feat: add trezor receive - #693

Open
ben-kaufman wants to merge 5 commits into
masterfrom
feat/trezor-receive
Open

feat: add trezor receive#693
ben-kaufman wants to merge 5 commits into
masterfrom
feat/trezor-receive

Conversation

@ben-kaufman

@ben-kaufmanben-kaufman commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Summary

  • open the existing Receive sheet on a Trezor tab from the paired hardware-wallet screen
  • render the watcher-provided next-unused address immediately, with an account-scan fallback
  • support safe amount/message editing on the hardware address and exact on-device verification
  • match the receive design with a white selected underline, blue hardware QR/action accents, and verification inside Show Details

Stack

Linked Issues/Tasks

Fixes#707

Validation

  • iPhone 16 simulator build passes against Core 0.5.10
  • focused watcher receive-address test passes
  • SwiftFormat passes

@greptile-apps

Copy link
Copy Markdown

Greptile Summary

Adds Trezor receiving to the existing receive sheet, using watcher-provided addresses with an account-scan fallback and optional on-device verification.

  • Opens receive directly on the Trezor tab from a hardware-wallet screen.
  • Supports amount and message parameters for hardware-wallet BIP21 requests.
  • Adds reconnect, pairing-code, and passphrase handling for device verification.
  • Updates Bitkit Core to 0.5.10 and extends watcher-event handling for next-unused addresses.

Confidence Score: 5/5

The PR appears safe to merge, with no concrete blocking or independently actionable non-blocking defects identified.

The receive flow preserves explicit hardware-wallet identity from its primary entry point, obtains a next-unused address through watcher or account-scan state, and rejects device verification unless the returned address exactly matches the displayed destination.

Important Files Changed

FilenameOverview
Bitkit/Managers/HwWalletManager.swiftStores watcher-provided next-unused addresses, adds account-scan fallback, and verifies the displayed derivation directly on the Trezor.
Bitkit/Views/Wallets/Receive/ReceiveQr.swiftAdds the Trezor receive tab, hardware BIP21 rendering, address loading, and reconnect/passphrase-aware verification.
Bitkit/Views/Wallets/Receive/ReceiveEdit.swiftAdds an on-chain-only editing mode that preserves amount and message state without invoking Lightning or Paykit flows.
Bitkit/Views/Wallets/Receive/ReceiveSheet.swiftCarries hardware-wallet identity through receive navigation and presents pairing requests during reconnect.
Bitkit/Components/TabBar/TabBar.swiftOpens the receive sheet on the Trezor tab when invoked from a hardware-wallet route.
Bitkit.xcodeproj/project.xcodeprojUpdates Bitkit Core to the version providing the watcher receive-address payload.

Sequence Diagram

sequenceDiagram
participant User
participant Receive as Receive Sheet
participant Manager as Hardware Wallet Manager
participant Watcher as Watch-only Watcher
participant Electrum
participant Trezor
User->>Receive: Open Trezor receive tab
Receive->>Manager: Request receive address
Manager->>Watcher: Read cached next-unused address
alt Watcher address available
Watcher-->>Manager: Address and derivation path
else Watcher address unavailable
Manager->>Electrum: Scan account addresses
Electrum-->>Manager: First unused external address
end
Manager-->>Receive: Address and derivation path
Receive-->>User: Display QR and details
opt Verify on device
User->>Receive: Verify address
Receive->>Manager: Verify displayed address
Manager->>Trezor: Derive and display exact path
Trezor-->>Manager: Device-derived address
Manager-->>Receive: Accept only exact match
end
Loading

Reviews (1): Last reviewed commit: "feat: add trezor receive" | Re-trigger Greptile

ovitrif

This comment was marked as resolved.

@piotr-iohk

piotr-iohk commented Sep 1, 2026

Copy link
Copy Markdown
Collaborator

Tested on simulator and device (iPhone 13 + Trezor Safe 7).

Generally all good. Able to present the receive address, verify the address on the device, etc.

One observation (looks intentional in code, but may be misleading to the user): with 2+ paired hardware wallets (e.g. standard + passphrase), Home → Receive does not show the Trezor tab, so there is no hardware receive address from that entry point. Fine to defer to a follow-up PR — if that's the case, let's create a ticket for this.

Steps to reproduce

  1. Pair a Trezor (standard wallet). Home should show one hardware wallet tile.
  2. Add a passphrase wallet on the same device (Paired → Passphrase → enter passphrase). Home should now show two hardware wallet tiles.
  3. From the main/home screen, tap Receive.
  4. Only Savings / Spending tabs are shown. No Trezor tab, so you cannot get a hardware receive address.

Expected (or less misleading)

Home → Receive either shows a Trezor tab (or a wallet picker) when more than one hardware wallet is paired, or makes it clear that hardware receive is only available from the specific wallet screen.

Workaround

Open the specific hardware wallet screen first, then Receive. That path still shows the address.

Recording

ScreenRecording_09-01-2026.10-03-56_1.MP4

piotr-iohk
piotr-iohk previously approved these changes Sep 1, 2026

@piotr-iohkpiotr-iohk left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve. Single-wallet receive looks good on simulator and device. See the QA comment for the multi-wallet Home Receive note (fine to defer).

Base automatically changed from feat/trezor-send to masterSeptember 1, 2026 08:43
@ovitrif
ovitrif dismissed piotr-iohk’s stale reviewSeptember 1, 2026 08:43

The base branch was changed.

