Wasabi Wallet on Raspberry Pi: Creating a Privacy-Focused Full Node and Wallet Device for Under $100

A Bitcoin user concerned with transaction surveillance has limited practical options. Using a light wallet connected to someone else's server exposes transaction requests to that server operator. Connecting through a public node pool reveals IP address associations with specific addresses. A full node running locally solves both problems, but the cost of dedicated hardware or the complexity of managing a separate machine often makes users accept less privacy than they prefer. Wasabi Wallet's architecture creates another possibility: run a complete Bitcoin validation environment on modest hardware, perform CoinJoin mixing locally, and broadcast transactions through your own node, all for the cost of a Raspberry Pi and a storage device.

This is not a novel idea in theory, but it is rarely executed in practice because the guides that exist tend to assume command-line fluency and omit the specific configuration steps that separate a project from a working installation. The practical barrier is not the cost. It is the gap between "Wasabi supports custom nodes" and "here is how to actually set this up on your Raspberry Pi, test the connection, and verify that your transactions are genuinely private." That gap exists because different versions of Wasabi, different Raspberry Pi models, different operating systems, and different storage options each introduce small variations that cascade into hours of troubleshooting.

Diagram showing a Raspberry Pi full node architecture connected to Wasabi Wallet desktop client, illustrating the local network connection path for transaction broadcasting without external server reliance

Why a local node changes the threat model

Running Wasabi Wallet against a public node—whether one provided by the Wasabi team or a random third party—creates an information leak at the network layer. When the wallet broadcasts a transaction or queries balances, the node operator can correlate the request with your IP address and approximate timestamp. Even if the transaction itself is obfuscated through CoinJoin mixing, the moment you connect to request balance information or broadcast an unsigned transaction for signing, that operator learns something about your activity pattern.

A full node under your control eliminates that specific vulnerability. Your Wasabi Wallet communicates exclusively with Bitcoin Core running on the same local network, over an encrypted connection that never exposes transaction details to external observers. The node validates every block from the Bitcoin network independently, meaning you do not rely on anyone's assertion about transaction confirmation or balance correctness. You receive the raw data directly from peer-to-peer connections to other Bitcoin nodes, and you verify it yourself.

The Raspberry Pi makes this economically viable because Bitcoin Core's full validation requires roughly 500–600 GB of disk space for the blockchain, an amount that fits on a single external SSD. A Raspberry Pi 4 or 5 with 4 GB of RAM can perform full validation, though slowly. Synchronization may take 24–48 hours on initial setup, but after that, the device consumes minimal electricity while running continuously in the background. The total cost—Pi, SSD, power supply, and case—rarely exceeds $100 if purchased carefully.

Choosing hardware and storage carefully

Not all Raspberry Pi models are suitable for this task. A Pi Zero or original Pi 1 lacks sufficient RAM and CPU for reliable Bitcoin Core operation. A Pi 3 is the bare minimum; it will work but will synchronize slowly and may struggle during periods of high network activity. A Pi 4 with 4 GB of RAM or a Pi 5 with 8 GB is the practical choice, though the extra expense over a Pi 3 is modest relative to the improvement in usability.

Storage is more critical than processing power. The Raspberry Pi's onboard SD card is not suitable for Bitcoin Core because SD cards have limited write endurance and degrade faster under the constant disk activity that blockchain validation requires. An external USB SSD—either 3.5-inch or 2.5-inch form factor—is mandatory. Kingston, Samsung, Crucial, and Western Digital all manufacture reliable models in the 500–1000 GB range for $40–$70. Avoid USB drives and mechanical USB hard drives; they are slower and less reliable for continuous operation.

Connection matters as well. A Pi 4 or 5 has a USB 3.0 port (or USB 3.1 on the Pi 5), which provides faster data transfer than the USB 2.0 ports on older models. Use a USB 3.0 cable and connect directly to the blue USB 3.0 port if available. The Pi's network port should be a wired Ethernet connection for consistency and speed, not Wi-Fi. Bitcoin Core will consume 5–10 GB of bandwidth during initial synchronization, and 100–200 MB daily afterward; Wi-Fi can introduce jitter and connection interruptions that slow the process or cause it to restart.

Setting up Bitcoin Core on the Raspberry Pi

Begin with a fresh Raspberry Pi OS installation on the onboard SD card. Download the official image from raspberrypi.com, write it using balena Etcher or a similar tool, and boot the Pi. Configure basic settings: set a static IP address on your local network, enable SSH, and update the operating system with `sudo apt update && sudo apt upgrade -y`. These steps are non-negotiable because they prevent the Pi from obtaining a different IP address mid-synchronization and ensure you can access it remotely without a monitor and keyboard attached.

