BitBanana: Bitcoin & Lightning
Latest release found by WalletScrutiny: 1.1.0
- Released
- 26th March 2023
- Source code
- Public on github
Our wallet review process
We examine wallets starting at the code level and continue all the way up to the finished app that lives on your device. Provided below is an outline of each of these steps along with security tips for you and general test results.
Custody
Self-custodial: The user holds the keys
As part of our Methodology, we ask: Does the product allow self-custody?
The answer is "yes". The user has control of their own keys.
Read more
Passed all 7 tests
We answered the following questions in this order:
The answer is "yes".
If the answer were "no", we would mark it as "Fake" and the following would apply:
The answer is "no". We marked it as "Fake".
We did not ask this question because we failed at a previous question.
If the answer were "no", we would mark it as "Fake" and the following would apply:
The bigger wallets often get imitated by scammers that abuse the reputation of the product by imitating its name, logo or both.
Imitating a competitor is a huge red flag and we urge you to not put any money into this product!
The answer is "yes".
If the answer were "no", we would mark it as "Not a wallet" and the following would apply:
The answer is "no". We marked it as "Not a wallet".
We did not ask this question because we failed at a previous question.
If the answer were "no", we would mark it as "Not a wallet" and the following would apply:
If it’s called “wallet” but is actually only a portfolio tracker, we don’t look any deeper, assuming it is not meant to control funds. What has no funds, can’t lose your coins. It might still leak your financial history!
If you can buy Bitcoins with this app but only into another wallet, it’s not a wallet itself.
The answer is "yes".
If the answer were "no", we would mark it as "A wallet but not for Bitcoin" and the following would apply:
The answer is "no". We marked it as "A wallet but not for Bitcoin".
We did not ask this question because we failed at a previous question.
If the answer were "no", we would mark it as "A wallet but not for Bitcoin" and the following would apply:
At this point we only look into wallets that at least also support BTC.
The answer is "yes".
If the answer were "no", we would mark it as "Can't send or receive bitcoins" and the following would apply:
The answer is "no". We marked it as "Can't send or receive bitcoins".
We did not ask this question because we failed at a previous question.
If the answer were "no", we would mark it as "Can't send or receive bitcoins" and the following would apply:
If it is for holding BTC but you can’t actually send or receive them with this product then it doesn’t function like a wallet for BTC but you might still be using it to hold your bitcoins with the intention to convert back to fiat when you “cash out”.
All products in this category are custodial and thus funds are at the mercy of the provider.
The product cannot be independently verified. If the provider puts your funds at risk on purpose or by accident, you will probably not know about the issue before people start losing money. If the provider is more criminally inclined he might have collected all the backups of all the wallets, ready to be emptied at the press of a button. The product might have a formidable track record but out of distress or change in management turns out to be evil from some point on, with nobody outside ever knowing before it is too late. The answer is "yes".
If the answer were "no", we would mark it as "Custodial: The provider holds the keys" and the following would apply:
The answer is "no". We marked it as "Custodial: The provider holds the keys".
We did not ask this question because we failed at a previous question.
If the answer were "no", we would mark it as "Custodial: The provider holds the keys" and the following would apply:
A custodial service is a service where the funds are held by a third party like the provider. The custodial service can at any point steal all the funds of all the users at their discretion. Our investigations stop there.
Some services might claim their setup is super secure, that they don’t actually have access to the funds, or that the access is shared between multiple parties. For our evaluation of it being a wallet, these details are irrelevant. They might be a trustworthy Bitcoin bank and they might be a better fit for certain users than being your own bank but our investigation still stops there as we are only interested in wallets.
Products that claim to be non-custodial but feature custodial accounts without very clearly marking those as custodial are also considered “custodial” as a whole to avoid misguiding users that follow our assessment.
We have to acknowledge that a huge majority of Bitcoiners are currently using custodial Bitcoin banks. If you do, please:
- Do your own research if the provider is trust-worthy!
- Check if you know at least enough about them so you can sue them when you have to!
- Check if the provider is under a jurisdiction that will allow them to release your funds when you need them?
- Check if the provider is taking security measures proportional to the amount of funds secured? If they have a million users and don’t use cold storage, that hot wallet is a million times more valuable for hackers to attack. A million times more effort will be taken by hackers to infiltrate their security systems.
The answer is "yes".
If the answer were "no", we would mark it as "No source for current release found" and the following would apply:
The answer is "no". We marked it as "No source for current release found".
We did not ask this question because we failed at a previous question.
