BB
← All projectsBitBox

BitBox02 firmware

Firmware and bootloader for BitBox02 signing devices.

BitcoinHardware walletsNormal
Repository coverage

779 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

231security candidates161second-pass queue719AI analyses
66commits · 30 days
136commits · 60 days
308commits · 180 days
692commits · 365 days
Backfill bands
Aug 5 → Feb 6335 seen28 candidatesComplete
Feb 6 → Jun 6265 seen19 candidatesComplete
Jun 6 → Jul 619 seen5 candidatesComplete
Jul 6 → Aug 526 seen3 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

58/100 average clarity
68Strong · 80–100
321Adequate · 60–79
302Thin · 40–59
88Opaque · 0–39
26security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Marko Bencun450131422357
benma's agent11240106164
Niklas Dusenlund15139130057
cedwies12512063
Tomas Vrba10410071
Cedric Wiese12312049
Jad14210060
Sebastian Sutter222050
thisconnect212072
benma212074
Yasser Aziza111070
Niklas111035
Analysis record

Published AI watches

Last scanned 0 minutes ago

Low 34 AI analysisMessage 50 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge remote-tracking branch 'agent/benma-agent/hww-start-session'

This commit adds a new 'session reset' command to the BitBox02 hardware wallet's USB protocol. It lets the host computer cleanly reset the device connection if a previous operation was interrupted, instead of leaving the device stuck mid-t…

New USB control command added to host-wallet protocolReset path cancels async task, resets Noise state, unlocks USB processing, and clears output queueU2F UI ownership check prevents reset from interrupting an active U2F workflow
04302490by Marko Bencun+485−1713 files
No security note in commit
Informational 15 AI analysisMessage 78 · Adequate
BB BitBoxBitBox02 firmware BitcoinHardware wallets

py: make session reset an API setup helper

This is a routine Python code refactor. It moves an existing 'reset session' command from one internal class to another and adds a version check so older firmware simply skips it. There is no security bug being fixed here; it is purely org…

50a9e76aby benma's agent+28−163 files
No security note in commit
Moderate 62 AI analysisMessage 78 · Adequate
BB BitBoxBitBox02 firmware BitcoinHardware wallets

hww: reset sessions on host reconnect

This commit fixes a bug in the BitBox02 hardware wallet where unplugging the USB cable at the wrong moment could leave a half-finished operation running. If the device stayed powered and a new host reconnected, the new host's first message…

Fixes cross-session state confusion on USB reconnectAdds explicit session reset command to cancel stale async workflowsResets Noise cryptographic session to prevent old-key encrypted responses
6679936fby benma's agent+473−1712 files
Vendor flagged security relevance
Informational 17 AI analysisMessage 58 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge commit 'refs/pull/2073/head' of https://github.com/BitBoxSwiss/bitbox02-firmware

This commit adds a new recovery-word entry screen for the upcoming BitBox03 hardware wallet. It is a large feature patch: it introduces a dedicated BIP39 wordlist keyboard, a new recovery-words review screen, and changes how the device han…

New UI workflow distinguishes 'back' from 'cancel' during seed restoration, reducing accidental aborts.Cancel actions still require an explicit confirmation prompt before the restore is abandoned.Wordlist keyboard disables keys that cannot lead to a valid BIP39 word, preventing invalid-word compositions at the widget level.
6b04e006by Marko Bencun+7010−24621 files
No security note in commit
Low 47 AI analysisMessage 50 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge remote-tracking branch 'agent/benma-agent/show-erc20-contract'

This commit improves the BitBox02 hardware wallet's Ethereum token-approval screen. When a user signs an ERC20 token transfer, the device now also shows the token's smart-contract address if the token symbol is ambiguous (the same ticker, …

UI hardening: adds contract-address confirmation for ERC20 tokens with ambiguous or unknown symbolsRegistry validation: rejects payment requests for tokens not present in the firmware's ERC20 registryBuild-time ambiguity detection: generates a sorted list of units shared by multiple contracts
410df562by Marko Bencun+203−123 files
No security note in commit
Low 26 AI analysisMessage 50 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge remote-tracking branch 'agent/benma-agent/bootloader-descriptor-compat'

