Clench
net.clench.wallet
Zapstore _@zapstore.dev Republished from GitHub / F-Droid by the Zapstore main account.
First release: Jul 31, 2026, 9 total releases.
Most recent release: Sep 24, 2026.
Appears in 0 app stacks.
0 sats / 0 zaps received in the past year.
Sats Received
Underlying data available via MCP: app_zaps, app_releases.
Zap Count
Underlying data available via MCP: app_zaps, app_releases.
Releases
- Sep 24, 2026 0.3.34# Clench Wallet 0.3.34 This maintenance release fixes startup routing after fresh wallet onboarding. Returning from HOME to the app now evaluates the current wallet state instead of reusing a stale pre-onboarding network-choice decision. StartupViewModel is owned by the loading navigation entry; its duplicate refresh is removed. Wallet data, signing policy, network transport, dependencies, BDK and SQLCipher are unchanged. No database migration is introduced.
More…
Independent source and runtime-evidence reviews passed for PR #102. A bounded external test of the minified release candidate on an accelerated Android 15 ARM64 emulator confirmed fresh offline wallet creation/import and immediate foreground reentry through both normal launcher-equivalent and explicit intents, retaining wallet/address, process and Activity/task identity before any force-stop. A subsequent process restart retained the imported wallet/address. The test used a disposable signer and strict 16 KB pages with compatibility fallback disabled. Its limits are recorded in the [runtime receipt](../../scripts/verification/startup-reentry/evidence/README.md). Existing hardware and native compatibility evidence is retained for unchanged code. No new hardware acceptance or broader security-audit clearance is claimed. The maintained strict-16-KB regression from #101/#99 remains unchanged and closed. The six native advisory applicability dispositions retain their October 16 expiry. Install only the signed `clench-0.3.34-release.apk` after publication and verify the established signer and public evidence bundle. The unsigned APK is non-installable reproducibility evidence. - Sep 23, 2026 0.3.33# Clench Wallet 0.3.33 This maintenance release updates JNA's Android runtime from 5.14.0 to 5.19.1. It repairs a native initialization crash encountered when creating or importing a wallet on Android devices using 16 KB memory pages. APK ZIP alignment alone could not prevent the internal ELF protection-layout failure. BDK, SQLCipher, database schema, wallet logic and signing policy are unchanged. The dependency lock, strict checksums, native payload inventory and source review are refreshed. Existing incomplete native-source assurance and the six
More…
legacy WebPKI applicability dispositions remain explicit, with their original 2026-10-16 expiry. The scoped acceptance uses release-mode APKs on disposable ARM64 emulators: Android 15 with 16 KB pages and compatibility fallback disabled, plus an Android 16 4 KB control. It checks offline wallet creation/import, receive addresses, encrypted storage and wallet reopen after process restart. Existing hardware acceptance is retained; no new hardware acceptance is claimed. Install only the signed `clench-0.3.33-release.apk` after publication and verify the established signer and published evidence bundle. The unsigned APK is non-installable reproducibility evidence. Publication requires independent review and the unchanged protected release gates; see the [compatibility evidence](../security/jna-16kb-compatibility.md). - Sep 21, 2026 0.3.32# Clench Wallet 0.3.32 This maintenance release strengthens signing-session ownership and Android network trust checks while preserving wallet identities, encrypted data and existing signing identities. ## Signing and wallet creation - Cancelling a TAPSIGNER operation closes an attached NFC connection and prevents obsolete callbacks from replacing a newer session or clearing its state. Connection cancellation cannot undo a command already delivered to a card or guarantee immediate interruption of a blocking connection attempt. - Multisig NFC imports are revoked when their destination changes. Starting a valid NFC import supersedes pending phone-signer generation, so late results cannot populate the wrong cosigner slot. - Asynchronous PSBT construction and signing completions must still belong to the current reviewed draft. Cancelled or replaced work cannot authorize a different transaction. - An interrupted signing operation requires explicit recovery and a fresh transaction review. Incomplete multisig transactions remain unavailable for broadcast.
