Jaxx Liberty

Build from source, compare the hash

Reproducible builds let you verify that the wallet you downloaded was built from the published source code — with nothing added, nothing removed, and nothing changed. Trust the math, not the build server.

What are reproducible builds?

A reproducible build (also called a deterministic build) is a compilation process that always produces the same binary output when given the same source code and build environment. If two people independently compile the same source code using the same toolchain, they will get identical binaries — byte for byte.

This matters because it creates a verifiable link between the source code you can read and the binary you actually run. Without reproducible builds, you must trust that the person who compiled the official release did not insert any malicious code during the build process. With reproducible builds, you can check for yourself.

Why it matters

Supply chain attacks are among the most dangerous threats in software security. An attacker who compromises a build server, a CI pipeline, or a developer's machine can inject malicious code into the binary without modifying the public source code. The source looks clean, the binary is compromised, and users have no way to detect the discrepancy.

High-profile supply chain attacks have affected major software projects across the industry. In the cryptocurrency space, the stakes are even higher because a compromised wallet binary can directly steal funds. Reproducible builds are the defense against this class of attack.

Jaxx Liberty's commitment to reproducible builds means that the open-source code is not just readable — it is verifiable. The hash published alongside each release can be independently confirmed by anyone who builds from source.

How to verify

  1. Clone the repository. Download the Jaxx Liberty source code from the official repository. Use the specific release tag that matches the version you want to verify.
  2. Set up the build environment. Follow the build instructions in the repository. The build environment is fully specified, including compiler version, dependency versions, and build flags.
  3. Run the build. Execute the build command. The process will produce a binary artifact for your target platform.
  4. Compute the hash. Calculate the SHA-256 hash of the binary you just built.
  5. Compare. Compare your hash with the official release hash published on the release page. If they match, the binary was built from the published source with no modifications.

Build instructions

Detailed build instructions for each platform are available in the Documentation. The build process requires standard development tools and is designed to be straightforward for anyone with basic command-line experience.

Desktop

Build for macOS, Windows, and Linux using the documented toolchain. Each platform has a pinned build environment to ensure deterministic output.

Mobile

Android and iOS builds follow the same reproducibility principles. APK and IPA artifacts can be compared against their published hashes.

Browser extension

The Chrome extension build produces a deterministic output that can be compared against the version published in the Chrome Web Store.

Hash comparison

Each Jaxx Liberty release includes a signed manifest file that lists the SHA-256 hash of every build artifact. The manifest itself is signed with the project's release key, so you can verify both the integrity of the individual binaries and the authenticity of the manifest.

This two-layer verification — deterministic builds plus signed manifests — provides defense in depth. Even if an attacker were to compromise the release infrastructure, independent builders would immediately detect the discrepancy between their own builds and the published artifacts.

Part of a broader security model

Reproducible builds are one component of Jaxx Liberty's layered security model. Together with open-source code, independent audits, hardware signing, and passkeys on every transaction, they form a security architecture where every claim is independently verifiable.

Verify your wallet

Build from source, compare the hash. Trust the math, not the build server.

Open Wallet