{
  "$schema": "https://degreesofsatoshi.com/encyclopedia/schemas/article-v1.json",
  "schemaVersion": "1.0.0",
  "id": "bitcoin-wallet-software-authenticity",
  "canonical": "https://degreesofsatoshi.com/encyclopedia/bitcoin-wallet-software-authenticity/",
  "collection": "bitcoin",
  "title": "Checking Bitcoin wallet downloads and software signatures",
  "description": "Check Bitcoin wallet software origin, release signatures and signer identity without mistaking a matching hash for proof of a safe program.",
  "aliases": [
    "verify bitcoin wallet download",
    "verify bitcoin wallet download explained"
  ],
  "dates": {
    "published": "2026-10-02",
    "modified": "2026-10-02",
    "verified": "2026-10-02T19:29:20.637Z",
    "dataAsOf": "2026-10-02"
  },
  "authorship": {
    "publisher": "Degrees of Satoshi editorial project",
    "process": "AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied."
  },
  "quickAnswer": {
    "text": "Download a Bitcoin wallet from the project’s documented distribution channel and follow its release-verification instructions. A checksum compares bytes; a digital signature can authenticate those bytes to a particular signing key. You must also establish that the key is the expected publisher’s. Neither check proves the program has no bugs or that every action requested inside it is safe.",
    "claimId": "bitcoin-wallet-software-authenticity-quick-answer",
    "sourceIds": [
      "x425-btc-core-download",
      "x425-btc-electrum-download",
      "x425-btc-secure"
    ]
  },
  "keyFacts": [
    {
      "label": "Checksum",
      "value": "Detects a mismatch against a trusted expected digest",
      "sourceIds": [
        "x425-btc-core-download"
      ],
      "id": "checksum",
      "claimId": "bitcoin-wallet-software-authenticity-fact-checksum"
    },
    {
      "label": "Signature",
      "value": "Authenticates the release to a signing key",
      "sourceIds": [
        "x425-btc-electrum-download"
      ],
      "id": "signature",
      "claimId": "bitcoin-wallet-software-authenticity-fact-signature"
    },
    {
      "label": "Trust question",
      "value": "Is that the expected publisher key?",
      "sourceIds": [
        "x425-btc-electrum-download"
      ],
      "id": "trust-question",
      "claimId": "bitcoin-wallet-software-authenticity-fact-trust-question"
    }
  ],
  "prerequisites": [
    "bitcoin-wallets-explained",
    "bitcoin-ponzi-schemes-and-scams"
  ],
  "sections": [
    {
      "id": "origin",
      "heading": "Start with the project, not an unsolicited update prompt",
      "sourceIds": [
        "x425-btc-electrum-download",
        "x425-btc-core-download"
      ],
      "paragraphs": [
        "A search advertisement or support message can point to an imitation download. Obtain the distribution instructions through the project’s established site and check the exact operating-system package and version. Do not use a recovery phrase as a software-verification input.",
        "Electrum’s site explains that signatures can expose a replaced download even if the attacker changes the executable. That protection depends on verifying against a trusted developer key rather than a replacement key supplied alongside the malicious file."
      ]
    },
    {
      "id": "checks",
      "heading": "Compare authenticity and integrity separately",
      "sourceIds": [
        "x425-btc-core-download",
        "x425-btc-electrum-download"
      ],
      "paragraphs": [
        "Suppose a download’s hash matches a digest copied from the same compromised page. Both could have been replaced together. A valid signature from an independently authenticated expected key adds a different check: that key authorized the signed release material.",
        "A signature verification tool may report a mathematically valid signature while also saying the key is not certified through its trust database. Those are different findings. Resolve key identity through the project’s documented process rather than suppressing the warning blindly."
      ]
    },
    {
      "id": "limits",
      "heading": "Verification is one step in a safe update",
      "sourceIds": [
        "x425-btc-secure",
        "x425-btc-electrum-faq"
      ],
      "paragraphs": [
        "Read release and compatibility notes, preserve the wallet’s required backups, and use a supported upgrade path. A valid official release can still contain defects, and an older file format may not be readable after an unsupported downgrade.",
        "Record the version you installed and the verification outcome. Recheck new downloads instead of assuming that trusting a previous release authenticates every future file with a similar name."
      ]
    }
  ],
  "faq": [
    {
      "question": "Does a matching file hash prove the wallet is genuine?",
      "answer": "Only if the expected hash itself comes from a trustworthy authenticated source. An attacker controlling both the file and the displayed checksum can make them agree. Signature verification with the expected publisher key addresses a separate authenticity question.",
      "sourceIds": [
        "x425-btc-core-download",
        "x425-btc-electrum-download"
      ]
    },
    {
      "question": "Does a valid release signature mean the software is bug-free?",
      "answer": "No. It links signed bytes to a key under the signature scheme. It does not audit the source code, prove every build assumption or guarantee that the application cannot be misused.",
      "sourceIds": [
        "x425-btc-electrum-download",
        "x425-btc-secure"
      ]
    }
  ],
  "claims": [
    {
      "id": "bitcoin-wallet-software-authenticity-quick-answer",
      "articleSlug": "bitcoin-wallet-software-authenticity",
      "statement": "Download a Bitcoin wallet from the project’s documented distribution channel and follow its release-verification instructions. A checksum compares bytes; a digital signature can authenticate those bytes to a particular signing key. You must also establish that the key is the expected publisher’s. Neither check proves the program has no bugs or that every action requested inside it is safe.",
      "sourceIds": [
        "source-4530aa79056687e5",
        "source-ea741b767cef08a4",
        "source-ccf126c494bfe748"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-4530aa79056687e5",
          "locator": "Verify your download"
        },
        {
          "sourceId": "source-ea741b767cef08a4",
          "locator": "Sources and Binaries; How to verify GPG signatures"
        },
        {
          "sourceId": "source-ccf126c494bfe748",
          "locator": "Be careful with online services; Backup your wallet; Encrypt your wallet; Offline wallet for savings; Hardware wallets; Keep your software up to date"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "Educational explanation. Product-specific behavior is scoped to the cited documentation, checked 2026-10-02.",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Read actual Core checksum/signature instructions and Electrum public-key fingerprint guidance. Hash matching, signature verification and trusted signer identity remain separate; authenticity does not guarantee absence of bugs."
