Highlights
- Redesigned Receive, Send, and trade screens, a new startup wizard, and wallet restore from seed.
- 24 new payment methods across Africa, Latin America, Asia, Europe, Türkiye, and Russia.
- Broad security hardening of trades, disputes, the network layer, and the API.
- Faster startup, more reliable wallet sync and recovery, and lower CPU and memory use.
- Restored command line API client, Tor onion API access, and a new API user guide.
Before updating
This is not a mandatory update, but it is recommended for all users.
- Arbitrators must update before users.
- Back up your application directory before updating.
- The user agreement has been rewritten. Existing users are asked to accept it after updating.
What's Changed
User Interface
- Redesign the Receive, Send, and trade screens, including transaction details and confirmation dialogs.
- Add a startup wizard with wallet import, password setup, preferred currency, Monero node configuration, and a light/dark theme toggle.
- Restore a Monero wallet from its seed phrase, with an optional restore height or date.
- Show offer terms during payment and open details with a double click.
- Refresh chat with send status on each message, text selection, and Shift+Enter for new lines.
- Improve market charts with crosshairs, clearer tooltips, and a market price deviation scale.
- Show offer counts by payment method and search payment methods by country or currency.
- Simplify Tor bridge configuration with Snowflake and custom bridges, including WebTunnel.
- Show Monero connection errors in the footer and reduce connection popups.
- Add screen reader support and improve keyboard navigation.
- Add an optional software rendering setting for display problems.
- Refresh the light theme and polish navigation, tables, payment instructions, chat windows, popups, and notifications.
- Update translations.
Payment Methods
Add 24 payment methods:
- Africa: M-Pesa; NIP Instant Bank Transfer / OPay / PalmPay.
- Latin America: Mercado Pago; Mexico/SPEI; Pago Móvil.
- Asia: GCash; MoMo; QRIS / BI-FAST; Raast / Easypaisa / JazzCash; PayNow / FAST; FPS (Hong Kong); DuitNow; PayPay; Kaspi.
- Europe: BLIK; Vipps MobilePay; TWINT; Wero; MB WAY; Ukrainian card transfers.
- Türkiye: Papara / FAST.
- Russia: SBP; Mir card transfer; YooMoney.
Retire Popmoney.
Support all payment methods through structured API forms for mobile access.
Core
- Improve startup speed, seed node connectivity, and recovery from stalled connections.
- Refresh network data and trade statistics after connection loss or waking from standby.
- Add experimental native Monero wallets.
- Improve wallet synchronization, payout detection, trade recovery, and transaction retries after Monero node failures.
- Preserve reserved offer funds during trade initialization and prevent canceling offers already reserved for trades.
- Make password changes reliable and add a tool to repair an interrupted password change.
- Improve account backups, interrupted wallet restoration, and shutdown handling.
- Keep trade wallet backups until payouts are finalized.
- Reduce CPU and memory use in encrypted storage, network processing, and trade statistics.
- Store closed trades in a crash-safe encrypted append log.
- Fix inconsistent historical trade counts and USD volume across restarts.
- Allow price deviation up to 100% and warn about conflicting payment amounts before posting an offer.
- Restore the command line API client, add trade filtering by status and alert notifications, publish daemon jars with releases, and support API access through a Tor onion service.
- Add an API user guide covering setup, market data, trade notifications, and trading with haveno-ts.
- Make packaged Java archives reproducible and standardize build locale and encoding.
- Fix Tails installation after Tor Proof of Work changes and improve installer verification.
- Update Monero to v0.18.5.3, monero-java to v0.8.62, Tor to v0.4.9.13, Apache HttpClient to v5.6.4, and Gradle to v8.14.2.
Security
- Strengthen verification of trade participants, dispute message senders, arbitrator authorization, and network alerts.
- Prevent replayed dispute messages from reverting state and apply revised rulings by their signed timestamps.
- Strengthen payout address and transaction fee validation, account signing, and signer chain verification.
- Reject oversized network messages and payloads with mismatched hashes, limit offer signing and trade requests from peers, and block peers connected to the wrong Haveno network.
- Protect master seed export with account unlock checks and rate limits, tighten key and backup file permissions, redact sensitive error details, and remove dispute log file transfers.
- Reject trade chat after completion and between arbitrators and traders.
- Prevent archive extraction outside the destination directory and strengthen signing key verification for application updates.
- Require an API password before daemon startup, listen only on localhost unless a bind address is set, throttle failed logins, and restrict the bundled web proxy to local hosts and origins.
Contributors
Thanks to monerobull, fenlark, atsamd21, jpk68, and bvcxza for code contributions, and to Kevlar for a security review whose findings informed many fixes this release.
Full Changelog: v1.8.0...v1.9.0
Running Haveno
For the best experience, running your own local Monero node is highly recommended, as the Tor network can be slow and unreliable when syncing with remote Monero nodes.
Haveno can be used on the Monero mainnet via third-party networks. We do not officially endorse any specific networks at this time. You can start your own network by following these guidelines.
Installation Notes
Download and install Haveno using an installer for your operating system. The installer is provided by the network you're using. Alternatively, you can build from source by customizing these instructions for your chosen network.
Windows & Linux
- Uninstall any previous versions of Haveno before running the installer.
macOS
- Open installer and drag Haveno.app to Applications.
- Open a terminal window (cmd + space then type "terminal").
- Copy and paste into the terminal:
sudo xattr -rd com.apple.quarantine /Applications/Haveno.appand press enter. - Enter your computer password.
- Right click /Applications/Haveno.app > Open. Repeat again if needed, even if reported as damaged.
Tails
- See instructions. Network administrators are encouraged to make the one-line installation command available for each release.
Default application directory:
- Linux: ~/.local/share/Haveno/
- macOS: ~/Library/Application Support/Haveno/
- Windows: ~\AppData\Roaming\Haveno\