Status
Internal review, October 2026
Before the first mainnet launch the codebase received an internal security review covering codec, proof of work, difficulty, emission, shielded validation, chain state, storage, fork choice, mempool, peer protocol, wallet and release handling. That review changed no consensus rule; the 1.0.0 release later introduced the early-emission rule with a new genesis. Thirteen findings were fixed, including:
- High: side-branch blocks are checked for header context and RandomX work before any branch replay; unknown parents are refused.
- High: policy rejections (full mempool, duplicates, timing races) no longer strike or ban honest relays — only invalid data is punished.
- Medium: indexed block locators and per-connection rate limits for GetBlocks, Ping and GetPeers.
- Medium: per-netgroup discovery caps, solicited peer lists only, four inbound connections per IP.
- Medium: blocks applied in place with tail-only header context — no quadratic cost growth.
- Medium: mining templates build their Halo 2 proofs outside the node lock; public RPC has its own concurrency budget.
- Low: fee-rate displacement in a full mempool, bounded ban tables, FIFO proof cache, HTTPS-only seed lists.
Admin endpoints answer HTTP 401 for a missing or wrong token, remote connections require HTTPS (plain HTTP only for literal loopback), and the repository has GitHub secret scanning and push protection enabled.
Residual risks are documented openly: block-by-block sync without headers-first download or minimum chain work, a nullifier root that hashes the whole set per block, and the need for independent cryptography, consensus and network audits.
Wallet protection
| Threat | Mitigation |
|---|---|
| Wallet file theft | Argon2id key derivation and XChaCha20-Poly1305 authenticated encryption. The recovery phrase comes from OS entropy and is never stored in plain text. |
| Unattended open wallet | Automatic lock after five minutes without input; Lock erases held password and phrase buffers and invalidates late responses. |
| Secret residue in memory | Rust zeroization of secret buffers; sensitive text fields discard undo history. Cannot guarantee removal from swap, crash dumps or clipboard managers. |
| Remote node control | Admin RPC binds to loopback only and requires a constant-time-compared capability token. Public RPC is read-only, opt-in, bounded and rate-limited by concurrency. |
| Invalid or malicious blocks | Full validation of proof of work, Halo 2 proofs, signatures, anchors and nullifier uniqueness. Frames bounded before allocation; misbehaving peers are disconnected and banned. |
| Inflation | Integer-only issuance with no mint class; exact coinbase amounts validated; proofs enforce value balance for shielded transfers. |
| Username impersonation | On-chain names are first-come in chain order, signed by a seed-derived owner key, permanent and resolved by your own node. Lookalike names remain a social risk. |
| Burned value | The burn address has a hash-to-curve spend key with no known discrete logarithm; breaking it would break Orchard spend authorization generally. |
| Tampered downloads | SHA-256 checksums for every package, a manifest with the source commit, and a wallet that never installs updates by itself. |
Node validation
In Full mode the wallet starts its own node; in Quick mode it fetches blocks from remote nodes over Tor and follows the chain with the most cumulative work as computed locally. Either way it does not trust seeds, explorers (including this one) or any server for consensus — it checks every block, proof, signature and nullifier itself. Seeds only help nodes meet; cached and exchanged peers, explicit peers and full validation remain independent of any seed operator.
The genoryn.io explorer is a convenience. It runs the same node software and shows what that node validated, but your wallet never relies on it.
Network privacy
In Direct and Hybrid mode, clearnet peers see your IP address. A Tor client is built in, and new installations start in Tor-only mode: every connection, peer lookup and payment broadcast goes through Tor and nothing ever falls back to a direct connection. Payments you create are first sent to one relay peer before wider broadcast. Tor does not protect against an adversary who watches both ends of a circuit, and application checks do not replace OS-level isolation such as Whonix or Tails. Details: Tor & privacy.
What is not protected
- Malware, keyloggers or remote-access tools on your computer.
- Copied or photographed recovery phrases; weak passwords.
- Screenshots, screen recording, clipboard history and clipboard managers.
- Transaction timing correlation and a small anonymity set while the network is young.
- In Direct or Hybrid mode, a network observer or peer that sees your IP address; in Tor mode, an adversary correlating both ends of a Tor circuit.
- Voluntary disclosures: payment proofs you share, off-chain metadata, exchange records.
GENORYN does not claim absolute anonymity, instant finality or an inherited audit.
Release verification
Every package on GitHub carries a .sha256 file, an internal SHA256SUMS list and a release manifest naming its exact source commit. The wallet only points to the official repository's releases and never downloads or installs anything automatically.
$ sha256sum -c genoryn-1.0.0-mainnet-linux-x86_64.zip.sha256
$ unzip genoryn-1.0.0-mainnet-linux-x86_64.zip && cd genoryn-1.0.0-mainnet-linux-x86_64
$ sha256sum -c SHA256SUMS --quietIndependent builder reproducibility, production signing and a multi-maintainer policy remain release gates before any mainnet.
Reporting a vulnerability
Please report security issues privately following the repository's security policy, or through GitHub's private vulnerability reporting on github.com/genoryn/genoryn/security. Do not open public issues for undisclosed vulnerabilities.
This website itself sends no trackers or cookies, loads no third-party scripts or fonts, serves a strict Content-Security-Policy, and exposes only read-only, rate-limited chain data.