BB
← All projectsBitBox

BitBox02 firmware

Firmware and bootloader for BitBox02 signing devices.

BitcoinHardware walletsNormal
Repository coverage

787 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

239security candidates161second-pass queue727AI analyses
72commits · 30 days
144commits · 60 days
316commits · 180 days
697commits · 365 days
Backfill bands
Aug 5 → Feb 6335 seen28 candidatesComplete
Feb 6 → Jun 6265 seen19 candidatesComplete
Jun 6 → Jul 619 seen5 candidatesComplete
Jul 6 → Aug 526 seen3 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

58/100 average clarity
69Strong · 80–100
325Adequate · 60–79
305Thin · 40–59
88Opaque · 0–39
26security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Marko Bencun452133424357
benma's agent11240106164
Niklas Dusenlund15543134057
cedwies12512063
Tomas Vrba10410071
Cedric Wiese12312049
Yasser Aziza333070
Jad14210060
Sebastian Sutter222050
thisconnect212072
benma212074
Niklas111035
Analysis record

Published AI watches

Last scanned 50 minutes ago

Informational 15 AI analysisMessage 58 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge commit 'refs/pull/2123/head' of https://github.com/BitBoxSwiss/bitbox02-firmware

This commit only adds two digital signature files for an already-released firmware version (v9.25.0). These are third-party reproducible-build assertions by a user named 'yaziza', not changes to the firmware source code. There is no code c…

b8bbbb64by Marko Bencun+0−02 files
No security note in commit
Informational 0 AI analysisMessage 58 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge commit 'refs/pull/2124/head' of https://github.com/BitBoxSwiss/bitbox02-firmware

This commit only adds two digital signature files for an already-released firmware version (v9.27.1). These are release attestation signatures from a contributor named 'yaziza'. There is no code change, no firmware change, and nothing in t…

392ac2ffby Marko Bencun+0−02 files
No security note in commit
Informational 12 AI analysisMessage 45 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge branch 'nickez/bb02-finalize-elf'

This commit is a build-system refactor that unifies how firmware image headers are generated for the BitBox02 and BitBox03. It replaces a device-specific Python script and a C header placeholder with a shared Python tool and JSON manifests…

New input validation in image_header.py for magic, flags, product_id, monotonic_version, marketing_version, image length, and zeroed signature slotsRust parsing now validates slot length, header length alignment, and image length bounds before deriving code lengthRemoval of prepare-stage1-unsigned path reduces attack surface in build tooling
810d3e87by Niklas Dusenlund+573−14413 files
No security note in commit
Informational 12 AI analysisMessage 78 · Adequate
BB BitBoxBitBox02 firmware BitcoinHardware wallets

bootloader: use shared stage1 header tool

This commit is a build-system refactoring for the BitBox02 bootloader. It replaces a C-language placeholder for the bootloader's stage1 header with a Python tool that generates the same header from JSON manifests during the build. The old …

5b14742fby Niklas Dusenlund+52−1105 files
No security note in commit
Low 27 AI analysisMessage 83 · Strong
BB BitBoxBitBox02 firmware BitcoinHardware wallets

scripts: unify the BitBox image format

This commit refactors the firmware image header format used by BitBox hardware wallets so that BitBox02 and BitBox03 share a single 1024-byte layout. It adds new metadata fields (product ID, version numbers, signature slots) and switches t…

Changed binary image header format and parserAdded checked integer conversions for 64-bit image lengthAdded bounds checks on slot length, header length, and image length in Rust loader
9403e6feby Niklas Dusenlund+524−376 files
No security note in commit
Informational 15 AI analysisMessage 68 · Adequate
BB BitBoxBitBox02 firmware BitcoinHardware wallets

scripts: rename image header tool

This commit simply renames a build script from bitbox03_image_header.py to image_header.py and updates all references in the Makefile and Rust build files. The script's contents and behavior are unchanged. There is no security issue here.