@ben-kaufman

Copy link
Copy Markdown
ContributorAuthor

The single-wallet hardware Receive flow remains green and its review threads are resolved. I filed #709 for the requested Home Receive wallet picker when multiple hardware wallets are paired. @piotr-iohk please re-review the current signed head because the earlier approval was dismissed after the branch update.

piotr-iohk
piotr-iohk previously approved these changes Sep 1, 2026
Comment threadBitkit/Managers/HwWalletManager.swift
Comment threadBitkit/Views/Wallets/Receive/ReceiveQr.swift Outdated

@ovitrifovitrif left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

utACK

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Receive to hardware wallet

4 participants

@ben-kaufman@piotr-iohk@ovitrif@coreyphillips
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat: add trezor receive - #693

Open
ben-kaufman wants to merge 5 commits into
masterfrom
feat/trezor-receive
Open

feat: add trezor receive#693
ben-kaufman wants to merge 5 commits into
masterfrom
feat/trezor-receive

Conversation

@ben-kaufman

@ben-kaufmanben-kaufman commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Summary

  • open the existing Receive sheet on a Trezor tab from the paired hardware-wallet screen
  • render the watcher-provided next-unused address immediately, with an account-scan fallback
  • support safe amount/message editing on the hardware address and exact on-device verification
  • match the receive design with a white selected underline, blue hardware QR/action accents, and verification inside Show Details

Stack

Linked Issues/Tasks

Fixes#707

Validation

  • iPhone 16 simulator build passes against Core 0.5.10
  • focused watcher receive-address test passes
  • SwiftFormat passes

@greptile-apps

Copy link
Copy Markdown

Greptile Summary

Adds Trezor receiving to the existing receive sheet, using watcher-provided addresses with an account-scan fallback and optional on-device verification.

  • Opens receive directly on the Trezor tab from a hardware-wallet screen.
  • Supports amount and message parameters for hardware-wallet BIP21 requests.
  • Adds reconnect, pairing-code, and passphrase handling for device verification.
  • Updates Bitkit Core to 0.5.10 and extends watcher-event handling for next-unused addresses.

Confidence Score: 5/5

The PR appears safe to merge, with no concrete blocking or independently actionable non-blocking defects identified.

The receive flow preserves explicit hardware-wallet identity from its primary entry point, obtains a next-unused address through watcher or account-scan state, and rejects device verification unless the returned address exactly matches the displayed destination.

Important Files Changed

FilenameOverview
Bitkit/Managers/HwWalletManager.swiftStores watcher-provided next-unused addresses, adds account-scan fallback, and verifies the displayed derivation directly on the Trezor.
Bitkit/Views/Wallets/Receive/ReceiveQr.swiftAdds the Trezor receive tab, hardware BIP21 rendering, address loading, and reconnect/passphrase-aware verification.
Bitkit/Views/Wallets/Receive/ReceiveEdit.swiftAdds an on-chain-only editing mode that preserves amount and message state without invoking Lightning or Paykit flows.
Bitkit/Views/Wallets/Receive/ReceiveSheet.swiftCarries hardware-wallet identity through receive navigation and presents pairing requests during reconnect.
Bitkit/Components/TabBar/TabBar.swiftOpens the receive sheet on the Trezor tab when invoked from a hardware-wallet route.
Bitkit.xcodeproj/project.xcodeprojUpdates Bitkit Core to the version providing the watcher receive-address payload.

Sequence Diagram

sequenceDiagram
participant User
participant Receive as Receive Sheet
participant Manager as Hardware Wallet Manager
participant Watcher as Watch-only Watcher
participant Electrum
participant Trezor
User->>Receive: Open Trezor receive tab
Receive->>Manager: Request receive address
Manager->>Watcher: Read cached next-unused address
alt Watcher address available
Watcher-->>Manager: Address and derivation path
else Watcher address unavailable
Manager->>Electrum: Scan account addresses
Electrum-->>Manager: First unused external address
end
Manager-->>Receive: Address and derivation path
Receive-->>User: Display QR and details
opt Verify on device
User->>Receive: Verify address
Receive->>Manager: Verify displayed address
Manager->>Trezor: Derive and display exact path
Trezor-->>Manager: Device-derived address
Manager-->>Receive: Accept only exact match
end
Loading

Reviews (1): Last reviewed commit: "feat: add trezor receive" | Re-trigger Greptile

ovitrif

This comment was marked as resolved.

@piotr-iohk

piotr-iohk commented Sep 1, 2026

Copy link
Copy Markdown
Collaborator

Tested on simulator and device (iPhone 13 + Trezor Safe 7).

Generally all good. Able to present the receive address, verify the address on the device, etc.

One observation (looks intentional in code, but may be misleading to the user): with 2+ paired hardware wallets (e.g. standard + passphrase), Home → Receive does not show the Trezor tab, so there is no hardware receive address from that entry point. Fine to defer to a follow-up PR — if that's the case, let's create a ticket for this.

Steps to reproduce

  1. Pair a Trezor (standard wallet). Home should show one hardware wallet tile.
  2. Add a passphrase wallet on the same device (Paired → Passphrase → enter passphrase). Home should now show two hardware wallet tiles.
  3. From the main/home screen, tap Receive.
  4. Only Savings / Spending tabs are shown. No Trezor tab, so you cannot get a hardware receive address.

Expected (or less misleading)

Home → Receive either shows a Trezor tab (or a wallet picker) when more than one hardware wallet is paired, or makes it clear that hardware receive is only available from the specific wallet screen.

Workaround

Open the specific hardware wallet screen first, then Receive. That path still shows the address.

Recording

ScreenRecording_09-01-2026.10-03-56_1.MP4

piotr-iohk
piotr-iohk previously approved these changes Sep 1, 2026

@piotr-iohkpiotr-iohk left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve. Single-wallet receive looks good on simulator and device. See the QA comment for the multi-wallet Home Receive note (fine to defer).

Base automatically changed from feat/trezor-send to masterSeptember 1, 2026 08:43
@ovitrif
ovitrif dismissed piotr-iohk’s stale reviewSeptember 1, 2026 08:43

The base branch was changed.

