winnow

Winnow · Architecture

How Winnow works.

Your phone finds and checks payments, keeps your wallet history, and signs with the keys you control.

Clearnet connections use your device’s IP address; your own Tor or I2P gateways can carry peer connections instead. Peers can see which blocks you request. Read the privacy and trust limits.

1 · Find payments on your phone

Winnow checks public block filters against your wallet on the phone. A possible match triggers a block download to check for your payments.

Every block · always

filter · newestchecked
filter · newerchecked
filter · olderchecked
filter · olderchecked
filter · oldestchecked

the same public filter any compact-filter client can request

MATCHED HERE against your own scripts, on the device

On a hit only · rare

a whole block the one block that matched

only when a filter matches

Your addresses stay on the device during filter matching. Requested blocks can still reveal interests to peers. Discovery and trust.

2 · Watch for pending payments

While Receive is open, Winnow briefly listens for relayed transactions and checks them locally. This can show a payment before it confirms; the listening window ends when you leave.

block
block
block
RECEIVE SCREEN OPEN
your payment
relayed transactions · matched locally your payment, spotted on the device

This uses extra bandwidth and can miss unconfirmed payments. Block scanning finds confirmed payments later. Phone resource limits.

3 · Restore from saved history

A new wallet scans from its creation height. A restored wallet resumes from the history and scan position in its iCloud or manual backup.

New walletstart at creation height H
never scanned
scanning forward →
Imported walletsaved at height H · resume from there
saved history
verifying →

Automatic encrypted iCloud recovery includes this phone’s signing key, history, shared accounts and saved people. Beginner mode shows its save status; Advanced can turn it off. For manual recovery, keep both recovery words and a backup file. Words alone do not restore past payments. A phrase-free file restores watch-only access on a replacement device; manual JSON import needs a file containing the words to restore signing. Cloud recovery requires the same Apple Account with iCloud Keychain. Without iCloud, the wallet remains usable and offers a manual backup. Backup and recovery.

4 · Share payment approval

A 2-of-2 MuSig2 account needs both independent keys to approve a payment. A script-path 2-of-3 account lets any two owners approve while the third is away.

Round 1 · nonces

Each signer publishes a public nonce. The phone’s secret nonce stays in the signing screen and never persists — leaving before round 2 abandons the session.

Round 2 · partials

The phone and second signer each sign the same sighash, producing a partial signature that is verified before it is attached. Signing zeroes the secret nonce.

Aggregate

Combine the partial signatures and verify the result against the account’s key.

→

On chain

64 bytes · P2TR key-path

The signature has the form of an ordinary Taproot key-path spend. It does not reveal how many signers participated.

Each owner must keep an independent key and backup. The recorded journey tests both policies with Bitcoin Core cosigners; hardware-wallet compatibility needs separate testing. Signing and recovery limits.

5 · Compare peer responses

Winnow compares filter checkpoints from up to three peers to detect disagreement. It also limits concentration when choosing peers automatically.

peer A cfcheckpt 000000a3f8…e21c ✓ agrees
peer B cfcheckpt 000000a3f8…e21c ✓ agrees
peer C cfcheckpt 0000004b17…9d02 ✕ dropped

For checkpoints, a strict majority identifies a disagreeing peer. Without a majority, Winnow replaces the queried peers. Other filter checks have their own rules.

Several peers can share an operator and agree on false data. These checks do not make the phone a fully validating node. What Winnow verifies.