KX
← All projectsKrux

Krux

Open-source signing firmware for Kendryte K210 devices.

BitcoinHardware walletsNormal
Repository coverage

223 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

58security candidates41second-pass queue216AI analyses
5commits · 30 days
41commits · 60 days
97commits · 180 days
200commits · 365 days
Backfill bands
Aug 5 → Feb 6116 seen6 candidatesComplete
Feb 6 → Jun 639 seen3 candidatesComplete
Jun 6 → Jul 622 seen1 candidatesComplete
Jul 6 → Aug 538 seen5 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

65/100 average clarity
60Strong · 80–100
66Adequate · 60–79
81Thin · 40–59
16Opaque · 0–39
6security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Odudex291429272
odudex902989159
Tads361036063
qlrd18216082
kdmukai424066
tadeubas414038
kkdao12012083
Jean Do1006072
Naman015505060
bitcoisas505066
Naman Gupta202079
SatsCzar202062
Analysis record

Published AI watches

Last scanned 29 minutes ago

Moderate 66 AI analysisMessage 45 · Thin
KX KruxKrux BitcoinHardware wallets

Merge branch 'release-26.08.0'

This is a routine release merge for Krux firmware (version 26.08.0). It includes several genuine security fixes: a heap buffer overflow in camera-based entropy generation for a discontinued device, stricter fee calculation when signing Bit…

Heap buffer overflow fix in camera entropy module (discontinued Maix Bit only)PSBT fee calculation stricter checks and unverified-input-amount warningStored mnemonic file corruption now preserved instead of overwritten
be5eda28by odudex+4335−3028123 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 40 · Thin
KX KruxKrux BitcoinHardware wallets

docs: update CHANGELOG

This commit only updates three date lines in the CHANGELOG.md file, changing '2025' to '2026' for three release entries. It does not modify any source code, build scripts, or documentation with security implications. The change is purely c…

ec058d86by odudex+3−31 file
No security note in commit
Moderate 66 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: bind BBQr parts to the first part of the stream

This commit fixes Krux's QR code scanner so that when it reads a series of animated BBQr codes, every later frame must match the encoding and file type announced by the first frame, must agree on the total number of frames, and cannot over…

Input validation added for multi-part BBQr streamsMemory exhaustion mitigation via accumulated payload capAnti-splicing: parts must agree with first part's encoding and file type
0b3e01b7by odudex+86−13 files
No security note in commit
Informational 15 AI analysisMessage 40 · Thin
KX KruxKrux BitcoinHardware wallets

docs: update CHANGELOG

This commit only updates the project's CHANGELOG.md file. It adds text describing several bug fixes and improvements that were apparently made in prior code changes, but no actual code is changed in this commit. By itself, this documentati…

4c05cefbby odudex+9−11 file
No security note in commit
Informational 0 AI analysisMessage 40 · Thin
KX KruxKrux BitcoinHardware wallets

chore(Maixpy): bump cUR

This commit appears to be a routine version bump of a component called 'cUR' inside the MaixPy firmware build. No actual code changes are visible in the provided diff, and the commit message gives no indication of a security fix or vulnera…

74d6ed40by odudex+1−11 file
No security note in commit
Informational 15 AI analysisMessage 57 · Thin
KX KruxKrux BitcoinHardware wallets

chore: bump version to 26.08.0

This commit is a routine version bump from 26.04.0 to 26.08.0. It only updates version strings in documentation, build files, and source metadata. No code behavior changes. The changelog text mentions a previously fixed heap buffer overflo…

Changelog references a prior heap buffer overflow in Shannon entropy module (camera frame copy into fixed 320x240 RGB565 buffer)No actual code or security fix present in this commit
dea991dfby odudex+5−55 files
Vendor flagged security relevance
Informational 2 AI analysisMessage 57 · Thin
KX KruxKrux BitcoinHardware wallets

chore: bump MaixPy with updated glyphs

This commit appears to update a submodule or dependency called MaixPy to a newer version that includes updated visual glyphs (small icons/symbols). The title and message describe it as a routine maintenance chore, not a security fix. No ac…

a9329228by odudex+1−11 file
No security note in commit
Informational 15 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: register embed_fire in the bdftokff device list