@ben-kaufman

Copy link
Copy Markdown
ContributorAuthor

The single-wallet hardware Receive flow remains green and its review threads are resolved. I filed #709 for the requested Home Receive wallet picker when multiple hardware wallets are paired. @piotr-iohk please re-review the current signed head because the earlier approval was dismissed after the branch update.

piotr-iohk
piotr-iohk previously approved these changes Sep 1, 2026
Comment threadBitkit/Managers/HwWalletManager.swift
Comment threadBitkit/Views/Wallets/Receive/ReceiveQr.swift Outdated

@ovitrifovitrif left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

utACK

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Receive to hardware wallet

4 participants

@ben-kaufman@piotr-iohk@ovitrif@coreyphillips
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: add trezor receive - #693

Open
ben-kaufman wants to merge 5 commits into
masterfrom
feat/trezor-receive
Open

feat: add trezor receive#693
ben-kaufman wants to merge 5 commits into
masterfrom
feat/trezor-receive

Conversation

@ben-kaufman

@ben-kaufmanben-kaufman commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Summary

  • open the existing Receive sheet on a Trezor tab from the paired hardware-wallet screen
  • render the watcher-provided next-unused address immediately, with an account-scan fallback
  • support safe amount/message editing on the hardware address and exact on-device verification
  • match the receive design with a white selected underline, blue hardware QR/action accents, and verification inside Show Details

Stack

Linked Issues/Tasks

Fixes#707

Validation

  • iPhone 16 simulator build passes against Core 0.5.10
  • focused watcher receive-address test passes
  • SwiftFormat passes

@greptile-apps

Copy link
Copy Markdown

Greptile Summary

Adds Trezor receiving to the existing receive sheet, using watcher-provided addresses with an account-scan fallback and optional on-device verification.

  • Opens receive directly on the Trezor tab from a hardware-wallet screen.
  • Supports amount and message parameters for hardware-wallet BIP21 requests.
  • Adds reconnect, pairing-code, and passphrase handling for device verification.
  • Updates Bitkit Core to 0.5.10 and extends watcher-event handling for next-unused addresses.

Confidence Score: 5/5

The PR appears safe to merge, with no concrete blocking or independently actionable non-blocking defects identified.

The receive flow preserves explicit hardware-wallet identity from its primary entry point, obtains a next-unused address through watcher or account-scan state, and rejects device verification unless the returned address exactly matches the displayed destination.

Important Files Changed

FilenameOverview
Bitkit/Managers/HwWalletManager.swiftStores watcher-provided next-unused addresses, adds account-scan fallback, and verifies the displayed derivation directly on the Trezor.
Bitkit/Views/Wallets/Receive/ReceiveQr.swiftAdds the Trezor receive tab, hardware BIP21 rendering, address loading, and reconnect/passphrase-aware verification.
Bitkit/Views/Wallets/Receive/ReceiveEdit.swiftAdds an on-chain-only editing mode that preserves amount and message state without invoking Lightning or Paykit flows.
Bitkit/Views/Wallets/Receive/ReceiveSheet.swiftCarries hardware-wallet identity through receive navigation and presents pairing requests during reconnect.
Bitkit/Components/TabBar/TabBar.swiftOpens the receive sheet on the Trezor tab when invoked from a hardware-wallet route.
Bitkit.xcodeproj/project.xcodeprojUpdates Bitkit Core to the version providing the watcher receive-address payload.

Sequence Diagram

sequenceDiagram
participant User
participant Receive as Receive Sheet
participant Manager as Hardware Wallet Manager
participant Watcher as Watch-only Watcher
participant Electrum
participant Trezor
User->>Receive: Open Trezor receive tab
Receive->>Manager: Request receive address
Manager->>Watcher: Read cached next-unused address
alt Watcher address available
Watcher-->>Manager: Address and derivation path
else Watcher address unavailable
Manager->>Electrum: Scan account addresses
Electrum-->>Manager: First unused external address
end
Manager-->>Receive: Address and derivation path
Receive-->>User: Display QR and details
opt Verify on device
User->>Receive: Verify address
Receive->>Manager: Verify displayed address
Manager->>Trezor: Derive and display exact path
Trezor-->>Manager: Device-derived address
Manager-->>Receive: Accept only exact match
end
Loading

Reviews (1): Last reviewed commit: "feat: add trezor receive" | Re-trigger Greptile

ovitrif

This comment was marked as resolved.

@piotr-iohk

piotr-iohk commented Sep 1, 2026

Copy link
Copy Markdown
Collaborator

Tested on simulator and device (iPhone 13 + Trezor Safe 7).

Generally all good. Able to present the receive address, verify the address on the device, etc.

One observation (looks intentional in code, but may be misleading to the user): with 2+ paired hardware wallets (e.g. standard + passphrase), Home → Receive does not show the Trezor tab, so there is no hardware receive address from that entry point. Fine to defer to a follow-up PR — if that's the case, let's create a ticket for this.

Steps to reproduce

  1. Pair a Trezor (standard wallet). Home should show one hardware wallet tile.
  2. Add a passphrase wallet on the same device (Paired → Passphrase → enter passphrase). Home should now show two hardware wallet tiles.
  3. From the main/home screen, tap Receive.
  4. Only Savings / Spending tabs are shown. No Trezor tab, so you cannot get a hardware receive address.

Expected (or less misleading)

Home → Receive either shows a Trezor tab (or a wallet picker) when more than one hardware wallet is paired, or makes it clear that hardware receive is only available from the specific wallet screen.

Workaround

Open the specific hardware wallet screen first, then Receive. That path still shows the address.

Recording

ScreenRecording_09-01-2026.10-03-56_1.MP4

piotr-iohk
piotr-iohk previously approved these changes Sep 1, 2026

@piotr-iohkpiotr-iohk left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve. Single-wallet receive looks good on simulator and device. See the QA comment for the multi-wallet Home Receive note (fine to defer).

Base automatically changed from feat/trezor-send to masterSeptember 1, 2026 08:43
@ovitrif
ovitrif dismissed piotr-iohk’s stale reviewSeptember 1, 2026 08:43

The base branch was changed.

