FD
← All projectsFoundation

Passport firmware

Firmware for Foundation Passport Bitcoin signing devices.

BitcoinHardware walletsNormal
Repository coverage

133 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

43security candidates46second-pass queue123AI analyses
33commits · 30 days
53commits · 60 days
80commits · 180 days
133commits · 365 days
Backfill bands
Aug 5 → Feb 612 seen0 candidatesComplete
Feb 6 → Jun 659 seen3 candidatesComplete
Jun 6 → Jul 64 seen0 candidatesComplete
Jul 6 → Aug 52 seen0 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

54/100 average clarity
6Strong · 80–100
38Adequate · 60–79
77Thin · 40–59
12Opaque · 0–39
4security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Matt Gleason651457351
Jacksper1314714367
Jack331731150
Jean-Pierre De Jesus DIAZ828061
mjg-foundation525065
Ken Carpenter313048
dependabot[bot]505076
Analysis record

Published AI watches

Last scanned 0 minutes ago

Informational 24 AI analysisMessage 73 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #665 from Foundation-Devices/casa-crypto-account-export

This commit adds a new feature to Foundation's Passport hardware wallet that exports two cryptographic public keys for Casa wallet registration: the master extended public key and a separate Casa-specific key derived at path m/45'. The key…

New key-export surface: two public keys (master + m/45' derived) are now exported togetherSensitive material is public-key/chain-code only; no private keys are exportedExport channels remain QR and microSD, unchanged from prior Casa export behavior
5e499107by mjg-foundation+291−315 files
No security note in commit
Low 25 AI analysisMessage 73 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #669 from Foundation-Devices/add-native-unchained-connect-wallet

This commit adds support for the Unchained wallet to the Passport hardware wallet. Most of the change is normal feature code, but it also introduces a new way to feed already-encoded data into the QR encoder and tightens up the encoder so …

New unsafe FFI function `ur_encoder_start_raw` added with documented safety preconditionsUR type string is validated (length, charset, UTF-8) before use in encoderEncoder now tracks a `started` flag and returns empty output if not started, reducing use-after-free/misuse risk
26bd36d5by mjg-foundation+426−1812 files
No security note in commit
Moderate 55 AI analysisMessage 78 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #655 from Foundation-Devices/sft-7320-entropy-hardening

This firmware update hardens the way Passport generates random numbers. Previously, a failing or stuck hardware random-number generator could silently produce weak or repeated values, which is dangerous for creating secret keys. The patch …

Fail-closed RNG error handling: persistent seed/clock errors now trigger a fatal handler instead of returning potentially weak valuesST-recommended seed-error recovery (RM0433 section 34.3.7): clear SEIS and flush 12 discard words, with bounded retry attemptsDuplicate and zero-value rejection in rng_try_sample to avoid returning stuck or invalid RNG output
0f1a5325by mjg-foundation+150−379 files
Vendor flagged security relevance
High 71 AI analysisMessage 83 · Strong
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #675 from Foundation-Devices/fix/verify-change-before-review

This firmware update moves the verification of Bitcoin 'change' addresses to happen before the user reviews the transaction on screen. Previously, the device checked whether change outputs truly belonged to the wallet only after the user h…

Reorders security-critical validation to occur before user approvalValidates change-output ownership before the review screen hides those outputsPrevents transaction signing if change derivation does not match the PSBT
1fea63c8by Jacksper13+174−454 files
Vendor flagged security relevance
Low 29 AI analysisMessage 83 · Strong
FD FoundationPassport firmware BitcoinHardware wallets

SFT-8098: skip change verification for transactions without change

This commit changes how the Passport hardware wallet reviews Bitcoin transactions that have no 'change' output. Previously, the wallet would always run a change-verification step that opens the secure key store, even when there was no chan…

Change reduces unnecessary access to the key store during transaction reviewNo cryptographic check is removed for transactions that actually contain changeUI label changed to more accurately describe the operation being performed
3df93748by Jacksper13+36−112 files
No security note in commit
Moderate 59 AI analysisMessage 83 · Strong
FD FoundationPassport firmware BitcoinHardware wallets

SFT-8098: complete change verification before transaction review

This commit moves a safety check earlier in the process of approving a Bitcoin transaction on the Passport hardware wallet. Previously, the wallet verified that 'change' outputs (money going back to your own wallet) truly belonged to you o…

