--- title: "Nuri | Free Banking, VISA Card, Bitcoin & Stablecoin Wallet." lang: "en" type: "landing-page" --- # Own and Manage Your Money Without a Bank. Nuri is a self-custodial Wallet for Euros, Dollars, Stablecoins and Bitcoin with free VISA card, IBAN & banking in 130 countries. ## Download - App Store: https://apps.apple.com/de/app/nuri-com/id6754772131 - Google Play: https://play.google.com/store/apps/details?id=com.nuri.mobileios ## A self-custodial wallet with VISA & IBAN. Self-custody as simple as Face-ID with your Passkey. No password. No recovery phrase. ## Buy and convert cash, crypto & bitcoin. Buy, hold and swap cash and crypto directly in your wallet. ## Pay and get paid in cash and crypto. Send and receive bank & crypto transfers from and to your wallet. ## Send and receive bank transfers from your wallet. Send and receive SEPA and USD ACH transfers, and send money to M-PESA and other mobile money networks. ## Get a free VISA card linked to your wallet. Virtual for Apple/Google pay or physical, withdraw or spend your cash worldwide. ## Pay worldwide. Pay online, in stores, with Apple Pay, Google Pay, payment ring, smartwatch, or Swatch Pay. ## Cash at ATMs. Withdraw cash worldwide with your physical Visa card. ## Private Bitcoin. Neo Bank. Your Keys, Your Coins. Many features work without ID verification. Nuri does not store user data. Nuri is not a bank. ## Help in the app. Get help directly in the app. Private chat with real people. ## Works with your AI in ChatGPT, Claude, Hermes & Co. Connect Nuri to ChatGPT, Claude, and more. Let AI analyse your spending, prepare payments, and pay for goods and services—with secure, permissioned access you control. ## FAQ ### Do I need ID to use Nuri? Not for the wallet itself. The passkey wallet starts without a heavy signup. Verification is for card access, IBAN, and local banking rails. ### Is Nuri custodial? The wallet layer is self-custodial. Nuri is designed to start with user ownership and only add local rails where they become practical. ### What does global cash and local spending mean in practice? You hold and move Bitcoin like open money. When real life still asks for a card, an IBAN, an ATM, or local transfers, Nuri unlocks those rails inside the same product. ### Why combine wallet, card, and IBAN in one flow? Because users should not have to juggle a crypto app, a banking app, and a payout tool just to move money. One account, two stages, clear utility. ### Why is Nuri so clearly Bitcoin-first? Because Bitcoin is the strongest open money network for self custody, permissionless access, and global portability. Card and IBAN solve everyday rails. Bitcoin is the actual foundation. --- --- title: "Nuri | Free Banking, VISA Card, Bitcoin & Stablecoin Wallet." lang: "de" type: "landing-page" --- # Sei deine eigene Bank. Eine App für Bitcoin, Stablecoins, Euro und Dollar – mit kostenloser Visa-Karte und Überweisungen. ## Download - App Store: https://apps.apple.com/de/app/nuri-com/id6754772131 - Google Play: https://play.google.com/store/apps/details?id=com.nuri.mobileios ## Besitze und verwalte dein Geld ohne Bank. Selbstverwahrung so einfach wie Face ID – mit deinem Passkey. Kein Passwort. Keine Wiederherstellungsphrase. ## Bitcoin, Euro und Dollar kaufen und tauschen. Kaufe Bitcoin mit Apple Pay oder Google Pay. Tausche Bitcoin und andere Kryptowährungen – darunter digitale Euro und Stablecoins – direkt in deiner Wallet. ## Euro, Dollar, Bitcoin und Stablecoins senden und empfangen. Sende und empfange Euro, Dollar, Bitcoin und Stablecoins direkt aus deiner Wallet. Schnell, einfach und ohne Bank. ## Per Banküberweisung, Krypto oder Mobile Money bezahlen und bezahlt werden. Verifiziere dich einmalig und erhalte deine eigene EU-IBAN, die direkt mit deiner Wallet verknüpft ist. Sende und empfange SEPA- und USD-ACH-Überweisungen und sende Geld an M-PESA und andere Mobile-Money-Netzwerke. ## Visa Karte für Bitcoin und Euro. Hol dir eine virtuelle oder physische Visa Karte. Lade sie mit Bitcoin, digitalen Euro oder Stablecoins auf. ## Weltweit bezahlen. Bezahle online, im Laden, mit Apple Pay, Google Pay, Bezahlring, Smartwatch oder Swatch Pay. ## Bargeld am Automaten. Heb mit deiner physischen Visa Karte weltweit Bargeld ab. ## Privates Bitcoin, ohne Bank. Deine Schlüssel, deine Coins. Viele Funktionen funktionieren ohne Ausweisprüfung. Nuri speichert keine Nutzerdaten. Nuri ist keine Bank. ## Hilfe in der App. Erhalte Hilfe direkt in der App. Privater Chat mit echten Menschen. ## Funktioniert mit deiner KI in ChatGPT, Claude, Hermes & Co. Verbinde Nuri mit ChatGPT, Claude und weiteren KI-Assistenten. Lass KI deine Ausgaben analysieren, Zahlungen vorbereiten und Waren und Dienstleistungen bezahlen – mit sicheren, von dir kontrollierten Berechtigungen. ## FAQ ### Brauche ich eine ID für Nuri? Nicht für die Wallet selbst. Die Passkey-Wallet startet ohne schwere Anmeldung. Verifizierung ist für Kartenzugang, IBAN und lokale Bank-Rails gedacht. ### Verwahrt Nuri mein Geld? Die Wallet liegt in deiner eigenen Verwahrung. Nuri ist so gebaut, dass Eigentum beim Nutzer startet und lokale Rails nur dort dazukommen, wo sie praktisch werden. ### Was bedeutet globales Cash und lokales Ausgeben konkret? Du hältst und bewegst Bitcoin wie offenes Geld. Wenn der Alltag nach Karte, IBAN, ATM oder lokalen Transfers verlangt, schaltet Nuri diese Rails im selben Produkt frei. ### Warum verbindet Nuri Wallet, Karte und IBAN in einem Flow? Weil Nutzer nicht zwischen Krypto-App, Banking-App und Auszahlungs-Tool springen sollten, nur um Geld zu bewegen. Ein Konto, zwei Stufen, klarer Nutzen. ### Warum ist Nuri so klar Bitcoin-first? Weil Bitcoin das stärkste offene Geldnetz für Selbstverwahrung, offenen Zugang und globale Tragfähigkeit ist. Karte und IBAN lösen die Alltags-Rails. Bitcoin ist die eigentliche Basis. --- --- title: "Nuri | Free Banking, VISA Card, Bitcoin & Stablecoin Wallet." lang: "es" type: "landing-page" --- # Sé tu propio banco. Una app para Bitcoin, stablecoins, euros y dólares, con una tarjeta Visa gratuita y transferencias bancarias. ## Download - App Store: https://apps.apple.com/de/app/nuri-com/id6754772131 - Google Play: https://play.google.com/store/apps/details?id=com.nuri.mobileios ## Sé dueño de tu dinero y gestiónalo sin un banco. Autocustodia tan sencilla como Face ID con tu passkey. Sin contraseña. Sin frase de recuperación. ## Compra e intercambia Bitcoin, euros y dólares. Compra Bitcoin con Apple Pay o Google Pay. Intercambia Bitcoin y otras criptomonedas —incluidos los euros digitales y las stablecoins— directamente en tu wallet. ## Envía y recibe euros, dólares, Bitcoin y stablecoins. Envía y recibe euros, dólares, Bitcoin y stablecoins directamente desde tu wallet. Rápido, fácil y sin banco. ## Paga y recibe pagos mediante transferencia bancaria, cripto o dinero móvil. Verifica tu identidad una sola vez para obtener tu propio IBAN europeo, vinculado directamente a tu wallet. Envía y recibe transferencias SEPA y ACH en dólares, y envía dinero a M-PESA y otras redes de dinero móvil. ## Tarjeta Visa para Bitcoin y euros. Obtén una tarjeta Visa virtual o física. Cárgala con Bitcoin, euros digitales o stablecoins. ## Paga en todo el mundo. Paga online, en tiendas, con Apple Pay, Google Pay, anillo de pago, smartwatch o Swatch Pay. ## Efectivo en cajeros. Retira efectivo en todo el mundo con tu tarjeta Visa física. ## Bitcoin privado y sin banco. Tus claves, tus monedas. Muchas funciones funcionan sin verificación de identidad. Nuri no almacena datos de usuario. Nuri no es un banco. ## Ayuda en la app. Recibe ayuda directamente en la app. Chat privado con personas reales. ## Funciona con tu IA en ChatGPT, Claude, Hermes y otros. Conecta Nuri con ChatGPT, Claude y otros asistentes. Permite que la IA analice tus gastos, prepare pagos y pague bienes y servicios, con permisos seguros que tú controlas. ## FAQ ### ¿Necesito ID para usar Nuri? No para la wallet. La wallet con passkey empieza sin registro pesado. La verificación es para tarjeta, IBAN y rails bancarios locales. ### ¿Nuri custodia mi dinero? La capa de wallet es de autocustodia. Nuri está diseñado para empezar con propiedad del usuario y añadir rails locales solo cuando son útiles. ### ¿Qué significa dinero global y gasto local en la práctica? Mantienes y mueves Bitcoin como dinero abierto. Cuando la vida diaria pide tarjeta, IBAN, cajero o transferencias locales, Nuri activa esos rails dentro del mismo producto. ### ¿Por qué juntar wallet, tarjeta e IBAN en un solo flujo? Porque los usuarios no deberían saltar entre una app cripto, una app bancaria y una herramienta de retiros solo para mover dinero. ### ¿Por qué Nuri es tan claramente Bitcoin-first? Porque Bitcoin es la red de dinero abierto más fuerte para autocustodia, acceso sin permisos y portabilidad global. Tarjeta e IBAN resuelven el uso diario. Bitcoin es la base real. --- --- title: "Nuri | Free Banking, VISA Card, Bitcoin & Stablecoin Wallet." lang: "it" type: "landing-page" --- # Sii la tua banca. Un’app per Bitcoin, stablecoin, euro e dollari, con una carta Visa gratuita e bonifici bancari. ## Download - App Store: https://apps.apple.com/de/app/nuri-com/id6754772131 - Google Play: https://play.google.com/store/apps/details?id=com.nuri.mobileios ## Possiedi e gestisci il tuo denaro senza una banca. Autocustodia semplice come Face ID con la tua passkey. Nessuna password. Nessuna frase di recupero. ## Compra e scambia Bitcoin, euro e dollari. Compra Bitcoin con Apple Pay o Google Pay. Scambia Bitcoin e altre criptovalute, inclusi euro digitali e stablecoin, direttamente nel tuo wallet. ## Invia e ricevi euro, dollari, Bitcoin e stablecoin. Invia e ricevi euro, dollari, Bitcoin e stablecoin direttamente dal tuo wallet. Veloce, semplice e senza banca. ## Paga e ricevi pagamenti tramite bonifico bancario, crypto o mobile money. Verifica la tua identità una sola volta per ottenere il tuo IBAN europeo, collegato direttamente al wallet. Invia e ricevi bonifici SEPA e trasferimenti ACH in dollari, e invia denaro a M-PESA e ad altre reti mobile money. ## Carta Visa per Bitcoin ed euro. Ottieni una carta Visa virtuale o fisica. Ricaricala con Bitcoin, euro digitali o stablecoin. ## Paga in tutto il mondo. Paga online, nei negozi, con Apple Pay, Google Pay, anello di pagamento, smartwatch o Swatch Pay. ## Contanti agli sportelli ATM. Preleva contanti in tutto il mondo con la tua carta Visa fisica. ## Bitcoin privato e senza banca. Le tue chiavi, le tue monete. Molte funzioni operano senza verifica dell’identità. Nuri non conserva i dati degli utenti. Nuri non è una banca. ## Assistenza nell'app. Ricevi assistenza direttamente nell'app. Chat privata con persone reali. ## Funziona con la tua AI in ChatGPT, Claude, Hermes e altri. Collega Nuri a ChatGPT, Claude e altri assistenti. Consenti all’AI di analizzare le tue spese, preparare pagamenti e pagare beni e servizi, con autorizzazioni sicure sotto il tuo controllo. ## FAQ ### Serve un documento per usare Nuri? Non per il wallet. Il wallet con passkey si apre senza una registrazione complessa. La verifica serve per carta, IBAN e servizi bancari locali. ### Nuri è custodial? Il wallet è in autocustodia. Nuri parte dalla proprietà dell’utente e aggiunge i servizi locali solo quando diventano utili. ### Cosa significa in pratica denaro globale e spesa locale? Conservi e trasferisci Bitcoin come denaro aperto. Quando la vita quotidiana richiede carta, IBAN, ATM o bonifici locali, Nuri li rende disponibili nello stesso prodotto. ### Perché unire wallet, carta e IBAN nello stesso flusso? Perché non dovresti dover gestire un’app crypto, un’app bancaria e uno strumento di pagamento separati. Un conto, due fasi, utilità chiara. ### Perché Nuri mette Bitcoin al primo posto? Perché Bitcoin è la più forte rete monetaria aperta per autocustodia, accesso senza permessi e portabilità globale. Carta e IBAN risolvono la spesa quotidiana. Bitcoin è la base. --- --- title: "Nuri | Free Banking, VISA Card, Bitcoin & Stablecoin Wallet." lang: "de" type: "landing-page" --- # Sei deine eigene Bank. Eine App für Bitcoin, Stablecoins, Euro und Dollar – mit kostenloser Visa-Karte und Überweisungen. ## Download - App Store: https://apps.apple.com/de/app/nuri-com/id6754772131 - Google Play: https://play.google.com/store/apps/details?id=com.nuri.mobileios ## Besitze und verwalte dein Geld ohne Bank. Selbstverwahrung so einfach wie Face ID – mit deinem Passkey. Kein Passwort. Keine Wiederherstellungsphrase. ## Bitcoin, Euro und Dollar kaufen und tauschen. Kaufe Bitcoin mit Apple Pay oder Google Pay. Tausche Bitcoin und andere Kryptowährungen – darunter digitale Euro und Stablecoins – direkt in deiner Wallet. ## Euro, Dollar, Bitcoin und Stablecoins senden und empfangen. Sende und empfange Euro, Dollar, Bitcoin und Stablecoins direkt aus deiner Wallet. Schnell, einfach und ohne Bank. ## Per Banküberweisung, Krypto oder Mobile Money bezahlen und bezahlt werden. Verifiziere dich einmalig und erhalte deine eigene EU-IBAN, die direkt mit deiner Wallet verknüpft ist. Sende und empfange SEPA- und USD-ACH-Überweisungen und sende Geld an M-PESA und andere Mobile-Money-Netzwerke. ## Visa Karte für Bitcoin und Euro. Hol dir eine virtuelle oder physische Visa Karte. Lade sie mit Bitcoin, digitalen Euro oder Stablecoins auf. ## Weltweit bezahlen. Bezahle online, im Laden, mit Apple Pay, Google Pay, Bezahlring, Smartwatch oder Swatch Pay. ## Bargeld am Automaten. Heb mit deiner physischen Visa Karte weltweit Bargeld ab. ## Privates Bitcoin, ohne Bank. Deine Schlüssel, deine Coins. Viele Funktionen funktionieren ohne Ausweisprüfung. Nuri speichert keine Nutzerdaten. Nuri ist keine Bank. ## Hilfe in der App. Erhalte Hilfe direkt in der App. Privater Chat mit echten Menschen. ## Funktioniert mit deiner KI in ChatGPT, Claude, Hermes & Co. Verbinde Nuri mit ChatGPT, Claude und weiteren KI-Assistenten. Lass KI deine Ausgaben analysieren, Zahlungen vorbereiten und Waren und Dienstleistungen bezahlen – mit sicheren, von dir kontrollierten Berechtigungen. ## FAQ ### Brauche ich eine ID für Nuri? Nicht für die Wallet selbst. Die Passkey-Wallet startet ohne schwere Anmeldung. Verifizierung ist für Kartenzugang, IBAN und lokale Bank-Rails gedacht. ### Verwahrt Nuri mein Geld? Die Wallet liegt in deiner eigenen Verwahrung. Nuri ist so gebaut, dass Eigentum beim Nutzer startet und lokale Rails nur dort dazukommen, wo sie praktisch werden. ### Was bedeutet globales Cash und lokales Ausgeben konkret? Du hältst und bewegst Bitcoin wie offenes Geld. Wenn der Alltag nach Karte, IBAN, ATM oder lokalen Transfers verlangt, schaltet Nuri diese Rails im selben Produkt frei. ### Warum verbindet Nuri Wallet, Karte und IBAN in einem Flow? Weil Nutzer nicht zwischen Krypto-App, Banking-App und Auszahlungs-Tool springen sollten, nur um Geld zu bewegen. Ein Konto, zwei Stufen, klarer Nutzen. ### Warum ist Nuri so klar Bitcoin-first? Weil Bitcoin das stärkste offene Geldnetz für Selbstverwahrung, offenen Zugang und globale Tragfähigkeit ist. Karte und IBAN lösen die Alltags-Rails. Bitcoin ist die eigentliche Basis. --- --- title: "Nuri | Free Banking, VISA Card, Bitcoin & Stablecoin Wallet." lang: "es" type: "landing-page" --- # Sé tu propio banco. Una app para Bitcoin, stablecoins, euros y dólares, con una tarjeta Visa gratuita y transferencias bancarias. ## Download - App Store: https://apps.apple.com/de/app/nuri-com/id6754772131 - Google Play: https://play.google.com/store/apps/details?id=com.nuri.mobileios ## Sé dueño de tu dinero y gestiónalo sin un banco. Autocustodia tan sencilla como Face ID con tu passkey. Sin contraseña. Sin frase de recuperación. ## Compra e intercambia Bitcoin, euros y dólares. Compra Bitcoin con Apple Pay o Google Pay. Intercambia Bitcoin y otras criptomonedas —incluidos los euros digitales y las stablecoins— directamente en tu wallet. ## Envía y recibe euros, dólares, Bitcoin y stablecoins. Envía y recibe euros, dólares, Bitcoin y stablecoins directamente desde tu wallet. Rápido, fácil y sin banco. ## Paga y recibe pagos mediante transferencia bancaria, cripto o dinero móvil. Verifica tu identidad una sola vez para obtener tu propio IBAN europeo, vinculado directamente a tu wallet. Envía y recibe transferencias SEPA y ACH en dólares, y envía dinero a M-PESA y otras redes de dinero móvil. ## Tarjeta Visa para Bitcoin y euros. Obtén una tarjeta Visa virtual o física. Cárgala con Bitcoin, euros digitales o stablecoins. ## Paga en todo el mundo. Paga online, en tiendas, con Apple Pay, Google Pay, anillo de pago, smartwatch o Swatch Pay. ## Efectivo en cajeros. Retira efectivo en todo el mundo con tu tarjeta Visa física. ## Bitcoin privado y sin banco. Tus claves, tus monedas. Muchas funciones funcionan sin verificación de identidad. Nuri no almacena datos de usuario. Nuri no es un banco. ## Ayuda en la app. Recibe ayuda directamente en la app. Chat privado con personas reales. ## Funciona con tu IA en ChatGPT, Claude, Hermes y otros. Conecta Nuri con ChatGPT, Claude y otros asistentes. Permite que la IA analice tus gastos, prepare pagos y pague bienes y servicios, con permisos seguros que tú controlas. ## FAQ ### ¿Necesito ID para usar Nuri? No para la wallet. La wallet con passkey empieza sin registro pesado. La verificación es para tarjeta, IBAN y rails bancarios locales. ### ¿Nuri custodia mi dinero? La capa de wallet es de autocustodia. Nuri está diseñado para empezar con propiedad del usuario y añadir rails locales solo cuando son útiles. ### ¿Qué significa dinero global y gasto local en la práctica? Mantienes y mueves Bitcoin como dinero abierto. Cuando la vida diaria pide tarjeta, IBAN, cajero o transferencias locales, Nuri activa esos rails dentro del mismo producto. ### ¿Por qué juntar wallet, tarjeta e IBAN en un solo flujo? Porque los usuarios no deberían saltar entre una app cripto, una app bancaria y una herramienta de retiros solo para mover dinero. ### ¿Por qué Nuri es tan claramente Bitcoin-first? Porque Bitcoin es la red de dinero abierto más fuerte para autocustodia, acceso sin permisos y portabilidad global. Tarjeta e IBAN resuelven el uso diario. Bitcoin es la base real. --- --- title: "Nuri | Free Banking, VISA Card, Bitcoin & Stablecoin Wallet." lang: "it" type: "landing-page" --- # Sii la tua banca. Un’app per Bitcoin, stablecoin, euro e dollari, con una carta Visa gratuita e bonifici bancari. ## Download - App Store: https://apps.apple.com/de/app/nuri-com/id6754772131 - Google Play: https://play.google.com/store/apps/details?id=com.nuri.mobileios ## Possiedi e gestisci il tuo denaro senza una banca. Autocustodia semplice come Face ID con la tua passkey. Nessuna password. Nessuna frase di recupero. ## Compra e scambia Bitcoin, euro e dollari. Compra Bitcoin con Apple Pay o Google Pay. Scambia Bitcoin e altre criptovalute, inclusi euro digitali e stablecoin, direttamente nel tuo wallet. ## Invia e ricevi euro, dollari, Bitcoin e stablecoin. Invia e ricevi euro, dollari, Bitcoin e stablecoin direttamente dal tuo wallet. Veloce, semplice e senza banca. ## Paga e ricevi pagamenti tramite bonifico bancario, crypto o mobile money. Verifica la tua identità una sola volta per ottenere il tuo IBAN europeo, collegato direttamente al wallet. Invia e ricevi bonifici SEPA e trasferimenti ACH in dollari, e invia denaro a M-PESA e ad altre reti mobile money. ## Carta Visa per Bitcoin ed euro. Ottieni una carta Visa virtuale o fisica. Ricaricala con Bitcoin, euro digitali o stablecoin. ## Paga in tutto il mondo. Paga online, nei negozi, con Apple Pay, Google Pay, anello di pagamento, smartwatch o Swatch Pay. ## Contanti agli sportelli ATM. Preleva contanti in tutto il mondo con la tua carta Visa fisica. ## Bitcoin privato e senza banca. Le tue chiavi, le tue monete. Molte funzioni operano senza verifica dell’identità. Nuri non conserva i dati degli utenti. Nuri non è una banca. ## Assistenza nell'app. Ricevi assistenza direttamente nell'app. Chat privata con persone reali. ## Funziona con la tua AI in ChatGPT, Claude, Hermes e altri. Collega Nuri a ChatGPT, Claude e altri assistenti. Consenti all’AI di analizzare le tue spese, preparare pagamenti e pagare beni e servizi, con autorizzazioni sicure sotto il tuo controllo. ## FAQ ### Serve un documento per usare Nuri? Non per il wallet. Il wallet con passkey si apre senza una registrazione complessa. La verifica serve per carta, IBAN e servizi bancari locali. ### Nuri è custodial? Il wallet è in autocustodia. Nuri parte dalla proprietà dell’utente e aggiunge i servizi locali solo quando diventano utili. ### Cosa significa in pratica denaro globale e spesa locale? Conservi e trasferisci Bitcoin come denaro aperto. Quando la vita quotidiana richiede carta, IBAN, ATM o bonifici locali, Nuri li rende disponibili nello stesso prodotto. ### Perché unire wallet, carta e IBAN nello stesso flusso? Perché non dovresti dover gestire un’app crypto, un’app bancaria e uno strumento di pagamento separati. Un conto, due fasi, utilità chiara. ### Perché Nuri mette Bitcoin al primo posto? Perché Bitcoin è la più forte rete monetaria aperta per autocustodia, accesso senza permessi e portabilità globale. Carta e IBAN risolvono la spesa quotidiana. Bitcoin è la base. --- --- title: "Nuri — the self-custodial money layer for people and AI agents" type: investor-briefing audience: "SM Capital" updated: 2026-07-22 canonical: https://nuri.com/invest --- # Nuri — the self-custodial money layer for people and AI agents Nuri combines a self-custodial wallet, replaceable regulated financial rails and live agentic-money infrastructure in one global product. ## Who is Emin? Emin is a hands-on technical founder who has built Bitcoin, Ethereum and wallet infrastructure since 2013. Today, he leads Nuri’s senior five-person team. - Built consumer products that reached hundreds of thousands of people and automation products used by thousands of businesses - Helped build æternity, which reached a €1.5 billion valuation - Former CPO of Börse Stuttgart Digital Exchange, responsible for BSDEX ## Why now? Natural’s $30M Series A validates the category. Nuri has already built most of the practical stack. Natural announced a $30M Series A on 20 July 2026 to build payments for AI agents. Approximately 80% of the practical agentic-money stack is already operational at Nuri, built largely by Emin using AI agents. This is a practical product-surface estimate, not a feature-for-feature audit. ## 01 — Easy onboarding Passkeys create a secure wallet in seconds. The live voice agent can guide onboarding and support conversationally. ## 02 — Independent of any one bank The self-custodial wallet is the durable customer relationship. IBAN, card, ACH and other regulated services are replaceable rails behind it. ## 03 — A human and agent wallet market Nuri targets 1% of an estimated 500 million-wallet opportunity: five million active human and AI-agent wallets within five years. ## 04 — Built with agents, for agents Approximately 80% of the practical agentic-money stack is operational. Agents can onboard, move money, remit, swap and support users through live services. ## Already live - [Nuri Connect](https://connect.nuri.com/mcp) — Passkey wallet, signing and wallet connection; 18 callable tools - [Banking](https://banking.nuri.com/mcp) — Wirex account, IBAN, ACH and card capabilities; 51 callable tools - [Monerium](https://monerium.nuri.com/mcp) — Additional IBAN and regulated euro rails; 27 callable tools - [Nuri Remit](https://remit.nuri.com/mcp) — ClickPesa mobile-money remittance; 5 callable tools - [SwapKit](https://swapkit.nuri.com/mcp) — Swaps and on/off-ramps across providers; 23 callable tools - Voice agent — Live for support, onboarding and conversational financial flows - [Nuri Solver](https://solver.nuri.com) — Live intent-based swap solver and liquidity service for the broader market Verified 2026-07-22: 124 callable tools across 5 MCP services. ## Funding plan - Runway: 12 months - Team: Existing five-person senior team - Infrastructure: AI infrastructure and usage credits - Next round: A milestone-driven institutional scaling round after active-wallet growth, transaction volume and revenue are proven - Existing five-person senior team - AI infrastructure and usage credits ## Five-year management case - Addressable opportunity: 500M new human and agent wallets - Target share: 1% - Active wallets: 5M - Monthly transaction volume per wallet: €500 - Annual transaction volume: €30B - Revenue take rate: 2% - Annual revenue: €600M Nuri becomes the global self-custodial money layer for people and AI agents—making onboarding, holding, exchanging, transferring and automating money as easy as using software, across borders and without dependence on a single bank. Five-year management objective, not current traction or a guarantee. €600M is projected annual revenue before operating costs, based on €30B annual transaction volume and a 2% take rate. ## Sources - [Natural — $30M Series A announcement](https://www.natural.com/blog/natural-series-a) - [Nuri live consumer product](https://nuri.com/) --- --- title: "About Nuri" lang: "en" type: "about-page" --- # About Nuri Nuri combines a passkey-based self-custodial crypto wallet with access to provider-operated card and banking services. ## Who runs Nuri Nuri is founded and run by Emin Mahrt and the Nuri team, and is operated by Nurisoft Development OÜ, Veskiposti tn 2-1002, 10138 Tallinn, Estonia. Nuri® is a registered trademark of Nurisoft Development OÜ. ## What we believe Your crypto keys should remain under your control. Nuri uses passkeys and co-signing in its wallet architecture. Security and recovery depend on the wallet and backup setup; this is not a blanket guarantee against server or device compromise. Read the [wallet recovery explanation](https://nuri.com/blog/how-nuri-wallets-survive-without-nuri) before choosing a backup method. Self-custody describes the crypto wallet, not a bank account or card balance. Card and banking services have separate provider terms and eligibility. Check the app and [Card & Bank support](https://nuri.com/card-support) for the relevant service. ## Built for humans and agents Nuri publishes OpenAPI, a read-only MCP server, llms.txt and an API catalog to read public content. These do not grant private account access. The postcard service has a separate paid fulfillment API. Start with [Nuri for developers](https://nuri.com/developers) or the [agent context index](https://nuri.com/llms.txt). - [Contact us](https://nuri.com/contact) - [Privacy Policy](https://nuri.com/privacy-policy) - [Terms of Service](https://nuri.com/terms-of-service) --- --- title: "Contact Nuri" lang: "en" type: "contact-page" --- # Contact Nuri For a card, account or bank question, start with Card & Bank support or the support options in the Nuri app. Public API and MCP tools read FAQs, not your account. ## App, card & bank support [Card & Bank support](https://nuri.com/card-support) covers declined payments, holds, refunds and chargebacks, limits, Apple Pay & Google Pay, and SEPA/ACH account guidance in the public FAQ. ## Email For general product, partnership and support questions, write to [support@nuri.com](mailto:support@nuri.com). ## Investors & press Read the [investor briefing](https://nuri.com/invest) for the company thesis and investment context. ## Registered office & legal Nuri is operated by Nurisoft Development OÜ, Veskiposti tn 2-1002, 10138 Tallinn, Estonia. Nuri® is a registered trademark of Nurisoft Development OÜ. No response-time guarantee is published here. Do not send private keys, recovery secrets or full card details by email. - [About Nuri](https://nuri.com/about) - [Developers](https://nuri.com/developers) - [Privacy Policy](https://nuri.com/privacy-policy) - [Terms of Service](https://nuri.com/terms-of-service) --- --- title: "Nuri for developers" description: "Read public Nuri content, connect a read-only MCP client, or integrate the separately paid postcard service. Start without an API key." lang: "en" type: "developer-documentation" canonical: "https://nuri.com/developers" --- # Nuri for developers Read public Nuri content, connect a read-only MCP client, or integrate the separately paid postcard service. Start without an API key. ## Start with a free public read The public website API, Markdown pages and MCP tools are free to read. No account, API key, wallet or payment is required. This quickstart does not create an account, move money or mail anything. The product feed returns JSON describing the published catalog. Its prices and payment metadata are not proof that an order has been placed. ```sh curl -fsS 'https://nuri.com/shop/feed.json' ``` - [Quickstart and API documentation](https://nuri.com/docs) - [OpenAPI specification](https://nuri.com/openapi.json) ## What you can build Compare Bitcoin hardware. Read GET /shop/feed.json, or call list_shop_products with {} and get_product with a slug returned by that list. These are catalog reads, not purchases. Answer a card or bank FAQ. Read GET /card-support/index.md, or call search_support_faq with {"query":"declined"}. Use get_support_answer with an id from the result for the full answer. These tools read public guidance, not a customer account or support ticket. Read Nuri guides and integration docs. Read GET /knowledge/index.md for the guide index and follow its links. Request a page with Accept: text/markdown, or call read_public_page_markdown with {"path":"/docs"} for this integration reference. Use tools/list to see the allowed paths. Prepare a postcard integration. Read GET /api/x402 for service details and follow the postcard reference. POST /api/x402/postcards/preview renders without mailing. POST /api/x402/postcards is a separate paid fulfillment endpoint and is not part of the read-only MCP server. - [Product feed](https://nuri.com/shop/feed.json) - [Card & Bank support](https://nuri.com/card-support) - [Knowledge guides](https://nuri.com/knowledge) - [Postcard API reference](https://nuri.com/docs/x402-username-marketplace) ## Standalone read-only CLI Download the standalone Node.js 22 CLI directly from Nuri. It needs no packages or API key and calls only the nine read-only public-site MCP tools. It cannot access accounts or send payments. Read the downloaded source before running it. This is not an npm package or wallet CLI. The first-party MCP manifest is not a claim of MCP registry registration. ```sh curl -fsS https://nuri.com/cli/nuri-site.mjs -o nuri-site.mjs node nuri-site.mjs list node nuri-site.mjs list_public_pages node nuri-site.mjs search_support_faq '{"query":"declined"}' ``` - [Download CLI source](https://nuri.com/cli/nuri-site.mjs) - [First-party MCP manifest](https://nuri.com/server.json) ## Connect your agent Add https://nuri.com/mcp as a remote Streamable HTTP MCP server in a compatible client. Use no authentication. The Node server is stateless and returns JSON responses; it does not issue an MCP session ID. Client configuration keys vary, so use the remote-server URL field rather than an unverified install command. Call tools/list to discover the nine public read-only tools. They cover page summaries, app links, product information and support FAQs. They cannot provision an IBAN, issue a card, access a balance, sign a transaction or submit a support ticket. - [MCP connection and request examples](https://nuri.com/docs#mcp) - [MCP server card](https://nuri.com/.well-known/mcp/server-card.json) ## Separate reads from real fulfillment Postcard preview is a no-mail provider operation, not a simulated payment sandbox. It sends the submitted image, message and recipient fields to thanks.io to render a preview. Use synthetic recipient details while evaluating it. Nuri does not require payment for the preview, but it depends on the configured provider and can fail or be unavailable. Paid postcard fulfillment uses real USDC and physical mail. Inspect the current service catalog and payment challenge, obtain explicit spending and mailing approval, then follow the postcard reference. Never retry a preview against the paid endpoint just because the preview failed. - [Authentication and access boundaries](https://nuri.com/docs#access) - [Versioning and deprecation](https://nuri.com/docs#versions) - [Existing postcard documentation](https://nuri.com/docs/x402-username-marketplace) --- --- title: "Nuri API and MCP documentation" description: "Working public-read examples, MCP setup, authentication boundaries, no-mail postcard preview and version compatibility for the Nuri website." lang: "en" type: "developer-documentation" canonical: "https://nuri.com/docs" --- # Nuri API and MCP documentation Working public-read examples, MCP setup, authentication boundaries, no-mail postcard preview and version compatibility for the Nuri website. ## Safe quickstart: no key and no payment Use curl for a JSON catalog or a Markdown support reference. These requests read public content only. A successful response is HTTP 200 with JSON or Markdown respectively; neither request modifies an account or places an order. ```sh curl -fsS 'https://nuri.com/shop/feed.json' curl -fsS 'https://nuri.com/card-support/index.md' curl -fsS -H 'Accept: text/markdown' 'https://nuri.com/developers' ``` - [Developer overview](https://nuri.com/developers) - [OpenAPI: request and response schemas](https://nuri.com/openapi.json) - [API discovery catalog](https://nuri.com/.well-known/api-catalog) ## Authentication, free access and boundaries Public website GET endpoints, Markdown and all public MCP tools require no authentication and no payment. Do not send a bearer token, private key, passkey material or customer information to read them. The optional anonymous /agent/auth discovery flow advertises public:read only. Its non-user-specific credential is not a customer session, a self-service API key or access to private banking. OAuth discovery on this website does not authorize private account actions. Balances, transactions, identity checks, bank-account provisioning, card actions and private support tickets are outside this public website API. Use the Nuri app and its support channels for account-specific requests. Banking and card services have separate provider terms and eligibility; a public MCP connection does not grant access. - [Public discovery auth reference](https://nuri.com/auth.md) - [Contact and account support](https://nuri.com/contact) ## MCP: connect and make a read-only call Endpoint: https://nuri.com/mcp. Transport: Streamable HTTP, JSON-RPC 2.0. Authentication: none. The Node transport is stateless, with JSON responses and no MCP session ID to retain. In an MCP-compatible client, add the endpoint as a remote HTTP server. The client should initialize, send notifications/initialized, list tools, then call a tool. The curl sequence below uses protocol 2025-11-05; initialization returns the negotiated protocolVersion. If a server negotiates another version, use that value in subsequent MCP-Protocol-Version headers. Expected results: initialize returns serverInfo and capabilities; the initialized notification returns HTTP 202 with no response body on the Node transport; tools/list returns nine read-only tool definitions; search_support_faq returns public answers with source links. JSON-RPC errors and tool isError values must be checked even when HTTP is 200. Tools: list_public_pages, get_site_summary, get_app_download_links, read_public_page_markdown, list_shop_products, get_product, list_support_topics, search_support_faq and get_support_answer. Use returned slugs and question IDs instead of guessing them. This server has no payment or fulfillment tool. ```sh curl -sS 'https://nuri.com/mcp' \ -H 'Content-Type: application/json' \ -H 'Accept: application/json, text/event-stream' \ --data '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-11-05","capabilities":{},"clientInfo":{"name":"nuri-docs-quickstart","version":"1.0.0"}}}' curl -sS 'https://nuri.com/mcp' \ -H 'Content-Type: application/json' \ -H 'Accept: application/json, text/event-stream' \ -H 'MCP-Protocol-Version: 2025-11-05' \ --data '{"jsonrpc":"2.0","method":"notifications/initialized"}' curl -sS 'https://nuri.com/mcp' \ -H 'Content-Type: application/json' \ -H 'Accept: application/json, text/event-stream' \ -H 'MCP-Protocol-Version: 2025-11-05' \ --data '{"jsonrpc":"2.0","id":2,"method":"tools/list","params":{}}' curl -sS 'https://nuri.com/mcp' \ -H 'Content-Type: application/json' \ -H 'Accept: application/json, text/event-stream' \ -H 'MCP-Protocol-Version: 2025-11-05' \ --data '{"jsonrpc":"2.0","id":3,"method":"tools/call","params":{"name":"search_support_faq","arguments":{"query":"declined"}}}' ``` - [MCP server card](https://nuri.com/.well-known/mcp/server-card.json) - [Source of support FAQ answers](https://nuri.com/card-support) ## Postcards: no-mail preview, paid real fulfillment GET /api/x402 lists the postcard service, schemas and payment terms. POST /api/x402/postcards/preview accepts the postcard request body documented in the reference and returns preview URLs without mailing a card. Nuri does not require payment for this preview. It still calls thanks.io and sends the submitted image, message and recipient details to that provider. Use synthetic details for evaluation. There is no public payment sandbox or test-account service documented here. A no-mail preview does not simulate settlement or delivery. Provider configuration and availability are required; a failed preview is not permission to invoke paid fulfillment. POST /api/x402/postcards is the separate real fulfillment route. An unpaid request creates an offer and returns HTTP 402 when the service is available. After explicit user approval, a payment-capable client retries the identical JSON with PAYMENT-SIGNATURE and the required payment-identifier. Payment verification can trigger physical mail and real USDC settlement. Consult the live challenge for supported networks, payout address and spending ceiling. Use GET /api/x402/orders/{publicOrderId} with the ID returned by your order to inspect privacy-safe status. Preserve the operation ID and payment identifier when retrying. Do not create a new operation to recover from an ambiguous payment or delivery result. The existing reference documents pricing, idempotency, cancellation and settlement_pending reconciliation. ```sh curl -fsS 'https://nuri.com/api/x402' ``` - [Postcard request, payment and fulfillment reference](https://nuri.com/docs/x402-username-marketplace) - [Current service catalog](https://nuri.com/api/x402) ## Versioning, compatibility and deprecation The existing public discovery API is version 1. Send X-Nuri-API-Version: 1 to pin this version, or omit it to use version 1. Other values return HTTP 400 with error: "unsupported_api_version", unless the shared quota is already exhausted (HTTP 429). This applies to GET and HEAD on /openapi.json, /shop/feed.json, /api, /api/x402 and /mcp, plus POST /mcp. It does not version private banking routes, payment protocols or the MCP protocol. Compatibility policy: preserve existing unversioned v1 public website surfaces. New optional fields may be added; clients should ignore unknown fields and read the current OpenAPI schemas. A future incompatible major version gets a separate path rather than silently changing the v1 contract. No successor path is currently published. Do not prepend /api/v1: that path is not a public website API alias. No public website API sunset is currently scheduled. Any future deprecation or sunset will be documented here and in OpenAPI with affected routes and migration guidance. No fixed notice period or deprecation SLA is promised. MCP protocol versions are negotiated at initialize; serverInfo.version and the OpenAPI document version are separate identifiers. When a deprecation is scheduled, the affected routes signal it machine-readably: responses carry an RFC 9745 Deprecation header and an RFC 8594 Sunset header, and the operation is marked deprecated: true in OpenAPI. Neither header is emitted today because no route is currently deprecated or scheduled for sunset. - [Current API contract](https://nuri.com/openapi.json) ## Errors and retries The discovery endpoints listed above share a limit of 600 requests per 60 seconds per runtime instance, across all clients. This is not a per-user or cluster-wide allowance; a restart resets it. Responses publish RateLimit-Policy and RateLimit with the remaining quota and reset interval. On exhaustion, HTTP 429 returns error: "rate_limited" and Retry-After in seconds. Quota-bearing responses are not cached. Website pages, paid postcard routes, order status and private account routes are outside this limiter. For HTTP errors, inspect the response body before retrying: 400 indicates invalid input, 402 is a payment challenge rather than a free trial, 404 means the route or item was not found, and 5xx may indicate unavailable infrastructure or a provider failure. Follow Retry-After if returned with 429; otherwise back off. No unlimited-access or uptime guarantee is made. Keep initial experiments to the GET and read-only MCP examples above. For paid calls, use the dedicated idempotency and reconciliation flow, not a generic automatic POST retry. Account support questions must go through the support page, not the public API. - [Paid-call reliability reference](https://nuri.com/docs/x402-username-marketplace) ## Standalone read-only CLI Download the standalone Node.js 22 CLI directly from Nuri. It needs no packages or API key and calls only the nine read-only public-site MCP tools. It cannot access accounts or send payments. Read the downloaded source before running it. This is not an npm package or wallet CLI. The first-party MCP manifest is not a claim of MCP registry registration. ```sh curl -fsS https://nuri.com/cli/nuri-site.mjs -o nuri-site.mjs node nuri-site.mjs list node nuri-site.mjs list_public_pages node nuri-site.mjs search_support_faq '{"query":"declined"}' ``` - [Download CLI source](https://nuri.com/cli/nuri-site.mjs) - [First-party MCP manifest](https://nuri.com/server.json) --- --- title: "Agent-ready x402 postcards on Nuri" description: "An agent supplies the postcard image, message and postal recipient. Nuri handles the seller, idempotency, x402 payment, and thanks.io fulfillment." type: api-documentation updated: 2026-08-29 --- # Agent-ready x402 postcards on Nuri An agent supplies the postcard image, message and postal recipient. Nuri handles the seller, idempotency, x402 payment, and thanks.io fulfillment. ## TL;DR - Point an agent to /api/x402; it discovers the postcard service and its complete schema. - The agent supplies only a public image URL, message and postal recipient. - Nuri automatically uses emino.nuri.eth as the service seller and creates the operation ID. - x402 settles the thanks.io cost plus 21%, then Nuri sends and tracks the 4x6 postcard. ## Endpoints - `GET /api/x402` — Service catalog, protocol metadata and schemas. - `GET /api/x402/resolve/{username}` — Resolve a Nuri username to its current ENS EVM address. - `POST /api/x402/postcards/preview` — Render a thanks.io preview. It never mails a card. - `POST /api/x402/postcards` — Create the x402 offer, verify payment, send one postcard and settle. - `GET /api/x402/orders/{publicOrderId}` — Read privacy-safe payment and delivery status. ## Request ```json { "front_image_url": "https://example.com/postcard.jpg", "message": "Hello from Nuri.", "handwriting_style_id": 4, "size": "4x6", "recipient": { "name": "Example Person", "address": "1 Main Street", "city": "Berlin", "province": "BE", "postal_code": "10115", "country": "DE" } } ``` ## Payment and fulfillment flow 1. **Prepare.** Validate image, message and postal recipient; choose the configured seller, resolve ENS, derive the operation ID and persist only the hash plus payout terms. 2. **Challenge.** Return HTTP 402 with x402 v2 USDC accepts on Base, Polygon and Arbitrum, scheme upto, the pinned payTo address, a $3.50 ceiling and required payment-identifier. 3. **Verify.** The buyer retries the identical JSON with PAYMENT-SIGNATURE. The facilitator verifies the signed maximum before fulfillment begins. 4. **Fulfill.** Submit exactly one 4x6 postcard to thanks.io. The response supplies authorization_total in cents. 5. **Settle.** Round authorization_total × 1.21 up to the next cent and settle only that USDC amount to the pinned seller address. 6. **Track.** Return a random public order ID. Status exposes delivery counts and transaction evidence, never the recipient address. ## Pricing The x402 endpoint uses v2 `upto` on Base, Polygon, or Arbitrum. The buyer authorizes at most **$3.50 USDC**. Nuri settles only: `ceil(thanks.io authorization_total × 1.21)` Example: thanks.io returns `252` cents. Nuri settles `305` cents, or `3,050,000` USDC atomic units, directly to the ENS-resolved seller address. ## Automatic seller resolution - Ordinary agents omit `seller`; this service defaults to `emino.nuri.eth`. - Advanced callers may supply an explicitly enabled seller, but it is not part of the normal purchase flow. - ENSIP-10/CCIP-read resolves the current Ethereum address. - The address is pinned when the 402 offer is created. - A later ENS change cannot redirect an existing operation. - Inspect resolution: https://nuri.com/api/x402/resolve/emino.nuri.eth ## Idempotency and failures Nuri derives `operation_id` deterministically from the normalized postcard request when the agent omits it; advanced callers may override it. An expired unpaid server-generated offer is safely replaced on the next identical call, while an expired explicit operation ID returns 410. The x402 payment-identifier remains required in the payment payload. A stored SHA-256 fingerprint binds the operation to the complete postcard request without persisting recipient PII. Process-local plus filesystem locks serialize the complete provider-send and settlement flow across overlapping deployment containers. Retries cannot send or settle twice. If hard settlement fails after thanks.io accepted the order, Nuri immediately requests cancellation. A broadcast-but-unconfirmed `settlement_pending` transaction is not canceled; it enters reconciliation with the transaction hash retained. ## Privacy Recipient details go to thanks.io for fulfillment but are not persisted in Nuri's order ledger. Public status exposes only the seller, payout address, provider order ID, charged amount, payment transaction, delivery counters and error counts. ## Current boundary - Agents do not need to know or submit a seller; emino.nuri.eth is configured for this postcard service. - A postal recipient address remains required because thanks.io must physically deliver the card. - Only the reviewed thanks-postcard-v1 adapter is active. - One recipient and 4x6 Standard Mail only; no mailing lists, radius search or arbitrary callbacks. - The receiving wallet supplies no private key. The address is a payment destination only. - This is a reusable payment and fulfillment seam, not an unmoderated arbitrary-offer marketplace. ## Machine-readable sources - Catalog: https://nuri.com/api/x402 - OpenAPI: https://nuri.com/openapi.json - Agentic commerce: https://nuri.com/.well-known/agentic-commerce.json - This document as Markdown: https://nuri.com/docs/x402-username-marketplace/index.md ## Discovery and market listing - Nuri catalog: /api/x402 lists active paid services and adapter boundaries. - Agent discovery: OpenAPI, llms.txt, Markdown negotiation and /.well-known/agentic-commerce.json expose the endpoint immediately. - Bazaar declaration: every 402 challenge includes a typed Bazaar body schema, service name and tags. - External market listing: a paying client must echo the Bazaar extension through a supporting facilitator; verify /discovery/resources before claiming listed. The Nuri-owned discovery surfaces are live. External Bazaar listing is not yet claimed because no funded client has echoed and settled the Bazaar extension through the facilitator. ## Add the next paid endpoint 1. Define one fulfillment adapter ID, one bounded input schema and one authoritative cost source. 2. Configure seller normalization and ENS resolution inside the adapter so ordinary buyers never enter a seller. 3. Choose exact for known prices or upto for metered prices, then bind operation ID, payment ID and request fingerprint. 4. Publish OpenAPI, llms, agentic-commerce and Bazaar input/output examples with descriptions for every field. 5. Prove zero side effects before payment, one side effect under concurrent retries, public status, then one funded canary and Bazaar lookup. --- --- title: "Nuri Privacy Policy" lang: "en" type: "legal-page" --- # Nuri Privacy Policy Canonical URL: https://nuri.com/privacy-policy This public legal page is available as HTML on the Nuri website. --- --- title: "Nuri Terms of Service" lang: "en" type: "legal-page" --- # Nuri Terms of Service Canonical URL: https://nuri.com/terms-of-service This public legal page is available as HTML on the Nuri website. --- --- title: "Nuri Bitcoin Shop" lang: "en" type: "shop-index" --- # Nuri Bitcoin Shop The agent-ready Bitcoin shop: hardware wallets, home miners, node kits, steel backups, books and gift cards. Every product is machine-readable and payable with Bitcoin, Lightning or the x402 agent-payment protocol. ## Categories - [Hardware Wallets](https://nuri.com/shop/hardware-wallets) — Cold storage signers, from $20 cards to air-gapped flagships (31 products) - [Home Miners](https://nuri.com/shop/miners) — Solo lottery miners and desktop heaters, from Bitaxe up (15 products) - [Node Kits](https://nuri.com/shop/node-hardware) — Run your own full node and verify, don’t trust (4 products) - [Steel Backups](https://nuri.com/shop/steel-backups) — Fireproof, waterproof seed-phrase storage (8 products) - [Accessories](https://nuri.com/shop/accessories) — Bearer sticks, Faraday bags and Bitcoin clocks (7 products) - [Payment Wearables](https://nuri.com/shop/wearables) — Tap-to-pay rings and bands for the spend side (7 products) - [Apparel](https://nuri.com/shop/apparel) — Wear the orange — soft tees, hoodies and caps (4 products) - [Books](https://nuri.com/shop/books) — The must-reads, from macro to code (17 products) - [Gift Cards](https://nuri.com/shop/gift-cards) — Orange-pill someone, or spend Bitcoin anywhere (3 products) ## Reviewed & recommended - [Ledger Nano X](https://nuri.com/shop/hardware-wallets/ledger-nano-x) — $149 - [Ledger Stax](https://nuri.com/shop/hardware-wallets/ledger-stax) — $399 - [Trezor Safe 5](https://nuri.com/shop/hardware-wallets/trezor-safe-5) — $169 - [BitBox02 Bitcoin-only](https://nuri.com/shop/hardware-wallets/bitbox02-bitcoin-only) — $99 - [Blockstream Jade Plus](https://nuri.com/shop/hardware-wallets/blockstream-jade-plus) — $149 - [Foundation Passport Core](https://nuri.com/shop/hardware-wallets/foundation-passport-core) — $199 - [Keystone 3 Pro](https://nuri.com/shop/hardware-wallets/keystone-3-pro) — $129 - [Bitaxe Gamma](https://nuri.com/shop/miners/bitaxe-gamma) — $175 approx - [FutureBit Apollo II](https://nuri.com/shop/miners/futurebit-apollo-ii) — $1,199 approx - [Umbrel Home](https://nuri.com/shop/node-hardware/umbrel-home) — $549 - [Cryptosteel Capsule Solo](https://nuri.com/shop/steel-backups/cryptosteel-capsule) — $53 approx - [Coinkite Blockclock Mini](https://nuri.com/shop/accessories/blockclock-mini) — $399 - [Opendime 3-Pack](https://nuri.com/shop/accessories/opendime-3pack) — $69 - [Broken Money — Lyn Alden](https://nuri.com/shop/books/book-broken-money) — $24 - [The Bitcoin Standard — Saifedean Ammous](https://nuri.com/shop/books/book-bitcoin-standard) — $24 approx - [Mastering Bitcoin (3rd ed.) — Antonopoulos & Harding](https://nuri.com/shop/books/book-mastering-bitcoin) — $50 approx - [Orange-Pill Gift Set](https://nuri.com/shop/gift-cards/nuri-orange-pill-set) — $129 bundle ## For agents - Product feed (JSON): https://nuri.com/shop/feed.json - Agentic commerce discovery: https://nuri.com/.well-known/agentic-commerce.json - x402 checkout: https://nuri.com/shop/checkout?sku=PRODUCT_SLUG --- --- title: "Hardware Wallets — Nuri Shop" lang: "en" type: "shop-category" --- # Hardware Wallets Dedicated devices that keep your private keys offline. We stock every wallet people actually search for — open-source and closed, USB and fully air-gapped, Bitcoin-only and multi-coin — with honest reviews of the trade-offs. ## Products - [Ledger Nano S Plus](https://nuri.com/shop/hardware-wallets/ledger-nano-s-plus) — $59 · Ledger Cheap USB-only entry wallet with broad coin support and a certified secure element. - [Ledger Nano X](https://nuri.com/shop/hardware-wallets/ledger-nano-x) — $149 · Ledger — reviewed 3.5/5 Bluetooth mobile wallet with huge coin support — convenient, but closed-source and controversial with purists. - [Ledger Flex](https://nuri.com/shop/hardware-wallets/ledger-flex) — $249 · Ledger E-Ink touchscreen mid-flagship — the Stax experience for less, still closed-source. - [Ledger Stax](https://nuri.com/shop/hardware-wallets/ledger-stax) — $399 · Ledger Premium curved E-Ink touchscreen designed by Tony Fadell. Gorgeous, expensive, and no more secure than a Nano. - [Trezor Safe 3](https://nuri.com/shop/hardware-wallets/trezor-safe-3) — $79 · Trezor Best-value Trezor: adds a secure element to the classic open-source design. - [Trezor Safe 5](https://nuri.com/shop/hardware-wallets/trezor-safe-5) — $169 · Trezor — reviewed 4.2/5 Color touchscreen, open-source, now with a secure element — polished UX with an honest security story. - [BitBox02 Bitcoin-only](https://nuri.com/shop/hardware-wallets/bitbox02-bitcoin-only) — $99 · BitBox (Shift Crypto) — reviewed 4.4/5 Minimal Swiss USB-C wallet with a reduced attack surface in its Bitcoin-only edition. - [BitBox02 Multi](https://nuri.com/shop/hardware-wallets/bitbox02-multi) — $109 · BitBox (Shift Crypto) Same Swiss device, multi-coin firmware — Bitcoin plus Ethereum and ERC-20s. - [Blockstream Jade](https://nuri.com/shop/hardware-wallets/blockstream-jade) — $65 approx · Blockstream The cheapest credible open-source signer — camera QR air-gap and an optional stateless mode. - [Blockstream Jade Plus](https://nuri.com/shop/hardware-wallets/blockstream-jade-plus) — $149 · Blockstream — reviewed 4.0/5 Premium aluminium Jade with a bigger screen, camera QR and SD — open-source with a blind-oracle design. - [Foundation Passport Core](https://nuri.com/shop/hardware-wallets/foundation-passport-core) — $199 · Foundation Devices — reviewed 4.4/5 Sleek Bitcoin-only air-gapped signer with a keypad and camera. Beautiful and open-source. - [Foundation Passport Prime](https://nuri.com/shop/hardware-wallets/foundation-passport-prime) — $299 from · Foundation Devices Broader device: Bitcoin plus 2FA, passkeys and encrypted files. Newer and less battle-tested. - [Keystone 3 Pro](https://nuri.com/shop/hardware-wallets/keystone-3-pro) — $129 · Keystone — reviewed 3.9/5 Big air-gapped QR touchscreen with a fingerprint sensor, three secure elements and open-source firmware. - [Tangem Wallet (3-card)](https://nuri.com/shop/hardware-wallets/tangem-wallet) — $69 approx · Tangem NFC smart-card wallet with no screen or battery — tap your phone to sign. Simple, but you trust the card. - [Cypherock X1](https://nuri.com/shop/hardware-wallets/cypherock-x1) — $199 approx · Cypherock Seedless design: your key is Shamir-split across a set of cards, so there’s no single seed to steal. - [Ellipal Titan 2.0](https://nuri.com/shop/hardware-wallets/ellipal-titan-2) — $169 approx · Ellipal Fully air-gapped sealed metal wallet, QR-only, tamper-resistant. Closed hardware, wide coin support. - [SafePal S1](https://nuri.com/shop/hardware-wallets/safepal-s1) — $50 approx · SafePal Very cheap air-gapped QR wallet backed by Binance Labs. Budget option with broad coin support. - [OneKey Pro](https://nuri.com/shop/hardware-wallets/onekey-pro) — $278 approx · OneKey Open-source touchscreen flagship with fingerprint, camera, NFC and air-gap modes. - [Bitkey](https://nuri.com/shop/hardware-wallets/bitkey) — $250 · Block, Inc. Seedless Bitcoin-only 2-of-3 multisig (phone + device + server recovery). Self-custody without a seed phrase. - [NGRAVE Zero](https://nuri.com/shop/hardware-wallets/ngrave-zero) — $398 from · NGRAVE EAL7-certified fully air-gapped premium wallet with biometrics — the most security-certified device on the market. - [SeedSigner (DIY kit)](https://nuri.com/shop/hardware-wallets/seedsigner) — $65 DIY, approx · Open-source community Stateless open-source DIY air-gap signer built from a Raspberry Pi Zero and a camera. Holds no keys at rest. - [Coinkite Tapsigner](https://nuri.com/shop/hardware-wallets/tapsigner) — $20 approx (sale) · Coinkite A tap-to-sign key sealed in a bank-card form factor. Slips into a wallet; pairs with mobile apps over NFC. - [OneKey Classic 1S](https://nuri.com/shop/hardware-wallets/onekey-classic-1s) — $99 approx · OneKey Affordable open-source wallet with a secure element and Bluetooth. A budget open-source daily driver. - [OneKey Classic 1S Pure](https://nuri.com/shop/hardware-wallets/onekey-classic-1s-pure) — $79 approx · OneKey The cheapest OneKey — an air-gapped variant with no wireless radios at all. - [SafePal S1 Pro](https://nuri.com/shop/hardware-wallets/safepal-s1-pro) — $90 approx · SafePal Upgraded air-gapped QR wallet with a better build and battery than the S1. - [SafePal X1](https://nuri.com/shop/hardware-wallets/safepal-x1) — $70 approx · SafePal Bluetooth SafePal, now open-source. Cheap and convenient, with a smaller trust story than an air-gap. - [D'CENT Biometric](https://nuri.com/shop/hardware-wallets/dcent-biometric) — $119 approx · D'CENT Mobile-first Bluetooth wallet with a fingerprint sensor. Convenient, with a fingerprint you trust the device to hold. - [Arculus](https://nuri.com/shop/hardware-wallets/arculus-wallet) — $99 approx · Arculus (CompoSecure) NFC metal card wallet with 3-factor tap-to-sign. Slick, but closed-source and app-dependent. - [GridPlus Lattice1](https://nuri.com/shop/hardware-wallets/gridplus-lattice1) — $397 approx · GridPlus Large always-on desktop wallet with swappable SafeCards. Powerful for DeFi/enterprise, overkill for most. - [Ellipal Titan Mini](https://nuri.com/shop/hardware-wallets/ellipal-titan-mini) — $89 approx · Ellipal Smaller, cheaper fully air-gapped Ellipal. QR-only, closed hardware, broad coin support. - [Krux (DIY signer)](https://nuri.com/shop/hardware-wallets/krux-diy) — $45 DIY, approx · Open-source community Open-source firmware that turns cheap K210 dev boards into an air-gapped QR signer. Maximal verifiability, DIY effort. --- --- title: "Home Miners — Nuri Shop" lang: "en" type: "shop-category" --- # Home Miners Small ASIC miners for the home. Be clear-eyed: against a ~980+ EH/s network these are lottery tickets, heaters and learning tools, not investments. We say so on every listing. ## Products - [Bitaxe Gamma](https://nuri.com/shop/miners/bitaxe-gamma) — $175 approx · Open-source (Solo Satoshi et al.) — reviewed 4.3/5 Palm-sized, silent open-source solo miner (~1.2 TH/s at ~15–21W). Best efficiency in the line — and a lottery ticket, honestly. - [Bitaxe Supra](https://nuri.com/shop/miners/bitaxe-supra) — $185 approx · Open-source Prior-generation single-chip Bitaxe (~0.6–0.8 TH/s). Only worth it if it’s cheaper than a Gamma. - [Bitaxe Gamma Turbo (GT)](https://nuri.com/shop/miners/bitaxe-gamma-turbo) — $350 approx · Open-source Dual-chip Bitaxe (~2.15 TH/s). More hash, more heat and power — still lottery economics. - [NerdQaxe++](https://nuri.com/shop/miners/nerdqaxe-plus-plus) — $550 approx · Open-source Quad-chip open-source solo miner (~4.8–6 TH/s at ~72–103W) in a desktop stand. - [Canaan Avalon Nano 3](https://nuri.com/shop/miners/avalon-nano-3) — $99 approx · Canaan The cheapest real ASIC home miner (~4 TH/s at 140W). Doubles as a small heater and USB warmer. - [Canaan Avalon Nano 3S](https://nuri.com/shop/miners/avalon-nano-3s) — $250 approx · Canaan Better-efficiency quiet desk miner (~6 TH/s at 140W, ~23 J/TH). - [Bitmain Antminer S21](https://nuri.com/shop/miners/antminer-s21) — $3,500 approx, market · Bitmain Current-gen efficiency workhorse (~200 TH/s at ~14 J/TH). Needs serious cooling and a strong circuit — loud. - [FutureBit Apollo II](https://nuri.com/shop/miners/futurebit-apollo-ii) — $1,199 approx · FutureBit — reviewed 4.0/5 Quiet desktop full node + solo miner in one box (~9–10 TH/s). The sovereignty-appliance pick. - [Heatbit Trio](https://nuri.com/shop/miners/heatbit-trio) — $849 approx · Heatbit Living-room heater and air purifier that also mines (~10 TH/s at 400W). The heat is the real product. - [Lucky Miner LV07](https://nuri.com/shop/miners/lucky-miner-lv07) — $179 approx · Lucky Miner Cheap pre-assembled Bitaxe-class single-ASIC solo miner (~1 TH/s at ~25W). - [Bitaxe Ultra](https://nuri.com/shop/miners/bitaxe-ultra) — $150 approx · Open-source Older single-chip Bitaxe (~0.5 TH/s), superseded by Supra and Gamma. Only for collectors or bargains. - [NerdMiner V2](https://nuri.com/shop/miners/nerdminer-v2) — $40 approx · Open-source An ESP32 educational lottery toy (~kilohash-class) with a display. Near-zero odds — pure novelty and learning. - [NerdOctaxe Gamma](https://nuri.com/shop/miners/nerdoctaxe-gamma) — $750 approx · Open-source Eight-chip open-source home solo miner (~9–12 TH/s). The most hash in the Nerd line — and louder for it. - [GekkoScience Compac F](https://nuri.com/shop/miners/gekkoscience-compac-f) — $90 approx · GekkoScience The best-known USB stick miner (~0.2–0.4 TH/s). Needs a powered hub; a hobby curiosity, not income. - [Bitmain Antminer S19 XP](https://nuri.com/shop/miners/antminer-s19-xp) — $1,200 approx, market · Bitmain Prior-gen workhorse (~140 TH/s at ~21 J/TH). The only S19 credible on home power — and still loud and hot. --- --- title: "Node Kits — Nuri Shop" lang: "en" type: "shop-category" --- # Node Kits Plug-and-play Bitcoin nodes. Verify your own transactions, run Lightning, and pair with a hardware wallet for full sovereignty. ## Products - [Umbrel Home](https://nuri.com/shop/node-hardware/umbrel-home) — $549 · Umbrel The simplest plug-and-play node with the widest app catalog and Tailscale remote access. - [Umbrel Pro](https://nuri.com/shop/node-hardware/umbrel-pro) — $699 · Umbrel Power-user node: up to 16TB, 2.5Gbps networking and WiFi 6. - [Start9 Server One](https://nuri.com/shop/node-hardware/start9-server-one) — $899 · Start9 Privacy-maximalist node on a fully auditable open-source OS with an 8-core Ryzen. - [myNode Model Two](https://nuri.com/shop/node-hardware/mynode-two) — $599 approx · myNode A Bitcoin-focused node that sits between Umbrel and Start9 in openness and polish. --- --- title: "Steel Backups — Nuri Shop" lang: "en" type: "shop-category" --- # Steel Backups Stamp or tile your recovery seed into stainless steel or titanium so a house fire or flood can’t take your coins with it. ## Products - [Cryptosteel Capsule Solo](https://nuri.com/shop/steel-backups/cryptosteel-capsule) — $53 approx · Cryptosteel — reviewed 3.9/5 The original stainless tile capsule, fireproof to ~1400°C. An independent brand — not a Ledger product. - [Blockplate (12/24)](https://nuri.com/shop/steel-backups/blockplate) — $35 approx (2-pack ~$69) · Blockplate One-punch marking on a single thick steel plate — the cheapest credible backup. - [Stamp Seed Kit](https://nuri.com/shop/steel-backups/stamp-seed-kit) — $100 approx · Stamp Seed Hand-stamp your seed into titanium or steel with a full punch kit. Maximum durability, more effort. - [Coinkite SEEDPLATE 24](https://nuri.com/shop/steel-backups/seedplate-24) — $50 approx · Coinkite Center-punch stainless steel plate for a 24-word BIP39 seed. - [Keystone Tablet Plus](https://nuri.com/shop/steel-backups/keystone-tablet-plus) — $50 approx · Keystone Slotted steel tiles that hold your seed under heat and deformation. - [Billfodl](https://nuri.com/shop/steel-backups/billfodl) — $60 approx · Billfodl Stainless steel tile backup, a long-standing Cryptosteel alternative. Waterproof, fireproof, tile-based. - [Tiny Seed (Titanium)](https://nuri.com/shop/steel-backups/tiny-seed) — $30 approx · Coinplate / various A credit-card-size stamped titanium backup that fits in a wallet. Minimal, durable, cheap. - [Coldbit Steel](https://nuri.com/shop/steel-backups/coldbit-steel) — $50 approx · Coldbit Minimalist stamped steel plates with a clean, no-frills design. --- --- title: "Accessories — Nuri Shop" lang: "en" type: "shop-category" --- # Accessories The extras that round out a self-custody setup — bearer USB sticks, signal-blocking bags, and glanceable Bitcoin displays. ## Products - [Coinkite Blockclock Mini](https://nuri.com/shop/accessories/blockclock-mini) — $399 · Coinkite — reviewed 3.2/5 Iconic eInk desk clock: price, block height, Moscow time and sats/dollar. A fun gift — but it needs Wi-Fi and a trusted price API. - [Coinkite Blockclock Micro](https://nuri.com/shop/accessories/blockclock-micro) — $175 approx · Coinkite Smaller sibling of the Mini — price, block height and sats/dollar in a compact display. - [Opendime 3-Pack](https://nuri.com/shop/accessories/opendime-3pack) — $69 · Coinkite Bearer USB Bitcoin sticks: load once, pass like a physical bill, snap to spend. Trust-minimised cash. - [Coinkite Satscard](https://nuri.com/shop/accessories/satscard) — $15 approx · Coinkite An Opendime-style reusable NFC bearer card — tap to check, slide to reveal. - [Mission Darkness Faraday Bag](https://nuri.com/shop/accessories/faraday-bag) — $30 from · MOS Equipment Signal-blocking bag that isolates phones, hardware wallets and keys from all wireless signals. - [USB Data Blocker](https://nuri.com/shop/accessories/usb-data-blocker) — $12 approx · PortaPow / various A "USB condom" that blocks data lines so you can charge a device without any data connection. - [SeedSigner Case](https://nuri.com/shop/accessories/seedsigner-case) — $20 approx · CryptoCloaks A 3D-printed enclosure for a DIY SeedSigner build. Tidy and protective for a bare-board signer. --- --- title: "Payment Wearables — Nuri Shop" lang: "en" type: "shop-category" --- # Payment Wearables Contactless payment wearables (rings, bands, fobs). These are NFC spend devices linked to a card — not Bitcoin key storage. We list them for the everyday-spend side of a Bitcoin life and label them honestly. ## Products - [Starmoon Gen2 Payment Ring](https://nuri.com/shop/wearables/starmoon-gen2-ring) — $250 approx · Starmoon Silver-alloy NFC tap-to-pay ring linked to a card. A spend device — not Bitcoin key storage. - [PAGO Payment Ring](https://nuri.com/shop/wearables/pago-ring) — $130 approx · PAGO NFC payment ring in several finishes. Contactless spend linked to a card. - [Ceramic Standard Payment Ring](https://nuri.com/shop/wearables/ceramic-standard-ring) — $100 approx · Curve line Lightweight ceramic NFC payment ring for everyday tap-to-pay. - [Kinetic Orbit Payment Ring](https://nuri.com/shop/wearables/kinetic-orbit-ring) — $65 approx · Kinetic Budget black NFC payment ring — the cheapest way into tap-to-pay wearables. - [Paycelet Payment Bracelet](https://nuri.com/shop/wearables/paycelet-bracelet) — $110 approx · Paycelet NFC payment bracelet with a rope band. Tap-to-pay on your wrist. - [Adornpay Payment Key Fob](https://nuri.com/shop/wearables/adornpay-keyfob) — $26 approx · Adornpay An NFC payment key fob linked to a card. Tap to pay from your keyring — a spend device, not key storage. - [Architect Payment Smartwatch](https://nuri.com/shop/wearables/architect-watch) — $130 approx · Architect An NFC payment smartwatch for contactless spending. A watch with tap-to-pay, not a Bitcoin device. --- --- title: "Apparel — Nuri Shop" lang: "en" type: "shop-category" --- # Apparel Bitcoin-native apparel and merch. Own-brand, comfortable, quietly orange-pilling. Pay with Bitcoin like everything else in the shop. ## Products - [Orange Pill Tee](https://nuri.com/shop/apparel/tee-bitcoin-orange) — $32 from · Nuri A soft heavyweight-cotton tee with a subtle Bitcoin mark. Quietly orange-pilling. - [Satoshi Hoodie](https://nuri.com/shop/apparel/hoodie-satoshi) — $58 from · Nuri A heavyweight hoodie for cold-storage weather. Understated, warm, brushed inside. - [21M Cap](https://nuri.com/shop/apparel/cap-21m) — $30 from · Nuri An embroidered "21M" cap — the supply cap you can wear. - [Stack Sats Socks](https://nuri.com/shop/apparel/socks-sats) — $16 from · Nuri Crew socks for stacking sats on your feet. Cushioned, low-key, orange-accented. --- --- title: "Books — Nuri Shop" lang: "en" type: "shop-category" --- # Books The Bitcoin canon — the economics, the history, the technology and the philosophy. Honest notes on what each book is good for and where it falls short. ## Products - [Broken Money — Lyn Alden](https://nuri.com/shop/books/book-broken-money) — $24 · Lyn Alden — reviewed 4.6/5 Why the money system is broken and how Bitcoin could fix it — the measured, data-driven macro case. Increasingly the top single recommendation. - [The Bitcoin Standard — Saifedean Ammous](https://nuri.com/shop/books/book-bitcoin-standard) — $24 approx · Saifedean Ammous — reviewed 3.4/5 The influential "sound money" case via monetary history. Persuasive, but heavily Austrian-biased and its stock-to-flow model aged badly. - [Mastering Bitcoin (3rd ed.) — Antonopoulos & Harding](https://nuri.com/shop/books/book-mastering-bitcoin) — $50 approx · A. Antonopoulos & D. Harding — reviewed 4.4/5 The technical bible: keys, transactions, scripts, mining, SegWit/Taproot/Lightning — with code. Free online, genuinely technical. - [The Internet of Money — Andreas Antonopoulos](https://nuri.com/shop/books/book-internet-of-money) — $16 approx · Andreas Antonopoulos Accessible essays on why Bitcoin matters, drawn from Andreas’ best talks. - [Programming Bitcoin — Jimmy Song](https://nuri.com/shop/books/book-programming-bitcoin) — $45 approx · Jimmy Song Build Bitcoin from scratch in Python — elliptic curves, transactions, scripts, blocks. - [Grokking Bitcoin — Kalle Rosenbaum](https://nuri.com/shop/books/book-grokking-bitcoin) — $45 approx (free online) · Kalle Rosenbaum A visual, illustrated deep-dive into how Bitcoin actually works. Free online. - [Layered Money — Nik Bhatia](https://nuri.com/shop/books/book-layered-money) — $18 approx · Nik Bhatia Money as historical "layers," from gold to Bitcoin and Lightning. Short and clarifying. - [The Blocksize War — Jonathan Bier](https://nuri.com/shop/books/book-blocksize-war) — $20 approx · Jonathan Bier The inside story of the 2015–17 scaling war — who controls Bitcoin’s rules, and why decentralization won. - [21 Lessons — Gigi](https://nuri.com/shop/books/book-21-lessons) — $18 approx (free online) · Der Gigi Philosophical reflections on what Bitcoin teaches about money, time and truth. Free online. - [Inventing Bitcoin — Yan Pritzker](https://nuri.com/shop/books/book-inventing-bitcoin) — $12 approx · Yan Pritzker A short, plain-English walk through how Bitcoin was invented, step by step. - [Check Your Financial Privilege — Alex Gladstein](https://nuri.com/shop/books/book-financial-privilege) — $18 approx · Alex Gladstein Bitcoin as a human-rights tool in authoritarian and inflationary economies. Reporting from the real world. - [Bitcoin Money: A Tale of Bitville — Michael Caras](https://nuri.com/shop/books/book-bitcoin-money-kids) — $18 approx · Michael Caras An illustrated kids’ story that explains sound money through a village that discovers Bitcoin. - [The Price of Tomorrow — Jeff Booth](https://nuri.com/shop/books/book-price-of-tomorrow) — $20 approx · Jeff Booth The deflationary case: why technology makes everything cheaper, and what that means for debt-based money. - [Gradually, Then Suddenly — Parker Lewis](https://nuri.com/shop/books/book-gradually-then-suddenly) — $22 approx · Parker Lewis A collected first-principles bull case for Bitcoin, essay by essay. Clear and methodical. - [The Genesis Book — Aaron van Wirdum](https://nuri.com/shop/books/book-genesis-book) — $22 approx · Aaron van Wirdum The pre-history of Bitcoin: the cypherpunks, digital-cash pioneers and ideas Satoshi assembled. - [Digital Gold — Nathaniel Popper](https://nuri.com/shop/books/book-digital-gold) — $18 approx · Nathaniel Popper The narrative history of Bitcoin’s early years — the people, drama and money. Journalistic, not technical. - [The Sovereign Individual — Davidson & Rees-Mogg](https://nuri.com/shop/books/book-sovereign-individual) — $20 approx · Davidson & Rees-Mogg A 1997 classic on the digital age and individual sovereignty. Prescient in parts, dated and contrarian in others. --- --- title: "Gift Cards — Nuri Shop" lang: "en" type: "shop-category" --- # Gift Cards Give Bitcoin, or spend it: non-custodial gift cards redeemable at thousands of brands, plus