KX
← All projectsKrux

Krux

Open-source signing firmware for Kendryte K210 devices.

BitcoinHardware walletsNormal
Repository coverage

223 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

58security candidates41second-pass queue216AI analyses
5commits · 30 days
41commits · 60 days
97commits · 180 days
200commits · 365 days
Backfill bands
Aug 5 → Feb 6116 seen6 candidatesComplete
Feb 6 → Jun 639 seen3 candidatesComplete
Jun 6 → Jul 622 seen1 candidatesComplete
Jul 6 → Aug 538 seen5 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

65/100 average clarity
60Strong · 80–100
66Adequate · 60–79
81Thin · 40–59
16Opaque · 0–39
6security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Odudex291429272
odudex902989159
Tads361036063
qlrd18216082
kdmukai424066
tadeubas414038
kkdao12012083
Jean Do1006072
Naman015505060
bitcoisas505066
Naman Gupta202079
SatsCzar202062
Analysis record

Published AI watches

Last scanned 50 minutes ago

Moderate 66 AI analysisMessage 45 · Thin
KX KruxKrux BitcoinHardware wallets

Merge branch 'release-26.08.0'

This is a routine release merge for Krux firmware (version 26.08.0). It includes several genuine security fixes: a heap buffer overflow in camera-based entropy generation for a discontinued device, stricter fee calculation when signing Bit…

Heap buffer overflow fix in camera entropy module (discontinued Maix Bit only)PSBT fee calculation stricter checks and unverified-input-amount warningStored mnemonic file corruption now preserved instead of overwritten
be5eda28by odudex+4335−3028123 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 40 · Thin
KX KruxKrux BitcoinHardware wallets

docs: update CHANGELOG

This commit only updates three date lines in the CHANGELOG.md file, changing '2025' to '2026' for three release entries. It does not modify any source code, build scripts, or documentation with security implications. The change is purely c…

ec058d86by odudex+3−31 file
No security note in commit
Moderate 66 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: bind BBQr parts to the first part of the stream

This commit fixes Krux's QR code scanner so that when it reads a series of animated BBQr codes, every later frame must match the encoding and file type announced by the first frame, must agree on the total number of frames, and cannot over…

Input validation added for multi-part BBQr streamsMemory exhaustion mitigation via accumulated payload capAnti-splicing: parts must agree with first part's encoding and file type
0b3e01b7by odudex+86−13 files
No security note in commit
Informational 15 AI analysisMessage 40 · Thin
KX KruxKrux BitcoinHardware wallets

docs: update CHANGELOG

This commit only updates the project's CHANGELOG.md file. It adds text describing several bug fixes and improvements that were apparently made in prior code changes, but no actual code is changed in this commit. By itself, this documentati…

4c05cefbby odudex+9−11 file
No security note in commit
Informational 0 AI analysisMessage 40 · Thin
KX KruxKrux BitcoinHardware wallets

chore(Maixpy): bump cUR

This commit appears to be a routine version bump of a component called 'cUR' inside the MaixPy firmware build. No actual code changes are visible in the provided diff, and the commit message gives no indication of a security fix or vulnera…

74d6ed40by odudex+1−11 file
No security note in commit
Informational 15 AI analysisMessage 57 · Thin
KX KruxKrux BitcoinHardware wallets

chore: bump version to 26.08.0

This commit is a routine version bump from 26.04.0 to 26.08.0. It only updates version strings in documentation, build files, and source metadata. No code behavior changes. The changelog text mentions a previously fixed heap buffer overflo…

Changelog references a prior heap buffer overflow in Shannon entropy module (camera frame copy into fixed 320x240 RGB565 buffer)No actual code or security fix present in this commit
dea991dfby odudex+5−55 files
Vendor flagged security relevance
Informational 2 AI analysisMessage 57 · Thin
KX KruxKrux BitcoinHardware wallets

chore: bump MaixPy with updated glyphs

This commit appears to update a submodule or dependency called MaixPy to a newer version that includes updated visual glyphs (small icons/symbols). The title and message describe it as a routine maintenance chore, not a security fix. No ac…

a9329228by odudex+1−11 file
No security note in commit
Informational 15 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: register embed_fire in the bdftokff device list

