Ibis Wallet

github.aeonbtc.ibiswallet
by Zapstore _@zapstore.dev

Republished from GitHub / F-Droid by the Zapstore main account.

First release: Jul 22, 2026, 7 total releases.

Most recent release: Sep 24, 2026.

Repo

Appears in 0 app stacks.

0 sats / 0 zaps received in the past year.

Sats Received

Underlying data available via MCP: app_zaps, app_releases.

Zap Count

Underlying data available via MCP: app_zaps, app_releases.

Releases

  • Sep 24, 2026 5.0.1-beta
    ## v5.0.1-beta — Ark receive hotfix Fixes Ark-to-Ark payments that debited the sender while the recipient never saw the funds. No funds were lost; affected payments were stranded server-side. ### Action required Recipients missing an Ark payment: run a **mailbox rescan** from VTXO management screen and wait for it to complete. The payment should appear on the next sync. -======- SHA256: 53D9897459E0526519E3775F1EF79E602F596386238E8DC1C07357A342AC65D6
    More…
    MD5: 235FCCAC7BAA0D964485627FC57E6322 [PGP Public Key](https://github.com/aeonBTC/PGP-Public-Key) -======- **Full Changelog**: https://github.com/aeonBTC/IbisWallet/compare/v5.0-beta...v5.0.1-beta
  • Sep 20, 2026 5.0-beta
    ## Changelog ### New Features - **Ark Layer 2:** Full Ark support, send, receive, with Lightning support, and VTXO management - Refresh, Backup, and unilateral exit (Built on [Bark](https://github.com/ark-bitcoin/bark)) - **Spark Unilateral Exit:** Exit Spark balance on-chain with without Spark cooperation, with fee quote, build, and broadcast flow. - **Full Silent Payments Support + Frigate Server:** Send and receive to silent payment addresses. Added default Frigate Electrum server for SP lookup incoming scan. - **Edit Derivation Path:** Wallet derivation path can now be edited in wallet settings. - **Dice-Roll Entropy for Seed Generation:** Generate new seeds from dice rolls. - **Checksum Helper (11/23 Words):** Find valid BIP39 checksum words for partial 11/23-word seed phrases, with dice or random picker.
    More…
    - **German + French Localizations:** Full app translation for DE and FE alongside EN / ES / RU / PT-BR. ### Improvements - Various UI tweaks and optimizations. ### Bug Fixes - Various bug fixes and stability improvements. ## Security Fixes #### Big thanks to [haoxucu](https://github.com/haoxucu) for responsibly reporting these issues privately with full PoCs. Fixed before any public disclosure. - **Lightning Node (LND / CLN):** Connecting with TLS off used to send your admin macaroon / rune over an unverified connection, then fall back to plaintext HTTP. Credentials are no longer sent until your pasted certificate checks out, or you explicitly allow insecure transport for that host. - **Multisig import:** Import only checked the receive descriptor, so a crafted file could sneak in a different change descriptor and send your change to someone else's keys while showing a valid policy. Both descriptors are now checked to match (same keys and threshold), change is detected from the wallet itself, and the PSBT screen shows the change address. - **Liquid MAX send:** A `liquid:` link with a testnet address was accepted, and MAX would send your full balance to it even though normal sends block it. Testnet addresses are now rejected, and MAX checks the network before sending. *There are no known instances of funds being lost in relation to these vulnerabilities.* -======- SHA256: 8E0A8F97ED75C902D8C1959B188CFE66E3C704DB53C07EAD203690A914AB9FF0 MD5: 1EF2434C1E00B68F4DD4FAEA9A9B4DF3 [PGP Public Key](https://github.com/aeonBTC/PGP-Public-Key) -======- **Full Changelog**: https://github.com/aeonBTC/IbisWallet/compare/v4.7.1-beta...v5.0-beta
  • Aug 16, 2026 4.7.1-beta
    ## v4.7.1-beta (hotfix) ### Fixed - The biometric unlock key was deleted and recreated on every app start, permanently breaking wallet decryption for biometric-locked wallets after updating to v4.7.0-beta - Biometric key is no longer invalidated by fingerprint enrollment changes - A failed biometric decrypt no longer deletes the encrypted wallet key, and the app now reports the error instead of silently opening an empty wallet > [!WARNING] > **If you are on v4.6.2-beta or earlier: do not install v4.7.0-beta — update directly to this release.** >
    More…
