SW
← All projectsSparrow

Sparrow Wallet

Desktop Bitcoin wallet focused on security, privacy, multisignature, and hardware signers.

BitcoinHardware integrationSoftware walletsNormal
Repository coverage

411 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

71security candidates271second-pass queue399AI analyses
88commits · 30 days
152commits · 60 days
250commits · 180 days
405commits · 365 days
Backfill bands
Aug 5 → Feb 6100 seen9 candidatesComplete
Feb 6 → Jun 6128 seen15 candidatesComplete
Jun 6 → Jul 67 seen1 candidatesComplete
Jul 6 → Aug 546 seen8 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

48/100 average clarity
0Strong · 80–100
35Adequate · 60–79
325Thin · 40–59
51Opaque · 0–39
2security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Craig Raw39767385648
doblon8313048
nzb-tuxxx212060
Michele Balistreri212048
nroktib111050
Liz Lightning202045
PeterXMR101045
Ian McKenzie101050
ottosch101050
craigraw101060
Analysis record

Published AI watches

Last scanned 46 minutes ago

Informational 17 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

remove the surplus signatures progress bar segments a finalized multisig transaction discards

This commit fixes a UI display bug in Sparrow Wallet's signature progress bar. When a multi-signature Bitcoin transaction becomes finalized, extra signatures beyond the required threshold are discarded. Previously, the progress bar did not…

UI state desynchronization after multisig finalizationProgress bar segment count mismatch with actual signature setNo change to cryptographic or transaction validation code
40f77206by Craig Raw+9−12 files
No security note in commit
Informational 15 AI analysisMessage 38 · Opaque
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

bump to v2.5.6

This commit is a routine version bump from 2.5.5 to 2.5.6. It only changes version strings in four files (build configuration, documentation, macOS app metadata, and a Java source constant). There are no code logic changes, no bug fixes, a…

f7f36d00by Craig Raw+4−44 files
No security note in commit
Informational 17 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

use a framerate-capped interpolated timeline for the server toggle and wallet tab loading pulse animations, and stop any running server toggle pulse before starting a new one

This commit tweaks two visual animations in the Sparrow Wallet desktop app: the server connection toggle pulse and the wallet loading pulse. It caps how often the screen is redrawn during the pulse and makes sure any already-running pulse …

Resource-consumption / performance hardening: capped animation framerate reduces CPU/GPU load from continuous 60 Hz redraws.State-management hardening: stopping an existing pulse before starting a new one prevents accumulation of running Timelines.No direct security flaw is present in the diff; signals are defensive-hardening in nature.
4da29f4eby Craig Raw+7−132 files
No security note in commit
Low 45 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

cut pasted amounts to the unit precision in the send tab and send to many, and stop the csv import skipping fractional sats and exponent amounts

This commit fixes how Sparrow Wallet handles pasted or imported Bitcoin amounts. Previously, very small or oddly formatted amounts (like scientific notation '1e-8' or fractional satoshis) could be misread or silently skipped during CSV imp…

Amount parsing inconsistency between UI paste and CSV importSilent swallowing of NumberFormatException could skip payment rowsUse of Double.parseDouble for monetary amounts
9e999d3fby Craig Raw+39−362 files
No security note in commit
Informational 15 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

add a system theme option that follows the os light or dark setting, and make it the default for new installs

This commit adds a new 'System' theme option to the Sparrow Wallet desktop app that automatically follows the operating system's light or dark mode setting, and makes it the default for new installations. It also updates various UI compone…

a573f22aby Craig Raw+90−3215 files
No security note in commit
Low 36 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

refuse bitbox02 keystore import and discovery for legacy p2sh and p2pkh wallets it cannot sign for, and hide those script types from the device import menus

This commit tightens how Sparrow Wallet handles BitBox02 hardware wallets when working with older Bitcoin address formats (legacy P2PKH and P2SH). Previously, the app could let a user import or discover a wallet that the BitBox02 cannot ac…

