Fast on-device scanning
Your wallet detects incoming payments by scanning the chain locally for the best balance of speed and battery. No server ever learns which transactions are yours.
Receive to a single, reusable address that produces a unique, unlinkable output on-chain for every payment powered by silent payments, on by default.
Built on open standards
Silent payments
Reusing an address destroys your privacy, but handing out a fresh one for every payment breaks down in practice. Fire a few payments and watch what chain analysis sees — brightness is exposure.
ADDRESS REUSE
Every payment traces back to the same address — all linkable.
SILENT PAYMENT
Each payment lands somewhere new — nothing links them.
Features
Three things made possible by putting silent payments at the core of the wallet — not bolted on.
Your wallet detects incoming payments by scanning the chain locally for the best balance of speed and battery. No server ever learns which transactions are yours.
Save someone's SP address once, pay them forever. Every payment still lands on a different on-chain address and none of them are linkable. Only possible with silent payments.
Break one payment into multiple outputs inside a single transaction, so change and payment look alike. Harder for chain analysis ,not impossible, and we say so.
Under the hood
Four steps, zero interaction — the protocol behind the calm.
Your sp1… address encodes a scan key and a spend key. Put it in a bio or on an invoice — it reveals nothing about your balance or history.
Using ECDH between their input keys and your scan key, their wallet computes a one-time taproot output only you can recognize — per BIP-352. No interaction with you, ever.
Shroud pulls compact tweak data for new blocks and checks candidates on your device. The server you connect to serves blocks to everyone; it learns nothing about which outputs are yours.
On-chain, each payment is an ordinary taproot output at a never-before-seen address. Observers can't connect them to each other — or to the address you published.
Privacy & trust
Self-custody, no accounts, and nothing phoning home. Where a protection has limits, we say so — credibility is the product.
Keys are generated and stored on your device and never leave it. Your coins are yours — Shroud can't freeze, seize, or lose them.
Download and use it. No sign-up, no email, nothing to identify you. We couldn't hand over your data if asked — we don't have any.
No analytics, no crash reporters, no tracking pixels. The only traffic leaving the app is requests to the backend you choose.
Route all wallet traffic over Tor to keep your IP address out of the picture at the network layer.
Connect your own node, or pick the Electrum server you trust. No forced defaults, no silent fallback.
Every release can be rebuilt from public source and checked byte-for-byte against what you installed.
Verify yours →SECURITY & THREAT MODEL
Privacy tools that overpromise get people hurt. Here is exactly what Shroud protects against — and what it can't.
How we stack up
Get Shroud
Don't trust the download button — check the build. Every release is signed and reproducible from public source.
Built in the open
MIT-licensed and developed in public — funded by grants and donations, never by your data.
Shipped in v1.0 — receive to one reusable address and send to any sp1… address, with unique outputs on-chain for every payment.
Shipped in v1.0.2 — route all traffic over Tor, connect your own node or a trusted Electrum server, and split payments in one tap.
Next up — an external audit of key handling, the scanning pipeline, and the build process, published in full.
Next up — sign with external devices while scan keys stay on the phone, so detection keeps working without exposing spend keys.
Exploring — researching how each composes with silent payments without weakening the threat model. No promises until the design is sound.
No — and anyone who says otherwise is selling something. Silent payments remove address-level linkability on-chain, but privacy has layers. See “Honest about the limits” for exactly what Shroud does and doesn't cover.
Shroud is MIT-licensed and free. Development is funded by grants and donations — never by your data, and there is nothing to upsell.
No. You can connect to any Electrum server you trust, or your own node if you have one. Either way, scanning happens on your device — the server never learns which outputs are yours.
Nothing happens to your coins. Your keys live on your device, and BIP-352 is an open standard — any compatible wallet can restore from your seed phrase.
Android 10+ via direct APK, F-Droid, or the Play Store, and iOS 16+ via the App Store.
No — Shroud pulls compact tweak data instead of full blocks and tunes scanning for the best balance of speed and battery. A typical sync takes minutes, not hours.
A small open-source team building in public. Every commit, build, and release is published — you never have to take our word for it.