More…
## Network trust Configured Electrum certificate pins retain certificate identity and validity checks through direct and proxy routes. Android regressions cover chain, expiry, hostname and configured-pin rejection, proxy DNS/routing, interrupted handshakes and fresh connection recovery. This does not impose new pins on arbitrary third-party or user-configured endpoints. ## Verification and limits The integrated candidate passed 568 JVM tests, all 59 required Android runtime tests, the nine-test Android network contract, and encrypted-database, persisted-wallet and process-restart checks. Physical Pixel/TAPSIGNER acceptance verified both inputs of a synthetic BIP-48 transaction, incomplete 2-of-2 handling and freshly reviewed export recovery. Earlier transport/authentication failures remain recorded; successful recovery is not a guarantee against future NFC interruptions. Diagnostic timing evidence is kept separate from candidate acceptance. Install only `clench-0.3.32-release.apk`. The unsigned APK is reproducibility evidence. Use the published checksums, attestations and `signed-release-verification.md` to verify the release bundle. Production signing remains in the protected signing job, with independent source builds and unchanged signer identity. No native-library replacement or new database schema is introduced in this release. Existing schema-14 recovery remains forward-only. The six source-bound legacy WebPKI dispositions retain their original expiry. SQLCipher provenance and the remaining broader audit are separate, unfinished work; this release is not a whole-product security-audit completion claim. - Sep 20, 2026 0.3.31# Clench Wallet 0.3.31 This maintenance candidate addresses eight findings from the v0.3.30 application review. Publication is conditional on the version-specific QA gate; this source document alone is not a test receipt or proof of publication. ## Wallet policy and identity - Multisig creation accepts exactly one public account key per cosigner and verifies the native receive/change policy before saving the wallet. Existing
More…
policies are not silently rewritten. - Every nonempty BIP39 passphrase, including whitespace-only input, is preserved through preview, import and unlock. Passphrase wallet sessions remain locked until explicitly unlocked; private descriptors are not persisted for them. Existing wallet identities are not changed automatically. ## Wallet-local metadata and transactions - UTXO labels and frozen state are keyed by wallet and outpoint. The database upgrade preserves surviving rows, including legacy spelling aliases; backup import validates ownership and prevents cross-wallet replacement. - Current frozen-input policy is checked during transaction/PSBT construction, signing and retained-draft broadcast. A newly frozen input requires rebuilding and reviewing the transaction, not silently modifying a signed transaction. - Fresh successful native sync results replace the transaction-history snapshot atomically. An old positive confirmation count no longer overrides current native unconfirmed state; a failed sync does not erase the previous snapshot. ## Network and authentication boundaries - Offline mode denies new HTTP and Electrum work and cancels active transports. Requests and callbacks from an earlier mode generation cannot resume on a later online transition. Already transmitted bytes cannot be recalled. - Malformed NFC data is rejected without escaping the activity parser or partially delivering a signing payload. Locked or stale-session input remains rejected. - Relaxing background relock time requires fresh authentication under the currently configured PIN/system method. Cancellation, failure or a stale session does not persist a weaker setting. Separate seed/send gates remain. ## Upgrade and verification The Room database advances from schema13 to14. Preserve a backup and use a forward fix if recovery is necessary: an older APK cannot be assumed to open the new schema safely. This migration cannot reconstruct metadata overwritten by an older version. Do not clear app data or silently rederive existing wallets to work around an upgrade or passphrase identity problem. Install only `clench-0.3.31-release.apk` after publication. The unsigned APK is reproducibility evidence, not an installable release. Use the published `signed-release-verification.md`, checksums and attestations to verify the bundle. Signing identities and protected, independent build/signing controls are unchanged. The patched source-built native dependencies are unchanged from v0.3.30; six expiring legacy WebPKI call-path dispositions remain explicit. This is scoped remediation, not a completed whole-product security audit. SQLCipher vendor source correspondence, deeper native C assurance and unfinished audit coverage remain separate. Physical/OEM/hardware-wallet results must be recorded explicitly and are never inferred from emulator or JVM tests. See `docs/qa/v0.3.31-release-gate.md` for the mandatory candidate acceptance boundary. - Sep 16, 2026 0.3.30# Clench Wallet 0.3.30 This maintenance release source-builds BDK's Android native libraries with Rustls 0.23.45 and anyhow 1.0.103, plus their required compatible dependency updates. It retains the upstream BDK 3.0.0 Kotlin bindings and native interface across arm64-v8a, armeabi-v7a and x86_64. Wallet and database formats are unchanged. The native build uses pinned source, Rust and Android NDK inputs and strict artifact verification. The production release requires fresh Android migration and authentication tests, separate hosted unsigned builds, the established APK