This commit fixes a build-time font-generation script so that a newly supported device ('embed_fire') is recognized. Before the fix, the script printed an error but still produced the same font files. There is no security issue.

f15308e4by odudex+1−01 file
No security note in commit
Moderate 63 AI analysisMessage 57 · Thin
KX KruxKrux BitcoinHardware wallets

docs: add PSBT input amount fixes to CHANGELOG

This commit only updates the project's CHANGELOG.md to document earlier fixes related to PSBT (Partially Signed Bitcoin Transaction) fee and amount handling. It does not contain any code changes itself. The changelog entries describe secur…

Changelog documents prior PSBT fee/amount validation fixesMentions insufficient coordinator data as a security concernNo actual code or test changes in this commit
48920c31by odudex+4−01 file
Vendor flagged security relevance
High 78 AI analysisMessage 95 · Strong
KX KruxKrux BitcoinHardware wallets

fix: verify PSBT input amounts before showing the fee

This commit fixes a security flaw in Krux, a Bitcoin signing device. Before the fix, an attacker could trick the device into showing a low transaction fee on screen while actually signing a much higher fee. The fix makes the device verify …

Fixes fee-display/sighash amount mismatchAdds prevout txid hash verification for non_witness_utxoMandates non_witness_utxo for legacy inputs
fc808059by odudex+353−122 files
Vendor flagged security relevance
Moderate 66 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: reject a PSBT whose outputs exceed its inputs

This commit fixes a bug in Krux, a Bitcoin signing device, where a malformed transaction whose outputs spend more than its inputs could be loaded and shown to the user. Normally such a transaction is impossible on the Bitcoin network, but …

Input validation gap in PSBT parsingUI rendering bug masking invalid transaction economicsPotential social-engineering / user-confusion attack
d6813d88by odudex+52−02 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 50 · Thin
KX KruxKrux BitcoinHardware wallets

i18n: translate the unverified input amounts warning

This commit only adds translations for two existing warning messages in the Krux Bitcoin hardware wallet software. It does not change any code logic, security behavior, or fix any vulnerability. The messages warn users that displayed fees …

bdaed1a1by odudex+46−023 files
No security note in commit
Moderate 62 AI analysisMessage 90 · Strong
KX KruxKrux BitcoinHardware wallets

feat: warn when PSBT input amounts cannot be verified

This commit adds a warning screen to Krux, a hardware signing device, when it is asked to sign a multi-input Bitcoin transaction where the amounts of some inputs cannot be independently verified. The risk is that a malicious transaction co…

New user-facing warning for unverified multi-input SegWit amountsDetection logic tied to BIP143 signature semantics and inp.is_verifiedDoes not enforce previous-transaction inclusion; user can still proceed
518b3314by odudex+159−24 files
Vendor flagged security relevance
Low 27 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: render negative amounts correctly in format_btc

This commit fixes a display bug in how Krux formats negative Bitcoin amounts. Previously, a value like -1000 satoshis was shown incorrectly as roughly -1.99 bitcoins instead of -0.00001 bitcoins, because the code split the number before ha…

UI/display bug in financial amount renderingNo cryptographic, authorization, or memory-safety changesNo input validation, parsing, or serialization of untrusted data changed
c7e48ae1by odudex+22−12 files
No security note in commit
Moderate 53 AI analysisMessage 62 · Adequate
KX KruxKrux BitcoinHardware wallets

docs: add Maix Bit removal and Shannon calc fix to CHANGELOG

This commit is a documentation update to the project's changelog. It describes two security-related changes that were apparently made in earlier code: a heap buffer overflow in the camera-based entropy (randomness) module that could only b…

