Self-custodial · Transparent BTX · Keys never leave your device

Your BTX,
quantum-resistant.

A standalone desktop wallet for BTX, signed with post-quantum cryptography: ML-DSA and SLH-DSA over taproot-style P2MR. Built so the keys that hold your coins survive the machines that will one day try to break them.

Mac build signed by Bonuz Technology DMCC · mainnet · verify the SHA-256 before you run it.
First time install, read this first

The Mac build is signed and notarized, so it just opens. Windows and Linux are not signed yet, so those flag once on first run.

macOS

Open the .dmg and drag BTX PQ wallet into Applications. That is the whole install. The app is signed by Bonuz Technology DMCC and notarized by Apple, so it opens on a double-click and macOS names Bonuz as the verified developer. No right-click Open, no Terminal.

Full Mac install guide, step by step →

Windows

SmartScreen shows “Windows protected your PC”. Click More info, then Run anyway. No Terminal step.

Release · v1.1.0

Post-quantum self-custody, done properly.

The BTX PQ wallet holds your coins with lattice and hash based signatures, ML-DSA and SLH-DSA over taproot-style P2MR, keeps every key on your device, encrypts backups by default, and now lets you sign in to a site straight from the wallet with one click. You can also move a whole wallet in and out as a portable .btxwallet.json file, fully offline. Everything here sits on the v0.21.0 hardening, with the post-quantum signing core byte-unchanged and unit-tested.

Read the full changelog, every release since v0.1.0 →

Move a wallet as a file

Restore a portable .btxwallet.json bundle, the kind the website, a node, or btx-cli writes, straight into the wallet, and export the open wallet back out as one. Both directions are fully offline: read and written through the native dialog, no new network calls anywhere.

Open in wallet, one click

When a site offers "Open in BTX PQ Wallet", it launches the wallet straight to a "Sign in to this site" screen. You see the site, pick which wallet signs, and click. Nothing signs automatically, a mismatched or malformed request is refused, and a login can never move funds.

Backups encrypted by default

Saving a recovery file now encrypts it with Argon2id and AES-GCM from the start. Writing your master key to disk in plain text takes a deliberate second click after a warning.

Your key stays off the screen

Backup screens show dots until you press Reveal, and Settings warns you to check your surroundings first. Repeated wrong passphrases pause unlocking with growing delays, so guessing at the lock screen is pointless.

Smart network fees

Normal and Priority presets read the live mempool. On a clear network they stay low on purpose because a higher fee cannot confirm faster. Sends retry automatically when antivirus or a VPN drops the connection.

Sign in with your wallet

qID Sign-In: prove you control your BTX address to an app or service without exposing a key. Paste the request, check the site, sign. A login signature can never move funds.

Wrong-network guard

Test/regtest addresses decode to the same mainnet script, so the wallet now refuses any non-mainnet address before it signs. No test-looking address can quietly move real BTX.

Send twice, cleanly

The "bad-txns-inputs-missingorspent" error is gone. The wallet remembers the coins your last send used, tells you plainly it's still confirming, and self-heals if a send is dropped.

Money-in, alive

Coins drift onto your balance while a deposit confirms, then a bright double chime the moment it's final. The incoming line reads in clear white.

Cleaner send & receipt

The confusing "change" and "size" lines are gone. The sent receipt shows the amount big and white, with your saved contact's name.

Supply-chain lock

The entire front-end is sha256-pinned and a build-blocking check fails CI if any unsafe HTML/script sink is ever introduced. What ships is exactly what was reviewed.

Refresh on demand

A force-refresh on the "Your wallets" list updates every balance the instant you ask.

Experimental

Relics and NFTs, held in your wallet.

The wallet can show BTX artifacts, the relics and NFTs an address carries on chain, with their artwork verified against the chain before anything is shown. Treat this as a preview, not a permanent part of BTX. Whether it stays depends on the BTX core team and on the health of the network: artifacts put extra data on chain, and if that risks slowing or clogging it, the right home for them is a Layer 2 such as EVX, not the base chain. It may change or be removed.

The free artifact mint has ended. Browse the BTX artifacts →

Your relics and NFTs, in one tab

The BZA1 artifacts an address holds, Genesis relics, NFTs, attestations, appear in their own tab, decoded straight from the chain, each with a quantum sigil drawn from its on-chain fingerprint and a full detail page. Read-only: the wallet never mints or moves one on its own.

Artwork, verified, not trusted

Load an artifact's real image right in the wallet, through its own hardened network path. Every byte must hash to the commitment written on chain or nothing is shown. The gateway is never trusted, and only real image bytes are accepted, never a web page or SVG.

A relic can't be burned by accident

Send, Send-All, and the recovery sweep all keep your artifact coins back and fail closed on any coin they cannot verify, in every path. A relic or NFT can never be spent as an ordinary fee or input. Plain BTX sends stay plain and never mention artifacts.

History says when a relic moved

A transaction carrying an artifact now reads "Artifact received", "Artifact sent", or "Artifact minted to you" with its name, instead of a bare amount, decoded by the same parser the Artifacts tab uses, from data the history view already had. No new network calls.

Post-quantum by design

Built for the machine that hasn't been built yet.

Today's wallets lean on elliptic-curve signatures a large enough quantum computer could one day forge. BTX signs every output with lattice- and hash-based signatures (quantum-resistant by construction), and the keys are generated on your device and never leave it.

The identity and signing engine underneath is qID. It is post-quantum, byte-exact to the BTX node, and what makes the wallet work. See how qID works → qid.dev

ML-DSA login SLH-DSA recovery P2MR (taproot-style) Argon2id at-rest seal Touch ID / passkey Egress-pinned proxy
SignaturesML-DSA-44 + SLH-DSA
Key custodyOn device · never leaves
NetworkRust-only, egress-pinned
Webview reachno code-exec sink
At-rest sealArgon2id + AES-256-GCM
FundsTransparent · self-custodial
First time install, read this first

The Mac build is signed and notarized, so it just opens. Windows and Linux are not signed yet, so those flag once on first run.

macOS

Open the .dmg and drag BTX PQ wallet into Applications. That is the whole install. The app is signed by Bonuz Technology DMCC and notarized by Apple, so it opens on a double-click and macOS names Bonuz as the verified developer. No right-click Open, no Terminal.

Full Mac install guide, step by step →

Windows

SmartScreen shows “Windows protected your PC”. Click More info, then Run anyway. No Terminal step.

Download · v1.1.0

Get it, then verify it.

The Mac build is signed by Bonuz Technology DMCC and notarized by Apple. Windows and Linux are not signed yet. All builds run on mainnet, so sends move real BTX. Check the SHA-256 against the value below before you open the installer.

Debian or Ubuntu? Get the .deb package → All builds are also on the releases page.

Verify · SHA-256 (click a hash to open VirusTotal)