Skip to content

Releases: Instinctes/nightfall

NIGHTFALLCOIN Core 1.0.5

Choose a tag to compare

@Instinctes Instinctes released this 22 Sep 03:34

NIGHTFALLCOIN 1.0.5 — quiet recovery and a single mining reward

Core now keeps one startup screen visible while it verifies saved blocks,
downloads missing history and catches the wallet up to the node. It opens the
wallet after the node and saved scan agree for two seconds. Connection details
remain accessible when peers or archive history are unavailable; the screen
does not claim that an offline mainnet node is synchronized.

Normal background scans no longer replace the whole window with a waiting
panel. Trial decryption runs on an isolated wallet copy, then publishes a saved
batch only if the live wallet has not changed. Payments and invoice edits made
in the meantime win over stale scan work. Node status snapshots also run off
the UI thread, and routine background checks no longer flash the status light.

Wallet fixes

  • A changed scan anchor is reconciled automatically against the node's validated
    chain. This intentionally replaces 1.0.3's manual reconciliation policy.
    Pending inputs, invoices and recovery records are retained. Previously
    confirmed payments revived by a reorg are withheld from automatic relay.
  • Activity offers an explicit, reviewed, one-shot retry of a withheld saved
    transaction. It creates no replacement payment, does not release reservations
    or enable automatic rebroadcast, and refuses withdrawn swap-lock payments.
  • A pruned or unavailable chain is rejected before a manual rescan resets state.
    Rescans retain local invoices and the offline-signing journal.
  • Air stores a request's exact signed answer with its payment reservation.
    Repeating it, including after restarting, returns the same transaction.
    Reusing its nonce with changed terms is rejected. A failed relay can be retried
    without consuming the request first.
  • Encrypted wallet setup is enabled on Windows as well as Unix platforms.

Quiet background work and mining rewards

Routine chain changes, reconciliation and scan retries no longer open warnings,
dialogs or toasts. State checks and internal logs remain, and spending stays
blocked whenever the wallet cannot establish a valid scan. Previously saved
payments can be inspected in Activity without an automatic prompt.

Each newly observed live mining reward gets one small, centered animation.
Mining no longer also flashes the balance or triggers the old incoming/output
toasts. Initial catch-up and reconciled history stay quiet; an output seen again
after a reorg does not trigger another reward during the same session.

Mining → Reward-Sound controls a soft synthesized bell, enabled by default.
The choice survives restarts. Audio is generated locally (about 46 kB), with no
downloaded sound assets; playback runs off the UI thread. Linux uses an installed
PipeWire, PulseAudio or ALSA player (pw-play, paplay or aplay).

Web wallet

The completed glass-style web wallet lives at https://wallet.nightfallcoin.org/.
It stores an encrypted vault on the device, supports encrypted backups, and
requires an anchored mainnet scan before spending. Changed scan anchors recover
automatically after checking archive availability, without replaying old sends. Existing browser wallets
move through the separate, read-only exporter at
https://nightfallcoin.org/wallet/migrate/. Original browser data is retained.
The home-screen icon and standalone manifest are included for iPhone and other
supporting browsers. The browser wallet trusts its configured node's chain data;
it does not independently verify proof of work.

Upgrade

Same chain, genesis, protocol v8 and wire v6. No chain reset is required. Quit
Core fully before replacing the application, and keep an encrypted backup.
Using Air in 1.0.5 adds an optional encrypted signing journal that older wallet
versions cannot read. Use 1.0.5 or later for snapshots containing that journal.

Downloads include macOS arm64/Intel DMGs, Windows/Linux Core, node and CLI wallet
binaries, plus platform SHA256 lists. macOS bundles are ad-hoc signed; they are
not Developer-ID signed or notarized. Windows binaries have no publisher
certificate.

