Air-gapped Bitcoin signer for offline cold storage. QR-only, no network.
About this app
MetroVault turns an Android phone into a secure, air-gapped Bitcoin signing device like a cold-storage hardware wallet. It acts as an offline signer for your watch-only wallets (such as Sparrow, BlueWallet, or Electrum) running on an online device. Your private keys are generated and kept on a phone that never connects to the internet; all communication happens through QR codes, and network access is blocked at the Android level.
Because the keys never touch an online device, the attack surface for theft and malware is dramatically reduced. MetroVault is fully open source and auditable, built on a custom Kotlin Bitcoin library so every cryptographic operation can be reviewed.
Security
* Air-gapped operation — designed for devices with no internet (airplane mode, Wi-Fi/Bluetooth off) * Dual-layer encryption — AES-256-GCM with PBKDF2 (210k iterations) plus the Android Keystore * Biometric unlock — hardware-backed fingerprint/face authentication * Plausible deniability — separate "Main" and "Decoy" wallets behind different passwords * Brute-force protection — exponential backoff with lockout, and an optional automatic wipe after repeated failed logins * Screenshots and screen recording are blocked app-wide
Wallets
* Single-sig and multi-sig (collaborative custody) support * Address types: Native SegWit (bc1q), Taproot (bc1p), Nested SegWit (3...) and Legacy (1...) * BIP-352 Silent Payments support, both to send to or spend from an SP wallet * BIP-39 passphrase support, saved locally or kept in memory only * BIP-85 derivation of child seeds and passwords * Custom entropy from dice rolls or coin flips, plus mnemonic checksum tools * Testnet4 support for testing
Transaction signing
* PSBT workflow (BIP-174) for single-sig and multi-sig * Air-gapped flow: scan PSBT, verify, sign, export — entirely by QR * Animated QR support: BC-UR (v1/v2) and BBQr for large transactions * On-device address verification and watch-only XPUB/descriptor export * Message signing and verification
Permissions
MetroVault requests only the camera (optional, for scanning QR codes) and biometric permissions. It has no internet permission and cannot connect to any network.
Licensed under GPL-3.0-or-later, by Gorun Jinian.
What's New in v3.8.7
Imported from the F-Droid repository index.
- - Import Multisig Wallet is now available directly from the add-wallet menu on the home screen
- - Refreshed the app icon for consistent display across launchers and F-Droid
- - Documentation and reproducible-build improvements
Version history
Jun 25, 2026 · 8.8 MB · Android API 26–36 · code 6
Imported from the F-Droid repository index.
- - Import Multisig Wallet is now available directly from the add-wallet menu on the home screen
- - Refreshed the app icon for consistent display across launchers and F-Droid
- - Documentation and reproducible-build improvements
SHA-256 f2ac25f6dd350e46e6e19c8a7a2898588d9464b64dfe1d605221e76d03bab948
Jun 22, 2026 · 8.8 MB · Android API 26–36 · code 5
Imported from the F-Droid repository index.
- - Added BIP-352 Silent Payments support
- - Added multisig wallet registration and verification to guard against tampered descriptors and deceptive change outputs
- - Added BIP-322 message signing
- - UI cleanups and stability improvements
SHA-256 6a8575c879096b068eeeb21373ad8dd53f96505d1e42356fc210fb557d623f5c
Will it run on your device?
92%
- Runs on a broad range of modern Android versions.
- Multiple CPU architectures are covered.
- Aligned with the latest Android target SDK expectations.
Installation Guide
Open Settings on your Android device
Go to Security → Unknown sources (or Install unknown apps)
Enable "Allow from this source" for your browser or file manager
Open the downloaded APK file from your Downloads folder
Tap "Install" and wait for installation to complete
Launch the app from your home screen
Make sure to re-enable Unknown Sources restrictions after installation for security.
How to install this safely
How to verify the file you downloaded
Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.
What the signing certificate proves
Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be com.gorunjinian.metrovault is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.
How to roll back to an earlier version
If the current release misbehaves, 3.8.6 is the last build before it. Android will not install an older version code over a newer one, so you must uninstall MetroVault first — which clears its local data unless you have a backup. Reinstall the older APK only if its signing fingerprint matches the build you already trust, and check the API range: an older release may target an Android version your device has moved past.
Why we list sources instead of hosting everything
The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of MetroVault, and a listing is removed when the evidence for it stops holding up.
Get MetroVault
Every source we list for com.gorunjinian.metrovault is legality-reviewed. Pirated or cracked builds are never offered.
Other sources
F-Droid listing
officialF-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.
Source code
verified publisherThe upstream repository this build is compiled from.
We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.
App Information
Security Verification
We record provenance; we do not run malware scans. Verify the hash yourself before installing.
SHA-256 Hash
f2ac25f6dd350e46e6e19c8a7a2898588d9464b64dfe1d605221e76d03bab948
Signing certificate
1245554ceb17cea21e9912af7bf60d38d716f5884d4b3664e5338462cc76fd03
Permissions Required
Previous Versions
The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.
Report a problem with this listing
A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.