-
Morphit v1.20.0 Stable
released this
2026-09-30 18:02:27 +00:00 | 10 commits to main since this releaseMorphit v1.20.0
A major release. BLURT-paid orders now show on every instance, not only where they were posted.
Bitcoin and Monero fees can be tied to the order they pay for. You can sign in with a QR code
across instances. Each instance can set its own colour theme. Tor-only nodes keep even the
operating system off clearnet. It also carries a whole-system security, privacy and reliability
review.Four database migrations (v62–v65) run by themselves. The operator-register, release, order and
stranger-fee operations gain new optional fields. Older indexers ignore these fields, and nothing
that used to be valid stops being valid.New
- Orders paid in BLURT show on every instance.
- Before: each instance counted the operator's 90 % share of a listing fee only if it went
to its own fees account. An order posted through morphitir was therefore hidden as
"underpaid" on morphit.io, and first messages between users of different instances were
dropped. - Now: an instance publishes its fees account in its on-chain registration, and every
instance accepts payments to it.sudo morphit-ops upgradepublishes it by itself. The
10 % treasury share is still required. - Existing orders appear too. Once an operator has upgraded, its users' live orders
from before — including those paid on v1.19 — appear on every upgraded instance within
minutes, if their 90 % share went to the first fees account the operator registers. An
order whose share went to a fees account the operator had switched away from before
upgrading stays on its own instance only. Expired orders do not come back, and first
messages already dropped stay lost. - Which operators are accepted: every operator whose on-chain registration names a fees
account — the same registrations the Operators page shows. A new instance needs nothing
from anyone else. - An instance that never set a fees account keeps sending 100 % to the treasury.
- Before: each instance counted the operator's 90 % share of a listing fee only if it went
- Bitcoin fees get their own address for every order, once the treasury's extended public
key (xpub) is pinned in a release.- Users just pay the address shown, by QR code or link, and no longer paste a transaction
ID. - Nobody can claim someone else's payment.
- Payments no longer all go to one public address.
- Every instance and the browser compute the same address from chain data.
- "I've paid — check now" re-checks at once.
- For the treasury:
sudo morphit-ops treasury btcshows the gap limit to set in the
treasury wallet.
- Users just pay the address shown, by QR code or link, and no longer paste a transaction
- Monero fees work.
- Before: the transaction proof Morphit asked for could never be checked by the block
explorers, so every Monero-paid order ended up "missing". - Now: you prove the payment with the transaction key your wallet shows. There is help for
Feather, the Monero GUI and CLI, Cake Wallet and Monerujo. - Tying the payment to its order: once the treasury's main address is pinned in a release,
you pay a Monero integrated address made for your order, so a copied transaction cannot pay
for anyone else's order.
- Before: the transaction proof Morphit asked for could never be checked by the block
- Monero block explorers updated.
localmonero.co/blocksnow forwards to moneroblocks.info, which works differently, so it
is dropped. monerohash.com/explorer and exploremonero.com no longer answer and are dropped
too.- moneroblocks.info is back in a new way: it only sees the transaction ID. Your instance
checks the payment itself with the transaction key: the output, the amount (against the
amount commitment recorded on-chain) and the order binding. - The defaults are now xmrchain.net, moneroexplorer.org and moneroblocks.info.
- Two of them must now agree before a Monero fee counts as paid (it used to be one), so
no single explorer can decide it. An instance that lists only one explorer keeps accepting
one explorer's answer and says so when it starts;MORPHIT_INDEXER_XMR_MIN_SUCCESSFUL_RESPONSES
still sets it explicitly. - If you set your own list in
MORPHIT_INDEXER_XMR_EXPLORER_URLS, remove those three
explorers. For moneroblocks.info, writeraw-tx+https://moneroblocks.info.
- Sign in with a QR code across instances.
- Your phone, signed in on one instance, can approve a login on another instance's page. The
QR code must come from an instance in the Morphit directory. - Your phone only talks to its own instance, which passes the sealed message on (over Tor or
I2P where needed). The other instance never sees your phone's address. - QR sign-in now also works on .onion and .i2p pages.
- Your phone, signed in on one instance, can approve a login on another instance's page. The
- Your instance, your colours.
- For example:
sudo morphit-ops branding apply --theme-from '#f3dca0' --theme-to '#bb872f'
(on the server), or a ready-made theme such as--theme champagne-gold. - Every colour the site uses is derived from these, and each is checked for readable
contrast: buttons, links, cards, hover and focus, chat bubbles, the page background and its
corner glows. - Nothing is rebuilt and the build-integrity check stays green.