Validation covers workspace tests and Clippy, an isolated Devnet lifecycle with
automatic reconciliation and stale-scan conflicts, durable Air retries, native
layout/render checks, and the browser wallet's real-WASM persistence tests.
This is not a claim that every possible defect has been ruled out.

v1.0.4

Choose a tag to compare

@Instinctes Instinctes released this 19 Sep 08:58

NIGHTFALLCOIN 1.0.4 — the 1.0 release

This is the build to install. 1.0.0 through 1.0.3 were each published and
replaced within hours on 19 September, before the website offered them and
before anything was announced. Everything from those builds is here: the
encrypted Vault, Recovery Studio, encrypted backups, invoices and receipts,
Air offline signing, the Dashboard card fix, the upgrade path for wallets with
no scan anchor, the way out of a changed history, and the withdrawal of atomic
swap. Same chain, protocol v8, wire v6, n8 format — no reset, no migration,
nothing required of node operators or miners.

The window flickered while catching up

Two causes, both of them fixed in 1.0.2 and 1.0.3 creating the conditions for
each other.

Paired cards remember the height they were last measured at, so the two cards
in a row can be padded to the same bottom edge. That remembered height was
being applied at any width. When the scan banner appeared the page grew
taller, the scrollbar took a few points of width, the text inside the cards
rewrapped to a different natural height, and the padding that followed changed
the page height back — once per frame, visibly. A height measured for one width
is an answer to a different question at another, so it is now discarded when
the width changes rather than reused.

The status line alternated too. A catch-up is a sequence of short scan passes,
so the "currently scanning" flag flips true and false several times a second,
and the readout swapped between "Scanning…" and "Catching up · scanned block N"
fast enough to read as flicker. While the wallet is behind, being behind is the
stable fact worth showing; a pass running is how it stops being behind, not
separate news. "Scanning…" now appears only when the wallet is at the tip and a
pass is genuinely running.

A test that failed one run in a few

rejected_block_leaves_the_chain_untouched built a block, sealed it with nonce
1, and assumed that would miss the proof-of-work target. The miner address is
generated fresh on every run, so the block hash differs every run, and at
devnet difficulty nonce 1 clears the target often enough to be a coin flip.
When it cleared, the block was valid, the chain moved, and the test reported an
unreadable Hash256 != Hash256 — in CI, while passing locally all morning.

It now searches for a nonce that is known to miss, and asserts the block is
actually rejected before checking what the rejection left behind. A fixture
that is only probably invalid proves nothing about invalid blocks.

Download and verify

  • NIGHTFALLCOIN-Core-1.0.4-macOS-arm64.dmg — macOS 11+
  • NIGHTFALLCOIN-Core-1.0.4-macOS-intel.dmg — macOS 10.15+
  • nightfall-core-1.0.4-windows-x64.exe
  • nightfall-core-1.0.4-linux-x64 — GUI dependencies required
  • nightfalld and nightfall-wallet CLI binaries for Windows/Linux;
    macOS includes them inside the app bundle.

Verify against SHA256SUMS-1.0.4.txt, SHA256SUMS-1.0.4-windows.txt or
SHA256SUMS-1.0.4-linux.txt before running downloads. macOS apps are ad-hoc
signed, not Developer-ID signed or notarized; Windows builds have no publisher
signing certificate. A checksum verifies file integrity, not software safety.

Back up your recovery phrase and quit Core fully before replacing the
application.

Validation scope

Full workspace build with zero warnings; complete suite green at 438 tests,
including the isolated node lifecycle test covering scanning, the scan anchor,
competing branches, reconciliation and the payment path end to end.

The 1.0 in the version number is a statement about scope and stability of
interface, not a safety certificate. Independent review remains outstanding and
is named as such on the site.

v1.0.3

v1.0.3 Pre-release
Pre-release

Choose a tag to compare

@Instinctes Instinctes released this 19 Sep 08:30

NIGHTFALLCOIN 1.0.3 — a way out of a changed history

This is the 1.0 release to install. 1.0.0 through 1.0.2 were published and
superseded the same day, before any announcement and before the website offered
them. Everything from those builds is here: the encrypted Vault, Recovery
Studio, encrypted backups, invoices and receipts, Air offline signing, the
upgrade fix for wallets with no scan anchor, the Dashboard card fix, and the
withdrawal of atomic swap. Same chain, protocol v8, wire v6, n8 format.

