KX
← All projectsKrux

Krux

Open-source signing firmware for Kendryte K210 devices.

BitcoinHardware walletsNormal
Repository coverage

223 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

58security candidates41second-pass queue216AI analyses
5commits · 30 days
41commits · 60 days
97commits · 180 days
200commits · 365 days
Backfill bands
Aug 5 → Feb 6116 seen6 candidatesComplete
Feb 6 → Jun 639 seen3 candidatesComplete
Jun 6 → Jul 622 seen1 candidatesComplete
Jul 6 → Aug 538 seen5 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

65/100 average clarity
60Strong · 80–100
66Adequate · 60–79
81Thin · 40–59
16Opaque · 0–39
6security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Odudex291429272
odudex902989159
Tads361036063
qlrd18216082
kdmukai424066
tadeubas414038
kkdao12012083
Jean Do1006072
Naman015505060
bitcoisas505066
Naman Gupta202079
SatsCzar202062
Analysis record

Published AI watches

Last scanned 46 minutes ago

Moderate 66 AI analysisMessage 45 · Thin
KX KruxKrux BitcoinHardware wallets

Merge branch 'release-26.08.0'

This is a routine release merge for Krux firmware (version 26.08.0). It includes several genuine security fixes: a heap buffer overflow in camera-based entropy generation for a discontinued device, stricter fee calculation when signing Bit…

Heap buffer overflow fix in camera entropy module (discontinued Maix Bit only)PSBT fee calculation stricter checks and unverified-input-amount warningStored mnemonic file corruption now preserved instead of overwritten
be5eda28by odudex+4335−3028123 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 40 · Thin
KX KruxKrux BitcoinHardware wallets

docs: update CHANGELOG

This commit only updates three date lines in the CHANGELOG.md file, changing '2025' to '2026' for three release entries. It does not modify any source code, build scripts, or documentation with security implications. The change is purely c…

ec058d86by odudex+3−31 file
No security note in commit
Moderate 66 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: bind BBQr parts to the first part of the stream

This commit fixes Krux's QR code scanner so that when it reads a series of animated BBQr codes, every later frame must match the encoding and file type announced by the first frame, must agree on the total number of frames, and cannot over…

Input validation added for multi-part BBQr streamsMemory exhaustion mitigation via accumulated payload capAnti-splicing: parts must agree with first part's encoding and file type
0b3e01b7by odudex+86−13 files
No security note in commit
Informational 15 AI analysisMessage 40 · Thin
KX KruxKrux BitcoinHardware wallets

docs: update CHANGELOG

This commit only updates the project's CHANGELOG.md file. It adds text describing several bug fixes and improvements that were apparently made in prior code changes, but no actual code is changed in this commit. By itself, this documentati…

4c05cefbby odudex+9−11 file
No security note in commit
Informational 0 AI analysisMessage 40 · Thin
KX KruxKrux BitcoinHardware wallets

chore(Maixpy): bump cUR

This commit appears to be a routine version bump of a component called 'cUR' inside the MaixPy firmware build. No actual code changes are visible in the provided diff, and the commit message gives no indication of a security fix or vulnera…

74d6ed40by odudex+1−11 file
No security note in commit
Informational 15 AI analysisMessage 57 · Thin
KX KruxKrux BitcoinHardware wallets

chore: bump version to 26.08.0

This commit is a routine version bump from 26.04.0 to 26.08.0. It only updates version strings in documentation, build files, and source metadata. No code behavior changes. The changelog text mentions a previously fixed heap buffer overflo…

Changelog references a prior heap buffer overflow in Shannon entropy module (camera frame copy into fixed 320x240 RGB565 buffer)No actual code or security fix present in this commit
dea991dfby odudex+5−55 files
Vendor flagged security relevance
Informational 2 AI analysisMessage 57 · Thin
KX KruxKrux BitcoinHardware wallets

chore: bump MaixPy with updated glyphs

This commit appears to update a submodule or dependency called MaixPy to a newer version that includes updated visual glyphs (small icons/symbols). The title and message describe it as a routine maintenance chore, not a security fix. No ac…

a9329228by odudex+1−11 file
No security note in commit
Informational 15 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: register embed_fire in the bdftokff device list

This commit fixes a build-time font-generation script so that a newly supported device ('embed_fire') is recognized. Before the fix, the script printed an error but still produced the same font files. There is no security issue.