curated orange-pill gift sets. ## Products - [Bitrefill Gift Card](https://nuri.com/shop/gift-cards/bitrefill-gift-card) — any amount · Bitrefill Pay with Bitcoin or Lightning, get a redeemable code for 5,000+ brands. Non-custodial, no KYC. - [Orange-Pill Gift Set](https://nuri.com/shop/gift-cards/nuri-orange-pill-set) — $129 bundle · Nuri A curated starter gift: a must-read book, a steel backup plate and an Opendime bearer stick. The best way to orange-pill someone. - [Bitcoin Lightning Gift Card](https://nuri.com/shop/gift-cards/lightning-gift-card) — any amount · Nuri Gift actual Bitcoin over Lightning — instant, low-fee, redeemable into any Nuri wallet. --- --- title: "Nuri Blog" lang: "en" type: "blog-index" --- # Nuri Blog Product notes from the Nuri team and genuinely honest, multi-source reviews of Bitcoin hardware. ## Product notes - [Building Nuri for the days when something breaks](https://nuri.com/blog/building-nuri-for-the-days-when-something-breaks) — If one payment route stops working, the whole app should not feel broken. Here is what we learned and what we are changing. - [What Stripe's investor letter says about Nuri](https://nuri.com/blog/what-stripes-investor-letter-means-for-nuri) — Stripe just validated the agent economy. Nuri is taking the same future down an open, self-custodial and chain-agnostic path. - [The passkey that outlives the company](https://nuri.com/blog/how-nuri-wallets-survive-without-nuri) — What happens to your money when the wallet company is gone? Nuri is designed so the answer is: you still have it. Here is the architecture. ## Reviews - [Broken Money: The Best Money History Book, If You Can Sit Still](https://nuri.com/blog/broken-money-review) — 4.6/5. Lyn Alden's dense, engineering-first history of money is the most measured Bitcoin-adjacent book in print, but it is not light reading. - [The Bitcoin Standard: Genre-Defining, and Aging Unevenly](https://nuri.com/blog/bitcoin-standard-review) — 3.4/5. The book that made 'hard money' mainstream in Bitcoin is influential, quotable, and heavily biased, and its central scarcity model has not held up. - [Mastering Bitcoin: The Developer Bible That Isn't For Beginners](https://nuri.com/blog/mastering-bitcoin-review) — 4.4/5. The definitive technical reference to how Bitcoin actually works, free on GitHub, and genuinely hard going if you don't code. - [Blockclock Mini: A Beautiful $399 Number That Trusts a Server](https://nuri.com/blog/coinkite-blockclock-mini-review) — 3.2/5. Coinkite's eInk price-and-block display is a well-built object of desire, but it is a Wi-Fi novelty that leans on a trusted price API, not a trustless device. - [Cryptosteel Capsule: Fireproof and Fiddly, With One Real Weakness](https://nuri.com/blog/cryptosteel-capsule-review) — 3.9/5. The original stainless-steel seed capsule survives fire and water in independent testing, but the tile system is tedious and it's the one design that can fail if crushed. - [Bitaxe Gamma: The Honest Case for a $150 Lottery Miner](https://nuri.com/blog/bitaxe-gamma-review) — 4.3/5. A silent, open-source ASIC that mines almost no bitcoin in expected value — and is still one of the best gifts you can give a curious hodler. - [FutureBit Apollo II: A Great Node That Also Mines a Lottery](https://nuri.com/blog/futurebit-apollo-ii-review) — 4.0/5. One quiet desktop box runs a full Bitcoin node and mines solo — an appealing sovereignty appliance wrapped around miner economics that still don't add up. - [Blockstream Jade Plus: Fully Open, With a Security Model to Understand](https://nuri.com/blog/blockstream-jade-plus-review) — 4.0/5. A cheap, fully open-source signer with an excellent QR camera — built on a general-purpose ESP32 and a blind-oracle design you should understand before you trust it. - [Foundation Passport Core: The Air-Gap Purist's Beautiful Signer](https://nuri.com/blog/foundation-passport-core-review) — 4.4/5. No USB data, no radios, a phone-like keypad and fully open firmware — a genuinely air-gapped Bitcoin-only wallet that treats design as a feature. - [Ledger Nano X: Slick, Popular, and Still Asking for Trust](https://nuri.com/blog/ledger-nano-x-review) — 3.5/5. A polished, Bluetooth-enabled wallet from a company whose security promises have been tested more than once. - [Trezor Safe 5: Open Source Grows Up and Adds a Secure Chip](https://nuri.com/blog/trezor-safe-5-review) — 4.2/5. The first genuinely touch-friendly Trezor finally pairs open firmware with a real secure element — but it is no longer the top of the range. - [BitBox02 Bitcoin-only: Swiss, Open, and Refreshingly Boring](https://nuri.com/blog/bitbox02-bitcoin-only-review) — 4.4/5. A small, audited, fully open-source Bitcoin wallet that does the fundamentals right and asks little of you — if you can live with the tiny screen. - [Keystone 3 Pro: Big-Screen Air-Gapping With a Trust Asterisk](https://nuri.com/blog/keystone-3-pro-review) — 3.9/5. A slick, fully air-gapped QR wallet with three secure chips and a big touchscreen — whose openness and origins deserve a closer look. --- --- title: "Nuri Blog" lang: "de" type: "blog-index" --- # Nuri Blog Produktnotizen vom Nuri-Team und ehrliche Bitcoin-Testberichte mit nachvollziehbaren Quellen. ## Produktnotizen - [Nuri für die Tage bauen, an denen etwas kaputtgeht](https://nuri.com/de/blog/building-nuri-for-the-days-when-something-breaks) — Wenn ein Zahlungsweg ausfällt, sollte sich nicht gleich die ganze App kaputt anfühlen. Das haben wir gelernt – und das ändern wir jetzt. - [Was Stripes Investorenbrief über Nuri sagt](https://nuri.com/de/blog/what-stripes-investor-letter-means-for-nuri) — Stripe hat die Agentenökonomie bestätigt. Nuri verfolgt dieselbe Zukunft, aber offen, mit Selbstverwahrung und unabhängig von einzelnen Chains. - [Der Passkey, der das Unternehmen überlebt](https://nuri.com/de/blog/how-nuri-wallets-survive-without-nuri) — Was passiert mit deinem Geld, wenn die Wallet-Firma weg ist? Bei Nuri ist die Antwort: du hast es noch. Das ist die Architektur. ## Testberichte - [Broken Money: The Best Money History Book, If You Can Sit Still](https://nuri.com/de/blog/broken-money-review) — 4.6/5. Lyn Alden's dense, engineering-first history of money is the most measured Bitcoin-adjacent book in print, but it is not light reading. - [The Bitcoin Standard: Genre-Defining, and Aging Unevenly](https://nuri.com/de/blog/bitcoin-standard-review) — 3.4/5. The book that made 'hard money' mainstream in Bitcoin is influential, quotable, and heavily biased, and its central scarcity model has not held up. - [Mastering Bitcoin: The Developer Bible That Isn't For Beginners](https://nuri.com/de/blog/mastering-bitcoin-review) — 4.4/5. The definitive technical reference to how Bitcoin actually works, free on GitHub, and genuinely hard going if you don't code. - [Blockclock Mini: A Beautiful $399 Number That Trusts a Server](https://nuri.com/de/blog/coinkite-blockclock-mini-review) — 3.2/5. Coinkite's eInk price-and-block display is a well-built object of desire, but it is a Wi-Fi novelty that leans on a trusted price API, not a trustless device. - [Cryptosteel Capsule: Fireproof and Fiddly, With One Real Weakness](https://nuri.com/de/blog/cryptosteel-capsule-review) — 3.9/5. The original stainless-steel seed capsule survives fire and water in independent testing, but the tile system is tedious and it's the one design that can fail if crushed. - [Bitaxe Gamma: The Honest Case for a $150 Lottery Miner](https://nuri.com/de/blog/bitaxe-gamma-review) — 4.3/5. A silent, open-source ASIC that mines almost no bitcoin in expected value — and is still one of the best gifts you can give a curious hodler. - [FutureBit Apollo II: A Great Node That Also Mines a Lottery](https://nuri.com/de/blog/futurebit-apollo-ii-review) — 4.0/5. One quiet desktop box runs a full Bitcoin node and mines solo — an appealing sovereignty appliance wrapped around miner economics that still don't add up. - [Blockstream Jade Plus: Fully Open, With a Security Model to Understand](https://nuri.com/de/blog/blockstream-jade-plus-review) — 4.0/5. A cheap, fully open-source signer with an excellent QR camera — built on a general-purpose ESP32 and a blind-oracle design you should understand before you trust it. - [Foundation Passport Core: The Air-Gap Purist's Beautiful Signer](https://nuri.com/de/blog/foundation-passport-core-review) — 4.4/5. No USB data, no radios, a phone-like keypad and fully open firmware — a genuinely air-gapped Bitcoin-only wallet that treats design as a feature. - [Ledger Nano X: Slick, Popular, and Still Asking for Trust](https://nuri.com/de/blog/ledger-nano-x-review) — 3.5/5. A polished, Bluetooth-enabled wallet from a company whose security promises have been tested more than once. - [Trezor Safe 5: Open Source Grows Up and Adds a Secure Chip](https://nuri.com/de/blog/trezor-safe-5-review) — 4.2/5. The first genuinely touch-friendly Trezor finally pairs open firmware with a real secure element — but it is no longer the top of the range. - [BitBox02 Bitcoin-only: Swiss, Open, and Refreshingly Boring](https://nuri.com/de/blog/bitbox02-bitcoin-only-review) — 4.4/5. A small, audited, fully open-source Bitcoin wallet that does the fundamentals right and asks little of you — if you can live with the tiny screen. - [Keystone 3 Pro: Big-Screen Air-Gapping With a Trust Asterisk](https://nuri.com/de/blog/keystone-3-pro-review) — 3.9/5. A slick, fully air-gapped QR wallet with three secure chips and a big touchscreen — whose openness and origins deserve a closer look. --- --- title: "Nuri Blog" lang: "es" type: "blog-index" --- # Nuri Blog Notas de producto del equipo de Nuri y reseñas honestas de Bitcoin con fuentes verificables. ## Notas de producto - [Construir Nuri para los días en que algo falla](https://nuri.com/es/blog/building-nuri-for-the-days-when-something-breaks) — Si una vía de pago deja de funcionar, no debería parecer que toda la app está rota. Esto es lo que hemos aprendido y lo que vamos a cambiar. - [Qué dice de Nuri la carta a inversores de Stripe](https://nuri.com/es/blog/what-stripes-investor-letter-means-for-nuri) — Stripe acaba de validar la economía de los agentes. Nuri avanza hacia el mismo futuro por una vía abierta, autocustodial y agnóstica respecto a las cadenas. - [The passkey that outlives the company](https://nuri.com/es/blog/how-nuri-wallets-survive-without-nuri) — What happens to your money when the wallet company is gone? Nuri is designed so the answer is: you still have it. Here is the architecture. ## Reseñas - [Broken Money: The Best Money History Book, If You Can Sit Still](https://nuri.com/es/blog/broken-money-review) — 4.6/5. Lyn Alden's dense, engineering-first history of money is the most measured Bitcoin-adjacent book in print, but it is not light reading. - [The Bitcoin Standard: Genre-Defining, and Aging Unevenly](https://nuri.com/es/blog/bitcoin-standard-review) — 3.4/5. The book that made 'hard money' mainstream in Bitcoin is influential, quotable, and heavily biased, and its central scarcity model has not held up. - [Mastering Bitcoin: The Developer Bible That Isn't For Beginners](https://nuri.com/es/blog/mastering-bitcoin-review) — 4.4/5. The definitive technical reference to how Bitcoin actually works, free on GitHub, and genuinely hard going if you don't code. - [Blockclock Mini: A Beautiful $399 Number That Trusts a Server](https://nuri.com/es/blog/coinkite-blockclock-mini-review) — 3.2/5. Coinkite's eInk price-and-block display is a well-built object of desire, but it is a Wi-Fi novelty that leans on a trusted price API, not a trustless device. - [Cryptosteel Capsule: Fireproof and Fiddly, With One Real Weakness](https://nuri.com/es/blog/cryptosteel-capsule-review) — 3.9/5. The original stainless-steel seed capsule survives fire and water in independent testing, but the tile system is tedious and it's the one design that can fail if crushed. - [Bitaxe Gamma: The Honest Case for a $150 Lottery Miner](https://nuri.com/es/blog/bitaxe-gamma-review) — 4.3/5. A silent, open-source ASIC that mines almost no bitcoin in expected value — and is still one of the best gifts you can give a curious hodler. - [FutureBit Apollo II: A Great Node That Also Mines a Lottery](https://nuri.com/es/blog/futurebit-apollo-ii-review) — 4.0/5. One quiet desktop box runs a full Bitcoin node and mines solo — an appealing sovereignty appliance wrapped around miner economics that still don't add up. - [Blockstream Jade Plus: Fully Open, With a Security Model to Understand](https://nuri.com/es/blog/blockstream-jade-plus-review) — 4.0/5. A cheap, fully open-source signer with an excellent QR camera — built on a general-purpose ESP32 and a blind-oracle design you should understand before you trust it. - [Foundation Passport Core: The Air-Gap Purist's Beautiful Signer](https://nuri.com/es/blog/foundation-passport-core-review) — 4.4/5. No USB data, no radios, a phone-like keypad and fully open firmware — a genuinely air-gapped Bitcoin-only wallet that treats design as a feature. - [Ledger Nano X: Slick, Popular, and Still Asking for Trust](https://nuri.com/es/blog/ledger-nano-x-review) — 3.5/5. A polished, Bluetooth-enabled wallet from a company whose security promises have been tested more than once. - [Trezor Safe 5: Open Source Grows Up and Adds a Secure Chip](https://nuri.com/es/blog/trezor-safe-5-review) — 4.2/5. The first genuinely touch-friendly Trezor finally pairs open firmware with a real secure element — but it is no longer the top of the range. - [BitBox02 Bitcoin-only: Swiss, Open, and Refreshingly Boring](https://nuri.com/es/blog/bitbox02-bitcoin-only-review) — 4.4/5. A small, audited, fully open-source Bitcoin wallet that does the fundamentals right and asks little of you — if you can live with the tiny screen. - [Keystone 3 Pro: Big-Screen Air-Gapping With a Trust Asterisk](https://nuri.com/es/blog/keystone-3-pro-review) — 3.9/5. A slick, fully air-gapped QR wallet with three secure chips and a big touchscreen — whose openness and origins deserve a closer look. --- --- title: "Nuri Blog" lang: "it" type: "blog-index" --- # Nuri Blog Note sul prodotto dal team Nuri e recensioni oneste su Bitcoin con fonti verificabili. ## Note sul prodotto - [Costruire Nuri per i giorni in cui qualcosa si rompe](https://nuri.com/it/blog/building-nuri-for-the-days-when-something-breaks) — Se un canale di pagamento smette di funzionare, non dovrebbe sembrare che sia rotta tutta l'app. Ecco cosa abbiamo imparato e cosa stiamo cambiando. - [Cosa dice di Nuri la lettera agli investitori di Stripe](https://nuri.com/it/blog/what-stripes-investor-letter-means-for-nuri) — Stripe ha appena confermato l'economia degli agenti. Nuri segue la stessa direzione con un approccio aperto, in autocustodia e indipendente dalle chain. - [The passkey that outlives the company](https://nuri.com/it/blog/how-nuri-wallets-survive-without-nuri) — What happens to your money when the wallet company is gone? Nuri is designed so the answer is: you still have it. Here is the architecture. --- --- title: "Knowledge that makes money and Bitcoin less confusing" description: "Plain-language guides for people, builders and agents. Detailed enough to make a decision, readable without a technical background." lang: "en" type: "knowledge-index" canonical: "https://nuri.com/knowledge" --- # Knowledge that makes money and Bitcoin less confusing Plain-language guides for people, builders and agents. Detailed enough to make a decision, readable without a technical background. ## All knowledge guides - [Bitcoin RPC providers, explained without the jargon](https://nuri.com/knowledge/bitcoin-rpc-providers) — What a Bitcoin RPC provider does, who needs one, what each service costs, and when running your own node is worth it. - [The arrayref supply chain attack, and why your wallet needs no single point of failure](https://nuri.com/knowledge/supply-chain-attack-arrayref) — What the arrayref attack was, why supply chain attacks are accelerating, and how a wallet can be built so no single compromise exposes your keys. --- --- title: "Wissen, das Geld und Bitcoin verständlicher macht" description: "Verständliche Leitfäden für Menschen, Entwickler und Agents. Ausführlich genug für eine Entscheidung und auch ohne technischen Hintergrund gut lesbar." lang: "de" type: "knowledge-index" canonical: "https://nuri.com/de/wissen" --- # Wissen, das Geld und Bitcoin verständlicher macht Verständliche Leitfäden für Menschen, Entwickler und Agents. Ausführlich genug für eine Entscheidung und auch ohne technischen Hintergrund gut lesbar. ## Alle Wissensleitfäden - [Bitcoin-RPC-Anbieter, verständlich und ohne Fachjargon erklärt](https://nuri.com/de/wissen/bitcoin-rpc-anbieter) — Was ein Bitcoin-RPC-Anbieter tut, wer einen braucht, was die einzelnen Dienste kosten und wann sich eine eigene Node lohnt. - [Der arrayref-Supply-Chain-Angriff, und warum deine Wallet keine einzelne Angriffsfläche braucht](https://nuri.com/de/wissen/arrayref-supply-chain-angriff) — Was der arrayref-Angriff war, warum Supply-Chain-Angriffe schneller werden, und wie eine Wallet so gebaut sein kann, dass kein einziger Kompromittierung deine Schlüssel freilegt. --- --- title: "Conocimiento para entender mejor el dinero y Bitcoin" description: "Guías claras para personas, desarrolladores y agentes. Con suficiente detalle para tomar una decisión y comprensibles sin conocimientos técnicos." lang: "es" type: "knowledge-index" canonical: "https://nuri.com/es/conocimiento" --- # Conocimiento para entender mejor el dinero y Bitcoin Guías claras para personas, desarrolladores y agentes. Con suficiente detalle para tomar una decisión y comprensibles sin conocimientos técnicos. ## Todas las guías de conocimiento - [Proveedores RPC de Bitcoin, explicados sin tecnicismos](https://nuri.com/es/conocimiento/proveedores-rpc-bitcoin) — Qué hace un proveedor RPC de Bitcoin, quién necesita uno, cuánto cuesta cada servicio y cuándo vale la pena operar tu propio nodo. - [El ataque a la cadena de suministro de arrayref, y por qué tu wallet no necesita un punto único de fallo](https://nuri.com/es/conocimiento/ataque-de-cadena-de-suministro-arrayref) — Qué fue el ataque a arrayref, por qué los ataques a la cadena de suministro se aceleran y cómo se puede construir una wallet para que ninguna sola brecha exponga tus claves. --- --- title: "Conoscenze per capire meglio il denaro e Bitcoin" description: "Guide chiare per persone, sviluppatori e agenti. Abbastanza dettagliate per prendere una decisione e leggibili anche senza conoscenze tecniche." lang: "it" type: "knowledge-index" canonical: "https://nuri.com/it/conoscenza" --- # Conoscenze per capire meglio il denaro e Bitcoin Guide chiare per persone, sviluppatori e agenti. Abbastanza dettagliate per prendere una decisione e leggibili anche senza conoscenze tecniche. ## Tutte le guide - [Provider RPC per Bitcoin, spiegati senza gergo tecnico](https://nuri.com/it/conoscenza/provider-rpc-bitcoin) — Che cosa fa un provider RPC per Bitcoin, chi ne ha bisogno, quanto costa ogni servizio e quando conviene gestire un nodo proprio. - [L'attacco alla supply chain di arrayref, e perché il tuo wallet non ha bisogno di un singolo punto di guasto](https://nuri.com/it/conoscenza/attacco-a-arrayref-nella-cadena-di-fornitura) — Cosa è stato l'attacco a arrayref, perché gli attacchi alla supply chain accelerano, e come costruire un wallet in cui nessuna singola breach espone le tue chiavi. --- --- title: "Bitcoin RPC providers, explained without the jargon" description: "Compare Bitcoin RPC providers, understand hosted nodes and self-hosting, and choose the simplest option for your app without getting lost in jargon." lang: "en" type: "knowledge-guide" datePublished: "2026-08-21" dateModified: "2026-08-21" canonical: "https://nuri.com/knowledge/bitcoin-rpc-providers" tags: ["Bitcoin RPC provider","Bitcoin node provider","Bitcoin JSON-RPC","hosted Bitcoin node","Bitcoin full node","Bitcoin API","Bitcoin infrastructure"] --- # Bitcoin RPC providers, explained without the jargon **TL;DR:** A Bitcoin RPC provider lets an app read Bitcoin data and send transactions without maintaining its own Bitcoin node. Hosted services are easier to start with. Your own node gives you more privacy, control and access. Many serious products use both. If you only use a wallet such as Nuri, you do not need to choose an RPC provider at all. ## Contents - [The quick answer](#quick-answer) - [What RPC means in normal language](#what-rpc-means) - [Do you even need an RPC provider?](#do-you-need-one) - [Provider comparison](#comparison) - [What each option is good at](#provider-notes) - [Why method coverage matters](#method-coverage) - [Running your own Bitcoin node](#run-your-own-node) - [Privacy, trust and the part pricing tables miss](#privacy-and-trust) - [A decision guide that takes five minutes](#how-to-choose) - [The small glossary](#glossary) - [Questions people ask](#faq) ## The quick answer **Basically,** An RPC provider is a remote control for a Bitcoin node. Your app asks questions or sends a transaction. The provider runs the machinery. A Bitcoin app needs a reliable way to see what is happening on the Bitcoin network. It may need to check whether a payment arrived, read a transaction, estimate a suitable fee or send a signed transaction. A Bitcoin node can answer those requests. Running that node yourself takes storage, bandwidth, maintenance and time. A hosted Bitcoin RPC provider runs the node for you and gives your app an internet address to talk to. RPC means remote procedure call. The name sounds more complicated than the job. The convenience has a cost. The provider can see your requests, apply limits, change prices or go offline. A node you run yourself gives you more privacy and control, but you become responsible for keeping it healthy. There is no universal winner because the right choice depends on what you are building. ## What RPC means in normal language **Basically,** Your app sends a precise question to a Bitcoin node and gets a precise answer back. That request and response is the RPC. Think of a Bitcoin node as a library that keeps a verified copy of Bitcoin history and follows the network as new blocks arrive. RPC is the service desk. Your app does not walk through the whole library. It asks for one specific thing. A request might mean: give me block 900,000, tell me whether this transaction is known, show me the current fee estimate, or broadcast this already signed transaction. Bitcoin Core, the most widely used node software, exposes roughly 150 commands for jobs like these. The provider does not normally hold your bitcoin merely because you use its RPC endpoint. Good wallet architecture signs transactions with the user's keys before sending them to the node. Still, queries can reveal useful information about the wallet, such as addresses it is watching. That makes privacy part of the provider decision. - Read blockchain data: blocks, transactions and confirmations. - Inspect the mempool: transactions waiting to be confirmed. - Estimate fees: a practical guess for timely confirmation. - Broadcast a signed transaction: pass it to the Bitcoin network. ## Do you even need an RPC provider? **Basically,** Wallet users usually need nothing. App builders often do. Privacy-sensitive or infrastructure-heavy teams may want their own node. If you use Nuri or another consumer wallet, the answer is usually no. The wallet handles its own connection to Bitcoin. You do not need an account with QuickNode, Chainstack or any other infrastructure company. If you are building an app that reads or sends Bitcoin transactions, you need access to a node somehow. A hosted provider is the fastest way to start. You receive an endpoint and an API key, then your app can make requests within the plan limits. If you run a wallet backend, monitor many addresses, need every Bitcoin Core command or do not want another company to observe your requests, your own node becomes more attractive. Serious systems often use a self-hosted node first and keep a hosted endpoint as a fallback. - Using a Bitcoin wallet: probably no provider decision at all. - Building a prototype: start with a free hosted plan. - Running a production payment service: compare uptime, limits, privacy and fallback options. - Building privacy-sensitive wallet infrastructure: run your own node or design a careful hybrid. ## Provider comparison **Basically,** The free numbers use different units, so the largest-looking allowance is not always the largest. Compare the work you need rather than the headline number. The table below is a mid-2026 snapshot based on public information collected by Spark. Plans change. Treat it as a map of the market, then confirm the current price and limits on the provider website before committing. Credits, compute units, request units and raw requests are not directly equal. Some providers charge several units for one Bitcoin call. Historical or archive queries may cost more. Free tiers can also restrict speed even when the monthly allowance looks generous. | Option | Best for | Free start | Paid from | Free speed | Uptime | Signet | | --- | --- | --- | --- | --- | --- | --- | | QuickNode | Fast setup and add-ons | 10M credits/month | $49/month | 15/sec | 99.99% | No | | GetBlock | Low-cost entry | 50K compute units/day | about $23/month | 20/sec | 99% shared | No | | Chainstack | Broad RPC coverage | 3M request units/month | $49/month | 25/sec | 99.9% | Yes | | Alchemy | Teams already using Alchemy | 30M compute units/month | $0.45/M units | 25/sec | 99.99% | Yes | | Blockdaemon | Institutional compliance | 3M compute units/month | Contact sales | 5/sec | 99.9% | No | | NOWNodes | Simple request pricing | 100K requests, one-month trial | €20/month | 15/sec | 99.95% | No | | Blockstream Esplora | Free read-only lookups | about 500K requests/month | Custom | about 50/sec | 99.9% | Yes | | Your own Bitcoin Core node | Privacy and full control | Unlimited calls | $20–80/month VPS or home hardware | Hardware decides | You manage it | Yes | - QuickNode Bitcoin calls can consume multiple credits. - Alchemy lists 30M compute units, roughly 3M Bitcoin calls when each call costs 10 units. - Esplora is a REST API, not a full Bitcoin Core JSON-RPC endpoint. - An uptime percentage does not describe support quality, regional latency or how quickly a provider fixes an incident. ## What each option is good at **Basically,** Pick for your real workload. Chainstack covers many standard commands. Esplora is simple for read-only data. Your own node wins on control. Provider pages tend to lead with very large numbers. Those numbers matter less than whether the service exposes the commands your app needs, returns historical data, supports your test network and lets you grow without a surprise bill. ### QuickNode _A polished start and optional data add-ons._ QuickNode is a large multi-chain provider with Bitcoin mainnet and Testnet4. Its hosted nodes keep full historical data, so an app can look up old blocks and transactions. The useful difference is its add-on catalogue. Blockbook methods can make address balances, UTXOs and extended public keys easier to query. Ordinals and Runes APIs are separate extras. That can save work when raw Bitcoin Core commands are not enough. **Watch for:** Credits are not the same as calls, add-ons cost extra, and Bitcoin WebSocket support is not offered. ### GetBlock _A cheaper hosted entry point with several billing styles._ GetBlock documents a smaller set of Bitcoin commands than Bitcoin Core itself, but it covers the common jobs: blockchain data, the mempool, raw transactions, fee estimates and PSBT workflows. Its flat-rate Limitless Node can be easier to budget for predictable traffic. Dedicated nodes cost much more but remove shared limits. Regions include Frankfurt, New York and Singapore. **Watch for:** The shared-node uptime promise is 99%, and wallet commands are not available on shared infrastructure. ### Chainstack _Broad standard RPC coverage and signet support._ Chainstack documents 139 Bitcoin JSON-RPC methods, the broadest coverage in this comparison. Its shared Bitcoin nodes keep full history and enable the transaction index, which makes old transactions queryable. It also supports signet, a predictable Bitcoin test network. Wallet-related commands still require a dedicated node, so broad coverage does not mean every command is available on the normal shared plan. **Watch for:** Archive-style requests can use more request units, and the 99.9% service-credit promise is tied to enterprise terms. ### Alchemy _Teams already using Alchemy for Ethereum or other chains._ Alchemy brings Bitcoin into a platform many developers already use. It covers the common read, mempool, broadcast and fee jobs, and it supports mainnet, Testnet3, Testnet4 and signet. The free allowance looks much larger because it is shown in compute units. Spark estimates about 3 million Bitcoin calls when each method costs 10 units. Archive data is included. **Watch for:** The Bitcoin method set is smaller than Chainstack, wallet methods are absent, and WebSocket support is not documented. ### Blockdaemon _Institutions that need compliance evidence and dedicated support._ Blockdaemon targets institutional buyers and lists ISO 27001 and SOC 2 Type II certifications. It exposes standard Bitcoin methods plus proprietary helpers for balances, UTXOs and transaction history by address. This is less attractive for a weekend prototype because public pricing is limited and the free speed is low. It makes more sense when procurement, compliance and support commitments are part of the decision. **Watch for:** Paid pricing requires a sales conversation, signet is not listed, and Bitcoin WebSocket support is absent. ### NOWNodes _People who prefer simple request counts and a low published starting price._ NOWNodes counts requests instead of inventing another unit name. Archive access is included, and paid plans include WebSocket access through the provider's wider indexing setup. The entry price is lower than many competitors, but the free plan is a one-month trial rather than a permanent free tier. Dedicated Bitcoin nodes are a separate, much more expensive product. **Watch for:** The free allowance expires, signet is not available, and dedicated hosting starts far above the shared plans. ### Blockstream Esplora _Simple, read-only Bitcoin data without a full RPC service._ Esplora is different from every other hosted option here. It is an open-source REST API for blocks, transactions, addresses, UTXOs, mempool data and fee estimates. You can use Blockstream's public service or host the software yourself. For an app that only checks balances and transactions, that simpler interface may be enough. It does not expose the full Bitcoin Core command set, wallet controls or mining commands. **Watch for:** It is not a drop-in JSON-RPC replacement. Check broadcast and rate-limit requirements for your workload. ## Why method coverage matters **Basically,** Every provider handles basic reads and transaction broadcast. Wallet control and node administration are usually blocked on shared services. Bitcoin Core exposes many commands because a full node can do much more than look up a transaction. It can manage wallets, create partially signed transactions, inspect peers, change node settings and support mining work. A shared provider cannot safely hand every customer that level of control. Most apps need a small common set: read a block, read a transaction, inspect the mempool, estimate a fee and broadcast a signed transaction. If that is your workload, almost every option in the table can work. If you need wallet commands or unusual indexing, read the method list before you write the integration. | Capability | Bitcoin Core | Most hosted plans | Why it matters | | --- | --- | --- | --- | | Blocks and confirmations | Yes | Yes | Know whether and when a payment settled. | | Raw transactions | Yes | Usually | Read or submit transaction data. | | Fee estimates | Yes | Yes | Avoid paying far too much or waiting too long. | | Mempool inspection | Yes | Usually | Understand transactions still waiting. | | PSBT tools | Yes | Varies | Coordinate signing without exposing private keys. | | Wallet methods | Yes | Usually no | Create addresses and manage a node wallet. | | Node administration | Yes | No | Control peers, indexes and node settings. | | Address history helpers | Needs an indexer | Sometimes an add-on | Bitcoin Core does not provide every wallet-friendly lookup by default. | ## Running your own Bitcoin node **Basically,** You trade a provider bill for hardware, bandwidth and responsibility. In return, you choose the rules, keep queries private and remove rate limits. Self-hosting is the strongest option for privacy and control. Your requests stay with your infrastructure, you decide which Bitcoin Core version to run, and you can use the full command set without an API key or per-request bill. The operational work is real. A full node needs roughly 1 TB of SSD space for comfortable headroom. The source snapshot estimates about 745 GB of blockchain data in mid-2026, growing by roughly 70 to 80 GB per year. Initial synchronization can take two to seven days on modern hardware. A pruned node validates the entire chain but discards old block files. It can run with far less storage, sometimes around 10 GB for block data, but it cannot answer every historical transaction request and cannot run a full transaction index. Pruning is excellent when you need independent verification but not a complete public archive. At home, a mini PC or Raspberry Pi 5 with an external SSD may cost roughly $200 to $400 upfront. A budget VPS can cost around $20 to $50 per month; larger cloud platforms can cost far more, especially when bandwidth and storage are billed separately. These figures move with hardware and hosting prices. - Choose a full node when you need complete history or txindex. - Choose a pruned node when verification matters more than old block access. - Keep a hosted fallback if downtime would stop your product. - Monitor disk growth, sync status, backups and software updates. ## Privacy, trust and the part pricing tables miss **Basically,** The endpoint sees what you ask. Repeated address and transaction lookups can reveal how a wallet is used, even when the provider never sees the private key. A remote node learns the timing and content of your requests. If your app asks about the same addresses repeatedly, the provider may be able to group those requests. If it connects them to your account, API key or network address, it can learn more than a simple pricing table suggests. Using several public providers does not automatically fix this. It may spread the same information across more companies. Privacy-aware wallet software can use techniques such as compact block filters, private network routes or a user-selected node, but each design has tradeoffs. Trust also means correctness and availability. A provider can return stale data, throttle requests or have an outage. Your app should check errors, reject impossible responses and avoid treating one endpoint as unquestionable truth. For a payment product, a second independent source can help distinguish a provider incident from a Bitcoin network event. ## A decision guide that takes five minutes **Basically,** List the exact jobs, traffic and privacy needs first. Then eliminate providers that cannot meet them. Price comes after fit. Start with the smallest honest description of your app. "We need Bitcoin data" is too vague. "We check 20,000 addresses every hour, read old transactions, estimate fees and broadcast signed transactions" is useful. That sentence tells you whether you need an address index, archive history and what rate limit may hurt. 1. **Write down the commands or outcomes you need.** If you do not know the command names yet, describe the user action: check a payment, show transaction history, estimate a fee, broadcast a signed transaction or manage a server-side wallet. 2. **Estimate normal traffic and peak traffic.** Monthly allowances do not help if a short traffic spike hits a per-second limit. Include retries, background sync and growth. 3. **Decide what the provider is allowed to learn.** Address monitoring and wallet queries deserve more care than a public block-height widget. 4. **Test failure before production.** Remove the endpoint, trigger a rate limit and return stale data in a test environment. Your app should fail clearly and recover cleanly. 5. **Keep an exit path.** Use standard Bitcoin Core calls where possible, isolate provider-specific add-ons and know how long switching endpoints would take. ## The small glossary **Basically,** You only need a handful of terms to understand most provider pages. **Bitcoin node:** Software that verifies Bitcoin rules and shares blocks and transactions with the network. **Bitcoin Core:** The most widely used Bitcoin node software. It includes the standard JSON-RPC interface. **RPC:** A structured way for one program to ask another program to perform a task or return data. **JSON-RPC:** The message format Bitcoin Core uses for RPC requests and replies. **Mempool:** Transactions a node knows about that have not yet been included in a block. **UTXO:** A piece of bitcoin that can be spent. Wallet balances are built from one or more UTXOs. **Archive or unpruned node:** A node that keeps old block data and can answer historical requests. **Pruned node:** A node that validates everything but removes old block files to save storage. **txindex:** An optional Bitcoin Core index that makes any historical transaction easier to look up. **Testnet:** A public Bitcoin network for testing with coins that have no intended monetary value. **Signet:** A more controlled Bitcoin test network with steadier block production. **Regtest:** A private local Bitcoin test network where a developer creates blocks on demand. **RPS:** Requests per second, a speed limit on how many calls you can make. **SLA:** A service-level agreement, usually a written uptime promise with specific conditions. ## Questions people ask **Basically,** Hosted RPC is easiest. Your own node is most independent. A hybrid is common when both uptime and control matter. ### What is a Bitcoin RPC provider? It is a company that runs Bitcoin nodes and lets your app talk to them over the internet. Your app can read blocks and transactions, estimate fees and usually broadcast signed transactions without maintaining a node itself. ### Which Bitcoin RPC provider has the best free tier? For broad JSON-RPC use in the mid-2026 snapshot, Chainstack and Alchemy each translate to roughly 3 million basic monthly calls, but their units are different. Blockstream Esplora is attractive for free read-only REST lookups. The best free tier is the one that includes your required method, network and peak request rate. ### Do I need to run my own Bitcoin node? Run one when query privacy, full command access or independence from a provider matters enough to justify maintenance. A hosted endpoint is usually enough for prototypes and simple public-data apps. Many production systems use their own node plus a hosted fallback. ### Can an RPC provider steal my bitcoin? Using a read and broadcast endpoint should not reveal your private keys. Your wallet should sign transactions locally. A provider can still observe requests, return bad data or affect availability, so wallet design must validate responses and keep keys outside the RPC service. ### What is the difference between a Bitcoin API and Bitcoin RPC? Bitcoin RPC usually means commands shaped like Bitcoin Core. A Bitcoin API may offer simpler REST endpoints, address history or indexed data that Bitcoin Core does not provide directly. Esplora is a good example of an API that is useful but not a full JSON-RPC replacement. ### What is the difference between a full node and a pruned node? Both validate Bitcoin. A full node keeps old block files, while a pruned node deletes most of them after validation to save space. A pruned node cannot answer every historical-data request and cannot keep a complete transaction index. ### How much does it cost to run a Bitcoin full node? The source snapshot estimates about $20 to $80 per month on common VPS setups, depending on storage and bandwidth. Home hardware may cost roughly $200 to $400 upfront. Large cloud platforms can cost much more. Prices change, so size the current hardware and traffic before buying. ### Which providers support Bitcoin signet? The mid-2026 comparison lists Chainstack, Alchemy and Blockstream Esplora with signet support. A self-hosted Bitcoin Core node supports signet too. Confirm current network availability before choosing a plan. ### Does Bitcoin Core support WebSocket? Not natively. Bitcoin Core uses ZeroMQ for push notifications. Providers advertising Bitcoin WebSocket usually add another indexing or event layer rather than exposing Bitcoin Core WebSocket support. ### What should a production setup use? A common design uses a self-hosted node as the primary source and a hosted provider as an independent fallback. Smaller products can begin with two hosted endpoints. The important part is testing failover instead of assuming it works. ## Sources and update note Pricing, limits, network support and method lists change. The comparison figures are a mid-2026 snapshot from the linked Spark overview. Check the provider's current documentation before making an infrastructure decision. 1. [Spark: Bitcoin RPC Providers Overview](https://www.spark.money/tools/bitcoin-rpc-provider-comparison) 2. [Bitcoin Core documentation](https://bitcoincore.org/en/doc/) 3. [QuickNode](https://www.quicknode.com/) 4. [GetBlock](https://getblock.io/) 5. [Chainstack](https://chainstack.com/) 6. [Alchemy](https://www.alchemy.com/) 7. [Blockdaemon](https://www.blockdaemon.com/) 8. [NOWNodes](https://nownodes.io/) 9. [Blockstream Esplora API](https://blockstream.info/api/) ## Also available in - [Bitcoin-RPC-Anbieter, verständlich und ohne Fachjargon erklärt](https://nuri.com/de/wissen/bitcoin-rpc-anbieter) (de) - [Proveedores RPC de Bitcoin, explicados sin tecnicismos](https://nuri.com/es/conocimiento/proveedores-rpc-bitcoin) (es) - [Provider RPC per Bitcoin, spiegati senza gergo tecnico](https://nuri.com/it/conoscenza/provider-rpc-bitcoin) (it) --- --- title: "Bitcoin-RPC-Anbieter, verständlich und ohne Fachjargon erklärt" description: "Vergleiche Bitcoin-RPC-Anbieter, verstehe gehostete Nodes und Eigenbetrieb und finde die einfachste Lösung für deine App, ohne Fachjargon." lang: "de" type: "knowledge-guide" datePublished: "2026-08-21" dateModified: "2026-08-21" canonical: "https://nuri.com/de/wissen/bitcoin-rpc-anbieter" tags: ["Bitcoin-RPC-Anbieter","Bitcoin-Node-Anbieter","Bitcoin JSON-RPC","gehostete Bitcoin-Node","Bitcoin-Full-Node","Bitcoin-API","Bitcoin-Infrastruktur"] --- # Bitcoin-RPC-Anbieter, verständlich und ohne Fachjargon erklärt **TL;DR:** Ein Bitcoin-RPC-Anbieter ermöglicht einer App, Bitcoin-Daten zu lesen und Transaktionen zu senden, ohne eine eigene Bitcoin-Node zu betreiben. Mit gehosteten Diensten gelingt der Einstieg leichter. Eine eigene Node bietet mehr Privatsphäre, Kontrolle und Zugriffsmöglichkeiten. Viele professionelle Produkte nutzen beides. Wenn du nur eine Wallet wie Nuri verwendest, musst du überhaupt keinen RPC-Anbieter auswählen. ## Inhalt - [Die kurze Antwort](#quick-answer) - [Was RPC in normaler Sprache bedeutet](#what-rpc-means) - [Brauchst du überhaupt einen RPC-Anbieter?](#do-you-need-one) - [Anbietervergleich](#comparison) - [Wofür die einzelnen Optionen wirklich gut sind](#provider-notes) - [Warum die Methodenabdeckung wichtig ist](#method-coverage) - [Eine eigene Bitcoin-Node betreiben](#run-your-own-node) - [Privatsphäre, Vertrauen und was Preistabellen übersehen](#privacy-and-trust) - [Ein Entscheidungsleitfaden in fünf Minuten](#how-to-choose) - [Das kleine Glossar](#glossary) - [Fragen, die Menschen wirklich stellen](#faq) ## Die kurze Antwort **Kurz gesagt:** Ein RPC-Anbieter ist wie eine Fernbedienung für eine Bitcoin-Node. Deine App stellt Fragen oder sendet eine Transaktion. Der Anbieter betreibt die Technik dahinter. Eine Bitcoin-App braucht einen verlässlichen Weg, um zu sehen, was im Bitcoin-Netzwerk passiert. Sie muss vielleicht prüfen, ob eine Zahlung eingegangen ist, eine Transaktion lesen, eine passende Gebühr schätzen oder eine signierte Transaktion senden. Eine Bitcoin-Node kann diese Anfragen beantworten. Eine solche Node selbst zu betreiben, kostet Speicherplatz, Bandbreite, Wartung und Zeit. Ein gehosteter Bitcoin-RPC-Anbieter betreibt die Node für dich und gibt deiner App eine Internetadresse, über die sie mit ihr kommunizieren kann. RPC steht für Remote Procedure Call. Der Name klingt komplizierter als die Aufgabe. Diese Bequemlichkeit hat ihren Preis. Der Anbieter kann deine Anfragen sehen, Limits festlegen, Preise ändern oder ausfallen. Eine selbst betriebene Node bietet mehr Privatsphäre und Kontrolle, aber du bist dafür verantwortlich, dass sie zuverlässig läuft. Es gibt keinen universellen Sieger, denn die richtige Wahl hängt davon ab, was du entwickelst. ## Was RPC in normaler Sprache bedeutet **Kurz gesagt:** Deine App stellt einer Bitcoin-Node eine präzise Frage und erhält eine präzise Antwort. Diese Anfrage und Antwort ist der RPC. Stell dir eine Bitcoin-Node wie eine Bibliothek vor, die eine geprüfte Kopie der Bitcoin-Historie aufbewahrt und dem Netzwerk folgt, sobald neue Blöcke eintreffen. RPC ist der Serviceschalter. Deine App läuft nicht durch die ganze Bibliothek, sondern fragt nach einer ganz bestimmten Information. Eine Anfrage könnte lauten: Gib mir Block 900.000, sag mir, ob diese Transaktion bekannt ist, zeig mir die aktuelle Gebührenschätzung oder verbreite diese bereits signierte Transaktion. Bitcoin Core, die am weitesten verbreitete Node-Software, stellt für solche Aufgaben ungefähr 150 Befehle bereit. Nur weil du den RPC-Endpunkt eines Anbieters nutzt, verwahrt dieser normalerweise nicht deine Bitcoin. Bei einer guten Wallet-Architektur werden Transaktionen mit den Schlüsseln des Nutzers signiert, bevor sie an die Node gesendet werden. Anfragen können trotzdem nützliche Informationen über die Wallet preisgeben, etwa welche Adressen sie beobachtet. Deshalb gehört Privatsphäre zur Anbieterentscheidung. - Blockchain-Daten lesen: Blöcke, Transaktionen und Bestätigungen. - Den Mempool prüfen: Transaktionen, die auf ihre Bestätigung warten. - Gebühren schätzen: eine praktische Einschätzung für eine zeitnahe Bestätigung. - Eine signierte Transaktion verbreiten: sie an das Bitcoin-Netzwerk weitergeben. ## Brauchst du überhaupt einen RPC-Anbieter? **Kurz gesagt:** Wallet-Nutzer brauchen normalerweise nichts weiter. App-Entwickler dagegen oft schon. Teams mit hohen Anforderungen an Privatsphäre oder Infrastruktur können eine eigene Node bevorzugen. Wenn du Nuri oder eine andere Wallet für Endkunden nutzt, lautet die Antwort meist nein. Die Wallet kümmert sich selbst um ihre Verbindung zu Bitcoin. Du brauchst kein Konto bei QuickNode, Chainstack oder einem anderen Infrastrukturunternehmen. Wenn du eine App entwickelst, die Bitcoin-Transaktionen liest oder sendet, brauchst du auf irgendeine Weise Zugriff auf eine Node. Ein gehosteter Anbieter ist der schnellste Einstieg. Du erhältst einen Endpunkt und einen API-Schlüssel. Danach kann deine App innerhalb der Tariflimits Anfragen stellen. Wenn du das Backend einer Wallet betreibst, viele Adressen überwachst, jeden Bitcoin-Core-Befehl brauchst oder nicht möchtest, dass ein anderes Unternehmen deine Anfragen sieht, wird eine eigene Node attraktiver. Professionelle Systeme nutzen oft zuerst eine selbst gehostete Node und halten einen gehosteten Endpunkt als Reserve bereit. - Eine Bitcoin-Wallet nutzen: wahrscheinlich ist gar keine Anbieterentscheidung nötig. - Einen Prototyp entwickeln: mit einem kostenlosen gehosteten Tarif beginnen. - Einen produktiven Zahlungsdienst betreiben: Verfügbarkeit, Limits, Privatsphäre und Ausweichmöglichkeiten vergleichen. - Wallet-Infrastruktur mit hohen Datenschutzanforderungen entwickeln: eine eigene Node betreiben oder eine sorgfältige Hybridlösung entwerfen. ## Anbietervergleich **Kurz gesagt:** Die kostenlosen Kontingente verwenden unterschiedliche Einheiten. Deshalb ist das scheinbar größte Angebot nicht immer das umfangreichste. Vergleiche die benötigte Leistung, nicht nur die auffälligste Zahl. Die folgende Tabelle zeigt den Stand von Mitte 2026 und beruht auf öffentlich zugänglichen Informationen, die Spark gesammelt hat. Tarife ändern sich. Nutze sie als Marktübersicht und prüfe dann vor einer Entscheidung die aktuellen Preise und Limits auf der Website des Anbieters. Credits, Compute Units, Request Units und einfache Anfragen sind nicht direkt gleichwertig. Manche Anbieter berechnen für einen Bitcoin-Aufruf mehrere Einheiten. Historische Anfragen oder Archivabfragen können mehr kosten. Kostenlose Tarife können außerdem die Geschwindigkeit begrenzen, selbst wenn das monatliche Kontingent großzügig aussieht. | Option | Am besten geeignet für | Kostenloser Einstieg | Kostenpflichtig ab | Kostenlose Geschwindigkeit | Verfügbarkeit | Signet | | --- | --- | --- | --- | --- | --- | --- | | QuickNode | Schnelle Einrichtung und Erweiterungen | 10M Credits/Monat | $49/Monat | 15/s | 99.99% | Nein | | GetBlock | Günstiger Einstieg | 50K Compute Units/Tag | etwa $23/Monat | 20/s | 99% geteilt | Nein | | Chainstack | Breite RPC-Abdeckung | 3M Request Units/Monat | $49/Monat | 25/s | 99.9% | Ja | | Alchemy | Teams, die Alchemy bereits nutzen | 30M Compute Units/Monat | $0.45/M Einheiten | 25/s | 99.99% | Ja | | Blockdaemon | Institutionelle Compliance | 3M Compute Units/Monat | Vertrieb kontaktieren | 5/s | 99.9% | Nein | | NOWNodes | Einfache Abrechnung pro Anfrage | 100K Anfragen, einmonatiger Test | €20/Monat | 15/s | 99.95% | Nein | | Blockstream Esplora | Kostenlose schreibgeschützte Abfragen | etwa 500K Anfragen/Monat | Individuell | etwa 50/s | 99.9% | Ja | | Deine eigene Bitcoin-Core-Node | Privatsphäre und volle Kontrolle | Unbegrenzte Aufrufe | $20–80/Monat für VPS oder eigene Hardware | Hardware entscheidet | Du verwaltest sie | Ja | - Bitcoin-Aufrufe bei QuickNode können mehrere Credits verbrauchen. - Alchemy nennt 30M Compute Units, also ungefähr 3M Bitcoin-Aufrufe, wenn jeder Aufruf 10 Einheiten kostet. - Esplora ist eine REST-API und kein vollständiger Bitcoin-Core-JSON-RPC-Endpunkt. - Ein Verfügbarkeitswert sagt nichts über die Qualität des Supports, regionale Latenzen oder darüber aus, wie schnell ein Anbieter eine Störung behebt. ## Wofür die einzelnen Optionen wirklich gut sind **Kurz gesagt:** Entscheide nach deiner tatsächlichen Auslastung. Chainstack deckt viele Standardbefehle ab. Esplora ist einfach für schreibgeschützte Daten. Eine eigene Node bietet die meiste Kontrolle. Anbieterseiten werben meist zuerst mit sehr großen Zahlen. Diese Zahlen sind weniger wichtig als die Frage, ob der Dienst die von deiner App benötigten Befehle bereitstellt, historische Daten liefert, dein Testnetz unterstützt und Wachstum ohne überraschende Rechnung ermöglicht. ### QuickNode _Ein ausgereifter Einstieg und optionale Datenerweiterungen._ QuickNode ist ein großer Multi-Chain-Anbieter mit Bitcoin Mainnet und Testnet4. Seine gehosteten Nodes bewahren die vollständige Historie auf, sodass eine App alte Blöcke und Transaktionen abrufen kann. Der entscheidende Unterschied ist sein Erweiterungskatalog. Blockbook-Methoden können die Abfrage von Adressguthaben, UTXOs und erweiterten öffentlichen Schlüsseln vereinfachen. APIs für Ordinals und Runes sind separate Extras. Das kann Arbeit sparen, wenn die reinen Bitcoin-Core-Befehle nicht ausreichen. **Darauf achten:** Credits entsprechen nicht der Zahl der Aufrufe, Erweiterungen kosten extra und Bitcoin-WebSocket-Unterstützung wird nicht angeboten. ### GetBlock _Ein günstigerer gehosteter Einstieg mit mehreren Abrechnungsmodellen._ GetBlock dokumentiert weniger Bitcoin-Befehle als Bitcoin Core selbst, deckt aber die häufigsten Aufgaben ab: Blockchain-Daten, den Mempool, Rohtransaktionen, Gebührenschätzungen und PSBT-Abläufe. Die pauschal abgerechnete Limitless Node kann bei vorhersehbarem Datenverkehr die Budgetplanung erleichtern. Dedizierte Nodes kosten deutlich mehr, beseitigen aber die gemeinsamen Limits. Zu den Regionen gehören Frankfurt, New York und Singapur. **Darauf achten:** Die Verfügbarkeitszusage für gemeinsam genutzte Nodes beträgt 99%, und Wallet-Befehle sind auf der geteilten Infrastruktur nicht verfügbar. ### Chainstack _Breite Abdeckung von Standard-RPCs und Unterstützung für Signet._ Chainstack dokumentiert 139 Bitcoin-JSON-RPC-Methoden und bietet damit in diesem Vergleich die breiteste Abdeckung. Seine gemeinsam genutzten Bitcoin-Nodes speichern die vollständige Historie und aktivieren den Transaktionsindex, wodurch sich alte Transaktionen abfragen lassen. Außerdem unterstützt der Dienst Signet, ein berechenbares Bitcoin-Testnetz. Wallet-bezogene Befehle erfordern weiterhin eine dedizierte Node. Eine breite Abdeckung bedeutet also nicht, dass im normalen geteilten Tarif jeder Befehl verfügbar ist. **Darauf achten:** Archivähnliche Anfragen können mehr Request Units verbrauchen, und die Servicegutschrift bei weniger als 99.9% Verfügbarkeit ist an Enterprise-Bedingungen geknüpft. ### Alchemy _Teams, die Alchemy bereits für Ethereum oder andere Chains nutzen._ Alchemy integriert Bitcoin in eine Plattform, die viele Entwickler bereits verwenden. Der Dienst deckt die gängigen Lese-, Mempool-, Broadcast- und Gebührenaufgaben ab und unterstützt Mainnet, Testnet3, Testnet4 und Signet. Das kostenlose Kontingent wirkt deutlich größer, weil es in Compute Units angegeben wird. Spark schätzt es auf etwa 3 Millionen Bitcoin-Aufrufe, wenn jede Methode 10 Einheiten kostet. Archivdaten sind enthalten. **Darauf achten:** Der Umfang der Bitcoin-Methoden ist kleiner als bei Chainstack, Wallet-Methoden fehlen und WebSocket-Unterstützung ist nicht dokumentiert. ### Blockdaemon _Institutionen, die Compliance-Nachweise und dedizierten Support benötigen._ Blockdaemon richtet sich an institutionelle Kunden und nennt Zertifizierungen nach ISO 27001 und SOC 2 Type II. Der Dienst stellt Standardmethoden von Bitcoin sowie eigene Hilfsfunktionen für Guthaben, UTXOs und den Transaktionsverlauf nach Adresse bereit. Für einen Wochenendprototyp ist das weniger attraktiv, weil nur begrenzte öffentliche Preisinformationen verfügbar sind und die kostenlose Geschwindigkeit niedrig ist. Sinnvoller ist das Angebot, wenn Beschaffung, Compliance und Supportzusagen Teil der Entscheidung sind. **Darauf achten:** Für kostenpflichtige Preise ist ein Verkaufsgespräch nötig, Signet wird nicht aufgeführt und Bitcoin-WebSocket-Unterstützung fehlt. ### NOWNodes _Menschen, die einfache Anfragezahlen und einen niedrigen veröffentlichten Einstiegspreis bevorzugen._ NOWNodes zählt Anfragen, statt eine weitere eigene Einheit zu erfinden. Der Archivzugriff ist enthalten, und kostenpflichtige Tarife bieten WebSocket-Zugriff über die umfassendere Indexierungsinfrastruktur des Anbieters. Der Einstiegspreis ist niedriger als bei vielen Wettbewerbern, doch der kostenlose Tarif ist ein einmonatiger Test und kein dauerhaft kostenloses Angebot. Dedizierte Bitcoin-Nodes sind ein separates und wesentlich teureres Produkt. **Darauf achten:** Das kostenlose Kontingent läuft ab, Signet ist nicht verfügbar und dediziertes Hosting beginnt preislich weit oberhalb der geteilten Tarife. ### Blockstream Esplora _Einfache, schreibgeschützte Bitcoin-Daten ohne vollständigen RPC-Dienst._ Esplora unterscheidet sich von allen anderen hier aufgeführten gehosteten Optionen. Es ist eine quelloffene REST-API für Blöcke, Transaktionen, Adressen, UTXOs, Mempool-Daten und Gebührenschätzungen. Du kannst den öffentlichen Dienst von Blockstream nutzen oder die Software selbst hosten. Für eine App, die nur Guthaben und Transaktionen prüft, kann diese einfachere Schnittstelle genügen. Sie bietet nicht den vollständigen Befehlssatz von Bitcoin Core, keine Wallet-Steuerung und keine Mining-Befehle. **Darauf achten:** Es handelt sich nicht um einen direkt austauschbaren JSON-RPC-Ersatz. Prüfe die Anforderungen an Broadcast und Ratenbegrenzung für deine Auslastung. ## Warum die Methodenabdeckung wichtig ist **Kurz gesagt:** Jeder Anbieter beherrscht grundlegende Lesezugriffe und das Verbreiten von Transaktionen. Wallet-Steuerung und Node-Verwaltung sind bei gemeinsam genutzten Diensten normalerweise gesperrt. Bitcoin Core stellt viele Befehle bereit, weil eine Full Node weit mehr kann, als eine Transaktion abzurufen. Sie kann Wallets verwalten, teilweise signierte Transaktionen erstellen, Peers prüfen, Node-Einstellungen ändern und Mining-Aufgaben unterstützen. Ein gemeinsam genutzter Anbieter kann nicht jedem Kunden sicher dieses Maß an Kontrolle geben. Die meisten Apps benötigen nur eine kleine gemeinsame Auswahl: einen Block lesen, eine Transaktion lesen, den Mempool prüfen, eine Gebühr schätzen und eine signierte Transaktion verbreiten. Wenn das deine Auslastung beschreibt, kann fast jede Option in der Tabelle funktionieren. Wenn du Wallet-Befehle oder eine ungewöhnliche Indexierung brauchst, lies die Methodenliste, bevor du die Integration entwickelst. | Funktion | Bitcoin Core | Die meisten gehosteten Tarife | Warum das wichtig ist | | --- | --- | --- | --- | | Blöcke und Bestätigungen | Ja | Ja | Erkennen, ob und wann eine Zahlung abgeschlossen wurde. | | Rohtransaktionen | Ja | Meistens | Transaktionsdaten lesen oder übermitteln. | | Gebührenschätzungen | Ja | Ja | Vermeiden, viel zu viel zu zahlen oder zu lange zu warten. | | Mempool-Prüfung | Ja | Meistens | Noch wartende Transaktionen verstehen. | | PSBT-Werkzeuge | Ja | Unterschiedlich | Signaturen koordinieren, ohne private Schlüssel offenzulegen. | | Wallet-Methoden | Ja | Meistens nein | Adressen erstellen und eine Node-Wallet verwalten. | | Node-Verwaltung | Ja | Nein | Peers, Indizes und Node-Einstellungen kontrollieren. | | Hilfsfunktionen für den Adressverlauf | Benötigt einen Indexer | Manchmal als Erweiterung | Bitcoin Core bietet standardmäßig nicht jede walletfreundliche Abfrage. | ## Eine eigene Bitcoin-Node betreiben **Kurz gesagt:** Du tauschst die Anbieterrechnung gegen Hardware, Bandbreite und Verantwortung. Dafür bestimmst du die Regeln, hältst Anfragen privat und beseitigst Ratenlimits. Selbsthosting ist die stärkste Option für Privatsphäre und Kontrolle. Deine Anfragen bleiben in deiner Infrastruktur, du entscheidest, welche Version von Bitcoin Core läuft, und kannst ohne API-Schlüssel oder Abrechnung pro Anfrage den vollständigen Befehlssatz nutzen. Der Betriebsaufwand ist real. Eine Full Node braucht für genügend Reserve ungefähr 1 TB SSD-Speicherplatz. Die zugrunde liegende Momentaufnahme schätzt die Blockchain-Daten für Mitte 2026 auf etwa 745 GB. Jährlich kommen ungefähr 70 bis 80 GB hinzu. Die erste Synchronisierung kann auf moderner Hardware zwei bis sieben Tage dauern. Eine beschnittene Node validiert die gesamte Chain, verwirft aber alte Blockdateien. Sie kommt mit deutlich weniger Speicherplatz aus, bei Blockdaten manchmal mit etwa 10 GB. Dafür kann sie nicht jede historische Transaktionsanfrage beantworten und keinen vollständigen Transaktionsindex führen. Pruning eignet sich hervorragend, wenn du unabhängig verifizieren möchtest, aber kein vollständiges öffentliches Archiv brauchst. Zu Hause kann ein Mini-PC oder Raspberry Pi 5 mit externer SSD einmalig ungefähr $200 bis $400 kosten. Ein günstiger VPS kann rund $20 bis $50 pro Monat kosten. Größere Cloud-Plattformen können wesentlich teurer sein, besonders wenn Bandbreite und Speicher getrennt abgerechnet werden. Diese Werte verändern sich mit den Preisen für Hardware und Hosting. - Wähle eine Full Node, wenn du die vollständige Historie oder txindex brauchst. - Wähle eine beschnittene Node, wenn Verifizierung wichtiger ist als der Zugriff auf alte Blöcke. - Halte einen gehosteten Ausweichdienst bereit, wenn ein Ausfall dein Produkt stoppen würde. - Überwache Speicherwachstum, Synchronisierungsstatus, Backups und Softwareupdates. ## Privatsphäre, Vertrauen und was Preistabellen übersehen **Kurz gesagt:** Der Endpunkt sieht, wonach du fragst. Wiederholte Abfragen von Adressen und Transaktionen können zeigen, wie eine Wallet genutzt wird, selbst wenn der Anbieter den privaten Schlüssel nie sieht. Eine entfernte Node erfährt Zeitpunkt und Inhalt deiner Anfragen. Wenn deine App wiederholt dieselben Adressen abfragt, kann der Anbieter diese Anfragen möglicherweise gruppieren. Verknüpft er sie mit deinem Konto, API-Schlüssel oder deiner Netzwerkadresse, erfährt er mehr, als eine einfache Preistabelle vermuten lässt. Mehrere öffentliche Anbieter zu verwenden, löst dieses Problem nicht automatisch. Dadurch können dieselben Informationen auf noch mehr Unternehmen verteilt werden. Datenschutzbewusste Wallet-Software kann Techniken wie kompakte Blockfilter, private Netzwerkrouten oder eine vom Nutzer gewählte Node einsetzen, aber jedes Konzept bringt Kompromisse mit sich. Vertrauen betrifft auch Richtigkeit und Verfügbarkeit. Ein Anbieter kann veraltete Daten liefern, Anfragen drosseln oder ausfallen. Deine App sollte Fehler prüfen, unmögliche Antworten ablehnen und keinen einzelnen Endpunkt als unfehlbare Wahrheit behandeln. Bei einem Zahlungsprodukt kann eine zweite unabhängige Quelle helfen, eine Störung des Anbieters von einem Ereignis im Bitcoin-Netzwerk zu unterscheiden. ## Ein Entscheidungsleitfaden in fünf Minuten **Kurz gesagt:** Liste zuerst die genauen Aufgaben, den Datenverkehr und die Anforderungen an die Privatsphäre auf. Schließe dann Anbieter aus, die sie nicht erfüllen können. Der Preis kommt erst nach der Eignung. Beginne mit der kürzesten ehrlichen Beschreibung deiner App. „Wir brauchen Bitcoin-Daten“ ist zu ungenau. „Wir prüfen stündlich 20.000 Adressen, lesen alte Transaktionen, schätzen Gebühren und verbreiten signierte Transaktionen“ ist hilfreich. Dieser Satz zeigt dir, ob du einen Adressindex und eine Archivhistorie brauchst und welches Ratenlimit zum Problem werden könnte. 1. **Notiere die Befehle oder Ergebnisse, die du brauchst.** Wenn du die Namen der Befehle noch nicht kennst, beschreibe die Aktion des Nutzers: eine Zahlung prüfen, den Transaktionsverlauf anzeigen, eine Gebühr schätzen, eine signierte Transaktion verbreiten oder eine serverseitige Wallet verwalten. 2. **Schätze den normalen und den höchsten Datenverkehr.** Monatliche Kontingente helfen nicht, wenn eine kurze Lastspitze ein Limit pro Sekunde erreicht. Beziehe Wiederholungsversuche, die Synchronisierung im Hintergrund und Wachstum ein. 3. **Entscheide, was der Anbieter erfahren darf.** Die Überwachung von Adressen und Wallet-Anfragen erfordert mehr Sorgfalt als ein öffentliches Widget zur Blockhöhe. 4. **Teste Fehler vor dem Produktivbetrieb.** Entferne in einer Testumgebung den Endpunkt, löse ein Ratenlimit aus und gib veraltete Daten zurück. Deine App sollte verständlich scheitern und sich sauber erholen. 5. **Halte einen Ausstieg offen.** Nutze möglichst Standardaufrufe von Bitcoin Core, kapsle anbieterspezifische Erweiterungen und kläre, wie lange ein Wechsel der Endpunkte dauern würde. ## Das kleine Glossar **Kurz gesagt:** Du brauchst nur eine Handvoll Begriffe, um die meisten Anbieterseiten zu verstehen. **Bitcoin-Node:** Software, die die Bitcoin-Regeln überprüft und Blöcke sowie Transaktionen mit dem Netzwerk teilt. **Bitcoin Core:** Die am weitesten verbreitete Software für Bitcoin-Nodes. Sie enthält die standardmäßige JSON-RPC-Schnittstelle. **RPC:** Eine strukturierte Möglichkeit, mit der ein Programm ein anderes auffordert, eine Aufgabe auszuführen oder Daten zurückzugeben. **JSON-RPC:** Das Nachrichtenformat, das Bitcoin Core für RPC-Anfragen und Antworten verwendet. **Mempool:** Transaktionen, die einer Node bekannt sind, aber noch nicht in einen Block aufgenommen wurden. **UTXO:** Ein Teilbetrag in Bitcoin, der ausgegeben werden kann. Wallet-Guthaben bestehen aus einem oder mehreren UTXOs. **Archiv- oder unbeschnittene Node:** Eine Node, die alte Blockdaten aufbewahrt und historische Anfragen beantworten kann. **Beschnittene Node:** Eine Node, die alles validiert, aber alte Blockdateien entfernt, um Speicherplatz zu sparen. **txindex:** Ein optionaler Index von Bitcoin Core, mit dem sich jede historische Transaktion leichter finden lässt. **Testnet:** Ein öffentliches Bitcoin-Netzwerk für Tests mit Coins, die keinen vorgesehenen Geldwert haben. **Signet:** Ein stärker kontrolliertes Bitcoin-Testnetz mit gleichmäßigerer Blockproduktion. **Regtest:** Ein privates lokales Bitcoin-Testnetz, in dem ein Entwickler bei Bedarf Blöcke erzeugt. **RPS:** Anfragen pro Sekunde, also ein Geschwindigkeitslimit für die Zahl möglicher Aufrufe. **SLA:** Eine Dienstgütevereinbarung, meist eine schriftliche Verfügbarkeitszusage mit bestimmten Bedingungen. ## Fragen, die Menschen wirklich stellen **Kurz gesagt:** Gehostetes RPC ist am einfachsten. Eine eigene Node bietet die größte Unabhängigkeit. Eine Hybridlösung ist üblich, wenn sowohl Verfügbarkeit als auch Kontrolle wichtig sind. ### Was ist ein Bitcoin-RPC-Anbieter? Das ist ein Unternehmen, das Bitcoin-Nodes betreibt und deiner App erlaubt, über das Internet mit ihnen zu kommunizieren. Deine App kann Blöcke und Transaktionen lesen, Gebühren schätzen und normalerweise signierte Transaktionen verbreiten, ohne selbst eine Node zu betreiben. ### Welcher Bitcoin-RPC-Anbieter hat das beste kostenlose Angebot? Für eine breite JSON-RPC-Nutzung entsprechen Chainstack und Alchemy im Vergleich von Mitte 2026 jeweils ungefähr 3 Millionen einfachen monatlichen Aufrufen, ihre Einheiten unterscheiden sich jedoch. Blockstream Esplora ist für kostenlose schreibgeschützte REST-Abfragen attraktiv. Das beste kostenlose Angebot ist das, das deine benötigte Methode, dein Netzwerk und deine höchste Anfragerate abdeckt. ### Muss ich eine eigene Bitcoin-Node betreiben? Betreibe eine eigene Node, wenn die Privatsphäre deiner Abfragen, der vollständige Zugriff auf Befehle oder die Unabhängigkeit von einem Anbieter wichtig genug sind, um den Wartungsaufwand zu rechtfertigen. Für Prototypen und einfache Apps mit öffentlichen Daten reicht normalerweise ein gehosteter Endpunkt. Viele Produktivsysteme nutzen eine eigene Node und zusätzlich einen gehosteten Ausweichdienst. ### Kann ein RPC-Anbieter meine Bitcoin stehlen? Die Nutzung eines Endpunkts zum Lesen und Verbreiten sollte deine privaten Schlüssel nicht offenlegen. Deine Wallet sollte Transaktionen lokal signieren. Ein Anbieter kann trotzdem Anfragen beobachten, falsche Daten zurückgeben oder die Verfügbarkeit beeinträchtigen. Deshalb muss die Wallet Antworten prüfen und die Schlüssel außerhalb des RPC-Dienstes halten. ### Was ist der Unterschied zwischen einer Bitcoin-API und Bitcoin-RPC? Bitcoin-RPC bezeichnet normalerweise Befehle nach dem Vorbild von Bitcoin Core. Eine Bitcoin-API kann einfachere REST-Endpunkte, Adressverläufe oder indexierte Daten anbieten, die Bitcoin Core nicht direkt bereitstellt. Esplora ist ein gutes Beispiel für eine nützliche API, die jedoch kein vollständiger JSON-RPC-Ersatz ist. ### Was ist der Unterschied zwischen einer Full Node und einer beschnittenen Node? Beide validieren Bitcoin. Eine Full Node bewahrt alte Blockdateien auf. Eine beschnittene Node löscht die meisten davon nach der Validierung, um Platz zu sparen. Eine beschnittene Node kann nicht jede historische Datenanfrage beantworten und keinen vollständigen Transaktionsindex führen. ### Was kostet der Betrieb einer Bitcoin-Full-Node? Die zugrunde liegende Momentaufnahme schätzt die Kosten bei üblichen VPS-Konfigurationen je nach Speicherplatz und Bandbreite auf etwa $20 bis $80 pro Monat. Eigene Hardware kann einmalig ungefähr $200 bis $400 kosten. Große Cloud-Plattformen können wesentlich teurer sein. Preise ändern sich, daher solltest du vor dem Kauf den aktuellen Hardwarebedarf und Datenverkehr berechnen. ### Welche Anbieter unterstützen Bitcoin Signet? Der Vergleich von Mitte 2026 führt Chainstack, Alchemy und Blockstream Esplora mit Signet-Unterstützung auf. Eine selbst gehostete Bitcoin-Core-Node unterstützt Signet ebenfalls. Prüfe die aktuelle Netzwerkverfügbarkeit, bevor du einen Tarif auswählst. ### Unterstützt Bitcoin Core WebSocket? Nicht von Haus aus. Bitcoin Core verwendet ZeroMQ für Push-Benachrichtigungen. Anbieter, die Bitcoin-WebSocket bewerben, ergänzen normalerweise eine weitere Indexierungs- oder Ereignisschicht, statt WebSocket-Unterstützung von Bitcoin Core bereitzustellen. ### Was sollte eine Produktivumgebung verwenden? Ein verbreitetes Konzept nutzt eine selbst gehostete Node als Hauptquelle und einen gehosteten Anbieter als unabhängigen Ausweichdienst. Kleinere Produkte können mit zwei gehosteten Endpunkten beginnen. Entscheidend ist, das Failover zu testen, statt einfach anzunehmen, dass es funktioniert. ## Quellen und Hinweis zur Aktualität Preise, Limits, Netzwerkunterstützung und Methodenlisten ändern sich. Die Vergleichswerte zeigen den Stand von Mitte 2026 aus der verlinkten Spark-Übersicht. Prüfe die aktuelle Dokumentation des Anbieters, bevor du eine Infrastrukturentscheidung triffst. 