The wallet could get stuck with no way forward

When the chain changes below the position a wallet has already scanned — a
competing branch of the same height, which on a fifteen-second chain is weather
rather than catastrophe — the wallet stops, says which block it expected and
which it found, and refuses to spend.

That refusal is correct and stays. A branch of equal height is a decision with
money attached, and a wallet that quietly re-scans onto whichever branch its
node currently prefers has made that decision on its owner's behalf.

What was missing was the other half: any way for the owner to make it. The
banner said "reconcile the wallet before sending" and there was nothing to
press. The documented route, a rescan from Settings, is refused while any
payment is pending — and pending payments are exactly what a reorg calls into
question. A wallet in that state could not scan, could not rescan, and could not
send. It simply stopped, a hundred blocks behind its own node, and said
"catching up".

What is new

The scan warning now offers Reconcile with this chain, and only when the
anchor has actually broken. It explains itself before it acts and asks once more
before it does:

This reads the whole chain your node follows and makes this wallet agree with
it: anything that chain does not contain is dropped, and a payment whose
inputs it no longer spends goes back to unconfirmed. Nothing is broadcast.
Export an encrypted backup first — this cannot be undone from inside the
wallet.

It runs the same canonical pass a rescan ends in, on the scan worker rather than
the interface thread, without discarding what is already known and without the
no-pending-payments precondition. Reconciling is not a rebroadcast: nothing is
put back on the wire by it.

Pinned end to end in the isolated node test, which now builds two real competing
branches, confirms the wallet refuses to follow the second one by itself,
reconciles on request, and goes back to ordinary scanning afterwards — and that
the offer is absent when there is nothing to reconcile.

If your wallet is stuck right now

Install this build, open the Wallet scan incomplete banner, export an
encrypted backup from Settings, then press Reconcile with this chain. It
reads the whole chain once, so it takes a while; the scan resumes by itself
afterwards.

If the banner does not offer it, the wallet is not in that state and an ordinary
scan will catch up on its own.

Download and verify

  • NIGHTFALLCOIN-Core-1.0.3-macOS-arm64.dmg — macOS 11+
  • NIGHTFALLCOIN-Core-1.0.3-macOS-intel.dmg — macOS 10.15+
  • nightfall-core-1.0.3-windows-x64.exe
  • nightfall-core-1.0.3-linux-x64 — GUI dependencies required
  • nightfalld and nightfall-wallet CLI binaries for Windows/Linux;
    macOS includes them inside the app bundle.

Verify against SHA256SUMS-1.0.3.txt, SHA256SUMS-1.0.3-windows.txt or
SHA256SUMS-1.0.3-linux.txt before running downloads. macOS apps are ad-hoc
signed, not Developer-ID signed or notarized; Windows builds have no publisher
signing certificate. A checksum verifies file integrity, not software safety.

Back up your recovery phrase and quit Core fully before replacing the
application.

Validation scope

Full workspace build with zero warnings; complete suite green at 438 tests,
including the isolated node lifecycle test that now covers competing branches,
the refusal, and the reconciliation.

The 1.0 in the version number is a statement about scope and stability of
interface, not a safety certificate. Independent review remains outstanding and
is named as such on the site.

v1.0.2

v1.0.2 Pre-release
Pre-release

Choose a tag to compare

@Instinctes Instinctes released this 19 Sep 08:07

NIGHTFALLCOIN 1.0.2 — Dashboard cards the right height

This is the 1.0 release to install. 1.0.0 and 1.0.1 were published and
superseded the same day, before any announcement and before the website offered
them. Everything in
1.0.0 and 1.0.1 is here:
the encrypted Vault, Recovery Studio, encrypted backups, invoices and receipts,
Air offline signing, the upgrade fix for wallets with no scan anchor, and the
withdrawal of atomic swap. Same chain, protocol v8, wire v6, n8 format.