Change-address verification moved from post-approval signing stage to pre-review stagePSBT change output ownership now proved before user is shown transaction detailsSensitive key derivation context closed before transaction review is displayed
fb88001cby Jacksper13+150−464 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 58 · Thin
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #673 from Foundation-Devices/SFT-7945-add-pytest-to-devshell

This commit is a routine development tooling and cleanup change. It adds the Pytest testing framework to the project's Nix development shell, fixes a test runner path, adds a GitHub Actions workflow to run simulator tests automatically, an…

d8ee1164by mjg-foundation+101−25825 files
No security note in commit
Informational 18 AI analysisMessage 73 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #648 from Foundation-Devices/dependabot-host-tooling-hygiene

This commit updates the Python Pillow image-processing library used in host-side developer tooling from version 8.x to 12.3.x and requires Python 3.10 or newer. Pillow 8.x is known to have many publicly disclosed security vulnerabilities, …

Dependency version bump of a library with known historical vulnerabilities (Pillow 8.x)Constraint now requires Python 3.10+ alongside the newer Pillow major versionChange is limited to host tooling files (pyproject.toml, setup.py, requirements-optional.txt, tox.ini, DEVELOPMENT.md)
d6c05830by Jacksper13+6−55 files
No security note in commit
Informational 15 AI analysisMessage 58 · Thin
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #649 from Foundation-Devices/bitcoin-safe-wallet-flow

This commit adds support for a new Bitcoin software wallet called 'Bitcoin Safe' to the Passport hardware wallet firmware. It is a straightforward feature addition that registers the wallet in the firmware's list of supported software wall…

9f1e36b0by Jacksper13+27−03 files
No security note in commit
Moderate 62 AI analysisMessage 58 · Thin
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #653 from Foundation-Devices/show-op-return-output-amount

This update changes how the Passport hardware wallet displays Bitcoin transaction outputs that carry data (OP_RETURN outputs). Previously, only the embedded message was shown. Now the device also shows the amount of bitcoin assigned to tha…

UI spoofing hardening: user-controlled OP_RETURN data is now escaped before renderingNew display of OP_RETURN output amount reduces risk of hidden value leakageUnit test includes an attacker-controlled message simulating fake Amount/Destination headings
433c4a20by Jacksper13+79−33 files
No security note in commit
Moderate 59 AI analysisMessage 78 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #660 from Foundation-Devices/fix/legacy-settings-overflow

This commit fixes a bug in how the Passport hardware wallet saves its settings to internal flash memory. Previously, the code checked whether the settings data was too large only after it had already picked and erased a flash storage slot.…

Buffer size validation moved before flash write/erase operationsReplaced broken 'assert false' crash path with explicit ValueErrorAdded unit test for oversized settings rejection
180e183dby Jacksper13+34−113 files
No security note in commit
Low 33 AI analysisMessage 78 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

tooling: constrain tox Pillow dependency (SFT-7281)

This commit tightens a software dependency used only in testing/development tooling. It prevents an automated test environment from installing old, known-vulnerable versions of the Pillow image library when running under Python 3.10. The c…

Dependency constraint added to block known-vulnerable Pillow versionsCommit message acknowledges prior path could install an older vulnerable releaseChange is in Trezor external module tooling, not Passport firmware runtime
56799183by Jack+2−12 files
Vendor flagged security relevance
High 73 AI analysisMessage 58 · Thin
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #662 from Foundation-Devices/fix/unverified-psbt-fees

This firmware update fixes a security issue in the Passport hardware wallet's handling of Bitcoin transaction fees. Previously, when a transaction file (PSBT) only provided a claimed input amount without the full previous transaction to pr…

UI now displays 'Unverified' instead of a numeric network fee when input amounts cannot be independently verifiedNew assertion prevents witness/non-witness UTXO value or scriptPubKey mismatch for the same inputHistory-cache amount updates are deferred until after cryptographic proof of input ownership is completed
7b64e920by Jacksper13+336−627 files
Vendor flagged security relevance
Moderate 66 AI analysisMessage 58 · Thin
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #661 from Foundation-Devices/fix/seedqr-validation

This update tightens the checks on SeedQR codes, which are QR codes that encode a wallet's backup seed phrase as numbers. Before, the decoder might accept invalid or oddly-sized numeric strings and either crash or produce an incorrect seed…

