KX
← All projectsKrux

Krux

Open-source signing firmware for Kendryte K210 devices.

BitcoinHardware walletsNormal
Repository coverage

223 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

58security candidates41second-pass queue216AI analyses
5commits · 30 days
41commits · 60 days
97commits · 180 days
200commits · 365 days
Backfill bands
Aug 5 → Feb 6116 seen6 candidatesComplete
Feb 6 → Jun 639 seen3 candidatesComplete
Jun 6 → Jul 622 seen1 candidatesComplete
Jul 6 → Aug 538 seen5 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

65/100 average clarity
60Strong · 80–100
66Adequate · 60–79
81Thin · 40–59
16Opaque · 0–39
6security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Odudex291429272
odudex902989159
Tads361036063
qlrd18216082
kdmukai424066
tadeubas414038
kkdao12012083
Jean Do1006072
Naman015505060
bitcoisas505066
Naman Gupta202079
SatsCzar202062
Analysis record

Published AI watches

Last scanned 1 hour, 2 minutes ago

Moderate 66 AI analysisMessage 45 · Thin
KX KruxKrux BitcoinHardware wallets

Merge branch 'release-26.08.0'

This is a routine release merge for Krux firmware (version 26.08.0). It includes several genuine security fixes: a heap buffer overflow in camera-based entropy generation for a discontinued device, stricter fee calculation when signing Bit…

Heap buffer overflow fix in camera entropy module (discontinued Maix Bit only)PSBT fee calculation stricter checks and unverified-input-amount warningStored mnemonic file corruption now preserved instead of overwritten
be5eda28by odudex+4335−3028123 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 40 · Thin
KX KruxKrux BitcoinHardware wallets

docs: update CHANGELOG

This commit only updates three date lines in the CHANGELOG.md file, changing '2025' to '2026' for three release entries. It does not modify any source code, build scripts, or documentation with security implications. The change is purely c…

ec058d86by odudex+3−31 file
No security note in commit
Moderate 66 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: bind BBQr parts to the first part of the stream

This commit fixes Krux's QR code scanner so that when it reads a series of animated BBQr codes, every later frame must match the encoding and file type announced by the first frame, must agree on the total number of frames, and cannot over…

Input validation added for multi-part BBQr streamsMemory exhaustion mitigation via accumulated payload capAnti-splicing: parts must agree with first part's encoding and file type
0b3e01b7by odudex+86−13 files
No security note in commit
Informational 15 AI analysisMessage 40 · Thin
KX KruxKrux BitcoinHardware wallets

docs: update CHANGELOG

This commit only updates the project's CHANGELOG.md file. It adds text describing several bug fixes and improvements that were apparently made in prior code changes, but no actual code is changed in this commit. By itself, this documentati…

4c05cefbby odudex+9−11 file
No security note in commit
Informational 0 AI analysisMessage 40 · Thin
KX KruxKrux BitcoinHardware wallets

chore(Maixpy): bump cUR

This commit appears to be a routine version bump of a component called 'cUR' inside the MaixPy firmware build. No actual code changes are visible in the provided diff, and the commit message gives no indication of a security fix or vulnera…

74d6ed40by odudex+1−11 file
No security note in commit
Informational 15 AI analysisMessage 57 · Thin
KX KruxKrux BitcoinHardware wallets

chore: bump version to 26.08.0

This commit is a routine version bump from 26.04.0 to 26.08.0. It only updates version strings in documentation, build files, and source metadata. No code behavior changes. The changelog text mentions a previously fixed heap buffer overflo…

Changelog references a prior heap buffer overflow in Shannon entropy module (camera frame copy into fixed 320x240 RGB565 buffer)No actual code or security fix present in this commit
dea991dfby odudex+5−55 files
Vendor flagged security relevance
Informational 2 AI analysisMessage 57 · Thin
KX KruxKrux BitcoinHardware wallets

chore: bump MaixPy with updated glyphs

This commit appears to update a submodule or dependency called MaixPy to a newer version that includes updated visual glyphs (small icons/symbols). The title and message describe it as a routine maintenance chore, not a security fix. No ac…

a9329228by odudex+1−11 file
No security note in commit
Informational 15 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: register embed_fire in the bdftokff device list

This commit fixes a build-time font-generation script so that a newly supported device ('embed_fire') is recognized. Before the fix, the script printed an error but still produced the same font files. There is no security issue.

