spark.exposed

Recovery requirements and wallet support

The exit

The documented operatorless-exit procedure, its state and fee prerequisites, and what eleven reviewed consumer-wallet surfaces exposed.

How to read this topic: 5 principal evidence groups organize 25 supporting records by the question they answer.

Critical boundary: The review identifies implementation, usability, and economic constraints. It does not claim that protocol-level exit is impossible or that a prepared user with current recovery state and external fee funds cannot exit.

Evidence group 01

Recovery state must extend beyond the seed

An all-Operator-outage exit requires current leaf and ancestor state acquired while Operators are reachable; wallet mutations can make a one-time backup stale.

Scope boundary: The state need not use Blink's format. With complete current state, matching keys, and fee funds, the documented procedure can continue without later Operator cooperation.

Evidence group 02

Exit is a staged execution workflow

The reviewed reference path constructs and advances ordered packages, persists progress, waits through timelocks, and performs later sweeps rather than broadcasting one transaction.

Scope boundary: Separate tooling can automate these stages. Their complexity establishes operational burden, not cryptographic impossibility.

The exit

Spark’s FAQ reduces exit to a pre-signed broadcast; its beta manual documents a multi-stage expert procedure

Spark's FAQ says a user can exit at any time by broadcasting a pre-signed transaction. Its dedicated beta manual separately requires Bitcoin Core v29, external L1 UTXOs, economic leaf selection, exact package ordering, mainnet signing and timelock handling, and warns that the wallet is unusable until completion. [4 sources]

Official documentation · Pinned source codeRead the analysis

Evidence group 03

Economics depend on wallet history and fee conditions

Leaf values, ancestry depth, and external fee inputs determine package count and net recovery; a displayed Spark balance alone does not express exit cost.

Scope boundary: Large, shallow leaves can remain economical. The measured figures describe one documented wallet and should not be generalized to every balance.

Evidence group 04

Advertised self-custody stops short of outage recovery

The wallets advertise non-custodial control or seed recovery, but the dated review found no complete in-app operatorless workflow across eleven named surfaces. In an all-Operator failure, the ordinary mobile user remains operationally dependent on third-party services.

Scope boundary: Open-source results are snapshot-specific; binary searches cannot rule out obfuscated paths; closed-source results are limited to public claims and observed interfaces.

The exit

No complete in-app operatorless exit was found in eleven reviewed consumer-wallet products

The reviewed snapshots and public interfaces for Blink, Primal, Cake, Blitz, Radar, Flash, Agicash, Layerz, Club Orange, Wallet of Satoshi, and Bringin exposed no complete in-app sequence for preserving current exit state, supplying CPFP funds, ordered broadcasting, durable resume, timelock handling, and final sweeping. Closed-source findings are limited to public claims and observed interfaces. [14 sources]

Repository record · Web source · Blog or announcementRead the analysis

The exit

Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path

Across Primal, Radar, Wallet of Satoshi, and Bringin, public control or recovery claims were not matched in the reviewed surfaces by a demonstrated complete user-operated exit. Closed-source findings are limited to published claims, instructions, and observed interfaces rather than unseen implementation code. [18 sources]

Repository record · Pinned source code · Web sourceRead the analysis

Evidence group 05

Public descriptions require careful accounting

One published account described seed-only recovery and an amount as received before the reviewed record showed the final sweep and full economic accounting.

Scope boundary: Real mainnet packages were advanced without later Operator cooperation. The discrepancy concerns prerequisites and completion language, not whether the exit began.