@ben-kaufman

Copy link
Copy Markdown
ContributorAuthor

The single-wallet hardware Receive flow remains green and its review threads are resolved. I filed #709 for the requested Home Receive wallet picker when multiple hardware wallets are paired. @piotr-iohk please re-review the current signed head because the earlier approval was dismissed after the branch update.

piotr-iohk
piotr-iohk previously approved these changes Sep 1, 2026
Comment threadBitkit/Managers/HwWalletManager.swift
Comment threadBitkit/Views/Wallets/Receive/ReceiveQr.swift Outdated

@ovitrifovitrif left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

utACK

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Receive to hardware wallet

4 participants

@ben-kaufman@piotr-iohk@ovitrif@coreyphillips
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: add trezor receive - #693

Open
ben-kaufman wants to merge 5 commits into
masterfrom
feat/trezor-receive
Open

feat: add trezor receive#693
ben-kaufman wants to merge 5 commits into
masterfrom
feat/trezor-receive

Conversation

@ben-kaufman

@ben-kaufmanben-kaufman commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Summary

  • open the existing Receive sheet on a Trezor tab from the paired hardware-wallet screen
  • render the watcher-provided next-unused address immediately, with an account-scan fallback
  • support safe amount/message editing on the hardware address and exact on-device verification
  • match the receive design with a white selected underline, blue hardware QR/action accents, and verification inside Show Details

Stack

Linked Issues/Tasks

Fixes#707

Validation

  • iPhone 16 simulator build passes against Core 0.5.10
  • focused watcher receive-address test passes
  • SwiftFormat passes

@greptile-apps

Copy link
Copy Markdown

Greptile Summary

Adds Trezor receiving to the existing receive sheet, using watcher-provided addresses with an account-scan fallback and optional on-device verification.

  • Opens receive directly on the Trezor tab from a hardware-wallet screen.
  • Supports amount and message parameters for hardware-wallet BIP21 requests.
  • Adds reconnect, pairing-code, and passphrase handling for device verification.
  • Updates Bitkit Core to 0.5.10 and extends watcher-event handling for next-unused addresses.

Confidence Score: 5/5

The PR appears safe to merge, with no concrete blocking or independently actionable non-blocking defects identified.

The receive flow preserves explicit hardware-wallet identity from its primary entry point, obtains a next-unused address through watcher or account-scan state, and rejects device verification unless the returned address exactly matches the displayed destination.

Important Files Changed

FilenameOverview
Bitkit/Managers/HwWalletManager.swiftStores watcher-provided next-unused addresses, adds account-scan fallback, and verifies the displayed derivation directly on the Trezor.
Bitkit/Views/Wallets/Receive/ReceiveQr.swiftAdds the Trezor receive tab, hardware BIP21 rendering, address loading, and reconnect/passphrase-aware verification.
Bitkit/Views/Wallets/Receive/ReceiveEdit.swiftAdds an on-chain-only editing mode that preserves amount and message state without invoking Lightning or Paykit flows.
Bitkit/Views/Wallets/Receive/ReceiveSheet.swiftCarries hardware-wallet identity through receive navigation and presents pairing requests during reconnect.
Bitkit/Components/TabBar/TabBar.swiftOpens the receive sheet on the Trezor tab when invoked from a hardware-wallet route.
Bitkit.xcodeproj/project.xcodeprojUpdates Bitkit Core to the version providing the watcher receive-address payload.

Sequence Diagram

sequenceDiagram
participant User
participant Receive as Receive Sheet
participant Manager as Hardware Wallet Manager
participant Watcher as Watch-only Watcher
participant Electrum
participant Trezor
User->>Receive: Open Trezor receive tab
Receive->>Manager: Request receive address
Manager->>Watcher: Read cached next-unused address
alt Watcher address available
Watcher-->>Manager: Address and derivation path
else Watcher address unavailable
Manager->>Electrum: Scan account addresses
Electrum-->>Manager: First unused external address
end
Manager-->>Receive: Address and derivation path
Receive-->>User: Display QR and details
opt Verify on device
User->>Receive: Verify address
Receive->>Manager: Verify displayed address
Manager->>Trezor: Derive and display exact path
Trezor-->>Manager: Device-derived address
Manager-->>Receive: Accept only exact match
end
Loading

Reviews (1): Last reviewed commit: "feat: add trezor receive" | Re-trigger Greptile

ovitrif

This comment was marked as resolved.

@piotr-iohk

piotr-iohk commented Sep 1, 2026

Copy link
Copy Markdown
Collaborator

Tested on simulator and device (iPhone 13 + Trezor Safe 7).

Generally all good. Able to present the receive address, verify the address on the device, etc.

One observation (looks intentional in code, but may be misleading to the user): with 2+ paired hardware wallets (e.g. standard + passphrase), Home → Receive does not show the Trezor tab, so there is no hardware receive address from that entry point. Fine to defer to a follow-up PR — if that's the case, let's create a ticket for this.

Steps to reproduce

  1. Pair a Trezor (standard wallet). Home should show one hardware wallet tile.
  2. Add a passphrase wallet on the same device (Paired → Passphrase → enter passphrase). Home should now show two hardware wallet tiles.
  3. From the main/home screen, tap Receive.
  4. Only Savings / Spending tabs are shown. No Trezor tab, so you cannot get a hardware receive address.

Expected (or less misleading)

Home → Receive either shows a Trezor tab (or a wallet picker) when more than one hardware wallet is paired, or makes it clear that hardware receive is only available from the specific wallet screen.

Workaround

Open the specific hardware wallet screen first, then Receive. That path still shows the address.

Recording

ScreenRecording_09-01-2026.10-03-56_1.MP4

piotr-iohk
piotr-iohk previously approved these changes Sep 1, 2026

@piotr-iohkpiotr-iohk left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve. Single-wallet receive looks good on simulator and device. See the QA comment for the multi-wallet Home Receive note (fine to defer).

Base automatically changed from feat/trezor-send to masterSeptember 1, 2026 08:43
@ovitrif
ovitrif dismissed piotr-iohk’s stale reviewSeptember 1, 2026 08:43

The base branch was changed.

