Your node
Two steps, in this order: open the tunnel, then tell your wallet to query your node instead of public servers. Every screen is shown, in the order you will see it, for AmneziaWG, then for Electrum, Sparrow, BlueWallet and Nunchuk.
A wallet fresh out of the box asks strangers' public servers for its balance, handing them the list of your addresses to do so. The step described here replaces those strangers with your node, the one included in your NODECOVE subscription. Allow a quarter of an hour the first time; there is nothing to redo afterwards.
What you will enter
Every wallet on this page asks for the same thing: a hostname, a port, and whether the connection is encrypted. Some want all three on a single line, others in separate fields. Here are the two forms; it's the only thing to remember from this page.
On a single line: Electrum, desktop and Android
The final :s announces the encrypted connection. A :t would mean "unencrypted": that is not what we serve.
electrum.nodecove.net:50002:s
In separate fields: Sparrow, BlueWallet, Nunchuk
Host on one side, port on the other, and the SSL or TLS switch turned on. Nunchuk has only one field and does not expect the suffix: host and port are enough.
electrum.nodecove.net
The tunnel first, always
Our node does not answer from the open internet: it only answers inside the tunnel. A wallet that is configured correctly but whose tunnel is closed will therefore stay hopelessly "not connected", with nothing actually misconfigured. This is intentional: no one can probe this node, or count who connects to it.
What your node changes, and what it doesn't
It changes who learns your addresses: your node already knows them, since it's yours, and public servers will no longer see them. It does not change what is written into the chain: a transaction remains public, and where your bitcoins came from stays visible to anyone tracing the trail. The What we see page states exactly where this limit stops.
Part one · the tunnel
One application, one file, one switch. AmneziaWG takes the .conf file we give you exactly as it is, and the obfuscation lines it contains are read without anything to type. It runs on iPhone, Android, Mac and Windows; on Linux, the same protocol comes as command-line tools. An ordinary WireGuard client will not do: it ignores those lines, so the tunnel opens where nothing is filtered and stays shut everywhere else.
Download AmneziaWG Other systems
Install AmneziaWG from the App Store.
Save the .conf file attached to your delivery email, or downloaded from your account: it lands in Downloads.
In the Files application, press and hold the file until the menu appears. A simple tap only opens a preview.
Share, then AmneziaWG in the list of applications. If it is not there, scroll, or tap More.
Tap the switch to the right of the tunnel's name. iOS asks for permission to add a VPN configuration: Allow. The switch turns green.
Install AmneziaWG from Google Play.
In the application, tap the ➕ icon at the bottom right, then Import from file or archive.
Choose the .conf file, usually in Downloads. If that folder does not open by itself, the menu icon at the top left leads to it; otherwise Recents, or a search on the file's name.
Tap the switch to the right of the tunnel's name. Connected appears underneath.
Another VPN application in the way
Android grants the VPN permission to one application at a time. If another VPN is installed, turn it off before importing, and in Settings → Network & Internet → VPN, on that other application's gear icon, turn off Always-on VPN and Block connections without VPN. The exact path varies by phone brand.
Install AmneziaWG from the Mac App Store: publisher Privacy Technologies OU. The release published on August 24, 2026 carries version number 3.1.4.
Open the application. The window is called Manage AmneziaWG Tunnels; it is empty the first time.
Click Import tunnel(s) from file, or go through File → Import Tunnel(s) from File…, and choose the .conf file downloaded from your account, it is in Downloads. Then Import.
macOS asks for permission to add a VPN configuration: answer Allow. Without it, the tunnel will not open.
Select the tunnel and click Activate: the status goes through Activating… then shows Active. To close it, Deactivate, or Tunnel → Toggle Status (⌘T).
A permission to grant, once. If the tunnel refuses to open, go to System Settings → Privacy & Security, General section, and click Allow for AmneziaWG.
The file already carries the obfuscation. The Jc, Jmin, Jmax, S1, S2 and H1 to H4 lines in our configuration are read by the application: there is nothing to enter by hand. They must, however, match the client's protocol version, our files are written for AmneziaWG 3.1.
Download the .msi file matching your machine from the published releases of the Windows client: amneziawg-amd64 for a common PC, arm64 or x86 depending on your case. The release from August 21, 2026 carries version number 3.1.0.
Run the file and answer Yes to Windows's prompt: the installation requires administrator rights.
Open AmneziaWG, then Add Tunnel → Import tunnel(s) from file, choose the .conf file and click Open.
Click Activate. Afterwards, the icon near the clock offers Manage tunnels… to reopen the window.
On Windows, this application and no other. It is the only path supported by the publisher for our configurations, and an ordinary WireGuard client would leave the obfuscation lines unread.
There is no graphical application. You install the amneziawg kernel module and the amneziawg-tools utilities, place our file at /etc/amnezia/amneziawg/nodecove.conf, then run awg-quick up nodecove as administrator, and awg-quick down nodecove to close it.
Where to find these applications
Mac: AmneziaWG on the App Store. Windows: the .msi files from the latest published release of the Windows client. Linux: the kernel module and the command-line tools. The publisher's instructions are published in its documentation.
Part two · wallets
Electrum accepts the full address on a single line, and can limit itself to a single server, it is the most direct wallet to connect to your own node.