Prevents user from configuring a signing device for wallet types the device cannot sign forCould avoid funds becoming unspendable or requiring complex recovery if a user unknowingly imported an unsupported legacy script typeReplaces hard-coded device-specific logic with a generic capability model, reducing future similar issues
de169b18by Craig Raw+23−73 files
No security note in commit
Low 37 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

reject unknown command line options and values given to flags with an error and exit code instead of starting on the default network, and accept the --option=value form

This commit tightens how Sparrow Wallet handles command-line arguments. Previously, typos or unexpected values could silently be ignored, causing the wallet to start on the default Bitcoin network instead of the one the user intended. Now,…

Command-line argument parsing now rejects unknown options instead of silently ignoring themBoolean flags now reject `--flag=value` forms that would otherwise silently pass the value through as a file/URI argumentProgram now exits with non-zero status on argument errors, reducing risk of unintended default-network startup
46197586by Craig Raw+26−12 files
No security note in commit
Low 37 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

ignore amount digits beyond the selected unit precision in the send tab amount and fee fields and the send to many grid, instead of truncating them in the payment

This commit fixes a UI bug in the Sparrow Bitcoin wallet where typing or pasting too many decimal digits into amount or fee fields could be silently truncated, potentially causing a user to send a different amount than they saw on screen. …

Precision-loss / truncation bug in financial input fieldsUser-facing amount/fee mismatch between displayed value and parsed valueInput validation now tied to unit-specific precision (satoshis indivisible)
6cde97adby Craig Raw+48−315 files
No security note in commit
Low 41 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

derive public keys from the seed when importing a sparrow wallet file

This commit changes how Sparrow Wallet restores its own wallet files. Previously, when importing a Sparrow wallet file, the public keys (used to find transactions and addresses) might not be correctly rebuilt from the seed phrase. The fix …

Correctness fix for key material restoration during wallet importAdds test coverage for encrypted and unencrypted seed-based wallet importAdds test coverage for watch-only wallet import
1fb4e8bbby Craig Raw+149−23 files
No security note in commit
Informational 21 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

add file import of the xpub descriptor jade writes to usb storage

This commit adds the ability to import a Bitcoin wallet's extended public key (xpub) into Sparrow Wallet from a file written by a Blockstream Jade hardware wallet via USB storage. Previously, Jade only supported QR-code import. The change …

New file import path parses external descriptor data and converts it to a keystoreScript type mismatch is explicitly rejected with an IllegalArgumentExceptionSilent payments policy (SINGLE_SP) is explicitly rejected
c4b53879by Craig Raw+74−44 files
No security note in commit
Low 34 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

include the non-witness utxo in psbts for krux keystores, and in the qr display when the psbt has more than one input

This commit changes how Sparrow Wallet builds QR codes for partially-signed Bitcoin transactions (PSBTs). For certain hardware wallets (Krux), it now includes extra data (the full previous transaction, called 'non-witness utxo') in the QR …

Hardware wallet signing correctness: missing non-witness UTXO data can cause some signers to reject or mis-handle multi-input segwit PSBTsQR payload size increase: larger QR codes may be harder to scan reliably, potentially affecting usabilitySubproject update (drongo) likely contains related serialization logic changes
0e2c402fby Craig Raw+4−32 files
No security note in commit
Low 35 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

clear a scanned wallet when a file, text payload or unrecognised qr is imported in the same pane

This commit fixes a UI state bug in Sparrow Wallet's import pane. Previously, when a user scanned or imported a wallet and then imported a non-wallet file, text payload, or unrecognized QR code in the same pane, the previously loaded walle…

Stale UI state could mislead users about which wallet is loadedCross-import state retention in single import paneUser interface consistency fix with security-relevant consequences
d7ded1e7by Craig Raw+4−21 file
No security note in commit
Low 35 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

lock the cormorant store against client connection reads and serve history as a copy, and close the client socket however its handler exits

This commit fixes two reliability issues in Sparrow Wallet's built-in Electrum server (Cormorant). First, it makes sure the internal transaction store is locked while being read or updated, and returns a fresh copy of a wallet's history so…

Concurrency: shared mutable store accessed by client handler and polling threads now synchronizedData consistency: history returned as a defensive copy to avoid iterator seeing concurrent modificationsResource leak: client socket now closed in finally block regardless of exception path
6cc4d50aby Craig Raw+57−94 files
No security note in commit
Low 44 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

ensure cormorant responses and notifications are always serialized per client connection

