Skip to main content

What Privacy Stack Should I Use for Mobile?

Mobile devices are the weakest link in most bitcoiners' privacy stacks. They broadcast location, run closed-source basebands, and constantly phone home to Apple or Google. This page maps a practical mobile privacy stack from OS to wallet.

Bottom line: If you cannot switch OS, you can still harden Android/iOS significantly. If you can switch OS, GrapheneOS on a Pixel is the current gold standard for mobile bitcoin privacy.

Quick Decision Flow

Are you willing to buy a dedicated device for bitcoin?
|
├── Yes → GrapheneOS Pixel + Mullvad VPN + Samourai/Blockstream Green
│ Maximum isolation; no Google telemetry; sandboxed apps if needed
|
└── No → Harden your existing phone
├── Android → Disable Google apps, use Shelter work profile,
│ Mullvad VPN, Signal, Samourai (if installed)
└── iOS → Limited hardening; accept higher metadata leakage;
use Signal, Blockstream Green, avoid iCloud backup of wallet

Layer 0: Operating System

The OS is the foundation. Everything above it inherits its trust model.

OSPrivacy LevelBitcoin Wallet SupportNotes
GrapheneOSHighestFull Android compatibilityNo Google by default; sandboxed Play Services optional; verified boot
CalyxOSHighFull Android compatibilitymicroG for app compatibility; pre-installed privacy tools
Stock AndroidLowFullConstant Google connectivity checks; location history; app telemetry
iOSLow–MediumLimited by App StoreClosed source; iCloud backups leak wallet metadata; Lockdown Mode helps

Recommendation: A used Pixel 3a or newer running GrapheneOS costs ~$100–$300 and removes the largest surveillance surface on your stack.

Layer 1: Network Hygiene

Mobile networks are uniquely hostile: IMEI tracking, cell tower triangulation, carrier data sales.

ToolPurposeCost
Mullvad VPNHide traffic from carrier; anonymous signup (cash/BTC)~$5/mo
Tor Browser / OrbotOnion-routing for wallet traffic and webFree
Burner SIMCash pay-as-you-go; no identity linked to IMEI~$10–$30
Silent LinkAnonymous eSIM; no ID requiredVaries

Critical: Even with a VPN, your carrier knows your IMEI and approximate location via cell towers. A burner SIM or Silent Link eSIM breaks that link.

Layer 2: Bitcoin Wallet

Mobile wallets trade security for convenience. Use them for spending money, not long-term savings.

WalletPrivacy FeaturesPlatformBest For
SamouraiWhirlpool, Stonewall, PayNyms, DojoAndroidOn-chain privacy; existing installs only (delisted 2024)
Blockstream Green2FA multisig, Tor, own nodeAndroid, iOSSecurity-first hot wallet
Blue WalletLightning + own node, TorAndroid, iOSLightning spending
MuunSimple UX, submarine swapsAndroid, iOSBeginners; on-chain + Lightning
ZeusSelf-hosted Lightning node UIAndroid, iOSPower users with own node

Trade-offs:

  • Samourai has the strongest on-chain privacy but is Android-only and delisted
  • iOS users lack CoinJoin wallets; use Blockstream Green or Muun and accept weaker transaction privacy
  • Never back up wallet seeds to iCloud or Google Drive

Layer 3: Acquisition on Mobile

Buying bitcoin from a mobile device is inherently higher risk than from a desktop or node.

MethodMobile ViabilityPrivacyNotes
Azteco voucherExcellentMediumBuy voucher in person or via web; redeem on mobile wallet
BisqPoorHighDesktop-only; do not run Java apps on mobile
Peer-to-peerGoodHighMeetups, friends, Telegram/Signal groups; cash or Strike
Bitcoin ATMGoodMediumUse burner phone; high fees (8–20%)

Recommendation: Use Azteco for small amounts on mobile. For larger amounts, acquire on desktop (Bisq) and transfer to mobile wallet over Lightning or PayJoin.

Layer 4: Communication

Your messaging app leaks metadata: who you talk to, when, how often.

AppMetadata ProtectionBitcoin IntegrationNotes
SignalSealed sender, no logsNoneGold standard for private messaging
SimpleXNo user IDs, no central serversNoneMaximum metadata resistance
TelegramSecret Chats onlySome botsDefault chats are not E2E encrypted
Matrix/ElementFederated, self-hostableNoneGood for communities; higher complexity

Avoid: WhatsApp (Meta), default SMS (carrier logged), iMessage (Apple logged).

Hardening Without Switching OS

If you cannot switch to GrapheneOS, do this on any Android device:

  1. Disable Google apps you do not use (Maps, Assistant, Photos)
  2. Turn off location history and Wi-Fi scanning
  3. Review app permissions — deny location, contacts, microphone unless essential
  4. Use Shelter (work profile) to isolate bitcoin apps from daily apps
  5. Set DNS to Mullvad or Quad9 to block trackers at the network level
  6. Disable connectivity checks if rooted (stops Google ping on every Wi-Fi join)

On iOS:

  1. Enable Lockdown Mode (Settings > Privacy & Security)
  2. Disable iCloud Backup for wallet apps
  3. Use Sign in with Apple with hidden email for app accounts
  4. Accept that iOS privacy is fundamentally limited by closed-source design

Decision Matrix

ProfileOSNetworkWalletAcquisitionMessaging
Maximum privacyGrapheneOSMullvad + Tor + Silent LinkSamourai + DojoAzteco / P2PSignal / SimpleX
BalancedCalyxOSMullvad VPNBlockstream GreenAzteco / ATMSignal
Hardened stock AndroidStock + ShelterMullvad VPNBlockstream GreenAztecoSignal
iOS useriOS + LockdownMullvad VPNBlockstream GreenAztecoSignal
BeginnerAnyMullvad VPNMuunAzteco / ATMSignal

Common Mistakes

MistakeWhy It HurtsFix
Backing up seed to iCloud/Google DriveCloud accounts are hackable and subpoena-ableSteel backup or encrypted local storage
Using same phone for bitcoin and social mediaSocial apps harvest contacts, location, usage patternsDedicated device or Shelter work profile
Ignoring baseband riskCellular modem firmware is closed-source and privilegedAirplane mode + Wi-Fi when possible; burner SIM
Using KYC exchange app on daily phoneExchange links identity to IMEI, location, contactsAcquire via Azteco or P2P; use web, not app
Reusing addressesLinks all your transactions togetherUse wallets with automatic address rotation