Private Bitcoin payments. One address.

Receive to a single, reusable address that produces a unique, unlinkable output on-chain for every payment powered by silent payments, on by default.

Shroud wallet home screen showing a 0.00004511 BTC balance, Request and Pay buttons, and a list of unlinkable silent-payment transactions
Payment received fresh output · no link on-chain
Contact paid saved once · sp1qq…k2f4
Scanning on-device your server learns nothing
Payment split change hidden from analysis

Built on open standards

BITCOIN CORE BIP-352 Taproot TOR Electrum

Silent payments

The address problem, solved

Reusing an address destroys your privacy, but handing out a fresh one for every payment breaks down in practice. Fire a few payments and watch what chain analysis sees — brightness is exposure.

Features

Manage your privacy

Three things made possible by putting silent payments at the core of the wallet — not bolted on.

Fast on-device scanning

Your wallet detects incoming payments by scanning the chain locally for the best balance of speed and battery. No server ever learns which transactions are yours.

ON-DEVICE

Silent payment contacts

Save someone's SP address once, pay them forever. Every payment still lands on a different on-chain address and none of them are linkable. Only possible with silent payments.

Payment splitting

Break one payment into multiple outputs inside a single transaction, so change and payment look alike. Harder for chain analysis ,not impossible, and we say so.

Under the hood

How a silent payment finds you

Four steps, zero interaction — the protocol behind the calm.

Publish one address, once

Your sp1… address encodes a scan key and a spend key. Put it in a bio or on an invoice — it reveals nothing about your balance or history.

The sender derives a fresh output

Using ECDH between their input keys and your scan key, their wallet computes a one-time taproot output only you can recognize — per BIP-352. No interaction with you, ever.

Your device scans locally

Shroud pulls compact tweak data for new blocks and checks candidates on your device. The server you connect to serves blocks to everyone; it learns nothing about which outputs are yours.

Funds appear. Links don't.

On-chain, each payment is an ordinary taproot output at a never-before-seen address. Observers can't connect them to each other — or to the address you published.

Privacy & trust

What we don't do matters more

Self-custody, no accounts, and nothing phoning home. Where a protection has limits, we say so — credibility is the product.

Non-custodial, always

Keys are generated and stored on your device and never leave it. Your coins are yours — Shroud can't freeze, seize, or lose them.

No KYC, no accounts

Download and use it. No sign-up, no email, nothing to identify you. We couldn't hand over your data if asked — we don't have any.

Zero telemetry

No analytics, no crash reporters, no tracking pixels. The only traffic leaving the app is requests to the backend you choose.

Tor supported

Route all wallet traffic over Tor to keep your IP address out of the picture at the network layer.

Your node, your rules

Connect your own node, or pick the Electrum server you trust. No forced defaults, no silent fallback.

Reproducible builds

Every release can be rebuilt from public source and checked byte-for-byte against what you installed.

Verify yours →

SECURITY & THREAT MODEL

Honest about the limits.

Privacy tools that overpromise get people hurt. Here is exactly what Shroud protects against — and what it can't.

✓ Protects against

  • Address-reuse clustering — payments to you can't be linked to each other on-chain.
  • Server surveillance of your history — scanning happens on-device.
  • Network-level IP correlation — when Tor is enabled.
  • Custodial risk — no one holds your keys but you.
  • Tampered downloads — reproducible, signed builds you can verify.

✗ Does not protect against

  • A compromised device — malware with your seed phrase has your coins.
  • Sender-side leaks — if the sender doxxes the payment, cryptography can't help.
  • Amount analysis — splitting makes it harder, not impossible.
  • You publishing your own history — opsec still matters.
  • Losing your seed phrase — back it up. There is no recovery service, by design.

How we stack up

The edge, made concrete

Capability Shroud Typical wallet
Silent payments — send + receive Full support Rare / receive-only
Payment detection On-device scanning Often server-assisted
SP address as a saved contact Built in
Payment splitting for change ambiguity One tap
Custody Non-custodial Varies
KYC / accounts None Varies
Open source MIT, reproducible Varies

Get Shroud

Download it. Then verify it.

Don't trust the download button — check the build. Every release is signed and reproducible from public source.

Built in the open

Roadmap & questions

MIT-licensed and developed in public — funded by grants and donations, never by your data.

Shipped in v1.0 — receive to one reusable address and send to any sp1… address, with unique outputs on-chain for every payment.

Shipped in v1.0.2 — route all traffic over Tor, connect your own node or a trusted Electrum server, and split payments in one tap.

Next up — an external audit of key handling, the scanning pipeline, and the build process, published in full.

Next up — sign with external devices while scan keys stay on the phone, so detection keeps working without exposing spend keys.

Exploring — researching how each composes with silent payments without weakening the threat model. No promises until the design is sound.

No — and anyone who says otherwise is selling something. Silent payments remove address-level linkability on-chain, but privacy has layers. See “Honest about the limits” for exactly what Shroud does and doesn't cover.

Shroud is MIT-licensed and free. Development is funded by grants and donations — never by your data, and there is nothing to upsell.

No. You can connect to any Electrum server you trust, or your own node if you have one. Either way, scanning happens on your device — the server never learns which outputs are yours.

Nothing happens to your coins. Your keys live on your device, and BIP-352 is an open standard — any compatible wallet can restore from your seed phrase.

Android 10+ via direct APK, F-Droid, or the Play Store, and iOS 16+ via the App Store.

No — Shroud pulls compact tweak data instead of full blocks and tunes scanning for the best balance of speed and battery. A typical sync takes minutes, not hours.

A small open-source team building in public. Every commit, build, and release is published — you never have to take our word for it.

Get Shroud