Clench Wallet
Secure non-custodial Bitcoin wallet with multisig support
新版本 0.3.26
Security hardening release:
- Uses explicit Android OS entropy for new seeds and rejects weak external-signer signature policies.
- Strengthens authentication, secure screens, lifecycle cleanup, Electrum TLS/Tor, backups, and hostile NFC/QR/file handling.
- Strengthens TAPSIGNER setup proof binding; direct TAPSIGNER payment signing remains unavailable.
- Keeps hardware-wallet transport to QR, intentional NFC taps, or user-selected files—never USB or Bluetooth data connections.
- Adds two-gate r
- Uses explicit Android OS entropy for new seeds and rejects weak external-signer signature policies.
- Strengthens authentication, secure screens, lifecycle cleanup, Electrum TLS/Tor, backups, and hostile NFC/QR/file handling.
- Strengthens TAPSIGNER setup proof binding; direct TAPSIGNER payment signing remains unavailable.
- Keeps hardware-wallet transport to QR, intentional NFC taps, or user-selected files—never USB or Bluetooth data connections.
- Adds two-gate r
Clench is a Bitcoin-only, non-custodial Bitcoin wallet for Android. It uses Bitcoin Dev Kit and stores wallet data locally on the device.
Wallet features:
- Create single-sig and multisig wallets.
- Import watch-only wallets from descriptors.
- Create or restore BIP-39 seed phrase wallets with an optional passphrase.
- Use native SegWit, nested SegWit, legacy, and Taproot script types.
- Connect to Electrum servers, including personal servers and Tor SOCKS5 routes.
- Use coin control, UTXO freezing, labels, batch payments, RBF fee bumping, CPFP, cancel replacement attempts, raw transaction import, and sweep flows.
- Run node diagnostics for Electrum route, Tor mode, TLS pinning, server version, and tip height.
Hardware-wallet features:
- Exchange PSBTs by animated QR, BBQr, an intentional NFC tap, microSD/user-selected file import, or signed-return import where supported.
- Clench does not communicate with signing devices over USB or Bluetooth. A signer may still use USB for power.
- Work with QR-based signers such as SeedSigner, Keystone, Foundation Passport, and Blockstream Jade.
- Work with Coldcard Q, Coldcard Mk4, and Coldcard Mk5 transfer paths.
- Check Tapsigner NFC Tap Protocol status.
- Sweep SATSCARD active slots with certificate verification and explicit CVC-authenticated unseal confirmation.
- TAPSIGNER setup, verification, xpub import, multisig policy import, and encrypted backup are available; direct payment signing is a temporary software limitation.
- Require explicit broadcast confirmation after hardware-wallet signing.
Security and privacy features:
- Encrypt keys with Android Keystore.
- Encrypt the local wallet database with SQLCipher.
- Protect wallet access with PIN and biometric authentication where available.
- Validate signed PSBTs and finalized transactions before broadcast.
- Avoid analytics, advertising SDKs, Firebase, Google Play Services, crash reporting services, and account sign-in.
Network use is limited to wallet sync and optional user-triggered fee or price data lookups.
Clench is free software under the MIT License.
Wallet features:
- Create single-sig and multisig wallets.
- Import watch-only wallets from descriptors.
- Create or restore BIP-39 seed phrase wallets with an optional passphrase.
- Use native SegWit, nested SegWit, legacy, and Taproot script types.
- Connect to Electrum servers, including personal servers and Tor SOCKS5 routes.
- Use coin control, UTXO freezing, labels, batch payments, RBF fee bumping, CPFP, cancel replacement attempts, raw transaction import, and sweep flows.
- Run node diagnostics for Electrum route, Tor mode, TLS pinning, server version, and tip height.
Hardware-wallet features:
- Exchange PSBTs by animated QR, BBQr, an intentional NFC tap, microSD/user-selected file import, or signed-return import where supported.
- Clench does not communicate with signing devices over USB or Bluetooth. A signer may still use USB for power.
- Work with QR-based signers such as SeedSigner, Keystone, Foundation Passport, and Blockstream Jade.
- Work with Coldcard Q, Coldcard Mk4, and Coldcard Mk5 transfer paths.
- Check Tapsigner NFC Tap Protocol status.
- Sweep SATSCARD active slots with certificate verification and explicit CVC-authenticated unseal confirmation.
- TAPSIGNER setup, verification, xpub import, multisig policy import, and encrypted backup are available; direct payment signing is a temporary software limitation.
- Require explicit broadcast confirmation after hardware-wallet signing.
Security and privacy features:
- Encrypt keys with Android Keystore.
- Encrypt the local wallet database with SQLCipher.
- Protect wallet access with PIN and biometric authentication where available.
- Validate signed PSBTs and finalized transactions before broadcast.
- Avoid analytics, advertising SDKs, Firebase, Google Play Services, crash reporting services, and account sign-in.
Network use is limited to wallet sync and optional user-triggered fee or price data lookups.
Clench is free software under the MIT License.
- 作者: Clench Wallet
- 许可: MIT License
- 网站
- 问题跟踪系统
- 源代码
- 更新日志
- 构建元数据
- 可重复性状态
版本
尽管下面提供了 APK 安装包的下载选项,但你应该注意,以这种方式安装将不会收到更新通知,这是一种不太安全的下载方式。 我们建议你安装使用 F-Droid 客户端。
下载 F-Droid-
arm64-v8aarmeabi-v7ax86_64该版本需要 Android 8.0 及以上版本。
此包由原始开发者构建并签名,并保证对应于此源代码 tarball。
-
arm64-v8aarmeabi-v7ax86_64该版本需要 Android 8.0 及以上版本。
此包由原始开发者构建并签名,并保证对应于此源代码 tarball。
-
arm64-v8aarmeabi-v7ax86_64该版本需要 Android 8.0 及以上版本。
此包由原始开发者构建并签名,并保证对应于此源代码 tarball。
新版本 0.3.23
Removes unused Bluetooth permissions and stale USB/Bluetooth/Virtual Disk signer claims. Clench now enforces QR, intentional NFC tap, and user-selected file/removable-card transports, and verifies the chain code used when setting up TAPSIGNER.
新版本 0.3.21
Fixes Clench phone-signer multisig wallet creation and unavailable-authentication signing dead ends. Multisig PSBT reviews now show an estimated final signed size and fee rate. Improves Bitcoin wallet search metadata for F-Droid.