f15308e4by odudex+1−01 file
No security note in commit
Moderate 63 AI analysisMessage 57 · Thin
KX KruxKrux BitcoinHardware wallets

docs: add PSBT input amount fixes to CHANGELOG

This commit only updates the project's CHANGELOG.md to document earlier fixes related to PSBT (Partially Signed Bitcoin Transaction) fee and amount handling. It does not contain any code changes itself. The changelog entries describe secur…

Changelog documents prior PSBT fee/amount validation fixesMentions insufficient coordinator data as a security concernNo actual code or test changes in this commit
48920c31by odudex+4−01 file
Vendor flagged security relevance
High 78 AI analysisMessage 95 · Strong
KX KruxKrux BitcoinHardware wallets

fix: verify PSBT input amounts before showing the fee

This commit fixes a security flaw in Krux, a Bitcoin signing device. Before the fix, an attacker could trick the device into showing a low transaction fee on screen while actually signing a much higher fee. The fix makes the device verify …

Fixes fee-display/sighash amount mismatchAdds prevout txid hash verification for non_witness_utxoMandates non_witness_utxo for legacy inputs
fc808059by odudex+353−122 files
Vendor flagged security relevance
Moderate 66 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: reject a PSBT whose outputs exceed its inputs

This commit fixes a bug in Krux, a Bitcoin signing device, where a malformed transaction whose outputs spend more than its inputs could be loaded and shown to the user. Normally such a transaction is impossible on the Bitcoin network, but …

Input validation gap in PSBT parsingUI rendering bug masking invalid transaction economicsPotential social-engineering / user-confusion attack
d6813d88by odudex+52−02 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 50 · Thin
KX KruxKrux BitcoinHardware wallets

i18n: translate the unverified input amounts warning

This commit only adds translations for two existing warning messages in the Krux Bitcoin hardware wallet software. It does not change any code logic, security behavior, or fix any vulnerability. The messages warn users that displayed fees …

bdaed1a1by odudex+46−023 files
No security note in commit
Moderate 62 AI analysisMessage 90 · Strong
KX KruxKrux BitcoinHardware wallets

feat: warn when PSBT input amounts cannot be verified

This commit adds a warning screen to Krux, a hardware signing device, when it is asked to sign a multi-input Bitcoin transaction where the amounts of some inputs cannot be independently verified. The risk is that a malicious transaction co…

New user-facing warning for unverified multi-input SegWit amountsDetection logic tied to BIP143 signature semantics and inp.is_verifiedDoes not enforce previous-transaction inclusion; user can still proceed
518b3314by odudex+159−24 files
Vendor flagged security relevance
Low 27 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: render negative amounts correctly in format_btc

This commit fixes a display bug in how Krux formats negative Bitcoin amounts. Previously, a value like -1000 satoshis was shown incorrectly as roughly -1.99 bitcoins instead of -0.00001 bitcoins, because the code split the number before ha…

UI/display bug in financial amount renderingNo cryptographic, authorization, or memory-safety changesNo input validation, parsing, or serialization of untrusted data changed
c7e48ae1by odudex+22−12 files
No security note in commit
Moderate 53 AI analysisMessage 62 · Adequate
KX KruxKrux BitcoinHardware wallets

docs: add Maix Bit removal and Shannon calc fix to CHANGELOG

This commit is a documentation update to the project's changelog. It describes two security-related changes that were apparently made in earlier code: a heap buffer overflow in the camera-based entropy (randomness) module that could only b…

Heap buffer overflow in camera entropy / Shannon entropy moduleOut-of-bounds write of 49,152 bytes on discontinued Maix Bit deviceRemoval of deterministic os.urandom() PRNG from firmware
b0a7357eby odudex+7−01 file
Vendor flagged security relevance
Moderate 55 AI analysisMessage 82 · Strong
KX KruxKrux BitcoinHardware wallets

chore: bump MaixPy with Shannon changes and RNG removal

This commit updates a bundled firmware component called MaixPy. The commit message says it fixes a 'Shannon heap overflow,' removes an unused random-number binding, and drops support for one hardware variant (Maix Bit). A heap overflow is …

Commit message explicitly mentions fixing a heap overflowRemoval of an unused cryptographic/randomness binding (os.urandom)Submodule bump only; no source-level patch visible in this commit
5c4ece9aby odudex+1−11 file
Vendor flagged security relevance
Moderate 52 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: remove Maix Bit and CIF camera support