    > If you installed v4.7.0-beta and biometric unlock stopped working (zero balance, "wallet not initialized", "no mnemonic found"): the encryption key was destroyed on first launch and cannot be recovered by an update. Your wallets can be restored by re-importing their seed phrases. -======- SHA256: D1D37E4423E9EF2C63D40F1159661CC888F858A123310EC72D543027DD451EBC MD5: 69414F290B0361A287946019C89C3889 [PGP Public Key](https://github.com/aeonBTC/PGP-Public-Key) -======- **Full Changelog**: https://github.com/aeonBTC/IbisWallet/compare/v4.7.0-beta...v4.7.1-beta
  • Aug 15, 2026 4.7.0-beta
    ## Changelog ### New Features - **Wipe PIN:** Optional secondary PIN that, when entered on the lock screen, silently erases all wallet data on the device. - **Clear Clipboard:** Option to automatically wipe the clipboard when the app locks or is closed. - **RBF On by Default:** On-chain sends signal replace-by-fee by default; option to disable in settings. - **Require Coin Control:** Option that forces UTXO selection before on-chain sends. ### Improvements - **Reduced APK Size:** Optimized package architecture to reduce app install size. - Various UI tweaks and optimizations.
    More…
    ## Security Audit: Grok 4.6 + Kimi K3 + DeepSeek V4 #### Big thanks to Bitcoin Red Team and PortlandHODL for performing a thorough security audit with Kimi K3. #### The [bug bounty](https://github.com/aeonBTC/IbisWallet#bug-bounty) has been awarded. The audit was not submitted as a means to claim the bug bounty, I offered it to them. All funds from the bounty will be used to further audit Bitcoin projects. ***There are no known instances of fund loss in relation to these vulnerabilities.*** ### Seed Protection - **Duress PIN isolated from the real wallet:** The decoy PIN no longer unwraps the real spend master. Only decoy secrets are re-encrypted under a separate key, so Backup/export in duress mode cannot leak the real seed. - **Locked spend-secret session no longer writes plaintext:** Writes after lock could persist unwrapped seeds, and a missing PIN wrap minted a new master that orphaned every secret. Locked writes now throw, locked reads return null, and PIN unlock only unwraps an existing master (`savePin` still enrolls). - **A Keystore flake no longer wipes every seed:** Transient EncryptedSharedPreferences errors abort startup without deleting anything. Only a confirmed permanent key invalidation recreates the store. - **Biometric enrollment no longer orphans recovery:** New fingerprints now invalidate the biometric key. The PIN wrap is kept so biometric re-enrollment does not destroy spend-secret recovery. ### Lightning Node (LND / CLN / NWC) - **LND/CLN no longer send credentials over unverified connections:** A TLS-off connect no longer attaches the macaroon or rune to a cleartext probe. Enabling TLS requires a pasted certificate and fails closed if it does not parse. Hostname verification is on for DNS names. Accepting any certificate requires an explicit insecure-TLS opt-in. - **Tor is onion-only for Lightning Node:** “Use Tor” on a clearnet host with no certificate used to accept any TLS cert, so a Tor exit could steal the macaroon or rune. Tor now applies only to `.onion` hosts. Clearnet connects directly and still requires a certificate or explicit insecure TLS. - **On-chain LND/CLN sends are not auto-retried:** SendCoins / SendMany / withdraw no longer re-fire after a dropped response, which previously could broadcast a second independent payment. - **Payments require a real receipt:** Responses must have a valid Nostr id/sig, matching pubkey/`e` tag/`result_type`, and `sha256(preimage)` must equal the invoice hash. Plaintext `ws://` relays are rejected. - **Invoice preview is bound to the BOLT11 amount:** A failed `lookup_invoice` could show the typed amount, then `pay_invoice` retried with no amount and paid the real invoice. Local decode now binds the preview; a mismatch throws; there is no amount-less retry. ### Boltz / SideSwap - **Boltz no longer pays an attacker-controlled lockup:** The REST submarine fallback that funded whatever address the server returned is gone. Lightning pays only go through the LWK path that reconstructs/validates the swap script. - **Boltz `invoice.paid` / `transaction.claimed` is not treated as settlement:** Success waits for LWK `complete()` / `completePay()`. Refund snapshots are kept until that verification, so a fake status cannot delete the refund path. - **Fee estimates and SideSwap peg-out rates are capped:** Electrum/HTTP presets cannot apply uncapped sat/vB values. Peg-out review and broadcast use the same clamped Liquid fee instead of showing ~20 sats and paying the server rate. ### Silent Payments - **Fee-bumps and custom-path wallets no longer burn outputs:** SP keys now