github.com/Kilombino/pyblock-watch/blob/master/README-REPRODUCIBLE.md). - Sep 10, 2026 0.8.1**v0.8.1 — `user@domain` (BIP-353) now resolves.** The DNS label has an extra `user` component: `kilombino@kilombino.com` lives at `kilombino.user._bitcoin-payment.kilombino.com`, which the previous build wasn't querying — so it reported "no payment record" even when the record (a silent payment) was there. **Reproducible build** — `./gradlew assembleRelease` at this tag: - Unsigned APK SHA-256: `2b49d1b48c2a166cfc8e0f79f99106e147d79b7198815e4e6bf921fa2a8db7ea` - Signed APK SHA-256: `a1d4cf9f475f73104617b802171b6806df71d8db92146c7778ae6d94c2ca6502` - Signing certificate SHA-256 (unchanged since v0.1.0): `b8d7ad679fbfbe39f5640bce01d675347f52b27b7ae6f3731d2ad982c92ef135` `apksigcopier` reproduces the signed APK from the unsigned one.
- Sep 10, 2026 0.8.0**v0.8.0 — Silent Payments and human-readable addresses.** - **Send to a Silent Payment address (`sp1…`, BIP-352).** The Taproot output is derived from the ECDH of your input keys with the recipient's scan key and built at signing time; pinned to the BIP-352 'Simple send' vector. - **Send to `user@domain` (BIP-353).** The handle is resolved over DNS-over-HTTPS to its payment address — which may itself be a silent payment. - The recipient field takes a normal address, an `sp1…` address, or a `user@domain` handle; the review flags a silent payment. - **App icon** is now full-bleed (adaptive), no white border. **Reproducible build** — `./gradlew assembleRelease` at this tag: - Unsigned APK SHA-256: `840057da65ae636fdf7ee017e78b5e0521671e10c38234060c825cb496e6354b` - Signed APK SHA-256: `5d15b6f2c66c2709b38da3b2cab9d8ef8b49afec0192db6ceee31438e0bb678f`
More…
- Signing certificate SHA-256 (unchanged since v0.1.0): `b8d7ad679fbfbe39f5640bce01d675347f52b27b7ae6f3731d2ad982c92ef135` `apksigcopier` reproduces the signed APK from the unsigned one. ⚠️ A spending wallet — test with small amounts. - Sep 10, 2026 0.7.7**v0.7.7 — the QR scanner finally reads and hands the address back.** Two fixes: the frame is now decoded via `ImageProxy.toBitmap()` + an RGB luminance source (the platform's own YUV→RGB, made upright by the reported rotation, three binarizers incl. inverted); and the unbind + result callback now run on the MAIN thread. Touching CameraX off the main thread was swallowing a successful decode, which is why the scanner would sit on a clear QR without ever closing or filling the field. **Reproducible build** — `./gradlew assembleRelease` at this tag: - Unsigned APK SHA-256: `018998f16488f744324f50fb8e76fb0b76ee7246d36be04828ce96e7541d1d4d` - Signed APK SHA-256: `b9f87e75b56a1da3cb392ddbf89bafa660138eef238f4d64184f020c42c6a8d2` - Signing certificate SHA-256 (unchanged since v0.1.0): `b8d7ad679fbfbe39f5640bce01d675347f52b27b7ae6f3731d2ad982c92ef135` `apksigcopier` reproduces the signed APK from the unsigned one.
- Sep 10, 2026 0.7.6**v0.7.6 — the QR scanner actually reads now.** The scanner would sit on a clear QR and never decode it — on send and on xpub import alike. The analyzer's rotation fallback relied on `PlanarYUVLuminanceSource.rotateCounterClockwise()`, which ZXing does not support and throws; a portrait phone feeds a landscape sensor buffer, so the first (unrotated) orientation almost always missed and the throw killed the frame. Now the luminance is packed and rotated in-tree through all four 90° orientations, with two binarizers tried. **Reproducible build** — `./gradlew assembleRelease` at this tag: - Unsigned APK SHA-256: `99735a5626ded277638672ae92d39b8e5fdb2bbab9e6a9605064c9c690c40325` - Signed APK SHA-256: `0d0f39e7ed1d41ff58ef45e94fffd76f4951ff5472de15df80de7778cf37cf37` - Signing certificate SHA-256 (unchanged since v0.1.0): `b8d7ad679fbfbe39f5640bce01d675347f52b27b7ae6f3731d2ad982c92ef135` `apksigcopier` reproduces the signed APK from the unsigned one.