Input validation added to seed-import pathOut-of-range BIP-39 word index now rejected explicitlyNon-digit characters rejected before integer conversion
2c41d1c5by Jacksper13+59−63 files
No security note in commit
Informational 18 AI analysisMessage 28 · Opaque
FD FoundationPassport firmware BitcoinHardware wallets

fixed excess delete call

This tiny change removes two variables ('pu' and 'skp') from a Python 'del' cleanup statement in the code that signs Bitcoin transactions. The commit message says it fixes an 'excess delete call.' In Python, deleting a name that does not e…

Change is in a sensitive operation: PSBT signingOriginal code could raise NameError and crash the signing taskNo explicit security claim in commit message or diff
1b2efc8fby Matt Gleason+1−11 file
No security note in commit
Informational 15 AI analysisMessage 18 · Opaque
FD FoundationPassport firmware BitcoinHardware wallets

fixed format

This commit adds a single blank line between two test functions to fix code formatting. It makes no functional changes to the firmware or its tests.

52ade0a1by Matt Gleason+1−01 file
No security note in commit
Moderate 59 AI analysisMessage 58 · Thin
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #672 from Foundation-Devices/fix/validate-local-multisig-xpub

This update fixes a validation gap when importing multisig wallets into the Passport hardware wallet. Previously, the device only checked that the public key matched; now it also checks the chain code. Without this check, a tampered extend…

Incomplete cryptographic input validation (public key only, not full xpub)Potential acceptance of tampered extended public keys in multisig wallet importFix adds chain_code equality check alongside existing public_key equality check
b1756906by Jacksper13+95−24 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 60 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

SFT-7945: test suite working in devshell, removed unused translation

This commit is a routine cleanup and test-infrastructure change. It removes an unused translation system (translation files, imports, and a test), updates linting rules to no longer exclude the now-removed translation folder, and fixes the…

d8353514by Matt Gleason+25−21420 files
No security note in commit
Low 36 AI analysisMessage 45 · Thin
FD FoundationPassport firmware BitcoinHardware wallets

Integrate PSBT fee and amount validation

This commit adds a test fixture flag called witness_utxo to a fake PSBT input object used in unit tests, and documents a changelog entry about marking network fees as 'unverified' when a PSBT input's UTXO data cannot be verified. The actua…

PSBT fee/amount validationunverifiable inputs flagged as unverifiedwitness UTXO handling
409137c9by Jack+2−02 files
Vendor flagged security relevance
Moderate 60 AI analysisMessage 45 · Thin
FD FoundationPassport firmware BitcoinHardware wallets

Reuse sensitive values during PSBT validation

This firmware update changes how Passport validates Bitcoin transaction files (PSBTs) before signing. It makes two main improvements: it reuses the wallet's secret seed for fewer key-derivation operations, and it verifies that the claimed …

Deferred and batched sensitive key derivation during PSBT validationAmount-cache update moved after ownership/key-path proofNew assertion to block re-signing already-signed non-multisig inputs
f88420bfby Jack+72−213 files
Vendor flagged security relevance
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queuedMerge pull request #665 from Foundation-Devices/casa-crypto-account-exportby mjg-foundation · 5e499107 · Sep 16, 2026 · 5 filesMessage 73 · AdequateInformational 24Details
Commit message · mjg-foundation

Merge pull request #665 from Foundation-Devices/casa-crypto-account-export

Export both Casa pairing keys by QR and microSD

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathparser or protocol pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Informational 24/100

This commit adds a new feature to Foundation's Passport hardware wallet that exports two cryptographic public keys for Casa wallet registration: the master extended public key and a separate Casa-specific key derived at path m/45'. The keys can be exported either as a QR code or saved to a microSD card. The change is a feature addition, not a bug fix, and there is no evidence in the commit that it addresses a security vulnerability. However, exporting additional key material always slightly increases the attack surface if the exported data is mishandled.

AI review queuedMerge pull request #669 from Foundation-Devices/add-native-unchained-connect-walletby mjg-foundation · 26bd36d5 · Sep 16, 2026 · 12 filesMessage 73 · AdequateLow 25Details
Commit message · mjg-foundation

Merge pull request #669 from Foundation-Devices/add-native-unchained-connect-wallet

Add native Unchained Connect Wallet support

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathparser or protocol pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Low 25/100

This commit adds support for the Unchained wallet to the Passport hardware wallet. Most of the change is normal feature code, but it also introduces a new way to feed already-encoded data into the QR encoder and tightens up the encoder so it won't produce output if it hasn't been started correctly. The simulator also gets clipboard copy/paste tweaks. There is no vendor statement that this fixes a security bug, and the changes look like defensive hardening rather than a patch for an active vulnerability.

AI review queuedMerge pull request #675 from Foundation-Devices/fix/verify-change-before-reviewby Jacksper13 · 1fea63c8 · Sep 14, 2026 · 4 filesMessage 83 · StrongHigh 71Details
Commit message · Jacksper13

Merge pull request #675 from Foundation-Devices/fix/verify-change-before-review

Complete change verification before transaction review

83/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
defensive validationsigning or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · High 71/100

This firmware update moves the verification of Bitcoin 'change' addresses to happen before the user reviews the transaction on screen. Previously, the device checked whether change outputs truly belonged to the wallet only after the user had already approved the transaction and while it was about to sign. Because the review screen hides change outputs from the user, a malicious or buggy PSBT could have asked the device to send change to an attacker's address, and the user would never see it before approving. The fix ensures the wallet proves it owns every hidden change output before showing the review screen, so a mismatch aborts the transaction before the user is asked to confirm.

AI review queuedSFT-8098: skip change verification for transactions without changeby Jacksper13 · 3df93748 · Sep 11, 2026 · 2 filesMessage 83 · StrongLow 29Details
Commit message · Jacksper13

SFT-8098: skip change verification for transactions without change

Avoid opening the key store when review does not require change verification. Clarify the spinner label and cover cancellation with and without change.

83/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
defensive validationsigning or wallet pathsecond-pass: near security thresholdsecond-pass: security-sensitive path
AI analysis · Low 29/100

This commit changes how the Passport hardware wallet reviews Bitcoin transactions that have no 'change' output. Previously, the wallet would always run a change-verification step that opens the secure key store, even when there was no change to verify. Now it skips that step when there is no change, and updates the on-screen spinner label from 'Validating transaction' to 'Verifying change' so the user knows what is happening. The change is framed by the developer as a user-experience and clarity improvement, not as a fix for a known security vulnerability.

AI review queuedSFT-8098: complete change verification before transaction reviewby Jacksper13 · fb88001c · Sep 11, 2026 · 4 filesMessage 83 · StrongModerate 59Details
Commit message · Jacksper13

SFT-8098: complete change verification before transaction review

Reuse the existing check after wallet approval and before transaction details. Keep one verification pass and extend the approval flow regressions.

83/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
defensive validationsigning or wallet pathsecond-pass: near security thresholdsecond-pass: security-sensitive path
AI analysis · Moderate 59/100

This commit moves a safety check earlier in the process of approving a Bitcoin transaction on the Passport hardware wallet. Previously, the wallet verified that 'change' outputs (money going back to your own wallet) truly belonged to you only after you had already reviewed the transaction and approved signing. Now that ownership proof happens before the transaction details are shown to the user. This prevents a scenario where a malicious or buggy PSBT (the file describing the transaction) hides a change address that actually belongs to an attacker, because the wallet will refuse to show the review screen if it cannot prove the change is yours. The change is defensive: it closes a window where a user might approve a transaction whose change output has not yet been validated.

AI review queuedMerge pull request #649 from Foundation-Devices/bitcoin-safe-wallet-flowby Jacksper13 · 9f1e36b0 · Sep 2, 2026 · 3 filesMessage 58 · ThinInformational 15Details
Commit message · Jacksper13

Merge pull request #649 from Foundation-Devices/bitcoin-safe-wallet-flow

Add Bitcoin Safe wallet flow

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit adds support for a new Bitcoin software wallet called 'Bitcoin Safe' to the Passport hardware wallet firmware. It is a straightforward feature addition that registers the wallet in the firmware's list of supported software wallets and defines how to export wallet data to it (via QR code or microSD card). There is no indication of a security bug, vulnerability, or fix in the changed code.