If the answer were "no", we would mark it as "No source for current release found" and the following would apply:
A wallet that claims to not give the provider the means to steal the users’ funds might actually be lying. In the spirit of “Don’t trust - verify!” you don’t want to take the provider at his word, but trust that people hunting for fame and bug bounties could actually find flaws and back-doors in the wallet so the provider doesn’t dare to put these in.
Back-doors and flaws are frequently found in closed source products but some remain hidden for years. And even in open source security software there might be catastrophic flaws undiscovered for years.
An evil wallet provider would certainly prefer not to publish the code, as hiding it makes audits orders of magnitude harder.
For your security, you thus want the code to be available for review.
If the wallet provider doesn’t share up to date code, our analysis stops there as the wallet could steal your funds at any time, and there is no protection except the provider’s word.
“Up to date” strictly means that any instance of the product being updated without the source code being updated counts as closed source. This puts the burden on the provider to always first release the source code before releasing the product’s update. This paragraph is a clarification to our rules following a little poll.
We are not concerned about the license as long as it allows us to perform our analysis. For a security audit, it is not necessary that the provider allows others to use their code for a competing wallet. You should still prefer actual open source licenses as a competing wallet won’t use the code without giving it careful scrutiny.
The product cannot be independently verified. If the provider puts your funds at risk on purpose or by accident, you will probably not know about the issue before people start losing money. If the provider is more criminally inclined he might have collected all the backups of all the wallets, ready to be emptied at the press of a button. The product might have a formidable track record but out of distress or change in management turns out to be evil from some point on, with nobody outside ever knowing before it is too late.Distribution
Build Verifications
If you have a binary for a version that doesn't appear on the list, you can dropselect the file here to register it so somebody can verify its reproducibility:
Custom Node Connection
The wallet can be configured to connect to a user-specified, independently operated Bitcoin node — such as Bitcoin Core, Electrum Server, or other compatible full node software — instead of the wallet provider’s default servers. The key requirement is that the node is clearly independent from the wallet vendor: a third-party node the user controls or trusts.
-
Privacy: Transaction queries go to your own node rather than a third-party server, so no provider learns your wallet addresses or balances.
-
Security: No risk of a provider lying about your balance or the state of the network.
-
Sovereignty: Full independence from wallet provider infrastructure.
- Requires running and maintaining your own Bitcoin node.
- More complex initial setup compared to using the provider’s default servers.
Why we list it for this wallet
Connect to remote lightning nodes/wallets (LND, Core Lightning, Nostr Wallet Connect & LndHub)
Source: README
App Description from Google Play
BitBanana is a native android app for node operators focused on user experience and ease of use. While it is not a wallet on its own, BitBanana works like a remote control allowing you to use your node as a wallet wherever you go. The app is designed with an educational approach, providing the user with guidance on every aspect of node operation.
Lightning Network support
The lightning Network (LN) is a layer two protocol that promises instant, low fee micro payments. Some wallets do not support receiving transactions which disqualifies them for this feature.
Transactions on LN are
- instant: It usually takes less than five seconds to finish a transaction.
- cheap: Transactions usually cost a tiny percentage (0.1%) of the transferred amount and might also be free.
- micro payments: The unit of account on the LN is micro Satoshis (mSat) or 0.00000000001 BTC.
LN is still in early development and several very feasible attacks are known that can cost users money or disrupt the network.
Why we list it for this wallet
Connect to remote lightning nodes/wallets (LND, Core Lightning, Nostr Wallet Connect & LndHub)
Source: README
Full SegWit Support
SegWit which is short for “Segregated Witness” was an August 2017 upgrade to the Bitcoin protocol which came with new address types.
Full SegWit Support means that the wallet can both send to and receive to all SegWit address types, including bech32 starting with “bc1…”.
- Receiving to SegWit addresses provides fee savings, as sending these funds is possible using less base-block space. In Bitcoin, transaction fees are proportional to the transaction size in bytes.
- Receiving to bech32 addresses provides more fee savings than P2SH Segwit addresses.
- Sending to SegWit addresses is sometimes required in order to use more modern tools that dropped support for legacy addresses, often because of another core property of SegWit transactions: They are not malleable, meaning that the transaction ID cannot be changed “in transit” (on unconfirmed transactions).
Why we list it for this wallet
Support for SegWit & Taproot
Source: README
Full Taproot Support
Taproot is an improvement of how Bitcoin transactions work and was activated on 2021-11-12. It uses a new address format, defined in BIP 350.
While some wallets will be able to send to but not receive to Taproot, this feature only tracks those that support both.
- Compatibility: Recipients have to choose an address format and due to efficiency improvements, they will tend more and more to expect being paid to a Taproot address. Wallets supporting this are generally more compatible.