- Sep 10, 2026 0.7.5**v0.7.5 — easier, more forgiving recipient entry on send.** - The QR scanner now accepts a BIP-21 URI (`bitcoin:ADDR?amount=…`) or a bare address in any case. - A **PASTE** button reads the address from the clipboard — a reliable alternative to the camera. **Reproducible build** — `./gradlew assembleRelease` at this tag: - Unsigned APK SHA-256: `7c30055f7f658f8856e668d080cce9a39a62e1ffc27dc389a70fea979cc20544` - Signed APK SHA-256: `f013aa9c7c91d2982bc9e388789e94c507d4b1ac4ae410e6c86e929982be8fb6` - Signing certificate SHA-256 (unchanged since v0.1.0): `b8d7ad679fbfbe39f5640bce01d675347f52b27b7ae6f3731d2ad982c92ef135`
More…
`apksigcopier` reproduces the signed APK from the unsigned one. - Sep 10, 2026 0.7.4**v0.7.4 — the app keeps up without a restart, plus QR and MAX on send.** - **Discovers movement while open:** the in-app refresh now does a silent gap-walk, so a payment to a freshly handed-out receive address, and the change a spend creates, show up (and confirmations advance) without restarting the app. - **Send:** scan a recipient's QR with the camera, and a **MAX** button to sweep (everything minus fee). - Notifications and the background service are now in English like the rest of the app. **Reproducible build** — `./gradlew assembleRelease` at this tag: - Unsigned APK SHA-256: `941662c367b3e1cd107a7162b97b33c5dc2d5a3cca019f9f8a2a25009bff5c6d` - Signed APK SHA-256: `2439c516d65131a1e32d22e8c95920d8029d4c7d82d9319a92686cec95df4a2f` - Signing certificate SHA-256 (unchanged since v0.1.0): `b8d7ad679fbfbe39f5640bce01d675347f52b27b7ae6f3731d2ad982c92ef135`
More…
`apksigcopier` reproduces the signed APK from the unsigned one. - Sep 10, 2026 0.7.3**v0.7.3 — receive, coin control, and fine-grained fees.** - **Receive:** shows a fresh unused address with its exact derivation path and a QR. Derived publicly from the xpub, so it works for watch-only wallets too. Copy, or step to the next address. - **Coin control:** an optional per-UTXO picker on the send screen — tick exactly which coins to spend instead of the automatic largest-first selection. - **Fees:** any rate from 0.1 to 1000 sat/vB, fractional included. **Reproducible build** — `./gradlew assembleRelease` at this tag: - Unsigned APK SHA-256: `a994513b7f1f46812d1c4475128f562accb8e550dddb9bc09a1c4099a2087f27` - Signed APK SHA-256: `b3d8ece83dbc8b70479199b63f757e3449b2cf982754af40b6c2706ec75453e2` - Signing certificate SHA-256 (unchanged since v0.1.0): `b8d7ad679fbfbe39f5640bce01d675347f52b27b7ae6f3731d2ad982c92ef135`
More…
`apksigcopier` reproduces the signed APK from the unsigned one. - Sep 9, 2026 0.7.2**v0.7.2 — Kilombino icon, and the spending option is now on the main screen.** - The app icon is the Kilombino logo. - A watch-only wallet shows a **Create a spending wallet** button right on the wallet screen (no longer only inside settings). **Reproducible build** — `./gradlew assembleRelease` at this tag: - Unsigned APK SHA-256: `c0ebcfe958227069797c4d530ceab54fd92e6321c58b9a541c454a5aaba8bf00` - Signed APK SHA-256: `ae1c061760f2122059dcd8aaa8a462f1f305620def721bbb2e1184e32a0d7660` - Signing certificate SHA-256 (unchanged since v0.1.0): `b8d7ad679fbfbe39f5640bce01d675347f52b27b7ae6f3731d2ad982c92ef135`