AI review queuedMerge pull request #653 from Foundation-Devices/show-op-return-output-amountby Jacksper13 · 433c4a20 · Sep 2, 2026 · 3 filesMessage 58 · ThinModerate 62Details
Commit message · Jacksper13

Merge pull request #653 from Foundation-Devices/show-op-return-output-amount

Show amounts for OP_RETURN outputs

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Moderate 62/100

This update changes how the Passport hardware wallet displays Bitcoin transaction outputs that carry data (OP_RETURN outputs). Previously, only the embedded message was shown. Now the device also shows the amount of bitcoin assigned to that output and escapes the message text so a crafted message cannot fake extra user-interface labels (like a fake 'Amount' or 'Destination' section). The included tests demonstrate that an attacker who controls an OP_RETURN message can no longer make the screen look like a real payment destination is being sent funds.

AI review queuedfixed excess delete callby Matt Gleason · 1b2efc8f · Aug 27, 2026 · 1 fileMessage 28 · OpaqueInformational 18Details
Commit message · Matt Gleason

fixed excess delete call

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 18/100

This tiny change removes two variables ('pu' and 'skp') from a Python 'del' cleanup statement in the code that signs Bitcoin transactions. The commit message says it fixes an 'excess delete call.' In Python, deleting a name that does not exist raises a NameError, which would crash the signing task. The patch prevents that crash but does not appear to be a security vulnerability itself; it is a bug fix for a runtime error in sensitive code.

AI review queuedfixed formatby Matt Gleason · 52ade0a1 · Aug 27, 2026 · 1 fileMessage 18 · OpaqueInformational 15Details
Commit message · Matt Gleason

fixed format

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit adds a single blank line between two test functions to fix code formatting. It makes no functional changes to the firmware or its tests.

AI review queuedMerge pull request #672 from Foundation-Devices/fix/validate-local-multisig-xpubby Jacksper13 · b1756906 · Aug 27, 2026 · 4 filesMessage 58 · ThinModerate 59Details
Commit message · Jacksper13

Merge pull request #672 from Foundation-Devices/fix/validate-local-multisig-xpub

Validate complete local multisig xpubs

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
defensive validationsigning or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Moderate 59/100

This update fixes a validation gap when importing multisig wallets into the Passport hardware wallet. Previously, the device only checked that the public key matched; now it also checks the chain code. Without this check, a tampered extended public key (xpub) could have been accepted as belonging to the wallet, potentially allowing an attacker to silently change the wallet's receiving addresses or make future transactions look valid when they are not. The fix is accompanied by a new test that confirms mismatched chain codes are rejected.

AI review queuedmultisig: validate complete local xpubby Jack · e712e425 · Aug 26, 2026 · 4 filesMessage 45 · ThinModerate 59Details
Commit message · Jack

multisig: validate complete local xpub

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
defensive validationsigning or wallet pathsecond-pass: near security thresholdsecond-pass: security-sensitive path
AI analysis · Moderate 59/100

This firmware update fixes a multisig wallet import check. Previously, the device only verified that the public key portion of an extended public key (xpub) matched what it expected; now it also verifies the chain code. A mismatched chain code could let a malicious or malformed xpub slip through validation, potentially causing the wallet to derive wrong or non-matching addresses and making backups or transaction coordination unreliable. The fix is accompanied by a new unit test that confirms a wrong chain code is rejected.

AI review queuedMerge pull request #666 from Foundation-Devices/fix/quirc-grid-boundsby Jacksper13 · bcb9c29e · Aug 26, 2026 · 7 filesMessage 58 · ThinModerate 60Details
Commit message · Jacksper13

Merge pull request #666 from Foundation-Devices/fix/quirc-grid-bounds

Reject oversized QR grids in quirc

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
parser or protocol pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Moderate 60/100

This update hardens the QR-code scanner library (quirc) used in the Passport hardware wallet so it refuses to process impossibly large QR grids and no longer reads past the end of its internal buffer when a malformed QR code is presented. It also fixes an off-by-one bug in grid indexing. The changes are defensive: they prevent memory corruption and crashes when scanning deliberately crafted or corrupted QR codes, rather than changing normal wallet behavior.