This commit removes support for an old, discontinued hardware device called the Maix Bit from the Krux Bitcoin wallet firmware. The commit message says the Maix Bit's camera resolution (CIF) was the only one that fed frames larger than QVG…

Buffer overflow / scratch buffer overflow claimed in commit message (49,152 bytes)Removal of vulnerable hardware code path rather than hardening the entropy moduleDiscontinuation of affected device reduces real-world exposure
8090ac73by odudex+11−1279 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 90 · Strong
KX KruxKrux BitcoinHardware wallets

refactor: use native uUR on tests and simulator

This commit is a routine engineering cleanup: it removes a Python-only compatibility layer (a 'shim') used for testing and simulation, and makes the test environment use the same C-language UR encoder/decoder module that the real hardware …

2fe2f5f5by odudex+108−24919 files
No security note in commit
Low 34 AI analysisMessage 62 · Adequate
KX KruxKrux BitcoinHardware wallets

refactor: catch Exception, not bare except, in parse_wallet fallbacks

This commit tightens error handling in Krux's wallet parsing. Previously, the code used bare 'except:' clauses that would catch everything, including KeyboardInterrupt and SystemExit. Those special exceptions should normally be allowed to …

Bare except clauses replaced with except Exception to avoid swallowing KeyboardInterrupt/SystemExitNew regression test ensures KeyboardInterrupt propagates through all parse_wallet fallback branchesComments explicitly call out untrusted input and interrupt propagation behavior
6f617710by kkdao+42−72 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Lower-priorityperf(test): stub gc.collect during testsby odudex · 29e4d43b · Jul 27, 2026 · 2 filesMessage 90 · StrongInformational 15Details
Commit message · odudex

perf(test): stub gc.collect during tests

krux calls gc.collect() to manage the device's small heap. On CPython each
call walks the much bigger test heap of mock objects for no benefit: 151s to
118s for the full suite, same coverage.

90/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
AI analysis · Informational 15/100

This commit only changes test infrastructure. It replaces the garbage collector's collect() function with a no-op during automated tests so the test suite runs faster. It does not change any code that runs on real Krux devices or affect how user funds or data are handled.

Security candidatefix(test): fake the clock in test_fill_flash timeout testby qlrd · 9fecf150 · Jul 27, 2026 · 1 fileMessage 95 · StrongInformational 15Details
Commit message · qlrd

fix(test): fake the clock in test_fill_flash timeout test

test_fill_flash_insufficient_entropy_scenario waited 25 real seconds for
MAX_CAPTURE_PERIOD to elapse, spinning ~500k iterations that piled up mock
call records. Patching time.time in fill_flash fires the timeout after 4
frames: 25.1s to 0.09s, same coverage.

95/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
entropy or randomness
AI analysis · Informational 15/100

This commit only changes a test file to make it run faster by faking the system clock. It does not modify any production code, so it has no direct security impact on users of the Krux device or software.

Lower-prioritydocs: document generated mnemonic actionsby Naman015 · c0759d9e · Jul 27, 2026 · 2 filesMessage 57 · ThinInformational 15Details
Commit message · Naman015

docs: document generated mnemonic actions

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit only updates user documentation and the changelog to describe a recent user-interface change for generated mnemonics. It does not modify any code, cryptographic logic, or security behavior, so it has no direct security relevance.

Lower-priorityfeat: simplify generated mnemonic actionsby Naman015 · aed4b007 · Jul 27, 2026 · 1 fileMessage 57 · ThinInformational 15Details
Commit message · Naman015

feat: simplify generated mnemonic actions

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
AI analysis · Informational 15/100

This commit reorganizes the on-screen menu shown after a wallet key is generated or loaded in the Krux firmware. It splits the existing options into a two-level menu for newly generated mnemonics while keeping the old layout for existing ones. There is no security-relevant change visible in the code.

Lower-prioritytest: cover generated mnemonic action flowby Naman015 · 21bd8e4c · Jul 27, 2026 · 1 fileMessage 67 · AdequateInformational 15Details
Commit message · Naman015

test: cover generated mnemonic action flow

67/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
AI analysis · Informational 15/100

This commit only adds new automated tests for the wallet login flow. It does not change any production code, so it cannot introduce a security vulnerability or fix one directly. The tests verify that menu navigation works correctly when a user creates a new wallet from a generated mnemonic versus loading an existing one.

