UtxoPocket
com.strhodler.utxopocket
devsigner Privacy-first Android watch-only wallet for Bitcoin descriptors and UTXO inspection.
UtxoPocket helps you monitor Bitcoin wallets from public descriptors without turning your phone into a signer. It focuses on wallet visibility, UTXO review, private Electrum connectivity, and local-first education for users who want to inspect their wallet state without exposing signing material. UtxoPocket is watch-only by design. It never handles seeds, private keys, WIF values, xprv/tprv values, PSBT signing, transaction construction, or transaction finalization. Features: - Import public Bitcoin descriptors by paste or QR, including receive/change pairs and BIP-389 multipath exports. - Monitor multiple wallets across Mainnet, Testnet3, Testnet4, and Signet. - Inspect balances, transactions, UTXOs, labels, value bands, age, spendability, collections, and transaction flows. - Import and export BIP-329 labels and encrypted watch-only backups. - Use Tor-by-default Electrum sync, custom onion endpoints, or explicit Local Direct mode for trusted private/local infrastructure. - Keep wallet data local with SQLCipher/Tink-backed storage, optional PIN, duress PIN, calculator camouflage, and panic wipe. - Run without analytics, crash reporters, ad SDKs, explorer lookups, or remote attribution services.
First release: May 7, 2026, 1 total release.
Most recent release: May 7, 2026.
Appears in 0 app stacks.
0 sats / 0 zaps received in the past year.
Sats Received
Underlying data available via MCP: app_zaps, app_releases.
Zap Count
Underlying data available via MCP: app_zaps, app_releases.
Releases
- May 7, 2026 0.12.0## UtxoPocket v0.12.0: privacy controls, local-node speed, and safer watch-only recovery v0.12.0 is one of the largest UtxoPocket releases so far. It focuses on the parts that matter when a watch-only wallet becomes part of your real operational setup: encrypted recovery, explicit network choices, safer PIN/duress transitions, local UTXO organization, and optional app camouflage. If you only try a few things first: - Create an encrypted `.ubak` backup and restore-preview it before you need it. - Connect UtxoPocket to your own Electrum node with `Local Direct` when you are on a trusted private/local network. - Try the new calculator camouflage flow if you want the app to look less obvious on your launcher. - Organize UTXOs with collections and inspect them through the improved wallet detail views.
More…
- Review the strengthened duress, PIN, panic wipe, Tor, and Local Direct behavior in the Security notes below. <img width="3320" height="2597" alt="screen_1" src="https://github.com/user-attachments/assets/5bc1e510-9320-4595-9c02-625d0e64e466" /> ### Calculator camouflage quick guide Calculator camouflage is optional and sits before the normal PIN prompt. It changes the app launcher presentation and adds a calculator-style gate, but it is not a second authentication factor. Your normal PIN checks, backoff, lockout, and duress PIN behavior remain unchanged. To enable it: 1. Open `Settings -> Security`. 2. Turn on `Calculator mode`. 3. Confirm the dialog. The app will appear as `Calculator` with calculator-style launcher and splash visuals. To open UtxoPocket while camouflage is enabled: 1. Open the app named `Calculator`. 2. Enter `21000000`. 3. Tap `=`. 4. Enter your normal UtxoPocket PIN. To disable it: 1. Open `Calculator`. 2. Enter `21000000` and tap `=`. 3. Unlock with your normal PIN. 4. Go back to `Settings -> Security`. 5. Turn off `Calculator mode`. This is intended as UI camouflage for casual observation and shoulder-surfing scenarios. It does not hide wallet data from a compromised device, replace PIN security, or remove the need for duress and panic-wipe planning. <img width="3320" height="2597" alt="screen_3" src="https://github.com/user-attachments/assets/57626aac-bb8a-4c48-8b4d-9f5bac856ea2" /> ### Local Direct is dramatically faster when you trust the network Tor remains the default privacy boundary for bundled public Electrum presets and onion endpoints. That is still the safest default for public infrastructure. `Local Direct` is different: it is an explicit opt-in mode for your own trusted private/local IP Electrum node, including a node reached through a VPN into your local network. It intentionally bypasses Tor, so use it only with infrastructure you control. The speed difference can be huge. In testing, a wallet sync that took about 3 minutes over Tor completed in about 20 seconds against a local node or through VPN access to the local network. Results will depend on wallet size, gap limit, node performance, and network conditions, but if you run your own node, this is one of the most practical upgrades in v0.12.0. <img width="3320" height="2597" alt="screen_2" src="https://github.com/user-attachments/assets/ae30f318-b916-4dce-a0f1-0c37fb28db6c" /> ## Highlights ### Added - **Encrypted watch-only backups** – Added passphrase-protected `.ubak` export/import flows for watch-only wallet data, with preview, restore validation, backup integrity checks, and safeguards that keep PIN, duress secrets, and node policy out of backup scope. - **Connection modes** – Added explicit connection-mode handling for Tor default networking and opt-in Local Direct mode. Local Direct is limited to custom private/local IP Electrum endpoints and remains separate from Tor presets. - **Nodes screen refresh** – Replaced the old connection tab with a clearer Nodes flow, moving Tor details into a dedicated details surface and improving node setup, status, retry, and transport messaging. - **Mode-aware node transport** – Added stronger UI and data-layer policy around Tor vs Local Direct routing, endpoint validation, node activation, and mode-aware connection commands. - **UTXO collections** – Added collection assignment and collection-oriented wallet detail views to help organize UTXOs locally without changing wallet funds or signing behavior. - **Wallet sync controls** – Added wallet sync gap controls and improved per-wallet sync state surfaces so rescans and manual sync actions are easier to inspect. - **Calculator camouflage mode** – Added optional calculator-style app camouflage and gate flow. - **Duress PIN hardening** – Added refined duress PIN transition handling and unified PIN prompt state so sensitive wallet content is not briefly exposed during duress flows. - **Incoming transaction placeholder improvements** – Incoming detection now keeps placeholder entries until successful BDK reconciliation and includes additional sanitized lifecycle logging. - **Markdown-powered wiki and glossary** – Wiki and glossary runtime content now come from repository Markdown sources, making bundled educational content easier to maintain and audit. - **Block explorer settings** – Split block explorer management into its own settings area and improved resolver behavior for wallet transaction actions. - **Wallet detail refinements** – Added richer UTXO/transaction detail components, filter presets, shared cards, detail preferences, and improved wallet detail state reduction. - **Address and descriptor import refinements** – Improved add-wallet parsing, extended-key descriptor building, and wallet validation flows with more focused import code paths. ### Changed - **Connection architecture** – Migrated connection handling to the newer orchestrator flow and removed older network intent paths, duplicate metadata polling, and temporary rollback wiring. - **Tor runtime ownership** – Moved Tor runtime control and public Tor text handling into project-owned layers, with dedicated Tor service/client/control abstractions and sanitizer coverage. - **Wallet repository architecture** – Retired the monolithic wallet repository and split wallet capabilities into focused read, provisioning, sync, address, label, backup, and maintenance repositories. - **Wallet sync internals** – Decomposed node sync into focused session, status, retry, persistence, and wallet sync collaborators to improve cancellation, queue handling, and persistence safety. - **BDK persistence handling** – Wallet sessions now surface BDK persistence failures more explicitly instead of hiding storage problems behind generic success states. - **Utxo analysis decomposition** – Split large wallet detail and analysis screens into focused modules for treemap, distribution, filter, UTXO detail, transaction detail, and shared UI state. - **Navigation and app shell** – Split the main nav host into feature subgraphs, centralized typed navigation args/options, and extracted app shell / overlay coordination out of `MainActivity`. - **Presentation state collection** – Updated UI flow collection to lifecycle-aware patterns and centralized top bar / wallet connection projections. - **Preferences and migrations** – Isolated legacy node parsing into one-time schema migration and added preference/state support for new connection, sync, detail, and camouflage options. - **Build and dependency baseline** – Updated Gradle, Android Gradle Plugin, Kotlin/Compose/Paging and related dependencies; added dependency verification metadata and CI checks. - **Runtime docs packaging** – Build now packages only generated runtime docs assets for wiki/glossary content. - **Testing baseline** – Removed unused connected Android instrumentation sample/tests and expanded JVM unit coverage across connection, backup, sync, Tor, wallet, PIN, and UI reducers. ### Fixed - **Receive address jumps** – Fixed a reported issue where pressing **Next address** could jump from the expected next receive address to a much higher derivation index, for example from address `28` to `77`. The receive screen now prefers already revealed unused external addresses before