github ZeusLN/zeus v13.2.3-rc1

pre-release3 hours ago
ZEUS v13.2.3

v13.2.3 Highlights:

  • Embedded LND v0.21.4
  • LDK Node v0.7.0-zeus-rl-0.2.7 (rust-lightning v0.2.7 security fixes)
  • Further security hardening measures
  • Miscellaneous bug fixes
  • Miscellaneous UI improvements

What's Changed

  • [Transifex] Updates for project ZEUS by @transifex-integration[bot] in #4812
  • fix(swaps): re-derive the preimage when rescuing reverse swaps by @kaloudis in #4460
  • GraphSyncPromptModal: use whole strings for button labels by @myxmaster in #4820
  • fix: disable Open Channel button on missing or invalid input by @myxmaster in #4811
  • Embedded LND: v0.21.4-beta-zeus by @kaloudis in #4813
  • [Transifex] Updates for project ZEUS by @transifex-integration[bot] in #4823
  • fix(android): keep inputs and buttons above the keyboard by @kaloudis in #4807
  • [Transifex] Updates for project ZEUS by @transifex-integration[bot] in #4824
  • tests: cover LND wallet password generation by @kaloudis in #4825
  • fix(deps): replace react-native-securerandom with react-native-get-random-values by @a-khushal in #4099
  • build: remove stale RNSecureRandom pod lock by @kaloudis in #4826
  • stores: remove no-op BalanceStore settings reaction by @myxmaster in #4815
  • views: always prefill the fixed LNURL amount by @TheSeydiCharyyev in #4723
  • [Transifex] Updates for project ZEUS by @transifex-integration[bot] in #4830
  • stores: BalanceStore: clear error after a successful fetch by @myxmaster in #4831
  • lint: add rule against negative layout offsets by @myxmaster in #4817
  • views: label fixed-amount LNURL-pay requests by @TheSeydiCharyyev in #4832
  • views: validate LnurlPay params before using them by @TheSeydiCharyyev in #4833
  • stores: BalanceStore: only reset the failed fetch's loading flag by @myxmaster in #4834
  • Don't arm the Wallet settings refresh for writes that don't need a refetch by @myxmaster in #4837
  • views: OpenChannel, Send: fix fund max amount handling by @myxmaster in #4836
  • fix(pos): store per-item order tax in cents, add PosStore tests by @shubhamkmr04 in #4706
  • ldk-node: bump to v0.7.0-zeus-rl-0.2.7 (rust-lightning v0.2.7 security fixes) by @kaloudis in #4822
  • views: reject LnurlPay requests with minSendable 0 by @TheSeydiCharyyev in #4843
  • fix(stealth): keep decoy screens clear of the navigation bar by @kaloudis in #4806
  • fix(LNC): reconnect reliably after restart and wallet switch by @kaloudis in #4481
  • fix(security): authenticate share intents on the POS cold start by @kaloudis in #4713
  • [Transifex] Updates for project ZEUS by @transifex-integration[bot] in #4849
  • stores: ChannelsStore: require a host in connectPeer by @myxmaster in #4847
  • [Transifex] Updates for project ZEUS by @transifex-integration[bot] in #4853
  • docs(security): use security@zeusln.com for vulnerability reports by @kaloudis in #4854
  • fix: name and show the real LSPS1 peer on Open Channel by @shubhamkmr04 in #4718
  • CLNRest: report pending channel opens as pending_open_balance by @kaloudis in #4743
  • ConnectivityStore: clear offline state when monitoring stops by @myxmaster in #4851
  • fix(pos): copy total_tax_money when re-saving a standalone order by @shubhamkmr04 in #4858
  • chore(deps): bump the minor-and-patch group with 7 updates by @dependabot[bot] in #4859
  • ThemeUtils: align upgrade tint ramp with getUpgradeIntensity by @kaloudis in #4709
  • chore(deps): bump react-native-view-shot from 5.1.1 to 6.1.0 by @dependabot[bot] in #4860
  • Apply the user's routing fee limit to LDK BOLT 12 payments by @kaloudis in #4353
  • chore(deps): bump source-map-js from 1.2.1 to 1.2.2 by @dependabot[bot] in #4872
  • chore(deps): bump joi from 17.13.7 to 17.13.8 by @dependabot[bot] in #4874
  • chore(deps): bump joi from 17.13.7 to 17.13.8 in /zeus_modules/@lightninglabs/lnc-rn by @dependabot[bot] in #4873
  • chore(deps): bump compression from 1.8.1 to 1.8.2 by @dependabot[bot] in #4871
  • chore(deps): bump shell-quote from 1.10.0 to 1.12.0 in /zeus_modules/@lightninglabs/lnc-rn by @dependabot[bot] in #4870
  • chore(deps): resolve shell-quote to 1.12.0 (GHSA-pqg4-j6r4-53mv) by @kaloudis in #4879
  • chore(deps): bump compression from 1.7.4 to 1.8.2 in /zeus_modules/@lightninglabs/lnc-rn by @dependabot[bot] in #4869
  • chore(deps): bump bs58check from 2.1.2 to 4.0.0 by @dependabot[bot] in #4868
  • chore(deps): bump @scure/bip39 from 1.6.0 to 2.4.0 by @dependabot[bot] in #4863
  • fix(pos): stop adding tax on top of the Square recon total by @shubhamkmr04 in #4857
  • docs: PR template: fix typo, heading levels and test question by @myxmaster in #4885
  • chore(deps): bump bip32 from 3.0.1 to 5.0.1 by @dependabot[bot] in #4864
  • deps: bump pbkdf2 resolution to 3.1.7 by @kaloudis in #4884
  • chore(deps): bump @react-native-community/datetimepicker from 8.5.1 to 9.2.1 by @dependabot[bot] in #4862
  • chore(deps): bump @react-native-vector-icons/feather from 12.4.0 to 13.1.4 by @dependabot[bot] in #4867
  • utils: show tb1 addresses for CLN on signet by @TheSeydiCharyyev in #4855
  • Don't read clipboard on launch when clipboard reading is off by @kaloudis in #4856
  • views: OpenChannel, ChannelsSettings: hide min confs on LDK Node, load a saved 0 by @kaloudis in #4841
  • [Transifex] Updates for project ZEUS by @transifex-integration[bot] in #4895
  • fix(pos): restore the header on the POS connection error screen by @kaloudis in #4699
  • fix(pos): quote recon export fields so formatted rates stay in one column by @shubhamkmr04 in #4892
  • skills: document channel min confs and functional settings updates by @kaloudis in #4901
  • [Transifex] Updates for project ZEUS by @transifex-integration[bot] in #4900
  • docs: note that PP Neue Montreal and Marlide Display are commercial by @kaloudis in #4906
  • fix(utils): keep CSV export cells from being run as spreadsheet formulas by @shubhamkmr04 in #4896
  • ci: run gates on PRs into slash-named branches and set least-privilege permissions by @kaloudis in #4928
  • [Transifex] Updates for project ZEUS by @transifex-integration[bot] in #4931
  • skills: refresh test counts in zeus-validation-and-qa by @kaloudis in #4930
  • skills: replace stale zero-test-coverage claims by @kaloudis in #4934
  • Swaps: fix reverse swap claim from the creation screen by @kaloudis in #4893
  • fix(pos): show the full sale date on order rows by @kaloudis in #4746
  • themes: remove retired themes from the picker by @kaloudis in #4768
  • fix: preset wallet pictures not saving on Android release builds by @kaloudis in #4708
  • [Transifex] Updates for project ZEUS by @transifex-integration[bot] in #4941
  • Settings: merge group writes inside the queue, drop write locks by @kaloudis in #4904
  • Embedded LND: v0.21.4-beta-zeus.1 by @kaloudis in #4950
  • Alerts: drop the zombie channel count warning by @kaloudis in #4953
  • [Transifex] Updates for project ZEUS by @transifex-integration[bot] in #4954
  • oss-scanner: add build image and threat model by @kaloudis in #4955
  • tests: use fake timers in NodeInfoStore and DateTimeUtils tests by @kaloudis in #4926
  • Swaps: verify reverse swap lockup before claiming by @kaloudis in #4894
  • Swaps: fall back to an uncooperative refund when the host won't co-sign by @kaloudis in #4942
  • fix(bolt12): require offer review before paying on LDK Node by @kaloudis in #4365
  • [Transifex] Updates for project ZEUS by @transifex-integration[bot] in #4958
  • Embedded LND: recreate missing channel edges on SQLite nodes by @kaloudis in #4814

