Marigold
Questions
Short answers, with the trade-offs stated rather than smoothed over.
Connecting
Should I use the public node or run my own?
Your wallet holds your notes. It still has to ask a node what is
happening on the network — whether a note is real, whether a payment landed.
That node is the only party in the whole system that learns anything about
you.
| Public node | Your own node |
| Ready | Immediately | After it catches up with the network |
| Disk | None | Several gigabytes, and it grows |
| Who sees your notes | Whoever runs the node | Nobody |
| Who sees your address | Whoever runs the node | Nobody |
What a node can see. The chain records
that a note was retired and a new one issued. It never records who did it,
or that the two belong to the same person — that is the whole design. But
your wallet asks a node about its own notes, and those questions
arrive together, from one network address. A node operator can therefore
learn which notes are held by the same wallet. It is the one place that
linkage exists, and it exists only because you asked someone else.
What a node cannot do. It cannot spend your notes, see
your keys, or stop you paying someone. Your money is not at risk either way.
What is at stake is only whether a stranger can tell your notes apart from
everyone else's.
A reasonable rule. Use the public node while you are
trying Marigold out, or for money you would carry in a pocket. Run your own
for anything you would rather nobody could correlate. In the wallet:
node start runs a node inside the wallet itself — no
separate program to install or supervise. connect public uses
one we run instead. You can switch whenever you like; the notes are yours
either way.
Who runs the public node?
We do. It is the same machine that runs one of the network's seed nodes,
and it can see exactly what the answer above describes: the address you
connect from, and which notes your wallet asks about.
We would rather say that plainly than have you assume a public node is
neutral. It is not — no node is. That is why the wallet can run its own.
How much disk and time does running my own node take?
Several gigabytes, growing as the chain does, and the first run has to
download and verify the chain before your balance is accurate. You can keep
using the wallet while it catches up; figures will be incomplete until it
has.
It lives beside your wallet files, so deleting your Marigold directory
removes both — you will not be left with gigabytes you cannot account for.
Notes and money
What is a note, exactly?
A key that is worth a fixed amount. Not a balance in an account — an
object you hold, like a banknote. Holding the key is owning the
money, and handing the key over is paying someone. There is no
sender, no receiver and no account anywhere in it.
Notes come in fixed sizes — 0.01, 0.1, 1, 10, 100 and up — so one 10
MAGLD note looks exactly like every other 10 MAGLD note.
What happens if I lose my notes?
They are gone. This is the part of bearer money that has no soft edge:
there is no recovery, no support line, no way to reverse it, exactly as with
a banknote you drop in the street.
So keep a backup — the wallet can keep one for you, see the answers
below — and please read them rather than assuming it works the way other
wallets do. It does not.
Are the 24 recovery words a backup of my money?
No — and this is the most expensive thing to get wrong about
Marigold.
In most crypto wallets a recovery phrase is the money: type the
words into a new device and every coin reappears, because the coins are
entries on a ledger and the phrase derives the keys that claim them.
Marigold does not work like that. Every note is its own independent
secret. Nothing derives them, because if anything could, they would not be
bearer instruments. The notes are files in your vault. The
words unlock those files — they are not a copy of them.
| What you have | What you can recover |
| A backup + the 24 words | Everything |
| A backup + your wallet password | Nothing. A backup never opens with the password (see the next answer) |
| The 24 words alone | Nothing. A key to a vault that is not there |
| A backup alone, no words | Nothing. A vault nothing opens |
So you need both, and they should not share a fate. Keep
a copy of the vault files somewhere the original disk failing will not take
with it, and keep the words somewhere separate — a fire that reaches one
should not reach the other.
In the wallet, backup writes the encrypted backup to a file
and telegram backup has the wallet keep one current in your
Telegram chat by itself. Restoring takes the backup and the words:
wallet restore <file> or telegram
restore, then the 24 words at the prompt.
Why does a backup open with the 24 words and not with my password?
Because a backup lives on servers you do not control — Telegram, a cloud
drive, a USB stick in a drawer — where whoever holds a copy can attack it
offline, at leisure, for as long as they like.
Your wallet password is something you type every day and chose to be
able to remember. That makes it, by construction, not random, and a
not-random secret is what an unhurried attacker brute-forces. The 24 words
are 256 bits that nobody chose; they cannot be guessed. So every backup the
wallet makes — the file from backup and the copies it posts to
Telegram — is sealed with a key derived from the words, and the password
never opens one.
That is why the wallet shows you the words when it is created, explains
them, and asks you for two of them by number before it lets you go on. Write
them on paper, not in a photo, and keep the paper somewhere a fire that
reaches your computer will not reach.
The automatic backup, plainly: after you run telegram backup
once, the wallet posts an encrypted copy of itself into your bot's chat and
keeps it current while it is open — a full copy every week, the changes
within minutes of a payment, silently. To restore on a new machine, run
telegram restore there, forward the bot everything from
the last dashed line in the chat to the end, and give the words.
Do I need to be online to pay? Do I need a wallet that is always on?
No, and no. Bitcoin can be kept offline as a QR code, but it cannot be
spent that way: paying with it means broadcasting a transaction, so somebody
has to be online, and a wallet that is never online cannot pay.
A Marigold note is the key itself. It can pass from hand to hand offline,
exactly like a banknote — printed, texted, shown as a QR code — and the
network is touched only when the new holder decides to swap the lock, which
they can do whenever they next have a connection. Nothing about paying
requires your wallet to be connected at that moment, or to be permanently
online at all.
Can I keep notes on my phone as QR codes?
Yes, and it is worth being clear about what that is. Marigold has no
standalone phone app on purpose: the full wallet runs on a computer or a
server you control. Your phone can still be used in two ways — as a remote
control through Telegram, with the wallet open on a connected machine, or
simply as a place to keep pictures of note QR codes, the way you keep
banknotes in a wallet.
A note is a key, and a QR code of that key is the money. Anyone
who sees, copies or scans the picture can claim the note by putting their
own lock on it. So treat those pictures exactly like cash: not in a shared
album, not in a chat, not on a screen someone else can photograph.
What does it cost to pay someone?
0.01 MAGLD — one hundredth of a coin — for any everyday payment, however
much you are sending. The fee is a single small note handed over with the
payment, so a coffee and a car cost the same to move. Only unusually large
operations, bundling dozens of notes at once, step up to two or three
hundredths.
And when a hundredth of a coin stops being small change? The smallest
note is 0.01 MAGLD and the fee is one such note. Should 1 MAGLD come to be
worth more than about a dollar, the plan on record is to add a 0.001 note
(or smaller) by a network upgrade and make the fee that new smallest note.
Every existing note stays exactly as it is; the table of note sizes has
room reserved for the new rung. The ladder does not start at a petal
because every note size is a separate key to rotate on every payment —
cash stops at the cent for the same reason.