- With no theme set, Morphit looks exactly as before.
- For example:
- Tor-only nodes keep the operating system off clearnet too.
- System updates are fetched over Tor.
- The clock is set from onion sites over Tor instead of public time servers.
- Ubuntu's news fetches are switched off.
- The upgrade switches an existing node, checks it works, and puts everything back if it
doesn't.
- IPFS clean-up. Old release and snapshot copies are unpinned every week. The current and
previous release and recent snapshots are always kept.
Fixed — critical
- One malformed character could stop every indexer. Chain data containing a NUL character
made the database refuse the whole block, and indexers retried it forever. Such text is now
handled the same way on every node, and indexing never stops on it. - Fast-sync no longer rejects honest snapshots that contain orders or fees signed with an
active key.
Fixed — privacy
- Servers no longer write visitors' IP addresses to disk.
- Before, BunkerWeb kept an access log with every visitor's address in Docker's log files,
with no size limit. The frontend's web server logged the forwarded visitor address, and
bare-metal installs logged every page and API call. - Now access logging is off everywhere. BunkerWeb's log line no longer contains an address,
and Docker keeps no BunkerWeb log. The exception: if CrowdSec reads that log, a small
rotating one (5 MB) is kept for it. - To watch BunkerWeb live without storing anything, run this on the server:
sudo docker attach --no-stdin --sig-proxy=false bunkerweb.
- Before, BunkerWeb kept an access log with every visitor's address in Docker's log files,
- Tor and I2P visitors now get the same browser protections as everyone else. Their pages
used to be served with no Content-Security-Policy and no anti-framing header. The onion and
I2P policy allows the page itself plus the seven onion RPC nodes. - The QR login camera works again on Ansible-installed BunkerWeb sites. BunkerWeb's default
policy blocked it in Chrome-based browsers. (Firefox ignores that header.) - Hidden-only nodes stop two leftover clearnet contacts. Publishing a snapshot no longer asks
ipfs.io, and the hourly IPFS pin no longer waits 15 minutes for the public network.
Fixed — money
- The relay can no longer pay the same thing twice.
- If an RPC node lost its reply, the relay used to sign and send a second, different
transaction. The same happened when a node rejected a transfer that another node had
already accepted. Welcome bonuses, the 2 BLURT signup dust and power-ups could be paid two
or three times. - Now every payment is signed once and the same bytes are offered to each node. Anything
uncertain is settled by reading the chain before anything is sent again.
- If an RPC node lost its reply, the relay used to sign and send a second, different
- Signups keep their limits through restarts and bad nodes.
- The daily signup ceiling was never saved on installed boxes, so it reset on every restart.
TheSIGNUPS_DISABLEDswitch did nothing for the same reason. - Both now live in
/var/lib/morphit/relay, which is created by itself. - Signups from one address can no longer beat the per-address limit by arriving together.
- One invite can no longer create two accounts.
- A misbehaving RPC node can no longer push creations past the ceiling.
- The daily signup ceiling was never saved on installed boxes, so it reset on every restart.
- The relay refuses a sudden account-creation fee spike (more than 1.5× the configured fee)
instead of paying it.- New error codes:
relay_fee_spikeandbroadcast_outcome_unknown. The second one means
"we can't tell yet whether your account was created — try again in a minute with the same
name". A retry with the same name is safe and costs nothing extra.
- New error codes:
- Typing
12,50into an amount no longer becomes 1250.- Every amount box now understands a comma or a point as the decimal mark, and Persian,
Arabic and full-width digits. - A number that could be read two ways, like
1,234, is refused with both readings shown.
- Every amount box now understands a comma or a point as the decimal mark, and Persian,
- Expired orders no longer raise your listing fee. The indexer never marks orders as
expired, so every order that ran out used to count as live forever. The fee grew 1.5× for
each one, up to a lockout. - Real BTC/XMR fee payments can't be pushed out of the re-check queue by a flood of fake
ones. A made-up XMR transaction is now marked missing, like BTC. A fee paid exactly at the
floor is no longer rejected by rounding. - Finishing a trade automatically keeps the buyer's trade credit. An automatic completion
used to drop it.
Fixed — security
- Notification links can't send you to another site any more.
- Remember me.
- The copy of your keys kept for a page reload now expires after 30 seconds and only
survives a real reload. - Going Back to Morphit after leaving now asks for your password again.
- The copy of your keys kept for a page reload now expires after 30 seconds and only
- Lock session locks every open Morphit tab, not just the current one.
- The Active-key prompt refuses your owner key, even when the account uses one key for
both. - Changing the auto-lock time takes effect at once.
