Canonical SHA-256 checksums for every published build. This page lives at the on-chain
name releases.silentmode.bch; the name pins where it is served from, so a tampered
mirror cannot change what you check against here.
Theseus Navigator 0.3.33
Windows 64-bit · unsigned · 2026-09-08 · Auto-updater now verifies SHA-256 before arming install — Companion to 0.3.32's flag fix. The in-app updater treated any Electron DownloadItem completed as ready-to-run, no hash check against the manifest. Electron has been observed to swallow mid-stream truncations (wrong Content-Length, CDN cache truncation, TLS interruption) as completed, which handed a half-file to install-update-now; NSIS integrity check then failed silently after the uninstaller had already wiped the app. Now the download handler streams the saved file through crypto.createHash("sha256"), compares against updateAvailable.setupHash from the manifest, refuses to arm install on mismatch, deletes the corrupt file, and marks the fetch failed so the next check pulls a clean copy. 0.3.32 closed the spawn-side of the "browser vanished" bug; 0.3.33 closes the download-side. Users stuck on 0.3.31 still need to manually download 0.3.33.
Windows 64-bit · unsigned · bundled Node runtime · 2026-09-08 · NRPT list from the BNS indexer + install-log-on-disk — TLD discovery now hits silentmode.st/api/tlds over HTTPS (electrum/config kept as fallbacks) so silent installs no longer get stuck when WSS is blocked. install.ps1 writes a persistent transcript at C:\ProgramData\Ariadne\install.log, plus a separate install-error.log on any uncaught exception, and Inno's own log is copied there too — so a /VERYSILENT failure always leaves forensics. Fixes the class of bug where the resolver appeared installed but the BNS Resolver Daemon scheduled task was never registered.
Android 5.0+ (API 21) · self-signed release key · 2026-08-30 · adds Sia CDN pull to the APK-bundled starter — post-install cold starts now catch up from the operator's latest published snapshot in one HTTP call
How to verify. After downloading, compute the file's SHA-256 and compare it to
the value above — on Windows: certutil -hashfile <file> SHA256;
on Android, hash the downloaded .apk on a computer before you move
it to the phone, or use any file-hashing app. Nothing here is signed by an authority your device
already trusts — by design — so it will warn about an unrecognized app; the checksum is the
real check. The machine-readable manifest is at
releases-manifest.json.