Marigold

Questions

Short answers, with the trade-offs stated rather than smoothed over.

Connecting

Should I use the public node or run my own?

Your wallet holds your notes. It still has to ask a node what is happening on the network — whether a note is real, whether a payment landed. That node is the only party in the whole system that learns anything about you.

Public nodeYour own node
ReadyImmediatelyAfter it catches up with the network
DiskNoneSeveral gigabytes, and it grows
Who sees your notesWhoever runs the nodeNobody
Who sees your addressWhoever runs the nodeNobody

What a node can see. The chain records that a note was retired and a new one issued. It never records who did it, or that the two belong to the same person — that is the whole design. But your wallet asks a node about its own notes, and those questions arrive together, from one network address. A node operator can therefore learn which notes are held by the same wallet. It is the one place that linkage exists, and it exists only because you asked someone else.

What a node cannot do. It cannot spend your notes, see your keys, or stop you paying someone. Your money is not at risk either way. What is at stake is only whether a stranger can tell your notes apart from everyone else's.

A reasonable rule. Use the public node while you are trying Marigold out, or for money you would carry in a pocket. Run your own for anything you would rather nobody could correlate. In the wallet:

node start runs a node inside the wallet itself — no separate program to install or supervise. connect public uses one we run instead. You can switch whenever you like; the notes are yours either way.

Who runs the public node?

We do. It is the same machine that runs one of the network's seed nodes, and it can see exactly what the answer above describes: the address you connect from, and which notes your wallet asks about.

We would rather say that plainly than have you assume a public node is neutral. It is not — no node is. That is why the wallet can run its own.

How much disk and time does running my own node take?

Several gigabytes, growing as the chain does, and the first run has to download and verify the chain before your balance is accurate. You can keep using the wallet while it catches up; figures will be incomplete until it has.

It lives beside your wallet files, so deleting your Marigold directory removes both — you will not be left with gigabytes you cannot account for.

Notes and money

What is a note, exactly?

A key that is worth a fixed amount. Not a balance in an account — an object you hold, like a banknote. Holding the key is owning the money, and handing the key over is paying someone. There is no sender, no receiver and no account anywhere in it.

Notes come in fixed sizes — 0.01, 0.1, 1, 10, 100 and up — so one 10 MAGLD note looks exactly like every other 10 MAGLD note.

What happens if I lose my notes?

They are gone. This is the part of bearer money that has no soft edge: there is no recovery, no support line, no way to reverse it, exactly as with a banknote you drop in the street.

So keep a backup — the wallet can keep one for you, see the answers below — and please read them rather than assuming it works the way other wallets do. It does not.

Are the 24 recovery words a backup of my money?

No — and this is the most expensive thing to get wrong about Marigold.

In most crypto wallets a recovery phrase is the money: type the words into a new device and every coin reappears, because the coins are entries on a ledger and the phrase derives the keys that claim them.

Marigold does not work like that. Every note is its own independent secret. Nothing derives them, because if anything could, they would not be bearer instruments. The notes are files in your vault. The words unlock those files — they are not a copy of them.

What you haveWhat you can recover
A backup + the 24 wordsEverything
A backup + your wallet passwordNothing. A backup never opens with the password (see the next answer)
The 24 words aloneNothing. A key to a vault that is not there
A backup alone, no wordsNothing. A vault nothing opens

So you need both, and they should not share a fate. Keep a copy of the vault files somewhere the original disk failing will not take with it, and keep the words somewhere separate — a fire that reaches one should not reach the other.

In the wallet, backup writes the encrypted backup to a file and telegram backup has the wallet keep one current in your Telegram chat by itself. Restoring takes the backup and the words: wallet restore <file> or telegram restore, then the 24 words at the prompt.

Why does a backup open with the 24 words and not with my password?

Because a backup lives on servers you do not control — Telegram, a cloud drive, a USB stick in a drawer — where whoever holds a copy can attack it offline, at leisure, for as long as they like.

Your wallet password is something you type every day and chose to be able to remember. That makes it, by construction, not random, and a not-random secret is what an unhurried attacker brute-forces. The 24 words are 256 bits that nobody chose; they cannot be guessed. So every backup the wallet makes — the file from backup and the copies it posts to Telegram — is sealed with a key derived from the words, and the password never opens one.

That is why the wallet shows you the words when it is created, explains them, and asks you for two of them by number before it lets you go on. Write them on paper, not in a photo, and keep the paper somewhere a fire that reaches your computer will not reach.

The automatic backup, plainly: after you run telegram backup once, the wallet posts an encrypted copy of itself into your bot's chat and keeps it current while it is open — a full copy every week, the changes within minutes of a payment, silently. To restore on a new machine, run telegram restore there, forward the bot everything from the last dashed line in the chat to the end, and give the words.

Do I need to be online to pay? Do I need a wallet that is always on?

No, and no. Bitcoin can be kept offline as a QR code, but it cannot be spent that way: paying with it means broadcasting a transaction, so somebody has to be online, and a wallet that is never online cannot pay.

A Marigold note is the key itself. It can pass from hand to hand offline, exactly like a banknote — printed, texted, shown as a QR code — and the network is touched only when the new holder decides to swap the lock, which they can do whenever they next have a connection. Nothing about paying requires your wallet to be connected at that moment, or to be permanently online at all.

Can I keep notes on my phone as QR codes?

Yes, and it is worth being clear about what that is. Marigold has no standalone phone app on purpose: the full wallet runs on a computer or a server you control. Your phone can still be used in two ways — as a remote control through Telegram, with the wallet open on a connected machine, or simply as a place to keep pictures of note QR codes, the way you keep banknotes in a wallet.

A note is a key, and a QR code of that key is the money. Anyone who sees, copies or scans the picture can claim the note by putting their own lock on it. So treat those pictures exactly like cash: not in a shared album, not in a chat, not on a screen someone else can photograph.

What does it cost to pay someone?

0.01 MAGLD — one hundredth of a coin — for any everyday payment, however much you are sending. The fee is a single small note handed over with the payment, so a coffee and a car cost the same to move. Only unusually large operations, bundling dozens of notes at once, step up to two or three hundredths.

And when a hundredth of a coin stops being small change? The smallest note is 0.01 MAGLD and the fee is one such note. Should 1 MAGLD come to be worth more than about a dollar, the plan on record is to add a 0.001 note (or smaller) by a network upgrade and make the fee that new smallest note. Every existing note stays exactly as it is; the table of note sizes has room reserved for the new rung. The ladder does not start at a petal because every note size is a separate key to rotate on every payment — cash stops at the cent for the same reason.