The Dashboard cards ran off the bottom of the window

"This node" and "Hashrate" hold four numbers each and were drawn as tall as the
window, with a field of empty glass beneath them.

Two faults, and the second one made the first permanent.

Cards that sit side by side are padded to a common height so their bottom edges
line up. That height was then measured after the padding — so the
measurement only ever confirmed the padding that produced it. A row that became
too tall once stayed too tall for good, and because the value lives in the
interface's own memory, it survived every later frame.

It became too tall in the first place because each row was identified by
counting the widgets drawn before it. A banner above the cards — "wallet scan
incomplete", a node error, the catching-up notice — renumbers everything below,
so the metrics row could pick up the height stored by the Activity row, which is
tall by nature. Rows are now named by what they hold rather than by where they
happen to fall, and the height reported upwards is the card's own content.

Pinned by a regression that settles a row on tall content, shrinks it, and
requires the row to shrink with it — on the old code it reports the row stuck at
408 points — and then makes a banner appear and requires the row to keep its own
height instead of inheriting its neighbour's.

Not a bug: "the chain changed below the scan position"

If the wallet tells you the chain changed beneath it and blocks sending, that is
the scan anchor working, not a fault. The node saw a competing branch at a
height the wallet had already scanned.

The wallet does not follow that quietly and will not be changed to. A branch of
equal height is a decision with money attached — re-scanning onto whichever one
a node currently prefers is how a wallet ends up somewhere its owner never
chose. So it stops, says which block it expected and which it found, refuses to
spend, and waits for a person. If the node settles back onto the chain the
wallet knows, scanning resumes by itself. If it does not, the resolution is a
rescan from Settings, after an encrypted backup.

(This was briefly "fixed" during development by reconciling automatically. The
isolated node test refused it, correctly, and the change was reverted.)

Download and verify

  • NIGHTFALLCOIN-Core-1.0.2-macOS-arm64.dmg — macOS 11+
  • NIGHTFALLCOIN-Core-1.0.2-macOS-intel.dmg — macOS 10.15+
  • nightfall-core-1.0.2-windows-x64.exe
  • nightfall-core-1.0.2-linux-x64 — GUI dependencies required
  • nightfalld and nightfall-wallet CLI binaries for Windows/Linux;
    macOS includes them inside the app bundle.

Verify against SHA256SUMS-1.0.2.txt, SHA256SUMS-1.0.2-windows.txt or
SHA256SUMS-1.0.2-linux.txt before running downloads. macOS apps are ad-hoc
signed, not Developer-ID signed or notarized; Windows builds have no publisher
signing certificate. A checksum verifies file integrity, not software safety.

Back up your recovery phrase and quit Core fully before replacing the
application.

Validation scope

Full workspace build with zero warnings; complete suite green at 438 tests,
including the isolated node lifecycle test that covers scanning, the scan
anchor, competing branches and the payment path end to end.

The 1.0 in the version number is a statement about scope and stability of
interface, not a safety certificate. Independent review remains outstanding and
is named as such on the site.

v1.0.1

v1.0.1 Pre-release
Pre-release

Choose a tag to compare

@Instinctes Instinctes released this 19 Sep 07:28

NIGHTFALLCOIN 1.0.1 — the 1.0 release, with the upgrade path fixed

Use this instead of 1.0.0. 1.0.0 was published and withdrawn within hours,
before it was announced and before it appeared on the website. If you installed
it, replace it with this build. Nothing was lost — see below.

Everything in 1.0.0 is here: the encrypted Vault,
Recovery Studio, encrypted backups, invoices and receipts, Air offline signing,
the rebuilt window, and the withdrawal of atomic swap. Same chain, protocol v8,
wire v6, n8 data format. No reset, no migration, no seed-node upgrade.

What 1.0.0 got wrong

An upgraded wallet stopped scanning, silently.

