Biscuit Wallet

All docs pages

Get started

Your wallet

Monero

Bitcoin and Litecoin

Swaps

Home tab

Privacy and network

Security

Reference

Help

Docs › Get started

Verify your download

It takes a couple of minutes, and it tells you the file you got is exactly the one we published, not something swapped in along the way.

The release signing key

Every release is signed with this key. Its fingerprint is what identifies it: compare it with the one your tools show.

NameBiscuit Wallet releases
TypeRSA 4096
FingerprintD714 332E 6101 C1DA AC60  E644 202F 1FA3 98DE CEFA

The public key is on the download page, in SECURITY.md, and built into Biscuit: the app installs an update only after checking this signature.

1. Check the signature of the checksums

Each release has a list of SHA-256 checksums, hashes-<version>-plain.txt, signed with the key above. With GnuPG installed (on a Mac, from GPG Suite or Homebrew; on Windows, Gpg4win):

gpg --import biscuit-release-key.asc
gpg --verify hashes-1.0.12-plain.txt

The output must say Good signature from “Biscuit Wallet releases”, and the fingerprint must match the one above. GnuPG may add that the key is not certified with a trusted signature: that only means you haven’t signed our key yourself.

2. Check the file against the list

Compute the checksum of the file you downloaded and find the same value, next to the same file name, in the signed list.

macOSshasum -a 256 biscuit-1.0.12-mac-arm64.zip
Linux, Tailssha256sum biscuit-1.0.12.AppImage
Windowscertutil -hashfile biscuit-1.0.12-win.zip SHA256

For version 1.0.12, the AppImage’s checksum is in a second list, hashes-1.0.12-appimage-plain.txt, signed with the same key: check its signature the same way. From the next version, every file is in one list.

If the values differ, don’t open the file: download it again from biscuitwallet.com.

Going further

Releases are built with Guix, so you can also rebuild one yourself and compare: see Reproducible builds.