Our Blockstream app binary releases are available on GitHub:
Each release includes a SHA256SUMS.asc file: a PGP clearsigned list of the SHA-256 hashes of every release file. Verifying it takes two checks. The signature check proves the hash list came from Blockstream. The hash check proves the file you downloaded matches that list. Both are required.
Our PGP fingerprint is:
04BE BF2E 35A2 AF2F FDF1 FA5D E7F0 54AA 2E76 E792
1. Import the Blockstream Public Key
gpg --keyserver keyserver.ubuntu.com --recv-keys 04BEBF2E35A2AF2FFDF1FA5DE7F054AA2E76E792
2. Verify the Signature on the Hash List
Run this in the folder where you saved SHA256SUMS.asc:
gpg --verify SHA256SUMS.asc
The output must contain a line starting with gpg: Good signature and the line Primary key fingerprint: 04BE BF2E 35A2 AF2F FDF1 FA5D E7F0 54AA 2E76 E792. If either line is missing, or gpg reports BAD signature, do not install the file.
The output also includes WARNING: This key is not certified with a trusted signature! This warning is expected. It appears because the Blockstream key has not been signed by a key in your own keyring, and it does not affect the result.
3. Check the Downloaded File Against the Signed List
Linux:
sha256sum --ignore-missing --check SHA256SUMS.asc
macOS:
shasum -a 256 --ignore-missing --check SHA256SUMS.asc
The output must show OK after the name of the file you downloaded. Lines about improperly formatted input can be ignored; they are the PGP wrapper. A FAILED result means the file was modified or corrupted. Delete it and download again.