Skip to content

Ibis Wallet v5.0-beta

Choose a tag to compare

@aeonBTC aeonBTC released this 20 Sep 23:07
· 7 commits to main since this release
7b6b86f

Changelog

New Features

  • Ark Layer 2: Full Ark support, send, receive, with Lightning support, and VTXO management - Refresh, Backup, and unilateral exit (Built on Bark)
  • Spark Unilateral Exit: Exit Spark balance on-chain with without Spark cooperation, with fee quote, build, and broadcast flow.
  • Full Silent Payments Support + Frigate Server: Send and receive to silent payment addresses. Added default Frigate Electrum server for SP lookup incoming scan.
  • Edit Derivation Path: Wallet derivation path can now be edited in wallet settings.
  • Dice-Roll Entropy for Seed Generation: Generate new seeds from dice rolls.
  • Checksum Helper (11/23 Words): Find valid BIP39 checksum words for partial 11/23-word seed phrases, with dice or random picker.
  • German + French Localizations: Full app translation for DE and FE alongside EN / ES / RU / PT-BR.

Improvements

  • Various UI tweaks and optimizations.

Bug Fixes

  • Various bug fixes and stability improvements.

Security Fixes

Big thanks to haoxucu for responsibly reporting these issues privately with full PoCs. Fixed before any public disclosure.

  • Lightning Node (LND / CLN): Connecting with TLS off used to send your admin macaroon / rune over an unverified connection, then fall back to plaintext HTTP. Credentials are no longer sent until your pasted certificate checks out, or you explicitly allow insecure transport for that host.
  • Multisig import: Import only checked the receive descriptor, so a crafted file could sneak in a different change descriptor and send your change to someone else's keys while showing a valid policy. Both descriptors are now checked to match (same keys and threshold), change is detected from the wallet itself, and the PSBT screen shows the change address.
  • Liquid MAX send: A liquid: link with a testnet address was accepted, and MAX would send your full balance to it even though normal sends block it. Testnet addresses are now rejected, and MAX checks the network before sending.

There are no known instances of funds being lost in relation to these vulnerabilities.

-======-
SHA256: 8E0A8F97ED75C902D8C1959B188CFE66E3C704DB53C07EAD203690A914AB9FF0
MD5: 1EF2434C1E00B68F4DD4FAEA9A9B4DF3
PGP Public Key
-======-

Full Changelog: v4.7.1-beta...v5.0-beta