frigate allows you to privately receive bitcoin silent payments.

installation

  • check the latest release of frigate and download it, alongside with signatures.
    $ VERSION="1.5.3"
    $ cd /tmp
    $ wget https://github.com/sparrowwallet/frigate/releases/download/$VERSION/frigate_${VERSION}_arm64.deb
    $ wget https://github.com/sparrowwallet/frigate/releases/download/$VERSION/frigate-$VERSION-manifest.txt
    $ wget https://github.com/sparrowwallet/frigate/releases/download/$VERSION/frigate-$VERSION-manifest.txt.asc
    
  • import craigraw’s key.
    $ curl https://keybase.io/craigraw/pgp_keys.asc | gpg --import
    
  • check the signature.
    $ sha256sum -b frigate_${VERSION}_arm64.deb
    > b690812a1c5212471038918694b6a3ca473631494ce2b75927218b3766b003bd *frigate_1.5.3_arm64.deb
    $ cat frigate-$VERSION-manifest.txt | grep arm64.deb
    > b690812a1c5212471038918694b6a3ca473631494ce2b75927218b3766b003bd *frigate_1.5.3_arm64.deb
    $ gpg --verify frigate-$VERSION-manifest.txt.asc frigate-$VERSION-manifest.txt
    > gpg: Signature made Sat 30 May 2026 10:30:31 AM CEST
    > gpg:                using RSA key D4D0D3202FC06849A257B38DE94618334C674B40
    > gpg: Good signature from "Craig Raw <craig@sparrowwallet.com>" [unknown]
    > gpg: Signature notation: manu=2,2.5+1.12,0,3
    > gpg: WARNING: This key is not certified with a trusted signature!
    > gpg:          There is no indication that the signature belongs to the owner.
    > Primary key fingerprint: D4D0 D320 2FC0 6849 A257  B38D E946 1833 4C67 4B40
    
  • install.
    $ sudo dpkg -i frigate_${VERSION}_arm64.deb
    
  • create the frigate user.
    $ sudo adduser --disabled-password --gecos "" frigate
    $ sudo adduser frigate bitcoin
    
  • create the data directory for the frigate user.
    $ sudo mkdir /data/frigate
    $ sudo chown -R frigate:frigate /data/frigate
    

reconfiguring electrs

we want to have all electrum requests going to frigate first, so we will redirect electrs to another port.

  • open the configruation file.
    $ sudo nano /data/electrs/electrs.conf
    
  • change the electrum_rpc_addr port to 60001.
    # Electrs settings
    electrum_rpc_addr = "127.0.0.1:60001"
    db_dir = "/data/electrs/db"
    
  • restart electrs.
    $ sudo systemctl restart electrs
    

running frigate

  • switch to frigate user.
    $ sudo su - frigate
    
  • create the configuration file.
    $ nano /data/frigate/config.toml
    
# Frigate configuration

[core]
connect = true
server = "http://127.0.0.1:8332"
authType = "COOKIE"            # COOKIE or USERPASS
dataDir = "/data/bitcoin"
# auth = "user:password"         # only needed for USERPASS
zmqSequenceEndpoint = "tcp://127.0.0.1:28336"   # bitcoind -zmqpubsequence endpoint for low-latency mempool ingestion
# rpcRequestTimeoutSeconds = 60                   # per-RPC read timeout (raise on slow/remote bitcoind, lower on fast LAN)
# rpcBatchSize = 100                              # max sub-requests per JSON-RPC array batch (mempool fill)

[index]
# startHeight = 0                # default: 709632 on mainnet (Taproot activation), 0 on testnet
cacheSize = "1M"              # scriptPubKey cache entries (1M, ~400MB RAM)

[scan]
# batchSize = 300000             # rows per GPU dispatch (reduce if scanning hangs on older GPUs)
# computeBackend = "AUTO"        # AUTO, GPU, or CPU
# dbThreads = 4                  # limit DuckDB threads (reduces CPU load when computeBackend = "CPU")
# memoryLimit = "8GB"            # cap DuckDB memory usage (default: 80% of system RAM)
# maxLabels = 10                 # maximum number of labels accepted per silent payments subscription
# maxSubscriptions = 100         # maximum number of silent payments subscriptions per connection
# metricsEnabled = true          # hourly aggregate scan stats log line (default: true)

[server]
# host = "ssl://xyz.com:50002"   # advertised in server.features; use array for multiple. Omit to advertise nothing.
tcp = "tcp://127.0.0.1:50001"    # plaintext listener bind URL; omit (or "") to disable. Default if neither tcp nor ssl is set.
# ssl = "ssl://0.0.0.0:50002"    # SSL listener bind URL; omit to disable
# sslCert = "cert.pem"           # PEM certificate (chain allowed); bare filename resolves under Frigate's home dir, or use an absolute path
# sslKey  = "key.pem"            # PEM-encoded PKCS#8 private key; bare filename resolves under Frigate's home dir, or use an absolute path
backendElectrumServer = "tcp://localhost:60001"   # backend must listen on a port distinct from Frigate's tcp/ssl listeners above
  • run frigate.
    $ /opt/frigate/bin/frigate -d /data/frigate
    
  • check if it works.
    > 2026-08-10 13:12:10,516 INFO Using configured Frigate home folder of /data/frigate
    > 2026-08-10 13:12:10,548 INFO Starting Frigate v1.5.3 on mainnet
    > 2026-08-10 13:12:10,549 INFO Using home directory /data/frigate
    > 2026-08-10 13:12:12,313 INFO Using CPU backend for scanning (no GPU detected)
    > 2026-08-10 13:12:12,571 INFO Indexing 252237 blocks (709632 to 961868)...
    > 2026-08-10 13:12:42,715 INFO Indexing progress: 95 / 252237 blocks (0.0%, height 709726)
    > 2026-08-10 13:13:13,004 INFO Indexing progress: 187 / 252237 blocks (0.1%, height 709818)
    > ^C2026-08-10 13:13:24,236 INFO Frigate shutting down...
    
  • exit the frigate user session.

systemd daemon

  • create the configuration.
    $ sudo nano /etc/systemd/system/frigate.service
    
[Unit]
Description=Frigate Electrum Server
After=network-online.target bitcoind.service
Wants=network-online.target

[Service]
Type=simple
User=frigate
StateDirectory=frigate
ExecStart=/opt/frigate/bin/frigate -d /data/frigate
Restart=on-failure
RestartSec=5

# Directory creation and permissions
####################################
User=frigate

# /run/frigate
RuntimeDirectory=frigate
RuntimeDirectoryMode=0710

# Hardening measures
####################
# Provide a private /tmp and /var/tmp.
PrivateTmp=true

# Use a new /dev namespace only populated with API pseudo devices
# such as /dev/null, /dev/zero and /dev/random.
PrivateDevices=true

[Install]
WantedBy=multi-user.target
  • enable and start frigate service.
    $ sudo systemctl enable frigate
    $ sudo systemctl start frigate
    
  • check the logs.
    $ sudo journalctl -f -u frigate
    
  • wait for the blockchain to be indexed. it should take around two to three days.