1. [Spark: Übersicht über Bitcoin-RPC-Anbieter](https://www.spark.money/tools/bitcoin-rpc-provider-comparison) 2. [Dokumentation von Bitcoin Core](https://bitcoincore.org/en/doc/) 3. [QuickNode](https://www.quicknode.com/) 4. [GetBlock](https://getblock.io/) 5. [Chainstack](https://chainstack.com/) 6. [Alchemy](https://www.alchemy.com/) 7. [Blockdaemon](https://www.blockdaemon.com/) 8. [NOWNodes](https://nownodes.io/) 9. [Blockstream Esplora API](https://blockstream.info/api/) ## Auch verfügbar auf - [Bitcoin RPC providers, explained without the jargon](https://nuri.com/knowledge/bitcoin-rpc-providers) (en) - [Proveedores RPC de Bitcoin, explicados sin tecnicismos](https://nuri.com/es/conocimiento/proveedores-rpc-bitcoin) (es) - [Provider RPC per Bitcoin, spiegati senza gergo tecnico](https://nuri.com/it/conoscenza/provider-rpc-bitcoin) (it) --- --- title: "Proveedores RPC de Bitcoin, explicados sin tecnicismos" description: "Compara proveedores RPC de Bitcoin, entiende los nodos alojados y el autoalojamiento y elige la opción más simple para tu app sin tecnicismos." lang: "es" type: "knowledge-guide" datePublished: "2026-08-21" dateModified: "2026-08-21" canonical: "https://nuri.com/es/conocimiento/proveedores-rpc-bitcoin" tags: ["proveedor RPC de Bitcoin","proveedor de nodos de Bitcoin","Bitcoin JSON-RPC","nodo de Bitcoin alojado","nodo completo de Bitcoin","API de Bitcoin","infraestructura de Bitcoin"] --- # Proveedores RPC de Bitcoin, explicados sin tecnicismos **TL;DR:** Un proveedor RPC de Bitcoin permite que una aplicación lea datos de Bitcoin y envíe transacciones sin mantener su propio nodo de Bitcoin. Los servicios alojados facilitan el inicio. Un nodo propio ofrece más privacidad, control y acceso. Muchos productos importantes usan ambas opciones. Si solo utilizas una cartera como Nuri, no necesitas elegir ningún proveedor RPC. ## Contenido - [La respuesta rápida](#quick-answer) - [Qué significa RPC en lenguaje normal](#what-rpc-means) - [¿De verdad necesitas un proveedor RPC?](#do-you-need-one) - [Comparación de proveedores](#comparison) - [Para qué sirve realmente cada opción](#provider-notes) - [Por qué importa la cobertura de métodos](#method-coverage) - [Operar tu propio nodo de Bitcoin](#run-your-own-node) - [Privacidad, confianza y lo que no muestran las tablas de precios](#privacy-and-trust) - [Una guía de decisión de cinco minutos](#how-to-choose) - [El pequeño glosario](#glossary) - [Preguntas que la gente realmente hace](#faq) ## La respuesta rápida **En pocas palabras:** Un proveedor RPC funciona como un mando a distancia para un nodo de Bitcoin. Tu aplicación hace preguntas o envía una transacción. El proveedor se ocupa de la maquinaria. Una aplicación de Bitcoin necesita una forma fiable de ver qué sucede en la red Bitcoin. Puede necesitar comprobar si llegó un pago, leer una transacción, calcular una comisión adecuada o enviar una transacción firmada. Un nodo de Bitcoin puede responder a esas solicitudes. Operar ese nodo por tu cuenta requiere almacenamiento, ancho de banda, mantenimiento y tiempo. Un proveedor RPC de Bitcoin alojado opera el nodo por ti y proporciona a tu aplicación una dirección de internet con la que comunicarse. RPC significa llamada a procedimiento remoto. El nombre suena más complicado que su función. Esa comodidad tiene un coste. El proveedor puede ver tus solicitudes, aplicar límites, cambiar los precios o dejar de funcionar. Un nodo operado por ti ofrece más privacidad y control, pero te hace responsable de mantenerlo en buen estado. No hay un ganador universal porque la opción correcta depende de lo que estés creando. ## Qué significa RPC en lenguaje normal **En pocas palabras:** Tu aplicación envía una pregunta precisa a un nodo de Bitcoin y recibe una respuesta precisa. Esa solicitud y su respuesta constituyen el RPC. Piensa en un nodo de Bitcoin como una biblioteca que conserva una copia verificada del historial de Bitcoin y sigue la red a medida que llegan nuevos bloques. RPC es el mostrador de atención. Tu aplicación no recorre toda la biblioteca, sino que pide algo concreto. Una solicitud podría ser: dame el bloque 900.000, dime si se conoce esta transacción, muéstrame la estimación actual de comisiones o difunde esta transacción ya firmada. Bitcoin Core, el software de nodo más utilizado, ofrece aproximadamente 150 comandos para tareas como estas. Por usar su punto de acceso RPC, el proveedor normalmente no custodia tus bitcoin. En una buena arquitectura de cartera, las transacciones se firman con las claves del usuario antes de enviarlas al nodo. Aun así, las consultas pueden revelar información útil sobre la cartera, como las direcciones que vigila. Por eso la privacidad forma parte de la elección del proveedor. - Leer datos de la cadena de bloques: bloques, transacciones y confirmaciones. - Inspeccionar la mempool: transacciones que esperan confirmación. - Estimar comisiones: una aproximación práctica para obtener una confirmación a tiempo. - Difundir una transacción firmada: transmitirla a la red Bitcoin. ## ¿De verdad necesitas un proveedor RPC? **En pocas palabras:** Quienes usan una cartera normalmente no necesitan hacer nada. Quienes crean aplicaciones suelen necesitarlo. Los equipos con mucha infraestructura o necesidades de privacidad pueden preferir un nodo propio. Si usas Nuri u otra cartera para consumidores, la respuesta suele ser no. La cartera gestiona su propia conexión con Bitcoin. No necesitas una cuenta en QuickNode, Chainstack ni ninguna otra empresa de infraestructura. Si estás creando una aplicación que lee o envía transacciones de Bitcoin, necesitas acceso a un nodo de alguna manera. Un proveedor alojado es la forma más rápida de empezar. Recibes un punto de acceso y una clave de API, y tu aplicación puede hacer solicitudes dentro de los límites del plan. Si operas el backend de una cartera, vigilas muchas direcciones, necesitas todos los comandos de Bitcoin Core o no quieres que otra empresa observe tus solicitudes, un nodo propio resulta más atractivo. Los sistemas importantes suelen usar primero un nodo autoalojado y mantener un punto de acceso alojado como alternativa. - Usar una cartera de Bitcoin: probablemente no tengas que elegir ningún proveedor. - Crear un prototipo: empieza con un plan alojado gratuito. - Operar un servicio de pagos en producción: compara disponibilidad, límites, privacidad y opciones alternativas. - Crear infraestructura de cartera con necesidades de privacidad: opera tu propio nodo o diseña una solución híbrida con cuidado. ## Comparación de proveedores **En pocas palabras:** Los planes gratuitos usan unidades diferentes, así que la asignación que parece mayor no siempre lo es. Compara el trabajo que necesitas, no solo la cifra destacada. La siguiente tabla refleja la situación a mediados de 2026 a partir de información pública recopilada por Spark. Los planes cambian. Úsala como mapa del mercado y confirma el precio y los límites actuales en el sitio web del proveedor antes de comprometerte. Los créditos, las unidades de cómputo, las unidades de solicitud y las solicitudes simples no son directamente equivalentes. Algunos proveedores cobran varias unidades por una llamada de Bitcoin. Las consultas históricas o de archivo pueden costar más. Los planes gratuitos también pueden limitar la velocidad aunque la asignación mensual parezca generosa. | Opción | Ideal para | Inicio gratuito | Plan de pago desde | Velocidad gratuita | Disponibilidad | Signet | | --- | --- | --- | --- | --- | --- | --- | | QuickNode | Configuración rápida y complementos | 10M créditos/mes | $49/mes | 15/s | 99.99% | No | | GetBlock | Entrada de bajo coste | 50K unidades de cómputo/día | unos $23/mes | 20/s | 99% compartido | No | | Chainstack | Amplia cobertura RPC | 3M unidades de solicitud/mes | $49/mes | 25/s | 99.9% | Sí | | Alchemy | Equipos que ya usan Alchemy | 30M unidades de cómputo/mes | $0.45/M unidades | 25/s | 99.99% | Sí | | Blockdaemon | Cumplimiento institucional | 3M unidades de cómputo/mes | Contactar con ventas | 5/s | 99.9% | No | | NOWNodes | Precios sencillos por solicitud | 100K solicitudes, prueba de un mes | €20/mes | 15/s | 99.95% | No | | Blockstream Esplora | Consultas gratuitas de solo lectura | unas 500K solicitudes/mes | Personalizado | unas 50/s | 99.9% | Sí | | Tu propio nodo Bitcoin Core | Privacidad y control total | Llamadas ilimitadas | $20–80/mes por un VPS o hardware doméstico | Hardware decide | Tú lo gestionas | Sí | - Las llamadas de Bitcoin en QuickNode pueden consumir varios créditos. - Alchemy ofrece 30M unidades de cómputo, aproximadamente 3M llamadas de Bitcoin si cada llamada cuesta 10 unidades. - Esplora es una API REST, no un punto de acceso JSON-RPC completo de Bitcoin Core. - Un porcentaje de disponibilidad no describe la calidad del soporte, la latencia regional ni la rapidez con la que un proveedor resuelve una incidencia. ## Para qué sirve realmente cada opción **En pocas palabras:** Elige según tu carga de trabajo real. Chainstack cubre muchos comandos estándar. Esplora es sencillo para datos de solo lectura. Tu propio nodo ofrece el máximo control. Las páginas de los proveedores suelen empezar con cifras muy grandes. Esas cifras importan menos que saber si el servicio ofrece los comandos que necesita tu aplicación, devuelve datos históricos, admite tu red de pruebas y te permite crecer sin una factura inesperada. ### QuickNode _Un inicio bien resuelto y complementos de datos opcionales._ QuickNode es un gran proveedor multicadena compatible con la red principal de Bitcoin y Testnet4. Sus nodos alojados conservan todos los datos históricos, por lo que una aplicación puede consultar bloques y transacciones antiguos. La diferencia útil está en su catálogo de complementos. Los métodos de Blockbook pueden facilitar las consultas de saldos de direcciones, UTXOs y claves públicas extendidas. Las API de Ordinals y Runes son extras independientes. Esto puede ahorrar trabajo cuando los comandos básicos de Bitcoin Core no bastan. **Ten en cuenta:** Los créditos no equivalen a llamadas, los complementos cuestan más y no se ofrece compatibilidad con Bitcoin WebSocket. ### GetBlock _Una opción alojada más económica con varias formas de facturación._ GetBlock documenta menos comandos de Bitcoin que el propio Bitcoin Core, pero cubre las tareas habituales: datos de la cadena de bloques, mempool, transacciones sin procesar, estimaciones de comisiones y flujos de trabajo con PSBT. Su Limitless Node con tarifa plana puede facilitar la planificación del presupuesto cuando el tráfico es predecible. Los nodos dedicados cuestan mucho más, pero eliminan los límites compartidos. Las regiones incluyen Fráncfort, Nueva York y Singapur. **Ten en cuenta:** La promesa de disponibilidad para nodos compartidos es del 99%, y los comandos de cartera no están disponibles en la infraestructura compartida. ### Chainstack _Amplia cobertura RPC estándar y compatibilidad con signet._ Chainstack documenta 139 métodos JSON-RPC de Bitcoin, la cobertura más amplia de esta comparación. Sus nodos de Bitcoin compartidos conservan todo el historial y tienen activado el índice de transacciones, lo que permite consultar transacciones antiguas. También admite signet, una red de pruebas de Bitcoin predecible. Los comandos relacionados con carteras siguen necesitando un nodo dedicado, por lo que una cobertura amplia no significa que todos los comandos estén disponibles en el plan compartido normal. **Ten en cuenta:** Las solicitudes de tipo archivo pueden consumir más unidades de solicitud, y la promesa de créditos de servicio del 99.9% está vinculada a las condiciones empresariales. ### Alchemy _Equipos que ya usan Alchemy para Ethereum u otras cadenas._ Alchemy incorpora Bitcoin a una plataforma que muchos desarrolladores ya utilizan. Cubre las tareas habituales de lectura, mempool, difusión y comisiones, y admite la red principal, Testnet3, Testnet4 y signet. La asignación gratuita parece mucho mayor porque se expresa en unidades de cómputo. Spark calcula unas 3 millones de llamadas de Bitcoin cuando cada método cuesta 10 unidades. Los datos de archivo están incluidos. **Ten en cuenta:** El conjunto de métodos de Bitcoin es menor que el de Chainstack, faltan los métodos de cartera y no se documenta la compatibilidad con WebSocket. ### Blockdaemon _Instituciones que necesitan pruebas de cumplimiento y soporte dedicado._ Blockdaemon se dirige a clientes institucionales y enumera las certificaciones ISO 27001 y SOC 2 Type II. Ofrece métodos estándar de Bitcoin, además de funciones propias para consultar saldos, UTXOs e historial de transacciones por dirección. Resulta menos atractivo para un prototipo de fin de semana porque la información pública sobre precios es limitada y la velocidad gratuita es baja. Tiene más sentido cuando la adquisición, el cumplimiento y los compromisos de soporte forman parte de la decisión. **Ten en cuenta:** Para conocer los precios de pago es necesario hablar con ventas, signet no aparece en la lista y no hay compatibilidad con Bitcoin WebSocket. ### NOWNodes _Personas que prefieren recuentos de solicitudes sencillos y un precio inicial publicado bajo._ NOWNodes cuenta solicitudes en lugar de inventar otra unidad. Incluye acceso a archivos, y los planes de pago incluyen acceso WebSocket mediante la infraestructura más amplia de indexación del proveedor. El precio inicial es menor que el de muchos competidores, pero el plan gratuito es una prueba de un mes y no un nivel gratuito permanente. Los nodos de Bitcoin dedicados son un producto separado y mucho más caro. **Ten en cuenta:** La asignación gratuita caduca, signet no está disponible y el alojamiento dedicado empieza muy por encima de los planes compartidos. ### Blockstream Esplora _Datos sencillos de Bitcoin, de solo lectura y sin un servicio RPC completo._ Esplora es diferente de todas las demás opciones alojadas que aparecen aquí. Es una API REST de código abierto para bloques, transacciones, direcciones, UTXOs, datos de la mempool y estimaciones de comisiones. Puedes usar el servicio público de Blockstream o alojar el software por tu cuenta. Para una aplicación que solo comprueba saldos y transacciones, esa interfaz más sencilla puede ser suficiente. No ofrece el conjunto completo de comandos de Bitcoin Core, controles de cartera ni comandos de minería. **Ten en cuenta:** No sustituye directamente a JSON-RPC. Comprueba los requisitos de difusión y los límites de velocidad para tu carga de trabajo. ## Por qué importa la cobertura de métodos **En pocas palabras:** Todos los proveedores gestionan lecturas básicas y difusión de transacciones. El control de carteras y la administración de nodos suelen estar bloqueados en los servicios compartidos. Bitcoin Core ofrece muchos comandos porque un nodo completo puede hacer mucho más que consultar una transacción. Puede gestionar carteras, crear transacciones parcialmente firmadas, inspeccionar pares, cambiar ajustes del nodo y ayudar en tareas de minería. Un proveedor compartido no puede dar de forma segura ese nivel de control a todos sus clientes. La mayoría de las aplicaciones necesitan un pequeño conjunto común: leer un bloque, leer una transacción, inspeccionar la mempool, estimar una comisión y difundir una transacción firmada. Si esa es tu carga de trabajo, casi todas las opciones de la tabla pueden servir. Si necesitas comandos de cartera o una indexación poco habitual, lee la lista de métodos antes de desarrollar la integración. | Función | Bitcoin Core | La mayoría de los planes alojados | Por qué importa | | --- | --- | --- | --- | | Bloques y confirmaciones | Sí | Sí | Saber si un pago se liquidó y cuándo. | | Transacciones sin procesar | Sí | Normalmente | Leer o enviar datos de transacciones. | | Estimaciones de comisiones | Sí | Sí | Evitar pagar demasiado o esperar demasiado tiempo. | | Inspección de la mempool | Sí | Normalmente | Entender las transacciones que siguen esperando. | | Herramientas PSBT | Sí | Varía | Coordinar firmas sin exponer claves privadas. | | Métodos de cartera | Sí | Normalmente no | Crear direcciones y gestionar una cartera del nodo. | | Administración del nodo | Sí | No | Controlar pares, índices y ajustes del nodo. | | Funciones de historial por dirección | Necesita un indexador | A veces como complemento | Bitcoin Core no ofrece de forma predeterminada todas las consultas útiles para una cartera. | ## Operar tu propio nodo de Bitcoin **En pocas palabras:** Cambias la factura de un proveedor por hardware, ancho de banda y responsabilidad. A cambio, eliges las reglas, mantienes las consultas en privado y eliminas los límites de velocidad. El autoalojamiento es la mejor opción para la privacidad y el control. Tus solicitudes permanecen en tu infraestructura, tú decides qué versión de Bitcoin Core ejecutar y puedes usar el conjunto completo de comandos sin clave de API ni factura por solicitud. El trabajo operativo es real. Un nodo completo necesita aproximadamente 1 TB de espacio SSD para contar con un margen cómodo. La fuente calcula unos 745 GB de datos de la cadena de bloques a mediados de 2026, con un crecimiento aproximado de 70 a 80 GB al año. La sincronización inicial puede tardar de dos a siete días con hardware moderno. Un nodo podado valida toda la cadena, pero descarta los archivos de bloques antiguos. Puede funcionar con mucho menos almacenamiento, a veces unos 10 GB para datos de bloques, pero no puede responder a todas las solicitudes de transacciones históricas ni mantener un índice completo de transacciones. La poda es excelente cuando necesitas una verificación independiente, pero no un archivo público completo. En casa, un mini PC o una Raspberry Pi 5 con un SSD externo puede costar aproximadamente entre $200 y $400 por adelantado. Un VPS económico puede costar entre $20 y $50 al mes. Las grandes plataformas en la nube pueden costar mucho más, sobre todo cuando el ancho de banda y el almacenamiento se cobran por separado. Estas cifras cambian con los precios del hardware y el alojamiento. - Elige un nodo completo cuando necesites todo el historial o txindex. - Elige un nodo podado cuando la verificación importe más que el acceso a bloques antiguos. - Mantén una alternativa alojada si una interrupción detendría tu producto. - Vigila el crecimiento del disco, el estado de sincronización, las copias de seguridad y las actualizaciones de software. ## Privacidad, confianza y lo que no muestran las tablas de precios **En pocas palabras:** El punto de acceso ve lo que preguntas. Las consultas repetidas de direcciones y transacciones pueden revelar cómo se usa una cartera, aunque el proveedor nunca vea la clave privada. Un nodo remoto conoce el momento y el contenido de tus solicitudes. Si tu aplicación consulta las mismas direcciones repetidamente, el proveedor puede llegar a agrupar esas solicitudes. Si las relaciona con tu cuenta, clave de API o dirección de red, puede saber más de lo que sugiere una simple tabla de precios. Usar varios proveedores públicos no soluciona esto automáticamente. Puede repartir la misma información entre más empresas. El software de cartera orientado a la privacidad puede emplear técnicas como filtros de bloques compactos, rutas de red privadas o un nodo elegido por el usuario, pero cada diseño tiene sus desventajas. La confianza también abarca la corrección y la disponibilidad. Un proveedor puede devolver datos obsoletos, limitar las solicitudes o sufrir una interrupción. Tu aplicación debe comprobar los errores, rechazar respuestas imposibles y evitar tratar un único punto de acceso como una verdad incuestionable. Para un producto de pagos, una segunda fuente independiente puede ayudar a distinguir una incidencia del proveedor de un suceso de la red Bitcoin. ## Una guía de decisión de cinco minutos **En pocas palabras:** Enumera primero las tareas exactas, el tráfico y las necesidades de privacidad. Después descarta los proveedores que no puedan cumplirlas. El precio viene después de la idoneidad. Empieza con la descripción más breve y sincera de tu aplicación. «Necesitamos datos de Bitcoin» es demasiado impreciso. «Comprobamos 20.000 direcciones cada hora, leemos transacciones antiguas, estimamos comisiones y difundimos transacciones firmadas» resulta útil. Esa frase te indica si necesitas un índice de direcciones, un historial de archivo y qué límite de velocidad podría perjudicarte. 1. **Anota los comandos o resultados que necesitas.** Si todavía no conoces los nombres de los comandos, describe la acción del usuario: comprobar un pago, mostrar el historial de transacciones, estimar una comisión, difundir una transacción firmada o gestionar una cartera del servidor. 2. **Calcula el tráfico normal y el tráfico máximo.** Las asignaciones mensuales no sirven si un pico breve de tráfico alcanza un límite por segundo. Incluye los reintentos, la sincronización en segundo plano y el crecimiento. 3. **Decide qué puede saber el proveedor.** La vigilancia de direcciones y las consultas de cartera merecen más cuidado que un indicador público de la altura de bloque. 4. **Prueba los fallos antes de llegar a producción.** En un entorno de pruebas, elimina el punto de acceso, activa un límite de velocidad y devuelve datos obsoletos. Tu aplicación debe fallar de forma clara y recuperarse sin problemas. 5. **Mantén una vía de salida.** Usa llamadas estándar de Bitcoin Core siempre que sea posible, aísla los complementos específicos del proveedor y averigua cuánto tardarías en cambiar de punto de acceso. ## El pequeño glosario **En pocas palabras:** Solo necesitas unos pocos términos para entender la mayoría de las páginas de proveedores. **Nodo de Bitcoin:** Software que verifica las reglas de Bitcoin y comparte bloques y transacciones con la red. **Bitcoin Core:** El software de nodo de Bitcoin más utilizado. Incluye la interfaz JSON-RPC estándar. **RPC:** Una forma estructurada para que un programa pida a otro que realice una tarea o devuelva datos. **JSON-RPC:** El formato de mensajes que Bitcoin Core utiliza para las solicitudes y respuestas RPC. **Mempool:** Transacciones que un nodo conoce y que todavía no se han incluido en un bloque. **UTXO:** Una cantidad de bitcoin que puede gastarse. Los saldos de las carteras se componen de uno o varios UTXOs. **Nodo de archivo o sin podar:** Un nodo que conserva los datos de bloques antiguos y puede responder a solicitudes históricas. **Nodo podado:** Un nodo que valida todo, pero elimina archivos de bloques antiguos para ahorrar almacenamiento. **txindex:** Un índice opcional de Bitcoin Core que facilita la consulta de cualquier transacción histórica. **Testnet:** Una red pública de Bitcoin para hacer pruebas con monedas que no tienen valor monetario previsto. **Signet:** Una red de pruebas de Bitcoin más controlada y con una producción de bloques más estable. **Regtest:** Una red de pruebas local y privada de Bitcoin en la que un desarrollador crea bloques cuando los necesita. **RPS:** Solicitudes por segundo, un límite de velocidad para la cantidad de llamadas que puedes hacer. **SLA:** Un acuerdo de nivel de servicio, normalmente una promesa escrita de disponibilidad sujeta a condiciones concretas. ## Preguntas que la gente realmente hace **En pocas palabras:** El RPC alojado es lo más sencillo. Un nodo propio es la opción más independiente. Es común usar una solución híbrida cuando importan tanto la disponibilidad como el control. ### ¿Qué es un proveedor RPC de Bitcoin? Es una empresa que opera nodos de Bitcoin y permite que tu aplicación se comunique con ellos por internet. Tu aplicación puede leer bloques y transacciones, estimar comisiones y normalmente difundir transacciones firmadas sin mantener un nodo propio. ### ¿Qué proveedor RPC de Bitcoin tiene el mejor plan gratuito? Para un uso amplio de JSON-RPC según la situación a mediados de 2026, Chainstack y Alchemy equivalen cada uno a unos 3 millones de llamadas básicas al mes, aunque sus unidades son diferentes. Blockstream Esplora resulta atractivo para consultas REST gratuitas de solo lectura. El mejor plan gratuito es el que incluye el método, la red y la velocidad máxima de solicitudes que necesitas. ### ¿Necesito operar mi propio nodo de Bitcoin? Opera uno cuando la privacidad de las consultas, el acceso a todos los comandos o la independencia de un proveedor sean suficientemente importantes como para justificar el mantenimiento. Un punto de acceso alojado suele bastar para prototipos y aplicaciones sencillas con datos públicos. Muchos sistemas en producción usan su propio nodo y una alternativa alojada. ### ¿Puede un proveedor RPC robar mis bitcoin? Usar un punto de acceso de lectura y difusión no debería revelar tus claves privadas. Tu cartera debe firmar las transacciones localmente. Aun así, un proveedor puede observar solicitudes, devolver datos incorrectos o afectar a la disponibilidad, por lo que el diseño de la cartera debe validar las respuestas y mantener las claves fuera del servicio RPC. ### ¿Qué diferencia hay entre una API de Bitcoin y RPC de Bitcoin? RPC de Bitcoin suele referirse a comandos con la estructura de Bitcoin Core. Una API de Bitcoin puede ofrecer puntos de acceso REST más sencillos, historial por dirección o datos indexados que Bitcoin Core no proporciona directamente. Esplora es un buen ejemplo de una API útil que no sustituye por completo a JSON-RPC. ### ¿Qué diferencia hay entre un nodo completo y un nodo podado? Ambos validan Bitcoin. Un nodo completo conserva los archivos de bloques antiguos, mientras que un nodo podado elimina la mayoría después de validarlos para ahorrar espacio. Un nodo podado no puede responder a todas las solicitudes de datos históricos ni mantener un índice completo de transacciones. ### ¿Cuánto cuesta operar un nodo completo de Bitcoin? La fuente calcula entre $20 y $80 al mes para configuraciones habituales de VPS, según el almacenamiento y el ancho de banda. El hardware doméstico puede costar aproximadamente entre $200 y $400 por adelantado. Las grandes plataformas en la nube pueden costar mucho más. Los precios cambian, así que calcula el hardware y el tráfico actuales antes de comprar. ### ¿Qué proveedores admiten signet de Bitcoin? La comparación de mediados de 2026 incluye a Chainstack, Alchemy y Blockstream Esplora con compatibilidad para signet. Un nodo Bitcoin Core autoalojado también admite signet. Confirma la disponibilidad actual de la red antes de elegir un plan. ### ¿Bitcoin Core admite WebSocket? No de forma nativa. Bitcoin Core usa ZeroMQ para las notificaciones push. Los proveedores que anuncian Bitcoin WebSocket suelen añadir otra capa de indexación o eventos, en lugar de ofrecer compatibilidad WebSocket de Bitcoin Core. ### ¿Qué debería usar una configuración de producción? Un diseño habitual usa un nodo autoalojado como fuente principal y un proveedor alojado como alternativa independiente. Los productos más pequeños pueden empezar con dos puntos de acceso alojados. Lo importante es probar la conmutación por error en vez de dar por hecho que funciona. ## Fuentes y nota de actualización Los precios, los límites, las redes compatibles y las listas de métodos cambian. Las cifras de la comparación reflejan la situación a mediados de 2026 según el resumen enlazado de Spark. Consulta la documentación actual del proveedor antes de tomar una decisión sobre infraestructura. 1. [Spark: resumen de proveedores RPC de Bitcoin](https://www.spark.money/tools/bitcoin-rpc-provider-comparison) 2. [Documentación de Bitcoin Core](https://bitcoincore.org/en/doc/) 3. [QuickNode](https://www.quicknode.com/) 4. [GetBlock](https://getblock.io/) 5. [Chainstack](https://chainstack.com/) 6. [Alchemy](https://www.alchemy.com/) 7. [Blockdaemon](https://www.blockdaemon.com/) 8. [NOWNodes](https://nownodes.io/) 9. [API Blockstream Esplora](https://blockstream.info/api/) ## También disponible en - [Bitcoin RPC providers, explained without the jargon](https://nuri.com/knowledge/bitcoin-rpc-providers) (en) - [Bitcoin-RPC-Anbieter, verständlich und ohne Fachjargon erklärt](https://nuri.com/de/wissen/bitcoin-rpc-anbieter) (de) - [Provider RPC per Bitcoin, spiegati senza gergo tecnico](https://nuri.com/it/conoscenza/provider-rpc-bitcoin) (it) --- --- title: "Provider RPC per Bitcoin, spiegati senza gergo tecnico" description: "Confronta i provider RPC per Bitcoin, comprendi i nodi in hosting e il self-hosting e scegli la soluzione più semplice per la tua app, senza gergo tecnico." lang: "it" type: "knowledge-guide" datePublished: "2026-08-21" dateModified: "2026-08-21" canonical: "https://nuri.com/it/conoscenza/provider-rpc-bitcoin" tags: ["provider RPC per Bitcoin","provider di nodi Bitcoin","Bitcoin JSON-RPC","nodo Bitcoin in hosting","nodo completo Bitcoin","API Bitcoin","infrastruttura Bitcoin"] --- # Provider RPC per Bitcoin, spiegati senza gergo tecnico **TL;DR:** Un provider RPC per Bitcoin consente a un’app di leggere i dati di Bitcoin e inviare transazioni senza dover mantenere un proprio nodo Bitcoin. I servizi in hosting sono più facili per iniziare. Un nodo proprio offre più privacy, controllo e possibilità di accesso. Molti prodotti importanti usano entrambe le soluzioni. Se utilizzi soltanto un wallet come Nuri, non devi scegliere alcun provider RPC. ## Indice - [La risposta breve](#quick-answer) - [Che cosa significa RPC in parole semplici](#what-rpc-means) - [Hai davvero bisogno di un provider RPC?](#do-you-need-one) - [Confronto tra provider](#comparison) - [In che cosa è davvero utile ogni opzione](#provider-notes) - [Perché la copertura dei metodi è importante](#method-coverage) - [Gestire un nodo Bitcoin proprio](#run-your-own-node) - [Privacy, fiducia e ciò che le tabelle dei prezzi non mostrano](#privacy-and-trust) - [Una guida alla scelta che richiede cinque minuti](#how-to-choose) - [Il piccolo glossario](#glossary) - [Le domande che le persone fanno davvero](#faq) ## La risposta breve **In breve:** Un provider RPC è come un telecomando per un nodo Bitcoin. La tua app fa domande o invia una transazione. Il provider gestisce la parte tecnica. Un’app Bitcoin ha bisogno di un modo affidabile per vedere che cosa succede sulla rete Bitcoin. Potrebbe dover controllare se è arrivato un pagamento, leggere una transazione, stimare una commissione adeguata o inviare una transazione firmata. Un nodo Bitcoin può rispondere a queste richieste. Gestire quel nodo in autonomia richiede spazio di archiviazione, larghezza di banda, manutenzione e tempo. Un provider RPC per Bitcoin in hosting gestisce il nodo per te e fornisce alla tua app un indirizzo internet con cui comunicare. RPC significa chiamata di procedura remota. Il nome sembra più complicato del compito. Questa comodità ha un costo. Il provider può vedere le tue richieste, applicare limiti, modificare i prezzi o interrompere il servizio. Un nodo gestito da te offre più privacy e controllo, ma sei tu a doverlo mantenere efficiente. Non esiste un vincitore assoluto, perché la scelta giusta dipende da ciò che stai costruendo. ## Che cosa significa RPC in parole semplici **In breve:** La tua app invia una domanda precisa a un nodo Bitcoin e riceve una risposta precisa. Quella richiesta e la relativa risposta sono l’RPC. Immagina un nodo Bitcoin come una biblioteca che conserva una copia verificata della storia di Bitcoin e segue la rete mentre arrivano nuovi blocchi. RPC è il banco informazioni. La tua app non percorre tutta la biblioteca, ma chiede una cosa specifica. Una richiesta potrebbe significare: dammi il blocco 900.000, dimmi se questa transazione è conosciuta, mostrami la stima attuale delle commissioni oppure diffondi questa transazione già firmata. Bitcoin Core, il software per nodi più diffuso, mette a disposizione circa 150 comandi per attività come queste. Il provider normalmente non custodisce i tuoi bitcoin solo perché utilizzi il suo endpoint RPC. Una buona architettura wallet firma le transazioni con le chiavi dell’utente prima di inviarle al nodo. Le query possono comunque rivelare informazioni utili sul wallet, come gli indirizzi che sta monitorando. Per questo la privacy fa parte della scelta del provider. - Leggere i dati della blockchain: blocchi, transazioni e conferme. - Controllare la mempool: transazioni in attesa di conferma. - Stimare le commissioni: una valutazione pratica per ottenere una conferma in tempi adeguati. - Diffondere una transazione firmata: inoltrarla alla rete Bitcoin. ## Hai davvero bisogno di un provider RPC? **In breve:** Chi usa un wallet di solito non deve fare nulla. Chi sviluppa app spesso ne ha bisogno. I team attenti alla privacy o con molta infrastruttura possono preferire un nodo proprio. Se usi Nuri o un altro wallet per consumatori, di solito la risposta è no. Il wallet gestisce autonomamente la connessione a Bitcoin. Non hai bisogno di un account presso QuickNode, Chainstack o un’altra società di infrastruttura. Se stai sviluppando un’app che legge o invia transazioni Bitcoin, devi poter accedere in qualche modo a un nodo. Un provider in hosting è il modo più rapido per iniziare. Ricevi un endpoint e una chiave API, poi la tua app può inviare richieste entro i limiti del piano. Se gestisci il backend di un wallet, monitori molti indirizzi, hai bisogno di ogni comando Bitcoin Core o non vuoi che un’altra azienda osservi le tue richieste, un nodo proprio diventa più interessante. I sistemi importanti spesso usano prima un nodo ospitato autonomamente e mantengono un endpoint in hosting come riserva. - Usi un wallet Bitcoin: probabilmente non devi scegliere alcun provider. - Sviluppi un prototipo: inizia con un piano gratuito in hosting. - Gestisci un servizio di pagamento in produzione: confronta disponibilità, limiti, privacy e alternative di riserva. - Sviluppi un’infrastruttura wallet attenta alla privacy: gestisci un nodo proprio o progetta con cura una soluzione ibrida. ## Confronto tra provider **In breve:** Le offerte gratuite usano unità diverse, quindi quella che sembra più ampia non è sempre la più generosa. Confronta il lavoro di cui hai bisogno, non soltanto il numero in evidenza. La tabella seguente fotografa la situazione a metà 2026 in base alle informazioni pubbliche raccolte da Spark. I piani cambiano. Usala come mappa del mercato, poi verifica prezzi e limiti attuali sul sito del provider prima di decidere. Crediti, unità di calcolo, unità di richiesta e semplici richieste non sono direttamente equivalenti. Alcuni provider addebitano diverse unità per una singola chiamata Bitcoin. Le query storiche o di archivio possono costare di più. I piani gratuiti possono anche limitare la velocità, nonostante un tetto mensile apparentemente generoso. | Opzione | Ideale per | Accesso gratuito | Piano a pagamento da | Velocità gratuita | Disponibilità | Signet | | --- | --- | --- | --- | --- | --- | --- | | QuickNode | Configurazione rapida e componenti aggiuntivi | 10M crediti/mese | $49/mese | 15/s | 99.99% | No | | GetBlock | Accesso a basso costo | 50K unità di calcolo/giorno | circa $23/mese | 20/s | 99% condiviso | No | | Chainstack | Ampia copertura RPC | 3M unità di richiesta/mese | $49/mese | 25/s | 99.9% | Sì | | Alchemy | Team che usano già Alchemy | 30M unità di calcolo/mese | $0.45/M unità | 25/s | 99.99% | Sì | | Blockdaemon | Conformità istituzionale | 3M unità di calcolo/mese | Contatta il reparto vendite | 5/s | 99.9% | No | | NOWNodes | Prezzi semplici per richiesta | 100K richieste, prova di un mese | €20/mese | 15/s | 99.95% | No | | Blockstream Esplora | Query gratuite in sola lettura | circa 500K richieste/mese | Personalizzato | circa 50/s | 99.9% | Sì | | Il tuo nodo Bitcoin Core | Privacy e controllo totale | Chiamate illimitate | $20–80/mese per VPS o hardware domestico | Dipende dall hardware | Lo gestisci tu | Sì | - Le chiamate Bitcoin di QuickNode possono consumare più crediti. - Alchemy indica 30M unità di calcolo, pari a circa 3M chiamate Bitcoin quando ciascuna costa 10 unità. - Esplora è un’API REST, non un endpoint JSON-RPC completo di Bitcoin Core. - Una percentuale di disponibilità non descrive la qualità dell’assistenza, la latenza regionale o la velocità con cui un provider risolve un incidente. ## In che cosa è davvero utile ogni opzione **In breve:** Scegli in base al tuo carico di lavoro reale. Chainstack copre molti comandi standard. Esplora è semplice per i dati in sola lettura. Un nodo proprio offre il massimo controllo. Le pagine dei provider tendono ad aprirsi con numeri molto grandi. Quei numeri contano meno della possibilità che il servizio offra i comandi necessari alla tua app, restituisca dati storici, supporti la tua rete di test e ti permetta di crescere senza una fattura imprevista. ### QuickNode _Un inizio ben rifinito e componenti aggiuntivi opzionali per i dati._ QuickNode è un grande provider multichain che supporta la mainnet Bitcoin e Testnet4. I suoi nodi in hosting conservano tutti i dati storici, quindi un’app può cercare vecchi blocchi e transazioni. La differenza utile è il catalogo di componenti aggiuntivi. I metodi Blockbook possono semplificare le query sui saldi degli indirizzi, gli UTXO e le chiavi pubbliche estese. Le API per Ordinals e Runes sono extra separati. Possono risparmiare lavoro quando i semplici comandi Bitcoin Core non bastano. **Fai attenzione a:** I crediti non equivalgono alle chiamate, i componenti aggiuntivi costano di più e il supporto Bitcoin WebSocket non è disponibile. ### GetBlock _Un punto di accesso in hosting più economico con diversi modelli di fatturazione._ GetBlock documenta meno comandi Bitcoin rispetto a Bitcoin Core, ma copre le attività comuni: dati della blockchain, mempool, transazioni grezze, stime delle commissioni e flussi di lavoro PSBT. Il suo Limitless Node a tariffa fissa può facilitare il budget in caso di traffico prevedibile. I nodi dedicati costano molto di più, ma eliminano i limiti condivisi. Le regioni includono Francoforte, New York e Singapore. **Fai attenzione a:** La garanzia di disponibilità per i nodi condivisi è del 99% e i comandi wallet non sono disponibili sull’infrastruttura condivisa. ### Chainstack _Ampia copertura RPC standard e supporto per signet._ Chainstack documenta 139 metodi Bitcoin JSON-RPC, la copertura più ampia del confronto. I suoi nodi Bitcoin condivisi conservano tutta la cronologia e abilitano l’indice delle transazioni, rendendo possibile interrogare le vecchie transazioni. Supporta anche signet, una rete di test Bitcoin prevedibile. I comandi relativi ai wallet richiedono comunque un nodo dedicato, quindi un’ampia copertura non significa che ogni comando sia disponibile nel normale piano condiviso. **Fai attenzione a:** Le richieste di tipo archivio possono usare più unità di richiesta e la promessa di crediti di servizio del 99.9% è legata alle condizioni enterprise. ### Alchemy _Team che usano già Alchemy per Ethereum o altre blockchain._ Alchemy porta Bitcoin su una piattaforma già usata da molti sviluppatori. Copre le comuni attività di lettura, mempool, diffusione e commissioni e supporta mainnet, Testnet3, Testnet4 e signet. La quota gratuita sembra molto più grande perché è espressa in unità di calcolo. Spark stima circa 3 milioni di chiamate Bitcoin quando ciascun metodo costa 10 unità. I dati di archivio sono inclusi. **Fai attenzione a:** L’insieme di metodi Bitcoin è più ridotto di quello di Chainstack, i metodi wallet sono assenti e il supporto WebSocket non è documentato. ### Blockdaemon _Istituzioni che richiedono prove di conformità e assistenza dedicata._ Blockdaemon si rivolge agli acquirenti istituzionali ed elenca le certificazioni ISO 27001 e SOC 2 Type II. Espone metodi Bitcoin standard e funzioni proprietarie per saldi, UTXO e cronologia delle transazioni per indirizzo. È meno interessante per un prototipo del fine settimana, perché le informazioni pubbliche sui prezzi sono limitate e la velocità gratuita è bassa. Ha più senso quando acquisti, conformità e impegni di assistenza fanno parte della decisione. **Fai attenzione a:** Per conoscere i prezzi a pagamento bisogna parlare con il reparto vendite, signet non è elencato e il supporto Bitcoin WebSocket è assente. ### NOWNodes _Chi preferisce un conteggio semplice delle richieste e un prezzo iniziale pubblicato basso._ NOWNodes conta le richieste invece di inventare un’altra unità. L’accesso all’archivio è incluso e i piani a pagamento includono l’accesso WebSocket tramite il più ampio sistema di indicizzazione del provider. Il prezzo iniziale è inferiore a quello di molti concorrenti, ma il piano gratuito è una prova di un mese, non un livello gratuito permanente. I nodi Bitcoin dedicati sono un prodotto separato e molto più costoso. **Fai attenzione a:** La quota gratuita scade, signet non è disponibile e l’hosting dedicato parte da prezzi molto superiori rispetto ai piani condivisi. ### Blockstream Esplora _Dati Bitcoin semplici e in sola lettura, senza un servizio RPC completo._ Esplora è diverso da tutte le altre opzioni in hosting presenti qui. È un’API REST open source per blocchi, transazioni, indirizzi, UTXO, dati della mempool e stime delle commissioni. Puoi utilizzare il servizio pubblico di Blockstream o ospitare autonomamente il software. Per un’app che controlla soltanto saldi e transazioni, questa interfaccia più semplice può essere sufficiente. Non espone l’intero insieme di comandi Bitcoin Core, i controlli wallet o i comandi di mining. **Fai attenzione a:** Non sostituisce direttamente JSON-RPC. Verifica i requisiti di diffusione e i limiti di velocità per il tuo carico di lavoro. ## Perché la copertura dei metodi è importante **In breve:** Ogni provider gestisce le letture di base e la diffusione delle transazioni. Il controllo dei wallet e l’amministrazione del nodo sono in genere bloccati sui servizi condivisi. Bitcoin Core mette a disposizione molti comandi perché un nodo completo può fare molto più che cercare una transazione. Può gestire wallet, creare transazioni parzialmente firmate, controllare i peer, modificare le impostazioni del nodo e supportare attività di mining. Un provider condiviso non può concedere in sicurezza questo livello di controllo a ogni cliente. La maggior parte delle app ha bisogno di un piccolo insieme comune: leggere un blocco, leggere una transazione, controllare la mempool, stimare una commissione e diffondere una transazione firmata. Se questo è il tuo carico di lavoro, quasi tutte le opzioni della tabella possono funzionare. Se ti servono comandi wallet o un’indicizzazione insolita, leggi l’elenco dei metodi prima di sviluppare l’integrazione. | Funzionalità | Bitcoin Core | La maggior parte dei piani in hosting | Perché è importante | | --- | --- | --- | --- | | Blocchi e conferme | Sì | Sì | Sapere se e quando un pagamento è stato regolato. | | Transazioni grezze | Sì | Di solito | Leggere o inviare i dati di una transazione. | | Stime delle commissioni | Sì | Sì | Evitare di pagare molto più del necessario o di aspettare troppo. | | Controllo della mempool | Sì | Di solito | Capire le transazioni ancora in attesa. | | Strumenti PSBT | Sì | Dipende | Coordinare le firme senza esporre le chiavi private. | | Metodi wallet | Sì | Di solito no | Creare indirizzi e gestire un wallet del nodo. | | Amministrazione del nodo | Sì | No | Controllare peer, indici e impostazioni del nodo. | | Funzioni per la cronologia degli indirizzi | Richiede un indicizzatore | Talvolta come componente aggiuntivo | Bitcoin Core non offre automaticamente tutte le query utili per un wallet. | ## Gestire un nodo Bitcoin proprio **In breve:** Sostituisci la fattura del provider con hardware, larghezza di banda e responsabilità. In cambio, scegli le regole, mantieni private le query ed elimini i limiti di velocità. L’hosting autonomo è la scelta migliore per privacy e controllo. Le tue richieste rimangono nella tua infrastruttura, decidi quale versione di Bitcoin Core eseguire e puoi usare l’intero insieme di comandi senza una chiave API o una tariffa per richiesta. Il lavoro operativo è concreto. Un nodo completo richiede circa 1 TB di spazio SSD per avere un margine adeguato. L’istantanea di origine stima circa 745 GB di dati della blockchain a metà 2026, con una crescita di circa 70-80 GB all’anno. La sincronizzazione iniziale può richiedere da due a sette giorni su hardware moderno. Un nodo potato convalida l’intera blockchain, ma elimina i vecchi file dei blocchi. Può funzionare con molto meno spazio, a volte circa 10 GB per i dati dei blocchi, ma non può rispondere a tutte le richieste di transazioni storiche né mantenere un indice completo delle transazioni. La potatura è ottima quando ti serve una verifica indipendente ma non un archivio pubblico completo. A casa, un mini PC o un Raspberry Pi 5 con SSD esterno può costare circa $200-$400 iniziali. Un VPS economico può costare circa $20-$50 al mese. Le piattaforme cloud più grandi possono costare molto di più, soprattutto quando larghezza di banda e spazio vengono fatturati separatamente. Queste cifre cambiano con i prezzi di hardware e hosting. - Scegli un nodo completo quando ti serve la cronologia completa o txindex. - Scegli un nodo potato quando la verifica conta più dell’accesso ai vecchi blocchi. - Mantieni un servizio in hosting di riserva se un’interruzione bloccherebbe il tuo prodotto. - Monitora la crescita del disco, lo stato della sincronizzazione, i backup e gli aggiornamenti software. ## Privacy, fiducia e ciò che le tabelle dei prezzi non mostrano **In breve:** L’endpoint vede che cosa chiedi. Le query ripetute su indirizzi e transazioni possono rivelare come viene usato un wallet, anche se il provider non vede mai la chiave privata. Un nodo remoto conosce il momento e il contenuto delle tue richieste. Se la tua app interroga ripetutamente gli stessi indirizzi, il provider potrebbe raggruppare quelle richieste. Se le collega al tuo account, alla chiave API o all’indirizzo di rete, può scoprire più di quanto suggerisca una semplice tabella dei prezzi. Usare diversi provider pubblici non risolve automaticamente il problema. Può distribuire le stesse informazioni tra più aziende. Un software wallet attento alla privacy può usare tecniche come filtri compatti dei blocchi, instradamenti di rete privati o un nodo scelto dall’utente, ma ogni soluzione comporta compromessi. La fiducia riguarda anche correttezza e disponibilità. Un provider può restituire dati obsoleti, limitare le richieste o subire un’interruzione. La tua app dovrebbe controllare gli errori, rifiutare risposte impossibili ed evitare di trattare un singolo endpoint come una verità indiscutibile. Per un prodotto di pagamento, una seconda fonte indipendente può aiutare a distinguere un incidente del provider da un evento della rete Bitcoin. ## Una guida alla scelta che richiede cinque minuti **In breve:** Elenca prima le attività esatte, il traffico e le esigenze di privacy. Poi elimina i provider che non possono soddisfarle. Il prezzo viene dopo l’idoneità. Inizia dalla descrizione più breve e onesta della tua app. «Ci servono dati Bitcoin» è troppo vago. «Controlliamo 20.000 indirizzi ogni ora, leggiamo vecchie transazioni, stimiamo le commissioni e diffondiamo transazioni firmate» è utile. Questa frase ti dice se hai bisogno di un indice degli indirizzi, di una cronologia di archivio e quale limite di velocità potrebbe creare problemi. 1. **Annota i comandi o i risultati di cui hai bisogno.** Se non conosci ancora i nomi dei comandi, descrivi l’azione dell’utente: controllare un pagamento, mostrare la cronologia delle transazioni, stimare una commissione, diffondere una transazione firmata o gestire un wallet sul server. 2. **Stima il traffico normale e quello di picco.** Le quote mensili non servono se un breve picco di traffico raggiunge un limite al secondo. Includi nuovi tentativi, sincronizzazione in background e crescita. 3. **Decidi che cosa può sapere il provider.** Il monitoraggio degli indirizzi e le query dei wallet richiedono più attenzione di un indicatore pubblico dell’altezza dei blocchi. 4. **Verifica i guasti prima della produzione.** In un ambiente di test, rimuovi l’endpoint, attiva un limite di velocità e restituisci dati obsoleti. La tua app dovrebbe fallire in modo chiaro e riprendersi senza problemi. 5. **Mantieni una via d’uscita.** Usa le chiamate standard di Bitcoin Core quando possibile, isola i componenti aggiuntivi specifici del provider e scopri quanto tempo servirebbe per cambiare endpoint. ## Il piccolo glossario **In breve:** Ti bastano pochi termini per capire la maggior parte delle pagine dei provider. **Nodo Bitcoin:** Software che verifica le regole di Bitcoin e condivide blocchi e transazioni con la rete. **Bitcoin Core:** Il software per nodi Bitcoin più utilizzato. Include l’interfaccia JSON-RPC standard. **RPC:** Un modo strutturato con cui un programma chiede a un altro di svolgere un’attività o restituire dati. **JSON-RPC:** Il formato dei messaggi usato da Bitcoin Core per le richieste e le risposte RPC. **Mempool:** Le transazioni note a un nodo che non sono ancora state incluse in un blocco. **UTXO:** Una quantità di bitcoin che può essere spesa. I saldi dei wallet sono composti da uno o più UTXO. **Nodo di archivio o non potato:** Un nodo che conserva i vecchi dati dei blocchi e può rispondere alle richieste storiche. **Nodo potato:** Un nodo che convalida tutto, ma rimuove i vecchi file dei blocchi per risparmiare spazio. **txindex:** Un indice opzionale di Bitcoin Core che semplifica la ricerca di qualsiasi transazione storica. **Testnet:** Una rete Bitcoin pubblica per i test, con monete che non hanno un valore monetario previsto. **Signet:** Una rete di test Bitcoin più controllata, con una produzione di blocchi più regolare. **Regtest:** Una rete di test Bitcoin locale e privata nella quale uno sviluppatore crea blocchi quando servono. **RPS:** Richieste al secondo, un limite di velocità sul numero di chiamate che puoi effettuare. **SLA:** Un accordo sul livello di servizio, di solito una promessa scritta di disponibilità con condizioni specifiche. ## Le domande che le persone fanno davvero **In breve:** L’RPC in hosting è la soluzione più semplice. Un nodo proprio offre la massima indipendenza. Una soluzione ibrida è comune quando contano sia la disponibilità sia il controllo. ### Che cos’è un provider RPC per Bitcoin? È un’azienda che gestisce nodi Bitcoin e permette alla tua app di comunicare con essi tramite internet. La tua app può leggere blocchi e transazioni, stimare le commissioni e in genere diffondere transazioni firmate senza dover mantenere un nodo proprio. ### Quale provider RPC per Bitcoin offre il miglior piano gratuito? Per un uso ampio di JSON-RPC nella panoramica di metà 2026, Chainstack e Alchemy corrispondono ciascuno a circa 3 milioni di chiamate di base al mese, ma usano unità diverse. Blockstream Esplora è interessante per le query REST gratuite in sola lettura. Il piano gratuito migliore è quello che include il metodo, la rete e il picco di richieste di cui hai bisogno. ### Devo gestire un nodo Bitcoin proprio? Gestiscine uno quando la privacy delle query, l’accesso completo ai comandi o l’indipendenza da un provider sono abbastanza importanti da giustificare la manutenzione. Un endpoint in hosting di solito basta per prototipi e app semplici basate su dati pubblici. Molti sistemi in produzione usano un nodo proprio e un servizio in hosting di riserva. ### Un provider RPC può rubare i miei bitcoin? L’uso di un endpoint per la lettura e la diffusione non dovrebbe rivelare le tue chiavi private. Il wallet dovrebbe firmare le transazioni localmente. Un provider può comunque osservare le richieste, restituire dati errati o compromettere la disponibilità. Per questo l’architettura del wallet deve verificare le risposte e mantenere le chiavi fuori dal servizio RPC. ### Qual è la differenza tra un’API Bitcoin e l’RPC Bitcoin? RPC Bitcoin indica in genere comandi strutturati come quelli di Bitcoin Core. Un’API Bitcoin può offrire endpoint REST più semplici, la cronologia degli indirizzi o dati indicizzati che Bitcoin Core non fornisce direttamente. Esplora è un buon esempio di API utile che non sostituisce completamente JSON-RPC. ### Qual è la differenza tra un nodo completo e un nodo potato? Entrambi convalidano Bitcoin. Un nodo completo conserva i vecchi file dei blocchi, mentre un nodo potato ne elimina la maggior parte dopo la convalida per risparmiare spazio. Un nodo potato non può rispondere a tutte le richieste di dati storici e non può mantenere un indice completo delle transazioni. ### Quanto costa gestire un nodo Bitcoin completo? L’istantanea di origine stima un costo di circa $20-$80 al mese per le comuni configurazioni VPS, a seconda dello spazio e della larghezza di banda. L’hardware domestico può costare circa $200-$400 iniziali. Le grandi piattaforme cloud possono costare molto di più. I prezzi cambiano, quindi calcola l’hardware e il traffico attuali prima dell’acquisto. ### Quali provider supportano signet di Bitcoin? Il confronto di metà 2026 indica Chainstack, Alchemy e Blockstream Esplora con supporto per signet. Anche un nodo Bitcoin Core ospitato autonomamente supporta signet. Verifica la disponibilità attuale della rete prima di scegliere un piano. ### Bitcoin Core supporta WebSocket? Non in modo nativo. Bitcoin Core usa ZeroMQ per le notifiche push. I provider che pubblicizzano Bitcoin WebSocket di solito aggiungono un ulteriore livello di indicizzazione o di eventi, invece di offrire il supporto WebSocket di Bitcoin Core. ### Che cosa dovrebbe usare una configurazione di produzione? Un’architettura comune usa un nodo ospitato autonomamente come fonte principale e un provider in hosting come alternativa indipendente. I prodotti più piccoli possono iniziare con due endpoint in hosting. La cosa importante è verificare il failover invece di presumere che funzioni. ## Fonti e nota di aggiornamento Prezzi, limiti, reti supportate ed elenchi dei metodi cambiano. Le cifre del confronto fotografano la situazione a metà 2026 in base alla panoramica Spark collegata. Controlla la documentazione attuale del provider prima di prendere una decisione sull’infrastruttura. 1. [Spark: panoramica dei provider RPC per Bitcoin](https://www.spark.money/tools/bitcoin-rpc-provider-comparison) 2. [Documentazione di Bitcoin Core](https://bitcoincore.org/en/doc/) 3. [QuickNode](https://www.quicknode.com/) 4. [GetBlock](https://getblock.io/) 5. [Chainstack](https://chainstack.com/) 6. [Alchemy](https://www.alchemy.com/) 7. [Blockdaemon](https://www.blockdaemon.com/) 8. [NOWNodes](https://nownodes.io/) 9. [API Blockstream Esplora](https://blockstream.info/api/) ## Disponibile anche in - [Bitcoin RPC providers, explained without the jargon](https://nuri.com/knowledge/bitcoin-rpc-providers) (en) - [Bitcoin-RPC-Anbieter, verständlich und ohne Fachjargon erklärt](https://nuri.com/de/wissen/bitcoin-rpc-anbieter) (de) - [Proveedores RPC de Bitcoin, explicados sin tecnicismos](https://nuri.com/es/conocimiento/proveedores-rpc-bitcoin) (es) --- --- title: "The arrayref supply chain attack, and why your wallet needs no single point of failure" description: "A 2-hour supply chain breach of a Rust crate with 245 million downloads, and what it means for the software that touches your money." lang: "en" type: "knowledge-guide" datePublished: "2026-08-21" dateModified: "2026-08-21" canonical: "https://nuri.com/knowledge/supply-chain-attack-arrayref" tags: ["software supply chain attack","arrayref crate","single point of failure","self-custody","bitcoin wallet security","MuSig2","stateless co-signing"] --- # The arrayref supply chain attack, and why your wallet needs no single point of failure **TL;DR:** Attackers compromised the account of a well-known Rust library and published a fake version that ran malware on a machine the moment someone built it. The bad version sat online for about 86 minutes, and the library has 245 million downloads. This is one of a wave of supply chain attacks that are getting more frequent and more aggressive. The bigger lesson for anyone whose money depends on software is that the code and the servers between you and your funds are a single point of failure. Nuri is built so that no single compromise, not a compromised app and not a hacked server, exposes the key that controls your bitcoin. Only one key ever sits on the phone. The second share lives with a stateless service. Stealing the money takes both. ## Contents - [The quick answer](#quick-answer) - [What actually happened](#what-happened) - [Why this is the new normal](#new-normal) - [What developers are saying](#what-developers-say) - [When the code controls the money](#why-it-matters) - [The single point of failure problem](#single-point) - [How Nuri removes it](#how-nuri) - [Wallet models, compared on one question](#comparison) - [The small glossary](#glossary) - [Questions people ask](#faqs) ## The quick answer **Basically,** A fake version of a popular library ran malware on machines during the build. The lesson: the software between you and your money is a single point of failure, so design it so no one compromise wins. On August 20, 2026, a report came in that a Rust library called proc-macro1 was malicious. The Rust Security Response Team confirmed it within minutes: the crate carried a build script that downloaded and ran a remote payload. Building any project that pulled in the crate was enough to execute it. Nobody had to call any function. The build itself was the trigger. The real target was arrayref, a small, well-known crate used by a huge number of other projects. Its owner account had been compromised. The attacker published a new version of arrayref that depended on the fake crate, and quietly yanked the old versions so that the build tool would point users at the bad one. None of this is about Rust specifically. It is about how software gets built: we all rely on thousands of pieces written by other people, and any one of them can be the one that is quietly poisoned. When the thing holding your money is software, that stops being a developer problem and becomes a money problem. ## What actually happened **Basically,** A compromised maintainer account shipped a fake dependency. Building the crate downloaded and ran a backdoor that steals credentials. The whole thing was online for under two hours. The attacker did not rewrite the library. They added one line: a dependency on proc-macro1, a deliberate misspelling of proc-macro2, one of the most downloaded crates in the entire ecosystem. The fake crate is a genuine copy of the real one, so the build succeeds and the software still works. That is exactly the point. Nothing looks broken. The payload runs before you notice anything at all. The build script quietly reconstructed the attacker server address from pieces of encoded text, turned off the security check that verifies the server is who it claims to be, and then downloaded a program chosen for your operating system and processor. On Mac and Linux it wrote the file to a temporary folder and launched it in the background. On Windows it wrote a script and started it hidden. The attacker chose all of this to avoid being noticed while the build was happening. The backdoor that was downloaded is a real piece of malware, not a test. Security researchers who analyzed it found that it phones home, reads your computer name and user, lists your installed programs, and looks through your browser profile for saved logins. It installs itself so it comes back after a restart. It can download and run more code on demand. If the main server goes down, it generates fresh domain names to find a new one. The malicious versions were deleted quickly: arrayref 0.3.10 was online for about 86 minutes, and the two related crates for about 90 and 107 minutes. The Rust team locked the owner account as a precaution and said they do not believe the author was acting in bad faith. Their computer or login is more likely the part that was compromised. The author of arrayref has been maintaining the crate since 2009. Wiz, a security company, found that the attacker infrastructure overlaps with recent operations attributed to North Korea, including campaigns against other popular libraries. This was not a one-off by a random script kiddie. It was an organized campaign using a pattern they have used before. - Target: arrayref 0.3.10, internment 0.8.7 and append-only-vec 0.1.9, all from one compromised account. - Vehicle: a new dependency, proc-macro1, a misspelling of the ubiquitous proc-macro2. - Trigger: the build itself. Running cargo build on an affected project executed the payload. - Online: 86 to 107 minutes before deletion on 2026-08-20. - Scale: arrayref has 245 million downloads and appears in the majority of environments that use Rust. ## Why this is the new normal **Basically,** Supply chain attacks are not a rare edge case. They are a growing, industrialized, and increasingly automated part of how the internet is attacked. The arrayref attack feels shocking because it hit a popular, trusted library. But the numbers say it should not. The same class of attack has been running against every major package registry for years, and the rate is climbing. Vendors that track this report more than a million malicious packages found across npm, PyPI, Maven, NuGet and Hugging Face, with the count of new malicious packages in 2025 up about 75 percent from the year before. The estimated cost of supply chain attacks reached roughly 60 billion dollars in 2025, with projections near 138 billion by 2030. Around 30 percent of data breaches now involve a third party, and the large majority of vulnerabilities in commercial software are found not in the main code but in the dependencies it pulls in. Two things are making it worse at the same time. First, the tooling that builds and runs software has gotten more complex, so there are more moving parts an attacker can touch. Second, the attackers are using AI to find targets, write the malicious code, and scale the campaign, while the people responsible for reviewing every dependency are mostly unpaid volunteers. The uncomfortable truth on Hacker News, where the main thread hit 400 points and hundreds of comments, is that developers see this coming. One of the most upvoted observations was that the build tooling runs code on your machine without your consent, so adding a dependency is enough to compromise you before you ever review the code. Another pointed out that the same thing happened with the xz compression library compromise, and nobody can read every small package in the deep dependency tree to prove it is clean. ## What developers are saying **Basically,** The reaction is not panic. It is a tired, informed recognition that the build tooling was never designed to be a security boundary. The Hacker News discussion was unusually calm and specific, which is usually the sign of an experienced community dealing with a known problem. Here is what kept coming up, in their own words, lightly trimmed. On why it keeps happening: "Why after many previous supply chain attacks do maintainers of package repositories still allow anyone uploading packages and pushing updates without security audit?" That question was not rhetorical. The follow-up was the real problem: "Who is funding this security audit? Are folks supposed to volunteer their free time?" On the build tooling: "The problem is that build scripts run automatically without user consent or intervention. Adding a dependency is sufficient to compromise you, before you have a chance to even vet the code." Several people noted that other package managers have controls that Cargo does not, such as allow-listing install scripts and putting a cooldown on brand new dependencies. On the target: "Developer machines are quite juicy targets. They tend to have all sorts of credentials lying around, so it is often not too difficult to escalate from that to compromising your cloud accounts." That is the real prize in most of these attacks. It is not the one machine. It is everything that machine can reach. On whether the language matters: "Rust seems barely better than Node in this regard." The counterargument, also widely shared, is that the ecosystem already has audit tools, and several large companies publish audits of the crates they depend on. The gap is that auditing is the exception, not the default. One detail stood out. Several people asked what the malicious code actually does, and the answer was that nobody could be sure, because the author account was deleted and the malicious releases were wiped from the registry rather than just withdrawn. The attacker cleaned up after themselves. That is a hallmark of an operation that has done this before. ## When the code controls the money **Basically,** A supply chain attack on a website is annoying. A supply chain attack on the software that holds your money is a different problem entirely. Most supply chain attacks target developers and companies, and the damage is stolen credentials, stolen data, or a slow, expensive cleanup. The blast radius is a build server or a corporate account. A wallet is different. The whole point of the software is to be able to move your money. If the code in that software, or the servers it depends on, can be compromised, then the compromise can go straight to the funds. There is no layer of "oops, we lost some logins" between the attacker and your balance. This is why the supply chain problem and the self-custody problem are the same problem. Both are about where the key that controls your money actually lives, and whether any single point in the chain, a library, a company, a server, a maintainer, a vendor, can take it. ## The single point of failure problem **Basically,** A single point of failure is the one thing that, if it breaks or is taken, loses everything. Most wallets have one. The goal is to have none. A single point of failure is simple to define and hard to design away. It is the one component that, if it is compromised or it goes down, means the whole thing fails. For a custodial exchange, it is their servers. If those are breached, or if they simply freeze your account, your money is at their mercy. For a software wallet that derives your key from one secret on your device, it is that one secret. If the app is compromised through a poisoned update, or your device is taken, the secret is exposed. The reason these designs have a single point of failure is that they are convenient. One place to put the key means one place to sign from and one place to back up. Convenience and safety pull in opposite directions, and most products pick convenience. There is a better shape. Split the authority to move your money across two or more things that an attacker would have to take together, and make sure none of them holds the whole key by itself. Then no single compromise, a bad library, a hacked server, a stolen phone, a malicious update, wins on its own. The attacker has to succeed twice, in two different places, at the same time. That is the difference between a target and a fortress. ## How Nuri removes it **Basically,** Nuri uses a split-signature model where only one key ever sits on the phone, and the second share is stateless, so neither the app nor the server alone exposes your key. Nuri is built on a split-signature scheme called MuSig2, in the 2-of-2 form that can be expanded to 2-of-3. Two separate shares are needed to sign and move the funds, and no single share can do it alone. On your phone, only one key ever exists: your own key. It is derived locally from your passkey, the biometric or device credential that unlocks your phone, through a function that turns it into a key. That key is generated on your device and it never leaves it. It is not uploaded, it is not sent to a server to be stored, and it is not baked into the app as something that could be pulled out of a compromised build. The second share is held by Nuri co-signing service. Here is the part that matters for this story. That service is built to be stateless. It holds the authority to co-sign within the policy you have set for your wallet, but it does not store a copy of your key. There is no vault of user keys on Nuri servers to breach. If the app you run is compromised through a supply chain bug, the attacker gets a compromised app, not your key. If Nuri servers are hacked, the attacker gets a stateless service with no user keys to take. Neither event, alone, exposes the private key. The result is that the arrayref pattern, a poisoned dependency that runs code at build time, does not translate into a stolen wallet. The key that matters is on the phone, derived from something on the phone, and the second signature piece lives with a service that has nothing to give up. Stealing the money requires two whole shares, and they are in two different places that the attacker would have to reach at once. The design also keeps an exit. The co-signing arrangement is time limited. After a fixed window, the user has an independent recovery path that does not depend on the co-signer. And if you want even more separation, a hardware wallet can be added as a third share, making it 2-of-3, so that no single device or service, phone or server, holds enough to move your funds. ## Wallet models, compared on one question **Basically,** Ask every model the same question: if the one thing breaks, is your money gone? The comparison that matters is not features. It is what a single breach exposes. Here are four common custody models asked the same question. | Model | Where the key lives | App is compromised | Provider server is breached | What the attacker needs | | --- | --- | --- | --- | --- | | Custodial exchange | On the exchange servers | You cannot move your money | Funds can be frozen or taken | One thing, the exchange | | Single key software wallet | One secret on your device | The secret can be exposed | Usually not in the path, but the app is the risk | One thing, your device secret | | MPC with a stored server share | Split, one share kept on the server | App can expose share handling | A stored share can be stolen | The stored share plus the device share | | Nuri, stateless co-signing | One key on the phone, a stateless share on Nuri | No usable key is in the app | No user key is stored to take | Two whole shares, in two places | - Not documented means the capability is not part of the described design, not that it can never exist. - The Nuri column describes the 2-of-2 model with a stateless co-signer, expandable to 2-of-3 with a hardware backup. - No model is immune to every attack. This is a comparison of the single point of failure each one leaves behind. ## The small glossary **Basically,** The words this story uses, in one line each. **Supply chain attack:** A compromise of a component or dependency that others trust, so the attacker reaches everyone who uses it. **Typosquat:** A name that looks like a well-known one with a small spelling change, so it is picked up by mistake. proc-macro1 for proc-macro2. **Build script:** Code that runs automatically when a project is built. In Rust it can execute before any of your own code, which is why it is a prime target. **Single point of failure:** The one component whose loss or compromise defeats the whole system. **Self-custody:** You hold the authority to move your own money, instead of a company holding it for you. **MuSig2:** A signature scheme that can split the right to sign across multiple keys, so no single key can move the funds alone. **Stateless:** The service does not keep a persistent copy of your key. There is nothing stored that a breach can steal. **Passkey:** The biometric or device credential that unlocks your phone, used here to derive your key locally. ## Questions people ask **Basically,** Supply chain attacks are a real and growing risk to the software around your money. Nuri is designed so none of them, alone, exposes your key. ### What does this Rust attack have to do with my wallet? Indirectly, a lot. The lesson is not about Rust. It is that the software between you and your money is built from pieces you do not control, and any one of them can be poisoned. A wallet is software whose job is to move your funds, so a supply chain compromise is a direct risk to that money, not just to a developer machine. ### Did this attack hit any wallet or any bitcoin user? There is no evidence the malicious versions were used to hit any wallet or any individual. The Rust team reported no evidence of actual usage, and no patched version exists because the fix was to delete the bad releases. The risk is the pattern, which applies to any software that depends on third party code, and wallets are high value targets for that pattern. ### Does self-custody protect me from supply chain attacks? It depends on the design. Self-custody means you hold the authority, but if that authority is one key in one place, a single compromise still wins. The protection comes from removing the single point of failure, so that the authority is split and no single component, app, server or device, holds enough on its own. ### What should I actually do right now? For your software, keep dependencies pinned and up to date, and watch for new malicious dependency names after incidents like this. For your money, choose a custody model where one breach does not expose your key. If you use Nuri, there is nothing to do. The design already keeps one key on your phone and a stateless share on our side, so a compromised app or a breached server does not hand an attacker your key. ### Does a hardware wallet solve this? A hardware wallet moves the signing away from the phone and the app, which removes a lot of the app supply chain risk. It is a strong choice. Nuri can use one as a third share in a 2-of-3 setup, which adds separation on top of the stateless co-signing rather than replacing it. ### What does stateless mean for the Nuri server? It means the co-signing service does not store your key. It holds the ability to co-sign within your wallet policy, not a copy of the private key itself. So there is no key vault on Nuri servers for an attacker to breach. The private key is derived on your phone from your passkey and stays there. ### If the app is compromised, can an attacker see my balance or send money? A compromised app can see what the app itself can see, and a malicious update could show false information. But moving your money requires a signature, and the signature needs both shares working together. A stateless co-signer with no stored key cannot produce that signature on its own, and the phone key never leaves the device. ### Why would an attacker care about a wallet at all? Because it is direct money. The arrayref backdoor was built to steal credentials, which can be traded or used to reach more. A wallet key is the most direct credential there is. That is exactly why the single point of failure is the thing to remove. Make the key impossible to get from any one place, and the attacker has to be twice as lucky and twice as coordinated. ### What can I do as a developer to protect my builds? Pin your dependency versions and do not auto-update to a brand new release the day it is published. Many teams wait a few days so that auditors and security firms can look at a new version first. Keep an audit of your dependency tree, and watch for new dependency names appearing after an incident like this one. These steps reduce the window in which a poisoned release can reach you. ### How often do attacks like this happen? More often than the headlines suggest. Vendors tracking package registries count thousands of new malicious packages every quarter, and the number keeps growing year over year. Most never make the news because they are typosquats nobody installs. The ones that make the news, like arrayref, are the ones that hit a popular, trusted package. That is the class of event that matters to anyone whose money depends on software. ## Sources and update note Attack details are as of 2026-08-21 and come from the linked Rust team post, security vendor reports and the Hacker News thread. Statistics are estimates from the linked 2026 industry reports and vary by source. Confirm current numbers before relying on them for a decision. 