More…
`apksigcopier` reproduces the signed APK from the unsigned one. - Sep 9, 2026 0.7.1**v0.7.1 — setup is reachable again.** Fixes being unable to create a spending wallet once a watch-only xpub was already loaded. - Settings now has **Create a spending wallet / Switch**, which reopens the chooser (dice · restore · watch-only) even with a wallet present — with a back-to-wallet escape and a "this replaces the current wallet" warning. - Everything from v0.7.0 (dice seed, biometric-gated signing, native-SegWit send) unchanged. **Reproducible build** — `./gradlew assembleRelease` at this tag: - Unsigned APK SHA-256: `416179406557aa482c95abf6e646bc63f27445741423afdb409649b7f72b5103` - Signed APK SHA-256: `df7d5ec8a22f18a01e4cb8a0bac32a8d4cf8d3133497420b9ef06c9f52548b71` - Signing certificate SHA-256 (unchanged since v0.1.0): `b8d7ad679fbfbe39f5640bce01d675347f52b27b7ae6f3731d2ad982c92ef135`
More…
`apksigcopier` reproduces the signed APK from the unsigned one. ⚠️ A spending wallet — back up your seed and test with small amounts. - Sep 9, 2026 0.7.0**v0.7.0 — Spending (hot) wallet.** The wallet can now SEND, not just watch. - **Create on-device:** roll physical dice, SeedSigner-style (50 rolls → 12 words, 99 → 24), or use the phone's secure RNG. The seed is shown once to back up, then encrypted with an Android Keystore key created with `setUserAuthenticationRequired(true)` — your fingerprint or device PIN is bound to the decryption cipher, not a screen the app could skip. - **Send native SegWit (bc1q):** choose recipient, amount and fee; review the coins, fee and change; unlock with biometrics to sign and broadcast. Signing is RFC-6979 ECDSA over the BIP-143 sighash, all pure Kotlin, pinned by the BIP-143 worked example (sighash and witness signature reproduced byte-for-byte) plus BIP-32/BIP-39/BIP-84 vectors. - **Restore** from a BIP-39 seed. Watch-only (xpub) still works. **Reproducible build** — clone at this tag and run `./gradlew assembleRelease`: - Unsigned APK SHA-256: `f4651247543d54680210daeae9a8b1f4be7dc57c0b1b49bbb5aae64d376e45a3` - Signed APK SHA-256: `a270bf5a4014f20e3699e8fc5ecd86e8c1cc665f9268f675e5e22967f97a2c99` - Signing certificate SHA-256 (unchanged since v0.1.0): `b8d7ad679fbfbe39f5640bce01d675347f52b27b7ae6f3731d2ad982c92ef135`
More…
`apksigcopier` reproduces the signed APK from the unsigned one, so the signature adds nothing but itself. ⚠️ This is now a wallet that holds a private key and can spend. Back up your seed on paper, and test with small amounts first. - Sep 6, 2026 0.6.0Watch-only wallet para la cadena BLAKE2b/BIP110 y Bitcoin mainnet. Sin claves, sin servidor de push: el teléfono consulta el Electrum directamente. ## Novedades en 0.6.0 - **Saldo en sats.** El número grande es ahora un recuento exacto de sats (agrupado 12 345 678), con el BTC como línea secundaria — en la cabecera, las pestañas y la lista de direcciones. Se acabó redondear un saldo de menos de un bitcoin a "0 ₿". - **Notificaciones por transacción.** En vez de por saldo agregado: "Nuevo envío/ingreso en la mempool: N sats" en cuanto aparece la tx, y "Primera confirmación del envío/ingreso de N sats" cuando esa misma tx recibe su primera confirmación. El importe se recuerda desde que entró en la mempool (una confirmación no cambia el saldo). Un cambio que solo se vio ya confirmado también avisa. - **Cuenta atrás de refresco.