Heap buffer overflow in camera entropy / Shannon entropy moduleOut-of-bounds write of 49,152 bytes on discontinued Maix Bit deviceRemoval of deterministic os.urandom() PRNG from firmware
b0a7357eby odudex+7−01 file
Vendor flagged security relevance
Moderate 55 AI analysisMessage 82 · Strong
KX KruxKrux BitcoinHardware wallets

chore: bump MaixPy with Shannon changes and RNG removal

This commit updates a bundled firmware component called MaixPy. The commit message says it fixes a 'Shannon heap overflow,' removes an unused random-number binding, and drops support for one hardware variant (Maix Bit). A heap overflow is …

Commit message explicitly mentions fixing a heap overflowRemoval of an unused cryptographic/randomness binding (os.urandom)Submodule bump only; no source-level patch visible in this commit
5c4ece9aby odudex+1−11 file
Vendor flagged security relevance
Moderate 52 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: remove Maix Bit and CIF camera support

This commit removes support for an old, discontinued hardware device called the Maix Bit from the Krux Bitcoin wallet firmware. The commit message says the Maix Bit's camera resolution (CIF) was the only one that fed frames larger than QVG…

Buffer overflow / scratch buffer overflow claimed in commit message (49,152 bytes)Removal of vulnerable hardware code path rather than hardening the entropy moduleDiscontinuation of affected device reduces real-world exposure
8090ac73by odudex+11−1279 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 90 · Strong
KX KruxKrux BitcoinHardware wallets

refactor: use native uUR on tests and simulator

This commit is a routine engineering cleanup: it removes a Python-only compatibility layer (a 'shim') used for testing and simulation, and makes the test environment use the same C-language UR encoder/decoder module that the real hardware …

2fe2f5f5by odudex+108−24919 files
No security note in commit
Low 34 AI analysisMessage 62 · Adequate
KX KruxKrux BitcoinHardware wallets

refactor: catch Exception, not bare except, in parse_wallet fallbacks

This commit tightens error handling in Krux's wallet parsing. Previously, the code used bare 'except:' clauses that would catch everything, including KeyboardInterrupt and SystemExit. Those special exceptions should normally be allowed to …

Bare except clauses replaced with except Exception to avoid swallowing KeyboardInterrupt/SystemExitNew regression test ensures KeyboardInterrupt propagates through all parse_wallet fallback branchesComments explicitly call out untrusted input and interrupt propagation behavior
6f617710by kkdao+42−72 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidatechore(firmware): bump MaixPy to k_quirc + bump uUC + Maixpy cleanupby odudex · 834d75be · May 14, 2026 · 1 fileMessage 62 · AdequateInformational 10Details
Commit message · odudex

chore(firmware): bump MaixPy to k_quirc + bump uUC + Maixpy cleanup

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
boot or update path
AI analysis · Informational 10/100

This commit appears to be a routine maintenance update that bumps the MaixPy firmware submodule to a newer version and updates another component (uUC). The title describes it as a cleanup chore. No actual code changes are visible in the provided diff, and no security-related information is present in the commit message or materials.

Lower-prioritychore: update Embit requires Docker image and toolchain rebuild in order to have compliant python version.by odudex · 5271ebdb · May 14, 2026 · 2 filesMessage 89 · StrongInformational 15Details
Commit message · odudex

chore: update Embit
requires Docker image and toolchain rebuild in order to have compliant python version.

89/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body✓ Explains rationale or failure mode
AI analysis · Informational 15/100

This commit updates the build environment for the Krux project. It changes the Docker base image from an older Debian version (Bullseye with GCC 9.5.0) to a newer one (Bookworm with GCC 12) and updates the bundled 'embit' library. The commit message frames this as a routine maintenance chore needed to keep Python versions compatible. There is no indication in the commit itself that this fixes a security vulnerability.

Lower-prioritydocs: add Stackbit 1248 vertical layout screenshots and documentationby bitcoisas · a7fcea84 · May 14, 2026 · 4 filesMessage 62 · AdequateInformational 15Details
Commit message · bitcoisas

docs: add Stackbit 1248 vertical layout screenshots and documentation

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit only adds documentation screenshots and text describing a vertical layout for the Stackbit 1248 metal backup format. It also updates a simulator script used to capture those screenshots. There is no code change that affects security.

