github citadel-foss/openswap v0.2.3

3 hours ago

OpenSwap v0.2.3 Release Notes

This is the first release under the OpenSwap name. Between July 1, 2026 and October 1, 2026, the project moved to the citadel-foss organization and the core library gained an Electrum backend, Lightning swaps, PaySwap payments to a third party, a negotiated fee policy with funding splits, and a sealed, always-encrypted wallet. An internal audit hardened the swap and recovery paths, and a new app, Portal, now brings the wallet and the maker into one client.

📋 Changelog Summary (v0.2.2 → v0.2.3)

  • 🔧 54 Issues Closed across security, recovery, fee policy, wallet, and marketplace: View on GitHub
  • ✅ 80 Merged PRs in the core openswap repo for v0.2.2 → v0.2.3: View on GitHub
  • 🧱 Core repo diff since v0.2.2: 194 files changed, 56k+ insertions, 12k+ deletions

🔁 Special Note: Coinswap is now OpenSwap

The project has been renamed from Coinswap to OpenSwap and moved from citadel-tech to the citadel-foss organization (#988).

  • The crate is now openswap. The core repository is citadel-foss/openswap, and the bindings live in openswap-ffi.
  • The default data directory is now ~/.openswap.
  • Several swap APIs dropped the redundant protocol prefix (for example, prepare_openswap → prepare_swap). Downstream integrations need a rename pass.
  • The project website is now openswap.live, and the signet faucet is at faucet.openswap.live.

Highlights of v0.2.3

The major highlights of this release are as follows:

  • Electrum backend. The wallet, taker, maker, and watchtower can now run against either Bitcoin Core or an Electrum server, chosen at runtime from config. Users can now swap without running their own Bitcoin Core node.
  • Lightning swaps. A new LDK Server interface adds on-chain → Lightning, Lightning → on-chain, and routed swaps through two makers, with capacity limits, fee limits, and recovery of interrupted swaps. See lightning swaps.
  • PaySwap. A taker can now settle a swap straight to a third-party address. The receiver gets exactly the requested amount, and the route is replayed to the satoshi before the swap starts.
  • Negotiated fee policy. Taker and maker agree one fee rate at the start of each swap, makers can fund a hop with several smaller transactions (splits), the minimum swap amount is derived per swap instead of hardcoded, and recovery transactions are priced from our own backend. Automatic maker selection now picks the cheapest makers first. See the fee policy.
  • Wallet security. The master key stays sealed in memory and is only unsealed for a single signing step. Wallet files and backups are always encrypted. New wallets get a standard BIP39 seed phrase that works in other wallets and can restore the wallet. See wallet security.
  • Audit hardening. Two waves of internal audit fixes bound the Taproot key to the expected MuSig2 aggregate, capped concurrent swap admissions, rate-limited inbound Tor connections, authenticated the maker RPC with a local cookie, and closed several arithmetic overflow and underflow paths in the protocol code.
  • Trust in the marketplace. Takers now ban makers they can prove cheated, while failures that could be our own never count against a maker. Makers and takers can screen funding sources against an optional blocklist, makers publish a readable public name, and stale makers are pruned from the offerbook. See the blocklist.
  • Recovery overhaul. Recovery now broadcasts every refund before waiting, settles each swap exactly one way, and reads what is still owed from the wallet file and the chain. A crash or restart can no longer leave a claim unmade or settle a swap both ways.
  • Portal, a new desktop and self-hosted web app that combines the swap wallet and the maker in one client.