asking BDK to reveal a new one, preserving sequential receive-address navigation. - **Receive address reuse prevention** – Tightened incoming detection and receive placeholder handling so used or pending receive addresses are skipped more reliably. - **Wallet storage failures** – BDK persistence failures are surfaced instead of silently reporting successful wallet operations. - **Electrum response routing** – Fixed light Electrum client response routing by request ID and hardened diagnostics around stream routing. - **Malformed Electrum script handling** – Rejected malformed script hex instead of letting invalid data propagate through incoming detection or address checks. - **Tor fail-closed behavior** – Hardened Tor-required connection checks so Tor mode does not silently fall back to clearnet or Local Direct behavior. - **Connection mode reactivation** – Fixed mode-aware node reactivation and clearer Tor/Local Direct UX when switching or retrying connections. - **Panic wipe atomicity** – Hardened panic wipe behavior so wipe transitions are safer and documented. - **Duress wallet flash** – Prevented real wallet content from flashing during duress PIN transitions from wallet detail prompts. - **Wallet sync state alignment** – Improved sync state consistency between home, wallet detail, and node-driven sync flows. - **Wallet deletion sync handling** – Fixed wallet deletion triggering stale or incorrect wallet sync behavior. - **Wallet detail filtering** – Kept incoming transaction tab state and filters in sync with transaction data. - **Wallet detail layout** – Kept balances visible when labels are long by improving ellipsizing and layout behavior. - **Label import/export UX** – Streamlined BIP-329 label import feedback, hid confusing skipped counts, wired import modes, and moved expensive export work off the main thread. - **Build/lint issues** – Resolved resource/drawable lint violations, Compose sizing/resource warnings, and other build warnings. - **Cancellation handling** – Hardened coroutine cancellation paths so cancellation is not misreported as ordinary app errors in receive, label, transaction, UTXO, sync, and related ViewModel flows. - **Descriptor/wallet validation** – Hardened wallet validation and sync safety around descriptor import and wallet state transitions. ### Security - **Tor remains the default privacy boundary** for bundled public Electrum presets and onion endpoints. - **Local Direct remains explicit opt-in only** for private/local IP literal Electrum endpoints. - **No silent fallback** was introduced between Tor and Local Direct, and no clearnet fallback is used while Tor mode is active. - **Endpoint validation is stricter** for custom nodes, including rejection of unsupported DNS/public/onion combinations depending on the active connection mode. - **Watch-only scope is preserved**. No seeds, mnemonics, private keys, signing, PSBT finalization, or transaction construction flows were introduced. - **Backups remain watch-only scoped**. `.ubak` backups exclude PIN/duress secrets and node policy, and restore flows require explicit passphrase-based preview/import. - **Crypto/storage hardening remains fail-closed** around Tink, SQLCipher, BDK wallet materialization, sealing, and persistence errors. - **Sanitized logging was expanded** for Tor, connection, incoming transaction, and network diagnostic paths. - **Panic wipe handling was hardened** to reduce risk of sensitive local state surviving wipe transitions. ### Known issues - Wallet timeline still requires a manual refresh after an incoming alert to record confirmed transaction data in the database. - Local Direct is intentionally limited to private/local IP literal Electrum endpoints; DNS names, `.local`, public IPs, onion endpoints, and public presets are rejected by design. - Incoming transaction detection remains lightweight and local-first; BDK sync remains the canonical wallet state. ## Verification - **Version/Tag:** `v0.12.0` - **Signer certificate fingerprints:** ```bash SHA-256: e5b195f0592cb546494df04722e9140e7dd92f4efd377ad8b159496d9bde9524 SHA-1: 79e2591f07d8f439964ad320a3b8d1a2e4a75047 ``` - **Signature verification:** ```bash apksigner verify --print-certs UtxoPocket-v0.12.0.apk Signer #1 certificate DN: ST=Blockchain, L=Mempool, O=strhodler, OU=strhodler, CN=strhodler Signer #1 certificate SHA-256 digest: e5b195f0592cb546494df04722e9140e7dd92f4efd377ad8b159496d9bde9524 Signer #1 certificate SHA-1 digest: 79e2591f07d8f439964ad320a3b8d1a2e4a75047 Signer #1 certificate MD5 digest: 918a3acf4d973633cc40a84949238536 ``` - **Checksum:** ```bash sha256sum -c UtxoPocket-v0.12.0.apk.sha256 UtxoPocket-v0.12.0.apk: OK sha512sum -c UtxoPocket-v0.12.0.apk.sha512 UtxoPocket-v0.12.0.apk: OK ``` ## Artifacts - `UtxoPocket-v0.12.0.apk` - `UtxoPocket-v0.12.0.apk.sha256` - `UtxoPocket-v0.12.0.apk.sha512` - `deps-v0.12.0.txt`