v1.5.0
Latest 2026-10-05Includes everything prepared for 1.4.0 (below), which was never published, plus this round.
Your coins can move even if BTX switches off the everyday key. Every address this wallet has ever shown has two keys behind it: the everyday key (ML-DSA) and a recovery key (SLH-DSA). Until now the wallet could only use the first. BTX core can switch ML-DSA off if it is ever broken or doubted; it is not switched off today, but if it were, a wallet that cannot use its recovery key would hold coins it cannot move. Settings > Backup now has "Move coins with the recovery key": it moves every coin in the wallet to another wallet of yours, or to an address you type and confirm a second time.
What it costs, measured against a real BTX 0.34.12 node: the network charges each coin moved this way 10,000 vB, so 0.0001 BTX per coin at 1 sat/vB. Signing runs on up to four cores at once. Measured on an M5 with the window in the background: 5 coins in 7 seconds and 100 coins in about 7 minutes on 2026-10-03; on 2026-10-04, window hidden, 3 coins in 22 seconds, 5 in 42 seconds, 100 in 8 minutes 50 seconds (macOS slows background windows after about half a minute; the review screen's estimate assumes full speed, so with the window hidden it reads low). Coins worth no more than that are left where they are and listed, never dropped silently. One move signs at most 100 coins; the rest wait for a second move. Signing runs off the main window with a progress bar and a Cancel button, and nothing is sent until every coin is signed and checked. If a send does not land, the signed transaction is kept and sent again as is, never signed afresh.
Signing keeps going when you switch apps (macOS). WebKit pauses a background window's web page, and with it any signing in progress: measured on macOS, the second signature never finished. The wallet window now opts out of that (Tauri backgroundThrottling "disabled", macOS 14 and later), so a move signs at full speed whether or not the window is in front. While the window is minimized or fully covered the wallet skips its 30-second chain refresh and catches up the moment you return; a window merely behind other apps now keeps refreshing, which costs a little more network than 1.4.0. If no coin finishes for 45 seconds, the progress line says so plainly.
Newly mined coins wait until the network accepts them. A solo miner's block reward cannot be spent until it is 100 blocks old, and the network refuses a whole send that includes a younger one, so a miner who had just found a block could not send at all. Such coins are now left out of Send, the recovery-key move, the artifact forward and the node-wallet sweep, and the screen says how many blocks are left ("1 newly mined coin can be sent after about 99 more blocks"). Measured on a test node: a reward was held one block before the limit and sent at the limit.
The artifact check no longer trusts a shortened answer from the server. Before spending a coin the wallet now also checks that the output it reads is really that coin: this wallet's address, the coin's exact amount. A server that left an artifact's marker out of a transaction could otherwise make the artifact's coin look like plain BTX (a gap older than 1.5.0). Remembered checks are also forgotten when you switch servers.
Mining wallets can spend every coin. A wallet that receives mining payouts holds one coin per payout, often thousands. The wallet checks each coin's transaction before spending it (so an artifact's coin is never spent by accident), but it only ever checked about 600, and every coin past that was set aside with a note to "try again in a moment" that could never help. Measured on a test chain with 800 payouts: sending 10.5 of 11.2 BTX failed with "insufficient funds"; with this version the same wallet sends 9.5 BTX in one transaction. Every coin is now checked, eight at a time, and a transaction proven to carry no artifact is remembered until the wallet locks, so only the first send after opening the wallet takes a moment ("Checking your coins: N of M"). The Artifacts tab and Send share that work instead of each fetching every transaction.
Send knows when the everyday key is switched off. If every node that refuses a send says the everyday key is disabled, the wallet says so in plain words, remembers it, and shows a note on the Send tab with one click to the recovery-key move. The first normal send that goes through clears it. A new help topic explains the recovery key.
What it is not: both keys come from your master key, so this does not help if the master key itself is stolen.
Under the hood: the qID core is re-vendored (qid feat/recovery-spend-multi @ 4779eaf) and proven equivalent to the 1.4.0 core by the new tools/qid-equivalence.mjs (1,990 comparisons, 0 differences).