Last updated: October 30, 2026
Every wallet asks you to trust it. Nova asks you not to. Every release ships a signed SHA-256 manifest, the source is public, the builds are reproducible, and the zero-telemetry claim is testable from your own machine. Here is the five-minute version of doing all three.
A checksum answers exactly one question: did the bytes you downloaded equal the bytes we published? Not "is this software safe" — just "is this the artifact we released." That is a much stronger property than it sounds, because it removes the entire class of "the download was swapped in transit or on a mirror."
Each release ships a SHA256SUMS file — one digest per build artifact — signed with the release key. Verify the signature once to trust the manifest; then every artifact boils down to comparing 64 hex characters.
This is the check that matters. Take the SHA-256 of the file you downloaded (commands in the next section), paste it below, and compare it against the digest published in the manifest — the sweep compares all 64 characters, because a hash that differs at position 41 differs completely.
No tooling to install — every OS ships a hasher. One command per platform:
# in the folder with your download certutil -hashfile nova-2.4.1.zip SHA256 7396490d1d1026bb51315d3dd0d2578979e8cbf5080bf8132a76e12c8990a3ce
# in the folder with your download shasum -a 256 nova-2.4.1.zip 7396490d1d1026bb51315d3dd0d2578979e8cbf5080bf8132a76e12c8990a3ce nova-2.4.1.zip
# in the folder with your download sha256sum nova-2.4.1.zip 7396490d1d1026bb51315d3dd0d2578979e8cbf5080bf8132a76e12c8990a3ce nova-2.4.1.zip
If the output matches the manifest digest — all 64 characters — the file is the published build. If even one differs, delete it.
The strongest check doesn't involve trusting our binaries at all. Nova builds are reproducible — same source, same toolchain, same output bytes — so you can compile the release yourself and compare the result against the published manifest:
git clone https://github.com/novawallet/nova cd nova && git checkout v2.4.1 npm ci --ignore-scripts npm run dist # then hash dist/ output and diff against SHA256SUMS
Identical output means the published binary contains exactly the source you just read — nothing added at build time, nothing removed. A non-match means either the build isn't reproducible or the binary doesn't correspond to the tag; both are worth reporting.
"Zero telemetry" is a claim anyone can write on a landing page. Ours is checkable: open Nova, leave it idle, and capture its traffic. Below is what that capture looks like — the feed runs while you watch it:
RPC calls happen only when you ask for them — checking a balance, broadcasting a transaction. Analytics, crash reporters, fingerprinting beacons, session logs: none exist in the codebase, so none appear on the wire. Run it yourself with any packet capture tool and count.
WalletScrutiny tracks whether published wallet binaries actually correspond to their public source. Of 4,921 wallets reviewed, only 122 pass reproducibility checks — about 2.5%. The rest can't prove the download matches the code, which means "open source" on the README is doing the security work of a slogan.
Verification is not a feature you use once — it's a posture. Hash the release, skim the diff, watch the traffic. A wallet that survives that scrutiny earns the keys it holds; one that doesn't is asking for faith, and faith is what every drain on this site exploits.
Self-custody only means something if the software is the software you think it is. Five minutes with a checksum settles it.