This commit fixes a race condition in Sparrow Wallet's built-in Electrum server (Cormorant). Previously, a response to a wallet client and an asynchronous notification (like a new block or a balance update) could be written to the same net…

Race condition on shared socket output streamConcurrent writes from RPC response path and event-bus notification pathPotential interleaving/framing of JSON-RPC messages on same TCP connection
6d9d3014by Craig Raw+146−303 files
No security note in commit
Low 27 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

wake a silent payments history waiter when a failed widening restores a completed scan, rather than leaving it parked for the session

This commit fixes a bug in Sparrow Wallet's silent-payments scanning cache. If a background scan had already finished, then a later 'widening' request to extend the scan failed and rolled back, any history request that arrived during the f…

Concurrency / condition-variable waiter starvationSilent-payments history lookup hang / wallet UI unresponsivenessFailure-recovery path missing signal on rollback
7868a94dby Craig Raw+100−122 files
No security note in commit
Informational 18 AI analysisMessage 60 · Adequate
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

guard a short server.version response in the desktop and terminal connection tests

This commit fixes a minor crash bug in Sparrow Wallet's connection-test screens. Previously, if a Bitcoin Electrum server answered the version request with an unusually short response, the wallet would try to read list items that didn't ex…

Input validation hardening for external server responseIndexOutOfBoundsException prevented in UI feedback pathNo cryptographic, authentication, or transaction logic touched
66348fafby Craig Raw+4−42 files
No security note in commit
Low 37 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

omit a paynym contact whose payment code does not parse rather than keeping it with a null code or failing the whole paynym response

This commit fixes a bug in Sparrow Wallet's PayNym (BIP47 reusable payment code) contact handling. Previously, if a single contact in your PayNym following/followers list had a malformed payment code, the app either kept a broken contact w…

Null payment code previously stored in contact objectPotential NullPointerException or downstream dereference of null PaymentCode in contact lists/searchWhole PayNym response could fail on one malformed contact
94ebb849by Craig Raw+43−114 files
No security note in commit
Informational 19 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

skip the exchange currencies request in offline mode in the desktop and terminal general settings

This change stops Sparrow Wallet from trying to fetch live fiat-currency exchange rates when the user has explicitly chosen 'offline mode'. Instead of making a network request that is doomed to fail, it now reuses the currency already save…

Avoids unnecessary network egress in offline modeReduces error/warning noise for expected offline behavior
b91f7993by Craig Raw+15−12 files
No security note in commit
Low 37 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

skip addresses already given out under a label and widen the gap limit on an explicit advance in the terminal receive dialog

This commit fixes two related Bitcoin wallet behaviors in Sparrow. First, when you ask for a new receive address, the wallet now skips any address that already has a label, because a label means that address was already given to someone. P…

Address reuse prevention: labeled-but-empty addresses are now skipped consistently across desktop and terminal receive flowsGap-limit widening on explicit advance reduces risk of missing funds during wallet recovery/rescanLogic centralized in WalletForm to reduce UI-specific divergence
cae870ceby Craig Raw+85−164 files
No security note in commit
Low 44 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

cap bbqr display and pdf encodings at the 1295 parts the header can number, using larger parts for data that needs more rather than emitting a sequence that cannot be reassembled

This commit fixes a bug in Sparrow Wallet's BBQ QR code format. Previously, if a large transaction or data blob needed more than 1,295 QR-code-sized pieces, the app would generate pieces with impossible sequence numbers that could not be r…

Integer/sequence-number overflow-like limit violation in a data-encoding protocolPotential denial-of-service or data-integrity failure when exporting large transactions via QRRound-trip unit test added to prevent regression
4b5326d8by Craig Raw+27−12 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Lower-priorityupdate drongo submodule with minor fixesby Craig Raw · b38f517f · Aug 19, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Craig Raw

update drongo submodule with minor fixes

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queueddetect legacy multisig descriptors case insensitively when warning about key sortingby Craig Raw · e0ee957c · Aug 19, 2026 · 3 filesMessage 50 · ThinInformational 24Details
Commit message · Craig Raw

detect legacy multisig descriptors case insensitively when warning about key sorting

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 24/100

This commit fixes a minor user-facing bug in Sparrow Wallet where the app failed to recognize legacy multisig wallet descriptors if they used uppercase letters (for example, 'MULTI(' instead of 'multi('). As a result, Sparrow would not show its usual warning that it only supports BIP67-compatible sorted multisig wallets, and it would not automatically sort the public keys. The change makes the detection case-insensitive by using a regular expression pattern instead of a simple lowercase string check. This is a usability and correctness fix rather than a serious security vulnerability.