Lower-prioritydocs: add Stackbit 1248 vertical layout to CHANGELOGby bitcoisas · aa2751d9 · May 14, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · bitcoisas

docs: add Stackbit 1248 vertical layout to CHANGELOG

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit only updates the project's CHANGELOG.md file to document a new vertical layout option for the Stackbit 1248 backup display. It adds three lines of text describing a user-facing feature. There are no code changes, no configuration changes, and no security-relevant modifications.

Lower-prioritytest: add tests for Stackbit 1248 vertical layoutby bitcoisas · c6bd35bb · May 14, 2026 · 1 fileMessage 82 · StrongInformational 15Details
Commit message · bitcoisas

test: add tests for Stackbit 1248 vertical layout

Test grouped/compact layouts + 24-word pagination.

82/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body✓ Mentions testing or verification
AI analysis · Informational 15/100

This commit only adds and updates automated tests for a backup-screen layout feature called Stackbit. It does not change any production code, so it cannot introduce a security vulnerability or fix one.

Lower-priorityfeat(i18n): add Standard and Vertical strings for stackbit menuby bitcoisas · effba1bb · May 14, 2026 · 11 filesMessage 62 · AdequateInformational 15Details
Commit message · bitcoisas

feat(i18n): add Standard and Vertical strings for stackbit menu

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
translation-only discount
AI analysis · Informational 15/100

This commit only adds translated text strings for two menu labels, 'Standard' and 'Vertical', used in the stackbit feature. It does not change any program logic, security checks, or data handling. There is no security relevance.

Lower-priorityfeat: add vertical export methods to Stackbit 1248by bitcoisas · e04b36a1 · May 14, 2026 · 2 filesMessage 62 · AdequateInformational 15Details
Commit message · bitcoisas

feat: add vertical export methods to Stackbit 1248

Add grouped and compact export methods.

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
AI analysis · Informational 15/100

This commit adds new on-screen backup layout options for a Bitcoin hardware wallet feature called Stackbit 1248. It only changes how the wallet's seed phrase is drawn on the device display so users can physically punch it into a metal backup card. There is no security vulnerability visible in the change.

Lower-prioritychore(git): ignore AI-assisted configure filesby qlrd · 8c6579a7 · May 11, 2026 · 1 fileMessage 80 · StrongInformational 15Details
Commit message · qlrd

chore(git): ignore AI-assisted configure files

This commit add some common AI configuration files,
such as `CLAUDE.md`, `AGENT.md`, `.cursorrules` and
`.claude/`, since it should be a per-maintainer policy on local
development machine.

80/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This commit only updates the project's .gitignore file to exclude common AI assistant configuration files (like CLAUDE.md, AGENT.md, .cursorrules, and folders such as .claude/). It does not change any executable code, build scripts, cryptographic logic, or user-facing behavior. There is no security relevance.

AI review queuedfeat: add flash_success method to Page class (#853)by Naman Gupta · 2191ddde · May 7, 2026 · 14 filesMessage 93 · StrongInformational 15Details
Commit message · Naman Gupta

feat: add flash_success method to Page class (#853)

added flash_success that uses theme.go_color, giving success confirmations a distinct green color vs default foreground.
Fix #852

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a user-interface polish change: it adds a new green-colored success message method and switches existing success messages from the default text color to green. There is no security-relevant behavior change.

Security candidatefeat: migrate UR encoding to uUR MicroPython C moduleby odudex · 401c70c4 · May 6, 2026 · 12 filesMessage 95 · StrongLow 32Details
Commit message · odudex

feat: migrate UR encoding to uUR MicroPython C module

Switch src/krux from the pure-Python urtypes and foundation-ur-py packages to the new uUR C module (built into MaixPy). The simulator and tests reach the same API surface through a sys.modules shim that re-exports the Python packages.

chore: update to latest Maixpy develop commit

95/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
signing or wallet pathboot or update path
AI analysis · Low 32/100

This commit swaps out the pure-Python QR code encoding/decoding libraries used by the Krux hardware wallet for a new C module called uUR. The stated goal is faster scanning and lower memory use. The change touches code that handles Bitcoin wallet descriptors, seed phrases, and signed transactions (PSBTs). There is no direct evidence in the commit of a security vulnerability, but any rewrite of code that parses cryptographic data deserves careful review because a bug could in theory cause the wallet to misread a transaction or seed. The commit does not describe itself as a security fix.