This commit fixes a build-time font-generation script so that a newly supported device ('embed_fire') is recognized. Before the fix, the script printed an error but still produced the same font files. There is no security issue.

f15308e4by odudex+1−01 file
No security note in commit
Moderate 63 AI analysisMessage 57 · Thin
KX KruxKrux BitcoinHardware wallets

docs: add PSBT input amount fixes to CHANGELOG

This commit only updates the project's CHANGELOG.md to document earlier fixes related to PSBT (Partially Signed Bitcoin Transaction) fee and amount handling. It does not contain any code changes itself. The changelog entries describe secur…

Changelog documents prior PSBT fee/amount validation fixesMentions insufficient coordinator data as a security concernNo actual code or test changes in this commit
48920c31by odudex+4−01 file
Vendor flagged security relevance
High 78 AI analysisMessage 95 · Strong
KX KruxKrux BitcoinHardware wallets

fix: verify PSBT input amounts before showing the fee

This commit fixes a security flaw in Krux, a Bitcoin signing device. Before the fix, an attacker could trick the device into showing a low transaction fee on screen while actually signing a much higher fee. The fix makes the device verify …

Fixes fee-display/sighash amount mismatchAdds prevout txid hash verification for non_witness_utxoMandates non_witness_utxo for legacy inputs
fc808059by odudex+353−122 files
Vendor flagged security relevance
Moderate 66 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: reject a PSBT whose outputs exceed its inputs

This commit fixes a bug in Krux, a Bitcoin signing device, where a malformed transaction whose outputs spend more than its inputs could be loaded and shown to the user. Normally such a transaction is impossible on the Bitcoin network, but …

Input validation gap in PSBT parsingUI rendering bug masking invalid transaction economicsPotential social-engineering / user-confusion attack
d6813d88by odudex+52−02 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 50 · Thin
KX KruxKrux BitcoinHardware wallets

i18n: translate the unverified input amounts warning

This commit only adds translations for two existing warning messages in the Krux Bitcoin hardware wallet software. It does not change any code logic, security behavior, or fix any vulnerability. The messages warn users that displayed fees …

bdaed1a1by odudex+46−023 files
No security note in commit
Moderate 62 AI analysisMessage 90 · Strong
KX KruxKrux BitcoinHardware wallets

feat: warn when PSBT input amounts cannot be verified

This commit adds a warning screen to Krux, a hardware signing device, when it is asked to sign a multi-input Bitcoin transaction where the amounts of some inputs cannot be independently verified. The risk is that a malicious transaction co…

New user-facing warning for unverified multi-input SegWit amountsDetection logic tied to BIP143 signature semantics and inp.is_verifiedDoes not enforce previous-transaction inclusion; user can still proceed
518b3314by odudex+159−24 files
Vendor flagged security relevance
Low 27 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: render negative amounts correctly in format_btc

This commit fixes a display bug in how Krux formats negative Bitcoin amounts. Previously, a value like -1000 satoshis was shown incorrectly as roughly -1.99 bitcoins instead of -0.00001 bitcoins, because the code split the number before ha…

UI/display bug in financial amount renderingNo cryptographic, authorization, or memory-safety changesNo input validation, parsing, or serialization of untrusted data changed
c7e48ae1by odudex+22−12 files
No security note in commit
Moderate 53 AI analysisMessage 62 · Adequate
KX KruxKrux BitcoinHardware wallets

docs: add Maix Bit removal and Shannon calc fix to CHANGELOG

This commit is a documentation update to the project's changelog. It describes two security-related changes that were apparently made in earlier code: a heap buffer overflow in the camera-based entropy (randomness) module that could only b…

Heap buffer overflow in camera entropy / Shannon entropy moduleOut-of-bounds write of 49,152 bytes on discontinued Maix Bit deviceRemoval of deterministic os.urandom() PRNG from firmware
b0a7357eby odudex+7−01 file
Vendor flagged security relevance
Moderate 55 AI analysisMessage 82 · Strong
KX KruxKrux BitcoinHardware wallets

chore: bump MaixPy with Shannon changes and RNG removal

This commit updates a bundled firmware component called MaixPy. The commit message says it fixes a 'Shannon heap overflow,' removes an unused random-number binding, and drops support for one hardware variant (Maix Bit). A heap overflow is …