1.0 introduced a scan anchor: the hash of the block a scan ended on, stored so
the wallet can tell whether the chain moved underneath it. Wallets written by
0.9.5 have no such field, because it did not exist yet — which is every wallet
in existence.

scan_blocks refuses an incremental page from a wallet with no anchor, and
that refusal is correct: a page that begins at the scan position carries no
evidence at all about the history below it, so accepting one would let a wallet
adopt a chain it was never on. What was wrong is what happened next. The
application kept asking for the same incremental page every thirty seconds,
kept being refused, and reported nothing worse than "Catching up". The scan
position never moved again.

Symptom: the balance and Activity stay correct but frozen at the moment of the
upgrade, the node keeps advancing normally, and the wallet line reads
Wallet scan N / M — coins in the last … blocks are still being looked for
with N never changing.

No coins were ever at risk and nothing was written. The refusal happened
before any wallet save, which is also why every affected wallet file is still
byte-for-byte what 0.9.5 left behind.

The fix

A wallet with no anchor is now asked for the one range that can give it one: a
single canonical pass from its birth height. That is the repair the wallet
already implements and the only one it treats as sound — absence of a payment
means absence only when you have looked at the whole history — and it writes
the anchor on its way out. Every page after it is an ordinary one.

The pass reads the chain once, so the first launch after upgrading takes longer
than usual and uses more memory while it runs. After that, scanning is exactly
as before. On a pruned node the pass is impossible and the wallet now says so
instead of stalling.

Two regressions pin it: one that the range offered to an anchorless wallet is
the canonical one and that every other wallet keeps paging, and one that walks
a real wallet through the whole path — history without an anchor, an
incremental page still refused, the canonical pass accepted, the anchor
present, the balance identical to a wallet that scanned the same chain from
scratch, and ordinary incremental scanning working afterwards.

Also fixed

Two failures that only appeared off macOS, found by CI on the 1.0.0 tag:

  • feedback.rs kept an import and a guard outside the macOS-only block, so on
    Linux the block compiled away and left an unused import above a function
    whose entire body was a bare return. Clippy rejects both.
  • A vault storage test read its own directory while the store was still open.
    Byte-range locks are advisory on Unix and mandatory on Windows, so the read
    failed there and nowhere else.

Neither changed shipped behaviour; both would have turned CI red on every
future push.

If you installed 1.0.0

Replace the application and open it. The canonical pass runs once and the scan
catches up. There is nothing to restore and no rescan to request — and if you
had already gone back to 0.9.5, that also worked, because 1.0.0 never wrote to
the wallet file.

Download and verify

  • NIGHTFALLCOIN-Core-1.0.1-macOS-arm64.dmg — macOS 11+
  • NIGHTFALLCOIN-Core-1.0.1-macOS-intel.dmg — macOS 10.15+
  • nightfall-core-1.0.1-windows-x64.exe
  • nightfall-core-1.0.1-linux-x64 — GUI dependencies required
  • nightfalld and nightfall-wallet CLI binaries for Windows/Linux;
    macOS includes them inside the app bundle.

Verify against SHA256SUMS-1.0.1.txt, SHA256SUMS-1.0.1-windows.txt or
SHA256SUMS-1.0.1-linux.txt before running downloads. macOS apps are ad-hoc
signed, not Developer-ID signed or notarized; Windows builds have no publisher
signing certificate. A checksum verifies file integrity, not software safety.

Back up your recovery phrase and quit Core fully before replacing the
application.

Validation scope

Full workspace build with zero warnings; complete suite green at 437 tests.
The two new regressions above; ledger, consensus, storage and wallet
regressions; Core page-layout tests at three content widths; contrast tests
measured against the composited background; crash-injection tests on the vault
persistence adapter on Unix and Windows; an isolated node lifecycle test
covering the payment path end to end.

The upgrade path itself was also exercised against a real mainnet wallet that
had been left frozen by 1.0.0, rather than only in a fixture.

These are bounded checks, not an independent security audit. The 1.0 in the
version number is a statement about scope and stability of interface, not a
safety certificate. Independent review remains outstanding and is named as such
on the site.

v1.0.0

v1.0.0 Pre-release
Pre-release

Choose a tag to compare

@Instinctes Instinctes released this 19 Sep 02:30

NIGHTFALLCOIN 1.0.0 — mainnet wallets

The first 1.0 Core release for macOS Apple Silicon, Intel macOS, Windows x64
and Linux x64. This replaces 0.9.5 as the current download.