Lower-prioritychore: update Pillowby odudex · 63f40c37 · May 6, 2026 · 2 filesMessage 40 · ThinLow 29Details
Commit message · odudex

chore: update Pillow

40/100 · ThinMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope! No meaningful explanatory body
AI analysis · Low 29/100

This commit updates the Pillow image-processing library from version 12.1.1 to 12.2.0 in Krux's optional simulator dependencies. The change itself only bumps version numbers and lock-file hashes; it does not modify Krux application code. Pillow 12.2.0 is a routine maintenance release that fixes several bugs and security issues in image handling, so the update is generally beneficial. However, the commit message does not say which vulnerabilities are being addressed, and the diff provides no direct evidence of a specific security problem in Krux.

Lower-prioritychore: drop translate dev dep to remove lxml exposureby odudex · 701f8efd · May 6, 2026 · 4 filesMessage 85 · StrongLow 25Details
Commit message · odudex

chore: drop translate dev dep to remove lxml exposure

Removes the translate package and its i18n auto-fill helper
(print_missing/post_process_translation and the fill* CLI actions).

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
AI analysis · Low 25/100

This commit removes a developer-only translation helper that relied on the 'translate' package, which in turn pulled in the 'lxml' XML-processing library. The stated goal is to reduce exposure to lxml, a large native-code dependency that has a history of security vulnerabilities. The change only affects development tooling and does not alter the actual Krux firmware or wallet code that end users run.

Security candidatefeat(TinyScan): Remove grid from TinyScan #809by Tads · e4f6e788 · May 6, 2026 · 2 filesMessage 65 · AdequateInformational 15Details
Commit message · Tads

feat(TinyScan): Remove grid from TinyScan #809

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
seed or entropy path
AI analysis · Informational 15/100

This commit removes the visual grid lines drawn on camera scans of TinySeed metal backup plates. It is a user-interface improvement to make the punched holes easier to see; it does not change security logic, cryptography, or data handling.

Lower-prioritychore: bump version to 26.04.0by odudex · 00bf26d3 · Apr 22, 2026 · 4 filesMessage 57 · ThinInformational 15Details
Commit message · odudex

chore: bump version to 26.04.0

and add .claude .gitignore

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
AI analysis · Informational 15/100

This commit is a routine version bump from 26.03.1 to 26.04.0 across three configuration/source files, plus adding '.claude' to the .gitignore file. There are no code changes that affect security, functionality, or user behavior.

Security candidateSecurity Hardening (#851)by Odudex · 8f62c860 · Apr 22, 2026 · 9 filesMessage 83 · StrongHigh 74Details
Commit message · Odudex

Security Hardening (#851)

* fix: enforce minimum PBKDF2 iterations in kef.unwrap

A malicious envelope could declare iterations=0 and bypass key
stretching. Reject any envelope below 10000 iterations.

* fix: reject multiple origin-less xpubs in multi-key descriptors

Previously a second origin-less key would silently overwrite the first,
losing cosigner identity. Only the single taproot internal-key
exception remains allowed.

* fix: filter traversal entries from SD listings in file manager

A malicious or corrupted SD card could return names like ".", ".." or entries containing path separators which, concatenated into a path, would allow escaping the current directory. Drop those entries from os.listdir results. The intended ".." up-navigation is unaffected because it is added explicitly by the page.

* fix: add in-session backoff on KEF decryption failures

Track failed KEF decrypt attempts in a RAM-only class counter and sleep with exponentially growing delay (1s, 2s, 4s, capped at 30s) before each new attempt. Reset on success. A power cycle clears the counter, an accepted trade-off to slow interactive brute forcing without writing lockout state to flash.

