A developer releases software through a website, but how does a user know the downloaded file actually came from the developer and has not been intercepted, modified, or replaced by an attacker? This question becomes sharper when the software controls private keys to Bitcoin funds. Wasabi Wallet, an open-source, non-custodial Bitcoin wallet with built-in CoinJoin mixing, publishes releases across multiple platforms, but distribution channels are vulnerable to compromise. A network attacker, malicious ISP, or DNS hijack could serve a backdoored version without changing the filename or breaking HTTPS.
Signature verification using GPG (GNU Privacy Guard) solves that problem by proving that a specific developer signed the file with a private key that only they control. The process requires learning a few technical steps, but it transforms a trust assumption—”I hope this file is genuine”—into a cryptographic guarantee. For anyone downloading an open-source wallet or security tool, verification should not be optional. This article walks through the entire process, from obtaining the developer’s public key through confirming that your downloaded release is legitimate.
Why signature verification matters for a Bitcoin wallet download
A Bitcoin wallet holds the cryptographic keys to actual money. An attacker who replaces the legitimate software with a trojanized version can steal those keys the moment they are generated or imported. Unlike a compromised website that steals a password, a compromised wallet can drain funds without the user ever knowing until the balance is checked. The attack is also silent—the fake wallet can be designed to look and behave identically to the real one.
HTTPS offers transport security, preventing an attacker on your local network from seeing or altering the download in transit. It does not verify that the file came from Wasabi’s developers or that the server itself has not been compromised. A stolen server certificate, a misconfigured cloud provider, or a supply-chain attack on the hosting infrastructure could all result in serving malicious code over a secure connection. Signature verification operates at a different layer: it confirms that the file was signed by a specific private key before it ever left the developer’s machine, independent of how or where you obtained it.
Wasabi Wallet, as an open-source wallet, publishes its releases on GitHub and provides GPG signatures alongside binaries. This design allows anyone to verify that the version they download matches the one reviewed by the security community and committed to the public repository. The alternative—trusting only the website or the file hash alone—leaves users vulnerable to subtle attacks that occur after the code has been reviewed and before it reaches their machine.
The verification process is not difficult, but it requires understanding a few concepts: public-key cryptography, how GPG works, what a fingerprint is, and how to interpret the output. The payoff is immediate: confirmation that your wasabi wallet download has not been altered or replaced since the developer signed it.
Understanding GPG and public-key cryptography
GPG is a tool that implements the OpenPGP standard for signing and encrypting data using public-key cryptography. The central insight is that a pair of mathematically related keys can be created such that anything encrypted with the public key can only be decrypted with the private key, and anything signed with the private key can be verified with the public key. The developer keeps their private key secret; the public key is shared openly.
When a developer signs a software release, they run GPG with their private key to create a digital signature. The signature is a short piece of data (often a few hundred bytes) that corresponds to the exact content of the file. If even one bit of the file changes, the signature becomes invalid. The user downloads the file and the signature separately, then runs GPG with the developer’s public key to verify that the signature is valid. This proves that the file has not been modified and that it was signed by whoever controls the private key.
The security of this system rests on two assumptions. First, the private key must remain private—if an attacker gains access, they can forge signatures. Second, the user must obtain the genuine public key. If an attacker tricks you into using a fake public key, they can sign malicious files and you will verify them as legitimate. For this reason, the public key should come from a trusted source, preferably obtained through multiple independent channels or verified against a published fingerprint.
A fingerprint is a short hash of the public key, typically 40 hexadecimal characters. Rather than comparing entire keys (which are much longer), users often compare fingerprints. If the fingerprint you see locally matches the fingerprint published on the official wasabi wallet official site, GitHub, and other trusted sources, you can be confident you have the correct key.
Obtaining the Wasabi Wallet developer public key
The first step in verifying a wasabi wallet download is to obtain the public key used to sign the releases. Wasabi publishes this key on GitHub, in the official repository, and sometimes on the project website. The key is also distributed through the MIT PGP keyserver and other public key directories, though obtaining it from the official channels first is the most secure approach.
Visit the Wasabi GitHub repository and look for a file called something like KEYS, SIGNING.md, or a similar document in the root directory. This file will contain the public key or a link to where it can be found. You can also check the releases page, where signatures are often attached to each release alongside the binaries. Copy the public key text or download it as a .asc or .gpg file. Do not paste it into a password manager or email; keep it local during this process.
If you are using Linux or macOS and have GPG installed, you can import the key directly from a keyserver using a command like gpg –keyserver pgp.mit.edu –recv-keys KEYID, replacing KEYID with the actual key identifier. This approach is faster but less secure than importing from an official source, because you are trusting the keyserver not to serve a substituted key. For a wallet that controls Bitcoin, the extra step of verifying the key fingerprint against multiple published sources is worth the time.