29d6720aby Niklas Dusenlund+7−75 files
No security note in commit
Informational 15 AI analysisMessage 70 · Adequate
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Firmware v9.27.1 verification (yaziza)

This commit adds two digital signature files for BitBox02 firmware version 9.27.1. These signatures are a third-party reproducible-build verification (called an 'assertion') created by an independent contributor named yaziza. The commit do…

6d2e6955by Yasser Aziza+0−02 files
No security note in commit
Informational 15 AI analysisMessage 70 · Adequate
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Firmware v9.25.0 verification

This commit adds two digital signature files to the repository. They are third-party reproducible-build attestations (assertions) for the already-released BitBox02 firmware version 9.25.0. The commit does not change any firmware source cod…

b454a627by Yasser Aziza+0−02 files
No security note in commit
Low 34 AI analysisMessage 50 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge remote-tracking branch 'agent/benma-agent/hww-start-session'

This commit adds a new 'session reset' command to the BitBox02 hardware wallet's USB protocol. It lets the host computer cleanly reset the device connection if a previous operation was interrupted, instead of leaving the device stuck mid-t…

New USB control command added to host-wallet protocolReset path cancels async task, resets Noise state, unlocks USB processing, and clears output queueU2F UI ownership check prevents reset from interrupting an active U2F workflow
04302490by Marko Bencun+485−1713 files
No security note in commit
Informational 15 AI analysisMessage 78 · Adequate
BB BitBoxBitBox02 firmware BitcoinHardware wallets

py: make session reset an API setup helper

This is a routine Python code refactor. It moves an existing 'reset session' command from one internal class to another and adds a version check so older firmware simply skips it. There is no security bug being fixed here; it is purely org…

50a9e76aby benma's agent+28−163 files
No security note in commit
Moderate 62 AI analysisMessage 78 · Adequate
BB BitBoxBitBox02 firmware BitcoinHardware wallets

hww: reset sessions on host reconnect

This commit fixes a bug in the BitBox02 hardware wallet where unplugging the USB cable at the wrong moment could leave a half-finished operation running. If the device stayed powered and a new host reconnected, the new host's first message…

Fixes cross-session state confusion on USB reconnectAdds explicit session reset command to cancel stale async workflowsResets Noise cryptographic session to prevent old-key encrypted responses
6679936fby benma's agent+473−1712 files
Vendor flagged security relevance
Informational 17 AI analysisMessage 58 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge commit 'refs/pull/2073/head' of https://github.com/BitBoxSwiss/bitbox02-firmware

This commit adds a new recovery-word entry screen for the upcoming BitBox03 hardware wallet. It is a large feature patch: it introduces a dedicated BIP39 wordlist keyboard, a new recovery-words review screen, and changes how the device han…

New UI workflow distinguishes 'back' from 'cancel' during seed restoration, reducing accidental aborts.Cancel actions still require an explicit confirmation prompt before the restore is abandoned.Wordlist keyboard disables keys that cannot lead to a valid BIP39 word, preventing invalid-word compositions at the widget level.
6b04e006by Marko Bencun+7010−24621 files
No security note in commit
Low 47 AI analysisMessage 50 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge remote-tracking branch 'agent/benma-agent/show-erc20-contract'

This commit improves the BitBox02 hardware wallet's Ethereum token-approval screen. When a user signs an ERC20 token transfer, the device now also shows the token's smart-contract address if the token symbol is ambiguous (the same ticker, …

UI hardening: adds contract-address confirmation for ERC20 tokens with ambiguous or unknown symbolsRegistry validation: rejects payment requests for tokens not present in the firmware's ERC20 registryBuild-time ambiguity detection: generates a sorted list of units shared by multiple contracts
410df562by Marko Bencun+203−123 files
No security note in commit
Low 26 AI analysisMessage 50 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge remote-tracking branch 'agent/benma-agent/bootloader-descriptor-compat'

This commit relaxes a version check in the BitBox02 bootloader upgrade code. Previously, the firmware installer required that a stage0 bootloader descriptor's version exactly matched the currently expected image version. Now it accepts des…

