The phone is the constraint.

Five short papers, separate on purpose. Each owns one job the device cannot drop. The landing page is the popularization; these are the arguments.

Framing

A phone wallet

What a phone will not be (a full node, a thin client of someone else’s node), and what that forces: foreground-only, this-device keychain, Taproot-only, fresh and forward-only, one dependency.

Read mobile.md ›

What’s mine?

The read side

Who scans, what they learn, what it costs. Compact filters by default, bounded mempool windows, an honest threat model, and why BIP37 is the historically important wrong answer.

Read read-side.md ›

How it pays

The write side

Coin selection, a fee policy that admits it is blind, signing that holds the seed for one call, silent-payment send, and P2P relay that survives the app being killed.

Read write-side.md ›

Shared custody

Vaults

Two Taproot policies — NUMS + multi_a k-of-n, and MuSig2 n-of-n — coordinated by PSBTv2. No coordinator server.

Read vaults.md ›

Moving a wallet in

Import

There is no back-scan. The previous wallet ships its answers; this one checks them forward from a height. The bundle is the history.

Read import.md ›