1. [Rust blog: Supply chain attack on arrayref](https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/) 2. [The Hacker News: Rust supply chain attack puts build time malware in crates](https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html) 3. [Wiz: Rust supply chain attack on arrayref, DPRK overlap](https://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-overlap-with-dprk-campaigns) 4. [Socket: Popular Rust crates compromised](https://socket.dev/blog/popular-rust-crates-compromised) 5. [BleepingComputer: Hackers poison arrayref Rust crate](https://www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware/) 6. [Hacker News: Malicious Rust crate Arrayref runs a build time payload](https://news.ycombinator.com/item?id=49374269) 7. [RustSec advisory RUSTSEC-2026-0260](https://rustsec.org/advisories/RUSTSEC-2026-0260.html) 8. [CVE-2026-77651: arrayref supply chain compromise](https://cvefeed.io/vuln/detail/CVE-2026-77651) 9. [AppSec Santa: Supply chain attack statistics 2026](https://appsecsanta.com/research/supply-chain-attack-statistics) ## Also available in - [Der arrayref-Supply-Chain-Angriff, und warum deine Wallet keine einzelne Angriffsfläche braucht](https://nuri.com/de/wissen/arrayref-supply-chain-angriff) (de) - [El ataque a la cadena de suministro de arrayref, y por qué tu wallet no necesita un punto único de fallo](https://nuri.com/es/conocimiento/ataque-de-cadena-de-suministro-arrayref) (es) - [L'attacco alla supply chain di arrayref, e perché il tuo wallet non ha bisogno di un singolo punto di guasto](https://nuri.com/it/conoscenza/attacco-a-arrayref-nella-cadena-di-fornitura) (it) --- --- title: "Der arrayref-Supply-Chain-Angriff, und warum deine Wallet keine einzelne Angriffsfläche braucht" description: "Eine 2-Stunden-Compromittierung eines Rust-Crates mit 245 Millionen Downloads, und was das für die Software bedeutet, die dein Geld bewegt." lang: "de" type: "knowledge-guide" datePublished: "2026-08-21" dateModified: "2026-08-21" canonical: "https://nuri.com/de/wissen/arrayref-supply-chain-angriff" tags: ["Software-Supply-Chain-Angriff","arrayref Crate","einzige Angriffsfläche","Self-Custody","Bitcoin-Wallet-Sicherheit","MuSig2","Stateless Mitzeichnung"] --- # Der arrayref-Supply-Chain-Angriff, und warum deine Wallet keine einzelne Angriffsfläche braucht **TL;DR:** Angreifer haben das Konto eines bekannten Rust-Paketes übernommen und eine gefälschte Version veröffentlicht, die bei jedem Build automatisch Schadcode ausführt. Die bösartige Version lag rund 86 Minuten online, und das Paket hat 245 Millionen Downloads. Das ist einer einer Welle von Supply-Chain-Angriffen, die häufiger und aggressiver werden. Die wichtigere Lektion für alle, deren Geld an Software hängt, ist, dass der Code und die Server zwischen dir und deinem Geld eine einzelne Angriffsfläche sind. Nuri ist so gebaut, dass kein einziger Kompromittierung, weder eine kompromittierte App noch ein gehackter Server, den Schlüssel freilegt, der dein Bitcoin kontrolliert. Nur ein Schlüssel liegt je auf dem Telefon. Der zweite Anteil liegt bei einem Stateless-Dienst. Um das Geld zu stehlen, braucht der Angreifer beide. ## Inhalt - [Die kurze Antwort](#quick-answer) - [Was tatsächlich passiert ist](#what-happened) - [Warum das die neue Normalität ist](#new-normal) - [Was Entwickler sagen](#what-developers-say) - [Wenn der Code das Geld kontrolliert](#why-it-matters) - [Das Problem der einzelnen Angriffsfläche](#single-point) - [Wie Nuri sie entfernt](#how-nuri) - [Wallet-Modelle, auf eine Frage verglichen](#comparison) - [Das kleine Glossar](#glossary) - [Fragen, die Menschen stellen](#faqs) ## Die kurze Antwort **Kurz gesagt:** Eine gefälschte Version eines beliebten Paketes hat bei jedem Build Schadcode ausgeführt. Die Lektion: die Software zwischen dir und deinem Geld ist eine einzelne Angriffsfläche, also baue so, dass kein einziger Kompromittierung gewinnt. Am 20. August 2026 ging der Bericht ein, dass das Rust-Paket proc-macro1 bösartig sei. Das Rust Security Response Team bestätigte es binnen Minuten: Die Crate trug ein Build-Skript, das eine ferne Last herunterlud und ausführte. Es reichte, ein Projekt zu bauen, das die Crate einband. Niemand musste eine Funktion aufrufen. Der Build selbst war der Auslöser. Das eigentliche Ziel war arrayref, eine kleine, bekannte Crate, die von sehr vielen anderen Projekten genutzt wird. Das Konten-Inhaber war kompromittiert. Der Angreifer veröffentlichte eine neue Version von arrayref, die von der gefälschten Crate abhing, und zog die alten Versionen still zurück, damit das Build-Tool die Nutzer auf die schlechte Version lenkte. Das hier geht nicht speziell um Rust. Es geht darum, wie Software gebaut wird: Wir alle hängen an tausenden Bausteinen, die andere geschrieben haben, und jeder von ihnen kann der sein, der still vergiftet ist. Wenn das Ding, das dein Geld hält, Software ist, wird das aus einem Entwicklerproblem zum Geldproblem. ## Was tatsächlich passiert ist **Kurz gesagt:** Eines kompromittierten Inhaber-Accounts hat eine gefälschte Abhängigkeit verschickt. Das Bauen der Crate lud eine Backdoor herunter, die Zugangsdaten stiehlt. Das Ganze war unter zwei Stunden online. Der Angreifer hat die Bibliothek nicht neu geschrieben. Er hat eine Zeile hinzugefügt: eine Abhängigkeit auf proc-macro1, eine absichtliche Fehlschreibung von proc-macro2, einer der am häufigsten heruntergeladenen Crates im ganzen Ökosystem. Die gefälschte Crate ist eine echte Kopie der echten, damit der Build läuft und die Software weiterhin funktioniert. Das ist genau der Punkt. Nichts sieht kaputt aus. Die Last läuft, bevor du überhaupt merkst, dass irgendetwas nicht stimmt. Das Build-Skript hat die Server-Adresse des Angreifers still aus Teilen kodierten Texts rekonstruiert, die Sicherheitsprüfung deaktiviert, die den Server auf Identität prüft, und dann ein Programm für dein Betriebssystem und deinen Prozessor heruntergeladen. Auf Mac und Linux schrieb es die Datei in einen Temp-Ordner und startete sie im Hintergrund. Auf Windows schrieb es ein Skript und startete es versteckt. Der Angreifer hat all das so gewählt, dass es nicht auffällt, während der Build läuft. Die heruntergeladene Backdoor ist echte Schadsoftware, kein Test. Sicherheitsforscher, die sie analysiert haben, fanden, dass sie anruft, deinen Computer- und Benutzernamen liest, deine installierten Programme listet und in deinem Browserprofil nach gespeicherten Logins sucht. Sie installiert sich so, dass sie nach einem Neustart wiederkommt. Sie kann auf Abruf mehr Code herunterladen und ausführen. Wenn der Hauptserver ausfällt, generiert sie frische Domainnamen, um einen neuen zu finden. Die bösartigen Versionen wurden schnell gelöscht: arrayref 0.3.10 war rund 86 Minuten online, und die zwei verwandten Crates rund 90 und 107 Minuten. Das Rust-Team sperrte das Inhaber-Konto als Vorsichtsmaßnahme und gab an, es nicht zu glauben, dass der Autor in schlechter Absicht gehandelt hat. Sein Computer oder sein Login ist wahrscheinlicher der Teil, der kompromittiert wurde. Der Autor von arrayref pflegt die Crate seit 2009. Wiz, eine Sicherheitsfirma, fand, dass die Infrastruktur des Angreifers mit jüngeren Operationen übereinstimmt, die Nordkorea zugeschrieben werden, einschließlich Kampagnen gegen andere beliebte Bibliotheken. Das war kein Einzelfall eines zufälligen Anfängers. Es war eine organisierte Kampagne mit einem Muster, das sie schon vorher genutzt hatten. - Ziel: arrayref 0.3.10, internment 0.8.7 und append-only-vec 0.1.9, alle von einem kompromittierten Konto. - Vehikel: eine neue Abhängigkeit, proc-macro1, eine Fehlschreibung des allgegenwärtigen proc-macro2. - Auslöser: der Build selbst. cargo build auf einem betroffenen Projekt führte die Last aus. - Online: 86 bis 107 Minuten vor dem Löschen am 2026-08-20. - Größe: arrayref hat 245 Millionen Downloads und erscheint in der Mehrheit der Umgebungen, die Rust nutzen. ## Warum das die neue Normalität ist **Kurz gesagt:** Supply-Chain-Angriffe sind keine seltene Randerscheinung. Sie sind ein wachsendes, industrialisiertes und zunehmend automatisierter Teil davon, wie das Internet angegriffen wird. Der arrayref-Angriff wirkt schockierend, weil er eine beliebte, vertrauenswürdige Bibliothek traf. Aber die Zahlen sagen, dass es nicht schockierend sein sollte. Dasselbe Angriffsmuster läuft seit Jahren gegen jedes große Paket-Registry, und die Rate steigt. Anbieter, die das verfolgen, melden über eine Million bösartiger Pakete über npm, PyPI, Maven, NuGet und Hugging Face, mit einer Zahl neuer bösartiger Pakete im Jahr 2025, die um rund 75 Prozent zum Vorjahr stieg. Die geschätzten Kosten von Supply-Chain-Angriffen erreichten 2025 rund 60 Milliarden Dollar, mit Prognosen nahe 138 Milliarden bis 2030. Rund 30 Prozent der Datenlecks beinhalten inzwischen einen Dritten, und der Großteil der Schwachstellen in kommerzieller Software liegt nicht im Hauptcode, sondern in den Abhängigkeiten, die er einbindet. Zwei Dinge machen es gleichzeitig schlimmer. Erstens ist das Tooling, das Software baut und ausführt, komplexer geworden, also gibt es mehr bewegliche Teile, die ein Angreifer berühren kann. Zweitens nutzen die Angreifer KI, um Ziele zu finden, den bösartigen Code zu schreiben und die Kampagne zu skalieren, während die Leute, die jede Abhängigkeit prüfen, meist unbezahlte Freiwillige sind. Die unbequeme Wahrheit auf Hacker News, wo der Hauptthread 400 Punkte und Hunderte Kommentare erreichte, ist, dass Entwickler das kommen sehen. Eine der am häufigsten bewerteten Beobachtungen war, dass das Build-Tooling Code auf deinem Rechner ausführt, ohne deine Zustimmung, so dass das Hinzufügen einer Abhängigkeit reicht, um dich zu kompromittieren, bevor du den Code überhaupt prüfst. Eine andere stellte fest, dass dasselbe beim xz-Komprimierungskomprimierung passiert ist, und niemand kann jedes kleine Paket im tiefen Abhängigkeitsbaum lesen, um sicherzustellen, dass es sauber ist. ## Was Entwickler sagen **Kurz gesagt:** Die Reaktion ist keine Panik. Es ist eine müde, informierte Anerkennung, dass das Build-Tooling nie als Sicherheitsgrenze gedacht war. Die Hacker-News-Diskussion war ungewöhnlich ruhig und spezifisch, was meist das Zeichen einer erfahrenen Gemeinschaft ist, die ein bekanntes Problem bearbeitet. Hier ist, was immer wieder kam, in ihren eigenen Worten, leicht gekürzt. Zum Warum es immer wieder passiert: "Warum erlauben Inhaber von Paket-Registries nach so vielen früheren Supply-Chain-Angriffen noch jedem, Pakete hochzuladen und Updates zu pushen, ohne Sicherheitsprüfung?" Diese Frage war nicht rhetorisch. Die Folge war das eigentliche Problem: "Wer finanziert diese Sicherheitsprüfung? Sollen die Leute ihre freie Zeit freiwillig einsetzen?" Zum Build-Tooling: "Das Problem ist, dass Build-Skripte automatisch ohne Nutzerzustimmung eingreifen. Das Hinzufügen einer Abhängigkeit reicht, um dich zu kompromittieren, bevor du die Chance hast, den Code zu prüfen." Mehrere merkten an, dass andere Paketmanager Kontrollen haben, die Cargo nicht hat, wie das Erlauben von Install-Skripten und eine Wartefrist für brandneue Abhängigkeiten. Zum Ziel: "Entwicklermaschinen sind sehr saftige Ziele. Da liegen meist alle möglichen Zugangsdaten herum, so dass es oft nicht zu schwer ist, von dort zu deinen Cloud-Konten hochzusteigen." Das ist der eigentliche Preis in den meisten dieser Angriffe. Es ist nicht der eine Rechner. Es ist alles, was dieser Rechner erreichen kann. Dazu, ob die Sprache eine Rolle spielt: "Rust scheint in dieser Hinsicht kaum besser als Node." Die Gegenargumentation, die ebenfalls weite Verbreitung fand, ist, dass das Ökosystem bereits Audit-Werkzeuge hat und mehrere große Firmen Audits der Crates veröffentlichen, von denen sie abhängen. Die Lücke ist, dass Prüfen die Ausnahme und nicht der Standard ist. Ein Detail stach heraus. Mehrere fragten, was der bösartige Code tatsächlich tut, und die Antwort war, dass niemand es mit Sicherheit wisse, weil das Inhaber-Konto gelöscht und die bösartigen Veröffentlichungen vom Registry gelöscht statt nur zurückgezogen wurden. Der Angreifer räumte nach. Das ist das Merkmal einer Operation, die das schon vorher gemacht hat. ## Wenn der Code das Geld kontrolliert **Kurz gesagt:** Eine Supply-Chain-Angreift auf eine Website ist nervig. Eine Supply-Chain-Angreift auf die Software, die dein Geld hält, ist ein anderes Problem. Most Supply-Chain-Angriffe zielen auf Entwickler und Firmen ab, und der Schaden sind gestohlene Zugangsdaten, gestohlene Daten oder eine langsame, teure Reinigung. Die Reichweite ist ein Build-Server oder ein Firmenkonto. Eine Wallet ist anders. Der ganze Zweck der Software ist, dein Geld bewegen zu können. Wenn der Code in dieser Software oder die Server, von denen sie abhängt, kompromittiert werden können, kann der Kompromittierung direkt auf das Geld gehen. Es gibt keine Schicht aus "ups, wir haben ein paar Logins verloren" zwischen dem Angreifer und deinem Kontostand. Deshalb sind das Supply-Chain-Problem und das Self-Custody-Problem dasselbe Problem. Beide drehen sich darum, wo der Schlüssel, der dein Geld kontrolliert, tatsächlich liegt, und ob jeder einzelne Punkt in der Kette, eine Bibliothek, ein Unternehmen, ein Server, ein Inhaber, ein Anbieter, ihn nehmen kann. ## Das Problem der einzelnen Angriffsfläche **Kurz gesagt:** Eine einzelne Angriffsfläche ist die eine Sache, die, wenn sie kaputtgeht oder genommen wird, alles verliert. Die meisten Wallets haben eine. Das Ziel ist, keine zu haben. Eine einzelne Angriffsfläche ist einfach zu definieren und schwer wegzugestalten. Sie ist die eine Komponente, die, wenn sie kompromittiert wird oder ausfällt, das Ganze zum Scheitern bringt. Für eine Custodial-Börse sind es ihre Server. Wenn die kompromittiert werden oder sie einfach dein Konto einfrieren, liegt dein Geld in ihrer Hand. Für eine Software-Wallet, die deinen Schlüssel aus einem Geheimnis auf deinem Gerät ableitet, ist es dieses eine Geheimnis. Wenn die App durch ein vergiftetes Update kompromittiert wird oder dein Gerät wegkommt, ist das Geheimnis freigelegt. Der Grund, warum diese Designs eine einzelne Angriffsfläche haben, ist, dass sie bequem sind. Ein Ort für den Schlüssel bedeutet einen Ort zum Unterschreiben und einen Ort zum Sichern. Bequemlichkeit und Sicherheit ziehen in entgegengesetzte Richtungen, und die meisten Produkte wählen Bequemlichkeit. Es gibt eine bessere Form. Teile die Befugnis, dein Geld zu bewegen, auf zwei oder mehr Dinge, die ein Angreifer zusammen nehmen müsste, und achte darauf, dass keines von ihnen den ganzen Schlüssel allein hält. Dann gewinnt kein einzelner Kompromittierung, ein schlechtes Paket, ein gehackter Server, ein gestohlenes Telefon, ein bösartiges Update, allein. Der Angreifer muss zweimal erfolgreich sein, an zwei verschiedenen Orten, zur gleichen Zeit. Das ist der Unterschied zwischen einem Ziel und einer Festung. ## Wie Nuri sie entfernt **Kurz gesagt:** Nuri nutzt ein Split-Unterschriften-Modell, bei dem nur ein Schlüssel je auf dem Telefon liegt, und der zweite Anteil stateless ist, so dass weder die App noch der Server allein deinen Schlüssel freilegen. Nuri ist auf einem Split-Unterschriften-Schema namens MuSig2 gebaut, in der 2-von-2-Form, die auf 2-von-3 erweitert werden kann. Zwei getrennte Anteile sind nötig, um zu unterschreiben und das Geld zu bewegen, und kein einzelner Anteil kann es allein tun. Auf deinem Telefon existiert nur ein Schlüssel je: dein eigener Schlüssel. Er wird lokal aus deinem Passkey, dem biometrischen oder Geräte-Zugang, der dein Telefon entsperren kann, über eine Funktion abgeleitet, die ihn zu einem Schlüssel macht. Dieser Schlüssel wird auf deinem Gerät erzeugt und verlässt es nie. Er wird nicht hochgeladen, er wird nicht an einen Server zum Speichern geschickt, und er ist nicht in die App eingebacken, so dass er aus einem kompromittierten Build herausgezogen werden könnte. Den zweiten Anteil hält der Nuri-Mitzeichnungs-Dienst. Hier ist der Teil, der für diese Geschichte zählt. Dieser Dienst ist stateless gebaut. Er hält die Befugnis, innerhalb der von dir für deine Wallet gesetzten Politik mitzuzeichnen, aber er speichert keine Kopie deines Schlüssels. Es gibt keinen Vault mit Benutzerschlüsseln auf Nuri-Servern, der kompromittiert werden könnte. Wenn die App, die du ausführst, durch einen Supply-Chain-Bug kompromittiert wird, bekommt der Angreifer eine kompromittierte App, nicht deinen Schlüssel. Wenn Nuri-Server gehackt werden, bekommt der Angreifer einen stateless Dienst ohne Benutzerschlüssel, die er nehmen könnte. Keines dieser Ereignisse legt den privaten Schlüssel frei. Das Ergebnis ist, dass das arrayref-Muster, eine vergiftete Abhängigkeit, die Code beim Build ausführt, nicht in eine gestohlene Wallet übersetzt. Der Schlüssel, der zählt, liegt auf dem Telefon, abgeleitet aus etwas auf dem Telefon, und das zweite Unterschriften-Stück liegt bei einem Dienst, der nichts zu geben hat. Um das Geld zu stehlen, braucht es zwei ganze Anteile, und sie liegen an zwei verschiedenen Orten, die der Angreifer gleichzeitig erreichen müsste. Das Design behält auch einen Ausgang. Die Mitzeichnungs-Einrichtung ist zeitlich begrenzt. Nach einem festen Fenster hat der Benutzer einen unabhängigen Wiederherstellungsweg, der nicht vom Mitzeichner abhängt. Und wenn du noch mehr Trennung willst, kann eine Hardware-Wallet als dritter Anteil hinzukommen, so dass es 2-von-3 ist, damit kein einzelnes Gerät oder ein Dienst, Telefon oder Server, genug hält, um dein Geld zu bewegen. ## Wallet-Modelle, auf eine Frage verglichen **Kurz gesagt:** Frag jedes Modell dieselbe Frage: Wenn die eine Sache kaputtgeht, ist dein Geld weg? Der Vergleich, der zählt, ist nicht die Funktionen. Es ist, was ein einziger Bruch freilegt. Hier sind vier häufige Custody-Modelle, die dieselbe Frage gestellt bekommen. | Modell | Wo der Schlüssel liegt | App kompromittiert | Server des Anbieters kompromittiert | Was der Angreifer braucht | | --- | --- | --- | --- | --- | | Custodial-Börse | Auf den Servern der Börse | Du kannst dein Geld nicht bewegen | Gelder können eingefroren oder genommen werden | Eine Sache, die Börse | | Ein-Schlüssel-Software-Wallet | Ein Geheimnis auf deinem Gerät | Das Geheimnis kann freigelegt werden | Meist nicht im Pfad, aber die App ist das Risiko | Eine Sache, das Geheimnis deines Geräts | | MPC mit gespeichertem Server-Anteil | Geteilt, ein Anteil auf dem Server | App kann Anteil-Handhabung freilegen | Ein gespeicherter Anteil kann gestohlen werden | Der gespeicherte Anteil plus der Geräte-Anteil | | Nuri, stateless Mitzeichnung | Ein Schlüssel auf dem Telefon, ein stateless Anteil bei Nuri | Kein brauchbarer Schlüssel in der App | Kein Benutzerschlüssel gespeichert, um zu nehmen | Zwei ganze Anteile, an zwei Orten | - Nicht dokumentiert bedeutet, dass die Fähigkeit nicht Teil des beschriebenen Designs ist, nicht dass sie nie existieren kann. - Die Nuri-Spalte beschreibt das 2-von-2-Modell mit einem stateless Mitzeichner, erweiterbar auf 2-von-3 mit einer Hardware-Sicherung. - Kein Modell ist gegen jeden Angriff immun. Dies ist ein Vergleich der einzelnen Angriffsfläche, die jedes davon zurücklässt. ## Das kleine Glossar **Kurz gesagt:** Die Wörter, die diese Geschichte benutzt, in je einer Zeile. **Supply-Chain-Angriff:** Eine Kompromittierung eines Bausteins oder einer Abhängigkeit, auf die andere vertrauen, damit der Angreifer alle erreicht, die ihn nutzen. **Typosquatting:** Ein Name, der wie ein bekannter aussieht, mit einer kleinen Schreibänderung, damit er versehentlich aufgenommen wird. proc-macro1 für proc-macro2. **Build-Skript:** Code, der automatisch beim Bauen eines Projekts läuft. In Rust kann er vor deinem eigenen Code laufen, weshalb er ein prime Ziel ist. **Einzige Angriffsfläche:** Die eine Komponente, deren Verlust oder Kompromittierung das ganze System zum Scheitern bringt. **Self-Custody:** Du hältst die Befugnis, dein eigenes Geld zu bewegen, statt dass ein Unternehmen es für dich hält. **MuSig2:** Ein Unterschriftenschema, das das Recht zu unterschreiben über mehrere Schlüssel teilen kann, so dass kein einzelner Schlüssel das Geld allein bewegen kann. **Stateless:** Der Dienst behält keine dauerhafte Kopie deines Schlüssels. Es gibt nichts Gespeichertes, das ein Bruch stehlen könnte. **Passkey:** Der biometrische oder Geräte-Zugang, der dein Telefon entsperren kann, hier genutzt, um deinen Schlüssel lokal abzuleiten. ## Fragen, die Menschen stellen **Kurz gesagt:** Supply-Chain-Angriffe sind ein reales und wachsendes Risiko für die Software um dein Geld. Nuri ist so designed, dass keines davon, allein, deinen Schlüssel freilegt. ### Was hat dieser Rust-Angriff mit meiner Wallet zu tun? Indirekt viel. Die Lektion ist nicht über Rust. Es ist, dass die Software zwischen dir und deinem Geld aus Teilen gebaut ist, die du nicht kontrollierst, und jeder von ihnen kann vergiftet werden. Eine Wallet ist Software, deren Aufgabe es ist, dein Geld zu bewegen, so dass ein Supply-Chain-Kompromittierung ein direktes Risiko für dieses Geld ist, nicht nur für eine Entwicklermaschine. ### Hat dieser Angriff eine Wallet oder einen Bitcoin-Nutzer getroffen? Es gibt keinen Hinweis, dass die bösartigen Versionen genutzt wurden, um eine Wallet oder einen Einzelperson zu treffen. Das Rust-Team berichtete keine Hinweise auf tatsächliche Nutzung, und eine gepatchte Version existiert nicht, weil das war, die bösartigen Veröffentlichungen zu löschen. Das Risiko ist das Muster, das auf jede Software zutrifft, die von drittem Code abhängt, und Wallets sind Hochwert-Ziele für dieses Muster. ### Schützt mich Self-Custody vor Supply-Chain-Angriffen? Kommt auf das Design an. Self-Custody bedeutet, dass du die Befugnis hältst, aber wenn diese Befugnis ein Schlüssel an einem Ort ist, gewinnt ein einzelner Kompromittierung trotzdem. Der Schutz kommt vom Weglassen der einzelnen Angriffsfläche, damit die Befugnis geteilt ist und keine einzelne Komponente, App, Server oder Gerät, genug allein hält. ### Was sollte ich jetzt konkret tun? Für deine Software: Halte Abhängigkeitsversionen fest und auf dem neuesten Stand, und achte nach Vorfällen wie diesem auf neue bösartige Abhängigkeitsnamen. Für dein Geld: Wähle ein Custody-Modell, bei dem ein einziger Bruch deinen Schlüssel nicht freilegt. Wenn du Nuri nutzt, musst du nichts tun. Das Design hält bereits einen Schlüssel auf deinem Telefon und einen stateless Anteil auf unserer Seite, so dass eine kompromittierte App oder ein kompromittierter Server dem Angreifer keinen Schlüssel aushändigt. ### Löst eine Hardware-Wallet das? Eine Hardware-Wallet verlagert das Unterschreiben weg vom Telefon und der App, was viel des App-Supply-Chain-Risikos entfernt. Es ist eine starke Wahl. Nuri kann eine als dritten Anteil in einem 2-von-3-Setup nutzen, was zur stateless Mitzeichnung zusätzlich Trennung hinzuadds, statt sie zu ersetzen. ### Was bedeutet stateless für den Nuri-Server? Das bedeutet, der Mitzeichnungs-Dienst speichert deinen Schlüssel nicht. Er hält die Fähigkeit, innerhalb deiner Wallet-Politik mitzuzeichnen, nicht eine Kopie des privaten Schlüssels selbst. Also gibt es keinen Schlüssel-Vault auf Nuri-Servern, den ein Angreifer kompromittieren kann. Der private Schlüssel wird lokal auf deinem Telefon aus deinem Passkey abgeleitet und bleibt dort. ### Wenn die App kompromittiert ist, kann ein Angreifer meinen Kontostand sehen oder Geld senden? Eine kompromittierte App kann sehen, was die App selbst sehen kann, und ein bösartiges Update könnte falsche Informationen anzeigen. Aber dein Geld zu bewegen braucht eine Unterschrift, und die Unterschrift braucht beide Anteile zusammen. Ein stateless Mitzeichner ohne gespeicherten Schlüssel kann diese Unterschrift nicht allein erzeugen, und der Telefon-Schlüssel verlässt das Gerät nie. ### Warum sollte ein Angreifer überhaupt an einer Wallet interessiert sein? Weil es direktes Geld ist. Die arrayref-Backdoor wurde gebaut, um Zugangsdaten zu stehlen, die gehandelt oder genutzt werden können, um mehr zu erreichen. Ein Wallet-Schlüssel ist die direkteste Zugangsdaten überhaupt. Genau deshalb ist die einzelne Angriffsfläche das, was zu entfernen ist. Mach den Schlüssel unmöglich von einem einzigen Ort zu bekommen, und der Angreifer muss doppelt so glücklich und doppelt so koordiniert sein. ### Was kann ich als Entwickler tun, um meine Builds zu schützen? Halte deine Abhängigkeitsversionen fest und aktualisiere nicht automatisch auf eine brandneue Veröffentlichung an dem Tag, an dem sie erscheint. Viele Teams warten ein paar Tage, damit Prüfer und Sicherheitsfirmen sich zuerst eine neue Version ansehen können. Führe ein Audit deines Abhängigkeitsbaums und achte nach Vorfällen wie diesem auf neue Abhängigkeitsnamen. Diese Schritte verringern das Fenster, in dem eine vergiftete Veröffentlichung dich erreichen kann. ### Wie oft passieren Angriffe wie dieser? Häufiger als die Schlagzeilen vermuten lassen. Anbieter, die Paket-Registries verfolgen, zählen Tausende neue bösartiger Pakete jedes Quartal, und die Zahl steigt von Jahr zu Jahr. Die meisten werden nie Schlagzeilen, weil sie Typosquatting sind, die niemand installiert. Die, die Schlagzeilen machen, wie arrayref, sind die, die ein beliebtes, vertrauenswürdige Paket treffen. Das ist die Klasse von Ereignis, die für jeden zählt, dessen Geld an Software hängt. ## Quellen und Hinweis zur Aktualität Anggriffsdetails sind Stand 2026-08-21 und stammen aus dem verlinkten Rust-Team-Post, Berichten von Sicherheitsanbietern und dem Hacker-News-Thread. Statistiken sind Schätzungen aus den verlinkten Branchenberichten 2026 und variieren je nach Quelle. Bestätige aktuelle Zahlen, bevor du sie für eine Entscheidung verwendest. 1. [Rust-Blog: Supply-Chain-Angriff auf arrayref](https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/) 2. [The Hacker News: Rust-Supply-Chain-Angriff bringt Build-Zeit-Malware in Crates](https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html) 3. [Wiz: Rust-Supply-Chain-Angriff auf arrayref, DPRK-Übereinstimmung](https://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-overlap-with-dprk-campaigns) 4. [Socket: Beliebte Rust-Crates kompromittiert](https://socket.dev/blog/popular-rust-crates-compromised) 5. [BleepingComputer: Hacker vergiften arrayref Rust-Crate](https://www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware/) 6. [Hacker News: Bösartiger Rust-Crate Arrayref führt eine Build-Zeit-Last aus](https://news.ycombinator.com/item?id=49374269) 7. [RustSec-Beratschlagung RUSTSEC-2026-0260](https://rustsec.org/advisories/RUSTSEC-2026-0260.html) 8. [CVE-2026-77651: arrayref-Supply-Chain-Kompromittierung](https://cvefeed.io/vuln/detail/CVE-2026-77651) 9. [AppSec Santa: Supply-Chain-Angriffsstatistiken 2026](https://appsecsanta.com/research/supply-chain-attack-statistics) ## Auch verfügbar auf - [The arrayref supply chain attack, and why your wallet needs no single point of failure](https://nuri.com/knowledge/supply-chain-attack-arrayref) (en) - [El ataque a la cadena de suministro de arrayref, y por qué tu wallet no necesita un punto único de fallo](https://nuri.com/es/conocimiento/ataque-de-cadena-de-suministro-arrayref) (es) - [L'attacco alla supply chain di arrayref, e perché il tuo wallet non ha bisogno di un singolo punto di guasto](https://nuri.com/it/conoscenza/attacco-a-arrayref-nella-cadena-di-fornitura) (it) --- --- title: "El ataque a la cadena de suministro de arrayref, y por qué tu wallet no necesita un punto único de fallo" description: "Una brecha de 2 horas de un crate de Rust con 245 millones de descargas, y qué significa para el software que mueve tu dinero." lang: "es" type: "knowledge-guide" datePublished: "2026-08-21" dateModified: "2026-08-21" canonical: "https://nuri.com/es/conocimiento/ataque-de-cadena-de-suministro-arrayref" tags: ["ataque a la cadena de suministro","crate arrayref","punto único de fallo","autocustodia","seguridad de wallet de bitcoin","MuSig2","firma co-firmante sin estado"] --- # El ataque a la cadena de suministro de arrayref, y por qué tu wallet no necesita un punto único de fallo **TL;DR:** Los atacantes comprometieron la cuenta de una biblioteca Rust conocida y publicaron una versión falsa que ejecutaba malware en la máquina en el momento en que alguien la compilaba. La versión maliciosa estuvo online unas 86 minutos, y la biblioteca tiene 245 millones de descargas. Esto es parte de una oleada de ataques a la cadena de suministro que son más frecuentes y más agresivos. La lección más grande para cualquiera cuyo dinero depende de software es que el código y los servidores entre tú y tus fondos son un punto único de fallo. Nuri está construido para que ninguna sola brecha, ni una app comprometida ni un servidor hackeado, exponga la clave que controla tu bitcoin. Solo una clave está nunca en el teléfono. La segunda parte vive en un servicio sin estado. Robar el dinero toma ambas. ## Contenido - [La respuesta rápida](#quick-answer) - [Qué pasó realmente](#what-happened) - [Por qué esto es la nueva normalidad](#new-normal) - [Qué dicen los desarrolladores](#what-developers-say) - [Cuando el código controla el dinero](#why-it-matters) - [El problema del punto único de fallo](#single-point) - [Cómo Nuri lo elimina](#how-nuri) - [Modelos de wallet, comparados con una pregunta](#comparison) - [El pequeño glosario](#glossary) - [Preguntas que la gente hace](#faqs) ## La respuesta rápida **En pocas palabras:** Una versión falsa de una biblioteca popular ejecutaba malware en las máquinas durante la compilación. La lección: el software entre tú y tu dinero es un punto único de fallo, así que diseña para que ninguna sola brecha gane. El 20 de agosto de 2026 llegó un informe de que un crate de Rust llamado proc-macro1 era malicioso. El Rust Security Response Team lo confirmó en minutos: el crate llevaba un guion de compilación que descargaba y ejecutaba una carga remota. Compilar cualquier proyecto que incorporaba el crate era suficiente para ejecutarla. Nadie tenía que llamar a ninguna función. La compilación en sí era el detonante. El objetivo real era arrayref, un crate pequeño y conocido usado por un número enorme de otros proyectos. Su cuenta de propietario había sido comprometida. El atacante publicó una nueva versión de arrayref que dependía del crate falso, y retiró en silencio las versiones antiguas para que la herramienta de compilación dirigiera a los usuarios a la mala. Nada de esto se trata específicamente de Rust. Se trata de cómo se construye el software: todos dependemos de miles de piezas escritas por otras personas, y cualquiera de ellas puede ser la que está envenenada en silencio. Cuando lo que guarda tu dinero es software, eso deja de ser un problema de desarrollador y se convierte en un problema de dinero. ## Qué pasó realmente **En pocas palabras:** Una cuenta de mantenedor comprometida envió una dependencia falsa. Compilar el crate descargaba y ejecutaba una puerta trasera que roba credenciales. Todo estuvo online menos de dos horas. El atacante no reescribió la biblioteca. Añadió una línea: una dependencia en proc-macro1, un error deliberado en la ortografía de proc-macro2, una de las crates más descargadas de todo el ecosistema. El crate falso es una copia genuina del real, así que la compilación funciona y el software sigue funcionando. Ese es exactamente el punto. Nada parece roto. La carga se ejecuta antes de que notes cualquier cosa. El guion de compilación reconstruía en silencio la dirección del servidor del atacante a partir de trozos de texto codificado, desactivaba la comprobación de seguridad que verifica la identidad del servidor y descargaba un programa elegido para tu sistema operativo y procesador. En Mac y Linux escribía el archivo en una carpeta temporal y lo lanzaba en segundo plano. En Windows escribía un guion y lo iniciaba oculto. El atacante eligió todo esto para evitar ser notado durante la compilación. La puerta trasera descargada es malware real, no una prueba. Los investigadores de seguridad que la analizaron encontraron que llama a casa, lee el nombre de tu equipo y usuario, lista tus programas instalados y busca en tu perfil del navegador logins guardados. Se instala para volver tras un reinicio. Puede descargar y ejecutar más código bajo demanda. Si el servidor principal cae, genera nombres de dominio frescos para encontrar uno nuevo. Las versiones maliciosas se eliminaron rápido: arrayref 0.3.10 estuvo online unas 86 minutos, y los dos crates relacionados unas 90 y 107 minutos. El equipo de Rust bloqueó la cuenta del propietario como precaución y dijo que no cree que el autor actuara en mala fe. Es más probable que fuera comprometido su equipo o su inicio de sesión. El autor de arrayref ha mantenido el crate desde 2009. Wiz, una empresa de seguridad, encontró que la infraestructura del atacante se superpone con operaciones recientes atribuidas a Corea del Norte, incluidas campañas contra otras bibliotecas populares. No fue un suceso aislado de un aficionado aleatorio. Fue una campaña organizada usando un patrón que ya habían usado antes. - Objetivo: arrayref 0.3.10, internment 0.8.7 y append-only-vec 0.1.9, todos de una cuenta comprometida. - Vehículo: una dependencia nueva, proc-macro1, un error ortográfico del omnipresente proc-macro2. - Detonante: la compilación en sí. Ejecutar cargo build en un proyecto afectado ejecutaba la carga. - Online: de 86 a 107 minutos antes de la eliminación el 2026-08-20. - Escala: arrayref tiene 245 millones de descargas y aparece en la mayoría de entornos que usan Rust. ## Por qué esto es la nueva normalidad **En pocas palabras:** Los ataques a la cadena de suministro no son un caso raro. Son una parte creciente, industrializada y cada vez más automatizada de cómo se ataca a internet. El ataque a arrayref parece impactante porque golpeó una biblioteca popular y de confianza. Pero los números dicen que no debería serlo. La misma clase de ataque lleva años operando contra cada registro de paquetes mayor, y la tasa sube. Los proveedores que rastrean esto reportan más de un millón de paquetes maliciosos en npm, PyPI, Maven, NuGet y Hugging Face, con el conteo de paquetes maliciosos nuevos en 2025 subiendo unos 75 por ciento respecto al año anterior. El costo estimado de los ataques a la cadena de suministro alcanzó unos 60 mil millones de dólares en 2025, con proyecciones cercanas a 138 mil millones para 2030. Alrededor del 30 por ciento de las brechas de datos ahora involucra a un tercero, y la gran mayoría de las vulnerabilidades en software comercial se encuentran no en el código principal sino en las dependencias que incorpora. Dos cosas lo empeoran a la vez. Primero, las herramientas que construyen y ejecutan software se han vuelto más complejas, así que hay más piezas móviles que un atacante puede tocar. Segundo, los atacantes usan IA para encontrar objetivos, escribir el código malicioso y escalar la campaña, mientras la gente responsable de revisar cada dependencia son en su mayoría voluntarios no remunerados. La verdad incómoda en Hacker News, donde el hilo principal llegó a 400 puntos y cientos de comentarios, es que los desarrolladores ven esto venir. Una de las observaciones mejor puntuadas fue que las herramientas de compilación ejecutan código en tu máquina sin tu consentimiento, así que añadir una dependencia es suficiente para comprometerte antes de revisar el código. Otra señaló que lo mismo pasó con la brecha de la librería de compresión xz, y que nadie puede leer cada paquete pequeño del árbol profundo de dependencias para demostrar que está limpio. ## Qué dicen los desarrolladores **En pocas palabras:** La reacción no es pánico. Es un reconocimiento cansado e informado de que las herramientas de compilación nunca fueron diseñadas como una frontera de seguridad. La discusión de Hacker News fue inusualmente tranquila y específica, lo que suele ser la señal de una comunidad experimentada lidiando con un problema conocido. Esto es lo que volvió una y otra vez, en sus propias palabras, recortado ligeramente. Sobre por qué sigue pasando: "¿Por qué, después de tantos ataques previos a la cadena de suministro, los mantenedores de los registros de paquetes siguen permitiendo a cualquiera subir paquetes y empujar actualizaciones sin auditoría de seguridad?" Esa pregunta no era retórica. La secuela era el problema real: "¿Quién financia esta auditoría de seguridad? ¿Deben la gente voluntariar su tiempo libre?" Sobre las herramientas de compilación: "El problema es que los guiones de compilación se ejecutan automáticamente sin el consentimiento ni la intervención del usuario. Añadir una dependencia es suficiente para comprometerte, antes de que tengas la oportunidad de revisar el código." Varios señalaron que otros gestores de paquetes tienen controles que Cargo no tiene, como poner en lista blanca los guiones de instalación y aplicar una espera a las dependencias de última hora. Sobre el objetivo: "Las máquinas de desarrollo son objetivos muy jugosos. Suelen tener todo tipo de credenciales tiradas, así que a menudo no es demasiado difícil escalar de ahí a comprometer tus cuentas de nube." Ese es el verdadero premio en la mayoría de estos ataques. No es la máquina. Es todo lo que esa máquina puede alcanzar. Sobre si importa el lenguaje: "Rust apenas parece mejor que Node en esto." El contrargumento, también muy compartido, es que el ecosistema ya tiene herramientas de auditoría, y varias empresas grandes publican auditorías de las crates de las que dependen. La brecha es que auditar es la excepción, no la norma. Un detalle destacó. Varios preguntaron qué hacía exactamente el código malicioso, y la respuesta era que nadie podía tenerlo seguro, porque la cuenta del autor fue eliminada y las publicaciones maliciosas fueron borradas del registro en lugar de solo retiradas. El atacante se limpió a sí mismo. Esas son las señas de una operación que ha hecho esto antes. ## Cuando el código controla el dinero **En pocas palabras:** Un ataque a la cadena de suministro a un sitio web es molesto. Uno al software que guarda tu dinero es un problema totalmente distinto. La mayoría de los ataques a la cadena de suministro apuntan a desarrolladores y empresas, y el daño son credenciales robadas, datos robados o una limpieza lenta y cara. El radio de impacto es un servidor de compilación o una cuenta corporativa. Una wallet es distinta. El punto entero del software es poder mover tu dinero. Si el código en ese software, o los servidores de los que depende, puede ser comprometido, la brecha puede ir directo a los fondos. No hay ninguna capa de "oops, perdimos algunos logins" entre el atacante y tu saldo. Por eso el problema de la cadena de suministro y el problema de la autocustodia son el mismo problema. Ambos se tratan de dónde vive realmente la clave que controla tu dinero, y si cualquier punto único de la cadena, una librería, una empresa, un servidor, un mantenedor, un proveedor, puede tomarla. ## El problema del punto único de fallo **En pocas palabras:** Un punto único de fallo es lo que, si se rompe o es tomado, lo pierde todo. La mayoría de las wallets tienen uno. El objetivo es no tener ninguno. Un punto único de fallo es simple de definir y difícil de diseñar fuera. Es el único componente que, si es comprometido o deja de funcionar, hace que todo el sistema falle. Para un exchange de custodia, son sus servidores. Si esos son brechados, o simplemente congelan tu cuenta, tu dinero está a su merced. Para una wallet de software que deriva tu clave de un secreto en tu dispositivo, es ese único secreto. Si la app es comprometida a través de una actualización envenenada, o tu dispositivo es tomado, el secreto está expuesto. La razón por la que estos diseños tienen un punto único de fallo es que son cómodos. Un lugar para poner la clave significa un lugar para firmar y un lugar para hacer copia de seguridad. La comodidad y la seguridad tiran en direcciones opuestas, y la mayoría de los productos eligen la comodidad. Hay una mejor forma. Divide la autoridad para mover tu dinero en dos o más cosas que un atacante tendría que tomar juntas, y asegúrate de que ninguna de ellas mantiene la clave entera por sí sola. Entonces ninguna brecha sola, una librería mala, un servidor hackeado, un teléfono robado, una actualización maliciosa, gana por sí sola. El atacante tiene que tener éxito dos veces, en dos lugares distintos, al mismo tiempo. Esa es la diferencia entre un objetivo y una fortaleza. ## Cómo Nuri lo elimina **En pocas palabras:** Nuri usa un modelo de firma dividida donde solo una clave está nunca en el teléfono, y la segunda parte es sin estado, de modo que ni la app ni el servidor solos expongan tu clave. Nuri está construido sobre un esquema de firma dividida llamado MuSig2, en la forma 2-de-2 que puede expandirse a 2-de-3. Se necesitan dos partes separadas para firmar y mover los fondos, y ninguna parte sola puede hacerlo. En tu teléfono, solo una clave existe nunca: tu propia clave. Se deriva localmente de tu passkey, la credencial biométrica o de dispositivo que desbloquea tu teléfono, a través de una función que la convierte en una clave. Esa clave se genera en tu dispositivo y nunca lo abandona. No se sube, no se envía a un servidor para ser almacenada, y no está incrustada en la app como algo que podría ser extraído de un build comprometido. La segunda parte está mantenida por el servicio de cofirma de Nuri. Aquí está la parte que importa para esta historia. Ese servicio está construido para ser sin estado. Mantiene la autoridad para cofirmar dentro de la política que has fijado para tu wallet, pero no almacena una copia de tu clave. No hay un almacén de claves de usuario en los servidores de Nuri que brechar. Si la app que ejecutas es comprometida a través de un bug de cadena de suministro, el atacante obtiene una app comprometida, no tu clave. Si los servidores de Nuri son hackeados, el atacante obtiene un servicio sin estado sin claves de usuario que tomar. Ninguno de los dos eventos, por sí solo, expone la clave privada. El resultado es que el patrón de arrayref, una dependencia envenenada que ejecuta código en la compilación, no se traduce en una wallet robada. La clave que importa está en el teléfono, derivada de algo en el teléfono, y la segunda pieza de firma vive con un servicio que no tiene nada que entregar. Robar el dinero requiere dos partes completas, y están en dos lugares distintos que el atacante tendría que alcanzar a la vez. El diseño también mantiene una salida. El acuerdo de cofirma tiene un límite de tiempo. Después de una ventana fija, el usuario tiene una ruta de recuperación independiente que no depende del cofirmante. Y si quieres aún más separación, se puede añadir una wallet de hardware como tercera parte, haciendo 2-de-3, de modo que ningún dispositivo o servicio solo, teléfono o servidor, mantiene suficiente para mover tus fondos. ## Modelos de wallet, comparados con una pregunta **En pocas palabras:** Hazle la misma pregunta a cada modelo: si la única cosa se rompe, ¿tu dinero está perdido? La comparación que importa no son las funciones. Es qué expone una sola brecha. Aquí hay cuatro modelos de custodia comunes a los que se les hace la misma pregunta. | Modelo | Dónde está la clave | La app se compromete | El servidor del proveedor se brecha | Lo que el atacante necesita | | --- | --- | --- | --- | --- | | Exchange de custodia | En los servidores del exchange | No puedes mover tu dinero | Los fondos pueden ser congelados o tomados | Una cosa, el exchange | | Wallet de software de una clave | Un secreto en tu dispositivo | El secreto puede ser expuesto | Aunque no en el camino, la app es el riesgo | Una cosa, el secreto de tu dispositivo | | MPC con parte almacenada en servidor | Dividida, una parte en el servidor | La app puede exponer el manejo de la parte | Una parte almacenada puede ser robada | La parte almacenada más la del dispositivo | | Nuri, cofirma sin estado | Una clave en el teléfono, una parte sin estado en Nuri | No hay clave útil en la app | No hay clave de usuario almacenada que tomar | Dos partes completas, en dos lugares | - No documentado significa que la capacidad no es parte del diseño descrito, no que nunca pueda existir. - La columna de Nuri describe el modelo 2-de-2 con un cofirmante sin estado, expandible a 2-de-3 con una copia de seguridad de hardware. - Ningún modelo es inmune a cada ataque. Esto es una comparación del punto único de fallo que cada uno deja atrás. ## El pequeño glosario **En pocas palabras:** Las palabras que usa esta historia, en una línea cada una. **Ataque a la cadena de suministro:** Una brecha de un componente o dependencia en el que otros confían, para que el atacante alcance a todos los que lo usan. **Typosquat:** Un nombre que parece uno conocido con un pequeño cambio de ortografía, para ser tomado por error. proc-macro1 por proc-macro2. **Guion de compilación:** Código que se ejecuta automáticamente cuando se compila un proyecto. En Rust puede ejecutarse antes que tu propio código, por eso es un objetivo primario. **Punto único de fallo:** El único componente cuya pérdida o brecha hace fallar todo el sistema. **Autocustodia:** Tú mantienes la autoridad para mover tu propio dinero, en lugar de que una empresa lo mantenga por ti. **MuSig2:** Un esquema de firma que puede dividir el derecho a firmar entre varias claves, para que ninguna sola clave pueda mover los fondos sola. **Sin estado:** El servicio no mantiene una copia persistente de tu clave. No hay nada almacenado que una brecha pueda robar. **Passkey:** La credencial biométrica o de dispositivo que desbloquea tu teléfono, usada aquí para derivar tu clave localmente. ## Preguntas que la gente hace **En pocas palabras:** Los ataques a la cadena de suministro son un riesgo real y creciente para el software alrededor de tu dinero. Nuri está diseñado para que ninguno de ellos, por sí solo, exponga tu clave. ### Qué tiene que ver este ataque de Rust con mi wallet? Indirectamente, mucho. La lección no es sobre Rust. Es que el software entre tú y tu dinero está hecho de piezas que no controlas, y cualquiera de ellas puede estar envenenada. Una wallet es software cuyo trabajo es mover tus fondos, así que una brecha de cadena de suministro es un riesgo directo a ese dinero, no solo a una máquina de desarrollo. ### ¿Este ataque golpeó a alguna wallet o a algún usuario de bitcoin? No hay evidencia de que las versiones maliciosas fueran usadas para golpear alguna wallet o a alguna persona. El equipo de Rust reportó evidencia de uso real, y no existe una versión parcheada porque la corrección fue eliminar las publicaciones malas. El riesgo es el patrón, que se aplica a cualquier software que depende de código de terceros, y las wallets son objetivos de alto valor para ese patrón. ### ¿La autocustodia me protege de los ataques a la cadena de suministro? Depende del diseño. La autocustodia significa que tú mantienes la autoridad, pero si esa autoridad es una clave en un lugar, una sola brecha aún gana. La protección viene de eliminar el punto único de fallo, de modo que la autoridad esté dividida y ningún componente solo, app, servidor o dispositivo, mantenga suficiente por sí solo. ### Qué debería hacer yo ahora mismo? Para tu software, mantén tus dependencias fijas y actualizadas, y vigila nuevos nombres de dependencias maliciosas después de incidentes como este. Para tu dinero, elige un modelo de custodia donde una sola brecha no exponga tu clave. Si usas Nuri, no hay nada que hacer. El diseño ya mantiene una clave en tu teléfono y una parte sin estado en nuestro lado, así que una app comprometida o un servidor brechado no le entregan al atacante tu clave. ### ¿Una wallet de hardware resuelve esto? Una wallet de hardware mueve la firma lejos del teléfono y la app, lo que quita mucho del riesgo de cadena de suministro de la app. Es una elección fuerte. Nuri puede usar una como tercera parte en una configuración 2-de-3, lo que añade separación encima de la cofirma sin estado en lugar de reemplazarla. ### Qué significa sin estado para el servidor de Nuri? Significa que el servicio de cofirma no almacena tu clave. Mantiene la capacidad de cofirmar dentro de la política de tu wallet, no una copia de la clave privada en sí. Así que no hay un almacén de claves en los servidores de Nuri para un atacante brechar. La clave privada se deriva en tu teléfono de tu passkey y se queda ahí. ### Si la app está comprometida, ¿puede un atacante ver mi saldo o enviar dinero? Una app comprometida puede ver lo que la app misma puede ver, y una actualización maliciosa podría mostrar información falsa. Pero mover tu dinero requiere una firma, y la firma necesita ambas partes trabajando juntas. Un cofirmante sin estado sin clave almacenada no puede producir esa firma por sí solo, y la clave del teléfono nunca abandona el dispositivo. ### ¿Por qué le importaría a un atacante una wallet? Porque es dinero directo. La puerta trasera de arrayref fue construida para robar credenciales, que pueden ser comerciadas o usadas para alcanzar más. Una clave de wallet es la credencial más directa que hay. Por eso es exactamente el punto único de fallo la cosa a eliminar. Haz la clave imposible de obtener de un solo lugar, y el atacante tiene que ser el doble de afortunado y el doble de coordinado. ### Qué puedo hacer yo como desarrollador para proteger mis compilaciones? Fija las versiones de tus dependencias y no actualices automáticamente a una publicación de última hora el día que se publique. Muchos equipos esperan unos días para que los auditores y las empresas de seguridad se miren primero una versión nueva. Mantén una auditoría de tu árbol de dependencias, y vigila nombres de dependencias nuevos después de un incidente como este. Estos pasos reducen la ventana en la que una publicación envenenada puede alcanzarte. ### Cada cuánto ocurren ataques como este? Más de lo que las portadas sugieren. Los proveedores que rastrean los registros de paquetes cuentan miles de paquetes maliciosos nuevos cada trimestre, y el número sigue creciendo año tras año. La mayoría nunca sale en las noticias porque son typosquats que nadie instala. Los que salen en las noticias, como arrayref, son los que golpean un paquete popular y de confianza. Esa es la clase de evento que importa a cualquiera cuyo dinero depende de software. ## Fuentes y nota de actualización Los detalles del ataque son a fecha del 2026-08-21 y provienen del post enlazado del equipo de Rust, informes de empresas de seguridad y el hilo de Hacker News. Las estadísticas son estimaciones de los informes de industria de 2026 enlazados y varían según la fuente. Confirma los números actuales antes de apoyarte en ellos para una decisión. 1. [Blog de Rust: ataque a la cadena de suministro de arrayref](https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/) 2. [The Hacker News: ataque de Rust pone malware de compilación en crates](https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html) 3. [Wiz: ataque a la cadena de Rust en arrayref, superposición con DPRK](https://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-overlap-with-dprk-campaigns) 4. [Socket: crates populares de Rust comprometidos](https://socket.dev/blog/popular-rust-crates-compromised) 5. [BleepingComputer: hackers envenenan el crate Rust arrayref](https://www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware/) 6. [Hacker News: crate maliciosa de Rust Arrayref ejecuta una carga de compilación](https://news.ycombinator.com/item?id=49374269) 7. [Advisory RustSec RUSTSEC-2026-0260](https://rustsec.org/advisories/RUSTSEC-2026-0260.html) 8. [CVE-2026-77651: brecha de cadena de suministro de arrayref](https://cvefeed.io/vuln/detail/CVE-2026-77651) 9. [AppSec Santa: estadísticas de ataques a la cadena de suministro 2026](https://appsecsanta.com/research/supply-chain-attack-statistics) ## También disponible en - [The arrayref supply chain attack, and why your wallet needs no single point of failure](https://nuri.com/knowledge/supply-chain-attack-arrayref) (en) - [Der arrayref-Supply-Chain-Angriff, und warum deine Wallet keine einzelne Angriffsfläche braucht](https://nuri.com/de/wissen/arrayref-supply-chain-angriff) (de) - [L'attacco alla supply chain di arrayref, e perché il tuo wallet non ha bisogno di un singolo punto di guasto](https://nuri.com/it/conoscenza/attacco-a-arrayref-nella-cadena-di-fornitura) (it) --- --- title: "L'attacco alla supply chain di arrayref, e perché il tuo wallet non ha bisogno di un singolo punto di guasto" description: "Una breach di 2 ore di un crate Rust con 245 milioni di download, e cosa significa per il software che muove i tuoi soldi." lang: "it" type: "knowledge-guide" datePublished: "2026-08-21" dateModified: "2026-08-21" canonical: "https://nuri.com/it/conoscenza/attacco-a-arrayref-nella-cadena-di-fornitura" tags: ["attacco alla supply chain","crate arrayref","singolo punto di guasto","self-custody","sicurezza del wallet bitcoin","MuSig2","co-firma stateless"] --- # L'attacco alla supply chain di arrayref, e perché il tuo wallet non ha bisogno di un singolo punto di guasto **TL;DR:** I gliattor hanno compromesso l'account di una nota libreria Rust e pubblicato una versione falsa che eseguiva malware sulla macchina nel momento in cui qualcuno la compilava. La versione malevola è rimasta online per circa 86 minuti, e la libreria ha 245 milioni di download. Questo fa parte di un'onda di attacchi alla supply chain che diventano più frequenti e più aggressivi. La lezione più grande per chiunque i cui soldi dipendono da un software è che il codice e i server tra te e i tuoi fondi sono un singolo punto di guasto. Nuri è costruito in modo che nessuna singola breach, né un'app compromessa né un server violato, esponga la chiave che controlla il tuo bitcoin. Solo una chiave sta mai sul telefono. La seconda parte vive in un servizio stateless. Rubare i soldi richiede entrambe. ## Indice - [La risposta rapida](#quick-answer) - [Cosa è successo davvero](#what-happened) - [Perché questa è la nuova normalità](#new-normal) - [Cosa dicono gli sviluppatori](#what-developers-say) - [Quando il codice controlla i soldi](#why-it-matters) - [Il problema del singolo punto di guasto](#single-point) - [Come Nuri lo rimuove](#how-nuri) - [Modelli di wallet, confrontati su una domanda](#comparison) - [Il piccolo glossario](#glossary) - [Domande che la gente pone](#faqs) ## La risposta rapida **In breve:** Una versione falsa di una libreria popolare eseguiva malware sulle macchine durante la compilazione. La lezione: il software tra te e i tuoi soldi è un singolo punto di guasto, quindi progetta in modo che nessuna singola breach vinca. Il 20 agosto 2026 è arrivato un rapporto che un crate Rust chiamato proc-macro1 era malevolo. Il Rust Security Response Team lo ha confermato in pochi minuti: il crate portava un build script che scaricava ed eseguiva un payload remoto. Compilare qualsiasi progetto che includeva il crate era sufficiente per eseguirlo. Nessuno doveva chiamare alcuna funzione. La compilazione stessa era l'innesco. Il vero obiettivo era arrayref, un crate piccolo e noto usato da un numero enorme di altri progetti. Il suo account di proprietario era stato compromesso. L'attaccante ha pubblicato una nuova versione di arrayref che dipendeva dal crate falso, e ha ritirato in silenzio le versioni vecchie perché il tool di compilazione indirizzasse gli utenti alla versione cattiva. Nulla di questo riguarda specificamente Rust. Riguarda come viene costruito il software: tutti facciamo affidamento su migliaia di pezzi scritti da altre persone, e uno di loro può essere quello velenoso. Quando la cosa che tiene i tuoi soldi è un software, questo smette di essere un problema di sviluppatore e diventa un problema di soldi. ## Cosa è successo davvero **In breve:** Un account manutentore compromesso ha pubblicato una dipendenza falsa. Compilare il crate scaricava ed eseguiva un backdoor che ruba credenziali. Tutto è rimasto online meno di due ore. L'attaccante non ha riscritto la libreria. Ha aggiunto una riga: una dipendenza su proc-macro1, un errore deliberato nella scrittura di proc-macro2, uno dei crate più scaricati di tutto l'ecosistema. Il crate falso è una copia genuina di quello vero, quindi la build va a buon fine e il software continua a funzionare. Questo è esattamente il punto. Nulla sembra rotto. Il payload si esegue prima che tu noti qualsiasi cosa. Il build script ricostruiva in silenzio l'indirizzo del server dell'attaccante a partire da pezzi di testo codificato, disattivava il controllo di sicurezza che verifica l'identità del server e scaricava un programma scelto per il tuo sistema operativo e processore. Su Mac e Linux scriveva il file in una cartella temporanea e lo lanciava in background. Su Windows scriveva uno script e lo avviava nascosto. L'attaccante ha scelto tutto questo per evitare di essere notato durante la compilazione. Il backdoor scaricato è malware vero, non un test. I ricercatori di sicurezza che l’hanno analizzato hanno trovato che chiama a casa, legge il nome del computer e l’utente, elenca i programmi installati e cerca nei profili del browser i login salvati. Si installa per tornare dopo il riavvio. Può scaricare ed eseguire più codice su richiesta. Se il server principale va giù, genera nuovi nomi di dominio per trovarne uno nuovo. Le versioni malevole sono state rimosse rapidamente: arrayref 0.3.10 è rimasto online circa 86 minuti, e i due crate correlati circa 90 e 107 minuti. Il team Rust ha bloccato l'account del proprietario come precauzione e ha dichiarato di non credere che l'autore agisse in mala fede. È più probabile che il suo computer o il suo login siano stati compromessi. L'autore di arrayref mantiene il crate dal 2009. Wiz, un’azienda di sicurezza, ha trovato che l’infrastruttura dell’attaccante sovrappone operazioni recenti attribuite alla Corea del Nord, incluse campagne contro altre librerie popolari. Non è stato un evento isolato di un dilettante casuale. È stata una campagna organizzata usando un pattern che avevano già usato prima. - Obiettivo: arrayref 0.3.10, internment 0.8.7 e append-only-vec 0.1.9, tutti da un account compromesso. - Veicolo: una nuova dipendenza, proc-macro1, un errore di scrittura dell’onnipresente proc-macro2. - Innesco: la build stessa. Eseguire cargo build su un progetto interessato eseguiva il payload. - Online: da 86 a 107 minuti prima della rimozione il 2026-08-20. - Scala: arrayref ha 245 milioni di download e compare nella maggioranza degli ambienti che usano Rust. ## Perché questa è la nuova normalità **In breve:** Gli attacchi alla supply chain non sono un caso raro. Sono una parte in crescita, industrializzata e sempre più automatizzata di come viene attaccato internet. L'attacco ad arrayref sembra shockante perché ha colpito una libreria popolare e di fiducia. Ma i numeri dicono che non dovrebbe esserlo. La stessa classe di attacco opera da anni contro ogni registry di pacchetti maggiore, e il tasso sale. I vendor che monitorano questo riportano oltre un milione di pacchetti malevoli su npm, PyPI, Maven, NuGet e Hugging Face, con il conteggio di pacchetti malevoli nuovi nel 2025 in aumento di circa il 75 per cento rispetto all’anno prima. Il costo stimato degli attacchi alla supply chain ha raggiunto circa 60 miliardi di dollari nel 2025, con proiezioni vicine a 138 miliardi entro il 2030. Circa il 30 per cento delle breach di dati coinvolge ora un terzo, e la maggior parte delle vulnerabilità nel software commerciale si trova non nel codice principale ma nelle dipendenze che incorpora. Due cose lo peggiorano allo stesso tempo. Primo, il tooling che costruisce ed esegue il software è diventato più complesso, quindi ci sono più parti mobili che un attaccante può toccare. Secondo, gli attaccanti usano l’IA per trovare bersagli, scrivere il codice malevolo e scalare la campagna, mentre le persone responsabili di revisionare ogni dipendenza sono per lo più volontari non retribuiti. Su Hacker News, dove il thread principale ha raggiunto 400 punti e centinaia di commenti, la verità scomoda è che gli sviluppatori lo vedono arrivare. Una delle osservazioni più votate era che il tooling di build esegue codice sulla tua macchina senza il tuo consenso, quindi aggiungere una dipendenza basta a comprometterti prima ancora di revisionare il codice. Un’altra ha notato che la stessa cosa è successa con la breach della libreria di compressione xz, e che nessuno può leggere ogni piccolo pacchetto dell’albero profondo delle dipendenze per dimostrarlo pulito. ## Cosa dicono gli sviluppatori **In breve:** La reazione non è panico. È un riconoscimento stanco e informato che il tooling di build non era mai stato progettato come un confine di sicurezza. La discussione su Hacker News è stata insolitamente calma e specifica, che di solito è il segno di una community esperta che affronta un problema noto. Ecco cosa continuava a venire, nelle loro parole, leggermente ridotta. Su perché continua a succedere: "Dopo molti attacchi precedenti alla supply chain, perché i manutentori dei registry di pacchetti permettono ancora a chiunque di caricare pacchetti e spingere aggiornamenti senza audit di sicurezza?" Questa domanda non era retorica. Il seguito era il vero problema: "Chi finanzia questo audit di sicurezza? La gente dovrebbe fare volontariato del suo tempo libero?" Sul tooling di build: "Il problema è che i build script si eseguiscono automaticamente senza consenso o intervento dell’utente. Aggiungere una dipendenza basta a comprometterti, prima che tu abbia la possibilità di revisionare il codice." Diversi hanno notato che altri package manager hanno controlli che Cargo non ha, come l’allowlist dei script di installazione e un cooldown sulle dipendenze di giornata. Sull'obiettivo: "Le macchine degli sviluppatori sono bersagli molto succosi. Tendono ad avere ogni sorta di credenziali sparse, quindi spesso non è troppo difficile escalare da lì a compromettere i tuoi account cloud." Questo è il vero premio nella maggior parte di questi attacchi. Non è la macchina. È tutto ciò che quella macchina può raggiungere. Su se la lingua conti: "Rust sembra appena meglio di Node in questo." La controargomentazione, anch’essa ampiamente condivisa, è che l’ecosistema ha già strumenti di audit, e diverse grandi aziende pubblicano audit dei crate di cui dipendono. Il gap è che l’audit è l’eccezione, non la norma. Un dettaglio ha colpito. Diversi hanno chiesto cosa facesse esattamente il codice malevolo, e la risposta era che nessuno poteva esserne sicuro, perché l’account dell’autore era stato eliminato e le pubblicazioni malevole erano state cancellate dal registry anziché solo ritirate. L’attaccante si è pulito dietro. È il marchio di un’operazione che ha già fatto questa cosa prima. ## Quando il codice controlla i soldi **In breve:** Un attacco alla supply chain su un sito web è fastidioso. Uno sul software che tiene i tuoi soldi è un problema completamente diverso. La maggior parte degli attacchi alla supply chain colpisce sviluppatori e aziende, e il danno sono credenziali rubate, dati rubati o una pulizia lenta e costosa. L'area d'impatto è un server di build o un account aziendale. Un wallet è diverso. Il punto intero del software è poter muovere i tuoi soldi. Se il codice in quel software, o i server di cui dipende, può essere compromesso, la breach può andare dritta ai fondi. Non c’è un livello di "ops, abbiamo perso qualche login" tra l’attaccante e il tuo saldo. Per questo il problema della supply chain e il problema del self-custody sono lo stesso problema. Entrambi riguardano dove vive davvero la chiave che controlla i tuoi soldi, e se un singolo punto della catena, una libreria, un’azienda, un server, un manutentore, un provider, può prenderla. ## Il problema del singolo punto di guasto **In breve:** Un singolo punto di guasto è la cosa che, se si rompe o viene presa, fa perdere tutto. La maggior parte dei wallet ne ha uno. L’obiettivo è non averne. Un singolo punto di guasto è semplice da definire e difficile da progettare via. È l’unica componente che, se compromessa o in disavvio, fa fallire l’intero sistema. Per un exchange in custodia, sono i suoi server. Se vengono violati, o semplicemente congelano il tuo account, i tuoi soldi sono alla loro mercé. Per un wallet software che deriva la tua chiave da un segreto sul tuo dispositivo, è quel singolo segreto. Se l’app viene compromessa tramite un update velenoso, o il tuo dispositivo viene preso, il segreto è esposto. Il motivo per cui questi design hanno un singolo punto di guasto è che sono comodi. Un posto per mettere la chiave significa un posto per firmare e un posto per fare il backup. Comodità e sicurezza tirano in direzioni opposte, e la maggior parte dei prodotti sceglie la comodità. Esiste una forma migliore. Dividi l’autorità di muovere i tuoi soldi in due o più cose che un attaccante dovrebbe prendere insieme, e assicurati che nessuna di esse tenga la chiave intera da sola. Allora nessuna singola breach, una libreria cattiva, un server violato, un telefono rubato, un update malevolo, vince da sola. L’attaccante deve avere successo due volte, in due posti diversi, nello stesso momento. Questa è la differenza tra un bersaglio e una fortezza. ## Come Nuri lo rimuove **In breve:** Nuri usa un modello di firma divisa in cui solo una chiave sta mai sul telefono, e la seconda parte è stateless, quindi né l’app né il server da soli espongono la tua chiave. Nuri è costruito su uno schema di firma divisa chiamato MuSig2, nella forma 2-di-2 che può essere espansa a 2-di-3. Servono due parti separate per firmare e muovere i fondi, e nessuna parte da sola può farlo. Sul tuo telefono, solo una chiave esiste mai: la tua chiave. È derivata localmente dal tuo passkey, la credenziale biometrica o di dispositivo che sblocca il tuo telefono, attraverso una funzione che la trasforma in una chiave. Questa chiave è generata sul tuo dispositivo e non lo lascia mai. Non viene caricata, non viene inviata a un server per essere memorizzata, e non è incorporata nell’app come qualcosa che potrebbe essere estratto da un build compromesso. La seconda parte è tenuta dal servizio di co-firma di Nuri. Qui sta la parte che conta per questa storia. Questo servizio è costruito per essere stateless. Tiene l’autorità di co-firmare entro la policy che hai impostato per il tuo wallet, ma non memorizza una copia della tua chiave. Non c’è un vault di chiavi utente sui server Nuri da violare. Se l’app che esegui viene compromessa tramite un bug di supply chain, l’attaccante ottiene un’app compromessa, non la tua chiave. Se i server Nuri vengono violati, l’attaccante ottiene un servizio stateless senza chiavi utente da prendere. Nessuno dei due eventi, da solo, espone la chiave privata. Il risultato è che il pattern di arrayref, una dipendenza velenosa che esegue codice in build, non si traduce in un wallet rubato. La chiave che conta è sul telefono, derivata da qualcosa sul telefono, e il secondo pezzo di firma vive con un servizio che non ha nulla da cedere. Rubare i soldi richiede due parti intere, e stanno in due posti diversi che l’attaccante dovrebbe raggiungere insieme. Il design mantiene anche un’uscita. L’accordo di co-firma ha un limite di tempo. Dopo una finestra fissa, l’utente ha un percorso di recupero indipendente che non dipende dal co-firmante. E se vuoi ancora più separazione, si può aggiungere un hardware wallet come terza parte, rendendolo 2-di-3, in modo che nessun singolo dispositivo o servizio, telefono o server, tenga abbastanza per muovere i tuoi fondi. ## Modelli di wallet, confrontati su una domanda **In breve:** Fai a ogni modello la stessa domanda: se l’unica cosa si rompe, i tuoi soldi sono finiti? Il confronto che conta non sono le funzioni. È cosa espone una singola breach. Ecco quattro modelli di custodia comuni a cui viene posta la stessa domanda. | Modello | Dove sta la chiave | L'app è compromessa | Il server del provider è violato | Cosa serve all’attaccante | | --- | --- | --- | --- | --- | | Exchange in custodia | Sui server dell’exchange | Non puoi muovere i tuoi soldi | I fondi possono essere congelati o presi | Una cosa, l’exchange | | Wallet software a chiave singola | Un segreto sul tuo dispositivo | Il segreto può essere esposto | Di solito non nel percorso, ma l’app è il rischio | Una cosa, il segreto del tuo dispositivo | | MPC con parte memorizzata sul server | Divisa, una parte sul server | L'app può esporre la gestione della parte | Una parte memorizzata può essere rubata | La parte memorizzata più quella del dispositivo | | Nuri, co-firma stateless | Una chiave sul telefono, una parte stateless su Nuri | Nessuna chiave utilizzabile nell’app | Nessuna chiave utente memorizzata da prendere | Due parti intere, in due posti | - Non documentato significa che la capacità non fa parte del design descritto, non che non possa mai esistere. - La colonna Nuri descrive il modello 2-di-2 con un co-firmante stateless, espandibile a 2-di-3 con un backup hardware. - Nessun modello è immune a ogni attacco. Questo è un confronto del singolo punto di guasto che ognuno lascia dietro. ## Il piccolo glossario **In breve:** Le parole che questa storia usa, una riga ciascuna. **Attacco alla supply chain:** Una compromise di una componente o dipendenza su cui altri si fidano, in modo che l'attaccante raggiunga tutti quelli che la usano. **Typosquat:** Un nome che sembra uno noto con un piccolo cambio di ortografia, per essere preso per errore. proc-macro1 per proc-macro2. **Build script:** Codice che si esegue automaticamente quando si compila un progetto. In Rust può eseguire prima del tuo codice, motivo per cui è un bersaglio privilegiato. **Singolo punto di guasto:** L'unica componente la cui perdita o compromissione fa fallire l'intero sistema. **Self-custody:** Tu tieni l’autorità di muovere i tuoi soldi, invece di una compagnia che li tiene per te. **MuSig2:** Uno schema di firma che può dividere il diritto di firmare tra più chiavi, in modo che nessuna singola chiave possa muovere i fondi da sola. **Stateless:** Il servizio non mantiene una copia persistente della tua chiave. Non c’è nulla di memorizzato che una breach possa rubare. **Passkey:** La credenziale biometrica o di dispositivo che sblocca il tuo telefono, usata qui per derivare localmente la tua chiave. ## Domande che la gente pone **In breve:** Gli attacchi alla supply chain sono un rischio reale e in crescita per il software attorno ai tuoi soldi. Nuri è progettato in modo che nessuno di essi, da solo, esponga la tua chiave. ### Cosa c’entra questo attacco Rust con il mio wallet? Indirettamente, molto. La lezione non è su Rust. È che il software tra te e i tuoi soldi è fatto di pezzi che non controlli, e uno di loro può essere velenoso. Un wallet è un software il cui lavoro è muovere i tuoi fondi, quindi una compromise di supply chain è un rischio diretto per quei soldi, non solo per una macchina di sviluppo. ### Questo attacco ha colpito qualche wallet o qualche utente bitcoin? Non c’è evidenza che le versioni malevole siano state usate per colpire qualche wallet o qualche persona. Il team Rust ha riportato evidenze di uso reale, e non esiste una versione corretta perché la correzione è stata eliminare le pubblicazioni cattive. Il rischio è il pattern, che si applica a qualsiasi software che dipende da codice di terze parti, e i wallet sono bersagli ad alto valore per quel pattern. ### Il self-custody mi protegge dagli attacchi alla supply chain? Dipende dal design. Self-custody significa che tu tieni l'autorità, ma se quell'autorità è una chiave in un posto, una singola compromise vince comunque. La protezione viene dal rimuovere il singolo punto di guasto, in modo che l'autorità sia divisa e nessuna singola componente, app, server o dispositivo, tenga abbastanza da sola. ### Cosa dovrei fare io adesso? Per il tuo software, mantieni le versioni delle dipendenze fissate e aggiornate, e tieni d’occhio nuovi nomi di dipendenze malevole dopo incidenti come questo. Per i tuoi soldi, scegli un modello di custodia in cui una singola breach non esponga la tua chiave. Se usi Nuri, non c’è nulla da fare. Il design mantiene già una chiave sul tuo telefono e una parte stateless dal nostro lato, quindi un’app compromessa o un server violato non consegnano all’attaccante la tua chiave. ### Un hardware wallet risolve questo? Un hardware wallet sposta la firma via dal telefono e dall’app, che rimuove molto del rischio di supply chain dell’app. È una scelta forte. Nuri può usarne uno come terza parte in un setup 2-di-3, che aggiunge separazione sopra la co-firma stateless invece di sostituirla. ### Cosa significa stateless per il server Nuri? Significa che il servizio di co-firma non memorizza la tua chiave. Tiene la capacità di co-firmare entro la policy del tuo wallet, non una copia della chiave privata in sé. Quindi non c'è un vault di chiavi sui server Nuri per un attaccante da violare. La chiave privata è derivata sul tuo telefono dal tuo passkey e resta lì. ### Se l'app è compromessa, può un attaccante vedere il mio saldo o inviare soldi? Un'app compromessa può vedere ciò che l'app stessa può vedere, e un update malevolo potrebbe mostrare informazioni false. Ma muovere i tuoi soldi richiede una firma, e la firma ha bisogno di entrambe le parti che lavorino insieme. Un co-firmante stateless senza chiave memorizzata non può produrre quella firma da solo, e la chiave del telefono non lascia mai il dispositivo. ### Perché un attaccante dovrebbe curarsi di un wallet? Perché è denaro diretto. Il backdoor di arrayref è stato costruito per rubare credenziali, che possono essere scambiate o usate per raggiungere altro. Una chiave di wallet è la credenziale più diretta che esista. Ecco perché esattamente il singolo punto di guasto è la cosa da rimuovere. Rendi la chiave impossibile da ottenere da un solo posto, e l’attaccante deve essere doppio fortunato e doppio coordinato. ### Cosa posso fare io come sviluppatore per proteggere le mie build? Fissa le versioni delle tue dipendenze e non aggiornare automaticamente a una pubblicazione di giornata il giorno in cui esce. Molte team aspettano pochi giorni perché auditor e aziende di sicurezza guardino prima una versione nuova. Mantieni un audit del tuo albero di dipendenze, e tieni d’occhio nomi di dipendenze nuovi dopo un incidente come questo. Questi passi riducono la finestra in cui una pubblicazione velenosa può raggiungerti. ### Come spesso succedono attacchi come questo? Più di quanto i titoli suggeriscano. I vendor che monitorano i registry contano migliaia di pacchetti malevoli nuovi ogni trimestre, e il numero continua a crescere anno su anno. La maggior parte non fa mai notizia perché sono typosquat che nessuno installa. Quelli che fanno notizia, come arrayref, sono quelli che colpiscono un pacchetto popolare e di fiducia. Questa è la classe di evento che conta per chiunque i cui soldi dipendono da un software. ## Fonti e nota di aggiornamento I dettagli dell'attacco sono al 2026-08-21 e provengono dal post del team Rust collegato, dai rapporti delle aziende di sicurezza e dal thread di Hacker News. Le statistiche sono stime dai rapporti di industria 2026 collegati e variano per fonte. Conferma i numeri attuali prima di affidarti a essi per una decisione. 