AI review queuedchore(i18n): update generated mnemonic action translationsby Naman015 · 022b70d5 · Jul 27, 2026 · 23 filesMessage 62 · AdequateInformational 15Details
Commit message · Naman015

chore(i18n): update generated mnemonic action translations

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
translation-only discountsecond-pass: unusually broad change
AI analysis · Informational 15/100

This commit is a routine translation update. It adds or updates translated text strings for user interface labels such as "Continue", "Wallet Options", "Standard", and "Vertical" across multiple languages. There are no code logic changes, no security fixes, and no behavior changes.

AI review queueddocs: add generated mnemonic flow screenshotsby Naman015 · 61807e7e · Jul 27, 2026 · 8 filesMessage 57 · ThinInformational 15Details
Commit message · Naman015

docs: add generated mnemonic flow screenshots

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only updates user documentation. It adds new screenshots showing how to create a new wallet mnemonic and updates the script that automatically generates those screenshots. There are no code changes that affect security.

Lower-priorityrefactor: extract wallet info menu helperby odudex · 1b068748 · Jul 27, 2026 · 1 fileMessage 57 · ThinInformational 15Details
Commit message · odudex

refactor: extract wallet info menu helper

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
AI analysis · Informational 15/100

This commit is a simple code cleanup: it pulls duplicated code for drawing a wallet information screen into a single reusable helper function. There is no change to what the program does, no new behavior, and no security issue visible in the diff.

Lower-prioritychore(Embit): bump to fff7ffaby odudex · 77fc9698 · Jul 27, 2026 · 1 fileMessage 57 · ThinInformational 2Details
Commit message · odudex

chore(Embit): bump to fff7ffa

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
AI analysis · Informational 2/100

This commit is a routine dependency update that bumps the bundled 'embit' library to a newer commit. No actual code changes are shown, and no security relevance is stated in the commit message or title.

Lower-prioritydocs(parts): mark Maix Amigo as discontinued, drop sale linksby joaozinhom · 1b311fad · Jul 10, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · joaozinhom

docs(parts): mark Maix Amigo as discontinued, drop sale links

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit only updates project documentation. It removes shopping links for a discontinued hardware device and adds a note that the device is no longer for sale. There is no code change and no security relevance.

Lower-prioritychore: remove unused color constantsby qlrd · 3c5f395c · Jul 10, 2026 · 1 fileMessage 88 · StrongInformational 15Details
Commit message · qlrd

chore: remove unused color constants

This commit removes two constants on `src/krux/themes.py` once the
`vulture` tool found with a 60% of confidence their possibility to be a
dead code.

Fix #900

Co-authored-by: Naman Gupta <55298452+Naman015@users.noreply.github.com>

88/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
AI analysis · Informational 15/100

This is a routine cleanup commit that deletes two unused color constants (LIGHTGREY and PURPLE) from a theme file. It does not change any behavior, fix any bug, or alter any security-related logic.

Lower-prioritydocs(parts): mark Maix Amigo as discontinued, drop sale linksby joaozinhom · 7ea3f95e · Jul 10, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · joaozinhom

docs(parts): mark Maix Amigo as discontinued, drop sale links

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit only updates project documentation. It marks the Maix Amigo hardware device as discontinued and removes links to stores that used to sell it. There are no code changes and no security implications.

Security candidatechore: update cUR and k_quirkby odudex · f4796afe · Jul 8, 2026 · 1 fileMessage 57 · ThinInformational 0Details
Commit message · odudex

chore: update cUR and k_quirk

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
boot or update path
AI analysis · Informational 0/100

The commit title says it is a routine maintenance update ('chore') for two internal items named cUR and k_quirk in the MaixPy firmware file. No diff content is available, and no verified references were supplied, so there is no visible evidence of any security change.

Security candidatefix: pin gcc base image by digestby odudex · ceefbb19 · Jul 8, 2026 · 1 fileMessage 57 · ThinLow 25Details
Commit message · odudex

fix: pin gcc base image by digest

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
access control
AI analysis · Low 25/100

This change locks the Docker build to one specific, unchangeable version of the GCC compiler image by adding a cryptographic fingerprint (SHA digest). Without this, an attacker who compromises the GCC image registry could silently replace the 'gcc:12-bookworm' image with a malicious one, potentially injecting backdoors into Krux firmware builds. Pinning by digest prevents the build from accepting a substituted image, but it does not fix any already-known vulnerability in the code itself.

