dannybuntu's avatar
dannybuntu
dannybuntu@walletscrutiny.com
npub1r709...sf7d
Open Source contributor to FOSS project walletscrutiny.com and nostr.info
dannybuntu's avatar
dannybuntu 1 year ago
โœ… We verified that @nunchuk_io io.nunchuk.android v1.68.0 is reproducible! Despite minor expected diffs in AndroidManifest.xml & resources.arsc (e.g. Crashlytics ID, Google Play metadata), no functional changes were found. #ReproducibleBuilds #FOSS #Android
dannybuntu's avatar
dannybuntu 1 year ago
โœ… Just verified that Phoenix Wallet (Mainnet) v2.6.0 is reproducible! Built from source and matched Play Store APK byte-for-byte. ๐Ÿ”’ No signed tag/commit, but the build checks out. Full verification:
dannybuntu's avatar
dannybuntu 1 year ago
๐Ÿ” Verified: @nunchuk_io Desktop v1.9.46 is fully reproducible Built on Ubuntu 22.04 using their official Docker-based guide โœ… ZIP & AppImage SHA256 match official release ๐Ÿ›  Build: CMake + Qt + Docker ๐Ÿ“ฆ Result: Byte-for-byte identical #ReproducibleBuilds #Bitcoin #OpenSource
dannybuntu's avatar
dannybuntu 1 year ago
๐Ÿ” Just verified the Bitcoin Knots v28.1 (Linux x86_64) binary as reproducible! ๐Ÿงช Build matched byte-for-byte. ๐Ÿ” Signatures validated from Luke Dashjr & other Knots builders. ๐Ÿ“Ž Full details on WalletScrutiny: #Bitcoin #ReproducibleBuilds #FOSS
dannybuntu's avatar
dannybuntu 1 year ago
โœ… Reproducibility confirmed for it.airgap.vault v3.32.7 (68124) ๐Ÿ” APK hash: 5ae0a8...9c25 ๐Ÿงฌ Matches source at commit 3ec5c79... ๐Ÿ› ๏ธ Built using test.sh & Docker ๐Ÿ“„ Verified report: #ReproducibleBuilds #Android #OpenSource #WalletSecurity
dannybuntu's avatar
dannybuntu 1 year ago
Tried building Mixin Messenger for Linux (v2.2.0) from source โ€” ran into a missing breakpad_client error. No buildable path without upstream fix. ๐Ÿ”ง GitHub Issue: ๐Ÿ” WalletScrutiny Asset Info: #ReproducibleBuilds #CryptoWallets #LinuxApps
dannybuntu's avatar
dannybuntu 1 year ago
๐Ÿ”Ž Check out this asset information I registered on WalletScrutiny: โœ… Reproducible Electrum Windows Standalone Executable (v4.5.8) Full verification and report available here: Independent reproducibility strengthens open-source security. ๐Ÿ” #ReproducibleBuilds #OpenSource #Electrum #WalletScrutiny
dannybuntu's avatar
dannybuntu 1 year ago
๐Ÿš€ Successfully reproduced and verified Electrum 4.5.8 from source! ๐Ÿ”’ Full PGP verification passed โ€” signatures from Thomas Voegtlin, Emzy, and SomberNight were โœ… ultimate trust โœ…. ๐Ÿ“œ SHA256 matched: dd8595a138132dee87cee76ce760a1d622fc2fd65d3b6ac7df7e53b7fb6ea7e8 ๐Ÿ”Ž See the full asset registered at WalletScrutiny: ๐Ÿ‘‰ #Bitcoin #OpenSource #ReproducibleBuilds #Electrum #WalletScrutiny
dannybuntu's avatar
dannybuntu 1 year ago
๐Ÿ” Verified: Keystone3 Pro Firmware v2.0.4 (Cypherpunk, Modern) is reproducible โœ… Unsigned binary matches local build byte-for-byte. Signed hash differs (as expected due to signature). ๐Ÿ“„ Asset registered on WalletScrutiny: #ReproducibleBuilds #FirmwareIntegrity #Bitcoin
dannybuntu's avatar
dannybuntu 1 year ago
๐Ÿ” Verified! Keystone3 Pro Firmware v2.0.4 (Multi-Coin, Modern) is reproducible ๐Ÿงชโœ… Our build perfectly matches the unsigned official binary. Signed binary differs (expected due to signature). Tested with: keystone3pro.sh 2.0.4 multicoin modern ๐Ÿ”— #ReproducibleBuilds #Bitcoin #FirmwareIntegrity #WalletScrutiny
dannybuntu's avatar
dannybuntu 1 year ago
๐Ÿ” Tried to build Nunchuk Desktop from source โ€” but hit a wall. โŒ Missing submodule libnunchuk (404 GitLab link) breaks the build. ๐Ÿงช Tested on both local Ubuntu & remote Debian. ๐Ÿ” Not reproducible in current state. ๐Ÿ“ฆ SHA-256: (build failed โ€” no binary to hash) ๐Ÿ”— #Bitcoin #ReproducibleBuilds #WalletScrutiny
dannybuntu's avatar
dannybuntu 1 year ago
๐Ÿ” Just verified a reproducible build of Nunchuk v1.67.0 (io.nunchuk.android)! โœ… The APK from my phone matches the one built from source (tag: android.1.67) ๐Ÿ” Signing excluded, but the code checks out byte-for-byte. ๐Ÿ“ฆ SHA-256: 41a66972d53121db4c77fd54bd79202822074fea6db35059b3049bfb5571bb73 ๐Ÿ”—
dannybuntu's avatar
dannybuntu 1 year ago
๐Ÿงช Verified the BitBanana v0.9.4 Android app is functionally reproducible! ๐Ÿ“ฆ Official split APKs were compared to those built from source. ๐Ÿงพ Only minor binary diffs in AndroidManifest.xml & resources.arsc. ๐Ÿ”—
dannybuntu's avatar
dannybuntu 1 year ago
๐Ÿ” Just verified a reproducible build of Blockstream Green v4.1.8! โœ… The APK from my phone matches the one built from source. ๐Ÿ” Signing was missing, but the code checks out. ๐Ÿ“ฆ SHA-256: e2b842...50f89 ๐Ÿ”—
โ†‘