f15308e4by odudex+1−01 file
No security note in commit
Moderate 63 AI analysisMessage 57 · Thin
KX KruxKrux BitcoinHardware wallets

docs: add PSBT input amount fixes to CHANGELOG

This commit only updates the project's CHANGELOG.md to document earlier fixes related to PSBT (Partially Signed Bitcoin Transaction) fee and amount handling. It does not contain any code changes itself. The changelog entries describe secur…

Changelog documents prior PSBT fee/amount validation fixesMentions insufficient coordinator data as a security concernNo actual code or test changes in this commit
48920c31by odudex+4−01 file
Vendor flagged security relevance
High 78 AI analysisMessage 95 · Strong
KX KruxKrux BitcoinHardware wallets

fix: verify PSBT input amounts before showing the fee

This commit fixes a security flaw in Krux, a Bitcoin signing device. Before the fix, an attacker could trick the device into showing a low transaction fee on screen while actually signing a much higher fee. The fix makes the device verify …

Fixes fee-display/sighash amount mismatchAdds prevout txid hash verification for non_witness_utxoMandates non_witness_utxo for legacy inputs
fc808059by odudex+353−122 files
Vendor flagged security relevance
Moderate 66 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: reject a PSBT whose outputs exceed its inputs

This commit fixes a bug in Krux, a Bitcoin signing device, where a malformed transaction whose outputs spend more than its inputs could be loaded and shown to the user. Normally such a transaction is impossible on the Bitcoin network, but …

Input validation gap in PSBT parsingUI rendering bug masking invalid transaction economicsPotential social-engineering / user-confusion attack
d6813d88by odudex+52−02 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 50 · Thin
KX KruxKrux BitcoinHardware wallets

i18n: translate the unverified input amounts warning

This commit only adds translations for two existing warning messages in the Krux Bitcoin hardware wallet software. It does not change any code logic, security behavior, or fix any vulnerability. The messages warn users that displayed fees …

bdaed1a1by odudex+46−023 files
No security note in commit
Moderate 62 AI analysisMessage 90 · Strong
KX KruxKrux BitcoinHardware wallets

feat: warn when PSBT input amounts cannot be verified

This commit adds a warning screen to Krux, a hardware signing device, when it is asked to sign a multi-input Bitcoin transaction where the amounts of some inputs cannot be independently verified. The risk is that a malicious transaction co…

New user-facing warning for unverified multi-input SegWit amountsDetection logic tied to BIP143 signature semantics and inp.is_verifiedDoes not enforce previous-transaction inclusion; user can still proceed
518b3314by odudex+159−24 files
Vendor flagged security relevance
Low 27 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: render negative amounts correctly in format_btc

This commit fixes a display bug in how Krux formats negative Bitcoin amounts. Previously, a value like -1000 satoshis was shown incorrectly as roughly -1.99 bitcoins instead of -0.00001 bitcoins, because the code split the number before ha…

UI/display bug in financial amount renderingNo cryptographic, authorization, or memory-safety changesNo input validation, parsing, or serialization of untrusted data changed
c7e48ae1by odudex+22−12 files
No security note in commit
Moderate 53 AI analysisMessage 62 · Adequate
KX KruxKrux BitcoinHardware wallets

docs: add Maix Bit removal and Shannon calc fix to CHANGELOG

This commit is a documentation update to the project's changelog. It describes two security-related changes that were apparently made in earlier code: a heap buffer overflow in the camera-based entropy (randomness) module that could only b…

Heap buffer overflow in camera entropy / Shannon entropy moduleOut-of-bounds write of 49,152 bytes on discontinued Maix Bit deviceRemoval of deterministic os.urandom() PRNG from firmware
b0a7357eby odudex+7−01 file
Vendor flagged security relevance
Moderate 55 AI analysisMessage 82 · Strong
KX KruxKrux BitcoinHardware wallets

chore: bump MaixPy with Shannon changes and RNG removal

This commit updates a bundled firmware component called MaixPy. The commit message says it fixes a 'Shannon heap overflow,' removes an unused random-number binding, and drops support for one hardware variant (Maix Bit). A heap overflow is …

Commit message explicitly mentions fixing a heap overflowRemoval of an unused cryptographic/randomness binding (os.urandom)Submodule bump only; no source-level patch visible in this commit
5c4ece9aby odudex+1−11 file
Vendor flagged security relevance
Moderate 52 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: remove Maix Bit and CIF camera support

This commit removes support for an old, discontinued hardware device called the Maix Bit from the Krux Bitcoin wallet firmware. The commit message says the Maix Bit's camera resolution (CIF) was the only one that fed frames larger than QVG…