Strict version equality check removed from bootloader descriptor parsingChange located in bootloader upgrade / firmware installer verification pathNo bounds, length, or pointer validation changes observed
6dccfd24by Marko Bencun+19−72 files
No security note in commit
Moderate 53 AI analysisMessage 45 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge branch 'nickez/bb02-utf8-safe'

This commit hardens the BitBox02 firmware so it stops trusting that incoming text strings are valid UTF-8 or plain ASCII. It replaces risky C string copies with length-checked, UTF-8-aware helpers, rejects non-ASCII characters at UI bounda…

Replaced snprintf-based string copies with length-bounded UTF-8-aware copiesAdded explicit length parameter to memory_set_device_name and reject embedded/invalid nullsAdded printable-ASCII enforcement at Rust UI boundary before C rendering
0bbdf6f0by Niklas Dusenlund+338−9625 files
No security note in commit
Low 41 AI analysisMessage 28 · Opaque
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge branch 'benma/ub'

This commit fixes a coding guideline violation in the BitBox02 factory setup code. A 32-byte buffer that receives output from a Rust function was not initialized to zeroes before use. The accompanying documentation now explicitly requires …

Uninitialized stack buffer used as output buffer for Rust/C FFI callDefensive zero-initialization added to prevent use of stale stack data on error or partial write pathsProject coding guidelines updated to mandate zero-initialization for rust_util_bytes_mut buffers
8a6fd97bby Marko Bencun+3−12 files
No security note in commit
Low 35 AI analysisMessage 68 · Adequate
BB BitBoxBitBox02 firmware BitcoinHardware wallets

oled: hold display in reset during startup

This commit fixes a display behavior issue during startup of the BitBox02 hardware wallet. Previously, when the device turned on, the screen's reset pin was left in a state that could allow leftover images or text from an earlier session t…

Information disclosure via residual display content during bootOLED reset pin sequencing hardeningDefense against stale/misleading UI state before verified firmware initializes display
cdb27835by Niklas Dusenlund+2−11 file
Vendor flagged security relevance
Informational 18 AI analysisMessage 50 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge remote-tracking branch 'agent/benma-agent/factorysetup-trim-unused'

This commit trims the BitBox02 factory-setup firmware image by switching stored root attestation public keys from 65-byte uncompressed to 33-byte compressed secp256k1 keys, and by using a smaller static secp256k1 verification context inste…

Change in trusted public-key table format and derivation logicSwitch to static/no-precomp secp256k1 verification contextAddition of secp256k1 self-test at boot
554a0558by Marko Bencun+457−5647 files
No security note in commit
Low 37 AI analysisMessage 50 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge remote-tracking branch 'agent/benma-agent/validate-py-antiklepto-signatures'

This commit adds extra safety checks in the BitBox02 Python library for ECDSA signatures used in Bitcoin and Ethereum signing. It now validates that signatures have the correct length, use valid numbers, and use the safer low-S form. It al…

Defensive validation added for ECDSA signature format and low-S encodingRecovery ID range validation added for recoverable signaturesAnti-Klepto verification now rejects malformed/malleable signatures before nonce verification
0d1a7997by Marko Bencun+152−65 files
Vendor flagged security relevance
Informational 19 AI analysisMessage 50 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge remote-tracking branch 'agent/benma-agent/scroll-payment-request-memo-name'

This commit tweaks how the BitBox02 hardware wallet displays a payment-request memo on screen. It changes the label from 'Memo from\n\nMerchant' to 'Memo from: Merchant' and makes the screen scrollable so long merchant names don't get cut …

No security-relevant signal in commit message or diffUI/UX change only: text formatting and scrollabilityNo memory-safety, cryptographic, or authorization changes observed
be375664by Marko Bencun+115−66 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Lower-prioritycardano: harden Cardano host xpub derivation checksby Jad · bfc8bfdd · Mar 10, 2026 · 3 filesMessage 73 · AdequateModerate 58Details
Commit message · Jad

cardano: harden Cardano host xpub derivation checks

Cardano host-facing xpub usage now follows the same bitflip-mitigation
pattern already used for critical Bitcoin xpub operations.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
defensive validation
AI analysis · Moderate 58/100

This commit hardens how the BitBox02 firmware derives and exposes Cardano public keys (xpubs) by computing them twice and comparing the results. This matches a safety pattern already used for Bitcoin, meant to catch rare hardware errors or malicious bit flips that could silently produce a wrong xpub. A wrong xpub could lead a wallet app to generate addresses the user does not actually control, so the change is a defensive security improvement.