AI review queuedimprove max cosigner ui handling in settingsby Craig Raw · b99b880c · Aug 10, 2026 · 4 filesMessage 45 · ThinLow 27Details
Commit message · Craig Raw

improve max cosigner ui handling in settings

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 27/100

This commit tightens wallet validation in Sparrow Wallet. It replaces a simple validity check with a more detailed one that reports specific problems, and it prevents users from creating or loading wallets whose number of cosigners exceeds what the chosen Bitcoin script type supports. It also fixes UI slider behavior so the maximum cosigner count stays within allowed limits when the script type changes. The changes are defensive: they catch misconfigurations earlier and give clearer error messages, which reduces the chance of accidentally using an invalid or unsupported wallet.

AI review queuedresolve bip353 hrns over tcp via the socks proxy when one is configuredby Craig Raw · d9ad0618 · Aug 10, 2026 · 4 filesMessage 50 · ThinLow 38Details
Commit message · Craig Raw

resolve bip353 hrns over tcp via the socks proxy when one is configured

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 38/100

This commit changes Sparrow Wallet so that BIP353 human-readable payment names (like a Bitcoin email address) are resolved through the user's configured SOCKS proxy instead of directly over the internet. It also updates a related database field from seconds to milliseconds for storing key/seed creation times. The main security angle is privacy: without the proxy, DNS-style lookups for payment recipients could leak the recipient name and the user's IP address to DNS servers or observers. The change routes that traffic through Tor or another proxy if one is set. The database rename is a code-quality change and does not appear to be a security fix by itself.

AI review queuedclose remaining local dns resolution gaps when classifying hostnames and connecting via torby Craig Raw · 03222f20 · Aug 6, 2026 · 3 filesMessage 50 · ThinModerate 65Details
Commit message · Craig Raw

close remaining local dns resolution gaps when classifying hostnames and connecting via tor

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 65/100

This commit fixes privacy gaps in Sparrow Wallet when it connects through Tor or another proxy. Previously, the app could accidentally ask the computer's normal DNS resolver to translate server names, which could reveal which Bitcoin servers a user was trying to reach. It also could connect to local-network addresses directly even when a proxy was on, potentially bypassing Tor. The patch makes the app treat unknown hostnames as remote when a proxy is active and avoid resolving them locally, and it ensures Tor connections use the proxy for name resolution rather than the local system.

AI review queuedavoid deleting the backups of same-prefixed walletsby Craig Raw · b6ed4ba7 · Aug 5, 2026 · 2 filesMessage 50 · ThinLow 48Details
Commit message · Craig Raw

avoid deleting the backups of same-prefixed wallets

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 48/100

This commit fixes a bug in how Sparrow Wallet finds and deletes old wallet backups. Previously, the backup cleanup logic used loose pattern matching that could accidentally treat backups of one wallet as if they belonged to another wallet with a similar name. For example, a wallet named 'Savings' might incorrectly match backup files for 'SavingsX' or 'Savings.old'. The result could be that backups of a different wallet get deleted, or that cleanup of the intended wallet's backups fails. The patch replaces the loose prefix-and-date check with a strict regular expression that requires an exact wallet name, a complete 14-digit timestamp, and a matching file extension. New unit tests confirm that only correctly named backups are selected.

