Bitcoin wallet app made to test payment systems against double-spend attacks.
About this app
Double-spending is no longer a theoretical possibility but a practical reality. Most of the end-user applications used widely today leave their users vulnerable to being defrauded via double-spend attacks. PayNoWay is a tool that you can use to test the applications that you, or your business, depend on to accept on-chain cryptocurrency payments.
Features: - Send payment transactions with the same UX flow as other wallet applications. - Easily broadcast double-spend transaction after a payment is sent, to return the funds to the internal wallet address. - Fetch current network fee rate, or set a custom value. - Optionally set automatic broadcasting of double-spend transactions. - Control what happens to the payment transaction output - "Drop it" or "Replace with dust". - By default double-spend transactions are broadcast to several web services simultaneously to improve chances of confirmation. - Bitcoin mainnet and testnet networks - Several address types - Legacy (p2pkh), SegWit backwards compatible, SegWit (bech32). - Transaction history view where you can re-broadcast any past transaction, copy to clipboard any transaction as raw hexadecimal, or update any locally stored transaction by fetching it from the configured web service. - Statistics dashboard (Payments vs. Double-spends) which shows total number of transactions as well as their total values. Optionally reset the dashboard at any time.
Disclaimers: - This app is intended to be used for testing and educational purposes. - Please do not use this app to double-spend against merchants without their explicit consent. - A successful double-spend is not guaranteed - use at your own risk. - You are responsible for creating a backup of your private key(s). Without a backup, if you delete the app or lose your device, your funds will be permanently lost.
Permissions: - Camera, flashlight - To scan QR codes that contain an on-chain addresses, payment requests, and optionally a private key (WIF) during configuration. - Access network state - For detecting if the device is offline. This helps provide feedback to you, the user, in case of temporary loss of network connectivity. - Internet - To query web service APIs to broadcast transactions, fetch minimum relay fee rate, fetch transaction history and unspent transaction outputs.
Licensed under GPL-3.0-only, by Charles Hill.
What's New in v2.1.0
Imported from the F-Droid repository index.
Version history
May 23, 2021 · 6.8 MB · Android API 22–29 · code 20100
Imported from the F-Droid repository index.
SHA-256 a1ebc88ece1a313ffcaa5b6b880a316d1a4bcd4ee1bf0073306b50933cbfc19d
Will it run on your device?
73%
- Runs on a broad range of modern Android versions.
- ABI coverage is focused on newer 64-bit devices.
Installation Guide
Open Settings on your Android device
Go to Security → Unknown sources (or Install unknown apps)
Enable "Allow from this source" for your browser or file manager
Open the downloaded APK file from your Downloads folder
Tap "Install" and wait for installation to complete
Launch the app from your home screen
Make sure to re-enable Unknown Sources restrictions after installation for security.
How to install this safely
How to verify the file you downloaded
Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.
What the signing certificate proves
Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be com.github.samotari.paynoway is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.
How to roll back to an earlier version
No earlier build is on record for PayNoWay, so there is nothing to roll back to yet. When a second version is published, this section will explain how to move between them safely.
Why we list sources instead of hosting everything
The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of PayNoWay, and a listing is removed when the evidence for it stops holding up.
Get PayNoWay
Every source we list for com.github.samotari.paynoway is legality-reviewed. Pirated or cracked builds are never offered.
Other sources
F-Droid listing
officialF-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.
Source code
verified publisherThe upstream repository this build is compiled from.
We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.
App Information
Security Verification
We record provenance; we do not run malware scans. Verify the hash yourself before installing.
SHA-256 Hash
a1ebc88ece1a313ffcaa5b6b880a316d1a4bcd4ee1bf0073306b50933cbfc19d
Signing certificate
66f0669fb6c0f99e3425fb13c322a46393e92662f7602c8388978acadf23a855
Permissions Required
Previous Versions
No earlier build is on record — this is the first release we have listed.
The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.
Report a problem with this listing
A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.