Install Bitcoin Core from the ARM build maintained by the Bitcoin project. The command is straightforward—`wget https://bitcoincore.org/bin/bitcoin-core-25.0/bitcoin-25.0-arm-linux-gnueabihf.tar.gz` (replace version number with the current release)—followed by extraction and installation. Create a dedicated user for Bitcoin Core and configure it to run as a service, so it starts automatically on reboot and continues running even if you disconnect your SSH session.

Configuration requires a few critical settings in the `bitcoin.conf` file. Set `server=1` to enable the RPC interface, which Wasabi will use to communicate with the node. Set `rpcuser` and `rpcpassword` to something genuinely random—use `openssl rand -base64 32` to generate a strong password. Bind the RPC interface to localhost only: `rpcbind=127.0.0.1`. Set `txindex=1` if you plan to query transaction history by hash; it increases disk usage slightly but is useful for wallet operations. Finally, set reasonable resource limits: `maxconnections=40` and `maxuploadtarget=500` to prevent the node from consuming all available bandwidth or connections.

Start Bitcoin Core with `sudo systemctl start bitcoind` and monitor synchronization progress using `bitcoin-cli getblockchaininfo`. The output will show `blocks` (how many you have) and `headers` (how many exist). When they match, your node has synchronized. Depending on your Pi model and SSD speed, this can take 24–72 hours. Patience is necessary here; interrupting synchronization or forcing a restart can corrupt the blockchain database and force a restart from a checkpoint, wasting significant time.

Connecting Wasabi Wallet to your local node

Download Wasabi Wallet from the official site on the computer where you plan to run the desktop wallet. Verify the signature of the installer against the published checksum to confirm authenticity. This step is non-negotiable because a modified installer could silently steal private keys or intercept CoinJoin transactions. Open the installer only after verification succeeds.

When Wasabi launches, navigate to Settings and select the Network tab. By default, Wasabi connects to a public node pool maintained by the Wasabi team. Change this to connect exclusively to your local node. Enter the RPC endpoint as `http://127.0.0.1:8332`, and provide the `rpcuser` and `rpcpassword` you configured in `bitcoin.conf`. Wasabi will test the connection; if it fails, verify that Bitcoin Core is running (`sudo systemctl status bitcoind`), that the IP address and port are correct, and that the RPC credentials match exactly.

Once the connection succeeds, Wasabi will scan the blockchain for addresses belonging to your wallet. This is a one-time operation that may take 10–30 minutes depending on how many addresses you have and how old your wallet is. After that, Wasabi will pull new block information from your local node and remain synchronized in near-real time. The connection is encrypted by default, but it remains a local network connection, so eavesdropping risk is minimal unless someone has direct access to your network device.

Performing CoinJoin transactions privately

With your local node running and Wasabi connected, you are now in a position to perform Bitcoin privacy mixing through CoinJoin without exposing transaction requests to external servers. Open Wasabi's Send dialog, and you will see the option to participate in a CoinJoin round. Wasabi's CoinJoin implementation—developed collaboratively with the Wasabi team—pools multiple inputs and outputs together, making it difficult for chain analysis to determine which input corresponds to which output.

The process is not instant. A CoinJoin round typically takes 10–30 minutes from the moment you select "Mix" until the transaction is broadcast. During this time, your inputs are combined with others, and the system waits for all participants to confirm their inputs and outputs. You will see a waiting screen that shows the current round state. This waiting period exists because it strengthens privacy: if rounds completed instantly, the timing of your transaction would reveal information about your participation.

The fee for CoinJoin participation is modest—typically 0.003 BTC per input—but it is distinct from the mining fee. Wasabi calculates both and displays the total cost before you confirm. Confirm the amount only after verifying that the receiving address is correct and that you have written it down separately. If you lose the CoinJoin transaction ID, you can query it from your local Bitcoin Core using the transaction hash, but that requires some command-line familiarity.

After a CoinJoin round completes, the mixed outputs are flagged in Wasabi's interface with a privacy label. These outputs are available for subsequent transactions, and you can verify on the blockchain that they are indistinguishable from outputs created by other participants. The benefit persists only if you do not subsequently consolidate CoinJoined outputs with unmixed ones, which would break the privacy gained. Wasabi's interface warns against this by default, but you retain full control to override those warnings if you understand the consequences.

Verifying your setup and maintaining the node

After your node is synchronized and Wasabi is connected, perform a sanity check. Create a new receiving address in Wasabi, then query Bitcoin Core directly to confirm it recognizes that address. Use `bitcoin-cli importaddress [address]` to manually import it into the node, then `bitcoin-cli getaddressinfo [address]` to verify it is recognized. This step confirms that your node is not simply parroting information from somewhere else but actually validating addresses.

Monitor the node's health periodically using `bitcoin-cli getnetworkinfo` and `bitcoin-cli getpeerinfo`. The first command shows how many peer connections the node has (a number between 10 and 125 is normal); the second shows details about those peers. If peer connections drop to zero, the node has lost network connectivity and will not receive new blocks until it reconnects. Check the Ethernet cable, restart the network interface with `sudo systemctl restart networking`, or restart the entire Pi if the connection does not recover.