AI review queuedverify proof of work on chain tips and warn when a tip goes staleby Craig Raw · 5ccc4902 · Aug 5, 2026 · 5 filesMessage 60 · AdequateModerate 62Details
Commit message · Craig Raw

verify proof of work on chain tips and warn when a tip goes stale

60/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 62/100

This commit adds safety checks to the Bitcoin wallet Sparrow when it receives block-chain tip announcements from an Electrum server. It now verifies that the announced block header is properly formatted, not timestamped too far in the future, and meets the proof-of-work target encoded in the header itself. It also warns the user if the server stops sending new blocks for more than two hours, which can indicate a stale or malicious server. These changes reduce the risk of a hostile or malfunctioning server misleading the wallet about the state of the Bitcoin network.

AI review queuedprevent a password change from re-encrypting wallets whose filenames share the same prefixby Craig Raw · 24c6202e · Aug 5, 2026 · 3 filesMessage 50 · ThinModerate 66Details
Commit message · Craig Raw

prevent a password change from re-encrypting wallets whose filenames share the same prefix

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: broader security terminologysecond-pass: security-sensitive path
AI analysis · Moderate 66/100

This commit fixes a bug in Sparrow Wallet's password-change feature. Previously, when a user changed the password on a wallet file whose name was a prefix of another wallet file (for example, 'Savings' and 'Savings.old'), the underlying H2 database tool would also re-encrypt the sibling wallet file. That could corrupt or lock the sibling wallet. The fix copies the target wallet to its own temporary directory, performs the encryption change there, verifies it, and then atomically replaces the original file so no other wallet files are touched.

AI review queuedreject truncated and oversized tlv lengths when parsing keycard responsesby Craig Raw · b0b9cc23 · Aug 4, 2026 · 2 filesMessage 50 · ThinModerate 56Details
Commit message · Craig Raw

reject truncated and oversized tlv lengths when parsing keycard responses

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 56/100

This commit fixes a bug in how Sparrow Wallet reads data from Keycard hardware wallets. Previously, the code trusted the length declared inside a card response without checking whether that many bytes actually exist. A malicious or malfunctioning card could claim a huge length, causing the app to read past the end of the buffer and potentially return fabricated zero-filled data. The patch now rejects responses whose declared length is truncated, oversized, or malformed, and adds tests to confirm the new behavior.

Security candidatereject extended private keys when creating a terminal watch only wallet, and show import errorsby Craig Raw · fa0d4841 · Aug 4, 2026 · 2 filesMessage 50 · ThinLow 42Details
Commit message · Craig Raw

reject extended private keys when creating a terminal watch only wallet, and show import errors

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
secret or key materialsigning or wallet path
AI analysis · Low 42/100

This commit fixes a bug in Sparrow Wallet's terminal (command-line) watch-only wallet creation. Previously, a user could accidentally paste an extended private key (xprv) into a dialog meant only for public keys or output descriptors, and the wallet would silently fail or create an empty wallet. Now the app rejects xprv keys with a clear error message and also shows import errors to the user instead of logging them silently.

AI review queuedensure imported keystore labels are truncated and uniqueby Craig Raw · 7a3f775a · Aug 4, 2026 · 1 fileMessage 50 · ThinLow 49Details
Commit message · Craig Raw

ensure imported keystore labels are truncated and unique

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 49/100

This commit fixes a bug in Sparrow Wallet's import of wallet labels. Previously, labels for multi-signature participants (keystores) could be too long or identical to each other, which could make the wallet file impossible to reopen. The change now truncates long labels and rejects duplicates during import, preventing the wallet from becoming unopenable.

Security candidatealways check and restrict existing wallets and backup directories to owner only permissionsby Craig Raw · 5d387765 · Aug 4, 2026 · 1 fileMessage 50 · ThinModerate 61Details
Commit message · Craig Raw

always check and restrict existing wallets and backup directories to owner only permissions

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
credential or privilege statesigning or wallet path
AI analysis · Moderate 61/100

This update makes Sparrow Wallet automatically tighten the file permissions on wallet and backup folders so only the computer's owner can read them. Previously, if those folders already existed with looser permissions (for example, created by an older version or another user), other accounts on the same machine might have been able to read wallet files. The change also adds a warning if the app cannot fix the permissions.