More…
signer, and the complete checksummed and attested verification bundle. Install only `clench-0.3.30-release.apk`. The unsigned APK is non-installable reproducibility evidence. See `signed-release-verification.md` for verification. Six expiring legacy WebPKI advisory dispositions apply only to reviewed unused Esplora call paths; that legacy code is not represented as patched or removed. SQLCipher source correspondence, complete native C coverage, physical/OEM and hardware-wallet acceptance remain open as documented. This scoped dependency update does not complete the broader security audit. F-Droid publication follows its independent build and review schedule. - Aug 31, 2026 0.3.28# Clench Wallet 0.3.28 Clench Wallet 0.3.28 adds physically unverified air-gapped PSBT protocol presets intended for OneKey Pro, Krux, and Specter DIY; expands QR compatibility with formats used by coordinators and hardware signers; and implements a narrowly scoped TAPSIGNER BIP-48 native-SegWit multisig cosigner path whose physical acceptance remains `NOT RUN`. It also fixes persisted TAPSIGNER settings being displayed as `None`. The new device and TAPSIGNER multisig paths have extensive automated and
More…
independent-vector coverage but no recorded physical-device acceptance. This release does not claim compatibility with a particular model, firmware, camera, NFC controller, or removable-media implementation. The exact deferral is recorded in `docs/qa/physical-hardware-gates-v0.3.28.md`. ## Air-gapped hardware-wallet paths - A preset intended for OneKey Pro uses animated BC-UR v2 `crypto-psbt` QR. - A preset intended for Krux uses animated BC-UR v2 QR and an explicitly selected microSD/file PSBT round trip. - A preset intended for Specter DIY uses animated BC-UR v2 QR and an explicitly selected microSD/file PSBT round trip. - Clench still does not open a USB or Bluetooth data connection to a signer. QR, an intentional NFC tap, and a user-selected file/removable card remain the allowed transfer classes. These entries implement protocol paths intended for those devices; they are not a claim of interoperability or that the v0.3.28 APK was exercised on representative physical hardware. ## Sparrow-compatible QR imports The scanner and payload decoder now accept additional bounded inputs commonly encountered in coordinator and signer workflows: - legacy UR v1 multipart payloads; - `ur:psbt`; - binary PSBT/raw-transaction `ur:bytes`, or strict control-safe UTF-8 text handed to the existing downstream decoders; and - bounded static Base43 PSBT/raw-transaction text. Legacy multipart sessions are isolated and bounded, tolerate valid out-of-order frames, and reject conflicting or malformed streams. Binary `ur:bytes` is no longer forced through UTF-8 text conversion. Single-key `crypto-output` imports preserve the declared script type instead of silently treating every key as native SegWit. A fixed vector produced with Sparrow's Drongo code is used as an independent digest/signature oracle. No Sparrow Wallet coordinator or Drongo dependency was added to the app; Clench's existing Hummingbird BC-UR library remains a runtime QR dependency. ## TAPSIGNER native-P2WSH multisig An imported TAPSIGNER may now sign its own member inputs in a standard native- SegWit multisig wallet. The production boundary is deliberately narrow: - PSBT v0 only; - BIP-48 account zero, with the card-reported network flag required to agree with the hardened path coin type; - native P2WSH standard CHECKMULTISIG `multi` or `sortedmulti` policy; - receive/change child paths below the authenticated card account; - ECDSA `SIGHASH_ALL` only; and - complete in-app transaction review followed by a separate explicit broadcast action. Before requesting an NFC signature, Clench validates the witness UTXO and witness script, the complete multisig policy, card-reported network/path consistency, all supplied derivation pubkeys as policy members, the card's eligible member key/path, and any existing policy-member partial signatures. Other cosigner origins may differ and are not authenticated by the card. Clench accepts only a matching returned public key and valid low-S signature for the exact BIP-143 digest. Verified signatures are merged atomically: if any later input fails or the tap is interrupted, no earlier input is changed. After threshold finalization, the normal transaction policy still requires the same recipients, amounts, change, fee, version, locktime, sequences, and inputs that were reviewed. NFC signing never auto-broadcasts. TAPSIGNER is screenless, so it cannot independently display the transaction. Review every detail in Clench before entering the PIN and tapping the card. Taproot, legacy, nested SegWit, nonstandard P2WSH, other BIP-48 accounts, non-`SIGHASH_ALL` policies, and TAPSIGNER PIN change remain unsupported. ## Verification and security evidence The feature pull request passed the full JVM unit suite, Android lint, debug assembly, strict dependency verification, release-control self-tests, CodeQL, and the separate 5,000-case hostile protocol lane. Focused evidence includes: - positive and hostile TAPSIGNER BIP-48/P2WSH cases for policy binding, mixed cosigner origins, existing partial signatures, wrong key/path/card material, unsupported sighash, multi-input failure, and atomic merge; - a fixed Drongo-derived native-P2WSH vector that independently anchors the exact BIP-143 digest and known ECDSA signature; the same Clench test separately exercises the synthetic BIP-48 key/path selection and DER plus `SIGHASH_ALL` PSBT injection; and - an end-to-end legacy-UR scanner-to-payload fixture with reversed multipart frames, plus positive and hostile tests for the other accepted encodings. The release-preparation pull request, exact protected `master`, Android instrumentation, and the protected Signed Release workflow must revalidate the release gates before publication. The source-level review and residual risks are recorded in `docs/security/security-review-v0.3.28.md`. ## Physical evidence and authorized deferral After being told that OneKey Pro, Krux, Specter DIY, representative camera- format round trips, and real-card TAPSIGNER BIP-48 multisig acceptance remained outstanding, the maintainer instructed “merge and release” on 2026-08-31 UTC. This authorizes publication with those rows `NOT RUN`; automated, simulator, emulator, and independent-vector results are not relabeled as physical passes. The v0.3.27 record contains one identified debug-candidate real-card TAPSIGNER single-signature payment. That useful result does not prove v0.3.28 multisig or the final signed v0.3.28 APK. No new SATSCARD or previously listed hardware- wallet physical pass is claimed by this release. ## Release verification The only installable production artifact is `clench-0.3.28-release.apk` from the signed GitHub release. `clench-0.3.28-unsigned.apk` is non-installable reproducibility evidence. Verify the pinned-key signed annotated source tag, checksum manifests, APK signer certificate, package/version, SBOM, OSV result, provenance, independent-build evidence, and GitHub attestations as described in `docs/release/signed-release-verification.md`. The release workflow preserves the v0.3.27 three-build and isolated-runtime signing controls. The Android signing values are currently stored as repository secrets but referenced only by the approval-gated no-source signing job; moving or rotating them into environment-scoped secrets remains a documented defense- in-depth follow-up. F-Droid follows its own build and publication cadence and may continue to show v0.3.27 after the signed GitHub v0.3.28 release becomes available. - Aug 31, 2026 0.3.27# Clench Wallet 0.3.27 Clench Wallet 0.3.27 adds direct TAPSIGNER payment signing, moves wallet operations to BDK Android 3.0.0, and adds device-level persistence and encrypted database verification. The release retains the fail-closed, isolated signing and three-build reproducibility controls introduced in v0.3.26. ## TAPSIGNER payments Clench can now use an imported TAPSIGNER to sign a single-signature BIP-84
More…
native-SegWit payment directly over NFC. The supported boundary is deliberately narrow: - PSBT v0 with native-SegWit P2WPKH inputs; - ECDSA `SIGHASH_ALL` only; - unhardened input paths below the card's authenticated BIP-84 account; - complete recipient, amount, change, fee, fee-rate, and input review in Clench before the PIN and NFC tap; - verification of the returned public key, compact low-S signature, and input ownership before copying only the verified partial signature into the original PSBT; and - the existing final-transaction policy checks plus a separate explicit broadcast action. TAPSIGNER is screenless. It cannot display or independently confirm the transaction, so the payment shown by Clench must be reviewed before entering the PIN. Taproot, legacy, nested-SegWit, and P2WSH/multisig-cosigner TAPSIGNER signing remain unsupported. Clench also does not provide a TAPSIGNER PIN-change command in this version. ## Real-card interoperability and PIN handling The NFC implementation now accepts bounded, valid indefinite-length CBOR while retaining