        ]
      }
    },
    {
      "id": "bitcoin-wallet-software-authenticity-fact-checksum",
      "articleSlug": "bitcoin-wallet-software-authenticity",
      "statement": "Checksum: Detects a mismatch against a trusted expected digest",
      "sourceIds": [
        "source-4530aa79056687e5"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-4530aa79056687e5",
          "locator": "Verify your download"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Read actual Core checksum/signature instructions and Electrum public-key fingerprint guidance. Hash matching, signature verification and trusted signer identity remain separate; authenticity does not guarantee absence of bugs."
        ]
      }
    },
    {
      "id": "bitcoin-wallet-software-authenticity-fact-signature",
      "articleSlug": "bitcoin-wallet-software-authenticity",
      "statement": "Signature: Authenticates the release to a signing key",
      "sourceIds": [
        "source-ea741b767cef08a4"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-ea741b767cef08a4",
          "locator": "Sources and Binaries; How to verify GPG signatures"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Read actual Core checksum/signature instructions and Electrum public-key fingerprint guidance. Hash matching, signature verification and trusted signer identity remain separate; authenticity does not guarantee absence of bugs."
        ]
      }
    },
    {
      "id": "bitcoin-wallet-software-authenticity-fact-trust-question",
      "articleSlug": "bitcoin-wallet-software-authenticity",
      "statement": "Trust question: Is that the expected publisher key?",
      "sourceIds": [
        "source-ea741b767cef08a4"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-ea741b767cef08a4",
          "locator": "Sources and Binaries; How to verify GPG signatures"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Read actual Core checksum/signature instructions and Electrum public-key fingerprint guidance. Hash matching, signature verification and trusted signer identity remain separate; authenticity does not guarantee absence of bugs."
        ]
      }
    }
  ],
  "sources": [
    {
      "id": "x425-btc-core-download",
      "label": "Download Bitcoin Core",
      "publisher": "Bitcoin Core",
      "url": "https://bitcoincore.org/en/download/",
      "locator": "Verify your download",
      "note": "Current official distribution and binary verification instructions; do not infer third-party package safety.",
      "checkedAt": "2026-10-02T18:53:56.631Z",
      "contentSha256": "ce4ad6a91e072cc4a9c6b2f4c02aa376f6c1cdf8bd616463601dbe79e908db4a",
      "recordId": "source-4530aa79056687e5",
      "version": null
    },
    {
      "id": "x425-btc-electrum-download",
      "label": "Electrum Bitcoin Wallet",
      "publisher": "Electrum",
      "url": "https://electrum.org/",
      "locator": "Sources and Binaries; How to verify GPG signatures",
      "note": "Official wallet distribution and signature verification trust boundaries.",
      "checkedAt": "2026-10-02T18:53:56.639Z",
      "contentSha256": "ac2f033f358e4b6cd785c04754fb2d5aa51be195fe9e8791cedbb724b18160fa",
      "recordId": "source-ea741b767cef08a4",
      "version": null
    },
    {
      "id": "x425-btc-secure",
      "label": "Securing your wallet",
      "publisher": "Bitcoin.org",
      "url": "https://bitcoin.org/en/secure-your-wallet",
      "locator": "Be careful with online services; Backup your wallet; Encrypt your wallet; Offline wallet for savings; Hardware wallets; Keep your software up to date",
      "note": "Backup scope, online exposure, offline signing, custody and software update practices.",
      "checkedAt": "2026-10-02T18:53:53.659Z",
      "contentSha256": "b6017f869461de2150d6b3b328f2ff75aedcd888d7a66cc311acbc243d6ead49",
      "recordId": "source-ccf126c494bfe748",
      "version": null
    },
    {
      "id": "x425-btc-electrum-faq",
      "label": "Frequently Asked Questions",
      "publisher": "Electrum",
      "url": "https://electrum.readthedocs.io/en/latest/faq.html",
      "locator": "Does Electrum trust servers?; Can I import private keys from other Bitcoin clients?; Can I sweep private keys from other Bitcoin clients?; What is the gap limit?; How do I upgrade Electrum?",
      "note": "Electrum-specific sweep/import distinctions, seed recovery scope and address discovery.",
      "checkedAt": "2026-10-02T18:53:56.378Z",
      "contentSha256": "a7f9a2d109a2a753b0010cda1bd2d789a0417a0788a48ea6632c3fe3b391fb06",
      "recordId": "source-82375415e215e2f2",
      "version": null
    }
  ],
  "related": {
    "articles": [
      "bitcoin-wallets-explained",
      "bitcoin-ponzi-schemes-and-scams",
      "bitcoin-wallet-file-backups"
    ],
    "dossiers": [],
    "wallets": []
  },
  "revisionHistory": [
    {
      "date": "2026-10-02",
      "kind": "published",
      "summary": "First publication after primary-source research and separate automated verification."
    }
  ],
  "citation": "Degrees of Satoshi editorial project. “Checking Bitcoin wallet downloads and software signatures.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bitcoin-wallet-software-authenticity/"
}