Lower-priorityAGENTS: add review guidelinesby Marko Bencun · 3b0b85d5 · Mar 9, 2026 · 1 fileMessage 50 · ThinInformational 15Details
Commit message · Marko Bencun

AGENTS: add review guidelines

Document review guidance for removed function calls.

50/100 · ThinMessage clarity
✓ Descriptive subject✓ Provides an explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit only adds two sentences of documentation to the project's AGENTS.md file, giving reviewers guidance on what to check when a function call is removed in a code change. It does not modify any firmware code, cryptographic logic, build scripts, tests, or configuration. There is no security issue in this change.

Lower-priorityda14531.c: fix name len in memcpyby Marko Bencun · 75629365 · Mar 7, 2026 · 1 fileMessage 80 · StrongLow 35Details
Commit message · Marko Bencun

da14531.c: fix name len in memcpy

The BLE name was always <63 bytes due to validation in the
SetDeviceName API call, but since the function itself truncates to the
payload size when copying to the payload stack array, it should also
do so when passing its length to da14531_protocol_format.

80/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
AI analysis · Low 35/100

This commit fixes a small but real bug in how the BitBox02 hardware wallet tells its Bluetooth chip what name to broadcast. The code that copies the device name into a fixed-size buffer correctly limited the copy to 63 bytes, but then accidentally reported the original, possibly longer length to the next processing step. That mismatch could make the Bluetooth formatting function read past the end of the 64-byte buffer, leaking nearby memory or crashing the device. The fix makes the reported length match the actual copied length.

AI review queueddelay: remove unused delay_is_elapsedby Marko Bencun · d7eba581 · Mar 7, 2026 · 3 filesMessage 35 · OpaqueInformational 15Details
Commit message · Marko Bencun

delay: remove unused delay_is_elapsed

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit simply removes a software function named delay_is_elapsed that is no longer used anywhere in the code. It is a routine cleanup change with no apparent security relevance.

Lower-prioritybitbox02/delay: call delay_cancel after initby Marko Bencun · b07b98ba · Mar 7, 2026 · 1 fileMessage 72 · AdequateLow 33Details
Commit message · Marko Bencun

bitbox02/delay: call delay_cancel after init

Otherwise after 10 uses of delay_for().await, there is a `Too many
concurrent delays` abort.

72/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Explains rationale or failure mode
AI analysis · Low 33/100

This commit fixes a bug in the BitBox02 hardware wallet's Rust delay system. Previously, calling delay_for() 10 times without cleanup caused the device to abort with 'Too many concurrent delays'. The fix ensures each delay is cancelled automatically when finished, preventing the device from crashing. It is a reliability fix rather than a clear security vulnerability, though any device crash could theoretically affect availability or user workflow.

Lower-priorityBuild: move host hardware fakes into bitbox02-sysby Cedric Wiese · 191a5982 · Mar 5, 2026 · 8 filesMessage 57 · ThinInformational 13Details
Commit message · Cedric Wiese

Build: move host hardware fakes into bitbox02-sys

also stabilize fatfs diskio linking

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
AI analysis · Informational 13/100

This is a build-system cleanup, not a security fix. It moves test-only fake hardware code into a lower-level Rust crate and adds a linker trick so the fake disk storage implementation is not accidentally left out when building the desktop simulator. There is no change to how real devices work and no reported vulnerability.

Lower-priorityworkflow: use std::println! over C printf in C simulatorby Marko Bencun · 24b9cbae · Mar 3, 2026 · 1 fileMessage 65 · AdequateInformational 15Details
Commit message · Marko Bencun

workflow: use std::println! over C printf in C simulator

No need to depend on bitbox02/C for this.