Lower-priorityfix: add src to poe task PYTHONPATHby odudex · 566a0b93 · Jul 2, 2026 · 1 fileMessage 80 · StrongInformational 15Details
Commit message · odudex

fix: add src to poe task PYTHONPATH

Ensure poe-launched commands can import the local krux package under uv, where the project itself is not installed as a package.

80/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This commit adjusts how a Python build tool (poe) finds the project's own source code when running commands. It adds the local 'src' directory to the PYTHONPATH environment variable for poe tasks. There is no indication this is a security fix; it is a development workflow fix to make local imports work correctly under the 'uv' packaging tool.

AI review queuedfix: preserve corrupt seeds.json instead of overwriting on storeby odudex · e44d4324 · Jul 2, 2026 · 4 filesMessage 85 · StrongModerate 54Details
Commit message · odudex

fix: preserve corrupt seeds.json instead of overwriting on store

store_encrypted_kef raises StorageCorruptedError and leaves the file
untouched when an existing seeds.json is malformed or a non-dict, rather
than silently overwriting recoverable data. list_mnemonics returns [] for
non-dict storage so corrupt files no longer crash the menu; the UI reports
the corruption (English-only) and skips the store.

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
Why it was queued
second-pass: broader security terminology
AI analysis · Moderate 54/100

This commit fixes a bug in Krux, a Bitcoin hardware-wallet tool, where saving a new encrypted seed could silently overwrite a damaged seeds.json file. The patch makes the app detect corrupt or misshapen seed storage and stop the save, preserving the existing file so the user can recover it. It also prevents the seed list menu from crashing when the stored file is malformed. There is no evidence this was a malicious backdoor; it appears to be a defensive bug fix.

Lower-priorityfix: return None when decrypting an unknown or non-dict mnemonic idby kkdao · a2882082 · Jul 2, 2026 · 2 filesMessage 95 · StrongLow 29Details
Commit message · kkdao

fix: return None when decrypting an unknown or non-dict mnemonic id

MnemonicStorage.decrypt() resolved the id inside a try/except but then
called stored_value.get("b64_kef") outside it, so an unknown id (where
storage.get returns None) raised AttributeError instead of returning None.
A malformed seeds.json that parses to a non-dict (e.g. a JSON list) hit the
same path. Resolve the source dict and return None when the id is missing
or the stored entry isn't a dict -- no bare except, behaviour now tested.

The sole caller wraps the call in try/except, so this changes no on-device
behaviour; it gives decrypt() a clean return contract.

95/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
AI analysis · Low 29/100

This commit fixes a small bug in how Krux loads saved encrypted seed data. Previously, if the saved file was valid JSON but shaped like a list instead of a dictionary, or if the requested seed ID was missing, the code could crash with an AttributeError instead of cleanly returning None. The fix makes the code treat those cases as 'nothing found' and adds tests to confirm it. The commit message says the on-device behavior is unchanged because the only caller already catches exceptions.

Lower-priorityrefactor: narrow mnemonic storage file-load errorsby kkdao · aebbfc92 · Jul 2, 2026 · 2 filesMessage 85 · StrongLow 34Details
Commit message · kkdao

refactor: narrow mnemonic storage file-load errors

The four read/load fallbacks in MnemonicStorage caught everything with a
bare `except:`, hiding unexpected errors (and on the K210 even
KeyboardInterrupt/MemoryError). Narrow them to the file/JSON errors they
actually expect -- (OSError, ValueError) -- matching the OSError
convention already used in sd_card.py. Behaviour for a missing/unreadable
file or malformed JSON is unchanged (storage starts empty / first store
still writes); a genuinely unexpected error now propagates instead of
hiding.

The decrypt and write catches stay broad on purpose (wrong-key /
failed-save contracts) and are now commented as such.

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
AI analysis · Low 34/100

This commit is a defensive code cleanup, not an active vulnerability fix. It narrows four broad 'catch-everything' error handlers in the wallet's encrypted mnemonic storage module so they only ignore expected file/JSON problems. Unexpected errors (including serious ones like memory exhaustion or user cancellation) now surface instead of being silently swallowed. The change improves future bug detection and reliability but does not by itself create or close a known exploit.

AI review queuedrefactor: drop non-dict JSON coercion in encryption storageby kkdao · 2d195ad3 · Jul 2, 2026 · 2 filesMessage 85 · StrongLow 35Details
Commit message · kkdao

refactor: drop non-dict JSON coercion in encryption storage

Loading seeds.json no longer coerces valid-but-non-dict JSON to an
empty dict, so a wrong-shape file is preserved instead of being
silently overwritten on the next store. decrypt() keeps the
isinstance(source, dict) guard that prevents a crash on such files.