Buffer overflow / scratch buffer overflow claimed in commit message (49,152 bytes)Removal of vulnerable hardware code path rather than hardening the entropy moduleDiscontinuation of affected device reduces real-world exposure
8090ac73by odudex+11−1279 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 90 · Strong
KX KruxKrux BitcoinHardware wallets

refactor: use native uUR on tests and simulator

This commit is a routine engineering cleanup: it removes a Python-only compatibility layer (a 'shim') used for testing and simulation, and makes the test environment use the same C-language UR encoder/decoder module that the real hardware …

2fe2f5f5by odudex+108−24919 files
No security note in commit
Low 34 AI analysisMessage 62 · Adequate
KX KruxKrux BitcoinHardware wallets

refactor: catch Exception, not bare except, in parse_wallet fallbacks

This commit tightens error handling in Krux's wallet parsing. Previously, the code used bare 'except:' clauses that would catch everything, including KeyboardInterrupt and SystemExit. Those special exceptions should normally be allowed to …

Bare except clauses replaced with except Exception to avoid swallowing KeyboardInterrupt/SystemExitNew regression test ensures KeyboardInterrupt propagates through all parse_wallet fallback branchesComments explicitly call out untrusted input and interrupt propagation behavior
6f617710by kkdao+42−72 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Lower-priorityMerge pull request #937 from joaozinhom/docs/uv_frozenby Jean Do · 1e7216b1 · Sep 3, 2026 · 2 filesMessage 73 · AdequateTriage 0Details
Commit message · Jean Do

Merge pull request #937 from joaozinhom/docs/uv_frozen

docs: fix the freeze state of the uv auto updating libs when sync.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
merge-commit duplicate discount
Lower-priorityMerge pull request #921 from odudex/ci/bump-actionsby Jean Do · 5c487751 · Aug 30, 2026 · 4 filesMessage 58 · ThinTriage 0Details
Commit message · Jean Do

Merge pull request #921 from odudex/ci/bump-actions

Bump GitHub Actions to Node 24 releases

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
documentation-only discountmerge-commit duplicate discount
Lower-priorityMerge pull request #942 from qlrd/docs/mkdocs-update-installerby Jean Do · 847f164a · Aug 30, 2026 · 2 filesMessage 58 · ThinTriage 0Details
Commit message · Jean Do

Merge pull request #942 from qlrd/docs/mkdocs-update-installer

docs: update mkdocs.yml

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
merge-commit duplicate discount
Lower-prioritydocs: emphasize authencity and integrity check meaningby qlrd · d5d578ee · Aug 29, 2026 · 1 fileMessage 95 · StrongTriage 0Details
Commit message · qlrd

docs: emphasize authencity and integrity check meaning

This commit replaces a simple `/` to `**AND**` in the diff to emphasize
the importance of verify both by the authenticity of the integrity check
file as well the integrity check of binaries itself. With only `/`
someone could not understand the needed meaning to follow a correct
check procedure.

95/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
documentation-only discount
Lower-prioritydocs: update `mkdocs.yml`by qlrd · 6d300df9 · Aug 29, 2026 · 1 fileMessage 78 · AdequateTriage 0Details
Commit message · qlrd

docs: update `mkdocs.yml`

This commit updates `qlrd` contributor key as well update `yaml`
variables that points to correct binaries as well correct authenticity
and integrity check files.

refs #931.

78/100 · AdequateMessage clarity
✓ Descriptive subject✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Lower-priorityMerge pull request #920 from odudex/docs/security-contactsby Jean Do · 8afa9eed · Aug 6, 2026 · 1 fileMessage 63 · AdequateTriage 0Details
Commit message · Jean Do

Merge pull request #920 from odudex/docs/security-contacts

Add Jean Do as Security Contact

63/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
documentation-only discountmerge-commit duplicate discount
Lower-prioritydocs: add Jean Do as security contactby odudex · 1967e16b · Aug 6, 2026 · 1 fileMessage 62 · AdequateTriage 0Details
Commit message · odudex

docs: add Jean Do as security contact

62/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
documentation-only discount
Security candidateMerge branch 'release-26.08.0'by odudex · be5eda28 · Aug 4, 2026 · 123 filesMessage 45 · ThinModerate 66Details
Commit message · odudex

Merge branch 'release-26.08.0'

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet pathboot or update pathmerge-commit duplicate discount
AI analysis · Moderate 66/100

This is a routine release merge for Krux firmware (version 26.08.0). It includes several genuine security fixes: a heap buffer overflow in camera-based entropy generation for a discontinued device, stricter fee calculation when signing Bitcoin transactions, and a warning when a transaction's input amounts cannot be verified. It also swaps the QR-code encoding library for a faster native one, removes support for the discontinued Maix Bit device, and makes various reliability improvements. The commit itself is a large merge, so the exact code changes are spread across many files and not all visible in the supplied diff.