@ben-kaufman

Copy link
Copy Markdown
ContributorAuthor

The single-wallet hardware Receive flow remains green and its review threads are resolved. I filed #709 for the requested Home Receive wallet picker when multiple hardware wallets are paired. @piotr-iohk please re-review the current signed head because the earlier approval was dismissed after the branch update.

piotr-iohk
piotr-iohk previously approved these changes Sep 1, 2026
Comment threadBitkit/Managers/HwWalletManager.swift
Comment threadBitkit/Views/Wallets/Receive/ReceiveQr.swift Outdated

@ovitrifovitrif left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

utACK

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Receive to hardware wallet

4 participants

@ben-kaufman@piotr-iohk@ovitrif@coreyphillips
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat: add trezor receive - #693

Open
ben-kaufman wants to merge 5 commits into
masterfrom
feat/trezor-receive
Open

feat: add trezor receive#693
ben-kaufman wants to merge 5 commits into
masterfrom
feat/trezor-receive

Conversation

@ben-kaufman

@ben-kaufmanben-kaufman commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Summary

  • open the existing Receive sheet on a Trezor tab from the paired hardware-wallet screen
  • render the watcher-provided next-unused address immediately, with an account-scan fallback
  • support safe amount/message editing on the hardware address and exact on-device verification
  • match the receive design with a white selected underline, blue hardware QR/action accents, and verification inside Show Details

Stack

Linked Issues/Tasks

Fixes#707

Validation

  • iPhone 16 simulator build passes against Core 0.5.10
  • focused watcher receive-address test passes
  • SwiftFormat passes

@greptile-apps

Copy link
Copy Markdown

Greptile Summary

Adds Trezor receiving to the existing receive sheet, using watcher-provided addresses with an account-scan fallback and optional on-device verification.

  • Opens receive directly on the Trezor tab from a hardware-wallet screen.
  • Supports amount and message parameters for hardware-wallet BIP21 requests.
  • Adds reconnect, pairing-code, and passphrase handling for device verification.
  • Updates Bitkit Core to 0.5.10 and extends watcher-event handling for next-unused addresses.

Confidence Score: 5/5

The PR appears safe to merge, with no concrete blocking or independently actionable non-blocking defects identified.

The receive flow preserves explicit hardware-wallet identity from its primary entry point, obtains a next-unused address through watcher or account-scan state, and rejects device verification unless the returned address exactly matches the displayed destination.

Important Files Changed

FilenameOverview
Bitkit/Managers/HwWalletManager.swiftStores watcher-provided next-unused addresses, adds account-scan fallback, and verifies the displayed derivation directly on the Trezor.
Bitkit/Views/Wallets/Receive/ReceiveQr.swiftAdds the Trezor receive tab, hardware BIP21 rendering, address loading, and reconnect/passphrase-aware verification.
Bitkit/Views/Wallets/Receive/ReceiveEdit.swiftAdds an on-chain-only editing mode that preserves amount and message state without invoking Lightning or Paykit flows.
Bitkit/Views/Wallets/Receive/ReceiveSheet.swiftCarries hardware-wallet identity through receive navigation and presents pairing requests during reconnect.
Bitkit/Components/TabBar/TabBar.swiftOpens the receive sheet on the Trezor tab when invoked from a hardware-wallet route.
Bitkit.xcodeproj/project.xcodeprojUpdates Bitkit Core to the version providing the watcher receive-address payload.

Sequence Diagram

sequenceDiagram
participant User
participant Receive as Receive Sheet
participant Manager as Hardware Wallet Manager
participant Watcher as Watch-only Watcher
participant Electrum
participant Trezor
User->>Receive: Open Trezor receive tab
Receive->>Manager: Request receive address
Manager->>Watcher: Read cached next-unused address
alt Watcher address available
Watcher-->>Manager: Address and derivation path
else Watcher address unavailable
Manager->>Electrum: Scan account addresses
Electrum-->>Manager: First unused external address
end
Manager-->>Receive: Address and derivation path
Receive-->>User: Display QR and details
opt Verify on device
User->>Receive: Verify address
Receive->>Manager: Verify displayed address
Manager->>Trezor: Derive and display exact path
Trezor-->>Manager: Device-derived address
Manager-->>Receive: Accept only exact match
end
Loading

Reviews (1): Last reviewed commit: "feat: add trezor receive" | Re-trigger Greptile

ovitrif

This comment was marked as resolved.

@piotr-iohk

piotr-iohk commented Sep 1, 2026

Copy link
Copy Markdown
Collaborator

Tested on simulator and device (iPhone 13 + Trezor Safe 7).

Generally all good. Able to present the receive address, verify the address on the device, etc.

One observation (looks intentional in code, but may be misleading to the user): with 2+ paired hardware wallets (e.g. standard + passphrase), Home → Receive does not show the Trezor tab, so there is no hardware receive address from that entry point. Fine to defer to a follow-up PR — if that's the case, let's create a ticket for this.

Steps to reproduce

  1. Pair a Trezor (standard wallet). Home should show one hardware wallet tile.
  2. Add a passphrase wallet on the same device (Paired → Passphrase → enter passphrase). Home should now show two hardware wallet tiles.
  3. From the main/home screen, tap Receive.
  4. Only Savings / Spending tabs are shown. No Trezor tab, so you cannot get a hardware receive address.

Expected (or less misleading)

Home → Receive either shows a Trezor tab (or a wallet picker) when more than one hardware wallet is paired, or makes it clear that hardware receive is only available from the specific wallet screen.

Workaround

Open the specific hardware wallet screen first, then Receive. That path still shows the address.

Recording

ScreenRecording_09-01-2026.10-03-56_1.MP4

piotr-iohk
piotr-iohk previously approved these changes Sep 1, 2026

@piotr-iohkpiotr-iohk left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve. Single-wallet receive looks good on simulator and device. See the QA comment for the multi-wallet Home Receive note (fine to defer).

Base automatically changed from feat/trezor-send to masterSeptember 1, 2026 08:43
@ovitrif
ovitrif dismissed piotr-iohk’s stale reviewSeptember 1, 2026 08:43

The base branch was changed.