Same chain. Protocol v8, wire v6, n8 data format, unchanged emission and
genesis. No reset, no migration, no seed-node upgrade. If you run a node or
mine, nothing is required of you.

Encrypted Vault

Keys now live in an authenticated encrypted store instead of a plaintext seed
file. One shared vault engine serves the desktop wallet and the browser, with
a versioned envelope, bounded parsing, a fixed KDF cost and authenticated
network context. An unlocked session owns the keys; locking removes the
application's access to them.

Migration from a plaintext wallet is deliberately two-stage and failure-safe:
the encrypted copy is written and verified in full before any legacy secret is
retired, and an interrupted retirement resumes from its surviving files. If the
old and new state disagree, neither original is removed. Encryption at rest is
not protection against hostile code on the machine, a compromised device, every
memory copy, or backups you made earlier.

Automatic locking on loss of window focus and after inactivity. Password
rotation without re-creating the wallet. Old backups keep their old passwords.

Recovery Studio and encrypted backups

Rehearse your 24 words against the wallet you actually hold: the check derives
the address locally, compares it, and never writes a file, creates a wallet or
sends anything. A different valid phrase is refused by name rather than
silently accepted.

Encrypted .nfv backups can be exported and read back for a password,
identity and full-state comparison without overwriting anything. Recovery
offers two explicit modes and defaults to keys-only. A restored state that
could still broadcast an old payment is refused at two independent gates, and
withheld payments are shown in their own notice rather than mixed into the
stuck-payment one.

The rest of the wallet

Invoices and receipts, the address book, view keys, Air offline signing for a
machine that is never on a network, mining with a CPU-thread control, and a
rebuilt window: a rounded glass plate with the navigation rail standing off its
left edge, working traffic-light buttons, and text measured against the
background it is actually drawn on rather than against a colour that is never
displayed.

Atomic swap has been withdrawn

The NIGHT ↔ BTC atomic swap was built, reviewed, and removed before this
release. It is not disabled — it is gone, along with its crate, its page, its
bitcoind configuration and 21 third-party packages including all of
secp256k1, the bitcoin crate family, and a second implementation of the
same curve arithmetic the chain already uses.

Nightfall has no script language, so a NIGHT lock cannot refund itself on a
timer the way a Bitcoin lock can. A counterparty who cancels and walks away
leaves NIGHT locked permanently; a redeem published too late discloses its
secret while the cancel confirms, and one side can end up with both assets.
Neither is reachable by better implementation work. Shipping that unaudited was
not a trade worth making.

No user was ever exposed: swaps were blocked on mainnet in code, in every
published build. No consensus rule changed — there is no fork and no migration.
A wallet file written by an experimental build still opens; rescan and restore
stay blocked while it carries swap records, and an abandoned swap lock is never
rebroadcast on its own.

Reasoning: docs/SWAP-WITHDRAWN.md.

Web wallet — unchanged in this release

The browser wallet stays where it is, at nightfallcoin.org/wallet/. This
release is desktop Core only. Nothing about your browser wallet changes, and
there is nothing for you to move.

wallet.nightfallcoin.org exists and is reserved for it. A browser separates
stored keys by origin and by nothing smaller, so moving the wallet to its own
host is worth doing — but the build prepared there handles keys, backups and
recovery and cannot yet make a payment. Shipping it would trade a wallet that
pays for one that does not, so it waits.

When the move happens it will be announced, and the old address will hand your
wallet across before it stops serving one. Until then, the wallet at
/wallet/ remains a light wallet that trusts a node for chain data, with
browser storage that can be cleared or lost.

