SW
← All projectsSparrow

Sparrow Wallet

Desktop Bitcoin wallet focused on security, privacy, multisignature, and hardware signers.

BitcoinHardware integrationSoftware walletsNormal
Repository coverage

410 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

71security candidates271second-pass queue399AI analyses
88commits · 30 days
151commits · 60 days
249commits · 180 days
404commits · 365 days
Backfill bands
Aug 5 → Feb 6100 seen9 candidatesComplete
Feb 6 → Jun 6128 seen15 candidatesComplete
Jun 6 → Jul 67 seen1 candidatesComplete
Jul 6 → Aug 546 seen8 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

48/100 average clarity
0Strong · 80–100
35Adequate · 60–79
324Thin · 40–59
51Opaque · 0–39
2security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Craig Raw39667385647
doblon8313048
nzb-tuxxx212060
Michele Balistreri212048
nroktib111050
Liz Lightning202045
PeterXMR101045
Ian McKenzie101050
ottosch101050
craigraw101060
Analysis record

Published AI watches

Last scanned 31 minutes ago

Informational 17 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

remove the surplus signatures progress bar segments a finalized multisig transaction discards

This commit fixes a UI display bug in Sparrow Wallet's signature progress bar. When a multi-signature Bitcoin transaction becomes finalized, extra signatures beyond the required threshold are discarded. Previously, the progress bar did not…

UI state desynchronization after multisig finalizationProgress bar segment count mismatch with actual signature setNo change to cryptographic or transaction validation code
40f77206by Craig Raw+9−12 files
No security note in commit
Informational 15 AI analysisMessage 38 · Opaque
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

bump to v2.5.6

This commit is a routine version bump from 2.5.5 to 2.5.6. It only changes version strings in four files (build configuration, documentation, macOS app metadata, and a Java source constant). There are no code logic changes, no bug fixes, a…

f7f36d00by Craig Raw+4−44 files
No security note in commit
Informational 17 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

use a framerate-capped interpolated timeline for the server toggle and wallet tab loading pulse animations, and stop any running server toggle pulse before starting a new one

This commit tweaks two visual animations in the Sparrow Wallet desktop app: the server connection toggle pulse and the wallet loading pulse. It caps how often the screen is redrawn during the pulse and makes sure any already-running pulse …

Resource-consumption / performance hardening: capped animation framerate reduces CPU/GPU load from continuous 60 Hz redraws.State-management hardening: stopping an existing pulse before starting a new one prevents accumulation of running Timelines.No direct security flaw is present in the diff; signals are defensive-hardening in nature.
4da29f4eby Craig Raw+7−132 files
No security note in commit
Low 45 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

cut pasted amounts to the unit precision in the send tab and send to many, and stop the csv import skipping fractional sats and exponent amounts

This commit fixes how Sparrow Wallet handles pasted or imported Bitcoin amounts. Previously, very small or oddly formatted amounts (like scientific notation '1e-8' or fractional satoshis) could be misread or silently skipped during CSV imp…

Amount parsing inconsistency between UI paste and CSV importSilent swallowing of NumberFormatException could skip payment rowsUse of Double.parseDouble for monetary amounts
9e999d3fby Craig Raw+39−362 files
No security note in commit
Informational 15 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

add a system theme option that follows the os light or dark setting, and make it the default for new installs

This commit adds a new 'System' theme option to the Sparrow Wallet desktop app that automatically follows the operating system's light or dark mode setting, and makes it the default for new installations. It also updates various UI compone…

a573f22aby Craig Raw+90−3215 files
No security note in commit
Low 36 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

refuse bitbox02 keystore import and discovery for legacy p2sh and p2pkh wallets it cannot sign for, and hide those script types from the device import menus

This commit tightens how Sparrow Wallet handles BitBox02 hardware wallets when working with older Bitcoin address formats (legacy P2PKH and P2SH). Previously, the app could let a user import or discover a wallet that the BitBox02 cannot ac…

Prevents user from configuring a signing device for wallet types the device cannot sign forCould avoid funds becoming unspendable or requiring complex recovery if a user unknowingly imported an unsupported legacy script typeReplaces hard-coded device-specific logic with a generic capability model, reducing future similar issues
de169b18by Craig Raw+23−73 files
No security note in commit
Low 37 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

reject unknown command line options and values given to flags with an error and exit code instead of starting on the default network, and accept the --option=value form

This commit tightens how Sparrow Wallet handles command-line arguments. Previously, typos or unexpected values could silently be ignored, causing the wallet to start on the default Bitcoin network instead of the one the user intended. Now,…

Command-line argument parsing now rejects unknown options instead of silently ignoring themBoolean flags now reject `--flag=value` forms that would otherwise silently pass the value through as a file/URI argumentProgram now exits with non-zero status on argument errors, reducing risk of unintended default-network startup
46197586by Craig Raw+26−12 files
No security note in commit
Low 37 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

ignore amount digits beyond the selected unit precision in the send tab amount and fee fields and the send to many grid, instead of truncating them in the payment