This commit relaxes a version check in the BitBox02 bootloader upgrade code. Previously, the firmware installer required that a stage0 bootloader descriptor's version exactly matched the currently expected image version. Now it accepts des…

Strict version equality check removed from bootloader descriptor parsingChange located in bootloader upgrade / firmware installer verification pathNo bounds, length, or pointer validation changes observed
6dccfd24by Marko Bencun+19−72 files
No security note in commit
Moderate 53 AI analysisMessage 45 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge branch 'nickez/bb02-utf8-safe'

This commit hardens the BitBox02 firmware so it stops trusting that incoming text strings are valid UTF-8 or plain ASCII. It replaces risky C string copies with length-checked, UTF-8-aware helpers, rejects non-ASCII characters at UI bounda…

Replaced snprintf-based string copies with length-bounded UTF-8-aware copiesAdded explicit length parameter to memory_set_device_name and reject embedded/invalid nullsAdded printable-ASCII enforcement at Rust UI boundary before C rendering
0bbdf6f0by Niklas Dusenlund+338−9625 files
No security note in commit
Low 41 AI analysisMessage 28 · Opaque
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge branch 'benma/ub'

This commit fixes a coding guideline violation in the BitBox02 factory setup code. A 32-byte buffer that receives output from a Rust function was not initialized to zeroes before use. The accompanying documentation now explicitly requires …

Uninitialized stack buffer used as output buffer for Rust/C FFI callDefensive zero-initialization added to prevent use of stale stack data on error or partial write pathsProject coding guidelines updated to mandate zero-initialization for rust_util_bytes_mut buffers
8a6fd97bby Marko Bencun+3−12 files
No security note in commit
Low 35 AI analysisMessage 68 · Adequate
BB BitBoxBitBox02 firmware BitcoinHardware wallets

oled: hold display in reset during startup

This commit fixes a display behavior issue during startup of the BitBox02 hardware wallet. Previously, when the device turned on, the screen's reset pin was left in a state that could allow leftover images or text from an earlier session t…

Information disclosure via residual display content during bootOLED reset pin sequencing hardeningDefense against stale/misleading UI state before verified firmware initializes display
cdb27835by Niklas Dusenlund+2−11 file
Vendor flagged security relevance
Informational 18 AI analysisMessage 50 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge remote-tracking branch 'agent/benma-agent/factorysetup-trim-unused'

This commit trims the BitBox02 factory-setup firmware image by switching stored root attestation public keys from 65-byte uncompressed to 33-byte compressed secp256k1 keys, and by using a smaller static secp256k1 verification context inste…

Change in trusted public-key table format and derivation logicSwitch to static/no-precomp secp256k1 verification contextAddition of secp256k1 self-test at boot
554a0558by Marko Bencun+457−5647 files
No security note in commit
Low 37 AI analysisMessage 50 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge remote-tracking branch 'agent/benma-agent/validate-py-antiklepto-signatures'

This commit adds extra safety checks in the BitBox02 Python library for ECDSA signatures used in Bitcoin and Ethereum signing. It now validates that signatures have the correct length, use valid numbers, and use the safer low-S form. It al…

Defensive validation added for ECDSA signature format and low-S encodingRecovery ID range validation added for recoverable signaturesAnti-Klepto verification now rejects malformed/malleable signatures before nonce verification
0d1a7997by Marko Bencun+152−65 files
Vendor flagged security relevance
Informational 19 AI analysisMessage 50 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge remote-tracking branch 'agent/benma-agent/scroll-payment-request-memo-name'

This commit tweaks how the BitBox02 hardware wallet displays a payment-request memo on screen. It changes the label from 'Memo from\n\nMerchant' to 'Memo from: Merchant' and makes the screen scrollable so long merchant names don't get cut …