Major Improvements in v0.2.3

Type Improvement PR(s) Contributor
Security Bind the Taproot internal key to the expected MuSig2 aggregate on both sides, so a maker cannot control the key path. #963, #973 0xEgao, mojoX911
Security Audit fixes: cap concurrent swap admissions, persist incoming swapcoins at acceptance, bound backend waits, and invalidate the Electrum header cache on reorg. #973, #976 mojoX911
Security Rate-limit inbound Tor connections and bound the maker RPC frame size before allocation. #997, #955 0xEgao
Security Authenticate maker RPC requests with a local cookie. #943 0xEgao
Security Reject duplicate funding proofs and unbound legacy proof-of-funding contracts. #952, #944 0xEgao
Security Make the maker sign only its own contract, and detect a Legacy contract broadcast mid-swap. #1065, #1056 Godzilla-oss
Security Enforce the 21M cap and checked arithmetic in protocol amount, locktime, and fee-split code. #1011, #1013, #1018, #1020 ManthanNimodiya
Security Reject multisig redeemscripts too short to hold both pubkeys, so a peer cannot crash the maker thread reading its proof of funding. #1035 Atishyy27
Security Validate maker onion addresses and fidelity announcements, and clean invalid stored entries. #1000 0xEgao
Wallet Seal the master key in memory and make wallet file encryption mandatory. #993 mojoX911
Wallet Reject plaintext wallet files when a password is supplied. #942 0xEgao
Wallet Add a standard BIP39 seed phrase with restore support, and derive the coin type from the network per BIP-44. #960, #970 Godzilla-oss
Wallet Resume an interrupted restore scan before loading the wallet, so funds past the normal address gap are not missed. #1084 0xEgao
Backend Add the Electrum backend behind one Blockchain interface, alongside Bitcoin Core. #945 mojoX911
Backend Serialize Electrum requests on the shared socket and fix a watcher shutdown deadlock. #977, #1007 0xEgao
Lightning Add an LDK Server interface for on-chain ↔ Lightning and routed swaps. #972 stark-3k
Protocol Add PaySwap: settle a swap to a third-party receiver for an exact amount. #975 0xEgao
Fee Policy Negotiate one fee rate per swap and let makers fund a hop with several splits. #1015 mojoX911
Fee Policy Derive the minimum swap amount per swap and price timelock recovery from our own backend. #1057, #1044 mojoX911
Fee Policy Select automatic makers by estimated total fee. #1069 0xEgao
Marketplace Ban makers we can prove cheated, separate from makers that are only unavailable. #1034 mojoX911
Marketplace Add optional funding-source address blocklist screening. #999 Godzilla-oss
Marketplace Let makers publish a public name shown next to their address. #1060 mojoX911
Marketplace Prune stale makers and support safe rediscovery. #1017 0xEgao
Recovery Batch recovery broadcasts and settle each swap exactly one way. #1062 mojoX911
Recovery Settle recovered swaps from the wallet state so a crash cannot lose or double a claim. #1074 mojoX911
Recovery Scope taker recovery to failed swaps, and wait for it before the CLI exits. #1039, #1009 Godzilla-oss
Recovery Record confirmed timelock recoveries as resolved and discard unsigned legacy swapcoins when funding cannot confirm. #1058, #1027 ManthanNimodiya
Recovery Stop completed swaps from re-entering recovery. #1048 0xEgao
Maker Fail closed when the maker watchtower exits, and adopt an unconfirmed fidelity bond on restart. #978, #991 0xEgao, mojoX911
Taker Keep maker sessions and the route heartbeat alive through funding waits and finalization. #958, #965, #1042 0xEgao
Reporting Report swap UTXOs and wallet-owned sweep outputs in swap reports, and fix maker earned fees. #1006, #928 0xEgao
Testing Audit-driven test completion, and a test framework that takes a maker count instead of fixed ports. #984, #1025, #1046 mojoX911, Supremesv715, 0xEgao
Infrastructure Dispatch compatibility builds to the FFI, Maker Dashboard, and Taker App repos on every core merge. #959, #967, #985 0xEgao
Infrastructure Rebrand the project from Coinswap to OpenSwap. #988 mojoX911

Notable Issues Closed

The following issues were among the most important items addressed during the release window:

  • #961: A missing MuSig2 internal-key binding let a maker control the Taproot key path.
  • #941: The wallet password could be bypassed by replacing an encrypted wallet with a plaintext one.
  • #1064: The maker signed any receiver contract it was sent.
  • #660 and #661: Rate limiting for maker servers, and a UTXO blocking mechanism.
  • #953: The maker kept swapping after its watchtower thread died.
  • #940: A hardcoded 2 sat/vB fee floor broke mainnet swaps during mempool congestion.
  • #841: Add an Electrum replacement for Bitcoin Core RPC syncing.
  • #951: There was no way to back up or restore a wallet from a seed phrase.
  • #1033: The recovery loop could broadcast a live swap's contract transaction.
  • #1070, #1071, and #1072: A restarted maker could forget a hashlock claim, wallet and tracker saves were not crash-safe together, and a taker could claim its incoming after refunding its outgoing.
  • #981 and #1037: Bring back maker bans, and add human-readable maker names to the market.