follow the stored derivation path (not account 0). Destinations are stored per tx and included in backup/restore. If RBF adds an input, the replacement is rebuilt from spent+unspent outputs and fails closed instead of signing a stale or partial BIP-352 key. - **Uncompressed WIF inputs are skipped:** If no eligible compressed input remains, the send fails loudly. `input_hash` covers all vin outpoints. BIP-39 whitespace is normalized so SP keys match the wallet seed. ### Lock, wipe, backup, and cloak - **A correct duress PIN no longer resets the failed-attempt counter:** It still works during lockout, but auto-wipe progress is preserved so duress cannot be used to brute-force the real PIN. - **Lock timing and confirm dialogs resist bypass:** After-1/5-min lock and the SAF skip window used wall clock. Confirm dialogs were overlayable, and NFC/URI could swap the destination mid-confirm. Lock timing is monotonic; confirm snapshots the destination and blocks obscured touches. - **Wipe and cloak secrets are hardened:** Auto-wipe only ran on the lock-screen PIN, and the cloak code was stored reversibly. Wipe now also runs on spend / view-seed / per-wallet PIN failures; the cloak code is PBKDF2 + salt. - **Backup restore no longer auto-connects Lightning with insecure TLS:** Restored LN host + secrets no longer connect automatically. LN now needs a Connection save; insecure TLS is forced off. - **Electrum history cache is status-bound; Boltz Tor does not leak DNS:** History is served only when the cached Electrum status still matches. Boltz onion connects through SOCKS with unresolved hostnames. - **Cloak branding on notifications:** Incoming-tx notifications are suppressed when cloaked. The foreground service and recents use Calculator. -======- SHA256: 55B0AFD1FFCD0B6687BC177123A9D1B40DD9F3A551DA7FDFD30B3822A8337AC7 MD5: F3C04715CCDB46B6BF23FA8E94FD6E72 [PGP Public Key](https://github.com/aeonBTC/PGP-Public-Key) -======- **Full Changelog**: https://github.com/aeonBTC/IbisWallet/compare/v4.6.2-beta...v4.7.0-beta
  • Jul 26, 2026 4.6.2-beta
    ## Changelog ### Bug Fixes - Fixed Tor connectivity issue caused by recent Tor-android library upgrade -======- SHA256: 4DFCF62493E58BA74FA25571515A2B7429256FD152E260B158FB490F5AE8B8F8 MD5: 21DEB3DCD3EA4C6CF827A0D4FE412238 [PGP Public Key](https://github.com/aeonBTC/PGP-Public-Key) -======-
    More…
    **Full Changelog**: https://github.com/aeonBTC/IbisWallet/compare/v4.6.1-beta...v4.6.2-beta
  • Jul 25, 2026 4.6.1-beta
    ## Changelog ### New Features - Added donation option on the about page ### Bug Fixes - Fixed Lightning invoice generation failure when using Liquid; caused by recent LWK upgrade to v0.18.2 -======- SHA256: 53A6F0563FF6333F4091625D7C2620A22641B3F4EB2E3E8903A6B5DFCC8CB9EC MD5: E294ED13C67F61163F7C9CAA44208500
    More…
    [PGP Public Key](https://github.com/aeonBTC/PGP-Public-Key) -======- **Full Changelog**: https://github.com/aeonBTC/IbisWallet/compare/v4.6-beta...v4.6.1-beta
  • Jul 22, 2026 4.6-beta
    ## GPT 5.6 + Grok 4.5 + Kimi K3 Security Audit ### Bug Fixes - PIN lockout now enforced by both wall-clock and monotonic clocks — no longer bypassable by changing device time or rebooting (monotonic arm correctly dropped post-reboot so the real PIN never bricks). - Failed-attempt counter and lockout state persist with synchronous commits — a process kill can't regress auto-wipe progress. - Duress PIN is verified before the lockout check and always succeeds, so it can never trigger auto-wipe; counter shared between real and duress PINs. - Wallet create/import/load now sets ownership tracking (`loadedWalletId` + mutex) on every path — fixes empty Manage Wallets and concurrent-load races. - Stale Electrum syncs from a previous wallet/connection can no longer clobber state for the newly loaded wallet (ownership guards across subscription, quick-sync, and incremental paths). - Electrum responses are size-capped — a malicious server can no longer OOM the app via unbounded protocol lines. - Frozen UTXOs are excluded from CPFP/RBF fee-bump coin selection — the do-not-spend flag can't be bypassed through fee-bump paths.
    More…
    - CPFP package fee picker now prices the whole package (parent + child), not just the child vsize. -======- SHA256: B189D43D4ECB82EF2ADEC179964BFB6C91F0AF297D70CBE61DE4EB6355FF088F MD5: AA753DCA99F6CE8666EC1E39307E02B7 [PGP Public Key](https://github.com/aeonBTC/PGP-Public-Key) -======- **Full Changelog**: https://github.com/aeonBTC/IbisWallet/compare/v4.5-beta...v4.6-beta