Commit message explicitly mentions fixing a heap overflowRemoval of an unused cryptographic/randomness binding (os.urandom)Submodule bump only; no source-level patch visible in this commit
5c4ece9aby odudex+1−11 file
Vendor flagged security relevance
Moderate 52 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: remove Maix Bit and CIF camera support

This commit removes support for an old, discontinued hardware device called the Maix Bit from the Krux Bitcoin wallet firmware. The commit message says the Maix Bit's camera resolution (CIF) was the only one that fed frames larger than QVG…

Buffer overflow / scratch buffer overflow claimed in commit message (49,152 bytes)Removal of vulnerable hardware code path rather than hardening the entropy moduleDiscontinuation of affected device reduces real-world exposure
8090ac73by odudex+11−1279 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 90 · Strong
KX KruxKrux BitcoinHardware wallets

refactor: use native uUR on tests and simulator

This commit is a routine engineering cleanup: it removes a Python-only compatibility layer (a 'shim') used for testing and simulation, and makes the test environment use the same C-language UR encoder/decoder module that the real hardware …

2fe2f5f5by odudex+108−24919 files
No security note in commit
Low 34 AI analysisMessage 62 · Adequate
KX KruxKrux BitcoinHardware wallets

refactor: catch Exception, not bare except, in parse_wallet fallbacks

This commit tightens error handling in Krux's wallet parsing. Previously, the code used bare 'except:' clauses that would catch everything, including KeyboardInterrupt and SystemExit. Those special exceptions should normally be allowed to …

Bare except clauses replaced with except Exception to avoid swallowing KeyboardInterrupt/SystemExitNew regression test ensures KeyboardInterrupt propagates through all parse_wallet fallback branchesComments explicitly call out untrusted input and interrupt propagation behavior
6f617710by kkdao+42−72 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Lower-prioritydocs: update changelog following up #820by odudex · 5ae4ff5b · Jan 22, 2026 · 1 fileMessage 65 · AdequateInformational 15Details
Commit message · odudex

docs: update changelog following up #820

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit only adds one line to the changelog file describing a previously merged feature. It does not change any code, configuration, or executable behavior. There is no security-relevant change in the diff itself.

AI review queuedrefactor: black following up #820by odudex · 7644f965 · Jan 22, 2026 · 2 filesMessage 65 · AdequateInformational 15Details
Commit message · odudex

refactor: black following up #820

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is purely a code-style cleanup. It removes an extra blank line and adjusts spacing around a comment so the code matches the project's formatting rules (the 'black' formatter). No behavior of the wallet software changes, and there is no security fix or vulnerability introduced.

Security candidatefix: printer not changing TX/RX pin (#810)by Tads · 97d37c44 · Jan 22, 2026 · 2 filesMessage 65 · AdequateLow 28Details
Commit message · Tads

fix: printer not changing TX/RX pin (#810)

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
access control
AI analysis · Low 28/100

This commit fixes a bug where the Krux device could not switch which physical pins it uses to talk to a printer. The change forces the hardware to reassign the printer's data pins (TX/RX) even if they were already mapped to something else. This is a functional bug fix rather than a clear security patch, but incorrect pin mapping could in theory cause a printer to misbehave or leak data on the wrong pins.

AI review queuedSimplify internal key validation for taproot (#820)by Pac · 5dcab5f0 · Jan 22, 2026 · 2 filesMessage 96 · StrongLow 34Details
Commit message · Pac

Simplify internal key validation for taproot (#820)

* Simplify internal key validation for taproot

There is no standard for how to generate the taproot keypath chaincode to be used with the NUMS pubkey.
Liana does it by hashing the taptree keys;
Coldcard uses a random chaincode;
Nunchuck hashes the taptree keys, but remove duplicates and sort the keys before hashing.
This fix changes the verification logic to check only the NUMS pubkey and ignore the chaincode.

* Allow loading of non-deterministic chain code in wallet

The wallet now loads the non-deterministic chain code without raising an error, indicating it is considered valid.

96/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
defensive validationsigning or wallet pathsecond-pass: near security thresholdsecond-pass: security-sensitive path
AI analysis · Low 34/100

This change relaxes how Krux checks the 'internal key' used in Taproot multisig wallets. Previously it required the wallet to use a specific deterministic chain code derived from the other public keys; now it only checks that the internal key is the well-known NUMS (provably unspendable) public key and ignores the chain code. This makes Krux compatible with wallets like Coldcard and Nunchuck that use different chain-code conventions, but it removes a validation step that ensured the internal key was constructed in a specific reproducible way.

