Skip to content

Security model

Trust the smallest possible boundary.

The interface asks. The wallet core decides. Keys, policy, transaction truth, storage, and broadcast stay inside the trusted native application.

MainnetSigned GitHub releasesPublic source
Transaction review

Check the payment, not a summary

The details below come from the actual unsigned transaction.

You send250,000 sats
To
bc1q…5t8ul
Label
Hardware wallet
Network fee
1,540 sats
Change
Verified wallet address
✓Ready to signRecipient, fee, inputs, and change checked

Trust map

Public interface. Native authority.

The screen can display wallet data and collect your intent, but it cannot reach private keys. A narrow, typed boundary carries approved actions into the native wallet core.

  1. PublicSvelteKit interfacePresentation and intent
  2. TypedWalletPort + Tauri IPCExplicit operations and stable errors
  3. TrustedRust wallet coreKeys, descriptors, PSBTs, persistence
  4. ExternalCore + hardware signersAdversarial data, verified identities

Controls

Mechanisms, not reassurance.

01

Secrets stay native.

The webview never receives a generated mnemonic, seed, private descriptor, extended private key, or decrypted signing material. Rust creates software-wallet entropy with the operating system CSPRNG and presents recovery words through a native sheet.

02

Your encrypted wallet stays portable.

Groot protects a software wallet with authenticated encryption and your wallet passphrase. The encrypted profile can move with you, so a unique, long passphrase remains essential.

03

The PSBT is the record.

Review data comes from the persisted unsigned transaction. Rust checks inputs, fees, recipient, change, wallet ownership, and proposal identity again before signing, merging, finalizing, or broadcasting.

04

Hardware identity is checked.

USB operations reopen the exact signer by its validated fingerprint. Imported signatures must add valid policy signatures to the same transaction; changed or unrelated PSBTs fail closed.

05

Your node defines the network edge.

Wallet balances, history, fees, and broadcast use the Bitcoin Core node selected for that wallet. Connect locally or to your own remote node over HTTPS. There is no silent public wallet backend.

Release verification

Verify software before you trust it.

Download Groot from the official GitHub Releases page. Compare the published checksum with the file on your device, then verify the signed checksum with the published Groot PGP release key. Stop if the hash, signature, key fingerprint, or release origin does not match.

  1. 01

    Start at the official release origin.

    Open the Groot repository yourself and select the intended tagged release. Download the installer or binary, SHA256SUMS, and SHA256SUMS.asc from the same release.

    Open official GitHub Releases →
  2. 02

    Calculate the file checksum locally.

    Use the exact file you downloaded.

    macOS shasum -a 256 Groot-0.4.93.dmgLinux sha256sum Groot-0.4.93.AppImageWindows PowerShell Get-FileHash .\Groot-0.4.93.exe -Algorithm SHA256
  3. 03

    Compare the complete hash.

    Find the matching file in SHA256SUMS. Every character of the calculated hash must match. A partial or visual approximation is not enough.

  4. 04

    Import and identify the release key.

    Import the downloaded public key, then inspect its full fingerprint. Confirm that fingerprint through more than one official Groot channel.

    gpg --import groot-release.ascgpg --fingerprint security@usegroot.com
  5. 05

    Verify the signed checksums.

    Verify the signature over the checksum file, not just the downloaded binary. Proceed only when GPG reports a good signature from the independently confirmed release key.

    gpg --verify SHA256SUMS.asc SHA256SUMS

Product boundaries

Clear about what comes later.

  • Groot is available for desktop; iOS and Android are coming later.
  • Tor connectivity and compact-filter sync are not part of this release.
  • Family coordination and Business workflows remain separate coming-soon services.
  • Groot is onchain only: no Lightning, exchange, or cloud recovery dependency.
Find the canonical security model →

Your keys.
Your bitcoin.

Groot is new. Start small, verify every address, and rehearse your recovery before holding more.