Record the key fingerprint from at least two independent sources—the GitHub repository, the official website, and a public announcement by the developer. If you find that different sources show different fingerprints, do not proceed until you understand why. A discrepancy usually indicates a problem that needs investigation before you trust the key.
Downloading both the software and its signature
When you locate a wasabi wallet download on the official release page, you will find two types of files: the actual software binary (a .exe, .dmg, .tar.gz, or other installer) and a signature file, usually with a .sig, .asc, or .gpg extension. Download both files to the same directory on your computer. Do not extract or install the software yet.
The signature file is extremely small—usually under 1 KB—because it is just the cryptographic signature, not the entire software. It contains no executable code and poses no risk by itself. The signature corresponds to exactly one version of the software, so if you download version 2.0.4, you must also download the signature for 2.0.4. Mixing versions will cause verification to fail, and mixing signatures can mask a genuine problem as a false error.
If multiple signature files are available (for example, separate signatures for Windows and macOS versions), ensure you are matching the correct signature to the correct software. The filename usually makes this clear: wasabi-2.0.4-Windows.exe and wasabi-2.0.4-Windows.exe.sig should be paired together. Some developers also publish SHA256 checksums of the binaries, which is helpful for catching accidental corruption, but checksums alone do not prove authenticity—a signature does.
Keep your downloads in a dedicated directory until verification is complete. This reduces the chance of mixing versions or accidentally using the wrong signature. Once you have confirmed that the signature is valid, you can feel confident installing the software. If verification fails, delete both files and re-download from the official wasabi wallet official site.
Installing and using GPG on your platform
If you are using Linux, GPG is likely already installed. Open a terminal and type gpg –version to check. If it is not installed, use your distribution’s package manager: apt install gnupg on Debian/Ubuntu, pacman -S gnupg on Arch, or the equivalent for your system. macOS users can install GPG via Homebrew (brew install gnupg), MacPorts, or by downloading the GPG Suite, which includes a graphical interface. Windows users can download Gpg4win, which provides a command-line tool and optional graphical utilities.
After installation, verify that GPG is working by opening a terminal or command prompt and typing gpg –version. You should see version information and a list of supported features. If the command is not found, your PATH may need adjustment or the installation did not complete correctly. On Windows, you may need to use gpg.exe instead of gpg, or open PowerShell with administrator privileges.
For this guide, we will use the command-line interface, which works identically across all platforms and is less prone to mistakes than graphical tools. If you strongly prefer a graphical approach, Kleopatra (part of Gpg4win on Windows) and other GUIs provide equivalent functionality, but the steps will be slightly different. Reading this guide first will help you understand what the graphical tool is doing underneath.
Before proceeding, create a test directory and place your downloaded wasabi wallet software and signature file inside it. Using a separate directory keeps the process organized and prevents accidental operations on other files. On Windows, you can use File Explorer; on macOS or Linux, open Terminal and use mkdir to create a directory, then move your files there using mv or cp.
Importing the public key and verifying the signature
With your files in place and GPG installed, open a terminal or command prompt in your test directory. If you downloaded the public key as a separate file (ending in .asc or .gpg), import it using gpg –import wasabi-public-key.asc, replacing the filename with whatever you downloaded. GPG will confirm that the key has been imported and display information about it, including the key ID and any user IDs associated with the key.
If you copy-pasted the key text into a file, you can import that file in the same way. The important step is that GPG now has the public key loaded into its local keyring. You can verify this by running gpg –list-keys, which will display all keys you have imported. The Wasabi key should appear in that list.
Now verify the signature by running gpg –verify wasabi-2.0.4-Windows.exe.sig wasabi-2.0.4-Windows.exe, replacing the filenames with your actual downloaded files. The order matters: the .sig file comes first, then the software file. GPG will check whether the signature is valid, whether it was signed by a key you have imported, and whether the file has been modified since signing. A successful verification will produce output similar to: “Good signature from ‘Wasabi Wallet
The “not certified with a trusted key” message is normal if you have not explicitly told GPG that you trust the key. It does not mean the signature is invalid or the file is compromised. It simply means GPG is warning you that you have not gone through the formal process of certifying the key. For a software download, verifying the fingerprint as described earlier is sufficient trust confirmation.
If GPG produces an error like “Bad signature” or “Can’t find a public key,” stop immediately and do not install the software. A bad signature usually means the file or signature has been corrupted or tampered with. Delete both files and re-download from the official source. If verification fails repeatedly, investigate whether you have the correct version and signature pair, and double-check that the public key fingerprint matches published sources.
Verifying the key fingerprint and establishing trust
After importing the public key, display its fingerprint using gpg –fingerprint KEYID, where KEYID is the ID shown when you imported the key. This will print a line of 40 hexadecimal characters, formatted in groups of four. Take this fingerprint and compare it to at least two published sources: the GitHub repository, the official wasabi wallet official site, and any signed announcements by the project. Fingerprints must match exactly—a single different digit indicates a problem.