AI review queuedchore: update black follow-upby odudex · 6695d325 · Jan 22, 2026 · 8 filesMessage 57 · ThinInformational 15Details
Commit message · odudex

chore: update black follow-up

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only removes blank lines between import blocks in eight Python files. It is a code-formatting cleanup with no functional changes and no security relevance.

Security candidatechore: update blackby odudex · acf84c93 · Jan 22, 2026 · 3 filesMessage 40 · ThinInformational 15Details
Commit message · odudex

chore: update black

40/100 · ThinMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
boot or update path
AI analysis · Informational 15/100

This is a routine developer maintenance commit that updates the Black code formatter from version 25 to version 26, refreshes the Poetry lockfile with newer versions of many development and documentation dependencies, and applies one tiny formatting change (removing a blank line) in a font conversion script. There is no indication of any security fix or vulnerability being addressed.

Lower-priorityfix: build process (#823)by Tads · eab445b5 · Jan 22, 2026 · 1 fileMessage 55 · ThinInformational 18Details
Commit message · Tads

fix: build process (#823)

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI analysis · Informational 18/100

This commit changes how a build container downloads a third-party compiler toolchain. The old command tried to clone submodules in one step from the original binutils-gdb repository, which appears to be unavailable or moved. The new approach clones the main repository first, then redirects the submodule URL to an archived copy before initializing submodules. This is a build-fix change, not an obvious security patch, but it does alter which source code is pulled into the build environment.

Lower-prioritydocs: update telegram group linkby odudex · 97d1fb3c · Jan 13, 2026 · 3 filesMessage 57 · ThinInformational 15Details
Commit message · odudex

docs: update telegram group link

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
AI analysis · Informational 15/100

This commit simply updates the project's Telegram support group link from an old group name to a new one across three documentation files. It does not change any code, security settings, or functionality.

Lower-prioritydocs: update telegram group linkby odudex · bff65f4f · Jan 13, 2026 · 3 filesMessage 57 · ThinInformational 15Details
Commit message · odudex

docs: update telegram group link

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
AI analysis · Informational 15/100

This commit simply updates the project's Telegram support group link from one URL (t.me/SC_Krux) to another (t.me/KruxDIY) in three documentation files. It is a routine documentation change with no security relevance.

AI review queuedfeat: Loading a Descriptor Sets Wallet Attributes (#802)by Odudex · 86340f31 · Dec 17, 2025 · 31 filesMessage 93 · StrongLow 35Details
Commit message · Odudex

feat: Loading a Descriptor Sets Wallet Attributes (#802)

*feat: loading a descriptor sets wallet attributes

*feat: remove the feature to load xpubs as they were descriptors, with or without assumptions.

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Low 35/100

This commit changes how Krux handles wallet descriptors. Instead of requiring users to manually set wallet type (single-sig, multisig, miniscript), network (mainnet/testnet), and address format, Krux now reads these directly from the descriptor. It also removes the old feature that tried to guess these settings from raw xpubs, which could make unsafe assumptions. When a loaded descriptor doesn't match the currently configured wallet, Krux now shows a clear warning and asks the user whether to switch settings automatically. Overall this is a security-hardening and usability improvement, not an introduced vulnerability.

Lower-prioritydocs: add lavarand (#764)by Tads · b7484133 · Dec 10, 2025 · 1 fileMessage 55 · ThinInformational 15Details
Commit message · Tads

docs: add lavarand (#764)

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit only updates user documentation. It adds a footnote comparing Krux's camera-based mnemonic generation to an old system called Lavarand, and rewords some explanatory text about entropy quality indicators. No code, cryptography, or device behavior was changed.