83/100 · StrongMessage clarity
✓ Descriptive subject✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
access controldefensive validationsigning or wallet path
AI analysis · High 74/100

This commit fixes four security weaknesses in Krux, a Bitcoin hardware-wallet project. The changes prevent: (1) encrypted backups from declaring zero or very low password-stretching effort, which would make them easy to brute-force; (2) multi-signature wallet descriptors from silently accepting multiple cosigners whose identity cannot be verified; (3) a malicious or corrupted SD card from tricking the file manager into leaving its intended folder; and (4) repeated wrong password attempts on encrypted backups by adding growing delays between attempts. All four are hardening fixes rather than a single critical vulnerability.

Lower-priorityfix: validate settings.json on load to prevent OOM and type confusion (#850)by Odudex · e2a8bf7b · Apr 7, 2026 · 3 filesMessage 97 · StrongModerate 68Details
Commit message · Odudex

fix: validate settings.json on load to prevent OOM and type confusion (#850)

Enforces a maximum file size and rejects non-object payloads when loading
settings.json from SD/flash.

97/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference
Why it was queued
defensive validation
AI analysis · Moderate 68/100

This update fixes a security hole in how Krux reads its settings file from an SD card or flash storage. Before, an attacker with physical access could put an abnormally large or oddly shaped settings.json file on the card and crash or confuse the device. Now the device refuses to load any settings.json larger than 8 KB and rejects files whose contents are not a JSON object, falling back to safe default settings instead.

Security candidatefix: add zip bomb protection and QR part limit enforcement (#843) (#848)by Odudex · bd95e828 · Apr 7, 2026 · 10 filesMessage 93 · StrongModerate 66Details
Commit message · Odudex

fix: add zip bomb protection and QR part limit enforcement (#843) (#848)

DeflateIO now enforces a 100KB max decompressed size at the C level, protecting all callers (BBQR and KEF) from zip bomb OOM on K210.
pMofN parser validates part_total (1-99) and part_index range.
BBQR parser validates part_total >= 1.

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
defensive validationboot or update path
AI analysis · Moderate 66/100

This commit fixes two denial-of-service weaknesses in Krux, a Bitcoin hardware-wallet firmware. First, it caps how much data can come out of compressed (deflated) QR codes and encrypted backups, preventing a maliciously crafted 'zip bomb' from exhausting the device's memory. Second, it rejects QR-code part counts that are zero or absurdly high, preventing an attacker from tricking the wallet into reserving unbounded memory while scanning multi-part QR codes.

Security candidatefix: warn user before signing raw hashes in message signing (#846)by Odudex · 23bc73b3 · Apr 6, 2026 · 26 filesMessage 93 · StrongModerate 60Details
Commit message · Odudex

fix: warn user before signing raw hashes in message signing (#846)

Add a warning screen when the input is a raw 32-byte hash or 64-char hex string, alerting the user before signing. This mitigates the risk of an attacker submitting a transaction sighash disguised as a message. Fixes C3 of #843

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
explicit security languagesigning boundarysigning or wallet path
AI analysis · Moderate 60/100

This commit adds a warning screen to Krux's message-signing feature when the user is about to sign a raw 32-byte hash or a 64-character hex string. Previously, the device would silently treat such inputs as already-hashed values and sign them directly. Because a Bitcoin transaction's signature hash (sighash) is also a 32-byte value, an attacker could trick a user into signing what looks like a harmless message but is actually a transaction hash, effectively authorizing a transaction. The fix asks the user to confirm before proceeding.