No security-relevant signal in commit message or diffUI/UX change only: text formatting and scrollabilityNo memory-safety, cryptographic, or authorization changes observed
be375664by Marko Bencun+115−66 files
No security note in commit
Informational 19 AI analysisMessage 91 · Strong
BB BitBoxBitBox02 firmware BitcoinHardware wallets

factorysetup: compress constant root keys

This commit is a hardening and size-optimization change for the BitBox02 factory-setup firmware. It stores the 110 built-in root attestation public keys in compressed (33-byte) form instead of uncompressed (65-byte) form, and marks the tab…

Data table moved from writable RAM to read-only flash (const)Public-key table size reduced from 65 to 33 bytes per keyNew Rust helper normalizes compressed/uncompressed keys before hashing
e2273c1fby benma's agent+407−5552 files
No security note in commit
Informational 18 AI analysisMessage 78 · Adequate
BB BitBoxBitBox02 firmware BitcoinHardware wallets

factorysetup: reuse SHA-256 for HMAC

This commit swaps one internal cryptography library for another when computing HMAC-SHA256 in the factory-setup code. The goal is to reduce firmware size by reusing an existing SHA-256 implementation, not to fix a security bug. New test ve…

Cryptographic implementation change in HMAC-SHA256 helperUse of `.unwrap()` on `new_from_slice`, which can panic if key length is unsupported; for HMAC-SHA256 the RustCrypto `new_from_slice` accepts any key length, so this is effectively safe but still a panic pathNo removal of existing call sites; normal firmware still uses `bitcoin_hashes` for other callers
a790a7f0by benma's agent+24−55 files
No security note in commit
Informational 21 AI analysisMessage 78 · Adequate
BB BitBoxBitBox02 firmware BitcoinHardware wallets

factorysetup: use static secp context

This commit changes how the BitBox02 factory-setup program checks digital signatures. It switches from a dynamically created crypto context to a built-in, read-only verification context, which makes the factory-setup firmware about 35 KB s…

Cryptographic context change in verification pathRemoval of dynamic secp256k1 context creation in factory setupExplicit addition of secp256k1_selftest() to compensate for skipped implicit self-test
2756aca4by benma's agent+26−42 files
No security note in commit
Informational 18 AI analysisMessage 73 · Adequate
BB BitBoxBitBox02 firmware BitcoinHardware wallets

factorysetup: speed up certificate setup

This commit is a performance optimization in the BitBox02 factory setup process. It changes how the device picks which trusted root public key to use when verifying an attestation certificate. Previously, the device tried verifying the sig…

No removal of cryptographic verification: rust_secp256k1_verify is still performed after key selection.No change to accepted inputs: any certificate accepted before is still accepted, and any rejected before is still rejected.Identifier comparison uses MEMEQ over the full 32-byte SHA-256 digest, so collision resistance is standard.
d5617112by benma's agent+10−81 file
No security note in commit
Informational 15 AI analysisMessage 45 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge branch 'nickez/bb03-binaries'

This commit is a large feature merge that adds initial support for a new hardware variant, the BitBox03 (STM32U5-based development kit). It introduces new bootloader and firmware binaries, board support crates, vendored Rust dependencies (…

1a648595by Niklas Dusenlund+17103−5779170 files
No security note in commit
Informational 15 AI analysisMessage 58 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge commit 'refs/pull/1976/head' of https://github.com/BitBoxSwiss/bitbox02-firmware

This commit adds a progress bar that appears while the BitBox02 is loading large Ethereum transaction data from a connected computer. It is a user-experience improvement, not a security fix. The code only changes how progress is displayed …

386d86f5by Marko Bencun+139−134 files
No security note in commit
Informational 15 AI analysisMessage 35 · Opaque
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Add testboard openocd config

This commit adds a configuration file for OpenOCD, a debugging tool used during hardware development and testing. It tells the debugger how to connect to an STM32U5 test board using a J-Link adapter. There is no change to firmware code, no…

c5984b41by Niklas Dusenlund+16−01 file
No security note in commit
Informational 19 AI analysisMessage 28 · Opaque
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge branch 'py-proto'

This commit only adds explanatory comments to Python type-stub files describing what happens when an optional anti-klepto host nonce commitment is left out. It does not change any firmware logic, cryptographic code, or default behavior. Th…