Lower-priorityfix: adjust fingerprint warning message for rare case (#801)by Tads · 11791084 · Dec 10, 2025 · 2 filesMessage 70 · AdequateLow 32Details
Commit message · Tads

fix: adjust fingerprint warning message for rare case (#801)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI analysis · Low 32/100

This commit fixes a warning message that was being shown to users at the wrong time. The Krux device signs Bitcoin transactions using PSBT files. In rare cases, the device needs to fill in a missing 'fingerprint' (a short identifier for a wallet key) with zeros before signing. The warning 'Fingerprint unset in PSBT' was being displayed whenever this zero-fill happened, even when the wallet's own fingerprint was already zero. That meant users could see a confusing or misleading security warning in a legitimate situation. The change only shows the warning when the wallet actually has a non-zero fingerprint but the PSBT still needs zero filling. This is a user-interface and correctness fix, not a direct theft-of-funds vulnerability, but misleading warnings can train users to ignore real security alerts.

Lower-prioritydocs: macaw image by odudex (#803)by Odudex · 8f0fd5ee · Dec 9, 2025 · 5 filesMessage 65 · AdequateInformational 15Details
Commit message · Odudex

docs: macaw image by odudex (#803)

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI analysis · Informational 15/100

This commit is a documentation and simulator update. It swaps in a new macaw (arara) image for screenshots and QR-code simulation sequences, and adds one harmless mock method so the simulator can handle a camera lens-correction call. There is no security-relevant change.

Lower-priorityci: add convetional commits to krux (#787)by qlrd · ab08d5f1 · Dec 8, 2025 · 1 fileMessage 65 · AdequateInformational 15Details
Commit message · qlrd

ci: add convetional commits to krux (#787)

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit adds a new automated GitHub Actions check that enforces conventional commit message formatting (like 'feat:', 'fix:', 'ci:') for pull requests. It does not change any application code, cryptography, wallet logic, or user-facing behavior. There is no security relevance in the change itself.

Security candidatechore: require urllib3 >2.6 security fix for CVE-2025-66471 urllib3 is dependency of requests and translate, used in dev toolsby odudex · 268f3f7b · Dec 8, 2025 · 2 filesMessage 98 · StrongLow 36Details
Commit message · odudex

chore: require urllib3 >2.6
security fix for CVE-2025-66471
urllib3 is dependency of requests and translate, used in dev tools

98/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
explicit security language
AI analysis · Low 36/100

This commit updates the project's Python dependency lock file to require urllib3 version 2.6.0 or newer. The commit message says this is a security fix for CVE-2025-66471, a vulnerability in the urllib3 library. urllib3 is used indirectly through other packages (requests and translate) and only in development tools, not in the main Krux firmware that runs on hardware wallets. The change itself is a routine dependency bump, not a code fix inside Krux.

Security candidateInverted Color QR Code Decoding (#795)by Odudex · 573de433 · Dec 4, 2025 · 8 filesMessage 76 · AdequateInformational 15Details
Commit message · Odudex

Inverted Color QR Code Decoding (#795)

* feature: added inverted color QR code detection
with improved QR code decoding performance

* inverted color QR code: optional flag to find them

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
boot or update path
AI analysis · Informational 15/100

This commit is a normal feature update for the Krux Bitcoin signing device. It adds the ability to detect QR codes that have inverted colors (black background with white QR code) and renames some internal camera-mode functions. There is no indication of a security vulnerability or malicious change in the code.

Security candidateDatum crypto-bip39: join list so Datum can load and display it (#799)by Odudex · 9a06ae7f · Dec 4, 2025 · 2 filesMessage 58 · ThinInformational 18Details
Commit message · Odudex

Datum crypto-bip39: join list so Datum can load and display it (#799)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
secret or key material
AI analysis · Informational 18/100

This commit fixes a display bug in Krux's Datum tool. When a user scanned a BIP39 mnemonic seed phrase from a QR code, the device received the words as a list but tried to show them as a single string, which could not render correctly. The fix joins the word list into a normal spaced sentence so the device can display it. There is no direct evidence this is a security vulnerability, only a UI/data-format bug.

Lower-priorityTrue binary QRs: Deal with binary encoded UR QR code (#798)by Odudex · 499a163b · Dec 4, 2025 · 1 fileMessage 58 · ThinLow 32Details
Commit message · Odudex

True binary QRs: Deal with binary encoded UR QR code (#798)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI analysis · Low 32/100

This commit fixes a small bug in how Krux reads certain QR codes. Some QR codes carry raw binary data, and the code previously assumed the data would arrive as text. The fix converts binary data to text before passing it onward. This is a defensive correction that prevents a crash or misread when scanning a specific kind of QR code (binary-encoded Uniform Resource QR codes). There is no direct evidence in the commit that this is exploitable as a security attack.