Security candidateadd bitbox02 attestation failed dialogby Craig Raw · 1a810c06 · Aug 4, 2026 · 2 filesMessage 45 · ThinLow 25Details
Commit message · Craig Raw

add bitbox02 attestation failed dialog

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
update trustsigning or wallet path
AI analysis · Low 25/100

This commit adds a user-facing warning dialog when a BitBox02 hardware wallet fails an attestation check. Attestation is a process that helps verify the device is genuine and not a counterfeit or tampered unit. Previously, a failed attestation may not have been clearly communicated to the user. The change improves security by warning users not to store funds on a device that failed verification until they confirm it externally. It is a defensive hardening change, not an active vulnerability fix.

Security candidateimprove validation of payjoin proposals, and accept a substituted payment output where a change output is presentby Craig Raw · 32f7e58f · Aug 4, 2026 · 3 filesMessage 50 · ThinModerate 56Details
Commit message · Craig Raw

improve validation of payjoin proposals, and accept a substituted payment output where a change output is present

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundarysigning or wallet path
AI analysis · Moderate 56/100

This commit strengthens how Sparrow Wallet checks Payjoin proposals received from a payment receiver. Payjoin lets a receiver add their own inputs to a transaction to improve privacy. The changes add missing checks that could previously let a malicious or buggy receiver: (1) silently lower the transaction fee rate, (2) add key-path or signature data that leaks wallet information, (3) substitute the payment output even when no change output exists, or (4) return arbitrary error text that the wallet would show to the user. The patch also fixes handling for modern Taproot (P2TR) transactions, which were not being copied or validated correctly. A new set of unit tests confirms these protections.

AI review queuedimprove validation of legacy multipart qr part numbersby Craig Raw · 059f1e88 · Aug 4, 2026 · 2 filesMessage 50 · ThinLow 46Details
Commit message · Craig Raw

improve validation of legacy multipart qr part numbers

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 46/100

This commit tightens how Sparrow Wallet handles multi-part QR codes used to import older wallet data. It limits part numbers to four digits and rejects impossible values (like part 0 of 0, or part 5 of 2). The change prevents the app from allocating huge arrays or getting confused by malformed QR frames, which could otherwise crash or freeze the wallet during a scan.

Security candidateremove unused signature verification results in satochip and keycard signers, note where signatures are verifiedby Craig Raw · 866e9893 · Aug 4, 2026 · 2 filesMessage 65 · AdequateInformational 18Details
Commit message · Craig Raw

remove unused signature verification results in satochip and keycard signers, note where signatures are verified

65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
signing boundarydefensive validationsigning or wallet path
AI analysis · Informational 18/100

This commit removes leftover code that checked whether signatures from hardware card signers were valid, but then threw away the result. The signatures are still verified later by a different part of the wallet when the signed transaction is combined. The change is essentially a cleanup with no known security flaw, though it slightly reduces defense-in-depth by removing an early, unused sanity check.

AI review queuedimprove validation of bip129, descriptor and unchained wallet importsby Craig Raw · 3752540e · Aug 4, 2026 · 29 filesMessage 50 · ThinModerate 60Details
Commit message · Craig Raw

improve validation of bip129, descriptor and unchained wallet imports

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Moderate 60/100

This commit hardens how Sparrow Wallet imports wallet files from other tools. It adds checks that reject malformed or inconsistent imports—such as a multisig setup that says it needs 3 signers but only provides 2 keys, or a coordinator file that would silently make the wallet derive different Bitcoin addresses than the rest of the signing group. The change is defensive: it makes the wallet refuse suspicious imports rather than accepting them.

AI review queuedadd security policyby Craig Raw · 1a00e2ef · Aug 3, 2026 · 1 fileMessage 33 · OpaqueInformational 15Details
Commit message · Craig Raw

add security policy

33/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit simply adds a SECURITY.md file to the repository. It is a documentation-only change that tells people how to report security bugs privately and how the project handles vulnerability disclosures. It does not change any code, fix any bug, or introduce any new feature that could affect users directly.