65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
AI analysis · Informational 15/100

This commit is a small code cleanup in a test-only file for the C simulator. It replaces calls to a C-style print function with Rust's standard println macro. There is no security relevance: no real secrets are handled, no production code is changed, and no vulnerability is introduced or fixed.

Lower-priorityhal: add print_screen to Hal Uiby Marko Bencun · 0cedfa0d · Mar 3, 2026 · 9 filesMessage 68 · AdequateInformational 18Details
Commit message · Marko Bencun

hal: add print_screen to Hal Ui

The `print_debug_internal` function is removed from bitbox02_rust as
it depends on bitbox02, but one can use the print_screen HAL fn
instead.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 18/100

This commit is a routine internal code cleanup in the BitBox02 firmware. It moves a debug/error screen-printing function into a hardware-abstraction layer (HAL) so different parts of the code can use it without directly depending on low-level screen drivers. The visible behavior—showing error messages on the device screen—stays the same. There is no indication this fixes a security vulnerability or introduces a new attack path.

Lower-priorityrust-c: rename alloc module to c_allocby Marko Bencun · d4a29363 · Mar 3, 2026 · 3 filesMessage 68 · AdequateInformational 15Details
Commit message · Marko Bencun

rust-c: rename alloc module to c_alloc

Rename the internal allocator module in bitbox02-rust-c from `alloc`
to `c_alloc`.

This avoids a name clash with the Rust `alloc` crate, whichwill be
imported explicitly in a follow-up commit.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This commit simply renames an internal Rust module from `alloc` to `c_alloc` to avoid a naming conflict with Rust's standard `alloc` crate in a future change. The actual allocator code is identical; only file paths and a module reference are updated. There is no security-relevant change.

AI review queuedhal: add resetby Marko Bencun · d85daea2 · Mar 2, 2026 · 4 filesMessage 28 · OpaqueInformational 18Details
Commit message · Marko Bencun

hal: add reset

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 18/100

This commit is a small internal cleanup: it adds a new 'reset' method to the user-interface layer and makes the start of a new secure session call that method instead of calling a lower-level screen-clearing function directly. The behavior is essentially the same as before—clearing leftover screens when a new connection begins—so there is no new security problem. It is a refactoring change, not a fix for a known vulnerability.

AI review queuedUi: Display address in groups of 4 charactersby Cedric Wiese · a871abc7 · Mar 2, 2026 · 12 filesMessage 45 · ThinInformational 15Details
Commit message · Cedric Wiese

Ui: Display address in groups of 4 characters

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only changes how wallet addresses are shown on the BitBox02 screen. It inserts spaces every four characters (for example, a Bitcoin address becomes "bc1q k5f9 em9q ..." instead of one long string). There is no code that changes security logic, cryptography, or how transactions are approved. It is a user-experience improvement to make long addresses easier to read and compare.

Security candidatereplace asf4 C ringbuffer with Rust ByteQueueby Marko Bencun · 4c69f5c5 · Mar 2, 2026 · 26 filesMessage 45 · ThinLow 38Details
Commit message · Marko Bencun

replace asf4 C ringbuffer with Rust ByteQueue

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
boot or update pathparser or protocol path
AI analysis · Low 38/100

This commit swaps out an old C ringbuffer for a new Rust-based byte queue used to hold data sent to the Bluetooth chip. The change touches many files but is mostly a rewrite/refactor. It removes several explicit 'will it fit?' size checks before adding data to the queue, and it changes how callers pass the queue around. The Rust ByteQueue implementation itself is not shown in the diff, so we cannot verify whether it safely handles overflow, memory allocation failures, or concurrent access. The change is therefore a security-relevant refactor with some risk, but no proven vulnerability is visible in the supplied commit.

Lower-priorityadd bitbox-bytequeue workspace crateby Marko Bencun · ad7f8c9b · Mar 2, 2026 · 9 filesMessage 80 · StrongInformational 12Details
Commit message · Marko Bencun

add bitbox-bytequeue workspace crate

Trivial wrapper around `VecDeque`, with methods and a C API matching the
asf4 utils_ringbuffer.h interface shape. With a similar API, we can replace
all uses of it easily.