1. [Blog Rust: attacco alla supply chain di arrayref](https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/) 2. [The Hacker News: attacco Rust mette malware in build nei crate](https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html) 3. [Wiz: attacco alla supply chain Rust su arrayref, sovrapposizione DPRK](https://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-overlap-with-dprk-campaigns) 4. [Socket: crate Rust popolari compromesse](https://socket.dev/blog/popular-rust-crates-compromised) 5. [BleepingComputer: hacker avvelenano il crate Rust arrayref](https://www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware/) 6. [Hacker News: crate malevola Rust Arrayref esegue un payload in build](https://news.ycombinator.com/item?id=49374269) 7. [Avviso RustSec RUSTSEC-2026-0260](https://rustsec.org/advisories/RUSTSEC-2026-0260.html) 8. [CVE-2026-77651: compromise di supply chain di arrayref](https://cvefeed.io/vuln/detail/CVE-2026-77651) 9. [AppSec Santa: statistiche attacchi alla supply chain 2026](https://appsecsanta.com/research/supply-chain-attack-statistics) ## Disponibile anche in - [The arrayref supply chain attack, and why your wallet needs no single point of failure](https://nuri.com/knowledge/supply-chain-attack-arrayref) (en) - [Der arrayref-Supply-Chain-Angriff, und warum deine Wallet keine einzelne Angriffsfläche braucht](https://nuri.com/de/wissen/arrayref-supply-chain-angriff) (de) - [El ataque a la cadena de suministro de arrayref, y por qué tu wallet no necesita un punto único de fallo](https://nuri.com/es/conocimiento/ataque-de-cadena-de-suministro-arrayref) (es) --- --- title: "Building Nuri for the days when something breaks" description: "What Nuri learned from two weeks of real-world failures, and how we are making the app clearer, more resilient and easier to support." lang: "en" type: "blog-post" author: "Emin Mahrt" datePublished: "2026-08-11" dateModified: "2026-08-11" canonical: "https://nuri.com/blog/building-nuri-for-the-days-when-something-breaks" tags: ["Nuri","product reliability","Bitcoin","Lightning","payment routes"] --- # Building Nuri for the days when something breaks **TL;DR:** If one payment route stops working, the whole app should not feel broken. Nuri needs clear status, working fallbacks and support that knows what is available right now. We will move faster without pretending failures will stop happening, and show more clearly what works when they do. - **Author:** Emin Mahrt - **Published:** 2026-08-11 ## These two weeks did not go to plan We had a plan for the last two weeks. Then the two weeks happened. We wanted to spend the time polishing the app, starting distribution and bringing in more users. Instead, we spent a lot of it reacting to problems across Bitcoin, Lightning and different payment routes. Honestly, it was exhausting. Not because every problem was catastrophic. We are still early, and the number of affected users was manageable. But it felt like Groundhog Day: fix one moving part, another one changes, then a fallback stops working, then something else needs attention. My first reaction was frustration. After thinking about it, though, the bigger lesson became obvious. This is going to happen again. > “I must say I feel exhausted after these two weeks.” > > — Emin Mahrt · From the original recording **Basically,** We planned a normal two-week sprint. Reality gave us two weeks of firefighting instead. ## This is the environment we build in Nuri connects many different financial systems. Banking, cards, Bitcoin, Lightning, local currencies and payment rails all behave differently. Some parts are ours. Some parts connect us to outside infrastructure. Every part can change, go into maintenance or temporarily stop working. Everyone in this space is building difficult systems, including us. Changes and interruptions are part of that work. We chose to bring these systems together, so the experience users have when something changes is our responsibility. Our job is not to pretend every moving part will work perfectly forever. Our job is to make sure Nuri remains useful when one of them does not. > “if you're building a puzzle with many moving parts, of course, those moving parts are going to work, going to not work, going to break.” > > — Emin Mahrt · From the original recording **Basically,** Things will sometimes stop working. Our app still needs to make sense when they do. ## A fallback must work when you need it The most frustrating moment was not that a feature stopped working. That can happen. The frustrating part was discovering that a fallback was no longer available in the situation where users needed it. That taught us something very simple: a fallback that only works under normal conditions is not much of a fallback. We need to keep removing single points of failure wherever we can. Sometimes that means adding another route. Sometimes it means letting users recover or exit without depending on us. Sometimes it simply means separating two features that look similar but fail for completely different reasons. Bitcoin and Bitcoin Lightning are a good example. To many users, they may look like two versions of the same thing. Technically, they are very different systems with different tradeoffs and different ways of failing. Presenting them as one seamless balance may look cleaner, but it also means a Lightning problem can make the entire Bitcoin experience feel broken. For now, separating them is more honest and more useful. Bitcoin can continue working when Lightning is unavailable. Lightning can clearly show its current status. Users should not need to understand the technical reason. They only need to know what works, what does not, and what they can do next. **Basically,** Bitcoin and Lightning should not take each other down. A fallback has to be real, not decorative. ## We tried too hard to hide the machinery For a long time, I wanted Nuri to hide all the complexity. That is still the goal in many places. Nobody should need to understand nodes, liquidity, payment routing or infrastructure providers to send money. But hiding complexity cannot mean hiding reality. If a route is temporarily unavailable, the app should say so. If something is under maintenance, it should look like it is under maintenance. If a currency is supported as a payment route but not as a balance, the interface should make that difference clear. We previously tried to avoid messages like "temporarily unavailable." They felt technical and unfriendly. Looking back, that created a worse experience. A button that looks available but fails after you press it is much more frustrating than a grayed-out button with a clear explanation. This changes how we think about the main Nuri screen. It should not only show where your money is. It should also show what you can currently do with it. You may have money in euros, but several ways to use those euros: card payments, bank transfers or conversion into another currency. Some payment rails do not need their own balance at all. They are simply another way to send or receive money. At the same time, we must never show the same money twice. If your card and bank account use the same underlying balance, displaying that amount under both can make it look like you have twice as much money as you actually have. The first version may not be beautiful, but it must be clear. **Basically,** Do not hide a broken route behind a working-looking button. Tell people what works before they tap. ## Support should know what the app knows This week also changed how I think about support. Support should not be a separate system with an outdated list of features. It should understand the same Nuri that the user is looking at. If a route is unavailable, support should know immediately. If a feature has been disabled, our support agent should not recommend it. If somebody asks why they cannot pay a Lightning invoice, support should be able to see whether the route works, explain the current situation and suggest an available alternative. This is where our MCP work becomes practical. MCP sounds technical, but the basic idea is simple: we want every Nuri capability to be available through a clean interface that both the app and agents can understand. The Nuri MCP should contain the features that are genuinely available in Nuri. Experimental features should live somewhere else until they are ready. Right now, those boundaries are not always clean. We have experiments, app features and independent services living too close together. That made sense while we were moving quickly and testing ideas. It makes less sense now that we want agents to support real users. When something becomes available in Nuri, the support agent should understand it. When something disappears from the app, it should also disappear from the agent's available actions. App, support and infrastructure should describe the same reality. **Basically,** Our support agent should never send you to a feature that is currently unavailable. ## We are not waiting for perfection We can spend months designing the perfect fallback for every possible failure. Then we launch and discover that users are confused by something completely different. We need real users. We need people to open Nuri, try to use it and tell us where they get stuck. Not because they have a theory about our interface, but because they wanted to do something and could not. That feedback is more useful than ten internal opinions. One example came up around separating cards and bank transfers. From a technical perspective, putting them together can look logical because they may share a balance. But users repeatedly asked where their IBAN was. They opened the card screen, saw a card and stopped looking. They did not expect bank transfers to be hidden there. Users do not need to know why we originally grouped two things together. They only know that they could not find what they needed. So we will move faster with rough screens and rough flows. Then we will watch where people struggle and improve those parts. Some things will not look perfect, and some experiments will fail. An idea can make sense in a meeting and feel wrong the moment somebody tries it. We would rather learn that now. > “it's okay that things break it's okay that they don't look good we just react on it and basically make the best out of it” > > — Emin Mahrt · From the original recording **Basically,** Get Nuri into more hands, watch where people struggle, and fix the real problems first. ## What we are doing next We will keep improving the app, but we will also start bringing more people into it. Distribution cannot remain the task we postpone whenever something breaks. We are separating features so one unavailable route does not damage the rest of the experience, adding clearer status information, and cleaning up the Nuri MCP so it matches the app. Support should know which capabilities are live. Better monitoring will help us find problems before they turn into long support conversations. For Lightning, we will look at the available options without rushing into another permanent dependency. There are several possible steps. We can support regular swaps between Bitcoin and Lightning, investigate faster versions later, review other non-custodial approaches, or keep improving our current integration when the required capabilities become available. We do not need to make every decision today. Bitcoin can remain useful without pretending every Lightning use case is already solved. Lightning is difficult, and the wider industry is still working through some hard problems. We would rather be honest about that than force a seamless-looking experience that becomes confusing when something changes. The same principle applies beyond Bitcoin. If one local currency route goes into maintenance, the rest of Nuri should continue working. If a card service is unavailable, users should still find their bank transfer options. If a feature is experimental, it should not quietly appear as if it were production-ready. **Basically,** Show what works, keep the fallbacks working, make support match the app, and get Nuri in front of more people. ## From the original recording > “otherwise the train leaves the station without customers” > > — Emin Mahrt ## This post is also available in - [Nuri für die Tage bauen, an denen etwas kaputtgeht](https://nuri.com/de/blog/building-nuri-for-the-days-when-something-breaks) (de) - [Construir Nuri para los días en que algo falla](https://nuri.com/es/blog/building-nuri-for-the-days-when-something-breaks) (es) - [Costruire Nuri per i giorni in cui qualcosa si rompe](https://nuri.com/it/blog/building-nuri-for-the-days-when-something-breaks) (it) --- --- title: "What Stripe's investor letter says about Nuri" description: "Stripe's investor letter describes the agent economy. Nuri sees the same future, built around open standards, self-custody and user independence." lang: "en" type: "blog-post" author: "Emin Mahrt" datePublished: "2026-08-20" dateModified: "2026-08-20" canonical: "https://nuri.com/blog/what-stripes-investor-letter-means-for-nuri" tags: ["Nuri","Stripe","agentic finance","stablecoins","MCP","non-custodial"] --- # What Stripe's investor letter says about Nuri **TL;DR:** On August 19, Stripe told its investors that AI agents are becoming economic actors and that money will become native to the AI economy. We read the letter and recognized the future we are building for. The thesis is the same. The approach is different: Stripe is integrating more of the stack into one platform. Nuri is building around open standards, self-custody and independence from Nuri itself. Agents can own money, act autonomously or work for a human inside clear limits. And that money is not only stablecoins and fiat. It includes bitcoin, Lightning and whatever open rails come next. - **Author:** Emin Mahrt - **Published:** 2026-08-20 ## What Stripe actually wrote The letter is worth reading in full. Here is the short version. Stripe announced OpenRouter as its largest acquisition ever. The companies did not disclose the price. The New York Times reports $7.5 billion; Reuters reports slightly more than $8 billion. OpenRouter had been valued at $1.3 billion only three months earlier. Before OpenRouter came Bridge, Privy and Metronome. Bridge cost $1.1 billion. Metronome's official terms were not disclosed, but reporting puts the deal at about $1 billion. Privy's purchase price was also undisclosed; its last reported valuation before the acquisition was $230 million. That gives Stripe roughly $9.6 to $10.1 billion in reported deal value across OpenRouter, Bridge and Metronome, plus whatever it paid for Privy. It does not include the cost of building the rest of the stack. They wrote: "We decided that January 1st marked the beginning of the singularity, and we have since been operating on that basis." They report H1 net revenue up 41% year over year, free cash flow up 43%, 88% of the Forbes AI 50 on Stripe, and token consumption on OpenRouter compounding at 9% per week. The core sentence is this one: "building economic infrastructure for the internet is mostly the same thing as building the economic infrastructure for AI." And they name the pieces they are building for it: Stripe Projects and Directory for agent onboarding and discovery, Metronome for usage, Bridge and an Agentic Commerce Suite for payment, Tempo as their own blockchain for agents, MPP as a machine payments protocol, Privy for wallets, and Open Standard, their own stablecoin. They also wrote something I keep coming back to: "There is a fear that AI will yield unemployment or centralization; perhaps both. We think that it is important that deployment of AI enhances human agency." I agree with every word of the diagnosis. I disagree with the medicine. **Basically,** Stripe called January 1st the singularity after committing more than $9.6 billion to the stack around it. ## The part where they describe our product Go through Stripe's list of primitives and put it next to Nuri. Stripe now owns Privy. Privy calls its user wallets non-custodial and offers private-key export, which is a real escape hatch. But before export, signing still depends on Privy infrastructure: one encrypted key share is stored by Privy and the other can only be decrypted and combined inside its AWS Nitro Enclave. If that infrastructure disappears before the user exports, the wallet does not have a local recovery path. With Nuri, WebAuthn PRF derives the user's own key locally from the passkey. In multisig wallet models this is the user key, not every signer key. The co-signing path is time-limited through CSV, so after a fixed block window the user retains an independent recovery path. A separate backup key, such as a hardware wallet, can add a 2-of-3 recovery option. The same principle can be applied to EVM Safe accounts used by agents. The user does not have to remember to press an export button before Nuri disappears. That difference is not cosmetic. It is independence built into the wallet. Nuri brings fiat and crypto into one wallet, but pointed at people and their agents rather than only platforms: card and IBAN, bitcoin onchain and over Lightning, stablecoins, and the open rails that connect them. An agent may operate a user-owned wallet within limits, or own a wallet and act autonomously. Both modes matter. The important question is not where a budget rule happens to be enforced in one implementation. It is whether the authority is real. An agent needs enough freedom to act, spend, earn and complete work without asking a human about every cent. The owner still needs a way to define the boundaries and revoke delegated access. Nuri is AI-native below the interface. The system is operable through CLI and MCP, while onchain actions remain client-side where the wallet model requires it. The frontend can be the web app, the iOS app, the user's own agent or the Nuri agent on WhatsApp. Every important capability has to work without assuming a person is clicking through screens. We are not building a chain and we are not issuing money. Nuri is designed to be agnostic across chains, protocols and financial services, including the fiat side. Open source and open standards matter because the user should never depend on one company, including ours, to keep using their money. **Basically,** If your wallet needs an export button before the provider disappears, you are not independent. ## Same singularity, different answer Here is the honest way to say it: we believe what Stripe believes. Agents will hold money, work inside budgets, pay for services, subscribe, settle and earn. Stablecoins will carry a lot of it, but they are not the whole future. Fiat, bitcoin and Lightning are part of the same picture. Stripe's answer is vertical integration: intelligence routing, billing, wallets, a chain, a stablecoin and a directory. It is an impressive machine and it will work for a lot of businesses. Privy makes this more nuanced than a simple custodial-versus-non-custodial argument; it supports non-custodial and exportable wallets too. The concern is concentration. More and more of the agent economy can begin, move and settle inside one commercial universe. Human agency, as long as Stripe agrees. Nuri's answer is to compose rather than own. Self-custody where the user chooses it. Autonomous ownership where the agent needs it. Open source where independence depends on it. Open standards so another service can replace us without replacing the user's financial life. Chain-agnostic and service-agnostic, including on the fiat side. This is not a head-to-head fight with Stripe. They serve platforms building for agents at enormous scale. We start with the person and the agent working for them, or with an autonomous agent that needs a real financial identity of its own. The thesis is the same. The architecture and incentives are not. **Basically,** Human agency, as long as Stripe agrees, is not human agency. ## Agents with an actual bank account This is the part I am most excited about. An agent should be able to own a wallet and operate autonomously. It should also be able to act through a person's wallet with delegated authority. Those are different relationships, and Nuri has to support both. When the wallet belongs to the user, the passkey and keys stay with the user. The agent receives only the authority it needs. When a wallet belongs to an autonomous agent, the agent must be able to hold money, earn, spend and settle without waiting for a human click every time. Autonomy that stops at the payment screen is not autonomy. The fiat side is what turns this from a crypto demo into a financial product. Nuri connects agents to cards, IBAN and bank transfers as well as bitcoin, Lightning and stablecoins. An agent may need to pay a supplier by bank transfer, keep a card funded, settle over Lightning or pay an API with an open machine-payment protocol. These are not competing worlds. They are the world money already lives in. The architecture is chain-agnostic and service-agnostic. Capabilities are exposed through MCP and CLI rather than locked inside one frontend. The interface can be our web or iOS app, the user's own agent, or the Nuri agent on WhatsApp. The backend should not care which surface made the request, only whether that request has the authority to act. **Basically,** An agent can be autonomous on any rail. Nuri connects that autonomy to Bitcoin, Lightning and banking. ## Verification follows need, not ideology One design decision confuses people at first and then clicks: Nuri serves both sides, retail and institutions, and verification follows need. You want a self-custodial wallet for bitcoin and stablecoins, no account, no forms? That exists, that is live, and it works worldwide. You want the full picture with card, IBAN, and banking rails? Then KYC applies, because that is what the regulated side requires, and our partners handle it properly. A business wants the same thing with KYB and controls? Same framework, same tools, different verification tier. This is not fence-sitting. It is the only architecture that can actually be worldwide. Most of the planet cannot pass European KYC and should not need to just to hold their own money. And European users who want an IBAN should not have to leave the product to get one. One wallet, one passkey, and the user decides how deep into the regulated world they want to go. Agents inherit exactly the tier their human has. **Basically,** KYC should unlock banking, not decide who is allowed to hold money. ## Five people and a machine Stripe has thousands of employees. We are five. That is only possible because Nuri is AI-native all the way down. The backend is built to be operated through CLI and MCP. Onchain actions happen client-side where ownership requires it. The frontend is interchangeable: web, iOS, the user's own agent, or the Nuri agent on WhatsApp. A graphical app is one interface, not the product boundary. Support runs through an agent cockpit, with humans handling the cases that need a human. Content, product videos, monitoring and distribution increasingly run through agent pipelines. The website is not only readable by agents; it is operable by them. That is why agent readiness matters to us more than a design award. I will not pretend this is all smooth. Building a company this way means debugging your own future every day. But every claim we make about the agent economy is one we test on ourselves first. We are our own first customer. **Basically,** Nuri has no single frontend. Apps, WhatsApp and agents all use the same backend. ## Where this goes Stripe's letter ends with gratitude to their investors and a promise of intensity. Fair. Here is ours. The wallet keeps growing as the bridge between fiat and crypto for people, and becomes the same bridge for their agents. Bitcoin, Lightning, stablecoins and banking services should feel like parts of one financial life, not separate products owned by separate gatekeepers. The biggest company in payments just declared that the economic infrastructure of the internet and the economic infrastructure of AI are becoming the same thing. Cloudflare is building identity, wallets and payment infrastructure around its network. Circle is building autonomous wallets around stablecoins. PayBox is connecting agents to existing wallets, exchanges and cards. These are strong signals that the market is real. The risk is not that these companies are building. They should build. The risk is that identity, intelligence, wallets, payment rails and settlement collapse into a few vertically integrated clouds. Open source and open standards are how the rest of us keep the system composable. Self-custody and exportability are how users remain independent of the companies serving them. One direction we want to pursue is a collaboration with Nous Research around Hermes. This is a target, not an announced partnership. Hermes is open source, runs locally or in persistent cloud environments, and can connect to hundreds of models through different providers or custom endpoints. It already supports provider routing, fallbacks, tools, MCP and messaging channels. Put that together with Nuri and the idea becomes simple: agents on click. Choose a model, launch an agent locally or in the cloud, give it a wallet or delegated authority, and let it operate across the Nuri universe without locking the user into one model, one cloud or one financial provider. That is the future we want to build toward: direct access to many LLMs, routing across models, durable cloud agents and financial tools in one open-source, non-custodial system. The agent may belong to a person or stand on its own. The surface may be an app, WhatsApp or no graphical interface at all. What matters is that intelligence and money can meet without either becoming a new point of captivity. Nuri does not need to own every layer. It needs to connect the layers without becoming the reason a user is trapped inside them. That is a different kind of ambition: not to become the financial operating system that nobody can leave, but to build one that still works when they do. **Basically,** Stripe is buying the stack. Nuri is building one users can leave. ## Founder, Nuri > “Stripe's bet is that they hold the stack. Our bet is that you hold the keys.” > > — Emin Mahrt ## This post is also available in - [Was Stripes Investorenbrief über Nuri sagt](https://nuri.com/de/blog/what-stripes-investor-letter-means-for-nuri) (de) - [Qué dice de Nuri la carta a inversores de Stripe](https://nuri.com/es/blog/what-stripes-investor-letter-means-for-nuri) (es) - [Cosa dice di Nuri la lettera agli investitori di Stripe](https://nuri.com/it/blog/what-stripes-investor-letter-means-for-nuri) (it) --- --- title: "The passkey that outlives the company" description: "How Nuri wallets recover without Nuri: a passkey that carries its own secret, Bitcoin scripts with a built-in exit, and co-signers that decay on chain." lang: "en" type: "blog-post" author: "Emin Mahrt" datePublished: "2026-09-01" dateModified: "2026-09-01" canonical: "https://nuri.com/blog/how-nuri-wallets-survive-without-nuri" tags: ["Nuri","Bitcoin","Lightning","passkeys","self-custody","recovery"] --- # The passkey that outlives the company **TL;DR:** Most wallets promise self-custody. Few survive the question that actually matters: what happens to your money when the company that built the wallet is gone? This article walks through the full Nuri design: a passkey whose PRF extension carries the wallet secret itself, Bitcoin outputs whose 2-of-2 co-signing decays to 1-of-1 through a CSV timelock, and an Arkade Lightning layer whose three-key ladder decays from co-signers to the user key alone. Recovery works offline, without nuri.com, without servers, without an export button. Co-signers are passkey-gated, phishing-resistant, and mortal by design. The only immortal key is yours. - **Author:** Emin Mahrt - **Published:** 2026-09-01 ## Why a normal passkey is not enough A passkey is a beautiful authentication primitive. The private signing key never leaves the authenticator. Websites only ever see signatures. Phishing dies; password databases stop mattering. But as a wallet primitive, a normal passkey is a dead end. It can prove you are you, again and again, forever. It cannot hand you a secret. And a wallet needs a secret — a number from which your Bitcoin and Ethereum keys are derived. So most passkey wallets end up in one of two camps. The server holds the wallet key and the passkey is just a fancy login: custody with better UX. Or MPC and enclave models split the key across infrastructure — genuinely better, but reconstruction typically requires that infrastructure to be alive, and the escape hatch is export: if you remember to use it before the provider disappears. Both camps share a quiet assumption: the domain you log in to outlives your need for the key. There is also a second, less discussed trap. Passkeys are domain-bound. Your credential works for the RP ID it was created for — that is exactly what stops a random website from phishing your wallet login. But domain binding is protection for the company's lifetime, with no story for after. If your wallet key is entangled with a provider's ceremony and that provider's domain goes dark, your passkey still exists, still works — it just has nobody left to talk to. The industry treats that as an edge case. For money, it is the case. **Basically,** A passkey proves who you are. A wallet needs a secret. The question is who holds it: you, or a company you hope stays online. ## The passkey that carries its own secret Nuri uses the WebAuthn PRF extension. PRF lets the wallet ask the authenticator a fixed question and receive a stable, pseudorandom answer — tied to that credential, reproducible forever, and never exposed to any server. The RP ID is nuri.com, the PRF input is the fixed string "nuri-prf-salt-v1", and the output is 32 secret bytes, produced locally after user verification. Those 32 bytes are the seed. From there, everything is public, deterministic math: HKDF-SHA256 with domain separation into BIP32 paths m/86'/0'/0'/0/0 for Bitcoin Taproot and m/44'/60'/0'/0/0 for Ethereum. The derivation code and constants are public — the local-nuri-prf-passkey-recovery-tool on GitHub is exactly that code, packaged for the worst day. One distinction carries most of the security model. A passkey ceremony produces two things: the WebAuthn assertion — a public proof of user presence, origin, RP ID and intent — and the PRF output — the private, deterministic secret behind your wallet keys. The Nuri co-signer receives assertions to verify that you approved a co-signing action. It never receives the PRF output. The secret that creates your signature never travels; only the proof that you approved the server's signature does. Co-signing and recovery are separate ceremonies on purpose. The server can help you spend on a Tuesday and be irrelevant to your recovery a decade later. **Basically,** The server gets your approval, never your secret. It can help you spend on a Tuesday and be irrelevant to your recovery ten years later. ## But the passkey is bound to nuri.com Yes. The passkey is cryptographically bound to the RP ID nuri.com. We consider that a feature — it is what stops any random website from asking your passkey for money. But here is the part that took real design work: the RP ID is a string, not a subscription. WebAuthn checks that the page requesting the ceremony is a secure context whose hostname matches the RP ID. It does not check whether the company still exists, whether DNS resolves, or whether the certificate came from a public authority. Those are browser security properties, not corporate records. So the recovery tool recreates the relying-party context on your own machine. A hosts entry points nuri.com at your loopback address. A locally generated, locally trusted certificate makes the page a secure origin. The local server on https://nuri.com:8443 serves reviewed, committed files — no remote JavaScript, no analytics, no fonts. Your passkey asks for Face ID, Touch ID, or your PIN — the real ceremony, your real credential — and hands the PRF output to a page running entirely on your computer, ideally with the network cable pulled. This is not a WebAuthn bypass. An attacker still needs your passkey and your user verification. It is not a forged public certificate — you trust your own local CA only on your own machine, for one recovery session. It is the recognition that the user who owns the passkey owns the RP context — even when the domain registrar no longer cares. When the ceremony is done, you remove the hosts entry, delete the local CA, and disconnect. The string "nuri.com" in your passkey's memory outlived the company. That was the point. **Basically,** The domain binding protects the passkey from strangers. It does not chain you to the company. The origin can be rebuilt on your own machine. ## The Bitcoin layer: 2-of-2 with a built-in exit Normal spending on Nuri Bitcoin is a 2-of-2 MuSig2 collaboration. Your key — derived from the PRF — and the Nuri co-signer's key aggregate into a single Taproot key. On chain it looks like an ordinary Taproot output: fast, private, one signature. But every output also carries a Miniscript escape hatch, committed into the chain itself. The key path is the MuSig2 aggregate; the script path is your x-only key wrapped in a CSV delay: and_v(v:pk(user), older(csv_blocks)). While Nuri is alive, you and the co-signer spend together through the key path. The co-signer gives you instant, validated spending — spending limits, anomaly checks, a human-shaped safety net. If Nuri is gone, you wait out the CSV delay — CheckSequenceVerify, a relative timelock that starts counting when the output confirms — and then your key alone sweeps the funds through the script path. No permission needed, because the permission was baked into the output when it was created. The math is public: unlock height is confirmation height plus CSV blocks. The recovery tool can build and sign the sweep transaction before unlock for inspection, but refuses to broadcast until the unlock condition is satisfied. This is why we insist on the distinction: the private key is recoverable offline immediately; the onchain script may still require waiting. That is not provider custody — it is a public Bitcoin consensus rule committed into the output. Custody is when someone can refuse you. Nobody can refuse a timelock. **Basically,** The co-signer helps while it lives. After the CSV delay, your key alone sweeps. Waiting is not custody. Nobody can refuse a timelock. ## The decay architecture: co-signers that expire Now the part that is easiest to miss and hardest to build: who is allowed to sign, and how that set shrinks over time. Most multisig wallets treat the signer set as permanent. Revocation means infrastructure: a revocation server, a key-rotation ceremony, an upgrade transaction. Every one of those is a dependency that can fail exactly when you need it most. Nuri treats the signer set as a schedule. Co-signers are not revoked by infrastructure — they decay on chain, on a clock that Bitcoin itself enforces. The user key never rotates. The policy around it just gets simpler as time passes. On Bitcoin L1, the output starts as a 2-of-2: your key and the Nuri co-signer's key aggregate into one MuSig2 Taproot key. Then, at a fixed relative timelock after the output confirms, the co-signer decays out of existence. At time zero the set is user plus co-signer, instant key-path spends. After the CSV delay the set is the user alone, script-path sweep. No transaction removes the co-signer. No revocation server, no key rotation, no migration. The same output simply has two spending conditions, and time selects which one is live. That is what an honest non-custodial 2-of-2 has to mean: not 2-of-2 until we decide otherwise, but 2-of-2, decaying to 1-of-1, on a schedule nobody can pause. **Basically,** Two keys at the start. One key after the delay. Nothing gets revoked by infrastructure — the schedule sits in the script itself. ## The Arkade wallet: three keys, two decays The Lightning layer has one more signer, so the decay ladder has one more rung. Every VTXO — the virtual transaction output that represents your off-chain balance — commits to a Taproot tree with three leaves, each a complete spending condition. Leaf one is the arkade path: the MuSig2 aggregate of user and Nuri co-signer, together with the arkade server. Instant, off-chain, Lightning-fast. Leaf two is aggregate recovery: user and Nuri co-signer alone, after the arkade CSV delay. Leaf three is client recovery: the user key alone, after the sum of both delays. In plain words, the signer set decays like this: at time zero it is user, Nuri co-signer and arkade server — normal Lightning life. After the first delay, the arkade server has decayed: user and co-signer remain. After the full sum of both delays, the Nuri co-signer has decayed too, and only the user key remains. Three properties make this a ladder and not a pile of scripts. First, thresholds only ever shrink toward you: three keys, to two, to one. Never grows, never moves away from the user. Second, each delay is the sum of all delays above it: the client-recovery leaf unlocks at exactly the moment both co-signers have fully decayed, and the app structurally rejects any tree where the user-only path would unlock before the last co-signer's decay completes. While a co-signer is still in the script, it is still protecting you — against fat-fingered amounts, against a compromised client, against you at 3 a.m. Third, the decay is consensus, not infrastructure: at the first delay the arkade server does not get revoked — it simply stops being mentioned by any live spending condition. Even if it is still running, healthy and online, it has no mathematical role in your output anymore. This is what we mean when we say the Arkade wallet is a 2-of-2-of-3. Not three keys, threshold two, forever — but a multisig whose co-signers are mortal by design, and whose only immortal key is yours. **Basically,** Three keys become two, then one. Never the other way. A healthy server past its decay has no say anymore. ## How the operators and co-signers work together It helps to see the cast. Your key is derived from your passkey's PRF output — it lives on your devices, in your password manager, or on a hardware authenticator. The Nuri co-signer is an operator we run: it verifies WebAuthn assertions before it contributes its signature share. The arkade server is the Lightning operator that makes off-chain sends possible. The critical detail is how the co-signer decides to sign. It does not trust an API key or a session cookie. It requires a fresh WebAuthn assertion — a real passkey ceremony with user verification — for every co-signing action. That is what makes the whole system phishing-proof in depth: even if an attacker extracts a valid PRF output, they hold a deterministic key seed, but spending still requires the co-signer, and the co-signer only acts on a fresh passkey assertion from the user. A leaked PRF alone cannot move money while the co-signer is in the script. And once the co-signer has decayed, the attacker's window is the same CSV delay that protects everyone — a delay the user can also use to reach their funds first. This is also the no-single-point-of-failure core: the operator, the arkade server, and even the domain are all mortal, all replaceable, all outside the critical path after their decay. The design extends naturally: a hardware wallet can be added as a backup co-signer for a 2-of-3 recovery option, and PRF-capable hardware authenticators — YubiKeys with PRF support, or our biometric NFC passkey smartcard — can hold the user key in silicon. More keys, more decay rungs, same rule: thresholds only ever shrink toward the user. **Basically,** Every co-signing action needs a fresh passkey tap. A stolen PRF alone moves nothing while the co-signer lives. ## What this means when the lights go out Run the full scenario. It is 2040. Nuri GmbH was dissolved in 2031. Nobody renewed the domain. You still have your passkey in your password manager, your phone, or a hardware authenticator. On an offline computer, you run the open-source recovery tool. It recreates the nuri.com RP context locally — hosts entry, local CA, local server. Your passkey — the same credential, domain-bound to a string that no longer resolves — evaluates the PRF. Deterministic derivation produces your Bitcoin and Ethereum keys. You pull the encrypted Nostr backups, reconstruct your VTXOs, calculate each decay rung's unlock height, and sweep: L1 outputs where the CSV has matured, Arkade outputs where the ladder has finished decaying, anything still timelocked as soon as it matures. At no point in this story did anyone at a company have to press a button, approve a ticket, or keep a database alive. The rescue was designed in on day one. **Basically,** Company gone, domain gone, servers gone. Your passkey, the chain and the backups still meet. ## Why we keep saying rescue, not export An export button is a promise about your future behavior. A rescue path is a property of the system. Privy-style export is a real escape hatch — but it is an escape hatch you must remember to take, while the door is still open. Nuri's answer inverts the order. The key material lives with the user's passkey. The decay schedule lives in the chain. The recovery state lives on Nostr. The company's job is to be useful while it exists — not to be load-bearing after it doesn't. This is also why the Arkade architecture matters beyond Nuri. Agents that hold money need the same property: an operator that can make money fast while it exists, and mathematically cannot matter once its time is up. A wallet whose co-signers decay is a wallet an agent can inherit without inheriting a dependency. Self-custody that requires the custodian's continued existence is just custody with extra steps. We built Nuri so that even our absence is survivable. That is not a marketing line; it is testable, today, with tools we published and a scenario you can rehearse in an afternoon. Recovery still needs the original passkey, an authenticator that supports PRF, and a reviewed copy of the tool. And honesty about the trade-off: after the co-signers decay, their protections decay with them. Self-custody means owning that. The single most important sentence in this article is this one: check whether your wallet's passkey carries a secret, or just a signature. **Basically,** An export button is a promise about your future behavior. A rescue path is a property of the system. ## Founder, Nuri > “The co-signers decay. The user key never changes. That is the whole design.” > > — Emin Mahrt ## This post is also available in - [Der Passkey, der das Unternehmen überlebt](https://nuri.com/de/blog/how-nuri-wallets-survive-without-nuri) (de) - [The passkey that outlives the company](https://nuri.com/es/blog/how-nuri-wallets-survive-without-nuri) (es) - [The passkey that outlives the company](https://nuri.com/it/blog/how-nuri-wallets-survive-without-nuri) (it) --- --- title: "Nuri für die Tage bauen, an denen etwas kaputtgeht" description: "Was Nuri aus zwei Wochen mit Ausfällen gelernt hat und wie wir die App klarer und robuster machen und dafür sorgen, dass sie sich leichter supporten lässt." lang: "de" type: "blog-post" author: "Emin Mahrt" datePublished: "2026-08-11" dateModified: "2026-08-11" canonical: "https://nuri.com/de/blog/building-nuri-for-the-days-when-something-breaks" tags: ["Nuri","Produktzuverlässigkeit","Bitcoin","Lightning","Zahlungswege"] --- # Nuri für die Tage bauen, an denen etwas kaputtgeht **TL;DR:** Wenn ein Zahlungsweg ausfällt, sollte sich nicht gleich die ganze App kaputt anfühlen. Nuri braucht einen klaren Status, funktionierende Fallbacks und einen Support, der weiß, was gerade verfügbar ist. Wir werden schneller handeln, ohne so zu tun, als würden Ausfälle aufhören, und klarer zeigen, was trotzdem funktioniert. - **Von:** Emin Mahrt - **Veröffentlicht:** 2026-08-11 ## Diese zwei Wochen liefen nicht nach Plan Wir hatten einen Plan für die vergangenen zwei Wochen. Dann kamen diese zwei Wochen. Wir wollten die Zeit nutzen, um an der App zu feilen, mit der Distribution anzufangen und mehr Nutzer zu Nuri zu holen. Stattdessen verbrachten wir einen großen Teil davon damit, auf Probleme bei Bitcoin, Lightning und verschiedenen Zahlungswegen zu reagieren. Ehrlich gesagt war es anstrengend. Nicht weil jedes Problem katastrophal gewesen wäre. Wir stehen noch am Anfang, und die Zahl der betroffenen Nutzer war überschaubar. Aber es fühlte sich an wie in „Und täglich grüßt das Murmeltier“: Kaum hatten wir ein Teil repariert, änderte sich ein anderes. Dann funktionierte ein Fallback nicht mehr, dann brauchte noch etwas anderes unsere Aufmerksamkeit. Meine erste Reaktion war Frust. Aber als ich darüber nachdachte, wurde die wichtigere Lektion klar. Das wird wieder passieren. > “I must say I feel exhausted after these two weeks.” > > — Emin Mahrt · Aus der Originalaufnahme **Kurz gesagt,** Wir hatten einen normalen Zwei-Wochen-Sprint geplant. Stattdessen haben wir zwei Wochen lang nur Brände gelöscht. ## Das ist das Umfeld, in dem wir bauen Nuri verbindet viele verschiedene Finanzsysteme. Banking, Karten, Bitcoin, Lightning, lokale Währungen und Zahlungswege funktionieren alle unterschiedlich. Einige Teile gehören uns. Andere verbinden uns mit externer Infrastruktur. Jeder Teil kann sich verändern, in Wartung gehen oder vorübergehend ausfallen. Alle in diesem Bereich bauen schwierige Systeme, wir eingeschlossen. Veränderungen und Unterbrechungen gehören zu dieser Arbeit. Wir haben uns entschieden, diese Systeme zusammenzubringen. Deshalb tragen wir die Verantwortung dafür, was Nutzer erleben, wenn sich etwas ändert. Unsere Aufgabe ist nicht, so zu tun, als würden alle beweglichen Teile für immer perfekt funktionieren. Unsere Aufgabe ist, dafür zu sorgen, dass Nuri nützlich bleibt, wenn einer davon ausfällt. > “if you're building a puzzle with many moving parts, of course, those moving parts are going to work, going to not work, going to break.” > > — Emin Mahrt · Aus der Originalaufnahme **Kurz gesagt,** Manchmal fallen Dinge aus. Unsere App muss trotzdem verständlich bleiben. ## Ein Fallback muss funktionieren, wenn man ihn braucht Der frustrierendste Moment war nicht, dass ein Feature nicht mehr funktionierte. Das kann passieren. Frustrierend war, dass ein Fallback genau in der Situation nicht mehr verfügbar war, in der die Nutzer ihn brauchten. Das hat uns etwas sehr Einfaches beigebracht: Ein Fallback, der nur unter normalen Bedingungen funktioniert, ist kein besonders guter Fallback. Wir müssen überall dort, wo wir können, weitere Single Points of Failure beseitigen. Manchmal heißt das, einen weiteren Weg hinzuzufügen. Manchmal heißt es, Nutzern die Wiederherstellung oder den Ausstieg zu ermöglichen, ohne von uns abhängig zu sein. Und manchmal heißt es einfach, zwei Features voneinander zu trennen, die ähnlich aussehen, aber aus völlig unterschiedlichen Gründen ausfallen. Bitcoin und Bitcoin Lightning sind ein gutes Beispiel. Für viele Nutzer sehen sie vielleicht wie zwei Varianten derselben Sache aus. Technisch sind es sehr unterschiedliche Systeme mit unterschiedlichen Kompromissen und unterschiedlichen Arten auszufallen. Sie als ein einziges nahtloses Guthaben darzustellen, sieht vielleicht aufgeräumter aus. Es bedeutet aber auch, dass ein Lightning-Problem den Eindruck erwecken kann, die gesamte Bitcoin-Nutzung sei kaputt. Bis auf Weiteres ist es ehrlicher und nützlicher, sie zu trennen. Bitcoin kann weiter funktionieren, wenn Lightning nicht verfügbar ist. Lightning kann seinen aktuellen Status klar anzeigen. Nutzer sollten den technischen Grund nicht verstehen müssen. Sie müssen nur wissen, was funktioniert, was nicht funktioniert und was sie als Nächstes tun können. **Kurz gesagt,** Bitcoin und Lightning dürfen sich nicht gegenseitig mitreißen. Ein Fallback muss echt sein, nicht nur Deko. ## Wir haben zu sehr versucht, die Technik zu verstecken Lange wollte ich, dass Nuri die ganze Komplexität versteckt. An vielen Stellen ist das immer noch das Ziel. Niemand sollte Nodes, Liquidität, Zahlungsrouting oder Infrastrukturanbieter verstehen müssen, um Geld zu senden. Aber Komplexität zu verstecken darf nicht bedeuten, die Realität zu verstecken. Wenn ein Zahlungsweg vorübergehend nicht verfügbar ist, sollte die App das sagen. Wenn etwas gewartet wird, sollte es auch so aussehen. Wenn eine Währung als Zahlungsweg, aber nicht als Guthaben unterstützt wird, sollte die Oberfläche diesen Unterschied deutlich machen. Bisher haben wir versucht, Hinweise wie „vorübergehend nicht verfügbar“ zu vermeiden. Sie wirkten technisch und unfreundlich. Rückblickend hat das die Erfahrung verschlechtert. Ein Button, der verfügbar aussieht, aber nach dem Antippen nicht funktioniert, ist viel frustrierender als ein ausgegrauter Button mit einer klaren Erklärung. Das verändert, wie wir über den Hauptbildschirm von Nuri denken. Er sollte nicht nur zeigen, wo dein Geld ist. Er sollte auch zeigen, was du gerade damit tun kannst. Vielleicht hast du Geld in Euro, aber mehrere Möglichkeiten, diese Euro zu nutzen: Kartenzahlungen, Banküberweisungen oder die Umwandlung in eine andere Währung. Manche Zahlungswege brauchen gar kein eigenes Guthaben. Sie sind einfach nur eine weitere Möglichkeit, Geld zu senden oder zu empfangen. Gleichzeitig dürfen wir dasselbe Geld niemals zweimal anzeigen. Wenn deine Karte und dein Bankkonto dasselbe zugrunde liegende Guthaben nutzen, kann die Anzeige des Betrags an beiden Stellen den Eindruck erwecken, du hättest doppelt so viel Geld, wie du tatsächlich hast. Die erste Version ist vielleicht nicht schön, aber sie muss klar sein. **Kurz gesagt,** Versteckt einen kaputten Zahlungsweg nicht hinter einem Button, der so aussieht, als würde er funktionieren. Sagt den Leuten, was funktioniert, bevor sie darauf tippen. ## Der Support sollte wissen, was die App weiß Diese Woche hat auch verändert, wie ich über Support denke. Der Support sollte kein getrenntes System mit einer veralteten Liste von Features sein. Er sollte dasselbe Nuri verstehen, auf das der Nutzer gerade blickt. Wenn ein Zahlungsweg nicht verfügbar ist, sollte der Support es sofort wissen. Wenn ein Feature deaktiviert wurde, sollte unser Support-Agent es nicht empfehlen. Wenn jemand fragt, warum eine Lightning-Rechnung nicht bezahlt werden kann, sollte der Support sehen können, ob der Zahlungsweg funktioniert, die aktuelle Situation erklären und eine verfügbare Alternative vorschlagen. Hier wird unsere Arbeit an MCP praktisch. MCP klingt technisch, aber die Grundidee ist einfach: Jede Funktion von Nuri soll über eine saubere Schnittstelle verfügbar sein, die sowohl die App als auch Agents verstehen können. Das Nuri MCP sollte die Features enthalten, die in Nuri wirklich verfügbar sind. Experimentelle Features sollten woanders bleiben, bis sie bereit sind. Im Moment sind diese Grenzen nicht immer sauber. Experimente, App-Features und unabhängige Services liegen bei uns zu nah beieinander. Das war sinnvoll, solange wir schnell vorangekommen sind und Ideen getestet haben. Jetzt, da wir wollen, dass Agents echte Nutzer unterstützen, ist es weniger sinnvoll. Wenn etwas in Nuri verfügbar wird, sollte der Support-Agent es verstehen. Wenn etwas aus der App verschwindet, sollte es auch aus den verfügbaren Aktionen des Agents verschwinden. App, Support und Infrastruktur sollten dieselbe Realität beschreiben. **Kurz gesagt,** Unser Support-Agent sollte dich niemals zu einem Feature schicken, das gerade nicht verfügbar ist. ## Wir warten nicht auf Perfektion Wir können Monate damit verbringen, für jeden denkbaren Ausfall den perfekten Fallback zu entwerfen. Dann starten wir und stellen fest, dass die Nutzer etwas völlig anderes verwirrt. Wir brauchen echte Nutzer. Wir brauchen Menschen, die Nuri öffnen, versuchen, es zu benutzen, und uns sagen, wo sie nicht weiterkommen. Nicht weil sie eine Theorie über unsere Oberfläche haben, sondern weil sie etwas tun wollten und es nicht konnten. Dieses Feedback ist wertvoller als zehn interne Meinungen. Ein Beispiel dafür zeigte sich bei der Trennung von Karten und Banküberweisungen. Technisch kann es logisch wirken, beides zusammenzulegen, weil sie dasselbe Guthaben nutzen können. Aber Nutzer fragten immer wieder, wo ihre IBAN sei. Sie öffneten die Kartenansicht, sahen eine Karte und suchten nicht weiter. Sie erwarteten nicht, dass Banküberweisungen dort versteckt sind. Nutzer müssen nicht wissen, warum wir zwei Dinge ursprünglich zusammengefasst haben. Sie wissen nur, dass sie nicht finden konnten, was sie brauchten. Also werden wir mit unfertigen Screens und Abläufen schneller vorangehen. Dann beobachten wir, wo Menschen nicht weiterkommen, und verbessern diese Stellen. Manches wird nicht perfekt aussehen, und manche Experimente werden scheitern. Eine Idee kann in einem Meeting sinnvoll klingen und sich in dem Moment falsch anfühlen, in dem jemand sie ausprobiert. Das erfahren wir lieber jetzt. > “it's okay that things break it's okay that they don't look good we just react on it and basically make the best out of it” > > — Emin Mahrt · Aus der Originalaufnahme **Kurz gesagt,** Nuri in mehr Hände bringen, beobachten, wo Menschen nicht weiterkommen, und zuerst die echten Probleme lösen. ## Was wir als Nächstes tun Wir werden die App weiter verbessern, aber wir werden auch anfangen, mehr Menschen in die App zu holen. Distribution darf nicht die Aufgabe bleiben, die wir jedes Mal verschieben, wenn etwas kaputtgeht. Wir trennen Features, damit ein nicht verfügbarer Zahlungsweg nicht den Rest der Nutzung beeinträchtigt, ergänzen klarere Statusinformationen und räumen das Nuri MCP auf, damit es zur App passt. Der Support sollte wissen, welche Funktionen gerade verfügbar sind. Besseres Monitoring hilft uns, Probleme zu finden, bevor daraus lange Supportgespräche werden. Für Lightning werden wir uns die verfügbaren Optionen ansehen, ohne uns überstürzt die nächste dauerhafte Abhängigkeit einzuhandeln. Es gibt mehrere mögliche Schritte. Wir können reguläre Swaps zwischen Bitcoin und Lightning unterstützen, später schnellere Varianten untersuchen, andere Non-Custodial-Ansätze prüfen oder unsere aktuelle Integration weiter verbessern, sobald die nötigen Funktionen verfügbar sind. Wir müssen nicht heute jede Entscheidung treffen. Bitcoin kann nützlich bleiben, ohne dass wir so tun, als wäre schon jeder Anwendungsfall für Lightning gelöst. Lightning ist schwierig, und die gesamte Branche arbeitet noch an einigen harten Problemen. Wir sind lieber ehrlich, als eine nahtlos wirkende Nutzung zu erzwingen, die verwirrend wird, sobald sich etwas ändert. Dasselbe Prinzip gilt auch jenseits von Bitcoin. Wenn ein Zahlungsweg für eine lokale Währung in Wartung geht, sollte der Rest von Nuri weiter funktionieren. Wenn ein Kartendienst nicht verfügbar ist, sollten Nutzer trotzdem ihre Optionen für Banküberweisungen finden. Wenn ein Feature experimentell ist, sollte es nicht still und leise so wirken, als wäre es produktionsreif. **Kurz gesagt,** Zeigen, was funktioniert, Fallbacks am Laufen halten, Support und App auf denselben Stand bringen und Nuri mehr Menschen zeigen. ## Aus der Originalaufnahme > “Es wird Ausfälle geben, aber ein kaputter Teil sollte nicht den Rest von Nuri mitreißen.” > > — Emin Mahrt ## Diesen Beitrag gibt es auch auf - [Building Nuri for the days when something breaks](https://nuri.com/blog/building-nuri-for-the-days-when-something-breaks) (en) - [Construir Nuri para los días en que algo falla](https://nuri.com/es/blog/building-nuri-for-the-days-when-something-breaks) (es) - [Costruire Nuri per i giorni in cui qualcosa si rompe](https://nuri.com/it/blog/building-nuri-for-the-days-when-something-breaks) (it) --- --- title: "Was Stripes Investorenbrief über Nuri sagt" description: "Stripes Investorenbrief beschreibt die Agentenökonomie. Nuri sieht dieselbe Zukunft, gebaut auf offenen Standards, Selbstverwahrung und Unabhängigkeit der Nutzer." lang: "de" type: "blog-post" author: "Emin Mahrt" datePublished: "2026-08-20" dateModified: "2026-08-20" canonical: "https://nuri.com/de/blog/what-stripes-investor-letter-means-for-nuri" tags: ["Nuri","Stripe","Agentische Finanzen","Stablecoins","MCP","Non-Custodial"] --- # Was Stripes Investorenbrief über Nuri sagt **TL;DR:** Am 19. August erklärte Stripe seinen Investoren, dass KI-Agenten zu wirtschaftlichen Akteuren werden und Geld fester Bestandteil der KI-Ökonomie wird. Wir haben den Brief gelesen und darin die Zukunft wiedererkannt, für die wir bauen. Die These ist dieselbe. Der Ansatz ist ein anderer: Stripe integriert immer mehr Ebenen des Stacks in eine Plattform. Nuri baut auf offenen Standards, Selbstverwahrung und Unabhängigkeit von Nuri selbst. Agenten können Geld besitzen, autonom handeln oder innerhalb klarer Grenzen für einen Menschen arbeiten. Und dieses Geld besteht nicht nur aus Stablecoins und Fiatgeld. Es umfasst Bitcoin, Lightning und alle offenen Rails, die als Nächstes kommen. - **Autor:** Emin Mahrt - **Veröffentlicht:** 2026-08-20 ## Was Stripe tatsächlich geschrieben hat Der Brief lohnt sich in voller Länge. Hier ist die Kurzfassung. Stripe kündigte OpenRouter als seine bisher größte Übernahme an. Die Unternehmen nannten keinen Preis. Die New York Times berichtet von 7,5 Milliarden US-Dollar, Reuters von etwas mehr als 8 Milliarden US-Dollar. Nur drei Monate zuvor war OpenRouter mit 1,3 Milliarden US-Dollar bewertet worden. Davor kamen Bridge, Privy und Metronome. Bridge kostete 1,1 Milliarden US-Dollar. Die offiziellen Konditionen für Metronome wurden nicht veröffentlicht, Berichte beziffern den Deal aber auf rund 1 Milliarde US-Dollar. Auch der Kaufpreis für Privy blieb geheim. Die letzte gemeldete Bewertung vor der Übernahme lag bei 230 Millionen US-Dollar. Damit kommt Stripe für OpenRouter, Bridge und Metronome auf einen gemeldeten Dealwert von ungefähr 9,6 bis 10,1 Milliarden US-Dollar, zuzüglich des Preises für Privy. Die Kosten für den Aufbau des restlichen Stacks sind darin nicht enthalten. Sie schrieben: „Wir entschieden, dass der 1. Januar den Beginn der Singularität markierte, und arbeiten seitdem auf dieser Grundlage.“ Sie berichten für das erste Halbjahr von 41 % mehr Nettoumsatz als im Vorjahr, 43 % mehr Free Cashflow, davon, dass 88 % der Forbes AI 50 Stripe nutzen, und von einem Tokenverbrauch auf OpenRouter, der mit 9 % pro Woche wächst. Der Kernsatz lautet: „Wirtschaftliche Infrastruktur für das Internet zu bauen ist weitgehend dasselbe wie die wirtschaftliche Infrastruktur für KI zu bauen.“ Und sie nennen die Bausteine, die sie dafür entwickeln: Stripe Projects und Directory für Onboarding und Auffindbarkeit von Agenten, Metronome für die Nutzung, Bridge und eine Agentic Commerce Suite für Zahlungen, Tempo als eigene Blockchain für Agenten, MPP als Protokoll für Maschinenzahlungen, Privy für Wallets und Open Standard, ihren eigenen Stablecoin. Sie schrieben auch etwas, zu dem ich immer wieder zurückkehre: „Es gibt die Sorge, dass KI zu Arbeitslosigkeit oder Zentralisierung führt, vielleicht zu beidem. Wir halten es für wichtig, dass der Einsatz von KI die menschliche Handlungsfähigkeit stärkt.