winnow

Present · live walkthrough · ~19 sec per transaction

We’ll walk the site, not the slides.

This page is just the map. The story is already on the site — we’ll open it live and talk through it in order.

Most of what we’ll cover has a page. “What I learned” is the only stop that lives here — the rest are existing pages we’ll jump to.

Flow: present.html (here, 30s) → / → /custody → /architecture → back here for “what I learned” → Roadmap → Q&A.

What I learned — lives here

BIPs that actually run the wallet. BIP39/32/86 keys, 340/341/342 Schnorr/Taproot, 327 MuSig2, 370/371/373 PSBTv2, 387/388/390 descriptors, 157/158 filters, 125 RBF. Bitcoin is a BIP stack — Winnow just picks the modern ones.

Recovery has a defined scope. The import bundle supplies history for descriptor-derived coins; the phone verifies forward from its recorded height. Unsupported signing data is refused. Keep the original wallet and backup for any other coin types.

Most multisig is still legacy. Many wallets are still OP_CHECKMULTISIG/P2WSH/P2SH with ECDSA, coordinator servers, and mixed address types. The chain sees the policy, fees are larger, review is weaker. Nunchuk and Core are the exceptions — descriptor + PSBT + Taproot-aware, good covenant hygiene — they showed what modern actually looks like.

I changed my mind on custody. No pure model. Ladder: 1 key for spending, 2 independent makers that hide as one sig, 3 (2-of-3) for continuity — annoying wallets get emptied into worse ones, so use the smallest policy that fits the money.

Peer diversity is hard. 3 peers by default, headers retry on another peer, filters compared, blocks checked against headers — yet a fully eclipsed light client can still be shown one view. Usually you don’t care about privacy, but it’s good to be private by default and warn when you give it up to make things easier — manual peers / private Esplora are good for testing or if you already have one running for extra privacy, not an escape hatch.

Flow: this map → / → /custody → /architecture → back here for the five points above, then Roadmap.

Take the map with you

QR to winnowwallet.com/present

winnowwallet.com/present

Present map — links are existing pages; only “What I learned” lives here. Evidence · Source

04 · lives on this page — 7 points

What I learned

1 · The BIP stack

39 mnemonic / 32 HD / 86 Taproot derivation · 340/341/342 Schnorr/Taproot · 327 MuSig2 · 370/371/373 PSBTv2 · 387/388/390 descriptors · 157/158 compact filters · 125 RBF / 133 feefilter

2 · Recovery limits

A bundle carries the known coins, transaction history and last scanned height. The phone verifies forward; a recovery phrase alone is not a historical back-scan. Preserve the original wallet and backup for unsupported coin types.

3 · Why most multisig still feels old

Many wallets still ship OP_CHECKMULTISIG / P2WSH / P2SH + ECDSA, coordinator servers, and mixed address types — visible policy, larger witness, weaker review. Nunchuk and Core are the exceptions — descriptors, PSBT, Taproot, clean coordination — and they reset my bar for “good.”

4 · Custody: no pure model

I’m not using a pure model. 1 key for spending, 2 independent makers (one 64-byte sig, no policy leaked), 2-of-3 for continuity/loss/inheritance — the smallest policy that fits the money, because annoying wallets get emptied into worse ones.

5 · Peer diversity is hard

Default 3 peers, headers retry on another peer, filters compared, blocks checked against headers — yet eclipse remains real. Usually you don’t care about privacy, but it’s good to be private by default and warn when you give it up to make things easier — manual peers / private Esplora are good for testing or if you already have one running for extra privacy, not an escape hatch.

6 · Mempool sight is forward-only

Watching relay is private — public gossip, matched locally, indistinguishable from a full node. But peers announce a txid once: a payment already in the mempool before you opened the screen stays invisible until a block confirms it. BIP35 mempool would ask a peer for its pool, but Core gates it behind -whitelist=mempool@… — a permission only that node’s operator can grant, with no handshake to request it. So “is my payment pending?” has three answers: run your own node or Esplora, hand a third party your address, or wait for the block. My first real mainnet receive is what taught me that.

7 · A leaked key is gone in one block

I tested a mainnet receive with a wallet whose seed came from a fixed value in a shell command — so the key was, in effect, published. The coins were swept in the same block they arrived, the taker burning almost the entire amount as fee to win the race. Nothing failed: the wallet saw the payment and saw it spent, correctly, in seconds. That is the whole argument for the ladder in one event — one key is one point of failure, and there is no recovering from it. Two keys and a leaked one cannot spend alone. Also: a seed that touches a command line, a log, or a screen share is already someone else’s.

Received

a small test amount

one block

Sent

not by me

the same block

Illustration, not a screenshot. The sweeper spent nearly the whole amount on fee to win the race — it wanted the coins more than it wanted the value.

Then Roadmap (epic #60) → Q&A — paper, evidence, and source are one tap away.