@ben-kaufman

Copy link
Copy Markdown
ContributorAuthor

The single-wallet hardware Receive flow remains green and its review threads are resolved. I filed #709 for the requested Home Receive wallet picker when multiple hardware wallets are paired. @piotr-iohk please re-review the current signed head because the earlier approval was dismissed after the branch update.

piotr-iohk
piotr-iohk previously approved these changes Sep 1, 2026
Comment threadBitkit/Managers/HwWalletManager.swift
Comment threadBitkit/Views/Wallets/Receive/ReceiveQr.swift Outdated

@ovitrifovitrif left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

utACK

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Receive to hardware wallet

4 participants

@ben-kaufman@piotr-iohk@ovitrif@coreyphillips
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: add trezor receive - #693

Open
ben-kaufman wants to merge 5 commits into
masterfrom
feat/trezor-receive
Open

feat: add trezor receive#693
ben-kaufman wants to merge 5 commits into
masterfrom
feat/trezor-receive

Conversation

@ben-kaufman

@ben-kaufmanben-kaufman commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Summary

  • open the existing Receive sheet on a Trezor tab from the paired hardware-wallet screen
  • render the watcher-provided next-unused address immediately, with an account-scan fallback
  • support safe amount/message editing on the hardware address and exact on-device verification
  • match the receive design with a white selected underline, blue hardware QR/action accents, and verification inside Show Details

Stack

Linked Issues/Tasks

Fixes#707

Validation

  • iPhone 16 simulator build passes against Core 0.5.10
  • focused watcher receive-address test passes
  • SwiftFormat passes

@greptile-apps

Copy link
Copy Markdown

Greptile Summary

Adds Trezor receiving to the existing receive sheet, using watcher-provided addresses with an account-scan fallback and optional on-device verification.

  • Opens receive directly on the Trezor tab from a hardware-wallet screen.
  • Supports amount and message parameters for hardware-wallet BIP21 requests.
  • Adds reconnect, pairing-code, and passphrase handling for device verification.
  • Updates Bitkit Core to 0.5.10 and extends watcher-event handling for next-unused addresses.

Confidence Score: 5/5

The PR appears safe to merge, with no concrete blocking or independently actionable non-blocking defects identified.

The receive flow preserves explicit hardware-wallet identity from its primary entry point, obtains a next-unused address through watcher or account-scan state, and rejects device verification unless the returned address exactly matches the displayed destination.

Important Files Changed

FilenameOverview
Bitkit/Managers/HwWalletManager.swiftStores watcher-provided next-unused addresses, adds account-scan fallback, and verifies the displayed derivation directly on the Trezor.
Bitkit/Views/Wallets/Receive/ReceiveQr.swiftAdds the Trezor receive tab, hardware BIP21 rendering, address loading, and reconnect/passphrase-aware verification.
Bitkit/Views/Wallets/Receive/ReceiveEdit.swiftAdds an on-chain-only editing mode that preserves amount and message state without invoking Lightning or Paykit flows.
Bitkit/Views/Wallets/Receive/ReceiveSheet.swiftCarries hardware-wallet identity through receive navigation and presents pairing requests during reconnect.
Bitkit/Components/TabBar/TabBar.swiftOpens the receive sheet on the Trezor tab when invoked from a hardware-wallet route.
Bitkit.xcodeproj/project.xcodeprojUpdates Bitkit Core to the version providing the watcher receive-address payload.

Sequence Diagram

sequenceDiagram
participant User
participant Receive as Receive Sheet
participant Manager as Hardware Wallet Manager
participant Watcher as Watch-only Watcher
participant Electrum
participant Trezor
User->>Receive: Open Trezor receive tab
Receive->>Manager: Request receive address
Manager->>Watcher: Read cached next-unused address
alt Watcher address available
Watcher-->>Manager: Address and derivation path
else Watcher address unavailable
Manager->>Electrum: Scan account addresses
Electrum-->>Manager: First unused external address
end
Manager-->>Receive: Address and derivation path
Receive-->>User: Display QR and details
opt Verify on device
User->>Receive: Verify address
Receive->>Manager: Verify displayed address
Manager->>Trezor: Derive and display exact path
Trezor-->>Manager: Device-derived address
Manager-->>Receive: Accept only exact match
end
Loading

Reviews (1): Last reviewed commit: "feat: add trezor receive" | Re-trigger Greptile

ovitrif

This comment was marked as resolved.

@piotr-iohk

piotr-iohk commented Sep 1, 2026

Copy link
Copy Markdown
Collaborator

Tested on simulator and device (iPhone 13 + Trezor Safe 7).

Generally all good. Able to present the receive address, verify the address on the device, etc.

One observation (looks intentional in code, but may be misleading to the user): with 2+ paired hardware wallets (e.g. standard + passphrase), Home → Receive does not show the Trezor tab, so there is no hardware receive address from that entry point. Fine to defer to a follow-up PR — if that's the case, let's create a ticket for this.

Steps to reproduce

  1. Pair a Trezor (standard wallet). Home should show one hardware wallet tile.
  2. Add a passphrase wallet on the same device (Paired → Passphrase → enter passphrase). Home should now show two hardware wallet tiles.
  3. From the main/home screen, tap Receive.
  4. Only Savings / Spending tabs are shown. No Trezor tab, so you cannot get a hardware receive address.

Expected (or less misleading)

Home → Receive either shows a Trezor tab (or a wallet picker) when more than one hardware wallet is paired, or makes it clear that hardware receive is only available from the specific wallet screen.

Workaround

Open the specific hardware wallet screen first, then Receive. That path still shows the address.

Recording

ScreenRecording_09-01-2026.10-03-56_1.MP4

piotr-iohk
piotr-iohk previously approved these changes Sep 1, 2026

@piotr-iohkpiotr-iohk left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve. Single-wallet receive looks good on simulator and device. See the QA comment for the multi-wallet Home Receive note (fine to defer).

Base automatically changed from feat/trezor-send to masterSeptember 1, 2026 08:43
@ovitrif
ovitrif dismissed piotr-iohk’s stale reviewSeptember 1, 2026 08:43

The base branch was changed.