Lower-prioritydocs: update CHANGELOGby odudex · ec058d86 · Aug 3, 2026 · 1 fileMessage 40 · ThinInformational 15Details
Commit message · odudex

docs: update CHANGELOG

40/100 · ThinMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit only updates three date lines in the CHANGELOG.md file, changing '2025' to '2026' for three release entries. It does not modify any source code, build scripts, or documentation with security implications. The change is purely cosmetic/correctional and introduces no security risk.

Lower-priorityfix: bind BBQr parts to the first part of the streamby odudex · 0b3e01b7 · Aug 1, 2026 · 3 filesMessage 85 · StrongModerate 66Details
Commit message · odudex

fix: bind BBQr parts to the first part of the stream

Reject parts that disagree with the first part's encoding, file type or
total, or that conflict with content already stored at the same index.
Bound the accumulated payload at the base32 expansion of the deflate
decompression limit.

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
AI analysis · Moderate 66/100

This commit fixes Krux's QR code scanner so that when it reads a series of animated BBQr codes, every later frame must match the encoding and file type announced by the first frame, must agree on the total number of frames, and cannot overwrite an already-scanned frame with different data. It also caps how much data the scanner will accumulate, preventing a malicious or malformed stream from making the device run out of memory. The change is defensive hardening against QR stream confusion and memory exhaustion.

Lower-prioritydocs: update CHANGELOGby odudex · 4c05cefb · Aug 1, 2026 · 1 fileMessage 40 · ThinInformational 15Details
Commit message · odudex

docs: update CHANGELOG

40/100 · ThinMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit only updates the project's CHANGELOG.md file. It adds text describing several bug fixes and improvements that were apparently made in prior code changes, but no actual code is changed in this commit. By itself, this documentation edit does not alter software behavior or introduce any security issue.

Security candidatechore(Maixpy): bump cURby odudex · 74d6ed40 · Aug 1, 2026 · 1 fileMessage 40 · ThinInformational 0Details
Commit message · odudex

chore(Maixpy): bump cUR

40/100 · ThinMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
boot or update path
AI analysis · Informational 0/100

This commit appears to be a routine version bump of a component called 'cUR' inside the MaixPy firmware build. No actual code changes are visible in the provided diff, and the commit message gives no indication of a security fix or vulnerability. There is nothing here that can be independently assessed as a security issue.

Lower-prioritychore: bump version to 26.08.0by odudex · dea991df · Jul 31, 2026 · 5 filesMessage 57 · ThinInformational 15Details
Commit message · odudex

chore: bump version to 26.08.0

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
AI analysis · Informational 15/100

This commit is a routine version bump from 26.04.0 to 26.08.0. It only updates version strings in documentation, build files, and source metadata. No code behavior changes. The changelog text mentions a previously fixed heap buffer overflow, but that fix is not part of this diff.

Security candidatechore: bump MaixPy with updated glyphsby odudex · a9329228 · Jul 31, 2026 · 1 fileMessage 57 · ThinInformational 2Details
Commit message · odudex

chore: bump MaixPy with updated glyphs

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
boot or update path
AI analysis · Informational 2/100

This commit appears to update a submodule or dependency called MaixPy to a newer version that includes updated visual glyphs (small icons/symbols). The title and message describe it as a routine maintenance chore, not a security fix. No actual code changes are visible in the supplied diff, and no security references were provided.

Security candidatefix: register embed_fire in the bdftokff device listby odudex · f15308e4 · Jul 31, 2026 · 1 fileMessage 85 · StrongInformational 15Details
Commit message · odudex

fix: register embed_fire in the bdftokff device list

The device was added in 26.03.0 but never listed, so glyph generation fell
through to the unmapped-device branch and printed an error on every run.
That branch happened to write the same 16px font, so the generated files
are unchanged by this.

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
Why it was queued
boot or update path
AI analysis · Informational 15/100

This commit fixes a build-time font-generation script so that a newly supported device ('embed_fire') is recognized. Before the fix, the script printed an error but still produced the same font files. There is no security issue.

Security candidatedocs: add PSBT input amount fixes to CHANGELOGby odudex · 48920c31 · Jul 31, 2026 · 1 fileMessage 57 · ThinModerate 63Details
Commit message · odudex

docs: add PSBT input amount fixes to CHANGELOG

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing boundarydocumentation-only discount
AI analysis · Moderate 63/100

This commit only updates the project's CHANGELOG.md to document earlier fixes related to PSBT (Partially Signed Bitcoin Transaction) fee and amount handling. It does not contain any code changes itself. The changelog entries describe security-relevant bugs where incorrect fee/amount calculations could be shown or confirmed during Bitcoin signing, which could trick a user into approving a bad transaction. However, because the actual fixes are not in this commit, we cannot inspect or verify them here.

Security candidatefix: verify PSBT input amounts before showing the feeby odudex · fc808059 · Jul 31, 2026 · 2 filesMessage 95 · StrongHigh 78Details
Commit message · odudex

fix: verify PSBT input amounts before showing the fee

Display, policy and sighash now all read inp.utxo, so the amount on the
review screen is the amount the signer commits to. Any attached previous
transaction must hash to the outpoint being spent, and legacy inputs
require one since their sighash does not commit to the amount.

95/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
signing boundarysigning or wallet path
AI analysis · High 78/100

This commit fixes a security flaw in Krux, a Bitcoin signing device. Before the fix, an attacker could trick the device into showing a low transaction fee on screen while actually signing a much higher fee. The fix makes the device verify that any attached previous transaction really matches the input being spent, and forces legacy (non-Segwit) inputs to include that previous transaction. It also makes sure the amount shown to the user is always the same amount the signature commits to. A small residual risk remains for multi-input Segwit transactions where previous transactions are not required.

Security candidatefix: reject a PSBT whose outputs exceed its inputsby odudex · d6813d88 · Jul 31, 2026 · 2 filesMessage 85 · StrongModerate 66Details
Commit message · odudex

fix: reject a PSBT whose outputs exceed its inputs

Such a transaction is invalid on chain, and it used to render as a small
negative fee with fee_percent clamped to 0.1, so the high fee warning
did not fire either. Fail at load instead.

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
Why it was queued
signing boundarysigning or wallet path
AI analysis · Moderate 66/100

This commit fixes a bug in Krux, a Bitcoin signing device, where a malformed transaction whose outputs spend more than its inputs could be loaded and shown to the user. Normally such a transaction is impossible on the Bitcoin network, but Krux would display it with a tiny negative fee and skip the high-fee warning, potentially tricking a user into approving a transaction that can never be mined. The fix now rejects these PSBTs immediately when loading them.

AI review queuedi18n: translate the unverified input amounts warningby odudex · bdaed1a1 · Jul 31, 2026 · 23 filesMessage 50 · ThinInformational 15Details
Commit message · odudex

i18n: translate the unverified input amounts warning

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
translation-only discountsecond-pass: unusually broad change
AI analysis · Informational 15/100

This commit only adds translations for two existing warning messages in the Krux Bitcoin hardware wallet software. It does not change any code logic, security behavior, or fix any vulnerability. The messages warn users that displayed fees may be understated and that input amounts are unverified, but those warnings already existed in English; this change just makes them available in more languages.

Security candidatefeat: warn when PSBT input amounts cannot be verifiedby odudex · 518b3314 · Jul 31, 2026 · 4 filesMessage 90 · StrongModerate 62Details
Commit message · odudex

feat: warn when PSBT input amounts cannot be verified

BIP143 commits only to the amount of the input being signed, so a
coordinator can declare a different input truthfully in each of two
sessions and combine one valid signature per input. Warn when a
non-taproot PSBT has more than one input and any amount is unbacked
by its previous transaction.

The warning states the risk rather than instructing the user, since a
malicious retry request is indistinguishable from a failed transfer,
and signing the same transaction twice is legitimate when one person
holds more than one key of a multisig.

Translations for the two new strings are still pending.

90/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Names security-relevant behavior explicitly
Why it was queued
signing boundarysigning or wallet path
AI analysis · Moderate 62/100

This commit adds a warning screen to Krux, a hardware signing device, when it is asked to sign a multi-input Bitcoin transaction where the amounts of some inputs cannot be independently verified. The risk is that a malicious transaction coordinator could trick a user into paying a much higher fee than shown, or into signing away more money than intended, by lying about input amounts during separate signing sessions. The patch does not block signing; it only warns the user and asks whether to proceed. It also does not fix the underlying cryptographic gap in older SegWit (BIP143) signatures, which is why the warning is needed.