AI review queuedfixed buffer extension issueby Matt Gleason · ac7bbecb · Aug 25, 2026 · 3 filesMessage 35 · OpaqueLow 35Details
Commit message · Matt Gleason

fixed buffer extension issue

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 35/100

This commit fixes a low-level programming bug in how the Passport hardware wallet builds a special data format (CBOR) when exporting a public key to the Unchained Capital service. The original code passed raw numbers to a buffer-extension function in a way that could produce incorrect byte sequences. The fix wraps those numbers as explicit byte arrays. The commit also contains unrelated cosmetic changes to the simulator's README and adds clipboard keybindings to the simulator's terminal window.

AI review queuedRequire fingerprint for Unchained exportby Jack · 3fc52d3b · Aug 20, 2026 · 1 fileMessage 45 · ThinLow 46Details
Commit message · Jack

Require fingerprint for Unchained export

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 46/100

This commit tightens how Passport retrieves the wallet's fingerprint when exporting data for the Unchained wallet. Previously, if the fingerprint setting was missing, the code would silently fall back to a value of 0. Now it requires the actual fingerprint to be present. This is a hardening change: a missing or corrupted fingerprint setting could have led to an incorrect or invalid export rather than a clearly wrong one, which could confuse wallet software or, in worst-case scenarios, affect how multisig addresses are derived.

AI review queuedHarden raw Unchained UR encodingby Jack · f75bfd37 · Aug 20, 2026 · 4 filesMessage 45 · ThinLow 42Details
Commit message · Jack

Harden raw Unchained UR encoding

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
defensive validationsigning or wallet pathparser or protocol pathsecond-pass: near security thresholdsecond-pass: security-sensitive path
AI analysis · Low 42/100

This commit hardens the firmware's QR-code encoder used for the Unchained wallet export. It adds a safety flag so that if an invalid export request is rejected, the device won't accidentally reuse or leak a previously encoded QR message. It also fixes a fingerprint byte-order bug and switches from one export format to another for microSD exports. The changes are defensive hardening rather than a clear fix for an active exploit.

AI review queuedAdd native Unchained wallet connectionby Jack · 18e872f9 · Aug 20, 2026 · 10 filesMessage 45 · ThinInformational 24Details
Commit message · Jack

Add native Unchained wallet connection

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathparser or protocol pathsecond-pass: security-sensitive path
AI analysis · Informational 24/100

This commit adds support for connecting the Passport hardware wallet to the Unchained multisig service. It introduces a new way to pass already-encoded data into the QR/UR encoder, plus a new wallet definition and CBOR encoding helper. The changes are mostly additive feature code; there is no vendor statement that this fixes a security bug, and no independent security disclosure is referenced.

AI review queuedDocument and test multisig approval policyby Jack · 467818fc · Aug 17, 2026 · 2 filesMessage 55 · ThinLow 41Details
Commit message · Jack

Document and test multisig approval policy

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 41/100

This commit documents and tests a policy for approving multisignature wallets proposed by a PSBT (Partially Signed Bitcoin Transaction). The key functional change is that when a Passport device is using a temporary seed, it now requires explicit user confirmation before importing a multisig wallet proposed by a PSBT, and cancels signing if the user declines. The commit itself is mostly a changelog entry and unit tests; the actual security logic appears to have been implemented elsewhere.

AI review queuedReject oversized quirc gridsby Jack · 1e6d945b · Aug 13, 2026 · 6 filesMessage 35 · OpaqueModerate 63Details
Commit message · Jack

Reject oversized quirc grids

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
parser or protocol pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Moderate 63/100

This commit adds safety checks to the QR-code scanning library (quirc) used in Passport firmware. It rejects QR grids that are larger than the standard maximum size (version 40, or 177×177 cells) before they can be processed. Without these checks, a malformed or oversized QR code could cause memory corruption or crashes. The commit also fixes an off-by-one bug in grid index validation and adds tests to verify the new limits.

AI review queuedSimplify Casa microSD pairing fileby Jack · 4ca74d48 · Aug 13, 2026 · 1 fileMessage 45 · ThinInformational 18Details
Commit message · Jack

Simplify Casa microSD pairing file

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 18/100

This commit removes several lines of informational text from the Casa wallet pairing file that Passport writes to a microSD card. The deleted text included the blockchain name, coin type, internal symbol, and a generic warning not to deposit funds unless the user's wallet is ready. The remaining file still contains the master extended public key, the Casa derivation extended public key, and the master key fingerprint. There is no code change that alters how keys are derived, stored, or transmitted, and no security vulnerability is visible in the diff.

