spark.exposed

The exit

Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path

The refreshed public review found no complete in-app recovery flow in Primal or Radar. Primal Android has upgraded its SDK and iOS its compiled shared dependency. Wallet of Satoshi’s newer guidance and Bringin’s public translations still do not supply a complete operator-outage procedure; their app internals remain unverified. 123

3 sourcesEvidence reviewed through September 11, 2026

Fresh source, release metadata, APK-surface and public-documentation review on September 11. Source and release versions are distinguished; no funded wallet runtime or operator-outage execution was performed.

What the evidence shows

Technical and product details

  1. Primal

    Primal Android now pins Breez 0.23.1 and receives the UnilateralExitStateChanged event, which the inspected handler forwards to its SDK event stream and logs. No application call to initiate, export or execute an exit was found. The iOS wallet still exposes seed-based restore through an opaque PrimalShared 0.3.2 binary dependency; its public UI did not expose a complete operatorless flow. 1

    Supporting material shown on this page

  2. Radar

    The unchanged Android and iOS source heads expose seed backup and ordinary Spark payments. Neither source-visible interface supplied current exit-state export and an operatorless broadcast, confirmation and restart-recovery workflow. 1

    Supporting material shown on this page

  3. Wallet of Satoshi

    The new recovery-phrase article explicitly says a conventional Bitcoin wallet will not recreate the Spark balance and directs users to compatible Spark software. The disclosure still describes permissionless exits, but the reviewed public instructions do not supply an operator-outage procedure for preserving state and executing recovery. In-app exit support remains unverified because the application code and binary were not inspected. 21

    Supporting material shown on this page

  4. Bringin

    Bringin now publishes mobile UI translations, but not the executable application in its public organization. The reviewed strings describe cloud and twelve-word backups; no operational operatorless-exit procedure was found in those strings or the cited product material. Its public claim of pre-signed exits remains an unverified implementation claim. 31

    Supporting material shown on this page

    Bringin published recovery translationsPinned source code · github.com · checked 2026-09-11
    Relevant lines from the pinned source · open raw file
    541  "backup_prompt_heading": "Back up your wallet",
    542  "backup_prompt_why_title": "Why back up?",
    543  "backup_prompt_why_description": "Backing up your wallet ensures you can recover your Bitcoin if you lose access to your device or app. Without a backup, your funds cannot be recovered.",
    544  "backup_option_cloud_title": "Back up to Google Drive / iCloud",
    545  "backup_option_cloud_subtitle": "Automatic backup. If you lose your device, you can recover your wallet easily.",
    546  "backup_option_write_down_title": "Write down recovery phrase",
    547  "backup_option_write_down_subtitle": "Save your 12-word phrase securely. It’s the only way to recover your wallet.",

Product-level detail

What was publicly verifiable for the four named products

The conclusions below are reproduced here so the reader does not need to open the separate implementation review. Each result remains limited to the named source snapshot, published binary, or public product surface.

Primal

Surface reviewed: public android and ios source

Primal Android now pins Breez 0.23.1 and receives the UnilateralExitStateChanged event, which the inspected handler forwards to its SDK event stream and logs. No application call to initiate, export or execute an exit was found. The iOS wallet still exposes seed-based restore through an opaque PrimalShared 0.3.2 binary dependency; its public UI did not expose a complete operatorless flow.

Capabilities that were present: seed backup and live-network wallet restore; ordinary Breez Spark wallet operations; Android SDK 0.23.1 upgrade and exit-state event handling; no matching application recovery command found.

The result is bounded to the two pinned public repositories and does not test an unpublished build.

Radar

Surface reviewed: public android and ios source

The unchanged Android and iOS source heads expose seed backup and ordinary Spark payments. Neither source-visible interface supplied current exit-state export and an operatorless broadcast, confirmation and restart-recovery workflow.

Capabilities that were present: seed backup and live-network restoration in a Spark-compatible wallet; ordinary Breez Spark wallet operations.

The result is bounded to the two pinned public repositories.

Wallet of Satoshi

Surface reviewed: public documentation and source availability

The new recovery-phrase article explicitly says a conventional Bitcoin wallet will not recreate the Spark balance and directs users to compatible Spark software. The disclosure still describes permissionless exits, but the reviewed public instructions do not supply an operator-outage procedure for preserving state and executing recovery. In-app exit support remains unverified because the application code and binary were not inspected.

Capabilities that were present: published description of unilateral exit as a permissionless alternative; seed-backup and ordinary wallet-restore guidance; explicit documentation that Spark recovery needs compatible key derivation and software.

No source-code absence claim is made.

Bringin

Surface reviewed: public documentation and source availability

Bringin now publishes mobile UI translations, but not the executable application in its public organization. The reviewed strings describe cloud and twelve-word backups; no operational operatorless-exit procedure was found in those strings or the cited product material. Its public claim of pre-signed exits remains an unverified implementation claim.

Capabilities that were present: first-party claim that each wallet ships with pre-signed exits and can leave without Bringin cooperation.

No source-code absence claim is made because Bringin does not publish the reviewed mobile-app source.

See versions, search method, artifact hashes, and full review limits.

Scope control

What this does not establish

  • Primal iOS depends on the opaque PrimalShared 0.3.2 framework; Radar iOS omits its FFI binary and Pods submodule. The source-visible review cannot establish every transitive capability. Wallet of Satoshi and Bringin received public-documentation review, not a private-code or binary runtime audit. 1

Sources and excerpts

Primary sources

The relevant details and available source-code excerpts appear alongside the claims above. This list preserves the complete original-source trail for independent verification.

1

consumer-wallet exit audit manifest

Reproducible audit manifest · Review of Spark's trust model · Pinned or archival · checked 2026-09-11

Open original source
2

Wallet of Satoshi August 31 recovery guidance

Web source · support.walletofsatoshi.com · Live source · checked 2026-09-11

Open original source
3

Bringin published recovery translations

Pinned source code · github.com · Pinned or archival · checked 2026-09-11

Open original source

How sources, absence findings, and limitations were evaluated