SUBFROST is a non-custodial mobile wallet for staking, trading, and
managing Bitcoin and Bitcoin-native financial primitives. Your seed
phrase lives in your phone's hardware-backed keystore (StrongBox /
Secure Enclave / TEE) — Subzero Research never sees your keys, and
neither does anyone else.
An extended financial framework on Bitcoin
SUBFROST is more than a wallet. It is the mobile front-end for an
entire on-chain financial framework anchored to Bitcoin via the
alkanes metaprotocol layer + the SUBFROST peer-to-peer overlay
network — what we call the full materialization of L0.
This means you can:
• Stake Bitcoin — wrap BTC into frBTC, supply liquidity to
the SUBFROST AMM, earn yield from real on-chain trading volume.
• Trade alkanes — swap any pair of Bitcoin-native assets
through the SUBFROST factory in a single signed transaction.
• Hold stablecoins on Bitcoin — the framework supports
stable-value tokens (frUSD and partner stables) without bridges.
• Pair as a hardware signer — scan a QR from app.subfrost.io
and your phone becomes a remote signer for the web wallet, similar
to a hardware wallet but with biometric-gated approvals.
Self-custody, hardware-rooted
• Seed phrase wrapped by the on-device secure element. Biometric
unlock (Face ID / fingerprint) gates every signing operation.
• Lock screen on biometric cancel — Retry / Use PIN / Erase Wallet
with confirm. Wallet stays loaded on cancel; no surprise sign-outs.
• FLAG_SECURE on by default — screenshots, screen recording, and
recents-thumbnail capture are blocked. Opt out under Settings →
Security.
• Auto-lock 30s after backgrounded. Clipboard auto-wipes 30s after
copying an address, mnemonic, or transaction id.
Privacy + censorship-resistance
• Network calls flow through a Subfrost-operated tunnel
(wss-tls.subfrost.io) over an end-to-end-encrypted nested-TLS
pipe. The outer WSS layer is intentionally unpinned to survive
jurisdictions that MITM all TLS traffic; the inner layer is
SPKI-pinned.
• No analytics, no telemetry, no crash reporting.
• WalletConnect-style pairings (wc.subfrost.io) route encrypted
frames between your phone and any paired site; the relay only
ever sees ciphertext + a per-pair topic UUID.
• Foreground-service mode for de-Googled / MicroG / pure F-Droid
builds — works without Google Play Services. Persistent status
notification surfaces block height + pending tx count.
• Push notifications are 100% optional and per-event toggleable
(incoming receipt / outbound confirmation / WalletConnect
signature request).
Transaction transparency
• Every confirmed transaction renders with a colored, expandable
protostone trace tree — see exactly how the alkanes vm executed
your swap or wrap, with revert messages surfaced inline. Tap
any output to expand the full address with a copy button + an
"open in espo.sh" external link.
The SUBFROST p2p overlay (L0)
The "L0" in SUBFROST is the peer-to-peer messaging + state layer
that lets the framework operate independently of any single
coordinator. Wallets exchange encrypted frames over the
wss-tls layer.
Multilingual
The interface ships translations for English, 中文 (Simplified
Chinese), Tiếng Việt (Vietnamese), 한국어 (Korean), 日本語 (Japanese),
Українська (Ukrainian), Русский (Russian), and Bahasa Indonesia.
Switch under Settings → Language; the choice persists across
launches and follows your system locale by default.
What's experimental
This is alpha software for an experimental protocol. Bugs, indexer
divergence, or contract errors may cause loss of funds. The seed
phrase you generate or import is your only key — Subzero Research
Inc. cannot recover it. Use only with funds you can afford to lose.
Open source · open infrastructure
F-Droid repo at f-droid.subfrost.io.
Web wallet at app.subfrost.io.
© 2026 Subzero Research Inc. — released without warranty.
Stake, swap & trade Bitcoin — non-custodial wallet for the SUBFROST network