AI review queuedExport both Casa keys to microSDby Jack · ad5d1343 · Aug 12, 2026 · 1 fileMessage 45 · ThinInformational 19Details
Commit message · Jack

Export both Casa keys to microSD

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit changes how the Passport hardware wallet exports information for the Casa wallet. Previously, only the master extended public key was written to a microSD card. Now, the file also includes the Casa-specific extended public key at derivation path m/45'. This is a feature enhancement to make Casa multisig setup easier, not a security fix. The change does not appear to introduce a vulnerability, but it does export additional key material to removable storage.

AI review queuedExport Casa pairing as a crypto-account QRby Jack · 72fd63cf · Aug 12, 2026 · 5 filesMessage 45 · ThinInformational 24Details
Commit message · Jack

Export Casa pairing as a crypto-account QR

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathparser or protocol pathsecond-pass: security-sensitive path
AI analysis · Informational 24/100

This commit adds a new way for the Passport hardware wallet to export wallet pairing information to Casa, a Bitcoin custody service. Instead of exporting a single key, it now exports a 'crypto-account' QR code containing two related public keys: the wallet's root public key and a separate Casa-specific public key derived from path m/45'. The change is a feature addition; there is no direct evidence in the commit that it fixes a security vulnerability, but it does change what key material is exposed during pairing and how it is encoded.

AI review queuedPreserve SegWit input classificationby Jack · cd0844dc · Aug 10, 2026 · 2 filesMessage 35 · OpaqueModerate 59Details
Commit message · Jack

Preserve SegWit input classification

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Moderate 59/100

This firmware update changes how Passport classifies SegWit Bitcoin transaction inputs. Previously, the device tried to detect SegWit by inspecting the address type and redeem script, and would reject a PSBT that supplied a witness UTXO for what it thought was a non-SegWit input. Now, if a PSBT includes a witness UTXO, the input is marked SegWit immediately. The patch removes several safety checks, which could allow a malicious or malformed PSBT to bypass fee verification or signature checks. The commit message does not describe a security fix, but the change is in security-relevant code.

AI review queuedAdd Bitcoin Safe wallet flowby Jack · 66311050 · Jul 23, 2026 · 3 filesMessage 45 · ThinInformational 15Details
Commit message · Jack

Add Bitcoin Safe wallet flow

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit adds support for a new Bitcoin wallet app called Bitcoin Safe. It is a straightforward feature addition: a new wallet definition file is created and registered in two lists so the Passport device recognizes Bitcoin Safe during setup. There is no bug fix, no change to cryptographic code, and no indication of a security problem.

AI review queuedAdd Coconut Wallet single-sig Connect Wallet optionby Jack · 9d60781d · Jun 17, 2026 · 4 filesMessage 73 · AdequateInformational 18Details
Commit message · Jack

Add Coconut Wallet single-sig Connect Wallet option

Add Coconut Wallet (noncelab) to the Connect Wallet flow. It reuses the
generic single-sig JSON export (same payload as Sparrow) over an animated
UR2 QR code: single-sig QR only, no multisig or microSD.

Tag the export with a "model" field set to "passport-core" so Coconut
Wallet can label the imported wallet "Passport Core" (it shows a single
"Passport" connector and names the wallet from this flag). The field is
gated on the wallet config carrying a 'model' key, so all other wallets'
exports are unchanged.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 18/100

This commit adds support for a new Bitcoin wallet app called Coconut Wallet to the Passport hardware device. It lets users export their single-signature wallet setup to Coconut Wallet via an animated QR code, using the same data format already used for Sparrow Wallet. There is no indication of a security bug or fix in the change.

AI review queuedSFT-7133: fixed dangerous change check on all taproot inputsby Matt Gleason · 46efe834 · Jun 11, 2026 · 1 fileMessage 50 · ThinHigh 70Details
Commit message · Matt Gleason

SFT-7133: fixed dangerous change check on all taproot inputs

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · High 70/100

This firmware update fixes a bug in how Passport checks whether a Bitcoin transaction's 'change' output is safe to send back to the user's own wallet. For modern Taproot-style transactions, the device was skipping an important ownership check on inputs. That could let a malicious or crafted PSBT (Partially Signed Bitcoin Transaction) trick the user into treating someone else's coins as their own change, potentially approving a transaction that sends funds to an attacker while the screen says it is just change.