Bitcoin Core will consume roughly 100–200 MB of bandwidth per day after synchronization completes. Set bandwidth limits in `bitcoin.conf` if you have a metered connection, using `maxuploadtarget` to restrict outbound traffic. Storage usage is stable at 500–600 GB once synchronization finishes; the blockchain does not grow at a rate that will fill a typical SSD within several years. Plan to restart the node monthly to clear temporary memory usage and apply any operating system security updates.

Backup your Wasabi wallet seed phrase and store it offline in a secure location. The local Bitcoin Core node does not hold your private keys; it merely validates transactions and provides network connectivity. If your Pi fails or the SSD becomes corrupted, you can restore Wasabi's private keys from the seed phrase on any other computer running Wasabi Wallet. The blockchain data on the Pi can be recreated through re-synchronization, so it does not need to be backed up.

Limitations and realistic expectations

Running Bitcoin Core on a Raspberry Pi introduces genuine constraints that you should understand before investing time in the project. Synchronization is slow—initial blockchain download takes days, not hours. Query responses are slower than they would be on a desktop or server. If you need to scan a large wallet or query historical transactions frequently, the Pi will be noticeably laggy. These are not deal-breakers for most users, because Wasabi does most of its work in the background, but they should inform your expectations.

Hardware reliability is a second consideration. Raspberry Pi units are inexpensive, but they are not industrial equipment. A power failure, thermal stress, or power supply failure can render one unusable. The SSD is more robust, but SSDs can fail without warning. Plan for the possibility that you will need to replace the Pi and re-synchronize the blockchain. For users who cannot tolerate 24–48 hours of downtime for node recovery, a second Pi and SSD as a warm backup might be appropriate, though that increases total cost to $200.

Privacy at the application layer is separate from privacy at the network layer. Running your own Bitcoin Core node and connecting Wasabi locally protects you from server-based surveillance and correlation attacks. It does not protect you from network-level attackers who can observe your ISP's traffic, monitor your home network, or intercept packets in transit. Combining a local node with VPN or Tor connection at the ISP level provides layered protection, but that is a separate configuration task beyond the scope of this guide.

Next steps and future improvements

With a functioning Wasabi setup on Raspberry Pi, you have a foundation for more advanced privacy practices. Adding Tor support to Bitcoin Core's P2P connections (`onion=auto` in `bitcoin.conf`) makes your node's network connections harder to correlate with your IP address. Configuring a hardware wallet integration with Ledger or Trezor through Wasabi's Settings allows you to keep private keys offline while using the Pi for network connectivity and CoinJoin coordination.

The Wasabi development roadmap includes faster CoinJoin rounds, which would reduce the waiting time for transaction confirmation. Improved mobile interoperability is also planned, though mobile wallets introduce additional security considerations and do not integrate with a local Bitcoin Core node as directly as the desktop application does. Monitor the Wasabi project's GitHub repository for updates, and subscribe to release notifications so you can apply security patches promptly.

For users who find the initial setup overwhelming, the investment in time is front-loaded. The Wasabi setup and Bitcoin Core synchronization require active attention for the first week. After that, maintenance is minimal—a few commands per month to verify node health, and occasional software updates. The privacy benefit persists indefinitely, and the low cost of hardware means that even if the Pi fails, replacement and re-setup is economically feasible. This is a genuinely practical path to self-sovereign Bitcoin privacy.

Frequently asked questions

How long does Bitcoin Core synchronization take on a Raspberry Pi?

Initial synchronization typically takes 24–72 hours, depending on your Pi model, SSD speed, and network conditions. A Pi 4 with a modern SSD on gigabit Ethernet will synchronize faster than a Pi 3 with a slower drive on standard Ethernet. After the initial sync, the node stays current with new blocks in near-real time, requiring roughly 100–200 MB of bandwidth per day.

Can I run Wasabi Wallet on the Raspberry Pi itself, or does it have to be on a separate computer?

Wasabi Wallet is a desktop application designed for Windows, macOS, and Linux with a graphical interface. It requires more resources than a Raspberry Pi can comfortably provide while also running Bitcoin Core. The standard setup runs Bitcoin Core on the Pi and Wasabi on a separate computer (laptop or desktop) on the same local network, connected to the Pi's node via RPC.

Is my Bitcoin private if I use Wasabi with a local node but still connect to the internet normally?

A local node protects you from server-based surveillance by your node provider, but it does not protect you from network-level observation of your ISP traffic or home network. For stronger network privacy, combine a local node with Tor connections at the ISP level or use a VPN. However, a VPN introduces a different trust assumption: the VPN provider becomes your new network observer. A local node is one layer in a privacy strategy, not a complete solution by itself.

Leave a comment

Your email address will not be published. Required fields are marked *