-
Cheaper: Taproot allows for smaller transactions, especially for more complex uses of Bitcoin such as multi signature.
-
More private: As public data of a complicated transaction is usually indistinguishable from that of a simple transactions, special uses “hide in a bigger crowd” and become more private.
- More efficient for offline wallets: Hardware wallets ususally have only a very limited knowledge of the funds being spent, with the user confirming amounts sent but only implicitly the fee being paid. When spending from Taproot, the fee becomes knowable to the offline wallet, making protection against fee overpayment easier.
Initially the privacy will be worse, as using Taproot will make transactions stand out from the crowd.
Why we list it for this wallet
Support for SegWit & Taproot
Source: README
Connect To Own Lightning Node
The LN is very demanding on the wallet, especially for mobile devices, making custodial LN wallets somewhat acceptable. To have a light-weight client without having to trust a centralized provider, one can run ones own Lightning Node and remote-control it with this app.
Always online lightning node with the convenience of a mobile app.
Why we list it for this wallet
Use your node as a lightning wallet wherever you are
Source: README
TOR - The Onion Router
TOR is a tool to shield the IP address of communicating parties. When communicating with a node on the TOR network, the communication is also necessarily end to end encrypted but not when communicating to a server on the internet that does neither use TOR nor ssl (https). Modern Androids allow to put apps behind a local TOR node independently of the provider offering TOR features. While this can be desirable to shield one’s IP address, it also might expose unencrypted data to different, probably more aware third parties. It also does not replace more advanced TOR features in which the wallet creates multiple TOR identities for different requests.
- Privacy: TOR shields the client’s IP address and thus his real world location or identity from servers it talks to.
- Speed: TOR means bouncing messages around a bit more with extra encryption. That makes it slower.
Why we list it for this wallet
Tor support
Source: README
Free and Open Source (FOSS)
The wallet’s source code is published under a license approved by the Open Source Initiative (OSI) — such as MIT, GPL, Apache, or AGPL — allowing anyone to inspect, modify, and redistribute it. This is a prerequisite for independent security audits and reproducible builds. Licenses that are merely “source available” but not OSI-approved (e.g., those with Commons Clause restrictions, commercial use prohibitions, or other non-free terms) do NOT qualify. Reproducible builds are not sufficient alone.
-
Transparency: Anyone can verify what the code does — including whether it contains backdoors, bugs, or privacy-violating behavior.
-
Community auditing: More reviewers means vulnerabilities are more likely to be found and fixed.
-
Forkability: If the project is abandoned or goes rogue, the community can fork and continue it.
FOSS alone does not guarantee security. The released binary must also be reproducible from the public source to ensure users are actually running the code that was audited.
Why we list it for this wallet
MIT License Copyright (c) 2019-present Jack Mallers Copyright (c) 2019-present Michael Wuensch Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction
Source: License
Advanced UTXO Control
The wallet offers advanced control over which Unspent Transaction Outputs (UTXOs) are spent. This goes beyond simple coin selection — it may include the ability to freeze or exclude specific UTXOs (e.g., dusting attacks or tainted coins), label UTXOs, or select inputs manually. The user does not necessarily need full visibility of all UTXOs, but has meaningful control over what gets spent.
-
Privacy: Prevent spending from UTXOs linked to unwanted transaction history, or avoid merging coins from different sources in one transaction.
-
Dust protection: Mark suspicious incoming transactions as “do not spend” to avoid revealing your wallet’s full UTXO set.
-
Fee optimization: Strategically select inputs to manage transaction size and fees.
Why we list it for this wallet
Coin Control
Source: README
NFC (Near Field Communication)
The wallet supports Near Field Communication (NFC) for wireless interaction with hardware wallets, payment terminals, or signing cards. NFC enables tap-to-sign or tap-to-pay functionality over a very short range (typically a few centimeters) without cables or QR codes.
- Convenience: Quick tap interaction — no cables to connect or QR codes to scan.
- Hardware wallet compatibility: Some hardware signing cards communicate exclusively via NFC.
- Requires NFC hardware on both devices.
- Very short range limits usability compared to QR-based air-gapped setups.
Why we list it for this wallet
NFC support
Source: README
An issue has been opened at https://github.com/michaelWuensch/BitBanana/issues/95
Product page updated by Daniel Andrei R. Garcia, keraliss
Do your own research
In addition to reading our analysis, it is important to do your own checks. Before transferring any bitcoin to your wallet, look up reviews for the wallet you want to use. They should be easy to find. If they aren't, that itself is a reason to be extra careful.