@ben-kaufman

Copy link
Copy Markdown
ContributorAuthor

The single-wallet hardware Receive flow remains green and its review threads are resolved. I filed #709 for the requested Home Receive wallet picker when multiple hardware wallets are paired. @piotr-iohk please re-review the current signed head because the earlier approval was dismissed after the branch update.

piotr-iohk
piotr-iohk previously approved these changes Sep 1, 2026
Comment threadBitkit/Managers/HwWalletManager.swift
Comment threadBitkit/Views/Wallets/Receive/ReceiveQr.swift Outdated

@ovitrifovitrif left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

utACK

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Receive to hardware wallet

4 participants

@ben-kaufman@piotr-iohk@ovitrif@coreyphillips
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: add trezor receive - #693

Open
ben-kaufman wants to merge 5 commits into
masterfrom
feat/trezor-receive
Open

feat: add trezor receive#693
ben-kaufman wants to merge 5 commits into
masterfrom
feat/trezor-receive

Conversation

@ben-kaufman

@ben-kaufmanben-kaufman commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Summary

  • open the existing Receive sheet on a Trezor tab from the paired hardware-wallet screen
  • render the watcher-provided next-unused address immediately, with an account-scan fallback
  • support safe amount/message editing on the hardware address and exact on-device verification
  • match the receive design with a white selected underline, blue hardware QR/action accents, and verification inside Show Details

Stack

Linked Issues/Tasks

Fixes#707

Validation

  • iPhone 16 simulator build passes against Core 0.5.10
  • focused watcher receive-address test passes
  • SwiftFormat passes

@greptile-apps

Copy link
Copy Markdown

Greptile Summary

Adds Trezor receiving to the existing receive sheet, using watcher-provided addresses with an account-scan fallback and optional on-device verification.

  • Opens receive directly on the Trezor tab from a hardware-wallet screen.
  • Supports amount and message parameters for hardware-wallet BIP21 requests.
  • Adds reconnect, pairing-code, and passphrase handling for device verification.
  • Updates Bitkit Core to 0.5.10 and extends watcher-event handling for next-unused addresses.

Confidence Score: 5/5

The PR appears safe to merge, with no concrete blocking or independently actionable non-blocking defects identified.

The receive flow preserves explicit hardware-wallet identity from its primary entry point, obtains a next-unused address through watcher or account-scan state, and rejects device verification unless the returned address exactly matches the displayed destination.

Important Files Changed

FilenameOverview
Bitkit/Managers/HwWalletManager.swiftStores watcher-provided next-unused addresses, adds account-scan fallback, and verifies the displayed derivation directly on the Trezor.
Bitkit/Views/Wallets/Receive/ReceiveQr.swiftAdds the Trezor receive tab, hardware BIP21 rendering, address loading, and reconnect/passphrase-aware verification.
Bitkit/Views/Wallets/Receive/ReceiveEdit.swiftAdds an on-chain-only editing mode that preserves amount and message state without invoking Lightning or Paykit flows.
Bitkit/Views/Wallets/Receive/ReceiveSheet.swiftCarries hardware-wallet identity through receive navigation and presents pairing requests during reconnect.
Bitkit/Components/TabBar/TabBar.swiftOpens the receive sheet on the Trezor tab when invoked from a hardware-wallet route.
Bitkit.xcodeproj/project.xcodeprojUpdates Bitkit Core to the version providing the watcher receive-address payload.

Sequence Diagram

sequenceDiagram
participant User
participant Receive as Receive Sheet
participant Manager as Hardware Wallet Manager
participant Watcher as Watch-only Watcher
participant Electrum
participant Trezor
User->>Receive: Open Trezor receive tab
Receive->>Manager: Request receive address
Manager->>Watcher: Read cached next-unused address
alt Watcher address available
Watcher-->>Manager: Address and derivation path
else Watcher address unavailable
Manager->>Electrum: Scan account addresses
Electrum-->>Manager: First unused external address
end
Manager-->>Receive: Address and derivation path
Receive-->>User: Display QR and details
opt Verify on device
User->>Receive: Verify address
Receive->>Manager: Verify displayed address
Manager->>Trezor: Derive and display exact path
Trezor-->>Manager: Device-derived address
Manager-->>Receive: Accept only exact match
end
Loading

Reviews (1): Last reviewed commit: "feat: add trezor receive" | Re-trigger Greptile

ovitrif

This comment was marked as resolved.

@piotr-iohk

piotr-iohk commented Sep 1, 2026

Copy link
Copy Markdown
Collaborator

Tested on simulator and device (iPhone 13 + Trezor Safe 7).

Generally all good. Able to present the receive address, verify the address on the device, etc.

One observation (looks intentional in code, but may be misleading to the user): with 2+ paired hardware wallets (e.g. standard + passphrase), Home → Receive does not show the Trezor tab, so there is no hardware receive address from that entry point. Fine to defer to a follow-up PR — if that's the case, let's create a ticket for this.

Steps to reproduce

  1. Pair a Trezor (standard wallet). Home should show one hardware wallet tile.
  2. Add a passphrase wallet on the same device (Paired → Passphrase → enter passphrase). Home should now show two hardware wallet tiles.
  3. From the main/home screen, tap Receive.
  4. Only Savings / Spending tabs are shown. No Trezor tab, so you cannot get a hardware receive address.

Expected (or less misleading)

Home → Receive either shows a Trezor tab (or a wallet picker) when more than one hardware wallet is paired, or makes it clear that hardware receive is only available from the specific wallet screen.

Workaround

Open the specific hardware wallet screen first, then Receive. That path still shows the address.

Recording

ScreenRecording_09-01-2026.10-03-56_1.MP4

piotr-iohk
piotr-iohk previously approved these changes Sep 1, 2026

@piotr-iohkpiotr-iohk left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve. Single-wallet receive looks good on simulator and device. See the QA comment for the multi-wallet Home Receive note (fine to defer).

Base automatically changed from feat/trezor-send to masterSeptember 1, 2026 08:43
@ovitrif
ovitrif dismissed piotr-iohk’s stale reviewSeptember 1, 2026 08:43

The base branch was changed.