Documentation-only change in generated Python stubsMentions anti-klepto / S2C nonce commitment fallback behaviorNo logic, default, or cryptographic implementation change
926a5885by Marko Bencun+28−62 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Lower-priorityfactorysetup: fix UB use of bufferby Marko Bencun · 091a9a05 · Sep 9, 2026 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · Marko Bencun

factorysetup: fix UB use of buffer

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Security candidateoled: hold display in reset during startupby Niklas Dusenlund · cdb27835 · Sep 8, 2026 · 1 fileMessage 68 · AdequateLow 35Details
Commit message · Niklas Dusenlund

oled: hold display in reset during startup

Production stage0 verifies stage1 before initializing the OLED. Leaving
the reset pin high can allow previous display content to remain visible
at reduced brightness while the boost converter is disabled.

Set the reset output latch low before enabling the pin as an output.
Keep the OLED in reset until oled_init() releases it and uploads a
cleared framebuffer.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
access control
AI analysis · Low 35/100

This commit fixes a display behavior issue during startup of the BitBox02 hardware wallet. Previously, when the device turned on, the screen's reset pin was left in a state that could allow leftover images or text from an earlier session to briefly appear at low brightness before the device finished booting. The change ensures the screen is kept fully blank (held in reset) until the firmware is ready to draw a clean screen. This is a defensive fix to prevent a user from seeing stale or misleading information during boot.

Security candidateMerge remote-tracking branch 'agent/benma-agent/factorysetup-trim-unused'by Marko Bencun · 554a0558 · Sep 8, 2026 · 7 filesMessage 50 · ThinInformational 18Details
Commit message · Marko Bencun

Merge remote-tracking branch 'agent/benma-agent/factorysetup-trim-unused'

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathmerge-commit duplicate discount
AI analysis · Informational 18/100

This commit trims the BitBox02 factory-setup firmware image by switching stored root attestation public keys from 65-byte uncompressed to 33-byte compressed secp256k1 keys, and by using a smaller static secp256k1 verification context instead of a full signing context. It also adds a self-test and a helper that computes the key identifier from the uncompressed form so existing host tooling keeps working. The changes are framed as a size-reduction/cleanup patch; there is no direct evidence in the commit of a security vulnerability being fixed.

Lower-priorityMerge remote-tracking branch 'agent/benma-agent/payment-request-recipient-ascii'by Marko Bencun · fad0ea82 · Sep 8, 2026 · 1 fileMessage 50 · ThinTriage 0Details
Commit message · Marko Bencun

Merge remote-tracking branch 'agent/benma-agent/payment-request-recipient-ascii'

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
merge-commit duplicate discount
Lower-priorityMerge remote-tracking branch 'agent/benma-agent/commit-context-guidelines'by Marko Bencun · 0c02764a · Sep 8, 2026 · 2 filesMessage 50 · ThinTriage 0Details
Commit message · Marko Bencun

Merge remote-tracking branch 'agent/benma-agent/commit-context-guidelines'

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
documentation-only discountmerge-commit duplicate discount
Lower-priorityMerge branch 'nickez/ci-individual-commits'by Niklas Dusenlund · aba73b4f · Sep 8, 2026 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · Niklas Dusenlund

Merge branch 'nickez/ci-individual-commits'

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
merge-commit duplicate discount
Lower-prioritycardano: limit xpub batch sizeby benma's agent · b66f5ed3 · Sep 7, 2026 · 2 filesMessage 76 · AdequateTriage 0Details
Commit message · benma's agent

cardano: limit xpub batch size

Limit Cardano xpub requests to 20 keypaths, matching the Bitcoin batch
limit. Reject larger batches before allocating response vectors or
accessing the keystore to bound derivation work and response size.

Cover the 20/21 boundary and document the new API limit in the firmware
changelog. The generic response-capacity check is handled separately in
#2087.