** Con la app abierta, la cadena seleccionada se refresca cada 30 s con una cuenta atrás visible, y ese refresco también dispara las notificaciones si nota cambios. - La lógica de diferencias vive ahora en un motor compartido (BalanceWatch + Notifier), así que las mismas alertas salen del vigilante en segundo plano (cada 5 min) y del refresco en primer plano. ## Verificar
More…
Compilación reproducible: el APK sin firmar se reconstruye byte a byte desde este tag. ``` app-release-unsigned.apk SHA-256 06725332267d8feb1413054d50057ad4337258ca8b3213fade88f4498f716d6f ``` APK firmado (v2+v3, `--alignment-preserved`): ``` pyblock-watch-0.6.0.apk SHA-256 0f06f65bc6907f1544695133a140f4fe86da5819fe71801d60efb7b017c9c50c ``` Certificado del firmante (sin cambios desde 0.1.0): ``` b8d7ad679fbfbe39f5640bce01d675347f52b27b7ae6f3731d2ad982c92ef135 ``` `apksigcopier` confirma que el APK firmado es exactamente esa compilación sin firmar más la firma. Pasos completos en [README-REPRODUCIBLE.md](https://github.com/Kilombino/pyblock-watch/blob/master/README-REPRODUCIBLE.md). - Sep 6, 2026 0.5.0Watch-only wallet for the BLAKE2b/BIP110 chain and Bitcoin mainnet. No keys, no server, no push: the phone asks the Electrum server directly. ## Novedades en 0.5.0 - **Notificaciones de saldo que sí llegan.** El vigilante en segundo plano lleva ahora su propia marca de lo ya notificado, separada de las cifras que registra la app abierta. Antes, abrir la app reiniciaba la referencia y la notificación no saltaba nunca. Ahora avisa de verdad al recibir, enviar, ver algo en la mempool y al confirmarse. - **Primer saldo detectado.** La primera vez que el vigilante ve saldo en una cadena manda un aviso "saldo detectado", para que sepas que está funcionando. - **Canal de alertas de alta prioridad** y comprobación **cada 5 minutos** (antes 15). - **Lectura de QR de xpub densos.** La cámara captura a ~1280×720 con TRY_HARDER y un reintento rotado, así que un QR de clave extendida (versión 8–11, módulos diminutos) se lee bien. ## Verificar
More…
Compilación reproducible: el APK sin firmar se reconstruye byte a byte desde este tag. ``` app-release-unsigned.apk SHA-256 5237b543ecd605f7884abb415b811c2753e01a1cf6c101c0b85b8fe172835eac ``` APK firmado (v2+v3, `--alignment-preserved`): ``` pyblock-watch-0.5.0.apk SHA-256 b83899656568094a22d45c4b90f8bdab11e6f4a11305784dc49317555f752823 ``` Certificado del firmante (sin cambios desde 0.1.0): ``` b8d7ad679fbfbe39f5640bce01d675347f52b27b7ae6f3731d2ad982c92ef135 ``` `apksigcopier` confirma que el APK firmado es exactamente esa compilación sin firmar más la firma. Pasos completos en [README-REPRODUCIBLE.md](https://github.com/Kilombino/pyblock-watch/blob/master/README-REPRODUCIBLE.md). - Sep 5, 2026 0.4.0**PyBLØCK Watch 0.4.0** - **Live balances**: while the app is open, the selected chain's balance now refreshes every 30 s and the moment you switch chains — no more stale figures. It reuses the addresses already found, so there's no scan flicker. - **Re-centered app icon** so the black border no longer shows. - Mempool/confirmation notifications (from 0.3.0) unchanged: a receive is flagged pending, then confirmed. Verify before installing: - **Signed APK SHA-256:** `6e1aad68366f35cf3c66814977e0f8bbc0d0d4b416b784b79540787bc2a15ca3` - **Certificate SHA-256 (AppVerifier):** `b8d7ad679fbfbe39f5640bce01d675347f52b27b7ae6f3731d2ad982c92ef135` (unchanged)