Full Changelog: v13.2.3-alpha1...v13.2.3-rc1

Verifying the Release

In order to verify the release, you'll need to have gpg or gpg2 installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

gpg --keyserver hkps://keys.openpgp.org --recv-keys 96C225207F2137E278C31CF7AAC48DE8AB8DEE84

Once you have his PGP key you can verify the release (assuming manifest-v13.2.3-rc1.txt and manifest-v13.2.3-rc1.txt.sig are in the current directory) with:

gpg --verify manifest-v13.2.3-rc1.txt.sig manifest-v13.2.3-rc1.txt

You should see the following if the verification was successful:

gpg: Signature made Fri Oct  9 13:55:11 2026 EDT
gpg:                using RSA key 96C225207F2137E278C31CF7AAC48DE8AB8DEE84
gpg:                issuer "zeusln@tutanota.com"
gpg: Good signature from "Zeus LN <zeusln@tutanota.com>"
gpg:                 aka "ZEUS Support <support@zeusln.com>"
gpg:                 aka "ZEUS Security <security@zeusln.com>"

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

cat manifest-v13.2.3-rc1.txt

One can use the shasum -a 256 <file name here> tool in order to re-compute the sha256 hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.

Android fingerprint

Users verifying the release on an Android device can check against the key fingerprint below using AppVerifier. This fingerprint can also be found on our website here.

SHA1: 32:06:3C:97:96:38:0D:99:EE:4A:CB:B8:1E:2A:6F:27:FD:66:8E:C1
  SHA256: 2A:F8:E2:0A:C9:44:57:67:CB:D4:4E:D8:4D:BB:FC:33:C6:C9:82:48:89:7C:4F:84:3C:42:C2:76:5C:4A:D3:BA
Signature algorithm name: SHA256withRSA
Subject Public Key Algorithm: 2048-bit RSA key
Version: 3

External links

ZEUS documentation
PGP Key

Android

arm64-v8a APK
Universal APK
Manifest
Manifest Signature

iOS

Apple TestFlight
IPA

Don't miss a new zeus release

NewReleases is sending notifications on new releases.