Ecosystem Updates Beyond the Core Repo

This release also includes substantial work in the surrounding OpenSwap ecosystem:

  • Portal is new this cycle: one app for both roles, a swap wallet and a maker, that runs on the desktop or as a self-hosted server reached from a browser. It gained maker integration, a recovery and wallet-setup flow, the new fee policy and funding splits, maker names in the market table, a recovery view that separates locked funds from payments owed to the router, Umbrel packaging, and Linux and macOS desktop builds.
  • OpenSwap-FFI added C# bindings, Electrum support with a 2×4 backend test matrix, cross-language API contract tests, live swap coverage for JavaScript, Ruby, and React Native, and exposed the new blocklist, negotiated fee rate, and maker banning behavior.
  • BTCPay Plugin is new this cycle, bringing OpenSwap into BTCPay Server with a taker wallet, swap quotes, background swaps, and a maker dashboard with operator notifications and stalled-swap handling.
  • Maker Dashboard added deniability proof support, followed core API changes, and now reports upstream compatibility build failures.
  • coinswap-kotlin added an Android taker app built on the Electrum backend.
  • Protocol Specification added the PaySwap specification.

Documentation and References

Documentation also improved during this cycle:

  • Four new guides in the core repo: wallet security, fee policy, lightning swaps, and the blocklist.
  • A full docs sync for v0.2.3 brought the maker, taker, CLI, Docker, Tor, and bitcoind guides in line with the current commands, config, and logs, and fixed the Docker maker stack so it starts and runs (#1082, closing #1078).
  • The demo walkthrough was rewritten around Portal: getting the app, the Wallet and Router roles, and swapping on the custom signet against Portal's default Electrum server. See the demo.
  • The README now points to Portal, the demo, the new website, and the new faucet.
  • Portal added a developer guide, and OpenSwap-FFI documented the C# binding.

Full Changelog: v0.2.2...v0.2.3

Weighted Contribution Ranking

Contributions across all public citadel-foss repositories, including the new Portal app, are scored with a per-PR impact model that combines two tracks:

  • Authorship — each merged pull request scores severity × criticality × durability. Severity reflects the nature of the change (security > bug fix > feature > refactor/infrastructure > docs/chore); criticality weights the openswap core library highest and the other repositories lower, refined by how central the touched code is; durability discounts reverted work.
  • Stewardship — code review and issue triage (opening, closing, and labeling), weighted to favor substantive participation.

Each contributor's authorship and stewardship are combined into a single score, normalized to 100%. Automated bot accounts are excluded.

Rank Contributor PRs (core/aux) Reviews Issues (open/close) Authorship Score %
1 0xEgao 39 / 25 3 5 / 31 170.2 38.6%
2 mojoX911 15 / 1 51 31 / 48 45.5 20.7%
3 ManthanNimodiya 10 / 0 0 0 / 0 64.3 12.5%
4 Godzilla-oss 9 / 0 6 9 / 0 35.8 8.6%
5 uqlidi 0 / 17 3 3 / 0 21.7 4.9%
6 keraliss 0 / 16 0 0 / 0 21.7 4.2%
7 Atishyy27 2 / 0 0 0 / 0 15.4 3.0%
8 stark-3k 2 / 0 9 3 / 3 5.7 2.5%
9 NeoZ666 0 / 2 1 9 / 2 2.8 1.9%
10 Supremesv715 2 / 0 0 0 / 0 3.9 0.8%
11 YoganshSharma 1 / 0 0 1 / 0 3.0 0.7%
12 hulxv 0 / 1 0 0 / 0 2.1 0.4%
13 tanishkaa08 0 / 1 0 0 / 0 1.4 0.3%
14 6D-pixel 0 / 0 1 0 / 0 0.0 0.2%

Plus three issue-only reporters (LusterSourav, anipy1, kallal79) at ≈0.1–0.4% each.

Major References

Don't miss a new openswap release

NewReleases is sending notifications on new releases.