F8 (security). Two related fixes to how the wallet decides whether an RPC target is
safe to send Basic-auth credentials to:
- isLocalHost() was matching any host that merely *starts* "127." via
rfind("127.",0)==0, so "127.evil.com" (and "127.0.0.1.attacker", "127.300.0.1",
"1270.0.0.1") were misclassified as loopback and treated as local. It now uses a
strict isExactIPv4Loopback() parser: exactly four 0-255 dot-separated octets with
the first == 127. localhost / ::1 / [::1] handling is unchanged.
- A remote rpchost over plain HTTP (no rpctls=1) previously only produced a
dismissible warning and then sent rpcuser:rpcpassword in cleartext, where a
local-network MITM could capture them. tryConnect() now REFUSES that connection
(clear status line + one-time notification, no creds sent) unless the user opts in
explicitly with rpcallowplaintext=1 in DRAGONX.conf (new
ConnectionConfig::allow_plaintext_remote, parsed in parseConfFile; policy in the
new allowsPlaintextRemote()). Local/embedded daemons and rpctls=1 remotes are
unaffected.
BREAKING: a wallet configured for remote plaintext RPC will stop connecting until
rpcallowplaintext=1 (or rpctls=1) is added to DRAGONX.conf. Must be called out in the
release notes. The Settings-toggle UI is deferred (the conf-key opt-in is the recovery
path; see docs/daemon-startup-hardening.md).
Adds testIsLocalHost and testAllowsPlaintextRemote to test_phase4.cpp; one i18n key
(English) added to i18n.cpp.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
ObsidianDragon - DragonX Wallet
A lightweight, portable full-node cryptocurrency wallet for DragonX (DRGX), built with Dear ImGui.
Current pre-release: 1.2.0-rc1.
Features
- Full Node Support: Connects to dragonxd for complete blockchain verification
- Shielded Transactions: Full z-address support with encrypted memos
- Address Management: Labels, icons, favorites, hidden addresses, and address-to-address transfers
- Integrated Mining: Solo CPU mining plus pool mining through xmrig, with idle-mining controls
- Explorer Tools: Block/transaction lookup and bootstrap snapshot download
- Market Data: Real-time price charts from CoinGecko
- QR Codes: Generate and display QR codes for receiving addresses
- Multi-language: i18n support for English, German, Spanish, French, Japanese, Korean, Portuguese, Russian, and Chinese
- CJK Fonts: Bundled CJK subset font for translated interfaces
- Lightweight: ~5-10MB binary vs ~50MB+ for Qt version
- Fast Builds: Compiles in seconds, not minutes
Screenshots
Building
Quick Setup
The setup script detects your OS, installs all build dependencies, and validates your environment:
./setup.sh # Install core build deps (interactive)
./setup.sh --check # Just report what's missing
./setup.sh --all # Core + Windows/macOS cross-compile + Sapling params
./setup.sh --win # Also install mingw-w64 + libsodium-win
Manual Prerequisites
Click to expand manual install commands
Linux (Ubuntu/Debian):
sudo apt install build-essential cmake git pkg-config
sudo apt install libgl1-mesa-dev libx11-dev libxcursor-dev libxrandr-dev libxinerama-dev libxi-dev
sudo apt install libsodium-dev libcurl4-openssl-dev
Linux (Arch):
sudo pacman -S base-devel cmake git pkg-config mesa libx11 libxcursor libxrandr libxinerama libxi libsodium curl
macOS:
xcode-select --install
brew install cmake
Windows:
- Visual Studio 2019+ with C++ workload
- CMake 3.20+
Binaries
Download linux and windows binaries of latest releases and place in binary directories:
DragonX daemon (https://git.dragonx.is/DragonX/dragonx):
- prebuilt-binaries/dragonxd-linux/
- prebuilt-binaries/dragonxd-win/
- prebuilt-binaries/dragonxd-mac/
DRG-XMRig fork (https://git.dragonx.is/DragonX/drg-xmrig):
- prebuilt-binaries/drg-xmrig/
Build Steps
### Clone repository (if not already)
git clone https://git.dragonx.is/dragonx/ObsidianDragon.git
cd ObsidianDragon/
Windows Build
./build.sh --win-release
Release Build
./build.sh --linux-release # Linux release + AppImage
./build.sh --win-release # Windows cross-compile
./build.sh --mac-release # macOS .app bundle + DMG
./build.sh --clean --linux-release # Clean + Release
Running
-
Start dragonxd (if not using embedded daemon):
dragonxd -daemon -
Run the wallet:
cd build/bin ./ObsidianDragon
The wallet will automatically connect to the daemon using credentials from ~/.hush/DRAGONX/DRAGONX.conf.