byte, nesting, item-count, duplicate-key, and single-root limits. It also verifies the derive-signature profile used by deployed TAPSIGNER firmware, binds the selected account through an encrypted child-`0/0` proof, validates card/app network agreement, and canonicalizes and preflights the authenticated account xpub with the same Android BDK parser used during wallet import. Every TAPSIGNER PIN field uses a masked numeric keypad by default. Current cards accept numeric PIN changes; an explicit letters-and-symbols fallback is available for older cards that may retain a legacy alphanumeric PIN. PIN data remains transient, and Clench dismisses the keyboard before NFC operations and when leaving the relevant flow. ## BDK, database, and build updates - BDK Android is upgraded from 2.3.1 to 3.0.0. - A dedicated two-version verification fixture creates persisted wallet state with BDK 2, opens it with BDK 3, and checks descriptors, addresses, transactions, UTXOs, and staged persistence behavior in place. - Android instrumentation opens the actual SQLCipher-backed Room database and rejects plaintext, wrong-key, and incompatible database states without a destructive fallback. - The Android Gradle Plugin moves to 9.3.1 and Kotlin to 2.4.10, with updated locks and dependency-verification metadata. - The Android instrumentation workflow exercises the real BDK parser and native database boundary in addition to JVM tests and lint. BDK's per-wallet files contain public descriptors, scripts, and transaction metadata. They are not SQLCipher-encrypted and continue to rely on the Android application sandbox and device encryption. Seeds and extended private keys are not persisted in those files. ## Physical compatibility evidence and its limit On 2026-08-30 the maintainer exercised the new path on a Pixel 8 Pro with a real TAPSIGNER using the isolated debug candidate at commit `7a5918a`: - package/version: `net.clench.wallet.debug`, `0.3.26-tapsigner-test` (`326`); - APK size: 64,515,556 bytes; - APK SHA-256: `f2b5a2ec0d152798e36bd6b04806ff04db8565dc8ecd7064c307348e270d951a`; - Mainnet BIP-84 account at `m/84'/0'/0'`; - successful status, authenticated derive, encrypted child-`0/0` proof, Android BDK xpub preflight, and watch-only wallet import; and - one-input, one-output payment of 10,067 sats with a 110-sat fee, no change or unexpected output, an explicit phone-side broadcast action, and two observed confirmations. No PIN/CVC or wallet material was captured. This is useful real-card compatibility evidence, but it is not an exact-artifact physical pass for the final signed v0.3.27 APK. The later keyboard changes and the production build have automated coverage but were not put through the same funded physical flow. Multi-input, interruption, wrong-PIN, and the wider card/Android firmware matrix remain separate acceptance work. The exact boundary is recorded in `docs/qa/physical-hardware-gates-v0.3.27.md`. The source-level threat and control review for this feature is recorded in `docs/security/security-review-v0.3.27.md`. ## Release verification The only installable production artifact is `clench-0.3.27-release.apk` from the signed GitHub release. `clench-0.3.27-unsigned.apk` is non-installable reproducibility evidence. Verify the signed annotated source tag, checksum manifest, APK signer certificate, package/version, SBOM, provenance, and independent-build report as described in `docs/release/signed-release-verification.md`. F-Droid follows its own build and publication cadence and may show v0.3.26 briefly after the signed GitHub v0.3.27 release becomes available. - Aug 5, 2026 0.3.26# Clench Wallet 0.3.26 Clench Wallet 0.3.26 is the production security-hardening release that carries forward the application protections first prepared for v0.3.24. Two earlier signed candidates stopped safely inside the protected release workflow; neither v0.3.24 nor v0.3.25 published an APK or GitHub release. ## In plain English - New Clench seeds use explicit Android operating-system entropy. Creation
More…
fails closed if secure randomness is unavailable, and temporary entropy bytes are wiped after use. - External hardware-wallet returns are accepted only when their signatures commit to the complete transaction reviewed in Clench. Weak or unexpected sighash policies are rejected before merge, finalization, or broadcast. - Clench copies only verified signature material from returned PSBTs into the original transaction instead of trusting the returned container. - Seed, PIN, signing, and broadcast flows reject screenshots, Recents capture, stale authentication callbacks, obscured touches, and background lifecycle races. - Backgrounding stops new secret operations, drains active work, closes native wallet state, and then locks. Unverifiable cleanup requires an app restart. - Electrum TLS remains encrypted on every request path, and onion endpoints remain Tor-routed despite unusual case or a trailing