If the fingerprints do not match across sources, or if one source shows a different fingerprint than another, pause and investigate. This discrepancy is unlikely but more serious than a failed signature verification, because it suggests a compromised key or a supply-chain attack at a higher level. Reach out to the project through an alternative channel—a social media account known to belong to the developers, or a direct email address—and ask for clarification.
Once you have confirmed that the fingerprint matches across multiple sources, you have established that you are using the correct public key. You can now be confident that a valid signature produced by GPG is proof that the file came from the developers and has not been modified. The wasabi wallet download you have verified is authentic and ready to install.
Some users choose to mark the key as trusted in GPG using gpg –edit-key KEYID and selecting the trust option. This tells GPG that you have verified the key and it should not warn you about a “not certified with a trusted key” message in the future. This is optional, but it reduces noise in the output of future verifications and is reasonable after you have checked the fingerprint against multiple sources.
Installing and testing the verified software
After a successful signature verification, you can install Wasabi Wallet with confidence that the file is genuine and has not been modified in transit or on your disk. On Windows, double-click the .exe file to run the installer. On macOS, double-click the .dmg and drag the application to Applications. On Linux, extract the tar.gz file and run the binary or follow the project’s installation instructions.
During the first launch, Wasabi will ask you to set up a wallet, configure your privacy preferences, and optionally connect to a hardware wallet. Review these settings carefully. The software you are installing is open-source, so its code is transparent and can be audited by the security community. This transparency is the foundation of trust for a secure Bitcoin wallet, but it only matters if you have verified that you are actually running the code published in the repository.
Consider creating a test wallet with a small amount of Bitcoin before moving significant funds. This allows you to verify that the software behaves as expected, that you can send and receive transactions, and that the CoinJoin mixing feature works correctly. Only after confirming that the wallet functions properly should you import your actual seed phrase or create a wallet intended for long-term storage.
Keep your public key file and the signature of your downloaded version for future reference. If you ever need to verify a new release, the public key (if it has not changed) can be reused. The signature you verified today can serve as evidence that you obtained the software from a legitimate source, which is valuable if you ever need to justify your security practices or investigate a concern about wallet compromise.
Common verification failures and troubleshooting
A “No public key” error means GPG cannot find the key used to sign the file. This usually indicates that you have not imported the key, or that you imported a different key than the one used for this signature. Solution: verify that you have the correct public key, import it explicitly using gpg –import, and try verification again.
A “Bad signature” error means the file has been modified, the signature has been corrupted, or you are using the wrong signature for this version of software. Solution: delete both the file and signature, re-download them from the official wasabi wallet official site (not a mirror or third-party link), verify that the filenames match, and try again. If the problem persists, check whether you have the latest version of GPG installed.
A “Signature made from … key … (but the signature is not certified with a trusted key)” is not an error. This is a normal warning if you have not explicitly trusted the key in GPG. It does not indicate a problem with the file. If the key ID shown matches your imported key and the fingerprint is correct, the signature is valid.
On Windows, ensure you are using the correct path separator (backslash or forward slash, depending on your shell) and that file paths with spaces are quoted. For example: gpg –verify “wasabi-2.0.4-Windows.exe.sig” “wasabi-2.0.4-Windows.exe”. On Linux and macOS, forward slashes and no quotes are typical, but quotes do not hurt.
If you cannot locate a signature file on the release page, check whether the project publishes signatures in a separate file (for example, SHA256SUMS.asc or SIGNATURES.txt) that contains multiple signatures. Alternatively, visit the GitHub Releases page directly, which sometimes displays attachments that are not visible on the main website. Wasabi’s project maintains signature files for each release, though their exact location may vary between versions.
Frequently asked questions
Do I really need to verify the signature of my wasabi wallet download?
If you are downloading software that controls Bitcoin private keys, yes. Signature verification is the only way to confirm that the file has not been modified or replaced since the developer signed it. HTTPS protects the file in transit, but it does not prove authenticity. For a wallet, the additional 10 minutes required for verification is a worthwhile investment.
What if the signature verification fails?
Do not install the software. Delete both the file and the signature, then re-download from the official wasabi wallet official site. A failed signature usually indicates file corruption or a version mismatch. After re-downloading, verify again. If failure persists, contact the project to report the issue before proceeding.
Is Wasabi Wallet an open-source wallet, and does that make it more secure?
Yes, Wasabi is open-source, meaning its code is publicly available and can be reviewed by security researchers and the community. This transparency allows anyone to audit the code and report vulnerabilities. However, open-source alone does not guarantee security—you must verify that you are actually running the published code, which is why signature verification is essential.
Can I verify a wasabi wallet download on my smartphone or tablet?
GPG tools are available for Android and iOS, but most users should verify on a desktop or laptop where command-line and graphical tools are more mature and easier to use. If you must verify on a mobile device, use a dedicated GPG app from a trusted developer, but do not paste sensitive key information into untrusted applications.