Download and verify

  • NIGHTFALLCOIN-Core-1.0.0-macOS-arm64.dmg — macOS 11+
  • NIGHTFALLCOIN-Core-1.0.0-macOS-intel.dmg — macOS 10.15+
  • nightfall-core-1.0.0-windows-x64.exe
  • nightfall-core-1.0.0-linux-x64 — GUI dependencies required
  • nightfalld and nightfall-wallet CLI binaries for Windows/Linux;
    macOS includes them inside the app bundle.

Verify against SHA256SUMS-1.0.0.txt, SHA256SUMS-1.0.0-windows.txt or
SHA256SUMS-1.0.0-linux.txt before running downloads. macOS apps are ad-hoc
signed, not Developer-ID signed or notarized; Windows builds have no publisher
signing certificate. A checksum verifies file integrity, not software safety.

Back up your recovery phrase and quit Core fully before replacing the
application.

Validation scope

Full workspace build with zero warnings and the complete test suite green.
Ledger, consensus, storage and wallet regressions; Core page-layout tests at
three content widths; contrast tests measured against the composited
background; crash-injection tests on the vault persistence adapter on Unix and
Windows; an isolated node lifecycle test covering the payment path end to end.

These are bounded checks, not an independent security audit, and not every
operating system, screen reader, populated history or physical device. The
1.0 in the version number is a statement about scope and stability of
interface, not a safety certificate. Independent review remains outstanding and
is named as such on the site.

NIGHTFALLCOIN Core 0.9.5

Choose a tag to compare

@Instinctes Instinctes released this 06 Sep 18:19

NIGHTFALLCOIN 0.9.5 — mainnet wallets

The regular mainnet Core release for macOS Apple Silicon, Intel macOS,
Windows x64 and Linux x64, plus the responsive mobile/desktop web wallet.
This replaces 0.9.2 as the current wallet download. Same chain, protocol v8,
wire v6 and n8 data format. No reset, migration or seed-node upgrade.

A shared wallet interface

Soft violet surfaces, rounded cards, subtle shadows and pastel pink/cyan
accents now connect Core and the web wallet. Dark lettering on bright balance
cards and action buttons preserves readability. Desktop navigation uses an
icon sidebar; the responsive web wallet keeps bottom navigation on phones.

All eight Core pages were reviewed: Dashboard, Send, Receive, Activity,
Mining, Network, Swap and Settings. Improvements include responsive metrics,
independent scroll positions, clear connection states, keyboard focus and
genuinely disabled actions. Receive uses a square QR with a four-module quiet
zone. Payment review shows the full address and blocks the underlying form;
leaving Settings hides revealed keys.

The browser wallet carries the design through balances, activity, payments,
receive addresses, contacts and settings. Invalid/incomplete or unaffordable
payments cannot open review; the confirmation shows the complete address.
Node failures use readable connection errors. HTML escaping covers attribute
quotes. No third-party scripts, fonts, analytics or account services were added.

Mainnet use and the swap boundary

Core starts on mainnet by default. Mainnet mining, sending and receiving
continue as before. Existing wallet data is retained. Back up your recovery
phrase and quit Core fully before replacing the application.

Atomic swaps are still disabled on mainnet. The experimental devnet/testnet
implementation includes background monitoring, durable exact-transaction retries,
confirmed-chain observation, corrected signature-secret extraction and NIGHT
recovery after Bob's Bitcoin refund. These do not constitute a mainnet safety
approval. There is no independent timed NIGHT refund: if Bob never refunds,
Alice's NIGHT may remain locked permanently, even after punishment.
Use test coins only, keep both nodes and Core online, and back up per-swap
.secret files as well as the seed. Independent cryptographic review and
long-duration public-network acceptance are outstanding.

The web wallet remains a mainnet light wallet with its existing node-trust and
browser-storage limitations. It receives the design update, not atomic swaps.

Download and verify

  • NIGHTFALLCOIN-Core-0.9.5-macOS-arm64.dmg — macOS 11+
  • NIGHTFALLCOIN-Core-0.9.5-macOS-intel.dmg — macOS 10.15+
  • nightfall-core-0.9.5-windows-x64.exe
  • nightfall-core-0.9.5-linux-x64 — GUI dependencies required
  • nightfalld and nightfall-wallet CLI binaries for Windows/Linux;
    macOS includes them inside the app bundle.

