NovaNovaWallet Features Why Nova Rewards Security Learn Connect Wallet

Don't trust it. Verify it.

Last updated: October 30, 2026

Every wallet asks you to trust it. Nova asks you not to. Every release ships a signed SHA-256 manifest, the source is public, the builds are reproducible, and the zero-telemetry claim is testable from your own machine. Here is the five-minute version of doing all three.

What you can verify today
  • Every release publishes a SHA-256 manifest — hash the binary you downloaded, compare character-by-character.
  • Builds are reproducible: the same source produces the same bytes, so you can rebuild and diff instead of trusting us.
  • Zero telemetry is testable, not just claimed — watch the process on the wire and count the analytics frames yourself.
  • Only ~2.5% of wallets pass WalletScrutiny reproducibility checks — this page is how we pass ours.

The signed manifest

A checksum answers exactly one question: did the bytes you downloaded equal the bytes we published? Not "is this software safe" — just "is this the artifact we released." That is a much stronger property than it sounds, because it removes the entire class of "the download was swapped in transit or on a mirror."

Each release ships a SHA256SUMS file — one digest per build artifact — signed with the release key. Verify the signature once to trust the manifest; then every artifact boils down to comparing 64 hex characters.

Check your checksum

This is the check that matters. Take the SHA-256 of the file you downloaded (commands in the next section), paste it below, and compare it against the digest published in the manifest — the sweep compares all 64 characters, because a hash that differs at position 41 differs completely.

sha-256 · nova-2.4.1 idle
published manifest
7396490d1d1026bb51315d3dd0d2578979e8cbf5080bf8132a76e12c8990a3ce
your binarywaiting for input
—
try it: ·
Digest shown is a documentation example — the live manifest for each release ships inside the download and on the release notes page.

Hash it yourself

No tooling to install — every OS ships a hasher. One command per platform:

PowerShell / cmd
# in the folder with your download
certutil -hashfile nova-2.4.1.zip SHA256
7396490d1d1026bb51315d3dd0d2578979e8cbf5080bf8132a76e12c8990a3ce
Terminal
# in the folder with your download
shasum -a 256 nova-2.4.1.zip
7396490d1d1026bb51315d3dd0d2578979e8cbf5080bf8132a76e12c8990a3ce  nova-2.4.1.zip
shell
# in the folder with your download
sha256sum nova-2.4.1.zip
7396490d1d1026bb51315d3dd0d2578979e8cbf5080bf8132a76e12c8990a3ce  nova-2.4.1.zip

If the output matches the manifest digest — all 64 characters — the file is the published build. If even one differs, delete it.

Rebuild from source

The strongest check doesn't involve trusting our binaries at all. Nova builds are reproducible — same source, same toolchain, same output bytes — so you can compile the release yourself and compare the result against the published manifest:

reproduce the build
git clone https://github.com/novawallet/nova
cd nova && git checkout v2.4.1
npm ci --ignore-scripts
npm run dist
# then hash dist/ output and diff against SHA256SUMS

Identical output means the published binary contains exactly the source you just read — nothing added at build time, nothing removed. A non-match means either the build isn't reproducible or the binary doesn't correspond to the tag; both are worth reporting.

Watch the wire

"Zero telemetry" is a claim anyone can write on a landing page. Ours is checkable: open Nova, leave it idle, and capture its traffic. Below is what that capture looks like — the feed runs while you watch it:

wire watch — nova process · simulated capturelive
capture idle · 0 telemetry frames

RPC calls happen only when you ask for them — checking a balance, broadcasting a transaction. Analytics, crash reporters, fingerprinting beacons, session logs: none exist in the codebase, so none appear on the wire. Run it yourself with any packet capture tool and count.

How rare this is

WalletScrutiny tracks whether published wallet binaries actually correspond to their public source. Of 4,921 wallets reviewed, only 122 pass reproducibility checks — about 2.5%. The rest can't prove the download matches the code, which means "open source" on the README is doing the security work of a slogan.

Verification is not a feature you use once — it's a posture. Hash the release, skim the diff, watch the traffic. A wallet that survives that scrutiny earns the keys it holds; one that doesn't is asking for faith, and faith is what every drain on this site exploits.

Verify once. Then trust what's running.

Self-custody only means something if the software is the software you think it is. Five minutes with a checksum settles it.

Connect Wallet Security model
NovaWallet

Security-first self-custody.
Your keys never leave this window.

Product

FeaturesRewardsNova Points

Learn

BlogCompareChangelog

Legal

Terms of UsePrivacy Policy
© 2026 Nova WalletSelf-custody · Zero telemetry · Open source