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Security candidateMerge remote-tracking branch 'agent/benma-agent/validate-py-antiklepto-signatures'by Marko Bencun · 0d1a7997 · Sep 7, 2026 · 5 filesMessage 50 · ThinLow 37Details
Commit message · Marko Bencun

Merge remote-tracking branch 'agent/benma-agent/validate-py-antiklepto-signatures'

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundarydefensive validationcryptography-sensitive pathmerge-commit duplicate discount
AI analysis · Low 37/100

This commit adds extra safety checks in the BitBox02 Python library for ECDSA signatures used in Bitcoin and Ethereum signing. It now validates that signatures have the correct length, use valid numbers, and use the safer low-S form. It also validates the recovery ID for recoverable signatures. These are defensive hardening changes rather than a fix for a known active exploit, but they close a gap where a malicious or buggy device could return malformed or malleable signatures that the host software would previously accept.

Lower-priorityMerge remote-tracking branch 'agent/benma-agent/fix-simulator-printf'by Marko Bencun · 2de2dc0f · Sep 7, 2026 · 1 fileMessage 50 · ThinTriage 0Details
Commit message · Marko Bencun

Merge remote-tracking branch 'agent/benma-agent/fix-simulator-printf'

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
merge-commit duplicate discount
Lower-priorityMerge branch 'nickez/sanitize-legacy-backup-names'by Niklas Dusenlund · b388ef47 · Sep 7, 2026 · 4 filesMessage 50 · ThinTriage 0Details
Commit message · Niklas Dusenlund

Merge branch 'nickez/sanitize-legacy-backup-names'

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
defensive validationmerge-commit duplicate discount
AI review queuedMerge remote-tracking branch 'agent/benma-agent/scroll-payment-request-memo-name'by Marko Bencun · be375664 · Sep 5, 2026 · 6 filesMessage 50 · ThinInformational 19Details
Commit message · Marko Bencun

Merge remote-tracking branch 'agent/benma-agent/scroll-payment-request-memo-name'

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit tweaks how the BitBox02 hardware wallet displays a payment-request memo on screen. It changes the label from 'Memo from\n\nMerchant' to 'Memo from: Merchant' and makes the screen scrollable so long merchant names don't get cut off. It also updates test snapshots and bumps the firmware version to 9.27.2. There is no indication this fixes a security vulnerability; it appears to be a user-interface improvement.

Lower-priorityMerge remote-tracking branch 'agent/benma-agent/factorysetup-cert-speed'by Marko Bencun · d914bfe9 · Sep 5, 2026 · 1 fileMessage 50 · ThinTriage 0Details
Commit message · Marko Bencun

Merge remote-tracking branch 'agent/benma-agent/factorysetup-cert-speed'

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
merge-commit duplicate discount
Security candidatefactorysetup: compress constant root keysby benma's agent · e2273c1f · Sep 4, 2026 · 2 filesMessage 91 · StrongInformational 19Details
Commit message · benma's agent

factorysetup: compress constant root keys

Store the 110 root attestation public keys as const compressed SEC1
points instead of writable uncompressed points. Keep every key and its
index unchanged, and document conversion using Python's ecdsa module.

Derive root identifiers from the uncompressed encoding so the host's
identifiers and the single-signature verification added in #2081 are
preserved.

The factory-setup image shrinks from 155,088 to 152,472 bytes, saving
2,616 bytes. RAM usage drops from 203,304 to 196,152 bytes, saving
7,152 bytes by keeping the table out of writable memory.

Together with the earlier changes in this PR, the image shrinks from
195,296 to 152,472 bytes (-42,824, 21.9%), and RAM usage drops from
203,304 to 196,152 bytes (-7,152, 3.5%). These figures exclude the
peripheral and font changes split into #2092.

91/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
signing boundaryupdate trustdefensive validationcryptography-sensitive path
AI analysis · Informational 19/100

This commit is a hardening and size-optimization change for the BitBox02 factory-setup firmware. It stores the 110 built-in root attestation public keys in compressed (33-byte) form instead of uncompressed (65-byte) form, and marks the table as read-only (`const`). This shrinks the firmware image by about 2.6 KB and reduces RAM use by about 7 KB. A new helper is added so the device can still compute the same public-key identifiers used by host software, and the existing signature verification behavior is preserved. There is no direct vulnerability being fixed; the main security benefit is making the key table tamper-resistant in RAM because it now lives in read-only memory.