AI review queuedFix: Reject multisig policies with m=0 or m>n and guard against ZeroDivisionError in fee calculation and (#845)by Odudex · 33982945 · Apr 6, 2026 · 8 filesMessage 93 · StrongModerate 60Details
Commit message · Odudex

Fix: Reject multisig policies with m=0 or m>n and guard against ZeroDivisionError in fee calculation and (#845)

* fix: guard against ZeroDivisionError in fee calculation for zero-value outputs

* fix: validate multisig quorum m>0 and m<=n in key-value wallet files

* chore: bump version to 26.03.01

* fix: Be more specific about invalid multisig quorum errors

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
defensive validationsigning or wallet pathsecond-pass: near security thresholdsecond-pass: security-sensitive path
AI analysis · Moderate 60/100

This update fixes two security issues in Krux, a Bitcoin signing device. First, it prevents the device from crashing when calculating fees for transactions that send no regular bitcoin (only data outputs like OP_RETURN). Second, it now rejects invalid multisig wallet setups where zero signatures are required or where more signatures are required than keys exist, which could otherwise allow unauthorized or impossible spending rules.

Lower-priorityrefactor: remove unreachable code after while true (#842)by Tads · 0237152d · Apr 6, 2026 · 1 fileMessage 70 · AdequateInformational 15Details
Commit message · Tads

refactor: remove unreachable code after while true (#842)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI analysis · Informational 15/100

This commit removes a single line of Python code that could never run. The removed line sat immediately after a `while True:` loop that only exits by returning from the function, so execution could never reach it. It is a harmless cleanup with no security effect.

Lower-priorityrefactor: remove duplicated HEX and OCT digit constants (#841)by Tads · 756c2394 · Apr 6, 2026 · 1 fileMessage 70 · AdequateInformational 15Details
Commit message · Tads

refactor: remove duplicated HEX and OCT digit constants (#841)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI analysis · Informational 15/100

This commit removes two unused duplicate text strings that listed hexadecimal and octal digits from a login-related source file. There is no functional code change, no bug fix, and no security relevance visible in the diff.

Security candidatefix: reject PSBT inputs with non-standard sighash types before signing (#844)by Odudex · e5318112 · Mar 30, 2026 · 3 filesMessage 98 · StrongHigh 78Details
Commit message · Odudex

fix: reject PSBT inputs with non-standard sighash types before signing (#844)

Adds pre-sign validation that refuses to sign if any input requests SIGHASH_NONE, SIGHASH_SINGLE, or ANYONECANPAY, which could allow an attacker to redirect funds after signing. Addresses security audit C2 of #843

98/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
explicit security languagesigning boundarysigning or wallet path
AI analysis · High 78/100

Krux is a small, open-source Bitcoin signing device (hardware wallet). This commit fixes a security flaw where the device would sign transactions even if the sender asked it to use unusual Bitcoin signature modes—specifically SIGHASH_NONE, SIGHASH_SINGLE, or ANYONECANPAY. Those modes can let someone else change where the money goes after the device has already signed, which could be abused to steal funds. The fix makes the device refuse to sign any PSBT (the file format used to pass a transaction around) that contains those non-standard modes. The project labels this as a security fix for an external audit finding.

Lower-prioritychore: bump release versionby odudex · 941c4dfd · Mar 24, 2026 · 3 filesMessage 47 · ThinInformational 15Details
Commit message · odudex

chore: bump release version

47/100 · ThinMessage clarity
✓ Descriptive subject✓ Uses a recognizable type or scope! No meaningful explanatory body
AI analysis · Informational 15/100

This commit only updates three version strings from a beta release to a stable release. It changes no code logic, no security settings, and no dependencies. There is nothing here that affects security.

Lower-prioritychore: Add Embed Fire and WonderK to Actions build scriptby odudex · bf72db24 · Mar 24, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · odudex

chore: Add Embed Fire and WonderK to Actions build script

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit simply adds two new hardware device targets (Embed Fire and WonderK) to the project's automated build script. It is a routine configuration change with no security relevance.

Lower-prioritydocs: update CHANGELOGby odudex · 94760c52 · Mar 24, 2026 · 1 fileMessage 40 · ThinInformational 15Details
Commit message · odudex

docs: update CHANGELOG

40/100 · ThinMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit only updates the title line of the project's CHANGELOG file, changing the placeholder version and date to a concrete release version. It does not modify any code, configuration, or documentation that affects how the software behaves or how secure it is.