dot. - NFC, QR, UR, BBQr, PSBT, backup, descriptor, and file imports have stricter size, type, session, and private-key checks. - TAPSIGNER setup binds the selected card identity and account key to a fresh app-secret challenge before accepting its xpub. Direct TAPSIGNER payment and multisig-cosigner signing remain unimplemented. ## Two fail-closed release attempts The signed v0.3.24 source tag was never published as a GitHub release. Its protected workflow rejected an unexpected APK v4 incremental-install `.idsig` sidecar before independent reconstruction and publication. No v0.3.24 APK was published. The v0.3.25 workflow explicitly disabled that sidecar and completed isolated signing, key destruction, signature verification, and attestation. Its independent verifier then found that Android `apksigner` had deterministically rewritten local ZIP alignment metadata while creating the v2/v3 signing block. The entry contents and compressed streams matched, but the old verifier compared the independently rebuilt unsigned local headers directly with the post-`apksigner` headers. It rejected the mismatch and skipped publication. No v0.3.25 APK or GitHub release was published. These stops demonstrate the intended release posture: an unexplained evidence file or byte difference blocks publication rather than being ignored. ## Corrected reproducibility proof v0.3.26 keeps local ZIP headers inside the verification boundary by reproducing `apksigner`'s deterministic rewrite instead of pretending that an unsigned APK and an `apksigner`-processed APK are the same container. The workflow requires two comparison gates across three clean build outputs: 1. The exact unsigned APK A given to the isolated production signer must match separate clean rebuild B byte-for-byte before key access. B receives no expected APK artifact, and its attestation is verified before approval. 2. Separate clean rebuild C also receives no expected APK artifact. After its attestation is verified, C must match the same approved raw digest. A copy of C is processed with the pinned `apksigner` packaging policy and a disposable RSA-4096 verifier-only key. That key is destroyed before the verifier compares every ZIP entry—including local headers, compressed bytes, entry order, metadata, and archive comment—with the production-signed APK. No APK entry is excluded. Production and verifier normalization both explicitly select v2/v3 signing, disable v1, v4 sidecars, and verity, and pin the minimum SDK and native-library alignment policy. Their verification reports must also show v3.1, v4, and SourceStamp as false. The production signer remains separately checked against the established Clench signing-certificate digest. A disposable verifier key can reproduce only the deterministic packaging transformation; it cannot impersonate a Clench release. The release workflow still: - accepts only a pinned maintainer-signed tag on exact protected `master`; - produces A, B, and C in separate clean hosted builds without signing credentials; B and C receive no expected APK artifact; - gives the isolated signer only checksummed unsigned artifacts and a pinned `apksigner`, with no source checkout or Gradle execution; - destroys temporary signing material before signer verification, attestations, or artifact upload; - independently proves both raw unsigned identity and normalized full-entry identity before publication; and - publishes only the allowlisted APK and release evidence. The public `clench-0.3.26-unsigned.apk` is unsigned reproducibility evidence, not an application release, and must not be installed. The only production APK is `clench-0.3.26-release.apk` after its established signer is verified. ## Coldcard entropy boundary The security review found no Coldcard-style deterministic entropy fallback in Clench. Clench cannot determine from an imported xpub whether another device created its seed with affected firmware. Anyone covered by a hardware vendor's entropy advisory must follow that vendor's migration instructions independently of this update. This update does not, by itself, require owners of Clench-generated wallets to replace their seeds. High-value multisig policies should continue to use keys created independently on different devices. ## Physical-test and hardware boundaries The maintainer reported running physical-device checks and authorized publication. Device-, firmware-, transport-, and APK-specific row evidence was not supplied to the repository, so Clench does not invent individual physical-pass records. The detailed requirements and this evidence boundary are recorded in `docs/qa/physical-hardware-gates-v0.3.26.md`. Clench communicates with supported signing devices by QR, an intentional NFC tap, or a user-selected file/removable card—not USB or Bluetooth data connections. Direct TAPSIGNER payment signing, TAPSIGNER multisig signing, and PIN/CVC change remain unavailable. - Jul 31, 2026 0.3.23