Reverse-proxy mirrors

Some sites — including several of the most-cited pages in the Bitcoin Cash ecosystem — return HTTP 503 to Theseus, no matter what user-agent it sends. A short note on why, and how a .bch name gets you through.

Why Theseus 503s on some sites

Cloudflare's Bot Fight Mode (and similar WAF rules) fingerprints the TLS ClientHello — the cipher list, extensions, and JA3/JA4 hash your browser sends before any HTTP header is negotiated. Chromium's TLS stack, which Theseus is built on via Electron, ships with a slightly different fingerprint than desktop Chrome — enough to trigger the bot heuristic. The server replies with a short 503 page and the load fails.

Stripping Electron/… from the user-agent doesn't help: the fingerprint sits below HTTP. Disabling HTTP/2 doesn't help either. From the site's perspective, Theseus is indistinguishable from a scraper.

What a p record does

A BCDN name can carry a p record — a single upstream URL. When Theseus loads a name whose record picker returns p, it doesn't hand the request to Chromium's network stack. It hands it to Node's fetch() from the main process, which uses a different HTTP client (undici) with a completely different TLS fingerprint — one Cloudflare doesn't flag. The response body comes back and gets served under the .bch origin.

The address bar stays on the BNS name; the upstream never sees your IP resolve through Cloudflare's browser-bot rules, only through Theseus's outbound Node fetch. No captcha, no interstitial, no 503.

Trade-offs to know: the p path uses the upstream's own DNS and public certificate authority (unlike ip, which pins to a raw IP + on-chain TLS fingerprint), and Theseus streams the body through its own process — so the upstream sees Theseus's outbound IP, not yours. This is a shared proxy in effect, though only for the one request.

Featured mirrors

These names are registered on the Bitcoin Cash chain with a p record pointing at a Cloudflare-fronted upstream Theseus can't reach directly. Click any to open it in Theseus (or via navigate.st if you don't have the browser installed yet).

No mirrors published yet. The list will fill in as names are minted through Sirius. Check back, or mint one yourself — instructions below.

See a site missing? If a Cloudflare-fronted page you care about is unreachable from Theseus, either mint a p record for it yourself, or open an issue on the Theseus repo and we'll add it to the featured list once it's on chain.

Mint a mirror yourself

Registration costs a few sats of BCH. Theseus 0.3.14+ ships with the Aegis wallet — the wallet the Sirius UI signs against — so this is a couple of clicks once your wallet has a small balance.

1
Open sirius.x in Theseus and search for the label you want. Pick a .bch TLD if the site is BCH-related; other registered TLDs work too. Mint the name.
2
Once minted, open the name's record editor and add:
p: "https://the-original-upstream.example/"
The trailing slash matters — anything in the path is used as a prefix for every request.
3
Sign the record change. Wait one confirmation. The record is live as soon as the next Theseus resolve fetches the beacon.
4
Test: type yourname.bch in Theseus's address bar. If the upstream returns 200, Theseus renders it under your name. Send us the name and we'll add it to the featured list.
Be honest about what a mirror is. The upstream is unchanged — the site operator hasn't consented to being served under your BNS name, and doesn't get paid for any traffic that lands through the mirror. This is a workaround for a reachability problem, not a rehosting. If you'd rather leave the mirror to us, open an issue and we'll consider whether it's canonical enough to include.

The relevant code

For anyone curious about the exact mechanism: