Downloadscurrent v1.2.28windows + linuxsha256 with every release
Downloads
Every release ships the binaries and a SHA256SUMS file covering them. Verifying takes a second and is worth doing — it is the only thing standing between you and a file somebody else swapped out.
What's new in 1.2.28
The switch happened. Mainnet block 38841, 2026-09-21 12:00:58 UTC, was the first mined under PoW v2 and the consensus rules v2. This release changes nothing in consensus: a 1.2.26 or 1.2.27 node follows the same chain; a node on 1.2.23 or earlier is off it and must upgrade.
Network. Protocol 102, negotiated per peer: a checksum on every message, misbehaving peers scored and banned for 24 hours, a node behind its peers neither mines nor announces until level, block data synced to disk before the index points at it, and a deadlock present since 0.1.0 that could hang sendtoaddress fixed.
Tor where Tor is blocked. Managed Tor that reaches no peer climbs a ladder on its own — Snowflake, obfs4, webtunnel, meek, from Tor Browser's bundled list — keeps the onion, remembers what worked, and shows Tor's own bootstrap while it does. Bridges of your own go in bridges.txt or the paste box in Options. The releases are also served over Tor at rqzruhh4sm2s3fl6b4mpselkqsaaxebnyptpqhdpt236g57lof7j7sid.onion. See Bitflash on censored networks.
Wallet. Multisig and raw-transaction RPC (createmultisig, listunspent, createrawtransaction, signrawtransaction, sendrawtransaction…) ahead of rules v3; pay-to-script-hash addresses are understood but refused as a destination until that switch is scheduled. One OP_RETURN output per transaction is relayed.
01Bitflash v1.2.28
| File | Platform | Size |
|---|---|---|
| Bitflash-1.2.28-windows-with-tor.zip | Windows, x86_64 — portable zip with Tor bundled, extract and run Bitflash.exe | 29.7 MB |
| Bitflash-1.2.28-x86_64.AppImage | Linux, x86_64 — AppImage, chmod +x and run | 22.1 MB |
| bitflash-node-1.2.28-x86_64 | Linux, x86_64 — headless node binary, for servers | 3.5 MB |
| Bitflash-Miner-1.2.28-linux.tar.gz | Bitflash Miner, Linux x86_64 — XMRig plus Tor, run ./mine.sh with your address | 7.4 MB |
| Bitflash-Miner-1.2.28-windows.zip | Bitflash Miner, Windows — XMRig plus Tor, run mine.cmd with your address | 6.3 MB |
SHA256SUMSSHA256SUMS.ascSigning key
02Checksums
| Bitflash-1.2.28-windows-with-tor.zip | c86d65c0ae235c58d00ac8d77137af61b0b13b30e27469be92f348835c11ffd4 |
| Bitflash-1.2.28-x86_64.AppImage | d18c8fdeab5dfe0c9102e5ceb9bcfabf4fe644a8fcbeadf3a9ad27e36ec620c9 |
| bitflash-node-1.2.28-x86_64 | 6576b8f1998c1ba5fb1795474838fd572c5d603cecab28f28fd699e33504ec2b |
| Bitflash-Miner-1.2.28-linux.tar.gz | 11aae644dddb3375c48402ca30bf205ab5950b8e72bf66cbde21b61a63c7ada6 |
| Bitflash-Miner-1.2.28-windows.zip | 4c355b8f002d014e212d70c23ec3ea311c3fab4172fc7904bc77bc8e7642ad82 |
Every hash above was recomputed from the artifact when this page was built.
Verify what you downloaded
Put the release files and SHA256SUMS in one directory:
sha256sum -c SHA256SUMS
On Windows, without a shell:
certutil -hashfile Bitflash-1.2.28-windows-with-tor.zip SHA256
Checksums prove the files match each other; a signature proves they came from Bitflash. Import the release key once, then verify the checksum file against it before trusting it:
curl -O https://releases.bitflash.network/bitflash-release-key.asc
gpg --import bitflash-release-key.asc
gpg --verify SHA256SUMS.asc SHA256SUMS
sha256sum -c SHA256SUMS
The signing key fingerprint is 910A 2B4C CA87 9E81 FB4B 2AEA 1D4A 53D3 B78A A4B8. Check the gpg --verify output names exactly that key — a good signature by some other key means nothing.
The repository helper does this end to end, and refuses anything not signed by the pinned key:
scripts/verify-release.sh latest
The full audit procedure is in release verification.
Keep your node current
Consensus rules have changed since the first releases. 1.2.1 fixed a bug that let anyone spend anyone's coins, and 1.2.2 added a per-block signature-operation cap. A node on an older build will accept blocks that current nodes reject, which puts it on a different chain with no warning at all.
Your wallet and chain data live in %APPDATA%\Bitflash on Windows or ~/.bitflash on Linux and are shared by every version, so upgrading is just replacing the binary. Never delete that directory to "fix" something without a backup — it holds your keys.