AI review queuedonly save certificates passing hostname verification as ca validated, and retain not yet valid certificatesby Craig Raw · 372ebf2f · Aug 3, 2026 · 1 fileMessage 60 · AdequateModerate 59Details
Commit message · Craig Raw

only save certificates passing hostname verification as ca validated, and retain not yet valid certificates

60/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
defensive validationsigning or wallet pathsecond-pass: near security thresholdsecond-pass: security-sensitive path
AI analysis · Moderate 59/100

This commit tightens how Sparrow Wallet saves and reuses TLS certificates for private servers. Previously, any certificate that passed a basic CA check was saved as 'CA validated' even if it didn't actually match the server's hostname. That could let a malicious or misconfigured server trick the wallet into trusting the wrong certificate. Now the app also checks that the certificate's hostname matches the server, and it no longer deletes certificates that are merely 'not yet valid' (which can happen if the user's computer clock is wrong).

AI review queuedremove ineffective eckey clearby Craig Raw · 1636c7e2 · Aug 2, 2026 · 11 filesMessage 35 · OpaqueLow 28Details
Commit message · Craig Raw

remove ineffective eckey clear

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 28/100

This commit removes several calls that tried to wipe private-key material from memory. The developer says these wipes were 'ineffective' because the underlying ECKey object still held the secret bytes. The change is a cleanup, but it slightly increases the window during which private key bytes may sit in memory. It does not introduce a remotely exploitable bug; the main risk is a small worsening of local memory-exposure hygiene.

AI review queuedverify fetched transactions match requested txidby Craig Raw · 3979694e · Aug 2, 2026 · 3 filesMessage 55 · ThinHigh 72Details
Commit message · Craig Raw

verify fetched transactions match requested txid

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · High 72/100

This commit adds checks to make sure that when Sparrow Wallet asks an Electrum server for a specific Bitcoin transaction, the server actually returns the transaction that was requested. Before this change, a malicious or buggy server could return a different transaction than the one asked for, and Sparrow might trust it as if it were the right one. The fix verifies the transaction ID (a fingerprint of the transaction) matches in three places where transactions are fetched from the server.

AI review queuedrotate era logosby Craig Raw · 2b9c3eb7 · Jul 30, 2026 · 4 filesMessage 28 · OpaqueInformational 15Details
Commit message · Craig Raw

rotate era logos

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit simply rotates four logo images by 90 degrees. It changes only SVG graphics files and does not touch any code, cryptography, wallet logic, or network behavior. There is no security relevance.

AI review queuedbump to v2.5.4by Craig Raw · ef2c2cde · Jul 30, 2026 · 4 filesMessage 38 · OpaqueInformational 15Details
Commit message · Craig Raw

bump to v2.5.4

38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a routine version bump from 2.5.3 to 2.5.4. It only changes version strings in four files: the build configuration, macOS packaging metadata, in-app version constant, and documentation for reproducible builds. There are no code logic changes, bug fixes, or security-related modifications visible in the diff.

AI review queuedtreat whitespace-only labels as blank on label import and exportby Craig Raw · 0dce4783 · Jul 29, 2026 · 2 filesMessage 50 · ThinInformational 18Details
Commit message · Craig Raw

treat whitespace-only labels as blank on label import and export

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 18/100

This commit tightens how Sparrow Wallet treats labels made only of spaces or tabs during wallet label import and export. Previously, a label consisting solely of whitespace was considered a real label; now it is treated as blank and skipped. The change also renames an unrelated UI field from 'useDustLimitField' to 'ignoreDustField' for clarity. There is no direct security vulnerability here, but the fix prevents minor data-quality issues and avoids surprising behavior where whitespace-only labels are exported or imported as meaningful labels.

Security candidateadd option to ignore dust on private key sweepby nroktib · cf797ea0 · Jul 29, 2026 · 1 fileMessage 50 · ThinInformational 19Details
Commit message · nroktib

add option to ignore dust on private key sweep

50/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
secret or key materialsigning or wallet path
AI analysis · Informational 19/100

This commit adds a user-facing checkbox labeled 'Ignore dust' to the private-key sweep feature in Sparrow Wallet. When enabled, very small ('dust') unspent outputs linked to the swept key are excluded from the transaction. This is a usability and privacy improvement, not a security fix, because dust outputs are often sent by third parties to track wallets or to make sweeps uneconomical due to fees. There is no evidence in the commit or supplied references that this addresses a vulnerability or was disclosed as a security issue.