SUBFROST for Android Is Live
Your keys are held in your phone's own secure element. The SUBFROST app carries our whole stack, while integrating seamlessly with our webapp for desktop users.
Your phone becomes a high-powered Bitcoin DeFi wallet
SUBFROST for Android inverts everything that you know about Bitcoin wallet setups. Typically, phone apps are read-only. You can check a balance on it, show someone a QR code, but anything that actually moves money waits until you are back at a desktop.
With the SUBFROST app, the seed is generated on your phone and protected by its own secure element, allowing you to perform the same actions as you can on desktop. Send and receive, AMM swaps, live balances across BTC and Alkanes tokens, history with the on-chain trail, and the opcode console for technical users. Your** phone becomes the wallet, and if you prefer desktop, it becomes your signing device.**
This post covers what you get, the two ways to install it and how to import a webapp keystore wallet if that is what you currently use.
Screens below are from the shipping build on a real phone. Nothing here is mocked up.
How to download it
Three routes, same app.
From Google Play. SUBFROST on Google Play. Install, open, and either create a wallet or import one. There is no account to create and no email to hand over.
**Through F-Droid. **Add https://f-droid.subfrost.io/repo as a repository in the F-Droid client and install SUBFROST from there, which is the route that keeps updating itself.
From the APK. If you would rather have the file, subfrost.io/download/android hands you the same build the F-Droid client would install. This is the route if you run a de-Googled phone, or if you would rather take the APK from us than from a store. The two builds carry the same code, and because the store signs its own copy, the certificates differ, so install one or the other rather than trying to upgrade across. The app does not need Google Play Services.
Everything you hold, in one list
Unlock your wallet and native BTC sits in the same list as FIRE, DIESEL, frBTC, frUSD, and every other Alkanes token you hold. frBTC is SUBFROST's synthetic Bitcoin, pegged 1:1 to BTC and redeemable back to native BTC.
Send BTC or tokens to one recipient or multiple on a single fee rate, so it is one transaction rather than five.
Swap utilizes the same AMM experience users love today in the SUBFROST webapp, taking both sides of a pair with your own slippage.
**Receive **covers every Bitcoin address type.
**History **renders each confirmed transaction as an expandable protostone trace, so you can see how the Alkanes VM executed your swap or wrap, with revert messages inline, and open the whole transaction on the SUBFROST explorer when you want a second view.
And for technical users, the opcode console is here too. Every token detail page carries an Execute tab beside Trades and Holders: call an opcode, inspect the ABI tree, and execute against a contract from the phone. Talking to a contract no longer requires a desktop.
Your phone signs for the browser you are already using
Open a desktop site that wants a Bitcoin wallet, pick SUBFROST from its wallet picker, and start signing transactions from your phone. The site shows a QR code and six-character code: scan the QR with your phone and the app opens on an approval screen. Type the code, approve, and after that your phone will be paired with the site.
WalletConnect lists every site you have paired, what each session is permitted to do, and lets you drop any of them. Turn on notifications and the phone will ping you when a paired site asks for a signature. A pairing lives as long as the wallet is open or in the background, so a session does not survive the app being swiped away.
The WalletConnect bridge is ours (wss-tls.subfrost.io) and it is deliberately incurious. Pairings store the site's origin and a session key on your device only. The bridge routes ciphertext between the phone and the site and never holds the plaintext, seeing an encrypted frame and a per-pair topic id, nothing else.
The same pairing is how the phone signs for the SUBFROST webapp. Pair your phone app withapp.subfrost.io and your phone becomes a remote signer, close to what a hardware wallet does for a desktop.
The keys sit in the phone's secure element, enabled with biometric
The seed phrase is wrapped by the on-device secure element, StrongBox or TEE depending on your hardware, and phones with neither fall back to the Android keystore in software. Where a biometric is enrolled, it gates unlocking the wallet and then approvals sign without a second prompt. Cancel the biometric prompt and you get a lock screen offering retry, your recovery password, a PIN if you set one, or erase with a confirmation, and the wallet stays loaded rather than signing you out.
Screenshots, screen recording, and the recents thumbnail are blocked by default, which surprises people the first time they try to capture a balance. That is FLAG_SECURE, and it is a toggle under Settings > Security if you want it off. On a phone with a biometric or a PIN set, the wallet auto-locks 30 seconds after you background it, and the clipboard wipes itself 30 seconds after you copy an address, a mnemonic, or a transaction id.
There is no analytics and no telemetry, and crash reports are sent only if you switch them on under Settings > Privacy, where they are off by default. Network calls run through a SUBFROST-operated tunnel over a nested TLS pipe, where the inner layer is pinned to our own key, so a network that intercepts TLS still cannot read or reshape what the wallet says.
Bringing your webapp keystore across
If you already hold a wallet in the SUBFROST webapp, you do not need to start over, and the route we recommend never puts your seed phrase on screen.
- In the webapp, open your wallet
- Then select Security and backup
- Then Export keystore - your browser saves an encrypted JSON file protected by your existing keystore password
- Get that file onto your phone however you normally move a file
- In the SUBFROST app, import a wallet, hand it the
.jsonfile through the picker, and supply that password.
Going the other way, Settings > Wallet > Export keystore confirms it is you with your biometric or your recovery password, then asks for a fresh passphrase and hands you the JSON through the share sheet, encrypted with that new passphrase rather than the one already protecting the wallet. The webapp reads it.
If the file is refused, the recovery phrase is the fallback. A keystore written by a newer SDK than the phone knows, will come back as "Unsupported keystore version", and no password fixes that. Import the phrase instead, through the same Keyring entry, Import HD seed or keystore. It is the slower route, and it always works.
What is coming in the near future
Three things.
The Yield tab hands you to the webapp. This is the primary gap between the SUBFROST webapp and Android app. FIRE Vault and PERMAFROST Vault are rows that open app.subfrost.io in your browser rather than transacting on the phone. So the sentence above about not needing a desktop holds for sending, swapping and contract calls, and does not yet hold for yield.
SUBFROST Pay is in private rollout. The email login, virtual card, and burning frBTC to cash are wired on the backend and waiting on a few last approvals on our end. The section will light up on its own.
Hardware wallets pair but do not send. You can connect a OneKey or Trezor over Bluetooth, and in-app sending with one is not available yet. Until it is, sign through a paired site instead.
Fifteen languages, one wallet
The interface ships in English plus Simplified Chinese, Vietnamese, Korean, Japanese, Ukrainian, Russian, Indonesian, Spanish, French, Italian, Polish, Romanian, and both Portuguese variants. Set it under Settings > Language, and it follows your system locale until you say otherwise.
Put it in your pocket
Alkanes put application logic on Bitcoin L1, settling every block, with no sequencer and nothing batching your transactions for you. Reaching that amazing UX used to mean a desktop. Now it is the device already in your hand, holding its own keys, signing for everything else you use.
Install it, pair it, and execute.
You are responsible for your own keys. Anyone holding your seed phrase holds your funds, and nobody from SUBFROST will ever ask you for it.