Your coins. Final means final.
A desktop wallet that holds the key the miner made for you, or one you make here from 24 words. It sends, receives and reads your history, and it verifies every finality certificate itself with the node's own code. No confirmation counts, no trusting the node.
Three states, checked here
Every transfer in the history is pending, in a block, or final. The third one is the wallet's own verdict.
Signed on this machine and handed to the node. Nothing has carried it yet.
A block carries it and the chain's height passed it. It can still be reorganised until a checkpoint covers it.
Its block sits under a 30-second checkpoint whose certificate this wallet verified: the voter list, the aggregate BLS signature, two thirds of all weight.
- The certificate as a block carried it: the finality section of the blocks after the checkpoint.
- The canonical voter list: every key above dust and not stripped, sorted by key hash, as many as the certificate says.
- The aggregate signature over the checkpoint, by the keys the bitmap names.
- The rule: signed weight at least two thirds of the active weight and of the total weight. Then the transfer's block must sit under the checkpoint on the chain.
The same steps the browser verifier on the home page runs, with the node's own finality code compiled into the wallet. The node's own "locked" field is never read.
Every feature, one line each
Version 1, built on the miner's bones: the same local server, the same signed update manifest, the same key code.
Create or import, sealed on your disk
The password is never written anywhere. The plaintext only ever exists in the engine's memory and is zeroed when the wallet locks.
256 bits of entropy from the operating system, as 24 English words. The wallet asks for three of them typed back before it goes on.
Your 24 words, a raw private key, or the miner's own payout key file. One click brings the key the miner pays to into the wallet.
Argon2id (64 MiB, 3 passes) turns the password into a key; XChaCha20-Poly1305 seals the secret under it. The vault is one file in your user folder.
Keys follow BIP-39 and BIP-44 at the Ethereum path, so the same 24 words open the same account in MetaMask.
Everything on one screen
Signing happens in the engine, in Rust. Nothing on the window side ever holds the key.
Read from your node every few seconds, in IGN, with the block it was read at.
An EIP-1559 transfer. The review shows the amount, the fee at most as base fee plus tip, and what leaves the wallet at most. The zero address and more than the balance are refused.
The code is drawn on your machine as SVG. No image service, no call across the network.
Transfers in and out, block rewards from the execution records, one per blue block, and proving payouts when a block carries a proof record.
Pending, in a block, or final with the checkpoint index, verified here. How it checks.
One button locks the wallet and zeroes the key in memory. The password opens it again.
Reads the miner's node first
When the miner is installed, the wallet uses its node on this machine. Nobody else sees your balance.
Found on this machine and used as it is. Nothing is started.
Balances, sending and history work without a local node. Finality verification needs a node, so transfers stay "in a block" until one is there, and the wallet says so.
The wallet starts its own copy of the node on its own ports, no mining, and stops it when the wallet quits.
The same Ed25519 key as the miner's manifest, checked an hour apart. The download is checked against the manifest's hash before Install now opens it.
Export and add the network
For people who already live in MetaMask. The key leaves this app only when you copy it.
One click adds the Igneum network with its chain id and RPC. Copy network settings puts the same values on the clipboard.
Behind the password, behind a warning: a copied key can be stolen from the clipboard, a screenshot or a notes app. Paste it straight into MetaMask and clear the clipboard.
macOS now, as a disk image. The Windows host is written and untested. No browser extension and no phone app yet.
The first run, timed
A private test network, 5 Oct 2026: one node, one CPU miner paying to wallet A, wallet A sending to wallet B. The log entry ships with the wallet.
| Step | From the node's start | What was seen |
|---|---|---|
| Wallet A created, 24 words, three typed back | 0.3 s | an address |
| Wallet B: a wrong word refused, then created | 0.4 to 0.5 s | "word 1 is not right" |
| A's balance from block rewards | 3.5 s | 10.14 IGN at block 4 |
| Zero address, 999,999,999 IGN, a short address | 4.5 s | all three refused by the quote |
| Quote for 1.5 IGN to B | 4.6 s | gas 25,380; base fee 1 gwei; tip 1 gwei; fee at most 0.00007614 IGN |
| In a block | 5.6 s | chain block 8 |
| First locked checkpoint on the network | about 170 s | index 5 |
| Final in wallet A | 175.2 s | under checkpoint 5, certificate verified by the wallet: 1 of 1 voters, 100% of total weight |
| B's view of the same transfer | 175 s | 1.5 IGN, final |
Send to final: 170.6 s, all of it the network's first lock on a fresh chain. On the live devnet checkpoints lock every 30 seconds once the weight window is full. 13 unit tests cover the words, the path, the vault, the signing and the finality state machine.
Get the wallet
Download only from this domain. Nobody from Igneum will ask for your seed. The file below is the one the wallet's signed manifest names, with its version and size.
Public testnet: not yet open; the devnet build is here for people who want to look.
The wallet reads this machine's node when the miner is installed. Without it, a public RPC for balances and sending, or the bundled node for everything.
Read more in the litepaper