More…
- Unsigned (reproducible) APK SHA-256: `4a10be008fbce652bb7a9f596fae48b8b201a5aa3e4182a794454a2f007c53f3` Rebuild it yourself: [README-REPRODUCIBLE.md](https://github.com/Kilombino/pyblock-watch/blob/master/README-REPRODUCIBLE.md). - Sep 5, 2026 0.3.0**PyBLØCK Watch 0.3.0** New: - **Configurable gap limit** in settings (5–100) — how deep the scan looks. The background watcher uses it too. - **Richer notifications**: distinguishes *received* / *sent* / *pending in the mempool* / *just confirmed*, on either chain. Fires on any movement. - **Confirmations per transaction**: a movements list shows how many confirmations each tx has — a mempool receive is now clearly marked "0 conf", not silently counted as final. Verify before installing: - **Signed APK SHA-256:** `9346b00fe2bc13d33aafb0ecc32b681ab7773319bc7b960ae0ded89258608974`
More…
- **Certificate SHA-256 (AppVerifier):** `b8d7ad679fbfbe39f5640bce01d675347f52b27b7ae6f3731d2ad982c92ef135` (unchanged) - Unsigned (reproducible) APK SHA-256: `1459eee0e7b61c7161a37d682310b5c766fef2b45cc9084e957654e28fa1d8b4` Rebuild it yourself: [README-REPRODUCIBLE.md](https://github.com/Kilombino/pyblock-watch/blob/master/README-REPRODUCIBLE.md). - Sep 5, 2026 0.2.0**PyBLØCK Watch 0.2.0** New: - **Taproot (BIP-86)** support — pick `bc1p` in the address-type selector. Verified against the BIP-86 test vectors. - **Address-type selector** in settings: Native SegWit (BIP-84, default) / Nested (BIP-49) / Legacy (BIP-44) / Taproot (BIP-86). Switching re-scans both chains. - **Balance notifications on by default** — you're told when coins arrive on either chain without opening the app. - **Scan an xpub with the camera** (QR). - App icon. Verify before installing:
More…
- **Signed APK SHA-256:** `2947ca0e1a5bccb5fc31be9e8c772b9e36bd199b157502ed288298645861fbd9` - **Certificate SHA-256 (AppVerifier):** `b8d7ad679fbfbe39f5640bce01d675347f52b27b7ae6f3731d2ad982c92ef135` (unchanged from 0.1.0) - Unsigned (reproducible) APK SHA-256: `e668221b0eb97ffb38d039580427f63b10d01dc187f69b573d48bbda5247af8c` Rebuild it yourself: [README-REPRODUCIBLE.md](https://github.com/Kilombino/pyblock-watch/blob/master/README-REPRODUCIBLE.md). - Sep 5, 2026 0.1.0**PyBLØCK Watch 0.1.0** — watch-only, reproducible build. Verify before installing: - **Signed APK SHA-256:** `99a85cf1fd974a88626e2f5a21db5fb14babf6e3c31b13e288cd90c14d095151` - **Certificate SHA-256 (AppVerifier):** `b8d7ad679fbfbe39f5640bce01d675347f52b27b7ae6f3731d2ad982c92ef135` - Unsigned (reproducible) APK SHA-256: `9c97676adc3625399c222e5958074a4303e12420e79fe01316ec5ff9b3a86b0f` Anyone can rebuild this APK from source and confirm it matches, byte for byte — see [README-REPRODUCIBLE.md](https://github.com/Kilombino/pyblock-watch/blob/master/README-REPRODUCIBLE.md). Pure Kotlin crypto (no prebuilt native key libraries), 613 dependencies pinned by SHA-256.