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
Why it was queued
second-pass: broader security terminology
AI analysis · Low 35/100

This commit changes how Krux loads its encrypted seed storage file. Previously, if the file contained valid JSON but in the wrong shape (for example, a list instead of a dictionary), the app would silently treat it as empty and overwrite it on the next save. Now the app keeps the file's original contents and relies on a separate safety check to avoid crashing. The change is described as a code cleanup, but it also removes a behavior that could hide or destroy user data if a storage file were tampered with or corrupted.

Lower-priorityfix: improve default theme contrast (#879)by Naman Gupta · 782735a6 · Jun 23, 2026 · 5 filesMessage 65 · AdequateInformational 15Details
Commit message · Naman Gupta

fix: improve default theme contrast (#879)

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI analysis · Informational 15/100

This commit adjusts color values in the Krux device's user interface themes to improve text and icon contrast. It is purely a visual accessibility/usability fix and does not change any security-sensitive logic, cryptography, input handling, or network behavior.

Lower-priorityrefactor: cache Settings() namespace tree as a singletonby odudex · 0f28c9a7 · Jun 23, 2026 · 2 filesMessage 85 · StrongInformational 13Details
Commit message · odudex

refactor: cache Settings() namespace tree as a singleton

Avoids rebuilding ~16 namespace objects on every Settings() call;
values are still read live from the store singleton.

Reset the cache in mock_retro_compatibility so the patched
DefaultWallet is picked up.

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
AI analysis · Informational 13/100

This commit is a performance refactor, not a security fix. It caches a single copy of the app's settings object tree so it doesn't rebuild ~16 objects every time code asks for Settings(). The actual setting values are still read fresh from storage, so behavior should not change. A test helper is updated to clear that cache so a mocked wallet class gets picked up during tests.

Lower-priorityrefactor: dedupe flipped-orientation check in touch.py via is_flipped_orientationby kkdao · a0924c7c · Jun 17, 2026 · 2 filesMessage 62 · AdequateInformational 15Details
Commit message · kkdao

refactor: dedupe flipped-orientation check in touch.py via is_flipped_orientation

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
AI analysis · Informational 15/100

This commit is a simple code cleanup: it replaces two copies of the same display-orientation check with a single shared helper method. There is no security-relevant change in behavior; the logic before and after is functionally identical.

Security candidatedocs: update `poetry` to `uv commandsby qlrd · 55c72c34 · Jun 17, 2026 · 4 filesMessage 57 · ThinInformational 15Details
Commit message · qlrd

docs: update `poetry` to `uv commands

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
boot or update pathdocumentation-only discount
AI analysis · Informational 15/100

This commit only updates developer documentation, replacing instructions that mentioned the Poetry Python tool with instructions for the uv Python tool. No code, dependencies, or security behavior changed.

Lower-prioritychore: update `poetry` to `uv` commands.by qlrd · 5752a688 · Jun 17, 2026 · 3 filesMessage 57 · ThinInformational 15Details
Commit message · qlrd

chore: update `poetry` to `uv` commands.

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
AI analysis · Informational 15/100

This commit is a routine developer tooling change. It replaces the 'poetry' command with the 'uv' command in documentation and a screenshot-generation script, and adds a single trailing comma in one Python file. There is no change to the actual Krux wallet application that users run, and no security-relevant behavior is modified.

Lower-priorityfeat: replace `poetry` to `uv` as venv managerby qlrd · a8eca7c8 · Jun 17, 2026 · 3 filesMessage 90 · StrongInformational 15Details
Commit message · qlrd

feat: replace `poetry` to `uv` as venv manager

This commit replaces the current virtualenv manager to `uv`. It's a
battle tested one and well accepted by community. It do not changes the
current behaviour of `poe` tasks, instead, we noted a faster run with
this manager.

90/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
AI analysis · Informational 15/100

This commit swaps the project's Python virtual-environment and dependency-lock tooling from Poetry to uv. It deletes the old Poetry lockfile (poetry.lock), updates pyproject.toml to use uv-compatible metadata, and adds a new uv lockfile (uv.lock). There is no change to application source code, runtime behavior, or installed dependencies, and nothing in the commit indicates a security fix or vulnerability.