@ben-kaufman

Copy link
Copy Markdown
ContributorAuthor

The single-wallet hardware Receive flow remains green and its review threads are resolved. I filed #709 for the requested Home Receive wallet picker when multiple hardware wallets are paired. @piotr-iohk please re-review the current signed head because the earlier approval was dismissed after the branch update.

piotr-iohk
piotr-iohk previously approved these changes Sep 1, 2026
Comment threadBitkit/Managers/HwWalletManager.swift
Comment threadBitkit/Views/Wallets/Receive/ReceiveQr.swift Outdated

@ovitrifovitrif left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

utACK

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Receive to hardware wallet

4 participants

@ben-kaufman@piotr-iohk@ovitrif@coreyphillips
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat: add trezor receive - #693

Open
ben-kaufman wants to merge 5 commits into
masterfrom
feat/trezor-receive
Open

feat: add trezor receive#693
ben-kaufman wants to merge 5 commits into
masterfrom
feat/trezor-receive

Conversation

@ben-kaufman

@ben-kaufmanben-kaufman commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Summary

  • open the existing Receive sheet on a Trezor tab from the paired hardware-wallet screen
  • render the watcher-provided next-unused address immediately, with an account-scan fallback
  • support safe amount/message editing on the hardware address and exact on-device verification
  • match the receive design with a white selected underline, blue hardware QR/action accents, and verification inside Show Details

Stack

Linked Issues/Tasks

Fixes#707

Validation

  • iPhone 16 simulator build passes against Core 0.5.10
  • focused watcher receive-address test passes
  • SwiftFormat passes

@greptile-apps

Copy link
Copy Markdown

Greptile Summary

Adds Trezor receiving to the existing receive sheet, using watcher-provided addresses with an account-scan fallback and optional on-device verification.

  • Opens receive directly on the Trezor tab from a hardware-wallet screen.
  • Supports amount and message parameters for hardware-wallet BIP21 requests.
  • Adds reconnect, pairing-code, and passphrase handling for device verification.
  • Updates Bitkit Core to 0.5.10 and extends watcher-event handling for next-unused addresses.

Confidence Score: 5/5

The PR appears safe to merge, with no concrete blocking or independently actionable non-blocking defects identified.

The receive flow preserves explicit hardware-wallet identity from its primary entry point, obtains a next-unused address through watcher or account-scan state, and rejects device verification unless the returned address exactly matches the displayed destination.

Important Files Changed

FilenameOverview
Bitkit/Managers/HwWalletManager.swiftStores watcher-provided next-unused addresses, adds account-scan fallback, and verifies the displayed derivation directly on the Trezor.
Bitkit/Views/Wallets/Receive/ReceiveQr.swiftAdds the Trezor receive tab, hardware BIP21 rendering, address loading, and reconnect/passphrase-aware verification.
Bitkit/Views/Wallets/Receive/ReceiveEdit.swiftAdds an on-chain-only editing mode that preserves amount and message state without invoking Lightning or Paykit flows.
Bitkit/Views/Wallets/Receive/ReceiveSheet.swiftCarries hardware-wallet identity through receive navigation and presents pairing requests during reconnect.
Bitkit/Components/TabBar/TabBar.swiftOpens the receive sheet on the Trezor tab when invoked from a hardware-wallet route.
Bitkit.xcodeproj/project.xcodeprojUpdates Bitkit Core to the version providing the watcher receive-address payload.

Sequence Diagram

sequenceDiagram
participant User
participant Receive as Receive Sheet
participant Manager as Hardware Wallet Manager
participant Watcher as Watch-only Watcher
participant Electrum
participant Trezor
User->>Receive: Open Trezor receive tab
Receive->>Manager: Request receive address
Manager->>Watcher: Read cached next-unused address
alt Watcher address available
Watcher-->>Manager: Address and derivation path
else Watcher address unavailable
Manager->>Electrum: Scan account addresses
Electrum-->>Manager: First unused external address
end
Manager-->>Receive: Address and derivation path
Receive-->>User: Display QR and details
opt Verify on device
User->>Receive: Verify address
Receive->>Manager: Verify displayed address
Manager->>Trezor: Derive and display exact path
Trezor-->>Manager: Device-derived address
Manager-->>Receive: Accept only exact match
end
Loading

Reviews (1): Last reviewed commit: "feat: add trezor receive" | Re-trigger Greptile

ovitrif

This comment was marked as resolved.

@piotr-iohk

piotr-iohk commented Sep 1, 2026

Copy link
Copy Markdown
Collaborator

Tested on simulator and device (iPhone 13 + Trezor Safe 7).

Generally all good. Able to present the receive address, verify the address on the device, etc.

One observation (looks intentional in code, but may be misleading to the user): with 2+ paired hardware wallets (e.g. standard + passphrase), Home → Receive does not show the Trezor tab, so there is no hardware receive address from that entry point. Fine to defer to a follow-up PR — if that's the case, let's create a ticket for this.

Steps to reproduce

  1. Pair a Trezor (standard wallet). Home should show one hardware wallet tile.
  2. Add a passphrase wallet on the same device (Paired → Passphrase → enter passphrase). Home should now show two hardware wallet tiles.
  3. From the main/home screen, tap Receive.
  4. Only Savings / Spending tabs are shown. No Trezor tab, so you cannot get a hardware receive address.

Expected (or less misleading)

Home → Receive either shows a Trezor tab (or a wallet picker) when more than one hardware wallet is paired, or makes it clear that hardware receive is only available from the specific wallet screen.

Workaround

Open the specific hardware wallet screen first, then Receive. That path still shows the address.

Recording

ScreenRecording_09-01-2026.10-03-56_1.MP4

piotr-iohk
piotr-iohk previously approved these changes Sep 1, 2026

@piotr-iohkpiotr-iohk left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve. Single-wallet receive looks good on simulator and device. See the QA comment for the multi-wallet Home Receive note (fine to defer).

Base automatically changed from feat/trezor-send to masterSeptember 1, 2026 08:43
@ovitrif
ovitrif dismissed piotr-iohk’s stale reviewSeptember 1, 2026 08:43

The base branch was changed.

@ben-kaufman

Copy link
Copy Markdown
ContributorAuthor

The single-wallet hardware Receive flow remains green and its review threads are resolved. I filed #709 for the requested Home Receive wallet picker when multiple hardware wallets are paired. @piotr-iohk please re-review the current signed head because the earlier approval was dismissed after the branch update.

piotr-iohk
piotr-iohk previously approved these changes Sep 1, 2026
Comment threadBitkit/Managers/HwWalletManager.swift
Comment threadBitkit/Views/Wallets/Receive/ReceiveQr.swift Outdated

@ovitrifovitrif left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

utACK

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Receive to hardware wallet

4 participants

@ben-kaufman@piotr-iohk@ovitrif@coreyphillips