Avatar
dannybuntu
1f9e547c2f31942623b8ad1d07713282e8640fd8cf474e9f79f18ace8af216ed
Open Source contributor to FOSS project walletscrutiny.com and nostr.info

✅ Nunchuk Android v1.69.1 build verified!

No source-level or semantic diffs found—only benign differences in Play-injected metadata, manifest, and resource table due to known toolchain quirks.

Build is functionally reproducible per #WalletScrutiny standards.

🔍 Details: https://walletscrutiny.com/android/io.nunchuk.android/#verificationId=ea4e1677c875e352f9c1509513a1f23d61ec2ae6eec25eaee7da919871b51dc6 #Bitcoin #OpenSource

https://www.youtube.com/watch?v=pnzkKn5dqco Los Angeles riots June 2025 (livestreaming at the time I posted it)

Los Angeles riots.

I saw about a few posts on twitter, barely on FB. Hmmm, remember the times when civil disturbance content such as these permeated social media?

I feel as though content, is now very sanitized. Not that I am advocating for more dissident videos on Nostr - but it is, what it should be? Yes?

🔍 Just published a reproducibility report for Kraken Superwallet!

Can you build the app from source and get a byte-for-byte identical APK?

🧐 Spoiler: Still not a match, but every test brings us closer to true open source!

Check the details 👉 https://walletscrutiny.com/android/com.kraken.superwallet/#verificationId=3174b493fce0d9308db027668c97f2419619e523f6a99157131c7772da24acc5

#Bitcoin #OpenSource #WalletScrutiny 🚨

all I think is you

shouldn’t, but I always do—

too late for restraint

“It can’t be,” I think—

restless in her silent hours,

longing grows, unseen.

Why do you linger,

Sats dancing in restless dreams—

Questions echo on.

Always in my mind,

Thoughts of you just won't let go—

Peace, a ghost, denied.

Hearts race, restless dreams—

softly, longing slips away,

stillness fills the air.

Successfully reproduced Coldcard Q1 firmware v1.3.3Q from source—bit-for-bit identical to the official release (excluding ECDSA signature).

Proof of strong #ReproducibleBuilds and open auditability for Bitcoin hardware wallets.

Full details: https://walletscrutiny.com/hardware/coldcardQ1/#verificationId=4818c455a100a8f09ccbd86bc8bf33e731887b40c92c9c32d2196cf5296b17f1

#Bitcoin #Coldcard #SupplyChainSecurity

🔎✅ Verified: Nunchuk Android 1.68.1 split APKs reproducible!

Only expected binary diffs (manifest, resources, Play Store signing) observed—no functional or security differences.

Full report: https://walletscrutiny.com/android/io.nunchuk.android/#verificationId=b6aa6e6746fe405dc0c6f364565d059c741c1bb3a634dabdae056fa977c72676

#Bitcoin #OpenSource #ReproducibleBuilds 🚀🔐🔁

Thinking out loud: 'list framework, language and other dependencies for apps" With the verifications we have produced, we now have access to data that can be utilized to compare apps. Some are reproducibile, others are not. what frameworks do reproducible apps use? Although not exhaustively the source of non-reproducibility - these provide vital clues.

Yes, corellation isn't causation. But we have to start somewhere to help other app developers get their app reproducible.

✅ We verified that @nunchuk_io io.nunchuk.android v1.68.0 is reproducible!

Despite minor expected diffs in AndroidManifest.xml & resources.arsc (e.g. Crashlytics ID, Google Play metadata), no functional changes were found.

#ReproducibleBuilds #FOSS #Android

https://walletscrutiny.com/asset/?sha256=4a0c7dbaa9f697c009bbcba09d88c2768957f6fe335109bbd417f1100ddd7f4e

✅ Just verified that Phoenix Wallet (Mainnet) v2.6.0 is reproducible!

Built from source and matched Play Store APK byte-for-byte.

🔒 No signed tag/commit, but the build checks out.

Full verification:

https://walletscrutiny.com/asset/?sha256=e7d7012cd4ebae6441c59148a906129bd40e6a7a8f359262df4f943c62d0f4b4

🔍 Verified: @nunchuk_io Desktop v1.9.46 is fully reproducible

Built on Ubuntu 22.04 using their official Docker-based guide

✅ ZIP & AppImage SHA256 match official release

🛠 Build: CMake + Qt + Docker

📦 Result: Byte-for-byte identical

#ReproducibleBuilds #Bitcoin #OpenSource

https://walletscrutiny.com/asset/?sha256=0d01ff8e59a14a5fb7d4cf91cbe0069ec43314b463dac01eb1f41ad26abb63ee

🔍 Just verified the Bitcoin Knots v28.1 (Linux x86_64) binary as reproducible!

🧪 Build matched byte-for-byte.

🔐 Signatures validated from Luke Dashjr & other Knots builders.

📎 Full details on WalletScrutiny:

https://walletscrutiny.com/asset/?sha256=dd80fa2c5076299e79cb1df03f1813ef0364e9b8b8288d0746f1d21983ceac72

#Bitcoin #ReproducibleBuilds #FOSS

✅ Reproducibility confirmed for it.airgap.vault v3.32.7 (68124)

🔐 APK hash: 5ae0a8...9c25

🧬 Matches source at commit 3ec5c79...

🛠️ Built using test.sh & Docker

📄 Verified report: https://walletscrutiny.com/asset/?sha256=5ae0a8152166a22f9a6dab6a5469e8444cd7f704720230fa6caf71f92ab39c25

#ReproducibleBuilds #Android #OpenSource #WalletSecurity