Lower-priorityfix: render negative amounts correctly in format_btcby odudex · c7e48ae1 · Jul 31, 2026 · 2 filesMessage 85 · StrongLow 27Details
Commit message · odudex

fix: render negative amounts correctly in format_btc

Floor division and modulo round towards minus infinity, so -1000 sats
was shown as -1.99 999 000. Take the sign out before splitting.

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
AI analysis · Low 27/100

This commit fixes a display bug in how Krux formats negative Bitcoin amounts. Previously, a value like -1000 satoshis was shown incorrectly as roughly -1.99 bitcoins instead of -0.00001 bitcoins, because the code split the number before handling the minus sign. The fix simply removes the sign, formats the absolute value, then reattaches the minus sign. It is a user-interface bug, not a wallet-security vulnerability.

Lower-prioritydocs: add Maix Bit removal and Shannon calc fix to CHANGELOGby odudex · b0a7357e · Jul 31, 2026 · 1 fileMessage 62 · AdequateModerate 53Details
Commit message · odudex

docs: add Maix Bit removal and Shannon calc fix to CHANGELOG

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Moderate 53/100

This commit is a documentation update to the project's changelog. It describes two security-related changes that were apparently made in earlier code: a heap buffer overflow in the camera-based entropy (randomness) module that could only be triggered on a discontinued device called the Maix Bit, and the removal of an unused deterministic random function from the firmware. The commit itself only edits the changelog text; it does not contain the actual code fixes.

Security candidatechore: bump MaixPy with Shannon changes and RNG removalby odudex · 5c4ece9a · Jul 31, 2026 · 1 fileMessage 82 · StrongModerate 55Details
Commit message · odudex

chore: bump MaixPy with Shannon changes and RNG removal

Fixes the shannon heap overflow, removes the unused os.urandom binding,
and drops the Maix Bit build project.

82/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body✓ Names security-relevant behavior explicitly
Why it was queued
entropy or randomnessmemory safetyboot or update path
AI analysis · Moderate 55/100

This commit updates a bundled firmware component called MaixPy. The commit message says it fixes a 'Shannon heap overflow,' removes an unused random-number binding, and drops support for one hardware variant (Maix Bit). A heap overflow is a memory corruption bug that can sometimes be exploited to run attacker-controlled code, but the actual code change is just a one-line version bump of a submodule, so we cannot verify the fix from the diff alone.

Security candidatefix: remove Maix Bit and CIF camera supportby odudex · 8090ac73 · Jul 31, 2026 · 9 filesMessage 85 · StrongModerate 52Details
Commit message · odudex

fix: remove Maix Bit and CIF camera support

The device was discontinued in 25.09.0 and has no known users. Its CIF
framesize was the only caller that fed the shannon entropy module a frame
larger than QVGA, overflowing that module's scratch buffer by 49152 bytes.

Also drops the OV5642 sensor handling, which only the Maix Bit used.

85/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Names security-relevant behavior explicitly
Why it was queued
entropy or randomnessmemory safetyboot or update path
AI analysis · Moderate 52/100

This commit removes support for an old, discontinued hardware device called the Maix Bit from the Krux Bitcoin wallet firmware. The commit message says the Maix Bit's camera resolution (CIF) was the only one that fed frames larger than QVGA into a 'shannon entropy' module, overflowing that module's scratch buffer by 49,152 bytes. In plain terms, this is a fix for a buffer overflow bug, but the fix is to delete the only hardware configuration that triggered it rather than enlarge the buffer. Because the device was already discontinued and reportedly has no users, the practical risk is low, but the underlying overflow condition is a real memory-safety issue.

Security candidaterefactor: use native uUR on tests and simulatorby odudex · 2fe2f5f5 · Jul 31, 2026 · 19 filesMessage 90 · StrongInformational 15Details
Commit message · odudex

refactor: use native uUR on tests and simulator

Replace the pure-Python ur/urtypes vendor packages with the uUR CPython
extension built from the bc-ur submodule, so host and device run identical
UR code. Drops the simulator shim that mapped one API onto the other.

Tests now need a C compiler and Python headers.

90/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
signing or wallet pathboot or update path
AI analysis · Informational 15/100

This commit is a routine engineering cleanup: it removes a Python-only compatibility layer (a 'shim') used for testing and simulation, and makes the test environment use the same C-language UR encoder/decoder module that the real hardware device uses. There is no security bug being fixed here; the change is about making tests more realistic and reducing duplicated code.