Roadmap
What we want to make possible, and what must work before we call it ready.
These are planned milestones, not shipped features or promised dates. The wallet page describes current behavior. Early access is available while this work continues.
Now · A smaller, testable product
What you gain: the same supported wallet journeys with fewer alternate paths and clearer documentation.
Must pass: the real app creates a wallet, receives a payment, reviews and sends it, restores a backup, pays a person, and coordinates shared savings. Advanced features have their own documented journeys. Public feature descriptions and screenshots point to those tests.
Still to resolve: which boundaries, convenience APIs, duplicate tests, and undocumented features can be removed. Keep focused checks for cryptography, hostile inputs, and recovery failures that a successful screen flow cannot establish.
0.7 · An optional P2WSH Safe
What you gain: a separate, opt-in storage choice, explained under Advanced.
Must pass: create → receive → back up → restore on another installation → review and withdraw. The journey must exercise fresh change, exposure tracking, and refusal of damaged or incomplete backups.
Still to resolve: implementation and review of the Safe design and release criteria. Its limitations must be visible before funding. This milestone does not promise full post-quantum signing.
0.8 · Reliability through interruptions
What you gain: understandable recovery when the connection, app, or device interrupts a payment or sync.
Must pass: restart during sync, disconnect during sending, reopen a pending payment, increase its fee, restore a stale backup, switch networks, and recover after a chain reorganization. The screen, persisted wallet, and peer-observed transaction must agree.
Still to resolve: regressions found by those journeys and measured bandwidth, memory, and battery use on supported iPhones.
0.9 · A broader beta
What you gain: a defined feature set with usable recovery instructions and clearly stated limitations.
Must pass: new users complete everyday journeys and recovery using the published instructions. Feedback has a reproducible app scenario; critical regressions become tests of that scenario.
Still to resolve: the beta's supported devices, release blockers, and findings from broader use.
1.0 · A reviewed release
What you gain: a release whose review scope, evidence, and remaining limitations you can inspect.
Must pass: an independent security review, resolution of release-blocking findings, and verification of fixes against the intended release. Publish the exact reviewed revision and the journeys exercised.
Still to resolve: review findings and release readiness. A version target is not a security conclusion.
2.0 direction · Research
Potential user outcome: an explicit, opt-in migration path when future Bitcoin capabilities are ready.
Before this becomes a release plan: establish the relevant network rules, interoperability, recovery behavior, and a complete migration journey. Research and prototypes do not count as shipping support.
Open work: the P2MR investigation and other roadmap proposals. No deployment date or automatic upgrade is implied.