“ Ich stimme der Diagnose in jedem Wort zu. Ich widerspreche der Medizin. **Kurz gesagt,** Stripe erklärte den 1. Januar zur Singularität, nachdem das Unternehmen über 9,6 Milliarden US-Dollar in den Stack investiert hatte. ## Der Teil, in dem sie unser Produkt beschreiben Geh Stripes Liste der Grundbausteine durch und leg sie neben Nuri. Privy gehört inzwischen Stripe. Privy bezeichnet seine Nutzer-Wallets als Non-Custodial und bietet den Export privater Schlüssel an, ein echter Ausweg. Doch vor dem Export hängt das Signieren weiter von Privys Infrastruktur ab: Ein verschlüsselter Schlüsselanteil liegt bei Privy, der andere kann nur in der AWS Nitro Enclave von Privy entschlüsselt und zusammengeführt werden. Verschwindet diese Infrastruktur, bevor der Nutzer exportiert, bietet das Wallet keinen lokalen Wiederherstellungsweg. Bei Nuri leitet WebAuthn PRF den eigenen Schlüssel des Nutzers lokal aus dem Passkey ab. In Multisig-Wallet-Modellen ist das der Schlüssel des Nutzers, nicht der Schlüssel jedes Signierers. Der Co-Signing-Pfad ist durch CSV zeitlich begrenzt. Nach einem festen Blockfenster behält der Nutzer deshalb einen unabhängigen Wiederherstellungsweg. Ein separater Backup-Schlüssel, etwa in einem Hardware-Wallet, kann eine 2-of-3-Wiederherstellungsoption ergänzen. Dasselbe Prinzip lässt sich auf EVM Safe-Konten anwenden, die Agenten nutzen. Der Nutzer muss nicht daran denken, einen Exportknopf zu drücken, bevor Nuri verschwindet. Dieser Unterschied ist nicht kosmetisch. Die Unabhängigkeit steckt im Wallet selbst. Nuri bringt Fiatgeld und Krypto in einem Wallet zusammen, richtet sich aber an Menschen und ihre Agenten statt nur an Plattformen: Karte und IBAN, Bitcoin Onchain und über Lightning, Stablecoins und die offenen Rails, die sie verbinden. Ein Agent kann ein Wallet des Nutzers innerhalb gesetzter Grenzen bedienen oder selbst ein Wallet besitzen und autonom handeln. Beide Modelle sind wichtig. Die wichtige Frage ist nicht, wo eine Budgetregel in einer bestimmten Implementierung gerade durchgesetzt wird. Entscheidend ist, ob die Befugnis real ist. Ein Agent braucht genug Freiheit, um zu handeln, auszugeben, zu verdienen und Arbeit abzuschließen, ohne bei jedem Cent einen Menschen zu fragen. Der Eigentümer braucht trotzdem eine Möglichkeit, Grenzen zu setzen und delegierten Zugriff zu widerrufen. Nuri ist unterhalb der Oberfläche KI-nativ. Das System lässt sich über CLI und MCP bedienen, während Onchain-Aktionen dort clientseitig bleiben, wo das Wallet-Modell es verlangt. Das Frontend kann die Web-App, die iOS-App, der eigene Agent des Nutzers oder der Nuri-Agent auf WhatsApp sein. Jede wichtige Funktion muss laufen, ohne vorauszusetzen, dass sich ein Mensch durch Oberflächen klickt. Wir bauen keine Chain und geben kein Geld heraus. Nuri ist so konzipiert, dass es unabhängig von Chains, Protokollen und Finanzdienstleistern funktioniert, auch auf der Fiatseite. Open Source und offene Standards sind wichtig, weil Nutzer nie von einem einzigen Unternehmen abhängig sein sollten, auch nicht von unserem, um ihr Geld weiter nutzen zu können. **Kurz gesagt,** Braucht dein Wallet eine Exporttaste, bevor der Anbieter verschwindet, bist du nicht unabhängig. ## Dieselbe Singularität, eine andere Antwort Ehrlich gesagt glauben wir, was Stripe glaubt. Agenten werden Geld halten, innerhalb von Budgets arbeiten, Dienste bezahlen, Abos abschließen, abrechnen und verdienen. Stablecoins werden einen großen Teil davon tragen, aber sie sind nicht die ganze Zukunft. Fiatgeld, Bitcoin und Lightning gehören zum selben Bild. Stripes Antwort ist vertikale Integration: Modell-Routing, Abrechnung, Wallets, eine Chain, ein Stablecoin und ein Verzeichnis. Das ist eine beeindruckende Maschine, und sie wird für viele Unternehmen funktionieren. Privy macht die Sache differenzierter als eine einfache Gegenüberstellung von Custodial und Non-Custodial, denn es unterstützt ebenfalls Non-Custodial und exportierbare Wallets. Das Problem ist die Konzentration. Immer mehr wirtschaftliche Aktivität von Agenten kann in einem einzigen kommerziellen Universum beginnen, stattfinden und abgerechnet werden. Menschliche Handlungsfähigkeit, solange Stripe zustimmt. Nuris Antwort lautet: verbinden statt besitzen. Selbstverwahrung, wo der Nutzer sie wählt. Autonomer Besitz, wo der Agent ihn braucht. Open Source, wo Unabhängigkeit davon abhängt. Offene Standards, damit ein anderer Dienst uns ersetzen kann, ohne das finanzielle Leben des Nutzers zu ersetzen. Unabhängig von Chains und Diensten, auch auf der Fiatseite. Das ist kein direkter Kampf gegen Stripe. Stripe bedient Plattformen, die in enormem Maßstab für Agenten bauen. Wir beginnen beim Menschen und dem Agenten, der für ihn arbeitet, oder bei einem autonomen Agenten, der eine echte eigene Finanzidentität braucht. Die These ist dieselbe. Architektur und Anreize sind es nicht. **Kurz gesagt,** Menschliche Handlungsfähigkeit, solange Stripe zustimmt, ist keine menschliche Handlungsfähigkeit. ## Agenten mit einem echten Bankkonto Dieser Teil begeistert mich am meisten. Ein Agent sollte ein Wallet besitzen und autonom handeln können. Er sollte auch mit delegierter Befugnis über das Wallet eines Menschen handeln können. Das sind unterschiedliche Beziehungen, und Nuri muss beide unterstützen. Gehört das Wallet dem Nutzer, bleiben Passkey und Schlüssel beim Nutzer. Der Agent erhält nur die Befugnisse, die er braucht. Gehört ein Wallet einem autonomen Agenten, muss der Agent Geld halten, verdienen, ausgeben und abrechnen können, ohne jedes Mal auf einen menschlichen Klick zu warten. Autonomie, die am Zahlungsbildschirm endet, ist keine Autonomie. Die Fiatseite macht daraus erst ein Finanzprodukt statt einer Krypto-Demo. Nuri verbindet Agenten mit Karten, IBAN und Banküberweisungen sowie mit Bitcoin, Lightning und Stablecoins. Ein Agent muss vielleicht einen Lieferanten per Banküberweisung bezahlen, eine Karte gedeckt halten, über Lightning abrechnen oder eine API über ein offenes Protokoll für Maschinenzahlungen bezahlen. Das sind keine konkurrierenden Welten. Es ist die Welt, in der Geld schon heute lebt. Die Architektur ist unabhängig von Chains und Diensten. Funktionen werden über MCP und CLI bereitgestellt, statt in einem Frontend eingeschlossen zu sein. Die Oberfläche kann unsere Web-App oder iOS-App, der eigene Agent des Nutzers oder der Nuri-Agent auf WhatsApp sein. Dem Backend sollte egal sein, von welcher Oberfläche die Anfrage kommt. Entscheidend ist nur, ob die Anfrage zum Handeln berechtigt ist. **Kurz gesagt,** Ein Agent kann auf jeder Rail autonom sein. Nuri verbindet diese Autonomie mit Bitcoin, Lightning und Banking. ## Verifizierung folgt dem Bedarf, nicht der Ideologie Eine Designentscheidung verwirrt zunächst und leuchtet dann ein: Nuri bedient beide Seiten, Privatkunden und Institutionen, und die Verifizierung folgt dem Bedarf. Du willst ein selbstverwahrtes Wallet für Bitcoin und Stablecoins, ohne Konto und ohne Formulare? Das gibt es, es ist live und funktioniert weltweit. Du willst das Gesamtpaket mit Karte, IBAN und Banking-Rails? Dann gilt KYC, weil die regulierte Seite es verlangt, und unsere Partner kümmern sich ordentlich darum. Ein Unternehmen will dasselbe mit KYB und Kontrollen? Dasselbe Framework, dieselben Tools, eine andere Verifizierungsstufe. Das ist kein Versuch, sich nicht festzulegen. Es ist die einzige Architektur, die wirklich weltweit funktionieren kann. Ein Großteil der Welt kann kein europäisches KYC durchlaufen und sollte das auch nicht müssen, nur um eigenes Geld zu halten. Europäische Nutzer, die eine IBAN wollen, sollten dafür nicht das Produkt verlassen müssen. Ein Wallet, ein Passkey, und der Nutzer entscheidet, wie weit er in die regulierte Welt gehen will. Agenten übernehmen genau die Verifizierungsstufe ihres Menschen. **Kurz gesagt,** KYC sollte Banking freischalten, nicht darüber entscheiden, wer Geld halten darf. ## Fünf Leute und eine Maschine Stripe hat Tausende Beschäftigte. Wir sind fünf. Das geht nur, weil Nuri bis in den Kern KI-nativ ist. Das Backend ist für die Bedienung über CLI und MCP gebaut. Onchain-Aktionen laufen dort clientseitig, wo der Besitz es verlangt. Das Frontend ist austauschbar: Web, iOS, der eigene Agent des Nutzers oder der Nuri-Agent auf WhatsApp. Eine grafische App ist eine Oberfläche, nicht die Grenze des Produkts. Der Support läuft über ein Agenten-Cockpit, Menschen übernehmen die Fälle, die einen Menschen brauchen. Inhalte, Produktvideos, Monitoring und Distribution laufen zunehmend durch Agenten-Pipelines. Die Website ist für Agenten nicht nur lesbar, sondern auch bedienbar. Deshalb ist uns Agent Readiness wichtiger als ein Designpreis. Ich werde nicht behaupten, dass das alles reibungslos läuft. Ein Unternehmen so aufzubauen bedeutet, jeden Tag die eigene Zukunft zu debuggen. Aber jede Behauptung über die Agentenökonomie testen wir zuerst an uns selbst. Wir sind unser eigener erster Kunde. **Kurz gesagt,** Nuri hat kein einziges Frontend. Apps, WhatsApp und Agenten nutzen dasselbe Backend. ## Wohin das führt Stripes Brief endet mit Dank an die Investoren und dem Versprechen, mit hoher Intensität weiterzumachen. Fair. Hier ist unseres. Das Wallet wächst weiter als Brücke zwischen Fiatgeld und Krypto für Menschen und wird dieselbe Brücke für ihre Agenten. Bitcoin, Lightning, Stablecoins und Bankdienstleistungen sollten sich wie Teile eines finanziellen Lebens anfühlen, nicht wie getrennte Produkte verschiedener Gatekeeper. Das größte Zahlungsunternehmen der Welt hat gerade erklärt, dass die wirtschaftliche Infrastruktur des Internets und die wirtschaftliche Infrastruktur von KI dasselbe werden. Cloudflare baut Identität, Wallets und Zahlungsinfrastruktur rund um sein Netzwerk. Circle baut autonome Wallets rund um Stablecoins. PayBox verbindet Agenten mit bestehenden Wallets, Börsen und Karten. Das sind starke Signale dafür, dass dieser Markt real ist. Das Risiko ist nicht, dass diese Unternehmen bauen. Sie sollten bauen. Das Risiko ist, dass Identität, Intelligenz, Wallets, Zahlungswege und Abrechnung in wenigen vertikal integrierten Clouds zusammenfallen. Open Source und offene Standards halten das System für den Rest von uns kombinierbar. Durch Selbstverwahrung und Exportierbarkeit bleiben Nutzer unabhängig von den Unternehmen, die sie bedienen. Eine Richtung, die wir verfolgen wollen, ist eine Zusammenarbeit mit Nous Research rund um Hermes. Das ist ein Ziel, keine angekündigte Partnerschaft. Hermes ist Open Source, läuft lokal oder in dauerhaften Cloud-Umgebungen und kann über verschiedene Anbieter oder eigene Endpunkte mit Hunderten Modellen verbunden werden. Es unterstützt bereits Provider-Routing, Fallbacks, Tools, MCP und Messaging-Kanäle. Zusammen mit Nuri wird die Idee einfach: Agenten per Klick. Ein Modell wählen, einen Agenten lokal oder in der Cloud starten, ihm ein Wallet oder delegierte Befugnisse geben und ihn im gesamten Nuri-Universum arbeiten lassen, ohne den Nutzer an ein Modell, eine Cloud oder einen Finanzanbieter zu binden. Auf diese Zukunft wollen wir hinarbeiten: direkter Zugang zu vielen LLMs, Routing zwischen Modellen, dauerhaft laufende Cloud-Agenten und Finanzwerkzeuge in einem offenen, selbstverwahrten System. Der Agent kann einem Menschen gehören oder für sich selbst stehen. Die Oberfläche kann eine App, WhatsApp oder gar keine grafische Oberfläche sein. Entscheidend ist, dass Intelligenz und Geld zusammenkommen können, ohne dass eines von beiden zu einem neuen Gefängnis wird. Nuri muss nicht jede Ebene besitzen. Es muss die Ebenen verbinden, ohne selbst zum Grund zu werden, warum ein Nutzer darin gefangen ist. Das ist eine andere Art von Ehrgeiz: nicht das finanzielle Betriebssystem zu werden, das niemand verlassen kann, sondern eines zu bauen, das noch funktioniert, wenn jemand geht. **Kurz gesagt,** Stripe kauft den Stack. Nuri baut einen, den Nutzer verlassen können. ## Gründer, Nuri > “Stripes Wette ist, dass sie den Stack kontrollieren. Unsere Wette ist, dass du die Schlüssel hältst.” > > — Emin Mahrt ## Dieser Beitrag ist auch verfügbar auf - [What Stripe's investor letter says about Nuri](https://nuri.com/blog/what-stripes-investor-letter-means-for-nuri) (en) - [Qué dice de Nuri la carta a inversores de Stripe](https://nuri.com/es/blog/what-stripes-investor-letter-means-for-nuri) (es) - [Cosa dice di Nuri la lettera agli investitori di Stripe](https://nuri.com/it/blog/what-stripes-investor-letter-means-for-nuri) (it) --- --- title: "Der Passkey, der das Unternehmen überlebt" description: "Wie Nuri-Wallets ohne Nuri wiederhergestellt werden: ein Passkey, der sein eigenes Geheimnis trägt, Bitcoin-Scripts mit eingebautem Ausgang und Co-Signer, die on-chain verfallen." lang: "de" type: "blog-post" author: "Emin Mahrt" datePublished: "2026-09-01" dateModified: "2026-09-01" canonical: "https://nuri.com/de/blog/how-nuri-wallets-survive-without-nuri" tags: ["Nuri","Bitcoin","Lightning","Passkeys","Selbstverwahrung","Recovery"] --- # Der Passkey, der das Unternehmen überlebt **TL;DR:** Die meisten Wallets versprechen Selbstverwahrung. Wenige überleben die Frage, die wirklich zählt: Was passiert mit deinem Geld, wenn die Firma, die die Wallet gebaut hat, weg ist? Dieser Artikel beschreibt das komplette Nuri-Design: ein Passkey, dessen PRF-Erweiterung das Wallet-Geheimnis selbst trägt, Bitcoin-Outputs, deren 2-of-2-Co-Signing über einen CSV-Timelock zu 1-of-1 verfällt, und eine Arkade-Lightning-Schicht, deren Drei-Schlüssel-Leiter von Co-Signern zum Nutzerschlüssel allein verfällt. Recovery funktioniert offline, ohne nuri.com, ohne Server, ohne Export-Button. Co-Signer sind passkey-gegate, phishing-resistent und sterblich. Der einzige unsterbliche Schlüssel ist deiner. - **Autor:** Emin Mahrt - **Veröffentlicht:** 2026-09-01 ## Warum ein normaler Passkey nicht reicht Ein Passkey ist eine wunderschöne Authentifizierungs-Primitive. Der private Signaturschlüssel verlässt den Authenticator nie. Webseiten sehen nur Signaturen. Phishing stirbt, Passwort-Datenbanken werden egal. Aber als Wallet-Primitive ist ein normaler Passkey eine Sackgasse. Er kann beweisen, dass du du bist — immer wieder, für immer. Er kann dir kein Geheimnis übergeben. Und eine Wallet braucht ein Geheimnis — eine Zahl, aus der deine Bitcoin- und Ethereum-Schlüssel abgeleitet werden. Deshalb landen die meisten Passkey-Wallets in einem von zwei Lagern. Der Server hält den Wallet-Schlüssel und der Passkey ist nur ein schickes Login: Custody mit besserem UX. Oder MPC- und Enclave-Modelle teilen den Schlüssel über Infrastruktur — wirklich besser, aber die Rekonstruktion erfordert typischerweise, dass diese Infrastruktur lebt. Der Notausgang ist der Export: wenn du ihn nutzt, bevor der Anbieter verschwindet. Beide Lager teilen eine stillschweigende Annahme: Die Domain, in die du dich einloggst, überlebt dein Bedürfnis nach dem Schlüssel. Es gibt noch eine zweite, seltener diskutierte Falle. Passkeys sind domain-gebunden. Dein Credential funktioniert für die RP-ID, für die es erstellt wurde — genau das verhindert, dass eine fremde Webseite dein Wallet-Login phisht. Aber Domain-Bindung ist Schutz für die Lebensdauer der Firma, ohne Geschichte für danach. Wenn dein Wallet-Schlüssel mit der Zeremonie eines Anbieters verknüpft ist und dessen Domain dunkel wird, existiert dein Passkey noch, funktioniert noch — er hat nur niemanden mehr, mit dem er reden kann. **Kurz gesagt,** Ein Passkey beweist, wer du bist. Eine Wallet braucht ein Geheimnis. Die Frage ist, wer es hält: du oder eine Firma, von der du hoffst, dass sie online bleibt. ## Der Passkey, der sein eigenes Geheimnis trägt Nuri nutzt die WebAuthn-PRF-Erweiterung. PRF erlaubt der Wallet, dem Authenticator eine feste Frage zu stellen und eine stabile, pseudorandome Antwort zu bekommen — gebunden an dieses Credential, für immer reproduzierbar und niemals einem Server ausgesetzt. Die RP-ID ist nuri.com, der PRF-Input ist die feste Zeichenkette nuri-prf-salt-v1, und der Output sind 32 geheime Bytes, lokal erzeugt nach Nutzerverifizierung. Diese 32 Bytes sind der Seed. Von dort ist alles öffentliche, deterministische Mathematik: HKDF-SHA256 mit Domain-Trennung in BIP32-Pfade m/86'/0'/0'/0/0 für Bitcoin Taproot und m/44'/60'/0'/0/0 für Ethereum. Der Ableitungs-Code und die Konstanten sind öffentlich — das local-nuri-prf-passkey-recovery-tool auf GitHub ist genau dieser Code, verpackt für den schlimmsten Tag. Ein Unterschied trägt das meiste des Sicherheitsmodells. Eine Passkey-Zeremonie produziert zwei Dinge: die WebAuthn-Assertion — ein öffentlicher Beweis für Nutzerpräsenz, Origin, RP-ID und Absicht — und den PRF-Output — das private, deterministische Geheimnis hinter deinen Wallet-Schlüsseln. Der Nuri-Co-Signer erhält Assertionen, um zu verifizieren, dass du eine Co-Signing-Aktion genehmigt hast. Er erhält niemals den PRF-Output. Das Geheimnis, das deine Signatur erzeugt, reist nie; nur der Beweis, dass du die Signatur des Servers genehmigt hast. Co-Signing und Recovery sind absichtlich getrennte Zeremonien. Der Server kann dir an einem Dienstag beim Ausgeben helfen und ein Jahrzehnt später für deine Recovery irrelevant sein. **Kurz gesagt,** Der Server bekommt deine Zustimmung, nie dein Geheimnis. Er hilft dir beim Ausgeben und ist für deine Recovery zehn Jahre später egal. ## Aber der Passkey ist an nuri.com gebunden Ja. Der Passkey ist kryptografisch an die RP-ID nuri.com gebunden. Wir halten das für ein Feature — es ist genau das, was eine fremde Webseite daran hindert, deinen Passkey nach Geld zu fragen. Aber hier ist der Teil, der echte Design-Arbeit gekostet hat: Die RP-ID ist eine Zeichenkette, kein Abo. WebAuthn prüft, dass die anfragende Seite ein sicherer Kontext ist, dessen Hostname zur RP-ID passt. Es prüft nicht, ob die Firma noch existiert, ob DNS auflöst oder ob das Zertifikat von einer öffentlichen Autorität stammt. Das sind Browser-Sicherheitseigenschaften, keine Firmenregister. Deshalb baut das Recovery-Tool den Relying-Party-Kontext auf deiner eigenen Maschine wieder auf. Ein Hosts-Eintrag zeigt nuri.com auf deine Loopback-Adresse. Ein lokal erzeugtes, lokal vertrautes Zertifikat macht die Seite zu einem sicheren Origin. Der lokale Server auf https://nuri.com:8443 liefert geprüfte, eingecheckte Dateien — kein Remote-JavaScript, keine Analytics, keine Fonts. Dein Passkey fragt nach Face ID, Touch ID oder deiner PIN — die echte Zeremonie, dein echtes Credential — und übergibt den PRF-Output einer Seite, die vollständig auf deinem Computer läuft, idealerweise mit gezogenem Netzwerkkabel. Das ist kein WebAuthn-Bypass. Ein Angreifer braucht weiterhin deinen Passkey und deine Nutzerverifizierung. Es ist kein gefälschtes öffentliches Zertifikat — du vertraust deiner eigenen lokalen CA nur auf deiner eigenen Maschine, für eine Recovery-Session. Es ist die Erkenntnis, dass der Nutzer, dem der Passkey gehört, den RP-Kontext besitzt — auch wenn dem Domain-Registrar das egal ist. Wenn die Zeremonie fertig ist, entfernst du den Hosts-Eintrag, löschst die lokale CA und trennst die Verbindung. Die Zeichenkette nuri.com im Gedächtnis deines Passkeys hat das Unternehmen überlebt. Das war der Punkt. **Kurz gesagt,** Die Domain-Bindung schützt den Passkey vor Fremden. Sie kettet dich nicht an die Firma. Der Origin lässt sich auf deiner eigenen Maschine neu aufbauen. ## Die Bitcoin-Schicht: 2-of-2 mit eingebautem Ausgang Normales Ausgeben in Nuri Bitcoin ist eine 2-of-2-MuSig2-Kooperation. Dein Schlüssel — aus dem PRF abgeleitet — und der Schlüssel des Nuri-Co-Signers aggregieren zu einem einzigen Taproot-Schlüssel. On-chain sieht das wie ein gewöhnlicher Taproot-Output aus: schnell, privat, eine Signatur. Aber jeder Output trägt auch einen Miniscript-Notausgang, der in die Chain selbst eingebrannt ist: Der Key-Pfad ist das MuSig2-Aggregat; der Script-Pfad ist dein x-only-Schlüssel in einer CSV-Frist: and_v(v:pk(user), older(csv_blocks)). Solange Nuri lebt, gebt ihr gemeinsam über den Key-Pfad aus. Der Co-Signer gibt dir sofortiges, validiertes Ausgeben — Limits, Anomalie-Checks, ein menschlich geformtes Sicherheitsnetz. Wenn Nuri weg ist, wartest du die CSV-Frist ab — CheckSequenceVerify, ein relativer Timelock, der zu zählen beginnt, wenn der Output bestätigt — und dann kehrt dein Schlüssel allein die Gelder über den Script-Pfad. Keine Erlaubnis nötig, weil die Erlaubnis in den Output gebrannt war, als er erstellt wurde. Die Mathematik ist öffentlich: Die Unlock-Höhe ist Bestätigungshöhe plus CSV-Blöcke. Das Recovery-Tool kann die Sweep-Transaktion vor dem Unlock bauen und signieren, weigert sich aber zu senden, bis die Unlock-Bedingung erfüllt ist. Deshalb bestehen wir auf der Unterscheidung: Der private Schlüssel ist sofort offline wiederherstellbar; das Onchain-Script kann trotzdem Wartezeit verlangen. Das ist keine Anbieter-Verwahrung — es ist eine öffentliche Bitcoin-Konsensregel, die im Output steht. Verwahrung ist, wenn dich jemand ablehnen kann. Niemand kann einen Timelock ablehnen. **Kurz gesagt,** Der Co-Signer hilft, solange er lebt. Nach der CSV-Frist kehrt allein dein Schlüssel ab. Warten ist keine Verwahrung. Niemand kann einen Timelock verweigern. ## Die Verfalls-Architektur: Co-Signer, die ablaufen Jetzt der Teil, der am leichtesten zu übersehen und am schwersten zu bauen ist: Wer darf signieren, und wie schrumpft diese Menge mit der Zeit? Die meisten Multisig-Wallets behandeln den Signer-Set als permanent. Widerruf bedeutet Infrastruktur: ein Widerrufsserver, eine Key-Rotation-Zeremonie, eine Upgrade-Transaktion. Jede davon ist eine Abhängigkeit, die genau dann versagen kann, wenn du sie am meisten brauchst. Nuri behandelt den Signer-Set als Zeitplan. Co-Signer werden nicht per Infrastruktur widerrufen — sie verfallen on-chain, auf einer Uhr, die Bitcoin selbst durchsetzt. Der Nutzerschlüssel rotiert nie. Die Policy um ihn herum wird mit der Zeit nur einfacher. Auf Bitcoin L1 startet der Output als 2-of-2. Dein Schlüssel und der Schlüssel des Nuri-Co-Signers aggregieren zu einem MuSig2-Taproot-Schlüssel. Dann, zu einer festen relativen Frist nach Bestätigung des Outputs, verfällt der Co-Signer aus der Existenz. Zur Zeit null ist der Set Nutzer plus Co-Signer, sofortige Key-Pfad-Ausgaben. Nach der CSV-Frist ist der Set der Nutzer allein, Script-Pfad-Sweep. Keine Transaktion entfernt den Co-Signer. Kein Widerrufsserver, keine Key-Rotation, keine Migration. Derselbe Output hat einfach zwei Ausgabebedingungen, und die Zeit wählt, welche lebt. Das muss ein ehrliches nicht-custodiales 2-of-2 heißen: nicht 2-of-2, bis wir anders entscheiden, sondern 2-of-2, verfallend zu 1-of-1, auf einem Zeitplan, den niemand pausieren kann. **Kurz gesagt,** Zwei Schlüssel am Anfang. Einer nach der Frist. Nichts wird per Infrastruktur widerrufen — der Zeitplan steht im Script selbst. ## Die Arkade-Wallet: drei Schlüssel, zwei Verfälle Die Lightning-Schicht hat einen Signer mehr, also hat die Verfallsleiter eine Sprosse mehr. Jedes VTXO — der virtuelle Transaktions-Output, der dein Offchain-Guthaben repräsentiert — committet zu einem Taproot-Baum mit drei Blättern, jede eine vollständige Ausgabebedingung. Blatt eins ist der Arkade-Pfad: das MuSig2-Aggregat aus Nutzer und Nuri-Co-Signer, zusammen mit dem Arkade-Server. Sofort, offchain, Lightning-schnell. Blatt zwei ist die Aggregat-Recovery: Nutzer und Nuri-Co-Signer allein, nach der Arkade-CSV-Frist. Blatt drei ist die Client-Recovery: der Nutzerschlüssel allein, nach der Summe beider Fristen. In klaren Worten verfällt der Signer-Set so: Zur Zeit null ist er Nutzer, Nuri-Co-Signer und Arkade-Server — normales Lightning-Leben. Nach der ersten Frist ist der Arkade-Server verfallen: Nutzer und Co-Signer bleiben. Nach der vollen Summe beider Fristen ist auch der Nuri-Co-Signer verfallen, und nur der Nutzerschlüssel bleibt. Drei Eigenschaften machen das zur Leiter und nicht zu einem Haufen Scripts. Erstens: Thresholds schrumpfen nur auf dich zu. Drei Schlüssel, zu zwei, zu einem. Nie Wachstum, nie weg vom Nutzer. Zweitens: Jede Frist ist die Summe aller Fristen darüber. Das Client-Recovery-Blatt schaltet exakt dann frei, wenn beide Co-Signer vollständig verfallen sind, und die App lehnt strukturell jeden Baum ab, in dem der Nur-Nutzer-Pfad vor dem vollständigen Verfall des letzten Co-Signers freischalten würde. Solange ein Co-Signer im Script ist, schützt er dich noch — vor Vertipper-Beträgen, vor einem kompromittierten Client, vor dir um 3 Uhr morgens. Drittens: Der Verfall ist Konsens, nicht Infrastruktur. Nach der ersten Frist wird der Arkade-Server nicht widerrufen — er hört einfach auf, von einer lebenden Ausgabebedingung erwähnt zu werden. Selbst wenn er noch läuft, gesund und online, hat er keine mathematische Rolle mehr in deinem Output. Das meinen wir, wenn wir sagen, die Arkade-Wallet sei ein 2-of-2-of-3. Nicht drei Schlüssel, Threshold zwei, für immer — sondern ein Multisig, dessen Co-Signer sterblich sind und dessen einziger unsterblicher Schlüssel deiner ist. **Kurz gesagt,** Drei Schlüssel werden zwei, dann einer. Nie andersherum. Ein gesunder Server nach seinem Verfall hat nichts mehr zu sagen. ## Wie die Operatoren und Co-Signer zusammenspielen Es hilft, die Besetzung zu sehen. Dein Schlüssel wird aus dem PRF-Output deines Passkeys abgeleitet — er lebt auf deinen Geräten, in deinem Passwort-Manager oder auf einem Hardware-Authenticator. Der Nuri-Co-Signer ist ein Operator, den wir betreiben: Er verifiziert WebAuthn-Assertionen, bevor er seine Signatur beisteuert. Der Arkade-Server ist der Lightning-Operator, der Offchain-Sends möglich macht. Der kritische Punkt ist, wie der Co-Signer entscheidet zu signieren. Er vertraut keinem API-Key und keinem Session-Cookie. Er verlangt eine frische WebAuthn-Assertion — eine echte Passkey-Zeremonie mit Nutzerverifizierung — für jede Co-Signing-Aktion. Das macht das ganze System in der Tiefe phishing-resistent: Selbst wenn ein Angreifer einen gültigen PRF-Output extrahiert, hält er einen deterministischen Key-Seed, aber Ausgeben erfordert weiterhin den Co-Signer, und der Co-Signer handelt nur auf eine frische Passkey-Assertion des Nutzers. Ein geleakter PRF allein kann kein Geld bewegen, solange der Co-Signer im Script ist. Und nach dem Verfall des Co-Signers ist das Fenster des Angreifers dieselbe CSV-Frist, die alle schützt — eine Frist, die der Nutzer auch nutzen kann, um zuerst bei seinen Geldern zu sein. Das ist auch der Kern ohne Single Point of Failure: Der Operator, der Arkade-Server und sogar die Domain sind sterblich, ersetzbar und nach ihrem Verfall außerhalb des kritischen Pfads. Und das Design erweitert sich: Ein Hardware-Wallet kann als Backup-Co-Signer für eine 2-of-3-Recovery-Option hinzugefügt werden, und PRF-fähige Hardware-Authenticatoren — YubiKeys mit PRF-Support oder unsere biometrische NFC-Passkey-Smartcard — können den Nutzerschlüssel in Silizium halten. Mehr Schlüssel, mehr Verfallsprossen, dieselbe Regel: Thresholds schrumpfen nur auf den Nutzer zu. **Kurz gesagt,** Jede Co-Signing-Aktion braucht einen frischen Passkey-Tap. Ein gestohlener PRF allein bewegt nichts, solange der Co-Signer lebt. ## Was das bedeutet, wenn das Licht ausgeht Spiele das volle Szenario durch. Es ist 2040. Die Nuri GmbH wurde 2031 aufgelöst. Niemand hat die Domain verlängert. Du hast deinen Passkey noch in deinem Passwort-Manager, deinem Telefon oder einem Hardware-Authenticator. Auf einem offline Computer führst du das Open-Source-Recovery-Tool aus. Es baut den nuri.com-RP-Kontext lokal wieder auf — Hosts-Eintrag, lokale CA, lokaler Server. Dein Passkey — dasselbe Credential, domain-gebunden an eine Zeichenkette, die nicht mehr auflöst — evaluiert den PRF. Deterministische Ableitung erzeugt deine Bitcoin- und Ethereum-Schlüssel. Du ziehst die verschlüsselten Nostr-Backups, rekonstruierst deine VTXOs, berechnest die Unlock-Höhe jeder Verfallssprosse und sweepst: L1-Outputs, deren CSV gereift ist, Arkade-Outputs, deren Leiter fertig verfallen ist, alles noch Timelocked, sobald es reift. An keinem Punkt dieser Geschichte musste jemand in einer Firma einen Button drücken, ein Ticket genehmigen oder eine Datenbank am Leben halten. Die Rettung war von Tag eins an designed. **Kurz gesagt,** Firma weg, Domain weg, Server weg. Dein Passkey, die Chain und die Backups treffen sich trotzdem. ## Warum wir immer Rettung sagen, nicht Export Ein Export-Button ist ein Versprechen über dein künftiges Verhalten. Ein Rettungspfad ist eine Eigenschaft des Systems. Der Privy-artige Export ist ein echter Notausgang — aber einer, an den du denken musst, solange die Tür noch offen ist. Nuris Antwort dreht die Reihenfolge um. Das Schlüsselmaterial lebt beim Passkey des Nutzers. Der Verfallszeitplan lebt in der Chain. Der Recovery-State lebt auf Nostr. Der Job der Firma ist es, nützlich zu sein, solange sie existiert — nicht tragend zu sein, nachdem sie es nicht mehr ist. Das ist auch, warum die Arkade-Architektur über Nuri hinaus zählt. Agenten, die Geld halten, brauchen dieselbe Eigenschaft: einen Operator, der Geld schnell machen kann, solange er existiert, und mathematisch egal sein kann, wenn seine Zeit um ist. Eine Wallet, deren Co-Signer verfallen, ist eine Wallet, die ein Agent erben kann, ohne eine Abhängigkeit zu erben. Selbstverwahrung, die das Weiterleben des Verwahrers erfordert, ist nur Custody mit extraschritten. Wir haben Nuri so gebaut, dass sogar unsere Abwesenheit überlebensfähig ist. Das ist keine Marketing-Zeile; es ist testbar, heute, mit Tools, die wir veröffentlicht haben, und einem Szenario, das du an einem Nachmittag durchspielen kannst. Recovery braucht weiterhin den Original-Passkey, einen Authenticator mit PRF-Support und eine geprüfte Kopie des Tools. Und Ehrlichkeit beim Trade-off: Nach dem Verfall der Co-Signer verfallen auch deren Schutzfunktionen. Selbstverwahrung heißt, das zu besitzen. Der wichtigste Satz dieses Artikels ist dieser: Prüfe, ob der Passkey deiner Wallet ein Geheimnis trägt — oder nur eine Signatur. **Kurz gesagt,** Ein Export-Button ist ein Versprechen über dein künftiges Verhalten. Ein Rettungspfad ist eine Eigenschaft des Systems. ## Gründer, Nuri > “Die Co-Signer verfallen. Der Nutzerschlüssel ändert sich nie. Das ist das ganze Design.” > > — Emin Mahrt ## Dieser Beitrag ist auch verfügbar auf - [The passkey that outlives the company](https://nuri.com/blog/how-nuri-wallets-survive-without-nuri) (en) - [The passkey that outlives the company](https://nuri.com/es/blog/how-nuri-wallets-survive-without-nuri) (es) - [The passkey that outlives the company](https://nuri.com/it/blog/how-nuri-wallets-survive-without-nuri) (it) --- --- title: "Construir Nuri para los días en que algo falla" description: "Lo que Nuri aprendió tras dos semanas de fallos reales y cómo estamos haciendo la app más clara, resiliente y fácil de gestionar desde soporte." lang: "es" type: "blog-post" author: "Emin Mahrt" datePublished: "2026-08-11" dateModified: "2026-08-11" canonical: "https://nuri.com/es/blog/building-nuri-for-the-days-when-something-breaks" tags: ["Nuri","fiabilidad del producto","Bitcoin","Lightning","vías de pago"] --- # Construir Nuri para los días en que algo falla **TL;DR:** Si una vía de pago deja de funcionar, no debería parecer que toda la app está rota. Nuri necesita información de estado clara, alternativas que funcionen y un soporte que sepa qué está disponible en cada momento. Avanzaremos más rápido sin fingir que los fallos van a desaparecer y mostraremos con más claridad qué sigue funcionando cuando ocurren. - **Por:** Emin Mahrt - **Publicado:** 2026-08-11 ## Estas dos semanas no salieron según lo previsto Teníamos un plan para las dos últimas semanas. Entonces llegaron esas dos semanas. Queríamos dedicar ese tiempo a pulir la app, empezar a distribuirla e incorporar a más usuarios. En lugar de eso, pasamos buena parte del tiempo reaccionando a problemas en Bitcoin, Lightning y distintas vías de pago. Sinceramente, fue agotador. No porque todos los problemas fueran catastróficos. Aún estamos empezando y el número de usuarios afectados era manejable. Pero parecía el día de la marmota: arreglábamos una cosa, cambiaba otra, luego dejaba de funcionar una alternativa y después surgía algo más que necesitaba atención. Mi primera reacción fue de frustración. Pero, después de pensarlo, la lección más importante se hizo evidente. Esto volverá a pasar. > “I must say I feel exhausted after these two weeks.” > > — Emin Mahrt · De la grabación original **En pocas palabras,** Planeamos un sprint normal de dos semanas. En cambio, nos pasamos dos semanas apagando fuegos. ## Este es el entorno en el que construimos Nuri conecta muchos sistemas financieros distintos. La banca, las tarjetas, Bitcoin, Lightning, las monedas locales y las infraestructuras de pago se comportan de forma diferente. Algunas partes son nuestras. Otras nos conectan con infraestructura externa. Cualquiera de ellas puede cambiar, entrar en mantenimiento o dejar de funcionar temporalmente. Todo el mundo en este sector, nosotros incluidos, trabaja en sistemas complejos. Los cambios y las interrupciones forman parte de ese trabajo. Elegimos reunir estos sistemas, así que la experiencia que tienen los usuarios cuando algo cambia es responsabilidad nuestra. Nuestro trabajo no es fingir que todas las piezas funcionarán perfectamente para siempre. Nuestro trabajo es asegurarnos de que Nuri siga siendo útil cuando una de ellas falle. > “if you're building a puzzle with many moving parts, of course, those moving parts are going to work, going to not work, going to break.” > > — Emin Mahrt · De la grabación original **En pocas palabras,** A veces las cosas dejarán de funcionar. Nuestra app tiene que seguir teniendo sentido cuando ocurra. ## Una alternativa tiene que funcionar cuando hace falta El momento más frustrante no fue que una función dejara de funcionar. Eso puede pasar. Lo frustrante fue descubrir que una alternativa ya no estaba disponible justo en la situación en la que los usuarios la necesitaban. Eso nos enseñó algo muy sencillo: una alternativa que solo funciona en condiciones normales no es una gran alternativa. Tenemos que seguir eliminando puntos únicos de fallo siempre que podamos. A veces eso significa añadir otra vía. A veces significa dar a los usuarios una forma de recuperarse o de salir sin depender de nosotros. A veces solo significa separar dos funciones que parecen similares, pero fallan por motivos completamente distintos. Bitcoin y Lightning son un buen ejemplo. Para muchos usuarios pueden parecer dos versiones de lo mismo. Técnicamente, son sistemas muy distintos, con diferentes ventajas e inconvenientes y diferentes formas de fallar. Presentarlos como un único saldo integrado puede quedar más limpio, pero también significa que un problema de Lightning puede hacer que toda la experiencia con Bitcoin parezca rota. Por ahora, separarlos es más honesto y más útil. Bitcoin puede seguir funcionando cuando Lightning no está disponible. Lightning puede mostrar claramente su estado actual. Los usuarios no deberían tener que entender el motivo técnico. Solo necesitan saber qué funciona, qué no y qué pueden hacer a continuación. **En pocas palabras,** Bitcoin y Lightning no deberían tumbarse mutuamente. Una alternativa tiene que ser real, no decorativa. ## Nos esforzamos demasiado por ocultar la maquinaria Durante mucho tiempo quise que Nuri ocultara toda la complejidad. Ese sigue siendo el objetivo en muchos sitios. Nadie debería tener que entender de nodos, liquidez, encaminamiento de pagos o proveedores de infraestructura para enviar dinero. Pero ocultar la complejidad no puede significar ocultar la realidad. Si una vía no está disponible temporalmente, la app debería decirlo. Si algo está en mantenimiento, debería parecer que está en mantenimiento. Si una moneda está disponible como vía de pago, pero no como saldo, la interfaz debería dejar clara esa diferencia. Antes intentábamos evitar mensajes como «no disponible temporalmente». Parecían técnicos y poco amables. Visto ahora, eso creó una experiencia peor. Un botón que parece disponible, pero falla después de pulsarlo, es mucho más frustrante que un botón en gris con una explicación clara. Esto cambia nuestra forma de pensar en la pantalla principal de Nuri. No solo debería mostrar dónde está tu dinero. También debería mostrar qué puedes hacer con él en este momento. Puede que tengas dinero en euros y varias formas de usar esos euros: pagos con tarjeta, transferencias bancarias o convertirlos a otra moneda. Algunas infraestructuras de pago ni siquiera necesitan tener su propio saldo. Son simplemente otra forma de enviar o recibir dinero. Al mismo tiempo, nunca debemos mostrar el mismo dinero dos veces. Si tu tarjeta y tu cuenta bancaria usan el mismo saldo subyacente, mostrar esa cantidad en ambos sitios puede hacer que parezca que tienes el doble del dinero que realmente tienes. Puede que la primera versión no sea bonita, pero tiene que ser clara. **En pocas palabras,** No escondas una vía que no funciona detrás de un botón que parece funcionar. Dile a la gente qué funciona antes de que lo pulse. ## El soporte debería saber lo mismo que la app Esta semana también cambió mi forma de entender el soporte. El soporte no debería ser un sistema separado con una lista de funciones desactualizada. Debería entender la misma Nuri que está viendo el usuario. Si una vía no está disponible, el soporte debería saberlo de inmediato. Si se ha desactivado una función, nuestro agente de soporte no debería recomendarla. Si alguien pregunta por qué no puede pagar una factura de Lightning, el soporte debería poder ver si la vía funciona, explicar la situación actual y sugerir una alternativa disponible. Aquí es donde nuestro trabajo con MCP se vuelve práctico. MCP suena técnico, pero la idea básica es sencilla: queremos que todas las capacidades de Nuri estén disponibles a través de una interfaz limpia que puedan entender tanto la app como los agentes. El MCP de Nuri debería contener las funciones que están disponibles de verdad en Nuri. Las funciones experimentales deberían estar en otro lugar hasta que estén listas. Ahora mismo, esa separación no siempre está clara. Tenemos experimentos, funciones de la app y servicios independientes demasiado juntos. Tenía sentido cuando avanzábamos rápido y probábamos ideas. Tiene menos sentido ahora que queremos que los agentes den soporte a usuarios reales. Cuando algo pase a estar disponible en Nuri, el agente de soporte debería entenderlo. Cuando algo desaparezca de la app, también debería desaparecer de las acciones disponibles para el agente. La app, el soporte y la infraestructura deberían describir la misma realidad. **En pocas palabras,** Nuestro agente de soporte nunca debería dirigirte a una función que no está disponible en ese momento. ## No vamos a esperar a que todo sea perfecto Podemos pasar meses diseñando la alternativa perfecta para cada fallo posible. Luego lanzamos y descubrimos que los usuarios están confundidos por algo completamente distinto. Necesitamos usuarios reales. Necesitamos que la gente abra Nuri, intente usarla y nos diga dónde se atasca. No porque tenga una teoría sobre nuestra interfaz, sino porque quería hacer algo y no pudo. Ese feedback es más útil que diez opiniones internas. Un ejemplo surgió al separar las tarjetas y las transferencias bancarias. Desde el punto de vista técnico, juntarlas puede parecer lógico porque quizá compartan un saldo. Pero los usuarios preguntaban una y otra vez dónde estaba su IBAN. Abrían la pantalla de la tarjeta, veían una tarjeta y dejaban de buscar. No esperaban que las transferencias bancarias estuvieran escondidas allí. Los usuarios no necesitan saber por qué agrupamos dos cosas en un principio. Solo saben que no pudieron encontrar lo que necesitaban. Así que avanzaremos más rápido, aunque las pantallas y los flujos aún estén sin pulir. Después veremos dónde tiene problemas la gente y mejoraremos esas partes. Algunas cosas no tendrán un aspecto perfecto y algunos experimentos fallarán. Una idea puede tener sentido en una reunión y parecer equivocada en cuanto alguien la pruebe. Preferimos aprenderlo ahora. > “it's okay that things break it's okay that they don't look good we just react on it and basically make the best out of it” > > — Emin Mahrt · De la grabación original **En pocas palabras,** Poner Nuri en manos de más gente, ver dónde tiene problemas y arreglar primero los problemas reales. ## Lo que vamos a hacer ahora Seguiremos mejorando la app, pero también empezaremos a conseguir que la use más gente. La distribución no puede seguir siendo la tarea que posponemos cada vez que algo falla. Estamos separando funciones para que una vía no disponible no perjudique al resto de la experiencia, añadiendo información de estado más clara y ordenando el MCP de Nuri para que coincida con la app. Soporte debería saber qué funciones están disponibles. Una mejor monitorización nos ayudará a encontrar los problemas antes de que se conviertan en largas conversaciones con soporte. Para Lightning, estudiaremos las opciones disponibles sin precipitarnos y acabar atados a otra dependencia permanente. Hay varios pasos posibles. Podemos admitir intercambios normales entre Bitcoin y Lightning, investigar versiones más rápidas más adelante, evaluar otros enfoques sin custodia o seguir mejorando nuestra integración actual cuando estén disponibles las capacidades necesarias. No tenemos que tomar hoy todas las decisiones. Bitcoin puede seguir siendo útil sin fingir que todos los casos de uso de Lightning ya están resueltos. Lightning es difícil y el sector en general todavía está intentando resolver algunos problemas complicados. Preferimos ser honestos al respecto antes que forzar una experiencia que parezca integrada, pero se vuelva confusa cuando algo cambie. El mismo principio se aplica más allá de Bitcoin. Si la vía de una moneda local entra en mantenimiento, el resto de Nuri debería seguir funcionando. Si un servicio de tarjetas no está disponible, los usuarios deberían poder seguir encontrando sus opciones de transferencia bancaria. Si una función es experimental, no debería aparecer discretamente como si estuviera lista para producción. **En pocas palabras,** Mostrar qué funciona, mantener activas las alternativas, hacer que soporte refleje la app y poner Nuri delante de más gente. ## De la grabación original > “Habrá fallos, pero una pieza rota no debería tumbar el resto de Nuri.” > > — Emin Mahrt ## Este artículo también está disponible en - [Building Nuri for the days when something breaks](https://nuri.com/blog/building-nuri-for-the-days-when-something-breaks) (en) - [Nuri für die Tage bauen, an denen etwas kaputtgeht](https://nuri.com/de/blog/building-nuri-for-the-days-when-something-breaks) (de) - [Costruire Nuri per i giorni in cui qualcosa si rompe](https://nuri.com/it/blog/building-nuri-for-the-days-when-something-breaks) (it) --- --- title: "Qué dice de Nuri la carta a inversores de Stripe" description: "La carta a inversores de Stripe describe la economía de los agentes. Nuri ve el mismo futuro, construido sobre estándares abiertos, autocustodia e independencia del usuario." lang: "es" type: "blog-post" author: "Emin Mahrt" datePublished: "2026-08-20" dateModified: "2026-08-20" canonical: "https://nuri.com/es/blog/what-stripes-investor-letter-means-for-nuri" tags: ["Nuri","Stripe","finanzas agénticas","stablecoins","MCP","autocustodia"] --- # Qué dice de Nuri la carta a inversores de Stripe **TL;DR:** El 19 de agosto, Stripe dijo a sus inversores que los agentes de IA se están convirtiendo en actores económicos y que el dinero pasará a ser nativo de la economía de la IA. Leímos la carta y reconocimos el futuro para el que estamos construyendo. La tesis es la misma. El enfoque es distinto: Stripe integra cada vez más partes del stack en una sola plataforma. Nuri se construye sobre estándares abiertos, autocustodia e independencia respecto a la propia Nuri. Los agentes pueden ser dueños de dinero, actuar de forma autónoma o trabajar para una persona dentro de límites claros. Y ese dinero no se limita a las stablecoins y el dinero fiat. Incluye bitcoin, Lightning y cualquier vía abierta que venga después. - **Autor:** Emin Mahrt - **Publicado:** 2026-08-20 ## Lo que Stripe escribió de verdad Merece la pena leer la carta completa. Esta es la versión corta. Stripe anunció OpenRouter como su mayor adquisición hasta la fecha. Las empresas no revelaron el precio. The New York Times informa de 7.500 millones de dólares; Reuters, de algo más de 8.000 millones. OpenRouter había sido valorada en 1.300 millones solo tres meses antes. Antes de OpenRouter llegaron Bridge, Privy y Metronome. Bridge costó 1.100 millones de dólares. Las condiciones oficiales de Metronome no se hicieron públicas, pero las informaciones sitúan la operación en torno a 1.000 millones. El precio de compra de Privy tampoco se reveló; su última valoración publicada antes de la adquisición fue de 230 millones. Eso deja a Stripe entre 9.600 y 10.100 millones de dólares en valor de operaciones publicado entre OpenRouter, Bridge y Metronome, más lo que pagara por Privy. No incluye el coste de construir el resto del stack. Escribieron: «Decidimos que el 1 de enero marcó el comienzo de la singularidad y, desde entonces, hemos operado sobre esa base». Informan de que los ingresos netos del primer semestre subieron un 41 % interanual, el flujo de caja libre un 43 %, el 88 % de Forbes AI 50 usa Stripe y el consumo de tokens en OpenRouter crece de forma compuesta un 9 % por semana. La frase central es esta: «construir infraestructura económica para internet es prácticamente lo mismo que construir la infraestructura económica para la IA». Y enumeran las piezas que están construyendo: Stripe Projects y Directory para incorporar y descubrir agentes, Metronome para el uso, Bridge y una Agentic Commerce Suite para los pagos, Tempo como su propia blockchain para agentes, MPP como protocolo de pagos entre máquinas, Privy para las carteras y Open Standard, su propia stablecoin. También escribieron algo a lo que sigo dando vueltas: «Existe el temor de que la IA provoque desempleo o centralización; quizá ambas cosas. Creemos que es importante que el despliegue de la IA refuerce la capacidad de acción humana». Estoy de acuerdo con cada palabra del diagnóstico. Discrepo del tratamiento. **En pocas palabras,** Stripe llamó singularidad al 1 de enero tras comprometer más de 9.600 millones de dólares en el stack que la rodea. ## La parte en la que describen nuestro producto Repasa la lista de componentes básicos de Stripe y compárala con Nuri. Stripe ahora es propietaria de Privy. Privy define sus carteras de usuario como no custodiales y permite exportar la clave privada, una vía de escape real. Pero antes de exportarla, la firma sigue dependiendo de la infraestructura de Privy: Privy almacena un fragmento cifrado de la clave y el otro solo puede descifrarse y combinarse dentro de su AWS Nitro Enclave. Si esa infraestructura desaparece antes de que el usuario exporte la clave, la cartera no tiene una vía local de recuperación. Con Nuri, WebAuthn PRF deriva localmente la propia clave del usuario a partir de la passkey. En los modelos de cartera multifirma, esta es la clave del usuario, no todas las claves firmantes. La vía de cofirma está limitada en el tiempo mediante CSV, así que, tras una ventana fija de bloques, el usuario conserva una vía de recuperación independiente. Una clave de respaldo separada, como una cartera física, puede añadir una opción de recuperación 2 de 3. El mismo principio puede aplicarse a las cuentas EVM Safe que usan los agentes. El usuario no tiene que acordarse de pulsar un botón de exportación antes de que Nuri desaparezca. La diferencia no es cosmética. Es independencia integrada en la cartera. Nuri reúne dinero fiat y cripto en una sola cartera, pero se dirige a las personas y a sus agentes, no solo a las plataformas: tarjeta e IBAN, bitcoin onchain y mediante Lightning, stablecoins y las vías abiertas que los conectan. Un agente puede operar una cartera propiedad del usuario dentro de ciertos límites, o ser dueño de una cartera y actuar de forma autónoma. Ambos modos importan. La pregunta importante no es dónde se aplica una regla presupuestaria en una implementación concreta. Es si la autoridad es real. Un agente necesita libertad suficiente para actuar, gastar, ganar y completar tareas sin preguntar a una persona por cada céntimo. El propietario sigue necesitando una forma de definir los límites y revocar el acceso delegado. Nuri es nativa de IA por debajo de la interfaz. El sistema puede operarse mediante CLI y MCP, mientras que las acciones onchain siguen ejecutándose en el lado del cliente cuando así lo exige el modelo de cartera. La interfaz puede ser la app web, la app de iOS, el agente propio del usuario o el agente de Nuri en WhatsApp. Toda capacidad importante debe funcionar sin presuponer que una persona va pulsando botones en distintas pantallas. No estamos construyendo una blockchain ni emitiendo dinero. Nuri está diseñada para ser agnóstica respecto a cadenas, protocolos y servicios financieros, también en el lado fiat. El código abierto y los estándares abiertos importan porque el usuario nunca debería depender de una sola empresa, incluida la nuestra, para seguir usando su dinero. **En pocas palabras,** Si tu cartera necesita un botón de exportación antes de que desaparezca el proveedor, no eres independiente. ## La misma singularidad, otra respuesta La forma honesta de decirlo es esta: creemos lo mismo que Stripe. Los agentes tendrán dinero, trabajarán dentro de presupuestos, pagarán servicios, se suscribirán, liquidarán y ganarán. Las stablecoins moverán una gran parte, pero no son todo el futuro. El dinero fiat, bitcoin y Lightning forman parte del mismo panorama. La respuesta de Stripe es la integración vertical: enrutamiento de inteligencia, facturación, carteras, una blockchain, una stablecoin y un directorio. Es una máquina impresionante y funcionará para muchas empresas. Privy añade matices que impiden reducirlo a un simple debate entre custodia y no custodia; también admite carteras no custodiales y exportables. Lo preocupante es la concentración. Cada vez más partes de la economía de los agentes pueden nacer, moverse y liquidarse dentro de un único universo comercial. Capacidad de acción humana, mientras Stripe esté de acuerdo. La respuesta de Nuri es combinar en lugar de poseer. Autocustodia cuando el usuario la elige. Propiedad autónoma cuando el agente la necesita. Código abierto cuando la independencia depende de ello. Estándares abiertos para que otro servicio pueda sustituirnos sin sustituir la vida financiera del usuario. Agnóstica respecto a cadenas y servicios, también en el lado fiat. Esto no es una lucha directa con Stripe. Ellos sirven a plataformas que construyen para agentes a una escala enorme. Nosotros empezamos por la persona y el agente que trabaja para ella, o por un agente autónomo que necesita una identidad financiera propia y real. La tesis es la misma. La arquitectura y los incentivos no. **En pocas palabras,** La capacidad de acción humana, si depende de que Stripe esté de acuerdo, no es capacidad de acción humana. ## Agentes con una cuenta bancaria de verdad Esta es la parte que más me entusiasma. Un agente debería poder ser dueño de una cartera y operar de forma autónoma. También debería poder actuar a través de la cartera de una persona con autoridad delegada. Son relaciones distintas y Nuri debe admitir ambas. Cuando la cartera pertenece al usuario, la passkey y las claves permanecen con él. El agente recibe solo la autoridad que necesita. Cuando una cartera pertenece a un agente autónomo, el agente debe poder guardar dinero, ganar, gastar y liquidar sin esperar cada vez el clic de una persona. La autonomía que termina en la pantalla de pago no es autonomía. El lado fiat es lo que convierte esto de una demostración cripto en un producto financiero. Nuri conecta a los agentes con tarjetas, IBAN y transferencias bancarias, además de bitcoin, Lightning y stablecoins. Un agente puede necesitar pagar a un proveedor por transferencia bancaria, mantener una tarjeta con saldo, liquidar mediante Lightning o pagar una API con un protocolo abierto de pagos entre máquinas. No son mundos enfrentados. Son el mundo en el que ya vive el dinero. La arquitectura es agnóstica respecto a cadenas y servicios. Las capacidades se ofrecen mediante MCP y CLI en lugar de quedar encerradas en una única interfaz. La interfaz puede ser nuestra app web o de iOS, el agente propio del usuario o el agente de Nuri en WhatsApp. Al backend no debería importarle desde qué interfaz llegó la solicitud, solo si esa solicitud tiene autoridad para actuar. **En pocas palabras,** Un agente puede ser autónomo en cualquier vía. Nuri conecta esa autonomía con Bitcoin, Lightning y la banca. ## La verificación sigue a la necesidad, no a la ideología Hay una decisión de diseño que al principio desconcierta y luego se entiende: Nuri sirve tanto al mercado minorista como a las instituciones, y la verificación sigue a la necesidad. ¿Quieres una cartera autocustodial para bitcoin y stablecoins, sin cuenta ni formularios? Existe, está operativa y funciona en todo el mundo. ¿Quieres el conjunto completo con tarjeta, IBAN y vías bancarias? Entonces se aplica KYC, porque es lo que exige la parte regulada, y nuestros socios lo gestionan correctamente. ¿Una empresa quiere lo mismo con KYB y controles? Mismo marco, mismas herramientas, distinto nivel de verificación. Esto no es quedarse a medias. Es la única arquitectura que de verdad puede funcionar en todo el mundo. La mayor parte del planeta no puede superar un proceso KYC europeo y no debería necesitarlo solo para guardar su propio dinero. Y los usuarios europeos que quieran un IBAN no deberían tener que salir del producto para conseguirlo. Una cartera, una passkey, y el usuario decide hasta dónde quiere entrar en el mundo regulado. Los agentes heredan exactamente el nivel de verificación de su propietario. **En pocas palabras,** El KYC debería dar acceso a la banca, no decidir quién puede tener dinero. ## Cinco personas y una máquina Stripe tiene miles de empleados. Nosotros somos cinco. Eso solo es posible porque Nuri es nativa de IA de arriba abajo. El backend está diseñado para operarse mediante CLI y MCP. Las acciones onchain se ejecutan en el lado del cliente cuando la propiedad así lo exige. La interfaz es intercambiable: web, iOS, el agente propio del usuario o el agente de Nuri en WhatsApp. Una aplicación gráfica es una interfaz, no el límite del producto. El soporte funciona mediante una consola para agentes, con personas a cargo de los casos que necesitan intervención humana. El contenido, los vídeos de producto, la monitorización y la distribución pasan cada vez más por pipelines de agentes. El sitio web no solo es legible para los agentes, también pueden operarlo. Por eso la preparación para agentes nos importa más que un premio de diseño. No voy a fingir que todo esto sea sencillo. Construir una empresa de este modo significa depurar tu propio futuro cada día. Pero cada afirmación que hacemos sobre la economía de los agentes la probamos primero en nosotros mismos. Somos nuestro primer cliente. **En pocas palabras,** Nuri no tiene una única interfaz. Las apps, WhatsApp y los agentes usan el mismo backend. ## Hacia dónde va esto La carta de Stripe termina dando las gracias a sus inversores y prometiendo intensidad. Bien. Aquí va nuestra promesa. La cartera sigue creciendo como puente entre dinero fiat y cripto para las personas, y se convierte en el mismo puente para sus agentes. Bitcoin, Lightning, stablecoins y servicios bancarios deberían sentirse como partes de una sola vida financiera, no como productos separados en manos de guardianes distintos. La mayor empresa de pagos acaba de declarar que la infraestructura económica de internet y la infraestructura económica de la IA se están convirtiendo en lo mismo. Cloudflare está construyendo identidad, carteras e infraestructura de pagos alrededor de su red. Circle está construyendo carteras autónomas en torno a las stablecoins. PayBox está conectando agentes con carteras, plataformas de intercambio y tarjetas existentes. Son señales claras de que el mercado es real. El riesgo no es que estas empresas estén construyendo. Deben hacerlo. El riesgo es que la identidad, la inteligencia, las carteras, las vías de pago y la liquidación queden concentradas en unas pocas nubes integradas verticalmente. El código abierto y los estándares abiertos permiten que los demás mantengamos un sistema componible. La autocustodia y la capacidad de exportar permiten que los usuarios sigan siendo independientes de las empresas que les prestan servicio. Una vía que queremos explorar es colaborar con Nous Research en torno a Hermes. Es un objetivo, no una colaboración anunciada. Hermes es de código abierto, se ejecuta localmente o en entornos persistentes en la nube y puede conectarse a cientos de modelos mediante distintos proveedores o endpoints personalizados. Ya admite enrutamiento entre proveedores, mecanismos de respaldo, herramientas, MCP y canales de mensajería. Al unirlo con Nuri, la idea se vuelve sencilla: agentes con un clic. Elige un modelo, lanza un agente localmente o en la nube, dale una cartera o autoridad delegada y deja que opere en todo el universo Nuri sin encerrar al usuario en un solo modelo, una sola nube o un solo proveedor financiero. Ese es el futuro hacia el que queremos construir: acceso directo a muchos LLM, enrutamiento entre modelos, agentes persistentes en la nube y herramientas financieras dentro de un único sistema de código abierto y no custodial. El agente puede pertenecer a una persona o actuar por cuenta propia. La interfaz puede ser una app, WhatsApp o ninguna interfaz gráfica. Lo importante es que la inteligencia y el dinero puedan encontrarse sin que ninguno se convierta en un nuevo punto de cautividad. Nuri no necesita poseer todas las capas. Necesita conectarlas sin convertirse en la razón por la que un usuario queda atrapado en ellas. Es una ambición distinta: no convertirse en el sistema operativo financiero del que nadie puede salir, sino construir uno que siga funcionando cuando salgan. **En pocas palabras,** Stripe compra el stack. Nuri construye uno del que los usuarios pueden salir. ## Fundador, Nuri > “La apuesta de Stripe es que ellos controlen el stack. La nuestra es que tú conserves las claves.” > > — Emin Mahrt ## Este artículo también está disponible en - [What Stripe's investor letter says about Nuri](https://nuri.com/blog/what-stripes-investor-letter-means-for-nuri) (en) - [Was Stripes Investorenbrief über Nuri sagt](https://nuri.com/de/blog/what-stripes-investor-letter-means-for-nuri) (de) - [Cosa dice di Nuri la lettera agli investitori di Stripe](https://nuri.com/it/blog/what-stripes-investor-letter-means-for-nuri) (it) --- --- title: "The passkey that outlives the company" description: "How Nuri wallets recover without Nuri: a passkey that carries its own secret, Bitcoin scripts with a built-in exit, and co-signers that decay on chain." lang: "es" type: "blog-post" author: "Emin Mahrt" datePublished: "2026-09-01" dateModified: "2026-09-01" canonical: "https://nuri.com/es/blog/how-nuri-wallets-survive-without-nuri" tags: ["Nuri","Bitcoin","Lightning","passkeys","self-custody","recovery"] --- # The passkey that outlives the company **TL;DR:** Most wallets promise self-custody. Few survive the question that actually matters: what happens to your money when the company that built the wallet is gone? This article walks through the full Nuri design: a passkey whose PRF extension carries the wallet secret itself, Bitcoin outputs whose 2-of-2 co-signing decays to 1-of-1 through a CSV timelock, and an Arkade Lightning layer whose three-key ladder decays from co-signers to the user key alone. Recovery works offline, without nuri.com, without servers, without an export button. Co-signers are passkey-gated, phishing-resistant, and mortal by design. The only immortal key is yours. - **Author:** Emin Mahrt - **Published:** 2026-09-01 ## Why a normal passkey is not enough A passkey is a beautiful authentication primitive. The private signing key never leaves the authenticator. Websites only ever see signatures. Phishing dies; password databases stop mattering. But as a wallet primitive, a normal passkey is a dead end. It can prove you are you, again and again, forever. It cannot hand you a secret. And a wallet needs a secret — a number from which your Bitcoin and Ethereum keys are derived. So most passkey wallets end up in one of two camps. The server holds the wallet key and the passkey is just a fancy login: custody with better UX. Or MPC and enclave models split the key across infrastructure — genuinely better, but reconstruction typically requires that infrastructure to be alive, and the escape hatch is export: if you remember to use it before the provider disappears. Both camps share a quiet assumption: the domain you log in to outlives your need for the key. There is also a second, less discussed trap. Passkeys are domain-bound. Your credential works for the RP ID it was created for — that is exactly what stops a random website from phishing your wallet login. But domain binding is protection for the company's lifetime, with no story for after. If your wallet key is entangled with a provider's ceremony and that provider's domain goes dark, your passkey still exists, still works — it just has nobody left to talk to. The industry treats that as an edge case. For money, it is the case. **Basically,** A passkey proves who you are. A wallet needs a secret. The question is who holds it: you, or a company you hope stays online. ## The passkey that carries its own secret Nuri uses the WebAuthn PRF extension. PRF lets the wallet ask the authenticator a fixed question and receive a stable, pseudorandom answer — tied to that credential, reproducible forever, and never exposed to any server. The RP ID is nuri.com, the PRF input is the fixed string "nuri-prf-salt-v1", and the output is 32 secret bytes, produced locally after user verification. Those 32 bytes are the seed. From there, everything is public, deterministic math: HKDF-SHA256 with domain separation into BIP32 paths m/86'/0'/0'/0/0 for Bitcoin Taproot and m/44'/60'/0'/0/0 for Ethereum. The derivation code and constants are public — the local-nuri-prf-passkey-recovery-tool on GitHub is exactly that code, packaged for the worst day. One distinction carries most of the security model. A passkey ceremony produces two things: the WebAuthn assertion — a public proof of user presence, origin, RP ID and intent — and the PRF output — the private, deterministic secret behind your wallet keys. The Nuri co-signer receives assertions to verify that you approved a co-signing action. It never receives the PRF output. The secret that creates your signature never travels; only the proof that you approved the server's signature does. Co-signing and recovery are separate ceremonies on purpose. The server can help you spend on a Tuesday and be irrelevant to your recovery a decade later. **Basically,** The server gets your approval, never your secret. It can help you spend on a Tuesday and be irrelevant to your recovery ten years later. ## But the passkey is bound to nuri.com Yes. The passkey is cryptographically bound to the RP ID nuri.com. We consider that a feature — it is what stops any random website from asking your passkey for money. But here is the part that took real design work: the RP ID is a string, not a subscription. WebAuthn checks that the page requesting the ceremony is a secure context whose hostname matches the RP ID. It does not check whether the company still exists, whether DNS resolves, or whether the certificate came from a public authority. Those are browser security properties, not corporate records. So the recovery tool recreates the relying-party context on your own machine. A hosts entry points nuri.com at your loopback address. A locally generated, locally trusted certificate makes the page a secure origin. The local server on https://nuri.com:8443 serves reviewed, committed files — no remote JavaScript, no analytics, no fonts. Your passkey asks for Face ID, Touch ID, or your PIN — the real ceremony, your real credential — and hands the PRF output to a page running entirely on your computer, ideally with the network cable pulled. This is not a WebAuthn bypass. An attacker still needs your passkey and your user verification. It is not a forged public certificate — you trust your own local CA only on your own machine, for one recovery session. It is the recognition that the user who owns the passkey owns the RP context — even when the domain registrar no longer cares. When the ceremony is done, you remove the hosts entry, delete the local CA, and disconnect. The string "nuri.com" in your passkey's memory outlived the company. That was the point. **Basically,** The domain binding protects the passkey from strangers. It does not chain you to the company. The origin can be rebuilt on your own machine. ## The Bitcoin layer: 2-of-2 with a built-in exit Normal spending on Nuri Bitcoin is a 2-of-2 MuSig2 collaboration. Your key — derived from the PRF — and the Nuri co-signer's key aggregate into a single Taproot key. On chain it looks like an ordinary Taproot output: fast, private, one signature. But every output also carries a Miniscript escape hatch, committed into the chain itself. The key path is the MuSig2 aggregate; the script path is your x-only key wrapped in a CSV delay: and_v(v:pk(user), older(csv_blocks)). While Nuri is alive, you and the co-signer spend together through the key path. The co-signer gives you instant, validated spending — spending limits, anomaly checks, a human-shaped safety net. If Nuri is gone, you wait out the CSV delay — CheckSequenceVerify, a relative timelock that starts counting when the output confirms — and then your key alone sweeps the funds through the script path. No permission needed, because the permission was baked into the output when it was created. The math is public: unlock height is confirmation height plus CSV blocks. The recovery tool can build and sign the sweep transaction before unlock for inspection, but refuses to broadcast until the unlock condition is satisfied. This is why we insist on the distinction: the private key is recoverable offline immediately; the onchain script may still require waiting. That is not provider custody — it is a public Bitcoin consensus rule committed into the output. Custody is when someone can refuse you. Nobody can refuse a timelock. **Basically,** The co-signer helps while it lives. After the CSV delay, your key alone sweeps. Waiting is not custody. Nobody can refuse a timelock. ## The decay architecture: co-signers that expire Now the part that is easiest to miss and hardest to build: who is allowed to sign, and how that set shrinks over time. Most multisig wallets treat the signer set as permanent. Revocation means infrastructure: a revocation server, a key-rotation ceremony, an upgrade transaction. Every one of those is a dependency that can fail exactly when you need it most. Nuri treats the signer set as a schedule. Co-signers are not revoked by infrastructure — they decay on chain, on a clock that Bitcoin itself enforces. The user key never rotates. The policy around it just gets simpler as time passes. On Bitcoin L1, the output starts as a 2-of-2: your key and the Nuri co-signer's key aggregate into one MuSig2 Taproot key. Then, at a fixed relative timelock after the output confirms, the co-signer decays out of existence. At time zero the set is user plus co-signer, instant key-path spends. After the CSV delay the set is the user alone, script-path sweep. No transaction removes the co-signer. No revocation server, no key rotation, no migration. The same output simply has two spending conditions, and time selects which one is live. That is what an honest non-custodial 2-of-2 has to mean: not 2-of-2 until we decide otherwise, but 2-of-2, decaying to 1-of-1, on a schedule nobody can pause. **Basically,** Two keys at the start. One key after the delay. Nothing gets revoked by infrastructure — the schedule sits in the script itself. ## The Arkade wallet: three keys, two decays The Lightning layer has one more signer, so the decay ladder has one more rung. Every VTXO — the virtual transaction output that represents your off-chain balance — commits to a Taproot tree with three leaves, each a complete spending condition. Leaf one is the arkade path: the MuSig2 aggregate of user and Nuri co-signer, together with the arkade server. Instant, off-chain, Lightning-fast. Leaf two is aggregate recovery: user and Nuri co-signer alone, after the arkade CSV delay. Leaf three is client recovery: the user key alone, after the sum of both delays. In plain words, the signer set decays like this: at time zero it is user, Nuri co-signer and arkade server — normal Lightning life. After the first delay, the arkade server has decayed: user and co-signer remain. After the full sum of both delays, the Nuri co-signer has decayed too, and only the user key remains. Three properties make this a ladder and not a pile of scripts. First, thresholds only ever shrink toward you: three keys, to two, to one. Never grows, never moves away from the user. Second, each delay is the sum of all delays above it: the client-recovery leaf unlocks at exactly the moment both co-signers have fully decayed, and the app structurally rejects any tree where the user-only path would unlock before the last co-signer's decay completes. While a co-signer is still in the script, it is still protecting you — against fat-fingered amounts, against a compromised client, against you at 3 a.m. Third, the decay is consensus, not infrastructure: at the first delay the arkade server does not get revoked — it simply stops being mentioned by any live spending condition. Even if it is still running, healthy and online, it has no mathematical role in your output anymore. This is what we mean when we say the Arkade wallet is a 2-of-2-of-3. Not three keys, threshold two, forever — but a multisig whose co-signers are mortal by design, and whose only immortal key is yours. **Basically,** Three keys become two, then one. Never the other way. A healthy server past its decay has no say anymore. ## How the operators and co-signers work together It helps to see the cast. Your key is derived from your passkey's PRF output — it lives on your devices, in your password manager, or on a hardware authenticator. The Nuri co-signer is an operator we run: it verifies WebAuthn assertions before it contributes its signature share. The arkade server is the Lightning operator that makes off-chain sends possible. The critical detail is how the co-signer decides to sign. It does not trust an API key or a session cookie. It requires a fresh WebAuthn assertion — a real passkey ceremony with user verification — for every co-signing action. That is what makes the whole system phishing-proof in depth: even if an attacker extracts a valid PRF output, they hold a deterministic key seed, but spending still requires the co-signer, and the co-signer only acts on a fresh passkey assertion from the user. A leaked PRF alone cannot move money while the co-signer is in the script. And once the co-signer has decayed, the attacker's window is the same CSV delay that protects everyone — a delay the user can also use to reach their funds first. This is also the no-single-point-of-failure core: the operator, the arkade server, and even the domain are all mortal, all replaceable, all outside the critical path after their decay. The design extends naturally: a hardware wallet can be added as a backup co-signer for a 2-of-3 recovery option, and PRF-capable hardware authenticators — YubiKeys with PRF support, or our biometric NFC passkey smartcard — can hold the user key in silicon. More keys, more decay rungs, same rule: thresholds only ever shrink toward the user. **Basically,** Every co-signing action needs a fresh passkey tap. A stolen PRF alone moves nothing while the co-signer lives. ## What this means when the lights go out Run the full scenario. It is 2040. Nuri GmbH was dissolved in 2031. Nobody renewed the domain. You still have your passkey in your password manager, your phone, or a hardware authenticator. On an offline computer, you run the open-source recovery tool. It recreates the nuri.com RP context locally — hosts entry, local CA, local server. Your passkey — the same credential, domain-bound to a string that no longer resolves — evaluates the PRF. Deterministic derivation produces your Bitcoin and Ethereum keys. You pull the encrypted Nostr backups, reconstruct your VTXOs, calculate each decay rung's unlock height, and sweep: L1 outputs where the CSV has matured, Arkade outputs where the ladder has finished decaying, anything still timelocked as soon as it matures. At no point in this story did anyone at a company have to press a button, approve a ticket, or keep a database alive. The rescue was designed in on day one. **Basically,** Company gone, domain gone, servers gone. Your passkey, the chain and the backups still meet. ## Why we keep saying rescue, not export An export button is a promise about your future behavior. A rescue path is a property of the system. Privy-style export is a real escape hatch — but it is an escape hatch you must remember to take, while the door is still open. Nuri's answer inverts the order. The key material lives with the user's passkey. The decay schedule lives in the chain. The recovery state lives on Nostr. The company's job is to be useful while it exists — not to be load-bearing after it doesn't. This is also why the Arkade architecture matters beyond Nuri. Agents that hold money need the same property: an operator that can make money fast while it exists, and mathematically cannot matter once its time is up. A wallet whose co-signers decay is a wallet an agent can inherit without inheriting a dependency. Self-custody that requires the custodian's continued existence is just custody with extra steps. We built Nuri so that even our absence is survivable. That is not a marketing line; it is testable, today, with tools we published and a scenario you can rehearse in an afternoon. Recovery still needs the original passkey, an authenticator that supports PRF, and a reviewed copy of the tool. And honesty about the trade-off: after the co-signers decay, their protections decay with them. Self-custody means owning that. The single most important sentence in this article is this one: check whether your wallet's passkey carries a secret, or just a signature. **Basically,** An export button is a promise about your future behavior. A rescue path is a property of the system. ## Founder, Nuri > “The co-signers decay. The user key never changes. That is the whole design.” > > — Emin Mahrt ## This post is also available in - [The passkey that outlives the company](https://nuri.com/blog/how-nuri-wallets-survive-without-nuri) (en) - [Der Passkey, der das Unternehmen überlebt](https://nuri.com/de/blog/how-nuri-wallets-survive-without-nuri) (de) - [The passkey that outlives the company](https://nuri.com/it/blog/how-nuri-wallets-survive-without-nuri) (it) --- --- title: "Costruire Nuri per i giorni in cui qualcosa si rompe" description: "Cosa ha imparato Nuri da due settimane di problemi reali e come stiamo rendendo l'app più chiara, resiliente e facile da gestire per l'assistenza." lang: "it" type: "blog-post" author: "Emin Mahrt" datePublished: "2026-08-11" dateModified: "2026-08-11" canonical: "https://nuri.com/it/blog/building-nuri-for-the-days-when-something-breaks" tags: ["Nuri","affidabilità del prodotto","Bitcoin","Lightning","percorsi di pagamento"] --- # Costruire Nuri per i giorni in cui qualcosa si rompe **TL;DR:** Se un canale di pagamento smette di funzionare, non dovrebbe sembrare che sia rotta tutta l'app. Nuri ha bisogno di indicazioni chiare sullo stato, alternative che funzionino e un'assistenza che sappia cosa è disponibile in quel preciso momento. Ci muoveremo più velocemente senza fingere che i problemi smetteranno di capitare e mostreremo più chiaramente cosa continua a funzionare quando succedono. - **Di:** Emin Mahrt - **Pubblicato:** 2026-08-11 ## Queste due settimane non sono andate secondo i piani Avevamo un piano per le ultime due settimane. Poi sono arrivate quelle due settimane. Volevamo usare quel tempo per perfezionare l'app, avviare la distribuzione e coinvolgere più utenti. Invece, ne abbiamo passato buona parte a reagire a problemi che riguardavano Bitcoin, Lightning e diversi canali di pagamento. A dirla tutta, è stato estenuante. Non perché ogni problema fosse catastrofico. Siamo ancora all'inizio e il numero di utenti coinvolti era gestibile. Ma sembrava di essere in Ricomincio da capo: sistemavi una cosa, ne cambiava un'altra, poi un'alternativa smetteva di funzionare e subito dopo qualcos'altro richiedeva attenzione. La mia prima reazione è stata la frustrazione. Ripensandoci, però, la lezione più importante è diventata evidente. Succederà di nuovo. > “I must say I feel exhausted after these two weeks.” > > — Emin Mahrt · Dalla registrazione originale **In pratica,** Avevamo pianificato uno sprint normale di due settimane. Invece, abbiamo passato due settimane a spegnere incendi. ## Questo è l'ambiente in cui costruiamo Nuri collega molti sistemi finanziari diversi. Servizi bancari, carte, Bitcoin, Lightning, valute locali e circuiti di pagamento si comportano tutti in modo diverso. Alcune parti sono nostre. Altre ci collegano a infrastrutture esterne. Ogni parte può cambiare, entrare in manutenzione o smettere temporaneamente di funzionare. Tutti in questo settore lavorano su sistemi complessi, noi compresi. Cambiamenti e interruzioni fanno parte di questo lavoro. Abbiamo scelto di riunire questi sistemi, quindi siamo noi i responsabili dell'esperienza degli utenti quando qualcosa cambia. Il nostro compito non è fingere che ogni ingranaggio funzionerà perfettamente per sempre. Il nostro compito è fare in modo che Nuri resti utile quando uno di quegli ingranaggi non funziona. > “if you're building a puzzle with many moving parts, of course, those moving parts are going to work, going to not work, going to break.” > > — Emin Mahrt · Dalla registrazione originale **In pratica,** A volte qualcosa smetterà di funzionare. Quando succede, la nostra app deve comunque avere senso. ## Un'alternativa deve funzionare quando serve Il momento più frustrante non è stato quando una funzionalità ha smesso di funzionare. Può succedere. La parte frustrante è stata scoprire che un'alternativa non era più disponibile proprio nella situazione in cui gli utenti ne avevano bisogno. Questo ci ha insegnato una cosa molto semplice: un'alternativa che funziona solo in condizioni normali non è poi una grande alternativa. Dobbiamo continuare a eliminare i singoli punti di guasto ovunque sia possibile. A volte significa aggiungere un altro canale. A volte significa permettere agli utenti di recuperare in autonomia o di uscire senza dipendere da noi. A volte significa semplicemente separare due funzionalità che sembrano simili, ma smettono di funzionare per ragioni completamente diverse. Bitcoin e Bitcoin Lightning sono un buon esempio. A molti utenti potrebbero sembrare due versioni della stessa cosa. Tecnicamente sono sistemi molto diversi, con compromessi diversi e modi diversi di smettere di funzionare. Presentarli come un unico saldo perfettamente integrato può sembrare più pulito, ma significa anche che un problema di Lightning può far sembrare rotta l'intera esperienza Bitcoin. Per ora, tenerli separati è più onesto e più utile. Bitcoin può continuare a funzionare quando Lightning non è disponibile. Lightning può mostrare chiaramente il proprio stato attuale. Gli utenti non devono capire il motivo tecnico. Devono solo sapere cosa funziona, cosa non funziona e come possono procedere. **In pratica,** Bitcoin e Lightning non dovrebbero mandarsi in tilt a vicenda. Un'alternativa deve essere reale, non decorativa. ## Abbiamo cercato troppo di nascondere gli ingranaggi Per molto tempo ho voluto che Nuri nascondesse tutta la complessità. In molti casi è ancora questo l'obiettivo. Nessuno dovrebbe dover capire nodi, liquidità, instradamento dei pagamenti o fornitori di infrastruttura per inviare denaro. Ma nascondere la complessità non può significare nascondere la realtà. Se un canale è temporaneamente non disponibile, l'app dovrebbe dirlo. Se qualcosa è in manutenzione, l'app dovrebbe mostrarlo chiaramente. Se una valuta è supportata come canale di pagamento ma non come saldo, l'interfaccia dovrebbe rendere chiara questa differenza. In passato abbiamo cercato di evitare messaggi come «temporaneamente non disponibile». Sembravano tecnici e poco accoglienti. A ripensarci, questo ha creato un'esperienza peggiore. Un pulsante che sembra disponibile ma dà errore dopo averlo premuto è molto più frustrante di un pulsante disattivato accompagnato da una spiegazione chiara. Questo cambia il modo in cui pensiamo alla schermata principale di Nuri. Non dovrebbe mostrare soltanto dove si trova il tuo denaro. Dovrebbe mostrare anche cosa puoi farci in quel momento. Potresti avere denaro in euro, ma diversi modi di usare quegli euro: pagamenti con carta, bonifici bancari o conversione in un'altra valuta. Alcuni circuiti di pagamento non hanno affatto bisogno di un saldo dedicato. Sono semplicemente un altro modo per inviare o ricevere denaro. Allo stesso tempo, non dobbiamo mai mostrare due volte lo stesso denaro. Se la tua carta e il tuo conto bancario usano lo stesso saldo sottostante, mostrare quell'importo sotto entrambi può farti pensare di avere il doppio del denaro che possiedi davvero. La prima versione potrebbe non essere bella, ma deve essere chiara. **In pratica,** Non nascondere un canale fuori servizio dietro un pulsante che sembra funzionare. Di' alle persone cosa funziona prima che lo tocchino. ## L'assistenza dovrebbe sapere ciò che sa l'app Questa settimana ha cambiato anche il mio modo di pensare all'assistenza. L'assistenza non dovrebbe essere un sistema separato con un elenco obsoleto di funzionalità. Dovrebbe conoscere Nuri così come la vede l'utente. Se un canale non è disponibile, l'assistenza dovrebbe saperlo subito. Se una funzionalità è stata disabilitata, il nostro agente di assistenza non dovrebbe consigliarla. Se qualcuno chiede perché non riesce a pagare una fattura Lightning, l'assistenza dovrebbe poter vedere se il canale funziona, spiegare la situazione attuale e suggerire un'alternativa disponibile. È qui che il nostro lavoro su MCP diventa concreto. MCP suona tecnico, ma l'idea di base è semplice: vogliamo che ogni funzionalità di Nuri sia disponibile attraverso un'interfaccia pulita che sia l'app sia gli agenti possano capire. Il Nuri MCP dovrebbe contenere le funzionalità che sono davvero disponibili in Nuri. Quelle sperimentali dovrebbero stare altrove finché non saranno pronte. In questo momento, questi confini non sono sempre netti. Abbiamo esperimenti, funzionalità dell'app e servizi indipendenti troppo mescolati tra loro. Aveva senso mentre ci muovevamo velocemente e testavamo idee. Ne ha meno ora che vogliamo che gli agenti assistano utenti reali. Quando qualcosa diventa disponibile in Nuri, l'agente di assistenza dovrebbe capirlo. Quando qualcosa scompare dall'app, dovrebbe scomparire anche dalle azioni a disposizione dell'agente. App, assistenza e infrastruttura dovrebbero descrivere la stessa realtà. **In pratica,** Il nostro agente di assistenza non dovrebbe mai indirizzarti verso una funzionalità che in quel momento non è disponibile. ## Non stiamo aspettando la perfezione Possiamo passare mesi a progettare l'alternativa perfetta per ogni possibile guasto. Poi lanciamo e scopriamo che gli utenti sono confusi da qualcosa di completamente diverso. Abbiamo bisogno di utenti reali. Abbiamo bisogno che le persone aprano Nuri, provino a usarla e ci dicano dove si bloccano. Non perché abbiano una teoria sulla nostra interfaccia, ma perché volevano fare qualcosa e non ci sono riuscite. Quel feedback è più utile di dieci opinioni interne. Un esempio è emerso quando abbiamo parlato di separare carte e bonifici bancari. Dal punto di vista tecnico, raggrupparli può sembrare logico perché potrebbero condividere un saldo. Ma gli utenti continuavano a chiedere dove fosse il loro IBAN. Aprivano la schermata della carta, vedevano una carta e smettevano di cercare. Non si aspettavano che i bonifici bancari fossero nascosti lì. Gli utenti non hanno bisogno di sapere perché in origine avevamo raggruppato due cose. Sanno soltanto che non riuscivano a trovare ciò di cui avevano bisogno. Quindi ci muoveremo più velocemente con schermate e flussi ancora grezzi. Poi osserveremo dove le persone incontrano difficoltà e miglioreremo quelle parti. Alcune cose non saranno perfette e alcuni esperimenti falliranno. Un'idea può avere senso in una riunione e sembrare sbagliata nel momento in cui qualcuno prova a usarla. Preferiamo scoprirlo adesso. > “it's okay that things break it's okay that they don't look good we just react on it and basically make the best out of it” > > — Emin Mahrt · Dalla registrazione originale **In pratica,** Mettere Nuri nelle mani di più persone, vedere dove incontrano difficoltà e risolvere prima i problemi reali. ## Cosa faremo adesso Continueremo a migliorare l'app, ma cominceremo anche a farla usare a più persone. La distribuzione non può restare il compito che rimandiamo ogni volta che qualcosa si rompe. Stiamo separando le funzionalità affinché un canale non disponibile non danneggi il resto dell'esperienza, aggiungendo informazioni più chiare sullo stato e mettendo ordine nel Nuri MCP perché rispecchi l'app. L'assistenza dovrebbe sapere quali funzionalità sono disponibili. Un monitoraggio migliore ci aiuterà a individuare i problemi prima che si trasformino in lunghe conversazioni con l'assistenza. Per Lightning, valuteremo le opzioni disponibili senza introdurre in fretta un'altra dipendenza permanente. Ci sono diversi passi possibili. Possiamo supportare swap regolari tra Bitcoin e Lightning, studiarne versioni più veloci in seguito, valutare altri approcci non-custodial o continuare a migliorare la nostra integrazione attuale quando le funzionalità necessarie diventeranno disponibili. Non dobbiamo prendere ogni decisione oggi. Bitcoin può restare utile senza fingere che ogni caso d'uso di Lightning sia già risolto. Lightning è difficile e il settore nel suo complesso sta ancora affrontando alcuni problemi complessi. Preferiamo essere onesti su questo, anziché imporre un'esperienza che sembra perfettamente integrata ma diventa confusa quando qualcosa cambia. Lo stesso principio vale anche oltre Bitcoin. Se un canale di pagamento in valuta locale entra in manutenzione, il resto di Nuri dovrebbe continuare a funzionare. Se un servizio di carte non è disponibile, gli utenti dovrebbero comunque trovare le opzioni per i bonifici bancari. Se una funzionalità è sperimentale, non dovrebbe comparire senza spiegazioni come se fosse già pronta per la produzione. **In pratica,** Mostrare cosa funziona, mantenere attive le alternative, allineare l'assistenza all'app e far conoscere Nuri a più persone. ## Dalla registrazione originale > “Ci saranno problemi, ma una parte rotta non dovrebbe bloccare il resto di Nuri.” > > — Emin Mahrt ## Questo articolo è disponibile anche in - [Building Nuri for the days when something breaks](https://nuri.com/blog/building-nuri-for-the-days-when-something-breaks) (en) - [Nuri für die Tage bauen, an denen etwas kaputtgeht](https://nuri.com/de/blog/building-nuri-for-the-days-when-something-breaks) (de) - [Construir Nuri para los días en que algo falla](https://nuri.com/es/blog/building-nuri-for-the-days-when-something-breaks) (es) --- --- title: "Cosa dice di Nuri la lettera agli investitori di Stripe" description: "La lettera agli investitori di Stripe descrive l'economia degli agenti. Nuri vede lo stesso futuro, costruito su standard aperti, autocustodia e indipendenza dell'utente." lang: "it" type: "blog-post" author: "Emin Mahrt" datePublished: "2026-08-20" dateModified: "2026-08-20" canonical: "https://nuri.com/it/blog/what-stripes-investor-letter-means-for-nuri" tags: ["Nuri","Stripe","finanza agentica","stablecoin","MCP","non-custodial"] --- # Cosa dice di Nuri la lettera agli investitori di Stripe **TL;DR:** Il 19 agosto Stripe ha detto ai suoi investitori che gli agenti di IA stanno diventando attori economici e che il denaro entrerà nativamente nell'economia dell'IA. Abbiamo letto la lettera e riconosciuto il futuro per cui stiamo costruendo. La tesi è la stessa. L'approccio è diverso: Stripe sta integrando una parte sempre maggiore dello stack in un'unica piattaforma. Nuri si basa su standard aperti, autocustodia e indipendenza dalla stessa Nuri. Gli agenti possono possedere denaro, agire in autonomia o lavorare per una persona entro limiti chiari. E quel denaro non comprende soltanto stablecoin e valuta fiat. Comprende bitcoin, Lightning e qualsiasi altra rete aperta arrivi in futuro. - **Autore:** Emin Mahrt - **Pubblicato:** 2026-08-20 ## Cosa ha scritto davvero Stripe La lettera merita di essere letta per intero. Ecco la versione breve. Stripe ha annunciato OpenRouter come la sua più grande acquisizione di sempre. Le aziende non hanno comunicato il prezzo. Il New York Times parla di 7,5 miliardi di dollari, Reuters di poco più di 8 miliardi. Solo tre mesi prima OpenRouter aveva una valutazione di 1,3 miliardi di dollari. Prima di OpenRouter c'erano Bridge, Privy e Metronome. L'acquisizione di Bridge è costata 1,1 miliardi di dollari. I termini ufficiali dell'acquisizione di Metronome non sono stati resi noti, ma le fonti collocano l'operazione intorno a 1 miliardo di dollari. Anche il prezzo di acquisto di Privy non è stato comunicato; l'ultima valutazione riportata prima dell'acquisizione era di 230 milioni di dollari. Si arriva così per Stripe a un valore riportato delle operazioni tra 9,6 e 10,1 miliardi di dollari per OpenRouter, Bridge e Metronome, più quanto pagato per Privy. Il calcolo non include il costo di costruzione del resto dello stack. Hanno scritto: «Abbiamo deciso che il 1° gennaio segnava l'inizio della singolarità e da allora operiamo su questa base». Riportano ricavi netti nel primo semestre in crescita del 41% su base annua, free cash flow in crescita del 43%, l'88% della Forbes AI 50 su Stripe e il consumo di token su OpenRouter in aumento a un tasso composto del 9% a settimana. La frase centrale è questa: «costruire infrastrutture economiche per internet equivale in gran parte a costruire infrastrutture economiche per l'IA». E indicano i componenti che stanno costruendo: Stripe Projects e Directory per l'onboarding e la scoperta degli agenti, Metronome per l'utilizzo, Bridge e una Agentic Commerce Suite per i pagamenti, Tempo come propria blockchain per gli agenti, MPP come protocollo per i pagamenti tra macchine, Privy per i wallet e Open Standard, la loro stablecoin. Hanno scritto anche qualcosa su cui continuo a tornare: «C'è il timore che l'IA porti alla disoccupazione o alla centralizzazione; forse a entrambe. Riteniamo importante che l'adozione dell'IA rafforzi l'autonomia umana». Concordo con ogni parola della diagnosi. Non concordo con la cura. **In pratica,** Stripe ha chiamato il 1° gennaio «la singolarità», dopo aver impegnato oltre 9,6 miliardi di dollari nello stack che la circonda. ## La parte in cui descrivono il nostro prodotto Prendi l'elenco delle primitive di Stripe e mettilo accanto a Nuri. Stripe ora possiede Privy. Privy definisce i wallet degli utenti non-custodial e offre l'esportazione della chiave privata, che costituisce una vera via d'uscita. Ma prima dell'esportazione, la firma dipende ancora dall'infrastruttura di Privy: una quota cifrata della chiave è conservata da Privy e l'altra può essere decifrata e combinata solo all'interno del suo AWS Nitro Enclave. Se quell'infrastruttura sparisce prima che l'utente esporti la chiave, il wallet non dispone di un percorso di recupero locale. Con Nuri, WebAuthn PRF deriva localmente dalla passkey la chiave dell'utente. Nei modelli di wallet multisig è la chiave dell'utente, non ogni chiave firmataria. Il percorso di cofirma è limitato nel tempo tramite CSV, quindi dopo una finestra fissa di blocchi l'utente conserva un percorso di recupero indipendente. Una chiave di backup separata, per esempio un hardware wallet, può aggiungere un'opzione di recupero 2 su 3. Lo stesso principio può applicarsi agli account EVM Safe usati dagli agenti. L'utente non deve ricordarsi di premere un pulsante di esportazione prima che Nuri sparisca. Non è una differenza cosmetica. È indipendenza incorporata nel wallet. Nuri riunisce valuta fiat e crypto in un unico wallet, ma è pensata per le persone e i loro agenti, non soltanto per le piattaforme: carta e IBAN, bitcoin onchain e via Lightning, stablecoin e le reti aperte che li collegano. Un agente può operare un wallet di proprietà dell'utente entro limiti precisi oppure possederne uno e agire in autonomia. Entrambe le modalità contano. La domanda importante non è dove venga applicata una regola di budget in una specifica implementazione. È se l'autorità sia reale. Un agente ha bisogno di libertà sufficiente per agire, spendere, guadagnare e completare il lavoro senza chiedere a una persona conferma per ogni centesimo. Il proprietario deve comunque poter definire i confini e revocare l'accesso delegato. Nuri è AI-native al di sotto dell'interfaccia. Il sistema può essere gestito tramite CLI e MCP, mentre le operazioni onchain restano lato client quando il modello del wallet lo richiede. Il frontend può essere l'app web, l'app iOS, l'agente dell'utente o l'agente Nuri su WhatsApp. Ogni capacità importante deve funzionare senza dare per scontato che una persona debba cliccare su una serie di schermate. Non stiamo costruendo una chain e non stiamo emettendo denaro. Nuri è progettata per essere indipendente da chain, protocolli e servizi finanziari, anche sul versante fiat. Open source e standard aperti contano perché l'utente non dovrebbe mai dipendere da una sola azienda, compresa la nostra, per continuare a usare il proprio denaro. **In pratica,** Se il wallet richiede un pulsante di esportazione prima che il fornitore sparisca, non sei indipendente. ## Stessa singolarità, risposta diversa Ecco il modo onesto di dirlo: crediamo in ciò in cui crede Stripe. Gli agenti deterranno denaro, lavoreranno entro budget, pagheranno servizi, si abboneranno, regoleranno pagamenti e guadagneranno. Le stablecoin ne trasporteranno una parte importante, ma non sono tutto il futuro. Valuta fiat, bitcoin e Lightning fanno parte dello stesso quadro. La risposta di Stripe è l'integrazione verticale: routing dell'intelligenza, fatturazione, wallet, una chain, una stablecoin e una directory. È una macchina impressionante e funzionerà per molte aziende. Privy rende la questione più sfumata di un semplice confronto tra custodial e non-custodial; supporta anche wallet non-custodial ed esportabili. Il problema è la concentrazione. Una parte sempre maggiore dell'economia degli agenti può nascere, muoversi e regolarsi dentro un unico universo commerciale. Autonomia umana, finché Stripe è d'accordo. La risposta di Nuri è comporre anziché possedere. Autocustodia dove la sceglie l'utente. Proprietà autonoma dove serve all'agente. Open source dove ne dipende l'indipendenza. Standard aperti, così un altro servizio può sostituirci senza sostituire la vita finanziaria dell'utente. Indipendente da chain e servizi, anche sul versante fiat. Non è uno scontro diretto con Stripe. Loro servono piattaforme che costruiscono per gli agenti su scala enorme. Noi partiamo dalla persona e dall'agente che lavora per lei, oppure da un agente autonomo che ha bisogno di una vera identità finanziaria propria. La tesi è la stessa. L'architettura e gli incentivi no. **In pratica,** L'autonomia umana, finché Stripe è d'accordo, non è autonomia umana. ## Agenti con un vero conto bancario Questa è la parte che mi entusiasma di più. Un agente dovrebbe poter possedere un wallet e operare in autonomia. Dovrebbe anche poter agire attraverso il wallet di una persona con autorità delegata. Sono rapporti diversi e Nuri deve supportarli entrambi. Quando il wallet appartiene all'utente, la passkey e le chiavi restano con l'utente. L'agente riceve soltanto l'autorità necessaria. Quando un wallet appartiene a un agente autonomo, l'agente deve poter detenere denaro, guadagnare, spendere e regolare pagamenti senza attendere ogni volta un clic umano. L'autonomia che si ferma alla schermata di pagamento non è autonomia. Il versante fiat è ciò che trasforma una demo crypto in un prodotto finanziario. Nuri collega gli agenti a carte, IBAN e bonifici bancari, oltre che a bitcoin, Lightning e stablecoin. Un agente potrebbe dover pagare un fornitore con un bonifico, mantenere fondi disponibili su una carta, regolare un pagamento via Lightning o pagare un'API con un protocollo aperto per pagamenti tra macchine. Non sono mondi in competizione. Sono il mondo in cui il denaro vive già. L'architettura è indipendente da chain e servizi. Le capacità sono esposte tramite MCP e CLI, non rinchiuse in un unico frontend. L'interfaccia può essere la nostra app web o iOS, l'agente dell'utente o l'agente Nuri su WhatsApp. Al backend non dovrebbe importare quale interfaccia ha inviato la richiesta, ma soltanto se quella richiesta ha l'autorità per agire. **In pratica,** Un agente può essere autonomo su qualsiasi rete. Nuri collega quell'autonomia a Bitcoin, Lightning e servizi bancari. ## La verifica segue il bisogno, non l'ideologia Una scelta progettuale all'inizio spiazza, poi diventa ovvia: Nuri serve sia il mercato retail sia le istituzioni, e la verifica segue il bisogno. Vuoi un wallet in autocustodia per bitcoin e stablecoin, senza account e senza moduli? Esiste, è live e funziona in tutto il mondo. Vuoi il quadro completo con carta, IBAN e servizi bancari? Allora si applica il KYC, perché è ciò che richiede il lato regolamentato, e i nostri partner lo gestiscono correttamente. Un'azienda vuole lo stesso con KYB e controlli? Stesso framework, stessi strumenti, diverso livello di verifica. Non è evitare di scegliere. È l'unica architettura che può davvero funzionare in tutto il mondo. Gran parte della popolazione mondiale non può superare un KYC europeo e non dovrebbe essere costretta a farlo soltanto per detenere il proprio denaro. E gli utenti europei che vogliono un IBAN non dovrebbero dover lasciare il prodotto per ottenerlo. Un solo wallet, una sola passkey, e l'utente decide quanto addentrarsi nel mondo regolamentato. Gli agenti ereditano esattamente il livello della persona. **In pratica,** Il KYC dovrebbe aprire l'accesso ai servizi bancari, non decidere chi può detenere denaro. ## Cinque persone e una macchina Stripe ha migliaia di dipendenti. Noi siamo cinque. È possibile soltanto perché Nuri è AI-native fino alle fondamenta. Il backend è costruito per essere gestito tramite CLI e MCP. Le operazioni onchain avvengono lato client quando la proprietà lo richiede. Il frontend è intercambiabile: web, iOS, l'agente dell'utente o l'agente Nuri su WhatsApp. Un'app grafica è un'interfaccia, non il confine del prodotto. Il supporto funziona tramite un cockpit di agenti, con persone che gestiscono i casi in cui serve una persona. Contenuti, video di prodotto, monitoraggio e distribuzione passano sempre più spesso attraverso pipeline di agenti. Il sito non è soltanto leggibile dagli agenti, è anche utilizzabile da loro. Per questo l'agent readiness conta per noi più di un premio di design. Non fingerò che sia tutto semplice. Costruire un'azienda in questo modo significa fare ogni giorno il debug del proprio futuro. Ma ogni affermazione che facciamo sull'economia degli agenti la testiamo prima su noi stessi. Siamo il nostro primo cliente. **In pratica,** Nuri non ha un unico frontend. App, WhatsApp e agenti usano tutti lo stesso backend. ## Dove porta tutto questo La lettera di Stripe si chiude ringraziando gli investitori e promettendo intensità. Ci sta. Ecco la nostra. Il wallet continua a crescere come ponte tra valuta fiat e crypto per le persone, e diventa lo stesso ponte per i loro agenti. Bitcoin, Lightning, stablecoin e servizi bancari dovrebbero sembrare parti di un'unica vita finanziaria, non prodotti separati in mano a custodi diversi. La più grande azienda dei pagamenti ha appena dichiarato che l'infrastruttura economica di internet e quella dell'IA stanno diventando la stessa cosa. Cloudflare sta costruendo identità, wallet e infrastruttura di pagamento intorno alla sua rete. Circle sta costruendo wallet autonomi intorno alle stablecoin. PayBox sta collegando gli agenti a wallet, exchange e carte esistenti. Sono segnali forti che il mercato esiste. Il rischio non è che queste aziende stiano costruendo. È giusto che lo facciano. Il rischio è che identità, intelligenza, wallet, reti di pagamento e regolamento finiscano in pochi cloud integrati verticalmente. Open source e standard aperti permettono al resto di noi di mantenere il sistema componibile. Autocustodia ed esportabilità permettono agli utenti di restare indipendenti dalle aziende che li servono. Una direzione che vogliamo esplorare è una collaborazione con Nous Research su Hermes. È un obiettivo, non una partnership annunciata. Hermes è open source, gira in locale o in ambienti cloud persistenti e può collegarsi a centinaia di modelli tramite provider diversi o endpoint personalizzati. Supporta già routing tra provider, fallback, strumenti, MCP e canali di messaggistica. Insieme a Nuri, l'idea diventa semplice: agenti a portata di clic. Scegli un modello, avvia un agente in locale o nel cloud, assegnagli un wallet o un'autorità delegata e lascialo operare nell'universo Nuri senza vincolare l'utente a un solo modello, un solo cloud o un solo fornitore finanziario. È il futuro verso cui vogliamo costruire: accesso diretto a molti LLM, routing tra modelli, agenti cloud persistenti e strumenti finanziari in un unico sistema open source e non-custodial. L'agente può appartenere a una persona o esistere per conto proprio. L'interfaccia può essere un'app, WhatsApp o nessuna interfaccia grafica. Ciò che conta è che intelligenza e denaro possano incontrarsi senza che nessuno dei due diventi un nuovo punto di dipendenza. Nuri non deve possedere ogni livello. Deve collegare i livelli senza diventare il motivo per cui un utente vi resta intrappolato. È un'ambizione diversa: non diventare il sistema operativo finanziario da cui nessuno può uscire, ma costruirne uno che continui a funzionare anche quando l'utente lo lascia. **In pratica,** Stripe compra lo stack. Nuri ne costruisce uno che gli utenti possono lasciare. ## Fondatore, Nuri > “La scommessa di Stripe è che lo stack resti nelle loro mani. La nostra è che le chiavi restino nelle tue.” > > — Emin Mahrt ## Questo articolo è disponibile anche in - [What Stripe's investor letter says about Nuri](https://nuri.com/blog/what-stripes-investor-letter-means-for-nuri) (en) - [Was Stripes Investorenbrief über Nuri sagt](https://nuri.com/de/blog/what-stripes-investor-letter-means-for-nuri) (de) - [Qué dice de Nuri la carta a inversores de Stripe](https://nuri.com/es/blog/what-stripes-investor-letter-means-for-nuri) (es) --- --- title: "The passkey that outlives the company" description: "How Nuri wallets recover without Nuri: a passkey that carries its own secret, Bitcoin scripts with a built-in exit, and co-signers that decay on chain." lang: "it" type: "blog-post" author: "Emin Mahrt" datePublished: "2026-09-01" dateModified: "2026-09-01" canonical: "https://nuri.com/it/blog/how-nuri-wallets-survive-without-nuri" tags: ["Nuri","Bitcoin","Lightning","passkeys","self-custody","recovery"] --- # The passkey that outlives the company **TL;DR:** Most wallets promise self-custody. Few survive the question that actually matters: what happens to your money when the company that built the wallet is gone? This article walks through the full Nuri design: a passkey whose PRF extension carries the wallet secret itself, Bitcoin outputs whose 2-of-2 co-signing decays to 1-of-1 through a CSV timelock, and an Arkade Lightning layer whose three-key ladder decays from co-signers to the user key alone. Recovery works offline, without nuri.com, without servers, without an export button. Co-signers are passkey-gated, phishing-resistant, and mortal by design. The only immortal key is yours. - **Author:** Emin Mahrt - **Published:** 2026-09-01 ## Why a normal passkey is not enough A passkey is a beautiful authentication primitive. The private signing key never leaves the authenticator. Websites only ever see signatures. Phishing dies; password databases stop mattering. But as a wallet primitive, a normal passkey is a dead end. It can prove you are you, again and again, forever. It cannot hand you a secret. And a wallet needs a secret — a number from which your Bitcoin and Ethereum keys are derived. So most passkey wallets end up in one of two camps. The server holds the wallet key and the passkey is just a fancy login: custody with better UX. Or MPC and enclave models split the key across infrastructure — genuinely better, but reconstruction typically requires that infrastructure to be alive, and the escape hatch is export: if you remember to use it before the provider disappears. Both camps share a quiet assumption: the domain you log in to outlives your need for the key. There is also a second, less discussed trap. Passkeys are domain-bound. Your credential works for the RP ID it was created for — that is exactly what stops a random website from phishing your wallet login. But domain binding is protection for the company's lifetime, with no story for after. If your wallet key is entangled with a provider's ceremony and that provider's domain goes dark, your passkey still exists, still works — it just has nobody left to talk to. The industry treats that as an edge case. For money, it is the case. **Basically,** A passkey proves who you are. A wallet needs a secret. The question is who holds it: you, or a company you hope stays online. ## The passkey that carries its own secret Nuri uses the WebAuthn PRF extension. PRF lets the wallet ask the authenticator a fixed question and receive a stable, pseudorandom answer — tied to that credential, reproducible forever, and never exposed to any server. The RP ID is nuri.com, the PRF input is the fixed string "nuri-prf-salt-v1", and the output is 32 secret bytes, produced locally after user verification. Those 32 bytes are the seed. From there, everything is public, deterministic math: HKDF-SHA256 with domain separation into BIP32 paths m/86'/0'/0'/0/0 for Bitcoin Taproot and m/44'/60'/0'/0/0 for Ethereum. The derivation code and constants are public — the local-nuri-prf-passkey-recovery-tool on GitHub is exactly that code, packaged for the worst day. One distinction carries most of the security model. A passkey ceremony produces two things: the WebAuthn assertion — a public proof of user presence, origin, RP ID and intent — and the PRF output — the private, deterministic secret behind your wallet keys. The Nuri co-signer receives assertions to verify that you approved a co-signing action. It never receives the PRF output. The secret that creates your signature never travels; only the proof that you approved the server's signature does. Co-signing and recovery are separate ceremonies on purpose. The server can help you spend on a Tuesday and be irrelevant to your recovery a decade later. **Basically,** The server gets your approval, never your secret. It can help you spend on a Tuesday and be irrelevant to your recovery ten years later. ## But the passkey is bound to nuri.com Yes. The passkey is cryptographically bound to the RP ID nuri.com. We consider that a feature — it is what stops any random website from asking your passkey for money. But here is the part that took real design work: the RP ID is a string, not a subscription. WebAuthn checks that the page requesting the ceremony is a secure context whose hostname matches the RP ID. It does not check whether the company still exists, whether DNS resolves, or whether the certificate came from a public authority. Those are browser security properties, not corporate records. So the recovery tool recreates the relying-party context on your own machine. A hosts entry points nuri.com at your loopback address. A locally generated, locally trusted certificate makes the page a secure origin. The local server on https://nuri.com:8443 serves reviewed, committed files — no remote JavaScript, no analytics, no fonts. Your passkey asks for Face ID, Touch ID, or your PIN — the real ceremony, your real credential — and hands the PRF output to a page running entirely on your computer, ideally with the network cable pulled. This is not a WebAuthn bypass. An attacker still needs your passkey and your user verification. It is not a forged public certificate — you trust your own local CA only on your own machine, for one recovery session. It is the recognition that the user who owns the passkey owns the RP context — even when the domain registrar no longer cares. When the ceremony is done, you remove the hosts entry, delete the local CA, and disconnect. The string "nuri.com" in your passkey's memory outlived the company. That was the point. **Basically,** The domain binding protects the passkey from strangers. It does not chain you to the company. The origin can be rebuilt on your own machine. ## The Bitcoin layer: 2-of-2 with a built-in exit Normal spending on Nuri Bitcoin is a 2-of-2 MuSig2 collaboration. Your key — derived from the PRF — and the Nuri co-signer's key aggregate into a single Taproot key. On chain it looks like an ordinary Taproot output: fast, private, one signature. But every output also carries a Miniscript escape hatch, committed into the chain itself. The key path is the MuSig2 aggregate; the script path is your x-only key wrapped in a CSV delay: and_v(v:pk(user), older(csv_blocks)). While Nuri is alive, you and the co-signer spend together through the key path. The co-signer gives you instant, validated spending — spending limits, anomaly checks, a human-shaped safety net. If Nuri is gone, you wait out the CSV delay — CheckSequenceVerify, a relative timelock that starts counting when the output confirms — and then your key alone sweeps the funds through the script path. No permission needed, because the permission was baked into the output when it was created. The math is public: unlock height is confirmation height plus CSV blocks. The recovery tool can build and sign the sweep transaction before unlock for inspection, but refuses to broadcast until the unlock condition is satisfied. This is why we insist on the distinction: the private key is recoverable offline immediately; the onchain script may still require waiting. That is not provider custody — it is a public Bitcoin consensus rule committed into the output. Custody is when someone can refuse you. Nobody can refuse a timelock. **Basically,** The co-signer helps while it lives. After the CSV delay, your key alone sweeps. Waiting is not custody. Nobody can refuse a timelock. ## The decay architecture: co-signers that expire Now the part that is easiest to miss and hardest to build: who is allowed to sign, and how that set shrinks over time. Most multisig wallets treat the signer set as permanent. Revocation means infrastructure: a revocation server, a key-rotation ceremony, an upgrade transaction. Every one of those is a dependency that can fail exactly when you need it most. Nuri treats the signer set as a schedule. Co-signers are not revoked by infrastructure — they decay on chain, on a clock that Bitcoin itself enforces. The user key never rotates. The policy around it just gets simpler as time passes. On Bitcoin L1, the output starts as a 2-of-2: your key and the Nuri co-signer's key aggregate into one MuSig2 Taproot key. Then, at a fixed relative timelock after the output confirms, the co-signer decays out of existence. At time zero the set is user plus co-signer, instant key-path spends. After the CSV delay the set is the user alone, script-path sweep. No transaction removes the co-signer. No revocation server, no key rotation, no migration. The same output simply has two spending conditions, and time selects which one is live. That is what an honest non-custodial 2-of-2 has to mean: not 2-of-2 until we decide otherwise, but 2-of-2, decaying to 1-of-1, on a schedule nobody can pause. **Basically,** Two keys at the start. One key after the delay. Nothing gets revoked by infrastructure — the schedule sits in the script itself. ## The Arkade wallet: three keys, two decays The Lightning layer has one more signer, so the decay ladder has one more rung. Every VTXO — the virtual transaction output that represents your off-chain balance — commits to a Taproot tree with three leaves, each a complete spending condition. Leaf one is the arkade path: the MuSig2 aggregate of user and Nuri co-signer, together with the arkade server. Instant, off-chain, Lightning-fast. Leaf two is aggregate recovery: user and Nuri co-signer alone, after the arkade CSV delay. Leaf three is client recovery: the user key alone, after the sum of both delays. In plain words, the signer set decays like this: at time zero it is user, Nuri co-signer and arkade server — normal Lightning life. After the first delay, the arkade server has decayed: user and co-signer remain. After the full sum of both delays, the Nuri co-signer has decayed too, and only the user key remains. Three properties make this a ladder and not a pile of scripts. First, thresholds only ever shrink toward you: three keys, to two, to one. Never grows, never moves away from the user. Second, each delay is the sum of all delays above it: the client-recovery leaf unlocks at exactly the moment both co-signers have fully decayed, and the app structurally rejects any tree where the user-only path would unlock before the last co-signer's decay completes. While a co-signer is still in the script, it is still protecting you — against fat-fingered amounts, against a compromised client, against you at 3 a.m. Third, the decay is consensus, not infrastructure: at the first delay the arkade server does not get revoked — it simply stops being mentioned by any live spending condition. Even if it is still running, healthy and online, it has no mathematical role in your output anymore. This is what we mean when we say the Arkade wallet is a 2-of-2-of-3. Not three keys, threshold two, forever — but a multisig whose co-signers are mortal by design, and whose only immortal key is yours. **Basically,** Three keys become two, then one. Never the other way. A healthy server past its decay has no say anymore. ## How the operators and co-signers work together It helps to see the cast. Your key is derived from your passkey's PRF output — it lives on your devices, in your password manager, or on a hardware authenticator. The Nuri co-signer is an operator we run: it verifies WebAuthn assertions before it contributes its signature share. The arkade server is the Lightning operator that makes off-chain sends possible. The critical detail is how the co-signer decides to sign. It does not trust an API key or a session cookie. It requires a fresh WebAuthn assertion — a real passkey ceremony with user verification — for every co-signing action. That is what makes the whole system phishing-proof in depth: even if an attacker extracts a valid PRF output, they hold a deterministic key seed, but spending still requires the co-signer, and the co-signer only acts on a fresh passkey assertion from the user. A leaked PRF alone cannot move money while the co-signer is in the script. And once the co-signer has decayed, the attacker's window is the same CSV delay that protects everyone — a delay the user can also use to reach their funds first. This is also the no-single-point-of-failure core: the operator, the arkade server, and even the domain are all mortal, all replaceable, all outside the critical path after their decay. The design extends naturally: a hardware wallet can be added as a backup co-signer for a 2-of-3 recovery option, and PRF-capable hardware authenticators — YubiKeys with PRF support, or our biometric NFC passkey smartcard — can hold the user key in silicon. More keys, more decay rungs, same rule: thresholds only ever shrink toward the user. **Basically,** Every co-signing action needs a fresh passkey tap. A stolen PRF alone moves nothing while the co-signer lives. ## What this means when the lights go out Run the full scenario. It is 2040. Nuri GmbH was dissolved in 2031. Nobody renewed the domain. You still have your passkey in your password manager, your phone, or a hardware authenticator. On an offline computer, you run the open-source recovery tool. It recreates the nuri.com RP context locally — hosts entry, local CA, local server. Your passkey — the same credential, domain-bound to a string that no longer resolves — evaluates the PRF. Deterministic derivation produces your Bitcoin and Ethereum keys. You pull the encrypted Nostr backups, reconstruct your VTXOs, calculate each decay rung's unlock height, and sweep: L1 outputs where the CSV has matured, Arkade outputs where the ladder has finished decaying, anything still timelocked as soon as it matures. At no point in this story did anyone at a company have to press a button, approve a ticket, or keep a database alive. The rescue was designed in on day one. **Basically,** Company gone, domain gone, servers gone. Your passkey, the chain and the backups still meet. ## Why we keep saying rescue, not export An export button is a promise about your future behavior. A rescue path is a property of the system. Privy-style export is a real escape hatch — but it is an escape hatch you must remember to take, while the door is still open. Nuri's answer inverts the order. The key material lives with the user's passkey. The decay schedule lives in the chain. The recovery state lives on Nostr. The company's job is to be useful while it exists — not to be load-bearing after it doesn't. This is also why the Arkade architecture matters beyond Nuri. Agents that hold money need the same property: an operator that can make money fast while it exists, and mathematically cannot matter once its time is up. A wallet whose co-signers decay is a wallet an agent can inherit without inheriting a dependency. Self-custody that requires the custodian's continued existence is just custody with extra steps. We built Nuri so that even our absence is survivable. That is not a marketing line; it is testable, today, with tools we published and a scenario you can rehearse in an afternoon. Recovery still needs the original passkey, an authenticator that supports PRF, and a reviewed copy of the tool. And honesty about the trade-off: after the co-signers decay, their protections decay with them. Self-custody means owning that. The single most important sentence in this article is this one: check whether your wallet's passkey carries a secret, or just a signature. **Basically,** An export button is a promise about your future behavior. A rescue path is a property of the system. ## Founder, Nuri > “The co-signers decay. The user key never changes. That is the whole design.” > > — Emin Mahrt ## This post is also available in - [The passkey that outlives the company](https://nuri.com/blog/how-nuri-wallets-survive-without-nuri) (en) - [Der Passkey, der das Unternehmen überlebt](https://nuri.com/de/blog/how-nuri-wallets-survive-without-nuri) (de) - [The passkey that outlives the company](https://nuri.com/es/blog/how-nuri-wallets-survive-without-nuri) (es) --- --- title: "Broken Money: The Best Money History Book, If You Can Sit Still" lang: "en" type: "review" product: "book-broken-money" rating: 4.6 --- # Broken Money: The Best Money History Book, If You Can Sit Still _Lyn Alden's dense, engineering-first history of money is the most measured Bitcoin-adjacent book in print, but it is not light reading._ **Rating: 4.6 / 5** ## Verdict Broken Money is a rigorous, technology-driven history of money that earns its Bitcoin conclusions instead of assuming them. It is long, dense, and unmistakably sympathetic to Bitcoin, but Alden argues in good faith and names Bitcoin's own weaknesses. For serious readers it is close to essential; for beginners it can be a slog. ## What's good - Frames money through a rare dual lens: monetary policy AND telecommunications/engineering - Walks 5,000 years of monetary history (shells, gold, telegraph, Eurodollar system, Bitcoin) with clear causal logic - Actually addresses Bitcoin's weaknesses and open questions rather than cheerleading - Backed by Alden's macro track record and heavily cited; ~4.6 average across ~3,000 Goodreads ratings - Strong explanation of the ledger/Eurodollar plumbing most retail books skip ## What's not - 538 pages and genuinely dense; the macro sections can overwhelm finance newcomers - Ultimately pro-Bitcoin; readers who reject the 'fiat is broken' premise will find the framing one-sided - Some critics read the 'debasement is theft' thread as a familiar libertarian narrative - Underplays Bitcoin's volatility and regulatory risk relative to the space it gives the thesis - Repetition in the back half; the argument could land in fewer pages **Buy it if:** Readers who want the single most thorough, good-faith history of money and are willing to work for it. **Skip it if:** Someone wanting a short, neutral primer or who rejects the premise that the fiat system is structurally failing. ## Full review Broken Money sets out to explain not just what money is but why the forms we use keep changing. Alden's organizing idea is that money is a technology, and that whoever controls the fastest ledger controls the monetary system. She traces that thread from seashells and Rai stones through gold, the printing press, the telegraph, and finally the Eurodollar system and Bitcoin. The result is a history that treats settlement speed and communication infrastructure as first-class monetary forces, which is a genuinely different lens from most popular economics writing. The book's biggest strength is that it refuses to pick only one discipline. Alden writes from both a policy seat and an engineering seat, and the combination is what reviewers keep singling out: understanding money usually demands background in both economics and computer science, and few authors carry both. The chapters on the Eurodollar system and the mechanics of correspondent banking are the clearest retail-level treatment of that plumbing you are likely to find, and they matter because they explain why the current system behaves the way it does before Bitcoin is ever seriously introduced. To its credit, Broken Money is not a hype document. Alden spends real pages on Bitcoin's known weaknesses and open problems rather than waving them away, which is why even sympathetic reviewers describe her as analytical rather than a cheerleader. That intellectual honesty is the main reason the book reads as credible: the Bitcoin conclusion arrives only after a long historical argument, so it feels earned rather than assumed. The honest criticisms are real, though. This is a long, information-dense book, and its macro passages can overwhelm anyone new to finance. It is also, unmistakably, a book with a thesis: the fiat system is failing and harder money is the fix. Skeptical readers have flagged that the 'currency debasement is a form of theft from ordinary people' framing echoes a familiar libertarian narrative, and that Alden gives Bitcoin's upside far more room than its volatility and regulatory risk. If you disagree with the premise, you will find the framing one-sided. Reception has been strongly positive but not uncritical. The book sat near the top of Amazon's finance categories on release and holds roughly a 4.6 average across thousands of Goodreads ratings, with reviewers repeatedly calling it the best book of its kind they have read. The recurring complaint, even in glowing reviews, is length and repetition: the argument is sometimes restated more often than it needs to be. Bottom line, Broken Money is the most complete and most measured entry in the 'sound money' canon, and it is a meaningfully better starting point than the more polemical titles in the genre. Just go in knowing it is a commitment, and that its neutrality has limits: it is a very good argument for a particular conclusion, not a survey of all sides. **Bottom line:** The most rigorous and fair-minded money-history book in the Bitcoin canon, provided you have the patience for 500 dense pages. ## In the shop [Broken Money — Lyn Alden](https://nuri.com/shop/books/book-broken-money) — $24 ## Sources (11) 1. [Now Available: Broken Money (official author page)](https://www.lynalden.com/broken-money/) — Lyn Alden 2. [Broken Money on Goodreads (rating and reviews)](https://www.goodreads.com/book/show/197566578-broken-money) — Goodreads 3. [Broken Money (hardcover listing, publisher/ISBN)](https://www.amazon.com/Broken-Money-Financial-System-Failing/dp/B0CG83QBJ6) — Amazon 4. [Broken Money (Timestamp Press audiobook edition)](https://www.amazon.com/Broken-Money-Financial-System-Failing/dp/B0CNS7NQLD) — Amazon / Audible 5. [Broken Money book page](https://www.waterstones.com/book/broken-money/lyn-alden/9798988666318) — Waterstones 6. [Broken Money catalog record](https://openlibrary.org/books/OL57486777M/Broken_Money) — Open Library 7. [Broken Money by Lyn Alden Review](https://www.ypa.finance/en/blog/broken-money-lyn-alden-review) — YPA Finance 8. [Book Review: Broken Money by Lyn Alden](https://winchellhouse.com/2025/03/20/book-review-broken-money-by-lyn-alden/) — Winchell House 9. [Book review: Broken Money](https://cjshaver.com/bl0475) — cjshaver.com 10. [Broken Money Book Review (Treasury note risks)](https://www.vantagepointsoftware.com/blog/broken-money-book-review/) — Vantagepoint 11. [Book Review: Broken Money](https://faith-finances.com/blog/2026/6/24/book-review-broken-money) — Faith and Finances Ministry --- --- title: "The Bitcoin Standard: Genre-Defining, and Aging Unevenly" lang: "en" type: "review" product: "book-bitcoin-standard" rating: 3.4 --- # The Bitcoin Standard: Genre-Defining, and Aging Unevenly _The book that made 'hard money' mainstream in Bitcoin is influential, quotable, and heavily biased, and its central scarcity model has not held up._ **Rating: 3.4 / 5** ## Verdict The Bitcoin Standard is the most influential Bitcoin book ever written and a genuinely useful window into how the Bitcoin culture thinks. It is also an Austrian-school polemic that presents contested claims as settled, and its stock-to-flow framing of scarcity directly inspired a price model that later failed badly. Read it as a foundational cultural text, not as neutral economics. ## What's good - Enormously influential; shaped a generation of Bitcoiners and the 'sound money' vocabulary - Clear, forceful writing that makes the scarcity-and-time-preference argument accessible - Good popular history of gold, monetary metals, and the shift off the gold standard - Genuinely useful for understanding the worldview and rhetoric of the Bitcoin community - Published by Wiley with strong sales and staying power; a real reference point for debate ## What's not - Strongly Austrian-school; presents one contested economic tradition as settled truth - The stock-to-flow scarcity framing it popularized underpinned PlanB's price model, which failed (no ~$100k in Dec 2021) - Polemical and dismissive toward Keynesian economics, fiat, and most altcoins/'shitcoins' - Critics (Mises reviewers, David Gerard) flag overreach, cherry-picked history, and weak sourcing - Light on Bitcoin's own technical risks, custody realities, and scaling trade-offs **Buy it if:** Anyone who wants to understand why the Bitcoin community talks the way it does, read critically. **Skip it if:** A reader seeking balanced monetary economics or a technically accurate guide to how Bitcoin works. ## Full review The Bitcoin Standard is, culturally, the most important book Bitcoin has produced. Ammous's core argument is that money competes on 'hardness,' meaning how hard it is to produce more of it, and that gold historically won because of its high stock-to-flow ratio: a large existing supply relative to annual new production. Bitcoin, he argues, is harder still because its issuance is fixed and falls over time. This framing gave the community its vocabulary, from 'sound money' to 'low time preference,' and its influence on Bitcoin discourse is hard to overstate. As a piece of writing it works. Ammous is clear, confident, and quotable, and the popular history of monetary metals and the collapse of the classical gold standard is engaging. Even critics concede the book is effective at what it sets out to do. If your goal is to understand the mindset of the people building and buying Bitcoin, this book is close to required, because so much of that culture is downstream of it. The problems start with what the book presents as settled. It is written squarely from the Austrian school and treats that tradition's conclusions as fact rather than as one contested view among many. Reviewers even in the Austrian-friendly Mises orbit have pushed back on its overreach, and outside critics like David Gerard argue it manufactures theory to defend a rigid gold-standard worldview while dismissing mainstream macroeconomics wholesale. The tone toward fiat, Keynesians, and rival cryptocurrencies is polemical, which makes it persuasive to the converted and easy to distrust for everyone else. The most concrete honesty point is the scarcity model. The book's stock-to-flow framing of why gold and then Bitcoin should be valuable was later turned into an explicit price-prediction model by the pseudonymous analyst PlanB. That model forecast roughly $100k by December 2021; Bitcoin ended that year near $47k, and analysts have since documented how far and how persistently price has diverged from it. Statisticians showed the model's fit relied on autocorrelation and ignored demand entirely. The book did not make that specific prediction, but it supplied the intellectual scaffolding, and that scaffolding has not aged well as a valuation tool. There are also factual and framing complaints throughout, and the book is thin exactly where a shop's customers might want depth: custody, key management, on-chain mechanics, and the real trade-offs of Bitcoin's fixed block space. This is a book about why hard money matters, not a book about how to actually use or secure Bitcoin. So the fair verdict is split. As a movement-defining manifesto and a readable history, The Bitcoin Standard earns its place on the shelf. As economics, it is one-sided advocacy whose signature scarcity model has been discredited as a price predictor. Read it, argue with it, and pair it with something more measured like Broken Money. **Bottom line:** Essential reading to understand Bitcoin culture, but treat it as persuasive advocacy with a broken price model, not settled economics. ## In the shop [The Bitcoin Standard — Saifedean Ammous](https://nuri.com/shop/books/book-bitcoin-standard) — $24 approx ## Sources (12) 1. [The Bitcoin Standard on Goodreads](https://www.goodreads.com/en/book/show/36448501) — Goodreads 2. [Review: The Bitcoin Standard](https://mises.org/quarterly-journal-austrian-economics/review-bitcoin-standard-decentralized-alternative-central-banking) — Mises Institute (QJAE) 3. [Review of The Bitcoin Standard (full PDF)](https://qjae.mises.org/article/12292.pdf) — Quarterly Journal of Austrian Economics 4. [Saifedean Ammous: The Bitcoin Standard — the Austrian case for Bitcoin](https://davidgerard.co.uk/blockchain/2018/04/07/saifedean-ammous-the-bitcoin-standard-the-austrian-case-for-bitcoin/) — David Gerard 5. [A Critique of the Bitcoin Stock-to-Flow Model](https://mises.org/mises-wire/critique-bitcoin-stock-flow-model) — Mises Institute 6. [Why the Stock-to-Flow Bitcoin Valuation Model Is Wrong](https://www.coindesk.com/markets/2020/06/30/why-the-stock-to-flow-bitcoin-valuation-model-is-wrong) — CoinDesk 7. [Bitcoin Stock-to-Flow Model is Complete Nonsense, Bloomberg Editor](https://www.ccn.com/bitcoin-stock-flow-model-complete-nonsense-bloomberg-editor/) — CCN 8. [A researcher debunks Stock-to-Flow model](https://cointelegraph.com/news/a-researcher-debunks-stock-to-flow-model-likens-bitcoin-to-a-tech-stock) — Cointelegraph 9. [Bitcoin stock-to-flow PlanB invalidated ($100k by December)](https://protos.com/bitcoin-stock-to-flow-planb-invalidated-100k-by-december-womp-womp/) — Protos 10. [PlanB's Stock-to-Flow model off by $130k since 2021](https://cryptoslate.com/planbs-stock-to-flow-model-off-by-130k-bitcoin-trades-below-trend-since-2021/) — CryptoSlate 11. [The Bitcoin Standard: A review](https://coingeek.com/the-bitcoin-standard-a-review/) — CoinGeek 12. [PlanB's Bitcoin stock to flow model fails](https://wazirx.com/blog/planbs-bitcoin-stock-to-flow-model-fails/) — WazirX Blog --- --- title: "Mastering Bitcoin: The Developer Bible That Isn't For Beginners" lang: "en" type: "review" product: "book-mastering-bitcoin" rating: 4.4 --- # Mastering Bitcoin: The Developer Bible That Isn't For Beginners _The definitive technical reference to how Bitcoin actually works, free on GitHub, and genuinely hard going if you don't code._ **Rating: 4.4 / 5** ## Verdict Mastering Bitcoin is the standard technical reference for how Bitcoin works under the hood, and the Harding-updated 3rd edition modernizes it for Taproot-era Bitcoin. It is superb for developers and technically curious readers, and it is freely available online. But it is emphatically not a beginner's introduction, and buying the print copy is optional given the free text. ## What's good - The most authoritative end-to-end technical explanation of Bitcoin's protocol available - 3rd edition (2023) rewritten by David Harding, modernizing dated 2014/2017 material and adding Taproot/SegWit-era content - Entire text is free on GitHub under a Creative Commons license; print/ebook via O'Reilly is optional - Real code, real transactions, and diagrams; excellent as a working reference, not just a read-through - Widely regarded as the best technical reference in the space by developers ## What's not - Not a beginner book; only the first two chapters are broadly accessible, the rest assumes real technical comfort - Requires programming/command-line familiarity to get full value from the examples - Fast-moving subject means any print edition risks drifting out of date (the free repo stays current) - Narrow scope: it explains the technology, not investing, custody strategy, or economics - Dense and reference-like; not designed to be read cover to cover casually **Buy it if:** Developers, engineers, and technically-minded readers who want to understand Bitcoin at the protocol level. **Skip it if:** A newcomer wanting a plain-language 'what is Bitcoin and should I buy it' introduction. ## Full review Mastering Bitcoin is the book developers point newcomers-to-the-code toward, and for good reason. It explains Bitcoin from keys and addresses through transactions, scripts, the mempool, mining, and consensus, with enough precision that you come away understanding how the machine actually runs rather than just what it is for. O'Reilly and reviewers consistently describe it as the best technical reference on Bitcoin available, and that reputation is deserved. The 3rd edition matters because Bitcoin changed a lot after the earlier versions. This edition was written by David A. Harding, building on Andreas Antonopoulos's first two editions, with a stated focus on modernizing the 2017 second edition and the leftover 2014 first-edition material. That refresh brings the text closer to modern Bitcoin, including SegWit and Taproot-era concepts, which is exactly where the older editions had started to show their age. A genuinely important buying note: you do not have to buy it. The complete text of the 3rd edition is published free on GitHub under a Creative Commons license (initially non-commercial/no-derivatives, later moving to a more permissive share-alike license), and you can read every chapter in the browser. The O'Reilly paperback and ebook are for people who prefer a bound copy or want to support the authors. For a Bitcoin shop that's worth stating plainly rather than hiding. The honest limitation is audience. The book itself says the first two chapters are for everyone and the rest is aimed at developers, engineers, and systems architects, and that is accurate. If you can't read a bit of code or aren't comfortable at a command line, large stretches will wash over you. This is not a knock on the book; it is simply not trying to be a gentle primer, and pretending otherwise sets buyers up for frustration. Scope is also narrow by design. Mastering Bitcoin explains the technology and almost nothing else. There is no meaningful coverage of price, investing, custody strategy for ordinary users, or the monetary-economics debates that books like Broken Money and The Bitcoin Standard center on. Pair it accordingly. The other structural caveat is freshness. Bitcoin's tooling and best practices move quickly, so any static print edition drifts over time; the living GitHub repository is the version that stays current. Bottom line: for the right reader this is a five-star, career-useful reference, and the free online availability makes it an easy recommendation. Just make sure the buyer is actually the technical reader this book is written for. **Bottom line:** The definitive protocol-level Bitcoin reference and free online, but a developer's book, not a beginner's on-ramp. ## In the shop [Mastering Bitcoin (3rd ed.) — Antonopoulos & Harding](https://nuri.com/shop/books/book-mastering-bitcoin) — $50 approx ## Sources (11) 1. [bitcoinbook/bitcoinbook — Mastering Bitcoin 3rd Edition (repo)](https://github.com/bitcoinbook/bitcoinbook) — GitHub 2. [BOOK.md — read the full text in-browser](https://github.com/bitcoinbook/bitcoinbook/blob/develop/BOOK.md) — GitHub 3. [Mastering Bitcoin releases](https://github.com/bitcoinbook/bitcoinbook/releases) — GitHub 4. [Mastering Bitcoin, 3rd Edition](https://www.oreilly.com/library/view/mastering-bitcoin-3rd/9781098150082/) — O'Reilly Media 5. [Mastering Bitcoin, 2nd Edition](https://www.oreilly.com/library/view/mastering-bitcoin-2nd/9781491954379/) — O'Reilly Media 6. [Introduction (Chapter 1, audience note)](https://www.oreilly.com/library/view/mastering-bitcoin-2nd/9781491954379/ch01.html) — O'Reilly Media 7. [Mastering Bitcoin on Goodreads](https://www.goodreads.com/book/show/30955996-mastering-bitcoin) — Goodreads 8. [Book Review: Mastering Bitcoin](https://www.asisonline.org/security-management-magazine/articles/2018/05/book-review-mastering-bitcoin/) — ASIS / Security Management 9. [Mastering Bitcoin (catalog entry)](https://dl.acm.org/doi/10.5555/2695500) — ACM Digital Library 10. [Mastering Bitcoin 3rd Edition released on GitHub (announcement)](https://www.patreon.com/posts/major-mastering-97367320) — Andreas M. Antonopoulos (Patreon) 11. [Mastering Bitcoin, 3rd Edition (free access listing)](https://freecomputerbooks.com/Mastering-Bitcoin.html) — FreeComputerBooks --- --- title: "Blockclock Mini: A Beautiful $399 Number That Trusts a Server" lang: "en" type: "review" product: "blockclock-mini" rating: 3.2 --- # Blockclock Mini: A Beautiful $399 Number That Trusts a Server _Coinkite's eInk price-and-block display is a well-built object of desire, but it is a Wi-Fi novelty that leans on a trusted price API, not a trustless device._ **Rating: 3.2 / 5** ## Verdict The Blockclock mini is a genuinely nice-looking eInk display from a respected hardware maker, and as an ambient block-height and price ticker it does its one job well. But at $399 it is a luxury novelty that needs Wi-Fi and pulls its price from a third-party exchange API, so it is not the trustless, verify-it-yourself device some buyers assume. Buy it for the vibe, not for sovereignty. ## What's good - Clean 7-digit eInk display that's readable and low-glare; genuinely attractive on a desk or shelf - From Coinkite, the well-regarded maker of Opendime and other self-custody hardware - Flexible: shows block height, price, Moscow time, Opendime balances, QR codes and custom API messages - Opendime balance math is done on the device, so your balance isn't handed to Coinkite's server - Update cadence is configurable (from ~5 minutes up to hourly, or synced to new blocks) ## What's not - $399 for what is fundamentally a single-purpose novelty display - Requires Wi-Fi and an internet connection; it is not an offline or air-gapped device - Price data comes from a third-party exchange API, so the headline number relies on a trusted source, not trustless verification - It is not a full node and does not independently validate the chain (unlike node-style clocks such as Block Clock Jr.) - Phones out to fetch blocks and rates, so it is not a privacy-neutral fixture - Pure ornament: it holds no keys and does nothing for your actual custody security **Buy it if:** Bitcoiners who want a tasteful ambient price/block-height display and don't mind paying a premium for the object. **Skip it if:** Anyone expecting a trustless, self-validating, or offline device, or who wants function over decoration. ## Full review The Blockclock mini is easy to like on sight. It's a roughly 30x10 cm slab with seven eInk digits from Coinkite, the Canadian maker behind Opendime, Satscard and other Bitcoin hardware. That pedigree shows in the build and the software polish, and the eInk panel is the right call for something meant to sit on a shelf all day: crisp, low-glare, and comfortable to glance at. As an ambient object it delivers exactly the calm, always-on Bitcoin ticker it promises. It's also more flexible than a one-trick ticker. You can cycle it through current block height, spot price in your chosen fiat, 'Moscow time' (sats per dollar), Opendime balances, deposit QR codes, and custom messages pushed via API. Refresh cadence is configurable from around five-minute updates up to hourly, or you can sync it to fire on each new block. For the intended use, decorating a desk or a shop counter with live network data, it's well thought out. The honesty starts with what it is: a $399 novelty. That is real money for a device whose entire job is to show a number you can already see for free on your phone or any block explorer. Coinkite doesn't hide this, and plenty of owners are happy paying for the aesthetic, but a shop should be upfront that you're buying an ornament, not a tool that improves your security or custody in any way. It holds no keys and does nothing for self-custody. The more important caveat is the trust model. The Blockclock mini needs your Wi-Fi and an internet connection to work at all, and the price it displays is fetched from a third-party exchange API of your choosing. That means the headline BTC price is only as trustworthy as that external source; the clock is not independently verifying anything about price. Calling it 'trustless' would be wrong. It's a networked display that trusts servers, which is fine for a decoration but worth stating plainly. To Coinkite's credit, there is a real privacy nuance in its favor: for Opendime balances the fiat conversion is computed on the device, so your balance figure isn't shipped off to their backend. That's a thoughtful touch. But the device still reaches out over the internet to pull block data and exchange rates, so it isn't a privacy-neutral fixture, and it is not a full node. If you want a clock that actually validates the chain itself, node-style projects like the Block Clock Jr. are a different category of device. So the verdict is narrow but fair. If you want a beautiful, well-made ambient Bitcoin display from a trusted manufacturer and the price doesn't faze you, the Blockclock mini is a lovely object that does its job. Just go in clear-eyed: it's a premium novelty that depends on Wi-Fi and a trusted price feed, not a sovereignty tool. **Bottom line:** A gorgeous, well-built $399 desk ornament that trusts a Wi-Fi price API, worth it for the vibe, not for trustlessness. ## In the shop [Coinkite Blockclock Mini](https://nuri.com/shop/accessories/blockclock-mini) — $399 ## Sources (11) 1. [BLOCKCLOCK mini — official product page](https://blockclockmini.com/) — Coinkite 2. [BLOCKCLOCK mini — store listing and price](https://store.coinkite.com/store/bc-mini) — Coinkite Store 3. [BLOCKCLOCK category (mini/micro)](https://store.coinkite.com/store/category/blockclock) — Coinkite Store 4. [BLOCKCLOCK mini User Documentation (data sources, on-device balance math)](https://blockclockmini.com/docs.html) — Coinkite 5. [The BLOCKCLOCK (overview)](https://getblockclock.com/) — Coinkite / getblockclock 6. [Blockclock MINI/MICRO Update with BitcoinTreasuries.net](https://blog.coinkite.com/blockclock-upgrade-123/) — Coinkite Blog 7. [Coinkite (maker of Opendime, Satscard, etc.)](https://coinkite.com/) — Coinkite 8. [Twitter Reacts To Jack Dorsey's Bitcoin Blockclock ($399, how it works)](https://www.ibtimes.com/twitter-reacts-jack-dorseys-bitcoin-blockclock-how-does-it-work-3169764) — International Business Times 9. [The BLOCKCLOCK Mini and Micro Review](https://www.bitcoinlearning.org/the-blockclock-mini-and-micro-review/) — BitcoinLearning.org 10. [The Bitcoin Block Clock Jr. Is Half Full Node, Half Work Of Art (node-based alternative)](https://bitcoinmagazine.com/culture/bitcoin-block-clock-jr-half-full-node-half-work-art) — Bitcoin Magazine 11. [BLOCKCLOCK micro (compact sibling)](https://blockclockmicro.com/) — Coinkite --- --- title: "Cryptosteel Capsule: Fireproof and Fiddly, With One Real Weakness" lang: "en" type: "review" product: "cryptosteel-capsule" rating: 3.9 --- # Cryptosteel Capsule: Fireproof and Fiddly, With One Real Weakness _The original stainless-steel seed capsule survives fire and water in independent testing, but the tile system is tedious and it's the one design that can fail if crushed._ **Rating: 3.9 / 5** ## Verdict The Cryptosteel Capsule is a well-built, independently made stainless-steel seed backup that has passed serious fire and water stress tests, including Jameson Lopp's long-running series. Its weaknesses are real and specific: the loose-tile assembly is tedious and error-prone, and it is more vulnerable to crushing than solid engraved plates. A strong choice if you assemble it carefully; not the most crush-proof option out there. ## What's good - Solid 303/304 stainless construction; independently rated fireproof to very high temperatures (well above a typical house fire) - Passed fire-plus-water-quench testing in Jameson Lopp's independent stress-test series - Made by Cryptosteel, an established independent brand, not tied to any single wallet vendor like Ledger - Modular tiles let you back up any BIP39 seed length and correct mistakes without re-buying - Waterproof and corrosion-resistant; the common-core design keeps tiles together even under stress ## What's not - Loose-letter tile assembly is genuinely tedious and easy to get wrong (misordered or dropped tiles) - Reading the seed back is fiddly due to tile orientation and spacing - More vulnerable to crushing than solid engraved/stamped plates; it yielded under a 20-ton press in testing - A misplaced fastener/closing tile can risk data loss, a failure mode reviewers have flagged - Pricier and slower to set up than a simple stamped washer-plate kit **Buy it if:** Self-custody users who want a proven, brand-neutral steel backup and will take time to assemble it carefully. **Skip it if:** Someone who wants the most crush-resistant, fastest-to-set-up, or cheapest metal backup available. ## Full review The Cryptosteel Capsule is the product that more or less created the metal-seed-backup category, and it still holds up. It's a stainless-steel tube into which you load individual engraved letter tiles to spell out your recovery seed, then seal it. The appeal is durability: paper burns and rots, but a stainless capsule is meant to survive the house fire and the flood that would destroy a written backup. For anyone practicing real self-custody, moving the seed off paper is one of the highest-value things you can do, and this is a credible way to do it. On the durability claims, there's independent evidence rather than just marketing. Jameson Lopp's multi-round 'Metal Bitcoin Seed Storage Stress Test' series, the most cited independent testing in this space, subjects devices to fire and then a water quench (because real fires are usually put out with water, and rapid cooling is its own stress). The Cryptosteel Capsule has been part of that testing, and stainless capsule designs like it generally clear the fire-and-water bar that matters for a home disaster. Cryptosteel's own lab figures cite resistance well above typical house-fire temperatures. Worth stating clearly for buyers: Cryptosteel is an independent brand, not a Ledger product. There's frequent confusion because Ledger has at times sold co-branded 'Cryptosteel' units, but the Capsule reviewed here is the standalone stainless product, and choosing it doesn't tie you to any single wallet vendor's ecosystem. That brand-neutrality is a plus for people who don't want their backup coupled to one company. Now the honest downsides, and they're about usability. The loose-tile system is tedious. You sort through a bag of letter tiles, slide them onto a core in the exact right order, and hope you don't drop or transpose one. Reviewers consistently note it takes real focus, and that reading the seed back later is fiddly because of how the tiles sit and space out. It's doable in under half an hour, but it is the opposite of quick, and the error surface is entirely on you. The one substantive engineering weakness is crushing. Independent crush testing found the Capsule holds up to several tons but eventually deforms and gives way under a roughly 20-ton press, and solid stamped or engraved plates tend to do better against pure crushing force. There's also a specific failure mode reviewers have flagged: if the closing/fastener tile is placed incorrectly, you can risk the tiles coming loose, meaning assembly discipline isn't just tedium, it's a data-integrity issue. The saving grace is that the tiles share a common core, so partial damage usually doesn't scatter your seed. Balanced, the Cryptosteel Capsule is a very good backup with clearly understood limits. It survives the disasters most people actually face (fire, water, corrosion), it's made by an established independent maker, and it flexibly handles any seed length. If your threat model prioritizes maximum crush resistance or you want the fastest possible setup, a solid engraved-plate kit may suit you better. For everyone else, this is a proven, sensible choice, as long as you assemble it slowly and double-check every tile. **Bottom line:** A proven, brand-neutral stainless seed backup that shrugs off fire and water, but it's fiddly to assemble and not the most crush-proof design. ## In the shop [Cryptosteel Capsule Solo](https://nuri.com/shop/steel-backups/cryptosteel-capsule) — $53 approx ## Sources (12) 1. [Cryptosteel Capsule Review (independent review page)](https://jlopp.github.io/metal-bitcoin-storage-reviews/reviews/cryptosteel-capsule/) — Jameson Lopp — Metal Bitcoin Storage Reviews 2. [Metal Bitcoin Seed Storage Stress Test (original round)](https://blog.lopp.net/metal-bitcoin-seed-storage-stress-test/) — Jameson Lopp (blog.lopp.net) 3. [Metal Bitcoin Seed Storage Stress Test (Part II)](https://blog.lopp.net/metal-bitcoin-seed-storage-stress-test-part-ii/) — Jameson Lopp (blog.lopp.net) 4. [Metal Bitcoin Seed Storage Stress Test (Round III, adds water quench)](https://blog.lopp.net/metal-bitcoin-seed-storage-stress-test-round-iii/) — Jameson Lopp (blog.lopp.net) 5. [Metal Bitcoin Seed Storage Stress Test (Round V)](https://blog.lopp.net/metal-bitcoin-seed-storage-stress-tests-round-v/) — Jameson Lopp (blog.lopp.net) 6. [Cryptosteel Seed System / metal backup (official)](https://cryptosteel.com/seed-system-metal-backup/) — Cryptosteel 7. [The Block Review: Cryptosteel Capsule](https://www.theblock.co/post/45364/the-block-review-cryptosteel-capsule) — The Block 8. [Cryptosteel Capsule Review](https://billfodl.com/blogs/billfodl/cryptosteel-capsule-review) — Billfodl 9. [Cryptosteel Capsule Review (security, price, durability)](https://www.hardware-wallets.net/cryptosteel-capsule-review/) — Hardware-Wallets.net 10. [Cryptosteel Capsule Review (crush/fire testing notes)](https://buybitcoinworldwide.com/cryptosteel/) — BuyBitcoinWorldwide 11. [Cryptosteel Capsule Review: Steel-Based Wallet Protection](https://www.bitdegree.org/crypto/cryptosteel-capsule-review) — BitDegree 12. [7 Steel Crypto Wallets That Withstand Extreme Fire and Water Damage](https://news.bitcoin.com/7-steel-crypto-wallets-that-withstand-extreme-fire-and-water-damage/) — News.Bitcoin.com --- --- title: "Bitaxe Gamma: The Honest Case for a $150 Lottery Miner" lang: "en" type: "review" product: "bitaxe-gamma" rating: 4.3 --- # Bitaxe Gamma: The Honest Case for a $150 Lottery Miner _A silent, open-source ASIC that mines almost no bitcoin in expected value — and is still one of the best gifts you can give a curious hodler._ **Rating: 4.3 / 5** ## Verdict The Bitaxe Gamma is a beautifully executed, fully open-source solo miner that runs silent on 15-18W. Just be clear-eyed: against a ~900+ EH/s network, a single unit's expected earnings round to zero, and a real block win is a roughly-once-in-17,000-years event per device. Buy it as a heater, a teaching tool, and a lottery ticket — not as an investment. ## What's good - Fully open-source hardware and AxeOS firmware — schematics, PCB and code are public and auditable - Genuinely silent and low-power: ~1.2 TH/s at ~15-18W on the BM1370 ASIC (the same chip family as the Antminer S21 Pro) - Solo mining to a no-fee pool like Public Pool means you keep 100% of any block you find - Cheap ($60-$150) and self-contained: standard wall power, 2.4GHz WiFi, USB-C firmware flashing - Real solo wins do happen — a Bitaxe Gamma took block #957382 for 3.1382 BTC in July 2026 - Excellent education device: you learn stratum, difficulty, pools and firmware hands-on ## What's not - Expected value is effectively negative — you pay electricity to mine statistically nothing - Mean time-to-block for one ~1 TH/s unit is on the order of 17,000 years against the current network - The win everyone cites was one lucky household out of an enormous population of miners — survivorship bias is real - No secondary income stream: pointed at a pooled payout pool it earns only pennies per day - Overclocking for more hashrate raises heat, noise and failure risk with no change to the underlying lottery - It is a hobbyist board, not a supported appliance — you are your own tech support **Buy it if:** Tinkerers and hodlers who want to learn how mining actually works and enjoy holding a real, no-KYC lottery ticket. **Skip it if:** Anyone expecting the device to pay for itself or generate reliable income. ## Full review Start with the honest math, because everything else follows from it. Bitcoin's network hovered near 980 EH/s in early July 2026 and drifted around 866-908 EH/s later in the month. A single Bitaxe Gamma contributes roughly 1 TH/s — about one part in nine hundred million of that total. Multiply that share across a year of blocks and the expected number of blocks you find is a tiny fraction of a percent, which is another way of saying the mean time between wins for one unit is measured in tens of thousands of years. No firmware tweak changes this; it is arithmetic, not a settings problem. So why is this still a 4.3-star product? Because it is honest about what it is, and it executes that role beautifully. The Bitaxe is the world's first fully open-source ASIC miner, started by an engineer known as Skot in 2023. The hardware lives at github.com/skot/bitaxe and the AxeOS firmware at