The old C ringbuffer was fixed-size and not heap allocated. This queue uses
`VecDeque` and panics once we go above the intended fixed size to avoid
filling RAM in case of bugs.

80/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
AI analysis · Informational 12/100

This commit adds a brand-new Rust helper crate called bitbox-bytequeue. It is a small wrapper around Rust's standard growable queue type (VecDeque) that exposes a C-compatible API matching an older fixed-size C ringbuffer. The code is purely additive and does not change any existing security-critical logic. It includes overflow protection by deliberately crashing (panicking) if too many bytes are queued, which is intended to prevent memory exhaustion bugs.

Lower-prioritybitbox02-sys/build.rs: remove duplicate da14531_power_downby Marko Bencun · 46fa14bc · Mar 2, 2026 · 1 fileMessage 50 · ThinInformational 15Details
Commit message · Marko Bencun

bitbox02-sys/build.rs: remove duplicate da14531_power_down

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100

This commit removes a duplicate function name from a Rust build script list. It is a harmless cleanup change with no security relevance.

AI review queuedhal: add communication_timeout_resetby Marko Bencun · eae607ad · Mar 2, 2026 · 5 filesMessage 35 · OpaqueInformational 17Details
Commit message · Marko Bencun

hal: add communication_timeout_reset

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 17/100

This commit refactors how the BitBox02 hardware wallet resets its USB communication watchdog during long-running operations. It introduces a new method in the hardware abstraction layer so Rust code can reset the timeout without directly calling a lower-level USB module. The change itself is a structural cleanup; it does not appear to fix or introduce a security vulnerability, but it touches code that prevents tasks from being cancelled while handling sensitive operations like seed encryption and device reset.

AI review queuedhal/ui: add empty_create to Ui Halby Marko Bencun · 274acabe · Mar 2, 2026 · 5 filesMessage 45 · ThinInformational 19Details
Commit message · Marko Bencun

hal/ui: add empty_create to Ui Hal

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit is a small internal code cleanup in the BitBox02 hardware wallet firmware. It moves the creation of an empty on-screen placeholder component into a common hardware-abstraction layer (HAL) so that both real device code and automated test code use the same interface. There is no direct security fix here; it is a refactoring that makes the code easier to test and maintain.

Lower-priorityutil/bytes: document that NULL is allowed in rust_util_bytesby Marko Bencun · 471b82fa · Feb 28, 2026 · 1 fileMessage 65 · AdequateInformational 15Details
Commit message · Marko Bencun

util/bytes: document that NULL is allowed in rust_util_bytes

When length is 0. The as_ref/as_mut functions already explicitly
handle this.

65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
AI analysis · Informational 15/100

This commit only updates documentation comments and adds unit tests to clarify that a NULL pointer is acceptable when the length is zero. No code behavior was changed, so there is no security issue.

Security candidateAdd coin purchase memo supportby cedwies · 10746100 · Feb 26, 2026 · 8 filesMessage 45 · ThinLow 27Details
Commit message · cedwies

Add coin purchase memo support

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Low 27/100

This commit adds a new 'coin purchase memo' feature to BitBox02 payment requests. It lets a payment request include details about a separate coin purchase (e.g., '0.25 ETH to address 0x...') and verifies that the listed Ethereum address really belongs to the wallet by deriving it from a provided keypath. The change is mostly a feature addition, but it introduces cross-currency validation logic and a TODO noting that the user-interface confirmation for this new memo type is not yet implemented.

Lower-priorityspi: prefix MEMORY_SPI_BLE_FIRMWARE_(1|2)_ADDR with BITBOX02_by Marko Bencun · c39028bf · Feb 25, 2026 · 4 filesMessage 65 · AdequateInformational 15Details
Commit message · Marko Bencun

spi: prefix MEMORY_SPI_BLE_FIRMWARE_(1|2)_ADDR with BITBOX02_

Avoid any confusion that these should be used outside of BitBox02.