Lower-prioritySmall change on Touch Threshold, Buttons Debounce and Swipe Threshold constant (#793)by Tads · 0f0bb13d · Dec 2, 2025 · 4 filesMessage 58 · ThinInformational 15Details
Commit message · Tads

Small change on Touch Threshold, Buttons Debounce and Swipe Threshold constant (#793)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI analysis · Informational 15/100

This commit adjusts user-interface timing and sensitivity constants for the Krux hardware wallet: button debounce times are lowered, the allowed range for touch sensitivity is widened, and the swipe gesture threshold is reduced. These are usability/tuning changes, not security fixes. There is no indication in the commit or changelog that any vulnerability is being addressed.

Lower-priorityDocs: fix new version for krux-installer (#796)by Tads · a513e3eb · Dec 2, 2025 · 5 filesMessage 65 · AdequateInformational 16Details
Commit message · Tads

Docs: fix new version for krux-installer (#796)

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI analysis · Informational 16/100

This commit is a routine documentation update for the Krux project. It updates the website/docs to point users to a newer version of the Krux-Installer (v0.0.21 instead of v0.0.20), fixes some broken/typoed download links and file names, and reorganizes the macOS installation instructions. There is no code change and nothing in the commit suggests a security vulnerability or malicious behavior.

Lower-priorityfix: Compact SeedQR broken by commit f15e198 (#794)by Odudex · 38325dc7 · Dec 1, 2025 · 1 fileMessage 85 · StrongInformational 23Details
Commit message · Odudex

fix: Compact SeedQR broken by commit f15e198 (#794)

still adjusting the code for true binary QRs

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
AI analysis · Informational 23/100

This is a one-line bug fix in Krux's QR code parser. A previous change accidentally broke Compact SeedQR support by trying to decode binary QR data as text before checking the format. The fix moves the decode step inside a try block so binary data is handled safely. There is no direct evidence this is a security vulnerability; it appears to be a functionality regression.

Lower-priorityfix: Krux script wrong baudrate for dock (#792)by Tads · 6fa9e2d9 · Dec 1, 2025 · 1 fileMessage 65 · AdequateInformational 17Details
Commit message · Tads

fix: Krux script wrong baudrate for dock (#792)

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI analysis · Informational 17/100

This commit fixes a shell script that sets the serial communication speed (baudrate) when flashing Krux firmware to certain hardware devices. Previously, the 'dock' device was missing from the list that should use a 1.5 Mbps baudrate, which could cause flashing to fail or be unreliable for that device. There is no security vulnerability here—it's a device compatibility/operational bug fix.

Lower-prioritydocs: update installer info - fix typoby odudex · 53fa4d2c · Nov 30, 2025 · 1 fileMessage 57 · ThinInformational 15Details
Commit message · odudex

docs: update installer info - fix typo

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit fixes two typos in user-facing documentation. The instructions for verifying a downloaded file incorrectly included '.txt' in the filenames of the signature and checksum files. The patch removes '.txt' so the commands match the actual filenames produced by the project. There is no code change and no security vulnerability.

Lower-prioritydocs: update installer info - fix typoby odudex · 6c4a84fa · Nov 30, 2025 · 1 fileMessage 57 · ThinInformational 15Details
Commit message · odudex

docs: update installer info - fix typo

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit fixes two typos in the user documentation for verifying a downloaded Krux installer. The instructions previously told users to run commands with an extra '.txt' in the filename, which would have caused the commands to fail because the actual signature and checksum files do not include '.txt'. This is a documentation-only correction with no code changes.

AI review queueddocs: update installer info (#782)by qlrd · d2770c3f · Nov 30, 2025 · 13 filesMessage 98 · StrongInformational 15Details
Commit message · qlrd

docs: update installer info (#782)

The latest installer changed authenticity/integrity checks. This commit
removes `snippets/verify-the-*.en.txt` as well change some
`getting-started/installing/from-gui` files to comply with the necessary
steps.

98/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only updates user documentation for the Krux installer. It removes per-platform verification instructions and replaces them with a single new page explaining how to verify the installer's authenticity and integrity. No source code, build scripts, or cryptographic checks in the project itself were changed.