Download Electrum Other systems
electrum.nodecove.net:50002:s.
The point not to miss. In automatic mode, Electrum stays connected to about ten public servers in addition to yours: they do not learn your addresses, but they see that a client is querying the chain. Connect only to a single server mode removes this remainder. On the command line, this is written as: electrum --oneserver --server electrum.nodecove.net:50002:s
The certificate. Electrum only talks to servers over an encrypted connection and accepts each server's own certificate: on first connection, it remembers ours and will warn you if it ever changes. There is nothing to check.
The same wallet, on a phone
The Android application has the same mechanics, in a single screen.
electrum.nodecove.net:50002:s.
On a phone, the tunnel and the wallet coexist: the AmneziaWG tunnel must stay active while Electrum synchronises, otherwise the screen will stay stuck on an old block height.
For hardware wallets
Sparrow asks the question right on its first screen: public server, Bitcoin Core node, or private Electrum server. It is the third answer that concerns us.
Download Sparrow Other systems
electrum.nodecove.net · port field → 50002.
Sparrow expects separate fields: do not write :50002:s after the hostname, the connection would fail. Its own documentation puts it plainly: only connect to a server you trust, which is precisely the point of having your own.
On iPhone and on Android
BlueWallet chooses at random, by default, from a pool of public servers. Designating a preferred server puts an end to this lottery.
Download Blue Wallet Other systems
First: put Blue Wallet in your language
Blue Wallet often opens in English, even on a phone set to another language. Changing it takes thirty seconds.
Bull, for its part, follows the phone's language on its own.
Receiving bitcoin: copy your address
In your wallet, tap Receive, then tap the address under the QR code: Copied! appears, it is copied. Paste it into the app that is sending you the bitcoin.
Screenshots in English: in your app, the same buttons carry the names given in the text.
Receiving in Bull: copy your address
Sending from Blue Wallet
Paying from Blue Wallet: copy the address, then the amount
Is the payment page open on another screen? Tap Scan in Blue Wallet and aim at the QR code: the address and the amount are filled in at once.
electrum.nodecove.net.50002.
electrum.nodecove.net in the first field, 50002 in the second, Use SSL enabled, then Save.
Screenshots taken in Blue Wallet on iPhone. The green frame marks the row to tap: it is not part of the app.
The application warns you that designating a preferred server disables the connection to a randomly suggested server: that is exactly what you are after. Reset to default undoes the setting if you want to go back.
On a phone, including multi-key setups
Nunchuk keeps a list of servers and asks to restart after the change.
electrum.nodecove.net:50002 under Mainnet server.
Nunchuk does not expect a protocol suffix: enter the host and the port, without :s. Leave the Testnet server and Signet server fields as they are; they do not concern the bitcoins you hold.
On a phone, bitcoin only
Bull Bitcoin's wallet keeps your keys on the phone and only accepts bitcoins. It applies the server change immediately, with no restart needed.
electrum.nodecove.net:50002. The host and the number joined by a colon, nothing else: neither https:// nor a :s suffix, which this version does not expect.
electrum.nodecove.net:50002, Enable SSL enabled, then Add Server.
Screenshots taken in Bull Wallet on iPhone. The green frame marks the row to tap: it is not part of the app.
As soon as a custom server exists, Bull stops querying its own: there is no silent fallback to wes.bullbitcoin.com. The setting applies to on-chain bitcoins and to Liquid; it does not concern the application's exchange service, which follows its own path.
Bull only exists on iPhone and Android: there is no computer version. The advanced options: Stop Gap, Timeout, Retry Count, Validate Domain: do not need to be touched.
Where to find the application
The wallet's website links to the App Store and the Play Store; the code is published by Satoshi Portal. The settings path is described in their guide.
The four common issues
· The wallet stays "not connected"
Nine times out of ten, the tunnel is closed. Open AmneziaWG, check that the tunnel is active, then restart the wallet's synchronisation. Our node only answers inside the tunnel.
· The tunnel refuses to open on Android
Another VPN application is holding on. System settings, VPN section: turn off Always-on VPN and Block connections without VPN for those other applications.
· The setting was saved but nothing changes
BlueWallet and Nunchuk only apply the server change after the application restarts. Close it completely, then reopen it.
· Electrum synchronises, but not only with you
The connection mode stayed on automatic. Go back into Tools → Network, Server tab, and choose Connect only to a single server.
Versions used for these screens
AmneziaWG 3.1 on Mac, 3.1.0 on Windows, Electrum 4.8.1, Sparrow 2.5.4, BlueWallet 8.0.2, and the Nunchuk documentation from February 2022. The Sparrow screens are the official screenshots from the project; the Electrum, BlueWallet and Nunchuk ones are reconstructions faithful to the published wording, for lack of official screenshots. An updated piece of software may move a button: the bold labels remain the safest landmark.
Sources: Amnezia documentation · Electrum documentation · Sparrow quick-start guide · BlueWallet wiki · Nunchuk network settings.
And other wallets
Specter, the Blockstream app for a Jade, or any wallet that accepts an Electrum server are set up the same way: look for "Electrum server" in its network settings, enter the host, port 50002, and turn on the encrypted connection. Your customer account reminds you of these three values at any time.