Security candidatefactorysetup: reuse SHA-256 for HMACby benma's agent · a790a7f0 · Sep 4, 2026 · 5 filesMessage 78 · AdequateInformational 18Details
Commit message · benma's agent

factorysetup: reuse SHA-256 for HMAC

Use RustCrypto Hmac<Sha256> for the shared HMAC-SHA256 helper so factory
setup reuses the SHA-256 backend already linked for plain hashing.

This reduces the factory-setup image from 159,568 to 155,088 bytes,
saving 4,480 bytes. RAM usage remains 203,304 bytes.

Normal firmware still needs bitcoin_hashes for other callers. Multi
grows from 686,080 to 686,356 bytes (+276), and Bitcoin-only grows from
525,392 to 525,656 bytes (+264).

Add known-answer coverage for empty keys and keys longer than the
SHA-256 block size.

78/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
cryptography-sensitive path
AI analysis · Informational 18/100

This commit swaps one internal cryptography library for another when computing HMAC-SHA256 in the factory-setup code. The goal is to reduce firmware size by reusing an existing SHA-256 implementation, not to fix a security bug. New test vectors were added to confirm the new implementation still produces the correct answers.

Security candidatefactorysetup: use static secp contextby benma's agent · 2756aca4 · Sep 4, 2026 · 2 filesMessage 78 · AdequateInformational 21Details
Commit message · benma's agent

factorysetup: use static secp context

ECDSA verification can use libsecp256k1’s built-in static context.

A dynamically created context links signing support and its
precomputation table, even when Rust requests a verification-only
context.

The previous context initialization reached
secp256k1_context_preallocated_create(), which runs
secp256k1_selftest() automatically. The static context skips
initialization, so run the self-test explicitly once during factory
setup startup, as recommended by libsecp256k1.

This reduces the factory-setup image by 35,728 bytes.

78/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
signing boundarydefensive validationcryptography-sensitive path
AI analysis · Informational 21/100

This commit changes how the BitBox02 factory-setup program checks digital signatures. It switches from a dynamically created crypto context to a built-in, read-only verification context, which makes the factory-setup firmware about 35 KB smaller. The commit also adds an explicit self-test because the new static context skips the automatic self-test that the old path performed. The change is a size optimization, not a fix for an active security flaw, but it touches cryptographic verification code used during device manufacturing.

Lower-prioritybackup: sanitize legacy device namesby Niklas Dusenlund · 7e8cdb5f · Sep 3, 2026 · 4 filesMessage 78 · AdequateTriage 8Details
Commit message · Niklas Dusenlund

backup: sanitize legacy device names

Legacy backups may contain device names with characters outside the printable-ASCII set supported by the BitBox02 UI and device-name storage. Passing such names through can omit characters or abort backup checks and restores as those boundaries are hardened.

Replace unsupported characters when consuming a backup so it remains usable and the restored device gets a valid name. Preserve the original metadata for checksum validation.

Add regression coverage for Unicode and control characters.

78/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
defensive validation
Security candidatefactorysetup: speed up certificate setupby benma's agent · d5617112 · Sep 3, 2026 · 1 fileMessage 73 · AdequateInformational 18Details
Commit message · benma's agent

factorysetup: speed up certificate setup

Select the attestation root key by its identifier before verifying the
certificate signature. This decreases the time to set the certificate to
less than 0.1 seconds. Previously it took up to roughly 2.4 seconds for a
root key near the bottom of the list.

73/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Names security-relevant behavior explicitly
Why it was queued
signing boundaryupdate trust
AI analysis · Informational 18/100

This commit is a performance optimization in the BitBox02 factory setup process. It changes how the device picks which trusted root public key to use when verifying an attestation certificate. Previously, the device tried verifying the signature against every known root key until one worked, which could take up to about 2.4 seconds. Now it first looks up the correct root key using a short identifier (a hash of the public key) and then verifies the signature only once, taking less than 0.1 seconds. The security properties remain the same: the signature is still checked, just faster.