Verify against SHA256SUMS-0.9.5.txt, SHA256SUMS-0.9.5-windows.txt or
SHA256SUMS-0.9.5-linux.txt before running downloads. macOS apps are ad-hoc
signed, not Developer-ID signed or notarized; Windows builds have no publisher
signing certificate. A checksum verifies file integrity, not software safety.

Validation scope

Local gates include strict workspace Clippy, workspace tests, Core eight-page
layout tests at three content widths, normal-text and gradient contrast tests
and disabled-control regressions. Windows/Linux release jobs run workspace
tests before building. macOS app integrity and DMG checks precede upload.

The shared Core UI was visually checked in the installed test candidate on macOS.
Web wallet navigation/layout was checked at 320, 390, 768, 860, 1024 and 1440 px
using a public test phrase on localhost, with no real funds. These are bounded
checks, not every OS, screen reader, populated history or physical mobile device.
The isolated real-bitcoind/NIGHT Core-worker integration covers settlement and
cancel/refund/NIGHT recovery with session reloads between ticks. A separate
5,000-tick simulation passed on the preceding candidate. No claim of 100% safety.

0.9.4 remained an unpublished draft. This release adds explicit floating-point
types and removes unnecessary test clones to pass the newer CI compiler without
changing transaction rules or enabling mainnet swaps.

NIGHTFALLCOIN Core 0.9.2

Choose a tag to compare

@github-actions github-actions released this 04 Sep 13:12

Binaries built by this workflow. Verify the SHA256 before running anything.

NIGHTFALLCOIN Core 0.9.1

Choose a tag to compare

@Instinctes Instinctes released this 04 Sep 08:01

The desktop wallet redrawn against the phone wallet: flat cards, list rows with a rule between them, Send restructured so the numbers that decide a payment sit above the button that commits it.

The fee chooser is gone. Economy, Standard and Priority differed in no way the protocol can express — the fee is burned, not paid to a miner, and nothing orders the mempool by it.

Same chain: genesis 061a052d…, protocol v8, wire v6. No consensus change.

Verify the SHA256 before running anything.

NIGHTFALLCOIN Core 0.9.0

Choose a tag to compare

@Instinctes Instinctes released this 30 Aug 18:56

Same chain. Genesis 061a052d…, protocol v8, wire v6. No consensus
change. 0.8.x peers with this normally.

Upgrade if you swap or mine on Windows. Experimental NIGHT↔BTC swaps
land here, still disabled on mainnet. A Windows close-to-tray default
that left extra processes running is unchanged in behaviour: Quit from the
tray, do not open a second Core on the same folder.

Experimental NIGHT ↔ BTC swaps

Wallet-to-wallet, copy-paste packets, no operator. Bitcoin is P2WSH 2-of-2
with an ECDSA adaptor; NIGHT is a shared stealth address. There is no
NIGHT refund
. If the other side cancels and never refunds, NIGHT locked
in the swap is stuck forever.

Mainnet will not start a swap. Testnet and devnet will. The cross-curve
proof uses our own Ristretto leaf inside a reviewed combinator crate.
Nobody outside this project has signed that leaf. The gate stays until
it is opened on purpose.

Operator notes: docs/SWAP.md. Loss cases: docs/SWAP-LOSS.md. What we
attacked: docs/SWAP-ATTACKS.md.

bitcoind talking to the wallet needs -txindex=1. Without it, confirmed
locks look missing and the swap goes blind while H₁ runs.

Driver

A redeem that was safe last tick is not safe forever. Between ticks the
Bitcoin chain moves. The driver re-reads depth every time and will not
re-broadcast a pending redeem inside the H₁ margin. That race is how the
other side takes both coins.

Builds

This tag is 0.9.0 in the tree. Binaries, checksums, website, seed
installs: built and shipped by the operator, not from this checkout.

fmt, clippy -D warnings, workspace tests, mutation stand.