- Keys are wiped from memory when a 2FA code is required or wrong.
- The indexer no longer shows unsigned chat live, and a single RPC node can no longer plant a
posting key. Keys read from blocks are confirmed by two RPC operators before chat
verification relies on them. - Fast chat hardening.
- Clearnet fast-chat pushes connect only to the address that was checked to be public.
https://onion and I2P addresses are refused at registration and dialled correctly if
already registered.
- The federation directory.
- Censored instances are no longer dropped as dead one day after they last registered.
- A peer can no longer fill the directory with oversized or fake data.
- Behind BunkerWeb, one visitor can no longer rate-limit everyone. All visitors used to
share one limit bucket. - Server-side fixes.
- Several root-owned files could be redirected by a local account through symbolic links.
Among them: the upgrade's temporary folder, the branding ownership change, and two marker
files. - The first-boot helper ran any user's canary script as root.
- Several root-owned files could be redirected by a local account through symbolic links.
- Patched libraries. undici is now 7.29.1: before, a hostile peer could send the indexer a
compressed reply that expands until memory runs out. brace-expansion and ip-address are also
updated for newly published advisories.
Fixed — upgrades and operations
- The upgrade finds BunkerWeb by what it is, not by its name, so hand-made stacks (like
morphit.io's) are handled correctly.- It only restarts BunkerWeb, its scheduler and the frontend, and never the whole stack.
- It uses every compose file you started the stack with.
- If it can't tell which container is which, it changes nothing and says so.
- The upgrade checks that services actually stay up after a restart. A brief automatic
restart while the database starts is fine. A rollback now also brings back a service that
crashed. - The upgrade now also refreshes the helper scripts in
/usr/local/lib/morphit/. It also
opens the IPFS port (4001, TCP and UDP) on clearnet IPFS hosts that were installed before it
was added. - Every RPC use goes through the full node pool, with the healthiest node first:
morphit-opslookups and registration, the canary, and the release broadcast scripts. On a
tor-only box only hidden nodes are used. The browser on an onion page now uses all seven
onion RPC nodes, not two. - 16 old one-off debug and patch scripts in
ops/were removed. Several of them broke
today's indexer if run. - Honest messages.
morphit-ops doctorno longer tells you to remove an RPC node that is only briefly down.- The firewall check no longer says "OK" when it could not reach the site.
morphit-ops --versionshows the real version.branding statusasks for sudo instead of guessing.
- Plain-HTTP I2P visitors see a calm note where the browser does not allow a feature (2FA
codes, copy buttons), instead of an error. - Other.
- The homepage's "What Morphit is built around" heading is removed in all 10 languages. The
seven cards stay, and their titles are now proper headings for screen readers. - "agorist" is no longer translated, and Blurt is spelled Blurt in Persian.
- The homepage's "What Morphit is built around" heading is removed in all 10 languages. The
Upgrading
Run
sudo morphit-ops upgradeon each server. Nothing needs doing by hand.- Fees account. The upgrade publishes your instance's fees account in its operator
registration by itself. It keeps your current on-chain name, address and contact exactly as
they are.- If it can't unlock the relay key without you, it prints one line. Then run
sudo morphit-ops registeron that server. - Check the result with
sudo morphit-ops status→ "Fees account (federation)".
- If it can't unlock the relay key without you, it prints one line. Then run
- On BunkerWeb boxes the upgrade:
- applies the new privacy and header settings to BunkerWeb and the frontend, checks them, and
puts everything back if a check fails; - switches BunkerWeb to the frontend's new private port (8088) only after it sees that port
working.
- applies the new privacy and header settings to BunkerWeb and the frontend, checks them, and
- On Tor-only boxes the upgrade also moves system updates and the clock onto Tor, as above.
It finishes within its time limit. Anything left half-done is finished or undone by a timer
within six hours. - Some protections take effect from the next upgrade after this one, because this upgrade
is still run by v1.19.0's own code: the upgrade's private temporary folder, its own symlink
and npm checks, and its restart checks. - Registered
https://onion address? An operator who registered one should register again
withhttp://: runsudo morphit-ops registeron that server. - Bitcoin per-order addresses and Monero order-bound addresses start only when the maintainer
pins the treasury keys in a later release. That release comes after every instance runs
v1.20.0. Until then, Bitcoin fees work as before and Monero fees use the transaction key.
Branded instances keep their logo, icons and name, and now their colours: the upgrade
re-applies them.Downloads
-
Source code (ZIP)
1 download
-
Source code (TAR.GZ)
0 downloads
- Orders paid in BLURT show on every instance.