Security candidateMerge branch 'nickez/bb03-binaries'by Niklas Dusenlund · 1a648595 · Sep 3, 2026 · 170 filesMessage 45 · ThinInformational 15Details
Commit message · Niklas Dusenlund

Merge branch 'nickez/bb03-binaries'

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathboot or update pathmerge-commit duplicate discount
AI analysis · Informational 15/100

This commit is a large feature merge that adds initial support for a new hardware variant, the BitBox03 (STM32U5-based development kit). It introduces new bootloader and firmware binaries, board support crates, vendored Rust dependencies (once_cell, portable-atomic, rtt-target), build scripts, and CI targets. There is no indication in the commit message or diff that this is a security fix or that it addresses any vulnerability. It appears to be routine product/platform enablement work.

Lower-priorityMerge remote-tracking branch 'agent/benma-agent/factorysetup-rtt-robustness'by Marko Bencun · f5d11f2e · Sep 3, 2026 · 2 filesMessage 50 · ThinTriage 0Details
Commit message · Marko Bencun

Merge remote-tracking branch 'agent/benma-agent/factorysetup-rtt-robustness'

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
merge-commit duplicate discount
Lower-priorityfactorysetup: make RTT framing robustby benma's agent · f23389f5 · Sep 3, 2026 · 2 filesMessage 68 · AdequateTriage 0Details
Commit message · benma's agent

factorysetup: make RTT framing robust

Read the header and payload exactly so partial RTT reads cannot truncate API messages.

Send each response as one frame. Retry the complete buffer until NoBlockSkip publishes it.

Partial byte counts from NoBlockSkip are not committed and cannot be accumulated.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Lower-priorityMerge commit 'refs/pull/2079/head' of github.com:BitBoxSwiss/bitbox02-firmwareby Marko Bencun · 975c6f5c · Sep 3, 2026 · 1 fileMessage 50 · ThinTriage 0Details
Commit message · Marko Bencun

Merge commit 'refs/pull/2079/head' of github.com:BitBoxSwiss/bitbox02-firmware

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
merge-commit duplicate discount
Lower-priorityfactorysetup: fix RTT response endiannessby benma's agent · 7aefdee6 · Sep 3, 2026 · 1 fileMessage 68 · AdequateTriage 0Details
Commit message · benma's agent

factorysetup: fix RTT response endianness

Commit dff5254d5 ("factory-setup: Remove C implementation of RTT") changed the
response length encoding from a native little-endian uint16_t to manually
assembled big-endian bytes.

This made host clients parse short response lengths as much larger values.
Restore little-endian encoding to match requests and existing clients.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Lower-priorityMerge remote-tracking branch 'agent/benma-agent/require-py-antiklepto'by Marko Bencun · 29b3fb8e · Sep 2, 2026 · 3 filesMessage 50 · ThinTriage 0Details
Commit message · Marko Bencun

Merge remote-tracking branch 'agent/benma-agent/require-py-antiklepto'

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
merge-commit duplicate discount
Lower-priorityMerge remote-tracking branch 'agent/benma-agent/reject-invalid-backup-fields'by Marko Bencun · 1e3e398a · Sep 1, 2026 · 2 filesMessage 50 · ThinTriage 0Details
Commit message · Marko Bencun

Merge remote-tracking branch 'agent/benma-agent/reject-invalid-backup-fields'

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
merge-commit duplicate discount
AI review queuedMerge commit 'refs/pull/1976/head' of https://github.com/BitBoxSwiss/bitbox02-firmwareby Marko Bencun · 386d86f5 · Sep 1, 2026 · 4 filesMessage 58 · ThinInformational 15Details
Commit message · Marko Bencun

Merge commit 'refs/pull/1976/head' of https://github.com/BitBoxSwiss/bitbox02-firmware

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit adds a progress bar that appears while the BitBox02 is loading large Ethereum transaction data from a connected computer. It is a user-experience improvement, not a security fix. The code only changes how progress is displayed during normal data streaming and adds tests to verify the progress bar shows the right percentages.