Using Custom Node Binaries
The wallet checks its own directory first when looking for DragonX node binaries. This means you can test new or different branch builds of hush-arrakis-chain/hushd without waiting for a new wallet release:
- Build or download the node binaries you want to test
- Place them in the same directory as the wallet executable (e.g.
build/bin/) - Launch the wallet — it will use the local binaries instead of the bundled ones
Search order:
- Wallet executable directory (highest priority)
- Embedded/extracted daemon (app data directory)
- System-wide locations (
/usr/local/bin,~/dragonx/src, etc.)
This is useful for testing new branches or hotfixes to the node software before they are bundled into a wallet release.
Configuration
Configuration is stored in ~/.hush/DRAGONX/DRAGONX.conf:
rpcuser=your_rpc_user
rpcpassword=your_rpc_password
rpcport=21769
Project Structure
ObsidianDragon/
├── src/
│ ├── main.cpp # Entry point, SDL/ImGui setup
│ ├── app.cpp/h # Main application class
│ ├── data/ # WalletState, address book, exchange info
│ ├── config/ # Settings persistence and committed/generated version.h
│ ├── ui/
│ │ ├── schema/ # TOML UI schema and skin manager
│ │ ├── material/ # Material components, typography, layout
│ │ ├── windows/ # Tabs and dialogs
│ │ └── pages/ # Multi-page screens such as Settings
│ ├── rpc/
│ │ ├── rpc_client.cpp # JSON-RPC client
│ │ └── connection.cpp # Daemon connection
│ ├── resources/ # Embedded resource extraction
│ ├── platform/ # Windows DX11/backdrop helpers
│ ├── util/
│ │ ├── i18n.cpp # Internationalization
│ │ └── ...
│ └── daemon/
│ └── embedded_daemon.cpp
├── res/
│ ├── fonts/ # Ubuntu, icon, and CJK fonts
│ └── lang/ # Translation files
├── libs/
│ └── qrcode/ # QR code generation
├── CMakeLists.txt
├── build.sh # Release/cross-platform build script
└── scripts/create-appimage.sh # AppImage packaging
Dependencies
Fetched or discovered by CMake:
- SDL3 — Cross-platform windowing/input
- nlohmann/json — JSON parsing
- toml++ — TOML parsing (UI schema/themes)
- libcurl — HTTP/HTTPS transport for daemon RPC and network calls (system on Linux/macOS, fetched on Windows)
Bundled in libs/:
- Dear ImGui — Immediate mode GUI
- libsodium — Cryptographic operations (system on Linux or fetched by
scripts/fetch-libsodium.sh) - QR-Code-generator — QR code rendering
- miniz — ZIP compression
- GLAD — OpenGL loader (Linux/macOS)
- stb_image — Image loading
- incbin — Binary resource embedding (Windows builds)
Keyboard Shortcuts
| Shortcut | Action |
|---|---|
| Ctrl+, | Settings |
| F5 | Refresh |
| Alt+F4 | Exit |
Translation
Current language files live in res/lang/ as de, es, fr, ja, ko, pt, ru, and zh JSON files, with built-in English fallbacks.
To add a new language:
- Copy
res/lang/es.jsontores/lang/<code>.json - Translate all strings
- The language will appear in Settings automatically
License
This project is licensed under the GNU General Public License v3 (GPLv3).
Credits
- The Hush Developers
- DragonX Community
- Dear ImGui by Omar Cornut
- SDL by Sam Lantinga
Links
- Website: https://dragonx.is
- Explorer: https://explorer.dragonx.is
- Source: https://git.dragonx.is/dragonx/ObsidianDragon