github.com/skot/ESP-Miner, both public and auditable. You are not trusting a black box — you can read every line, flash it over USB-C, and watch the dashboard on your LAN. For a device class historically dominated by opaque industrial gear, that transparency is rare and valuable. The engineering is legitimately good. The Gamma runs the BM1370 ASIC harvested from Bitmain's S21 Pro line, delivering roughly 1.2 TH/s at 15-18W, or about 14-15 J/TH. A single 40mm fan keeps it near-silent, so it sits on a desk or shelf without annoying anyone. It sips power comparable to a small light bulb and doubles as a modest space heater — waste heat you were arguably going to spend on heating anyway, which softens the running-cost argument in winter. The lottery is real, not theoretical — that is the seductive part. On July 9, 2026, a solo miner running a single Bitaxe Gamma at about 995 GH/s for roughly eight hours mined block #957382 through Public Pool and collected the full 3.1382 BTC (subsidy plus fees), worth around $200,000 at the time. It happened. It also happens to almost no one: for every winner there is an effectively uncountable crowd of identical devices that will run for years and find nothing. Both statements are true at once, and any honest review has to hold them together. Set expectations correctly and it is hard to be disappointed. Point it at a no-fee solo pool and you keep everything if lightning strikes; point it at a shared pool and you will earn a few cents a day in steady, unexciting payouts. Neither path is a business. Treat the purchase price as the cost of the ticket and the electricity as the cost of playing, and you will enjoy the device for what it delivers: a tangible, sovereign, no-KYC connection to the network and a genuine, if microscopic, shot at a jackpot. Practical caveats: this is hobbyist hardware, so you are your own support desk, and community firmware moves fast. Overclocking chases higher numbers at the cost of heat, noise and chip longevity without improving your odds in any meaningful way — the network is simply too large. Buy one because you want to learn, to hold a real lottery ticket, and to run a warm, quiet, fully open piece of the Bitcoin network on your desk. Buy several only if you enjoy the game, not because more of them meaningfully changes the odds. **Bottom line:** A superb open-source lottery-and-education device that will almost certainly never pay you back — and is worth owning anyway if you know that going in. ## In the shop [Bitaxe Gamma](https://nuri.com/shop/miners/bitaxe-gamma) — $175 approx ## Sources (13) 1. [Bitaxe — Official Project Site](https://www.bitaxe.org/) — Bitaxe 2. [skot/bitaxe — Open source ASIC Bitcoin miner hardware](https://github.com/skot/bitaxe) — GitHub 3. [skot/ESP-Miner — AxeOS mining firmware](https://github.com/skot/ESP-Miner) — GitHub 4. [bitaxeorg/bitaxegamma — BM1370 Gamma reference design](https://github.com/bitaxeorg/bitaxegamma) — GitHub 5. [Bitaxe Gamma 1.2 TH/s Solo Miner — product & specs](https://www.solosatoshi.com/product/bitaxe-gamma/) — Solo Satoshi 6. [Bitaxe Gamma 601 realtime profit, specs & cost](https://miningnow.com/asic-miner/bitaxe-gamma-601-1-2th-s/) — Mining Now 7. [Solo BTC miner makes $200,000 using $150 equipment](https://www.coindesk.com/markets/2026/07/14/solo-btc-miner-makes-usd200-000-using-usd150-equipment) — CoinDesk 8. [Solo bitcoin miner turns $150 Bitaxe into a $200,000 block reward](https://cryptobriefing.com/solo-bitcoin-miner-bitaxe-200000-block-reward/) — Crypto Briefing 9. [Bitcoin's Lottery Jackpot: Solo Home Miner Wins $200,000](https://news.bitcoin.com/bitcoins-lottery-jackpot-solo-home-miner-wins-200000-with-a-150-mining-device/) — Bitcoin.com News 10. [Bitcoin Block #957382](https://mempool.space/block/957382) — mempool.space 11. [Public Pool — block find announcement](https://x.com/Public_Pool_BTC/status/2075431013497356538) — Public Pool (X) 12. [Bitcoin Hashrate Chart 2026](https://www.coinwarz.com/mining/bitcoin/hashrate-chart) — CoinWarz 13. [AxeOS Complete Guide: Bitaxe Firmware Settings Explained](https://d-central.tech/axeos-complete-guide-bitaxe-firmware-settings-explained/) — D-Central --- --- title: "FutureBit Apollo II: A Great Node That Also Mines a Lottery" lang: "en" type: "review" product: "futurebit-apollo-ii" rating: 4 --- # FutureBit Apollo II: A Great Node That Also Mines a Lottery _One quiet desktop box runs a full Bitcoin node and mines solo — an appealing sovereignty appliance wrapped around miner economics that still don't add up._ **Rating: 4.0 / 5** ## Verdict The Apollo II is the most polished full-node-plus-miner appliance you can buy: a 6-core ARM computer syncing a full node next to a 6-10 TH/s ASIC, all near-silent in Eco mode. As a node it earns its keep. As a miner its efficiency is mediocre and its solo economics are still a lottery — just a slightly bigger ticket than a Bitaxe. ## What's good - Two products in one: a full Bitcoin node and a solo miner in a single quiet desktop unit - Runs a real full node on a 6-core ARM system with 1-2TB NVMe, giving you independent transaction verification - Built-in one-toggle solo Stratum pool — solo mine straight to your own node, no external pool required - Genuinely quiet in Eco mode (under ~40 dB); vapor-chamber cooling handles the heat well - Plug-and-play Apollo OS 2.0 — WiFi and a wall outlet is the whole setup - Flexible power band: ~6 TH/s Eco up to ~9-10 TH/s Turbo depending on your noise and heat tolerance ## What's not - Mining efficiency is weak by modern standards — roughly 28 J/TH versus ~15 J/TH for current industrial ASICs - Solo economics remain a lottery: ~9 TH/s still implies a mean time-to-block on the order of ~2,000 years - Turbo mode gets loud (~55 dB) and hot — the quiet number and the fast number are not the same mode - Much more expensive than a Bitaxe, so the 'lottery ticket' costs several times more per unit - As an ASIC it will not earn back its price mining bitcoin at home in any realistic scenario - Most of its lasting value is the node — which you could run on far cheaper hardware if you skipped mining **Buy it if:** Sovereignty-minded users who want one attractive, quiet box that verifies their own transactions and lets them play the solo-mining lottery on the side. **Skip it if:** Anyone buying it primarily to earn bitcoin, or who needs competitive mining efficiency. ## Full review The Apollo II's best trick is combining two things people usually run separately. Inside one 6-inch aluminum desktop box sits a modern 6-core ARM Linux computer with 1-2TB of NVMe storage and a 5nm ASIC hash unit. The ARM side quietly syncs and runs a full Bitcoin node; the ASIC side mines. FutureBit's pitch is sovereignty as an appliance: verify your own transactions and, optionally, point hashrate at your own node with a single toggle that spins up a local solo Stratum pool. For a lot of people that integration is the entire appeal, and it is well executed. As a node, it is easy to recommend. You get independent verification without babysitting a Raspberry Pi build, running on Apollo OS 2.0 with the storage and horsepower to stay synced comfortably. If you value not trusting someone else's node to tell you your balance or to broadcast your transactions, that capability alone is real and durable — it keeps delivering value long after any mining novelty wears off. This is where most of the four stars come from. As a miner, the honesty gets harder. The hash unit does 6 TH/s in Eco mode and up to about 9-10 TH/s in Turbo, drawing roughly 400W at around 28 W/TH. That efficiency is well behind today's best industrial machines near 15 J/TH, which means at home electricity rates you are usually paying more in power than the tiny pooled payout returns. It is not a money machine; it is a heater that occasionally hashes for a jackpot. And the jackpot is still a lottery. Nine terahashes is roughly nine Bitaxe Gammas, so your odds improve by that factor — but against a network near 900 EH/s to nearly 1 ZH/s, nine times almost-nothing is still almost-nothing. The implied mean time between solo blocks for one Apollo II is on the order of a couple of thousand years. Solo mining to your own node is a lovely, sovereign way to buy that ticket, and the built-in toggle makes it trivial, but no framing changes the underlying probability. The noise story deserves a caveat too, because the marketing-friendly 'quiet' figure and the exciting 'fast' figure describe different modes. Eco mode is genuinely living-room quiet under about 40 dB; Turbo mode climbs to roughly 55 dB and runs noticeably hotter. You can have quiet or you can have maximum hashrate, not both at once, so plan around where the box will actually live. Net-net: buy the Apollo II if you want a single elegant appliance that gives you a full node plus the option to play the solo lottery, and you have made peace with mining being a cost center rather than a profit center. If your only goal is to earn bitcoin, this hardware will not get you there, and if your only goal is a node, cheaper hardware does that job. Its value is the combination and the polish — which, for the right buyer, is genuinely worth it. **Bottom line:** An excellent quiet node appliance with a solo miner bolted on — buy it for sovereignty and fun, not for a return on investment. ## In the shop [FutureBit Apollo II](https://nuri.com/shop/miners/futurebit-apollo-ii) — $1,199 approx ## Sources (12) 1. [Introducing Apollo II](https://www.futurebit.io/apollo-ii) — FutureBit 2. [Apollo II — Desktop Full Node System and Home Miner (product)](https://shop.futurebit.io/products/apollo-ii-next-generation-home-miner-and-desktop-full-node-system) — FutureBit Shop 3. [Apollo II vs Bitmain Antminer: Price, Efficiency & Everything Else](https://www.futurebit.io/blog/futurebit-apollo-ii-vs-bitmain-antminer-price-efficiency-amp-everything-else) — FutureBit Blog 4. [Apollo Solo Bitcoin Miner](https://www.futurebit.io/solo-bitcoin-miner) — FutureBit 5. [FutureBit Apollo II Full Node (9 TH/s) — product](https://bitcoinmerch.com/products/apollo-ii-next-generation-desktop-full-node-system-and-home-miner-9th-s) — Bitcoin Merch 6. [FutureBit Apollo II BTC Founders Edition — hands-on review](https://bitcointalk.org/index.php?topic=5492150.0) — Bitcointalk 7. [FutureBit Apollo II is More than Just a Bitcoin ASIC Miner](https://bloodys.medium.com/futurebit-apollo-ii-is-more-than-just-a-bitcoin-asic-miner-for-home-users-117f786ac082) — Medium (Bloodys) 8. [FutureBit Apollo II Full Node — product listing](https://www.amazon.com/Futurebit-Apollo-II-Full-Node/dp/B0D8RC4VRW) — Amazon 9. [FutureBit Apollo II Full Node Bitcoin Miner — overview](https://www.gadgetify.com/futurebit-apollo-ii-home-miner/) — Gadgetify 10. [Apollo BTC Support](https://www.futurebit.io/apollo-btc-support) — FutureBit 11. [Is Bitcoin Mining Profitable in 2026?](https://startmining.io/en/blog/is-bitcoin-mining-profitable-2026) — Startmining 12. [Bitcoin Hashrate Chart 2026](https://www.coinwarz.com/mining/bitcoin/hashrate-chart) — CoinWarz --- --- title: "Blockstream Jade Plus: Fully Open, With a Security Model to Understand" lang: "en" type: "review" product: "blockstream-jade-plus" rating: 4 --- # Blockstream Jade Plus: Fully Open, With a Security Model to Understand _A cheap, fully open-source signer with an excellent QR camera — built on a general-purpose ESP32 and a blind-oracle design you should understand before you trust it._ **Rating: 4.0 / 5** ## Verdict The Jade Plus is one of the best-value fully open-source hardware wallets: great QR scanning, multiple connectivity options, and firmware and hardware you can fully inspect. The trade-off is that it uses a general-purpose ESP32 MCU instead of a dedicated secure element, leaning on a 'blind oracle' for physical-attack resistance — a clever model, but one with real caveats and a documented history of ESP32-class attacks. ## What's good - Fully open-source hardware and firmware — you can even build a compatible device from off-the-shelf parts - Excellent built-in camera for fast, air-gap-friendly QR signing - Flexible connectivity: USB, Bluetooth, camera QR, and microSD - Inexpensive — the Plus is around $149 and the base Jade Core is even cheaper - Blind-oracle model can be self-hosted (e.g. on Umbrel) or run statelessly, so you're not forced to trust Blockstream's server - Larger, sharper screen and better build than the original Jade ## What's not - No dedicated secure element — it runs on a general-purpose ESP32-S3, a chip class with a documented fault-injection/glitching history - Physical-attack resistance depends on the blind oracle; run it fully stateless and you give up some of that protection - The blind oracle introduces an availability and privacy consideration you must reason about (self-hosting mitigates it) - Security researchers (esp32.fail / Ledger Donjon) have published evil-maid firmware-extraction and glitch findings on Jade-class hardware - At least one firmware-level bug (a CBOR 'register_descriptor' issue) was disclosed and patched — keep firmware updated - Bluetooth is convenient but adds attack surface some users prefer to avoid **Buy it if:** Value-focused and open-source-first users who will take the time to understand the blind-oracle model and keep firmware current. **Skip it if:** Buyers who specifically want a dedicated secure element and the simplest possible 'set it and forget it' physical-security story. ## Full review The Jade Plus makes a strong opening argument: it is fully open source, top to bottom. Blockstream publishes the hardware and firmware, and famously you can assemble a compatible Jade from off-the-shelf parts. For people who believe verifiability is the foundation of trust, that openness is the headline feature, and it is not marketing fluff — it is a genuine, auditable commitment that most competitors only partially match. In daily use it is pleasant and capable. The built-in camera is one of the better QR scanners on the market, which makes air-gapped signing fast rather than fiddly. You also get USB, Bluetooth and microSD, so it slots into almost any wallet workflow. The Plus adds a bigger, nicer screen and a more premium feel than the original. At roughly $149 — with the base Jade Core cheaper still — the value proposition is excellent on paper. The part that demands honesty is the security architecture. Unlike many competing hardware wallets, the Jade does not use a dedicated secure element. It runs on a general-purpose ESP32-S3 microcontroller. To compensate, Blockstream designed the 'blind oracle': your wallet encryption is split between your PIN, the device, and a remote oracle server that never learns your PIN, keys or addresses. It functions as a virtual secure element, and critically you can run your own oracle (for example on Umbrel) or operate the device in a stateless mode with no oracle at all. That design is genuinely clever, and it is the reason Jade can stay fully open — secure-element silicon is proprietary, so avoiding it is what buys the openness. But the trade-offs are real and worth stating plainly. Lean on the blind oracle and you introduce an availability and privacy consideration (mitigated, though not eliminated, by self-hosting). Run fully stateless and you shed some of the physical-attack resistance the oracle provides. There is no free lunch; there is a choice you should make deliberately. The ESP32 lineage also carries baggage. General-purpose MCUs of this class have a documented history of voltage-glitching and fault-injection attacks going back to Black Hat research, and security researchers have published evil-maid firmware-extraction work specifically against Jade-class hardware. Separately, a firmware-level vulnerability in the CBOR 'register_descriptor' path was responsibly disclosed and patched. None of this means Jade is broken — Blockstream has responded with updates — but it does mean physical security here is a moving target that depends on you keeping firmware current. We land at 4.0. The Jade Plus is a legitimately great open-source wallet at a great price, and for a threat model centered on remote attackers and everyday use it is more than sufficient. It loses points only against the strictest physical-security bar, where a dedicated secure element and a simpler trust story win. Buy it if openness and value are your priorities and you are willing to understand the oracle model; look elsewhere if you want a secure element and zero homework. **Bottom line:** A superb-value, fully open-source signer whose novel blind-oracle security model is a strength and a homework assignment in equal measure. ## In the shop [Blockstream Jade Plus](https://nuri.com/shop/hardware-wallets/blockstream-jade-plus) — $149 ## Sources (12) 1. [Blockstream Jade Plus — Official Product Page](https://blockstream.com/jade/jade-plus/) — Blockstream 2. [Blockstream Jade Plus — Store](https://store.blockstream.com/products/jade-plus) — Blockstream Store 3. [Introducing the All-New Blockstream Jade Plus](https://blog.blockstream.com/introducing-the-all-new-blockstream-jade-plus-simple-enough-for-beginners-advanced-enough-for-cypherpunks/) — Blockstream Blog 4. [Jade Security Model FAQs](https://help.blockstream.com/hc/en-us/articles/15884462476953-Jade-security-model-FAQs) — Blockstream Help Center 5. [Why Doesn't Jade Have a Secure Element?](https://help.blockstream.com/hc/en-us/articles/13745404122265-Why-doesn-t-Jade-have-a-secure-element) — Blockstream Help Center 6. [Blind Oracle — Glossary](https://glossary.blockstream.com/blind-oracle/) — Blockstream 7. [Set Up a Personal Blind Oracle with Umbrel](https://help.blockstream.com/hc/en-us/articles/18904765931161-Set-up-a-personal-blind-oracle-with-Umbrel) — Blockstream Help Center 8. [jade.fail / esp32.fail — Vulnerabilities & Mishaps of Blockstream Jade](https://esp32.fail/) — esp32.fail 9. [Firmware Extraction: Evil-Maid Attacks on Blockstream Jade](https://www.ledger.com/blog/firmware-extraction-evil-maid-attacks-on-blockstream-jade-hardware-wallet) — Ledger Donjon 10. [Jade Security Disclosure](https://blog.blockstream.com/jade-security-disclosure/) — Blockstream Blog 11. [Less Complexity, Same Security: Blockstream Introduces Jade Core](https://blockstream.com/press-releases/2026-04-28-blockstream-introduces-jade-core/) — Blockstream Press 12. [Blockstream Jade Review (2025): Open-Source Security](https://www.walletpilot.com/hardware-wallets/blockstream-jade/review) — WalletPilot --- --- title: "Foundation Passport Core: The Air-Gap Purist's Beautiful Signer" lang: "en" type: "review" product: "foundation-passport-core" rating: 4.4 --- # Foundation Passport Core: The Air-Gap Purist's Beautiful Signer _No USB data, no radios, a phone-like keypad and fully open firmware — a genuinely air-gapped Bitcoin-only wallet that treats design as a feature._ **Rating: 4.4 / 5** ## Verdict The Passport Core is one of the few wallets that is air-gapped by construction, not by user discipline: it has no USB data port and no wireless of any kind, communicating only via QR codes and microSD. Add fully open firmware, a US-assembled build and a genuinely pleasant keypad interface, and you get a polished, purist signer. You pay a premium for it, and it's Bitcoin-only. ## What's good - Truly air-gapped by design — no USB data, no Bluetooth, no WiFi; QR codes and microSD only - Fully open source: hardware schematics, MicroPython firmware, and the Envoy companion app are all published - Familiar phone-style numeric keypad and color screen make it one of the most intuitive air-gapped wallets to operate - Uses a Microchip ATECC608A secure element for key storage plus an avalanche-noise true RNG for provable entropy - Assembled in the USA under Foundation's supervision, with third-party-reviewed firmware - Bitcoin-only focus keeps the codebase and attack surface lean; works with Envoy, Sparrow and Electrum ## What's not - Premium price — the Core is $199, more than most mainstream wallets - Single-vendor secure element, versus competing dual-secure-element designs - MicroPython firmware favors auditability over raw performance - Bitcoin-only — no use if you also hold other assets - Physically larger than keychain-style devices, and USB-C is power-only (no data), so all transfers are QR or microSD - QR/microSD-only workflow is more deliberate (some would say slower) than just plugging in over USB **Buy it if:** Bitcoin-only holders who want a truly air-gapped, fully open-source signer with a polished, approachable interface. **Skip it if:** Multi-asset users, bargain hunters, or anyone who wants the convenience of direct USB signing. ## Full review Passport's defining trait is that its air-gap is not a mode you have to remember to use — it is baked into the hardware. There is no USB data connection and no wireless of any kind; the USB-C port is power-only. Everything moves in and out via QR codes or a microSD card. That means you cannot accidentally undermine the isolation, which is a meaningfully stronger guarantee than a device that merely offers an air-gapped option alongside USB and NFC. For a purist threat model, that design decision is the whole ballgame. The openness is comprehensive. Foundation publishes the hardware schematics, the firmware (open-source MicroPython), and the Envoy companion app, making Passport one of the most completely open-source wallets you can buy. It pairs an STMicroelectronics STM32H753 microcontroller with a Microchip ATECC608A secure element used purely for secure key storage, and adds an avalanche-noise circuit as a true random number generator — an open, provable entropy source rather than a black box. The firmware has also been third-party reviewed, and the hardware is assembled in the USA under the team's supervision. In the hand, Passport is the anti-cryptic wallet. Where many secure devices feel like puzzle boxes, Passport's numeric keypad and color screen feel like using a familiar phone. Reviewers who have lived with it for months consistently describe the interface as intuitive even for relative newcomers, which is rare in the air-gapped category. Design here is not vanity; a signer you understand is a signer you use correctly, and that reduces the human errors that cause most real-world losses. The honest trade-offs are mostly about positioning. Passport uses a single secure element, whereas some competing designs use two from different vendors — a defensible difference in defense-in-depth philosophy that stricter buyers will weigh. The MicroPython firmware optimizes for readability and auditability over speed, so it is not the snappiest device. And the QR/microSD-only workflow, while a security virtue, is more deliberate than plugging in a cable; you trade a little convenience for isolation on every transaction. Then there is price and scope. At $199 for the Core (with a $349 Prime above it), Passport sits at the premium end, and it is Bitcoin-only. For someone who holds a range of assets or wants the cheapest workable wallet, that is a poor fit. For someone who has decided Bitcoin cold storage is worth doing properly and wants every layer verifiable, the premium buys real things: a truly air-gapped design, full openness, domestic assembly and a genuinely nice interface. We rate it 4.4. Passport Core is close to the top of its class for air-gap purists who value design and openness, and the marks it loses are about cost, the single secure element, and the deliberate-by-nature workflow rather than any real weakness. If you want a beautiful, fully open, no-radios Bitcoin signer and the price does not scare you, it is one of the easiest recommendations in the category. **Bottom line:** A polished, fully open, genuinely air-gapped Bitcoin-only signer that justifies its premium for anyone who wants isolation and design without compromise. ## In the shop [Foundation Passport Core](https://nuri.com/shop/hardware-wallets/foundation-passport-core) — $199 ## Sources (11) 1. [Passport Core — Official Product Page](https://foundation.xyz/passport-core/) — Foundation 2. [Passport Is Now Passport Core](https://foundation.xyz/2025/03/passport-is-now-passport-core/) — Foundation Blog 3. [Foundation — Company Site](https://foundation.xyz/) — Foundation 4. [passport2 — v2.x firmware for Passport](https://github.com/Foundation-Devices/passport2) — GitHub (Foundation-Devices) 5. [Passport Firmware — SECURITY.md](https://github.com/Foundation-Devices/passport-firmware/blob/main/SECURITY/SECURITY.md) — GitHub (Foundation-Devices) 6. [Foundation Passport Review 2026: A True FOSS Hardware Wallet](https://blockdyor.com/foundation-passport-review/) — Blockdyor 7. [Foundation Passport Review: Pros, Cons and How It Compares](https://www.athena-alpha.com/foundation-passport-review/) — Athena Alpha 8. [Foundation Passport Review After Six Months of Daily Use](https://www.bitcoinproducts.com/blog/foundation-passport-review-six-months-daily-use) — Bitcoin Products 9. [Foundation Passport Review 2026 (8.5/10)](https://www.bitcoin.diy/reviews/foundation-passport) — Bitcoin.diy 10. [Foundation Passport Review 2026: Open-Source, US-Made Cold Storage](https://stateofsurveillance.org/resources/foundation-passport/) — State of Surveillance 11. [Foundation Passport Core Hardware Wallet — product](https://www.thecryptomerchant.com/products/foundation-passport-hardware-wallet) — The Crypto Merchant --- --- title: "Ledger Nano X: Slick, Popular, and Still Asking for Trust" lang: "en" type: "review" product: "ledger-nano-x" rating: 3.5 --- # Ledger Nano X: Slick, Popular, and Still Asking for Trust _A polished, Bluetooth-enabled wallet from a company whose security promises have been tested more than once._ **Rating: 3.5 / 5** ## Verdict The Nano X is a well-built, beginner-friendly multi-coin wallet with a genuine certified Secure Element, but its closed-source SE firmware, the 2020 customer-data breach, and the 2023 'Ledger Recover' backlash mean you are trusting Ledger's word on the parts you cannot audit. It works, and millions use it, but Bitcoin maximalists who value verifiability have better options. ## What's good - Certified ST33 Secure Element with a long track record against physical attacks - Very approachable Ledger Live app and setup, good for first-time users - Bluetooth 5.2 and USB-C allow mobile use without cables - Broad asset support (500+ coins and thousands of tokens) if you hold more than Bitcoin - Widely available, strong resale/support ecosystem ## What's not - The Secure Element's low-level firmware is closed source and under an STMicroelectronics NDA — Ledger itself calls it the ~5% you cannot inspect - 2020 e-commerce breach exposed ~1 million emails and 272,853 customers' names, physical addresses and phone numbers — a physical-safety concern for holders - The 2023 'Ledger Recover' service showed a firmware update can extract an encrypted seed backup off the device, contradicting years of 'keys never leave' messaging - Bluetooth enlarges the attack surface versus a USB-only device, even if Ledger rates the risk low - You are paying ~$149 (roughly double the USB-only Nano S Plus) largely for wireless convenience **Buy it if:** Beginners and multi-coin holders who want a polished app experience and accept trusting Ledger on the closed parts. **Skip it if:** Verification-focused Bitcoiners who want fully auditable firmware and were unsettled by the Recover episode or the address leak. ## Full review The Ledger Nano X is the wireless flagship of the world's best-selling hardware-wallet line. It pairs an ST33 Secure Element with Bluetooth 5.2 and USB-C, driving a small 128x64 monochrome OLED, and it manages 500+ assets through the Ledger Live app. At around $149 it costs roughly double the USB-only Nano S Plus, and most of that premium buys you Bluetooth and a larger transaction memory rather than any extra security. As a piece of consumer hardware it is genuinely good: fast, sturdy, and about as friendly as cold storage gets. The security model rests on that Secure Element, a bank-card-grade chip designed to resist physical extraction. The catch, which Ledger states openly, is that the SE's low-level firmware is closed source and locked behind an STMicroelectronics NDA. Ledger describes its stack as '95% open source'; the remaining 5% is exactly the part that governs the chip holding your keys. For many users that is an acceptable trade for certified hardware. For anyone who believes 'don't trust, verify,' it is the whole ballgame — you are trusting a company, not inspecting a design. That trust has been tested. In 2020 a breach of Ledger's e-commerce and marketing database exposed roughly one million customer emails and, in the public dump that followed, 272,853 buyers' names, home addresses and phone numbers. No funds, passwords or seed data were touched — the private keys were never at risk — but for a product bought specifically by people holding wealth, leaking a list of who owns hardware wallets and where they live is a serious physical-security failure, and it drove a wave of phishing and extortion attempts. The second dent came in May 2023 with 'Ledger Recover,' an optional paid service that splits an encrypted copy of your seed across three custodians so it can be restored with ID verification. The uproar was not really about the feature; it was Ledger's own explanation that firmware could facilitate key extraction. That single admission rewrote how many users understood the device, and Ledger postponed the launch, promising to open-source OS components first. It was a self-inflicted credibility wound more than a technical break. On Bluetooth, Ledger's position is that only public data crosses the radio, keys never leave the SE, and pairing uses numeric comparison to resist man-in-the-middle attacks. Independent reviewers generally rate the practical BLE risk as low, but note the obvious: a radio you can turn on is attack surface a USB-only wallet does not have. If you want the Ledger experience without it, the Nano S Plus is the cheaper, wire-only sibling. The verdict is nuanced. The Nano X is not insecure, and the millions of people using it without incident are not fools. But it is a device that repeatedly asks you to trust the maker on the parts you cannot check, and whose maker has twice given critics ammunition. If you value convenience, multi-coin support and a smooth app, it is a reasonable buy. If your priority is auditability and minimizing who you must trust, the open-source Bitcoin-only wallets in this roundup answer that need more directly for less money. **Bottom line:** A convenient, capable wallet with real certified hardware, undermined for verification-minded Bitcoiners by closed firmware and a rocky trust record. ## In the shop [Ledger Nano X](https://nuri.com/shop/hardware-wallets/ledger-nano-x) — $149 ## Sources (13) 1. [Buy Ledger Nano X Hardware Wallet](https://shop.ledger.com/products/ledger-nano-x) — Ledger 2. [Ledger Nano X & Bluetooth – Security Model of a Wireless Hardware Wallet](https://www.ledger.com/ledger-nano-x-bluetooth-security-model-of-a-wireless-hardware-wallet) — Ledger 3. [Is Ledger Open Source?](https://www.ledger.com/academy/topics/ledgersolutions/is-ledger-open-source) — Ledger Academy 4. [Ledger is 95% Open Source, why not 100%?](https://www.ledger.com/blog-ledger-is-95-opensource-why-not-100) — Ledger 5. [Addressing the July 2020 e-commerce and marketing data breach](https://www.ledger.com/addressing-the-july-2020-e-commerce-and-marketing-data-breach) — Ledger 6. [Message by Ledger's CEO — Update on the July data breach](https://www.ledger.com/message-ledgers-ceo-data-leak) — Ledger 7. [Physical addresses of 270K Ledger owners leaked on hacker forum](https://www.bleepingcomputer.com/news/security/physical-addresses-of-270k-ledger-owners-leaked-on-hacker-forum/) — BleepingComputer 8. [Crypto Firm Ledger's Breach Hits One Million Customers](https://www.infosecurity-magazine.com/news/crypto-firm-ledgers-breach-one/) — Infosecurity Magazine 9. [Ledger Data Breach](https://haveibeenpwned.com/Breach/Ledger) — Have I Been Pwned 10. [Ledger Bats Back Criticism of New Wallet Recovery Service](https://www.coindesk.com/tech/2023/05/16/ledger-bats-back-criticism-of-new-wallet-recovery-service) — CoinDesk 11. [Ledger defends crypto wallet recovery tool against hostile reaction](https://www.theblock.co/post/230992/ledger-defends-crypto-wallet-recovery-tool) — The Block 12. [Crypto Wallet Provider Ledger Delays Key-Recovery Service After Uproar](https://www.coindesk.com/business/2023/05/23/crypto-wallet-provider-ledger-postpones-release-of-key-recovery-service-after-public-criticism) — CoinDesk 13. [Ledger Nano X Review (2026 Updated): Is It Worth $149?](https://coinbureau.com/review/ledger-nano-x) — Coin Bureau --- --- title: "Trezor Safe 5: Open Source Grows Up and Adds a Secure Chip" lang: "en" type: "review" product: "trezor-safe-5" rating: 4.2 --- # Trezor Safe 5: Open Source Grows Up and Adds a Secure Chip _The first genuinely touch-friendly Trezor finally pairs open firmware with a real secure element — but it is no longer the top of the range._ **Rating: 4.2 / 5** ## Verdict The Safe 5 fixes the historic Trezor weakness — no secure element — by adding an EAL6+ Optiga chip while keeping the firmware fully open source. It is a polished, trustworthy device, but the newer Safe 7 now sits above it, the secure element's own firmware is still closed Infineon code, and mobile support remains limited. A strong pick that is one model short of being the flagship. ## What's good - EAL6+ Infineon Optiga Trust M secure element, added specifically to stop physical seed-extraction attacks that plagued older Trezors - Firmware is fully open source (GPL-3.0) and independently reviewable - Bright 1.54" color touchscreen with haptic feedback — the nicest Trezor UX yet - Supports Shamir Backup and thousands of assets via the mature Trezor Suite - Competitive price (official $129) for a modern secure-element device ## What's not - The Optiga secure element runs Infineon's closed, un-updateable firmware — Trezor guarantees public documentation and review, not open SE code - Older Trezor One and Model T had no secure element and were physically seed-extractable (Ledger Donjon 2019, Kraken 2020) - The newer Safe 7, with an open/auditable Tropic Square secure element, now sits above the Safe 5 in the lineup - iOS support is limited (view/receive/buy only; no send or setup on iPhone) - Small screen and Suite's learning curve; some coins (e.g. Solana SPL tokens) aren't fully managed in Suite **Buy it if:** Users who want an open-source wallet with a modern secure element and a genuinely pleasant touchscreen, at a mid-range price. **Skip it if:** Buyers who want the most auditable secure element available today (look at the Safe 7) or full-featured iPhone use. ## Full review The Trezor Safe 5 represents Trezor growing out of a long-standing criticism. For years Trezor's calling card was radical openness — fully open-source firmware you could inspect line by line — paired with an uncomfortable weakness: no secure element. The Safe 5 keeps the openness and adds an Infineon Optiga Trust M, a chip certified to Common Criteria EAL6+, chosen specifically because Infineon allows public review of it without an NDA. Wrap that in a bright 1.54-inch color touchscreen with haptic feedback and you get the most refined Trezor to date, at an official price of $129. To understand why the secure element matters, look at the attacks it answers. In 2019 Ledger's Donjon lab demonstrated an unfixable seed-extraction attack on the Trezor One and Model T, pulling the seed in minutes with about $100 of gear, because the secret lived on a general-purpose microcontroller. In early 2020 Kraken Security Labs showed a voltage-glitching variant needing roughly 15 minutes and $75 of hardware. Both required physical possession, and a strong passphrase mitigated them, but they were real and unpatchable by design. The Safe line exists to close that hole. It largely does. The secret material is now guarded by the Optiga secure element rather than a bare MCU, which defeats those cheap glitching attacks. The honest caveat is that the secure element itself runs closed Infineon firmware — Trezor gives you open documentation and the right to review, not open silicon. And the fix is not a magic shield: in March 2025 Ledger Donjon showed you can still glitch the microcontroller on the related Safe 3, which underlines the point that it is the secure element, not the MCU, doing the protecting. This is a more layered, more honest security story than before, not an absolute one. The everyday experience is the best Trezor has offered. The color touchscreen makes PIN and passphrase entry and address confirmation far nicer than the old two-button devices, though independent reviewers note the touch PIN can take a couple of tries and a stylus helps. Trezor Suite is mature and privacy-respecting, supports Shamir Backup for splitting your seed into multiple shares, and handles thousands of assets. The rough edges are on mobile — iOS is limited to viewing, receiving and buying, with no send or initial setup — and a few assets like Solana SPL tokens are not fully managed in Suite. The biggest strategic caveat is internal: the Safe 5 is no longer the flagship. In October 2025 Trezor launched the Safe 7, built around Tropic Square's TROPIC01, marketed as the first transparent, auditable secure element — the thing open-source purists always wanted. That does not make the Safe 5 bad; it makes it the value model beneath a more ideologically pure sibling. (Even the Safe 7 is not invincible: in mid-2026 a laser fault-injection flaw was disclosed in TROPIC01, though keys aren't stored on that chip so funds were unaffected.) Overall the Safe 5 earns a strong recommendation with clear eyes. It is open where it counts, hardened where it used to be soft, and pleasant to use, at a fair price. If you specifically want the most auditable hardware available, budget for the Safe 7; if you want an excellent open-source wallet and don't need to own the very top of the range, the Safe 5 is one of the easiest devices in this roundup to recommend. **Bottom line:** The Trezor that finally answers its critics on secure elements while staying open source — just no longer the top model in its own family. ## In the shop [Trezor Safe 5](https://nuri.com/shop/hardware-wallets/trezor-safe-5) — $169 ## Sources (13) 1. [Trezor Safe 5 | Secure Crypto Hardware Wallet](https://trezor.io/trezor-safe-5) — Trezor 2. [Secure Elements in Trezor Safe devices](https://trezor.io/learn/security-privacy/how-trezor-keeps-you-safe/secure-elements-in-trezor-safe-devices) — Trezor Knowledge Base 3. [trezor/trezor-firmware (Firmware Monorepo)](https://github.com/trezor/trezor-firmware) — GitHub / Trezor 4. [Unfixable Seed Extraction on Trezor – A practical and reliable attack](https://www.ledger.com/blog/unfixable-key-extraction-attack-on-trezor) — Ledger Donjon 5. [Kraken Identifies Critical Flaw in Trezor Hardware Wallets](https://blog.kraken.com/product/security/kraken-identifies-critical-flaw-in-trezor-hardware-wallets) — Kraken Blog 6. [Trezor discloses potential vulnerability in older Safe 3 wallets](https://www.theblock.co/post/346018/trezor-discloses-vulnerability-safe-3-crypto-wallet-rival-ledger) — The Block 7. [Trezor Launches Trezor Safe 7: First Hardware Wallet With Transparent Secure Element](https://satoshilabs.com/news/trezor-launches-trezor-safe-7-first-hardware-wallet-with-transparent-secure-element) — SatoshiLabs 8. [Trezor Safe 7 | Hardware Wallet with TROPIC01 Secure Element](https://trezor.io/trezor-safe-7) — Trezor 9. [Open Hardware Security Goes Mainstream with TROPIC01 in Trezor Safe 7](https://www.tropicsquare.com/news-and-events/open-hardware-security-goes-mainstream-with-tropic01-in-trezor-safe-7) — Tropic Square 10. [Trezor response: TROPIC01 chip disclosure (no impact to your funds)](https://trezor.io/blog/news/Trezor-response-TROPIC01-chip-disclosure-no-impact-to-your-funds) — Trezor Team 11. [Trezor Safe 5 Wallet Review 2026: Price, Features, and Where It Sits](https://cryptoslate.com/crypto-wallets/trezor-safe-5-review/) — CryptoSlate 12. [A review of the Trezor Safe 5 hardware cryptocurrency wallet](https://bdtechtalks.com/2025/11/16/trezor-safe-5-review/) — TechTalks 13. [Your Complete Guide to Trezor Safe 5 (Trezor Safe 5 Review)](https://coinbureau.com/review/trezor-safe-5-review) — Coin Bureau --- --- title: "BitBox02 Bitcoin-only: Swiss, Open, and Refreshingly Boring" lang: "en" type: "review" product: "bitbox02-bitcoin-only" rating: 4.4 --- # BitBox02 Bitcoin-only: Swiss, Open, and Refreshingly Boring _A small, audited, fully open-source Bitcoin wallet that does the fundamentals right and asks little of you — if you can live with the tiny screen._ **Rating: 4.4 / 5** ## Verdict The Bitcoin-only BitBox02 is one of the easiest wallets here to trust: Swiss-made, fully open-source and reproducibly built, dual-chip, and independently audited, with firmware locked to Bitcoin at the factory to shrink the attack surface. Its weaknesses are ergonomic — a tiny OLED, touch sliders with a learning curve, and a historically app-centric ecosystem — rather than security ones. A quietly excellent choice for focused Bitcoiners. ## What's good - Fully open-source firmware (Apache-2.0), reproducibly built and independently verified by WalletScrutiny - Dual-chip design pairing a microcontroller with an ATECC608B secure element - Firmware locked to Bitcoin-only at the factory, deliberately reducing attack surface - Independently audited (Census Labs and others) with an active bug bounty - Swiss-made by Shift Crypto with a clear, published threat model - Compact, includes a microSD card for encrypted backups, USB-C native ## What's not - The 128x64 OLED is small and, per reviewers, a fingerprint and scratch magnet - Capacitive touch sliders have a learning curve and can be awkward when the device lies flat on a desk - Historically tied to the BitBoxApp ecosystem, though third-party wallet options have grown - The secure element (ATECC608B) is a vendor chip, so that layer isn't open silicon even though the firmware is - Pricier than the cheapest wallets (around €109 direct, ~$150 via US resellers) **Buy it if:** Bitcoin-focused users who want a fully auditable, no-drama Swiss wallet and don't mind a small screen. **Skip it if:** Anyone holding altcoins, or who wants a large color display and a plug-and-play feel. ## Full review The BitBox02 Bitcoin-only edition is the anti-drama hardware wallet. Made by Shift Crypto in Zurich and released in 2019, it is a compact dual-chip device with a small monochrome OLED, capacitive touch sensors, USB-C, and an included microSD card for encrypted backups. The Bitcoin-only firmware is locked at the factory so the device literally cannot run altcoin code, which is a clean way to shrink the attack surface. Nothing about it is flashy, and that is rather the point: it aims to do the fundamentals correctly and get out of your way. Where it earns real trust is transparency. The firmware is fully open source under Apache-2.0, and — crucially — it is reproducibly built and independently verified by WalletScrutiny, which confirmed the wallet passed all of its verification tests. That means you are not merely told the code is open; a third party has checked that the code you can read is the code running on the device. Shift Crypto also publishes an honest threat model that spells out what the wallet does and does not protect against, and runs a bug bounty. This is the posture you want from something guarding money. The hardware security rests on a dual-chip split: a general-purpose microcontroller works alongside an ATECC608B secure element, so sensitive operations are guarded by dedicated hardware rather than living in plain firmware memory. The device's firmware has been audited by Census Labs and other firms. The honest caveat, common to this whole category, is that the secure element itself is a vendor chip whose internals aren't open silicon — but the surrounding firmware, which is where most real-world bugs live, is fully open and verifiable. No specific published CVE for the BitBox02 turned up in research, which is a reasonable sign for a wallet this scrutinized. The weaknesses are almost entirely about ergonomics. Independent reviewers like Decrypt and The Block are complimentary about the security but blunt about the experience: the small OLED is a fingerprint and scratch magnet, and the capacitive touch sliders take getting used to — they can be genuinely fiddly to tap when the device is resting flat on a table. The microSD backup slot has been called finicky compared with some full-size wallets. None of this affects safety; it affects how much you enjoy day-to-day use, and it is worth handling one before deciding. Ecosystem is the other consideration. The BitBox02 was historically centered on the BitBoxApp desktop and mobile software, which is clean and beginner-friendly but meant an app-first experience rather than a bring-your-own-wallet one. Third-party integrations have broadened over time, but if you specifically want to drive everything from Sparrow or Bitcoin Core, verify current support for your setup. Pricing sits in the mid-range — roughly €109 direct from Shift Crypto, closer to $150 through US resellers — cheaper than premium air-gapped wallets, dearer than the bargain options. The verdict is that the Bitcoin-only BitBox02 is one of the most quietly recommendable devices in this roundup. It is open, audited, reproducible, Swiss-made, and focused, and its downsides are a small screen and touch controls rather than anything that should keep you up at night. If you hold Bitcoin, value verifiability, and can live with a tiny display, it is an easy wallet to trust and a hard one to regret. **Bottom line:** A fully open, independently verified, Swiss Bitcoin-only wallet whose only real flaws are a tiny screen and fiddly touch controls. ## In the shop [BitBox02 Bitcoin-only](https://nuri.com/shop/hardware-wallets/bitbox02-bitcoin-only) — $99 ## Sources (12) 1. [BitBox - The Bitcoin-only hardware wallet](https://bitbox.swiss/bitbox02/bitcoin-only/) — Shift Crypto AG 2. [BitBox02 features](https://bitbox.swiss/bitbox02/features/) — Shift Crypto AG 3. [Security on every level (audits & secure element)](https://bitbox.swiss/bitbox02/security-features/) — Shift Crypto AG 4. [BitBox threat model](https://bitbox.swiss/bitbox02/threat-model/) — Shift Crypto AG 5. [About us (company background)](https://bitbox.swiss/about/) — Shift Crypto AG 6. [BitBoxSwiss/bitbox02-firmware](https://github.com/BitBoxSwiss/bitbox02-firmware) — GitHub / Shift Crypto 7. [BitBox02 review: Small, secure, expensive](https://decrypt.co/18792/bitbox02-review-small-secure-expensive) — Decrypt 8. [The Block Review: BitBox02](https://www.theblock.co/post/43675/the-block-review-bitbox02) — The Block 9. [BitBox02 hardware wallet (official shop)](https://shop.bitbox.swiss/en/products/bitbox02-80/) — BitBox Shop 10. [BitBox02 Hardware wallet test: security, price & more (2026)](https://www.hardware-wallets.net/bitbox02-review/) — hardware-wallets.net 11. [WalletScrutiny - BitBox02 hardware wallet](https://walletscrutiny.com/hardware/bitBox2/) — WalletScrutiny 12. [BitBox02 Hardware Wallet (Bitcoin Only Edition)](https://www.thecryptomerchant.com/products/shift-crypto-bitbox02-bitcoin) — The Crypto Merchant --- --- title: "Keystone 3 Pro: Big-Screen Air-Gapping With a Trust Asterisk" lang: "en" type: "review" product: "keystone-3-pro" rating: 3.9 --- # Keystone 3 Pro: Big-Screen Air-Gapping With a Trust Asterisk _A slick, fully air-gapped QR wallet with three secure chips and a big touchscreen — whose openness and origins deserve a closer look._ **Rating: 3.9 / 5** ## Verdict The Keystone 3 Pro delivers a genuinely air-gapped QR workflow, three secure elements, a fingerprint sensor and a large 4-inch touchscreen at a competitive $149. It is mostly open source and has been audited, but its builds are not fully reproducible, it leans on an Android-based OS, and its China-founded origins raise supply-chain questions some buyers will care about. Great hardware, with trust caveats you should weigh honestly. ## What's good - Fully air-gapped: signing happens only via QR codes (and microSD), with USB-C used for power only - Three secure elements, including a chip dedicated to protecting fingerprint data - Large 4-inch 480x800 touchscreen makes transaction verification easy to read - Anti-tamper self-destruct circuit that wipes keys on physical intrusion - Broad support (5,500+ assets, 45+ software wallets) with no mandatory proprietary app - Competitive price (~$149) for the feature set ## What's not - Firmware is open source but ships some pre-compiled binaries (MH1903 MCU library, QR library), so builds are not fully reproducible — you're partly trusting binaries - Runs an Android-based OS, which independent critics note is a larger attack surface than a minimal firmware - Founded by a China-based team (formerly Cobo Vault) with devices manufactured in China — a supply-chain/origin trust concern for some buyers - A high-severity tamper-response issue and a firmware vulnerability were found in audits (both reported fixed) — good disclosure, but a reminder it's not flawless - Bulkier than pocket wallets, and native staking/features are limited versus the companion-app ecosystem **Buy it if:** Users who prioritize a true air-gap and a large, readable screen, and are comfortable with the device's origins and partial reproducibility. **Skip it if:** Purists who require fully reproducible open-source builds, or buyers uncomfortable with China-manufactured key-management hardware. ## Full review The Keystone 3 Pro is one of the most feature-rich air-gapped wallets on the market. It signs transactions exclusively via QR codes (with microSD as an alternative), using its USB-C port for power only — there is no USB-data, Bluetooth, WiFi or NFC signing path, which is the strongest form of air-gap. It stacks three secure elements, a fingerprint sensor, an anti-tamper self-destruct circuit that wipes keys if the device is opened, and a large 4-inch 480x800 touchscreen that makes verifying addresses genuinely comfortable. At around $149 with support for thousands of assets and dozens of software wallets, the spec sheet is excellent. The air-gap is the headline and it is real. Because the device never establishes a data connection, the entire class of USB and wireless attack vectors is designed out; a compromised computer can hand the Keystone an unsigned transaction as a QR code and receive a signed one back, but it has no channel to reach the keys. The three secure elements split duties — two guard key material, and a dedicated chip protects the fingerprint data — so no single chip holds everything. The device is uniquely well-integrated with wallets like MetaMask over QR, which is a nice practical touch. Openness is where the honest asterisks begin. Keystone publishes its firmware on GitHub and provides a checksum-verification workflow, and that is meaningfully more transparent than a closed device. But the build is not fully reproducible: the MH1903 microcontroller library and the QR-code library ship as pre-compiled binaries due to IP restrictions, which independent guides like Michael Flaxman's 10x Security guide flag directly — with binaries in the mix, you are partly trusting code you cannot rebuild from source. That same critique notes the device runs an Android-based OS, a larger and busier attack surface than the minimal firmware on a BitBox. To Keystone's credit, its security process is visible. A Keylabs audit in late 2023 found one high-severity issue (an inadequacy in the tamper-response circuit) plus several low-severity findings, all reported resolved, and in 2024 Offside Labs disclosed a firmware vulnerability that was neutralized in version 1.2.8. Publishing these is the right behavior and better than silence. It is also a reminder that the self-destruct and secure-element story is not magic — the tamper response itself needed fixing — so treat the marketing claims as engineering in progress rather than guarantees. Then there is origin. Keystone was formerly Cobo Vault, built by a China-founded team originally serving Chinese Bitcoin miners, and rebranded to Keystone in 2021; the devices are manufactured in China. For many users this is a non-issue — open code and an air-gap are exactly the mitigations that reduce how much you must trust any manufacturer. But for buyers who factor geopolitics and supply-chain provenance into key-management hardware, it is a legitimate consideration worth naming plainly rather than dismissing. Combined with the partial reproducibility, it is the main reason a strong device doesn't score higher here. The verdict is that the Keystone 3 Pro is impressive hardware with a couple of trust caveats you should decide on with open eyes. If a true air-gap, a big readable screen and broad wallet support are your priorities, and you are comfortable with the origin and the not-fully-reproducible build, it is one of the most usable air-gapped wallets available. If you demand end-to-end reproducible open-source builds or are uneasy about China-manufactured key hardware, the BitBox02 answers those specific worries more cleanly. **Bottom line:** Excellent air-gapped hardware with a great screen, held back from a top score by partial reproducibility and origin-trust caveats worth weighing. ## In the shop [Keystone 3 Pro](https://nuri.com/shop/hardware-wallets/keystone-3-pro) — $129 ## Sources (12) 1. [Keystone 3 Pro — Secured Open Source Air-Gapped Hardware & Cold Wallet](https://shop.keyst.one/products/keystone-3-pro) — Keystone (official store) 2. [Keystone 3 Pro | Air-Gapped Crypto Hardware Wallet](https://keyst.one/shop/products/keystone-3-pro) — Keystone 3. [KeystoneHQ/keystone3-firmware](https://github.com/KeystoneHQ/keystone3-firmware) — GitHub / KeystoneHQ 4. [KeystoneHQ/keystone-se-firmware](https://github.com/KeystoneHQ/keystone-se-firmware) — GitHub / KeystoneHQ 5. [Open Source Code Verification for Firmware](https://guide.keyst.one/docs/verify-checksum) — Keystone Guide 6. [Bind MetaMask with Keystone (air-gapped QR workflow)](https://support.keyst.one/3rd-party-wallets/eth-and-web3-wallets-keystone/bind-metamask-with-keystone) — Keystone Support 7. [Supported Wallets and Assets](https://keyst.one/supported-wallets-and-assets) — Keystone 8. [Keystone x Offside Labs: Redefining the Hardware Wallet Security](https://blog.keyst.one/keystone-x-offside-labs-redefining-the-hardware-wallet-security-92fcb73dbf6c) — Keystone Blog 9. [Deep Dive into Next-Gen Hardware Wallet: Crashing Keystone3 Pro Audit](https://blog.keyst.one/deep-dive-into-next-gen-hardware-wallet-crashing-keystone3-pro-audit-2729bc551d7b) — Keystone Blog 10. [10x Bitcoin Security Guide — Keystone (formerly Cobo Vault)](https://btcguide.github.io/known-issues/hardware/keystone) — Michael Flaxman / btcguide 11. [Keystone 3 Pro Review 2026: Safe Hardware Wallet?](https://coinbureau.com/review/keystone-3-pro-review) — Coin Bureau 12. [S8 E7: Lixin Liu on Cobo Vault Hardware Wallet (Rebranded as Keystone)](https://bitcoin-takeover.com/s8-e7-lixin-liu-on-cobo-vault-hardware-wallet-keystone/) — Bitcoin Takeover --- --- title: Nuri Card & Bank Support FAQ type: support-faq updated: 2026-07-16 --- # Nuri Card & Bank Support FAQ Cardholder support for the Nuri Card (issued on Wirex BaaS): declines, holds, refunds and chargebacks, limits, Apple Pay / Google Pay, and SEPA/ACH bank accounts. Source of truth for the website and for agents. ## Card declines ### 1. Why was my Nuri Card declined? A card payment can be declined for many reasons. The most common by far is simply not enough money on the card at the moment of payment — including cases where an earlier hold or pending charge is still reserving part of your balance. Other frequent causes are a wrong PIN or CVC/expiry entered, a card that is frozen or not yet activated, a merchant or country that is restricted, or the bank’s fraud checks stepping in on an unusual transaction. The message shown at the terminal or in the app tells you which of these applied. See the decline-message reference below for the exact meaning of each one. Source: https://docs.wirexapp.com/docs/decline-codes ### 2. What does my decline message mean? (full reference) Here is what each decline message means in plain language: | Message | What it means | | --- | --- | | InsufficientFunds | Not enough available balance — check for pending holds too. | | DoNotHonor | Declined without a specific reason (generic bank decline). Try again or contact support. | | BlockedCard | The card is frozen or restricted. | | Fraud | Suspected fraud — the card may be flagged as compromised, lost or stolen. | | InvalidCVV2OrCIDOrExpiryDate | Wrong CVC/CVV or expiry date entered. | | InvalidPin | Wrong PIN entered. | | ExpiredCard | The card’s expiry date has passed. | | CardNotActive | The card is not activated, or it has been closed. | | TransactionNotPermittedToCardholder | This type of transaction isn’t allowed on the card. | | AllowedNumberOfPINTriesIsExceeded | Too many wrong PIN attempts (4 total) — the card is now blocked. | | CashWithdrawalAmountIsExceeded | ATM withdrawal amount limit reached. | | CashWithdrawalCountIsExceeded | Maximum number of ATM withdrawals reached. | | InvalidMerchant | The merchant isn’t supported. | | InvalidCurrency | The transaction currency isn’t supported. | | BadAVS | The billing address check (AVS) didn’t match. | | DeclinedExternalAuthorization | Declined on the merchant’s / acquirer’s side. | | DuplicatedTransaction | A duplicate of a transaction that already went through. | | GeneralTransactionDecline | Generic decline — try again. | | Error / FormatError / TimeOutIssuer | A temporary technical error — wait a moment and retry. | > If a payment keeps failing and none of these fit, contact Nuri support with the date, amount and merchant so we can look it up. Source: https://docs.wirexapp.com/docs/decline-codes ### 3. It says insufficient funds but I have money — why? The most common reason is a hold (pre-authorisation) that is still reserving part of your balance from an earlier payment — for example a fuel station, hotel or car rental. That reserved amount isn’t available to spend until the hold clears or expires. Check your recent activity for a pending item. See “Holds & pending charges” below for how long each type lasts. Source: https://docs.wirexapp.com/docs/holds-and-authorizations ### 4. My card is blocked after entering the wrong PIN For security, the card is blocked after 4 wrong PIN attempts (message: AllowedNumberOfPINTriesIsExceeded). Contact Nuri support to unblock the card and confirm or reset your PIN. Don’t keep retrying — that won’t help once the limit is reached. Source: https://docs.wirexapp.com/docs/decline-codes ## Holds & pending charges ### 5. Money is missing from my balance but I didn’t spend it This is almost always a hold (pre-authorisation), not a final charge. Merchants like fuel stations, hotels and car-rental companies temporarily reserve an amount to make sure the funds are there. The reserved money isn’t gone — it’s held until the real charge (the “clearing”) arrives, at which point the hold is released and replaced by the actual amount. The sections below explain the most common holds and how long they last. Source: https://docs.wirexapp.com/docs/holds-and-authorizations ### 6. Why did a car rental hold extra money? Car-rental and trailer-rental companies typically place a hold of around 20% on top of the authorised amount, as a buffer for possible extras such as fuel, tolls, fines or late returns. When the final charge arrives, any excess is released automatically. If the final amount is higher than the original authorisation, the difference is charged; otherwise the 20% buffer is returned to you. Source: https://docs.wirexapp.com/docs/holds-and-authorizations ### 7. A fuel station charged more than I pumped, or the hold won’t clear At pay-at-pump fuel dispensers the card is pre-authorised before you know the final amount, so a fixed hold is placed first — sometimes €1/£1, sometimes as much as €99/£99 depending on the network. This is a hold, not the final charge. When the station sends the real amount (the clearing), the hold is released and replaced by what you actually spent. > Fuel pre-authorisation holds can last up to 32 days by design. If no clearing arrives within 32 days, the hold expires and the money is released automatically. It can’t be released manually before then unless the merchant sends the clearing. Source: https://docs.wirexapp.com/docs/holds-and-authorizations ### 8. My balance went negative (e.g. after a transport/TfL charge) Some merchants — notably transit systems like Transport for London — process transactions offline and submit them for payment after your journey. If your balance is too low when that charge finally clears, it can still go through and leave the card with a negative balance. This is initiated by the merchant or card network, not by Nuri or Wirex, and can’t be blocked or reversed at that stage. To fix it, top up the card to clear the negative balance — there’s no minimum; even a small negative amount must be covered. The card stays restricted until the balance is positive again. If you’re unsure of the exact amount, contact Nuri support and we’ll confirm it. Once topped up, the card is unblocked automatically. Source: https://docs.wirexapp.com/docs/holds-and-authorizations ## Refunds, disputes & chargebacks ### 9. How long does a refund for a failed transaction take? Refunds for failed transactions are completed within 32 calendar days. This window is fixed — it doesn’t change with the transaction type or the reason it failed. A reversal sometimes happens sooner, but 32 days is the maximum you should expect. Source: https://docs.wirexapp.com/docs/chargebacks-and-refunds ### 10. How do I dispute a transaction or request a chargeback? Contact Nuri support with the transaction details (date, amount, merchant) and what went wrong. We raise a dispute ticket for that specific transaction, and you can track its status through the same ticket. A chargeback then moves through five stages: (1) review and analysis of your explanation and the transaction; (2) submission to the processor and card scheme (Visa/Mastercard); (3) the merchant may accept it or send a rebuttal with evidence; (4) that evidence is reviewed; (5) a final outcome — if won, the funds are returned to you; if lost, they stay with the merchant. Source: https://docs.wirexapp.com/docs/chargebacks-and-refunds ### 11. How long does a chargeback take, and is there a deadline to file? - Filing deadline: no later than 120 days from the transaction date. - Eligible transactions: successful transactions only. - Typical processing time: 60–90 days from the transaction date. Because chargebacks run on the card schemes’ timelines, they can’t be rushed. File as early as you can within the 120-day window. Source: https://docs.wirexapp.com/docs/chargebacks-and-refunds ### 12. Is there a fee for a chargeback? A $25 administration fee applies only if the dispute is lost. If you win, no fee is charged at all. Source: https://docs.wirexapp.com/docs/chargebacks-and-refunds ### 13. Why was I debited again after a chargeback? This is standard, not a new or duplicate charge. When a chargeback is opened, the disputed amount is credited back to your balance and a temporary hold is placed on it while the case is investigated. When the case is resolved, the hold is either released (you won — the money is yours) or removed so the debit stands (you lost — the money returns to the merchant). Source: https://docs.wirexapp.com/docs/chargebacks-and-refunds ## Limits & restrictions ### 14. What are the card spending limits? | Limit | Amount | | --- | --- | | Per transaction | £30,000 | | Per day | £30,000 | | Per month | £30,000 | | Per 3 months | £75,000 | | Per 6 months | £100,000 | | Transactions per day | Unlimited | Need more? See “How do I increase my card limit?” below. Source: https://docs.wirexapp.com/docs/card-limits ### 15. What are the ATM / cash withdrawal limits? | Limit | Amount | | --- | --- | | Per day | £500 | | Per month | £5,000 | | Withdrawals per day | 5 | Source: https://docs.wirexapp.com/docs/card-limits ### 16. What are the SEPA (EUR) deposit and transfer limits? | Transaction | Max per transaction | Max per day | | --- | --- | --- | | SEPA deposit (EUR) | €250,000 | — | | SEPA transfer (EUR) | €50,000 | €50,000 | Source: https://docs.wirexapp.com/docs/card-limits ### 17. Why is a merchant or category blocked? Certain merchant categories can’t be paid with the card. These currently include: - Drugs, druggist sundries and chemicals (MCC 5122, 5169) - Direct-marketing insurance, travel and outbound telemarketing (MCC 5960, 5962, 5966) - Dating and escort services (MCC 7273) - Massage parlors (MCC 7297) - Government-licensed gambling (MCC 7801) If a payment to one of these is declined, it’s by policy rather than a fault with your card. Source: https://docs.wirexapp.com/docs/card-limits ### 18. Why can’t I pay in a certain country or currency? Payments to merchants in sanctioned or restricted countries are blocked. These include Afghanistan, Belarus, Bosnia and Herzegovina, Central African Republic, Cuba, DR Congo, Ethiopia, Iran, Iraq, Lebanon, Libya, Myanmar, Nicaragua, North Korea, Palestine, Russia, Sudan, Syria, Venezuela and Zimbabwe. A few currencies are also not supported for card transactions: BDT (Bangladeshi Taka), BHD (Bahraini Dinar), BYN/BYR (Belarusian Ruble), PKR (Pakistani Rupee), RUB (Russian Ruble) and SAR (Saudi Riyal). Source: https://docs.wirexapp.com/docs/card-limits ## Account & payments ### 19. Why is the exchange rate different from the one I see online? The rate on a card transaction can differ from the market rate you see on Google, and that’s expected. Depending on the currency, a payment may be converted through more than one step (for example a local currency → GBP → USD), and a foreign-exchange margin is applied. - Local currencies (UAH, RON, CZK, …): converted local → GBP → USD, plus FX. - EUR: converted EUR → USD, plus FX. - USD: no conversion. Source: https://docs.wirexapp.com/docs/account-operations ### 20. How do I cancel a subscription or recurring payment? The most reliable way is to cancel directly with the merchant — the card issuer can’t unlink a card from an active subscription, block a single merchant, or cancel a subscription on your behalf. If a merchant keeps charging and won’t stop, the alternative is to have the card reissued. A new card number stops future charges — but note the old number becomes invalid, so any other services saved to that card will need updating. Source: https://docs.wirexapp.com/docs/account-operations ### 21. How do I get a transaction statement? Nuri support can generate a statement for you through the customer support portal. Contact us with the period you need and we’ll produce it. Source: https://docs.wirexapp.com/docs/account-operations ### 22. How do I check my remaining spending limit? Contact Nuri support and we can check your remaining unused limit for you through the support portal. Source: https://docs.wirexapp.com/docs/account-operations ### 23. How do I withdraw my balance after closing my account? Your card wallet is self-custody — the funds stay at your own address, not held by Wirex — so recovery goes through Nuri, not Wirex. Contact Nuri support and we’ll guide you through the withdrawal/recovery process for your account. Source: https://docs.wirexapp.com/docs/account-operations ## Raising your limit ### 24. How do I increase my card limit? The standard cap is £30,000 per transaction and per month. Higher limits can be approved with proper justification and documentation. You’ll be asked for: the limit amount and whether it’s a one-off or ongoing; the reason for the increase; and evidence of your source of wealth (how your wealth was built) and, for one-off transactions, source of funds (where the specific money came from). | Request type | Source of funds | Source of wealth | | --- | --- | --- | | One-off | Required | Required | | Ongoing | Not required | Required | Start a limit-increase request with Nuri support and we’ll tell you exactly what to provide. Source: https://docs.wirexapp.com/docs/card-limit-increase ### 25. What documents do I need for a higher limit? You’ll usually need identity and address verification (passport / national ID / driving licence, plus a utility bill or bank statement from the last 3 months), and evidence for where the money comes from. Typical evidence by source: | Source | Documents | | --- | --- | | Salary | Recent payslip + bank statement | | Sale of property | Contract of sale + bank statement showing proceeds | | Savings | 3+ months of bank statements showing the balance | | Loan | Loan agreement + bank statement | | Inheritance / gift | Testament or donor letter + bank statement | | Investment / trading | Exchange screenshots + transaction history | | Pension | Fund statement + bank statement | | Tax refund | Tax return (within 12 months) + bank statement | Source: https://docs.wirexapp.com/docs/card-limit-increase ### 26. How long does a limit increase take? Once you’ve submitted everything, review typically takes around 24 hours. If approved, the new limit is applied the same day (when submitted before 1pm CET) or the next business day. Outcomes are: approved in full, an alternative (lower) limit offered, or declined with feedback. Source: https://docs.wirexapp.com/docs/card-limit-increase ## Apple Pay & Google Pay ### 27. Apple Pay / Google Pay won’t add my card A previous failed or inactive attempt to add the card can block new attempts. The fix is usually to have the stale token deactivated: contact Nuri support and ask us to deactivate the affected card tokens, after which you should be able to add the card again. Before retrying, remove the card from any wallets or websites where an inactive copy might still be stored. Source: https://docs.wirexapp.com/docs/tokens-and-wallet-provisioning ### 28. What do the Apple Pay / Google Pay card statuses mean? | Status | Meaning | | --- | --- | | Active | Card successfully added and usable for payments. | | Inactive | Card added but unused, provisioning failed, or removed from the wallet. | | Deactivated | Card removed from the associated wallet or service. | Source: https://docs.wirexapp.com/docs/tokens-and-wallet-provisioning ### 29. Apple Pay keeps failing to add my card (“red path”) Sometimes Apple/Visa’s own provisioning service flags a device as suspicious during tokenisation and refuses to add the card. This is triggered by that antifraud check on the device — not by your card’s status or by Nuri. These cases are reviewed individually and, honestly, can’t always be overridden — resolution isn’t guaranteed. Contact Nuri support with your details and we’ll escalate it, but the decision ultimately sits with the provisioning service. Source: https://docs.wirexapp.com/docs/tokens-and-wallet-provisioning ## Bank accounts (SEPA & ACH) ### 30. Which countries can get a SEPA (EUR) account? A SEPA (EUR) account is available in 29 countries: Austria, Belgium, Bulgaria, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden and the United Kingdom. Source: https://docs.wirexapp.com/docs/bank-account-availability ### 31. Which countries can get an ACH (USD) account? An ACH (USD) account is available in 48 countries plus all US states and territories: Andorra, Argentina, Australia, Austria, Belgium, Brazil, Bulgaria, Chile, Colombia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Gibraltar, Greece, Hong Kong, Hungary, Iceland, Indonesia, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malaysia, Malta, Mexico, Monaco, Montenegro, Netherlands, Norway, Peru, Poland, Portugal, Romania, Singapore, Slovakia, Spain, Sweden, Switzerland, Taiwan, Thailand, United Kingdom, United States and Vietnam. Source: https://docs.wirexapp.com/docs/bank-account-availability ### 32. How do I check whether a bank account is available for me? Your available account types show up as capabilities on your profile, each with a status: - Active — the bank account is available and usable. - NotFulfilled — you need to complete additional verification first. - NotAvailable — not available for your country. Developers integrating the API can read these from the user endpoint (GET /api/v2/user), which returns SepaAccount / AchAccount capabilities and their status. Source: https://docs.wirexapp.com/docs/bank-account-availability