65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
AI analysis · Informational 15/100

This commit simply renames internal constants so they start with BITBOX02_. It does not change any values, memory addresses, or program behavior. The change is purely cosmetic/clarifying to avoid confusion when these constants are used in shared code.

Lower-prioritybluetooth: add upgrade unit testsby Marko Bencun · 1a58c01b · Feb 25, 2026 · 2 filesMessage 55 · ThinInformational 15Details
Commit message · Marko Bencun

bluetooth: add upgrade unit tests

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
AI analysis · Informational 15/100

This commit only adds unit tests for the Bluetooth firmware upgrade logic and improves the test-only mock memory implementation so it actually records firmware chunks. There are no changes to production code, no bug fixes, and no security-relevant behavior changes.

Lower-prioritymemory_spi: move SPI memory constants to Rustby Marko Bencun · 46b822b8 · Feb 25, 2026 · 8 filesMessage 80 · StrongInformational 15Details
Commit message · Marko Bencun

memory_spi: move SPI memory constants to Rust

bitbox_hal has the one needed for bitbox02-rust and all HAL impls to
function.

bitbox02-rust-c defines the constants needed by C. We can't keep part
in C and part in Rust because it there would be circular deps (C
headers can't include "rust/rust.h").

80/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
AI analysis · Informational 15/100

This commit is a routine code reorganization: it moves constants that describe where Bluetooth firmware is stored in SPI memory from C header files into Rust source files. The values themselves (32 KB max firmware size, two slots at addresses 0x00 and 0x8000, 4096-byte erase sectors) are unchanged. The change adds compile-time checks to ensure the Rust and C definitions stay consistent. There is no security bug being fixed here.

Lower-priorityhal: route BLE FW flashing through Memory HALby Marko Bencun · 9fd3ceea · Feb 25, 2026 · 4 filesMessage 68 · AdequateInformational 12Details
Commit message · Marko Bencun

hal: route BLE FW flashing through Memory HAL

Add BleFirmwareSlot, BLE_FW_FLASH_CHUNK_SIZE, and
ble_firmware_flash_chunk() to the Memory trait as higher level
concepts.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 12/100

This commit is a software architecture refactor: it moves the Bluetooth firmware flashing logic behind a higher-level 'Memory HAL' interface. It does not change the actual security behavior of the firmware upgrade process; it only reorganizes the code so that the same operations go through a trait method instead of being called directly. There is no indication this fixes a vulnerability or introduces a new one.

Lower-priorityhal: add get_active_ble_firmware_version to Memoryby Marko Bencun · 04f212e0 · Feb 25, 2026 · 4 filesMessage 50 · ThinInformational 15Details
Commit message · Marko Bencun

hal: add get_active_ble_firmware_version to Memory

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100

This commit is a small internal code cleanup. It moves the way the device reads its Bluetooth firmware version from a direct hardware call into a shared memory interface, so the same code can be used in both real devices and automated tests. There is no visible change in behavior for end users, and nothing in the commit suggests a security fix or vulnerability.

Lower-priorityhal: add ble_get_metadata and set_ble_metadata to Memoryby Marko Bencun · 6c8c8f76 · Feb 25, 2026 · 5 filesMessage 50 · ThinInformational 18Details
Commit message · Marko Bencun

hal: add ble_get_metadata and set_ble_metadata to Memory

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 18/100

This commit is a routine code reorganization. It moves the functions that read and write Bluetooth firmware metadata out of a low-level C-style module and into a Rust 'Memory' hardware-abstraction trait used by the rest of the firmware. The actual logic for reading, writing, and validating the metadata does not change. There is no indication this fixes a security bug; it appears to be part of making the code more testable and portable.

AI review queuedhal/ui: add switch_to_logo()by Marko Bencun · 2c3738cf · Feb 24, 2026 · 5 filesMessage 35 · OpaqueInformational 15Details
Commit message · Marko Bencun

hal/ui: add switch_to_logo()

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a small code cleanup in the BitBox02 hardware wallet firmware. It moves a direct call to a low-level screen-switching function into a proper hardware-abstraction trait, making the code more testable and consistent. There is no indication it fixes a security bug or changes user-visible behavior.