This commit fixes a UI bug in the Sparrow Bitcoin wallet where typing or pasting too many decimal digits into amount or fee fields could be silently truncated, potentially causing a user to send a different amount than they saw on screen. …

Precision-loss / truncation bug in financial input fieldsUser-facing amount/fee mismatch between displayed value and parsed valueInput validation now tied to unit-specific precision (satoshis indivisible)
6cde97adby Craig Raw+48−315 files
No security note in commit
Low 41 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

derive public keys from the seed when importing a sparrow wallet file

This commit changes how Sparrow Wallet restores its own wallet files. Previously, when importing a Sparrow wallet file, the public keys (used to find transactions and addresses) might not be correctly rebuilt from the seed phrase. The fix …

Correctness fix for key material restoration during wallet importAdds test coverage for encrypted and unencrypted seed-based wallet importAdds test coverage for watch-only wallet import
1fb4e8bbby Craig Raw+149−23 files
No security note in commit
Informational 21 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

add file import of the xpub descriptor jade writes to usb storage

This commit adds the ability to import a Bitcoin wallet's extended public key (xpub) into Sparrow Wallet from a file written by a Blockstream Jade hardware wallet via USB storage. Previously, Jade only supported QR-code import. The change …

New file import path parses external descriptor data and converts it to a keystoreScript type mismatch is explicitly rejected with an IllegalArgumentExceptionSilent payments policy (SINGLE_SP) is explicitly rejected
c4b53879by Craig Raw+74−44 files
No security note in commit
Low 34 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

include the non-witness utxo in psbts for krux keystores, and in the qr display when the psbt has more than one input

This commit changes how Sparrow Wallet builds QR codes for partially-signed Bitcoin transactions (PSBTs). For certain hardware wallets (Krux), it now includes extra data (the full previous transaction, called 'non-witness utxo') in the QR …

Hardware wallet signing correctness: missing non-witness UTXO data can cause some signers to reject or mis-handle multi-input segwit PSBTsQR payload size increase: larger QR codes may be harder to scan reliably, potentially affecting usabilitySubproject update (drongo) likely contains related serialization logic changes
0e2c402fby Craig Raw+4−32 files
No security note in commit
Low 35 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

clear a scanned wallet when a file, text payload or unrecognised qr is imported in the same pane

This commit fixes a UI state bug in Sparrow Wallet's import pane. Previously, when a user scanned or imported a wallet and then imported a non-wallet file, text payload, or unrecognized QR code in the same pane, the previously loaded walle…

Stale UI state could mislead users about which wallet is loadedCross-import state retention in single import paneUser interface consistency fix with security-relevant consequences
d7ded1e7by Craig Raw+4−21 file
No security note in commit
Low 35 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

lock the cormorant store against client connection reads and serve history as a copy, and close the client socket however its handler exits

This commit fixes two reliability issues in Sparrow Wallet's built-in Electrum server (Cormorant). First, it makes sure the internal transaction store is locked while being read or updated, and returns a fresh copy of a wallet's history so…

Concurrency: shared mutable store accessed by client handler and polling threads now synchronizedData consistency: history returned as a defensive copy to avoid iterator seeing concurrent modificationsResource leak: client socket now closed in finally block regardless of exception path
6cc4d50aby Craig Raw+57−94 files
No security note in commit
Low 44 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

ensure cormorant responses and notifications are always serialized per client connection

This commit fixes a race condition in Sparrow Wallet's built-in Electrum server (Cormorant). Previously, a response to a wallet client and an asynchronous notification (like a new block or a balance update) could be written to the same net…

Race condition on shared socket output streamConcurrent writes from RPC response path and event-bus notification pathPotential interleaving/framing of JSON-RPC messages on same TCP connection
6d9d3014by Craig Raw+146−303 files
No security note in commit
Low 27 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

wake a silent payments history waiter when a failed widening restores a completed scan, rather than leaving it parked for the session

This commit fixes a bug in Sparrow Wallet's silent-payments scanning cache. If a background scan had already finished, then a later 'widening' request to extend the scan failed and rolled back, any history request that arrived during the f…

Concurrency / condition-variable waiter starvationSilent-payments history lookup hang / wallet UI unresponsivenessFailure-recovery path missing signal on rollback
7868a94dby Craig Raw+100−122 files
No security note in commit
Informational 18 AI analysisMessage 60 · Adequate
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

guard a short server.version response in the desktop and terminal connection tests

This commit fixes a minor crash bug in Sparrow Wallet's connection-test screens. Previously, if a Bitcoin Electrum server answered the version request with an unusually short response, the wallet would try to read list items that didn't ex…

Input validation hardening for external server responseIndexOutOfBoundsException prevented in UI feedback pathNo cryptographic, authentication, or transaction logic touched
66348fafby Craig Raw+4−42 files
No security note in commit
Low 37 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

omit a paynym contact whose payment code does not parse rather than keeping it with a null code or failing the whole paynym response

This commit fixes a bug in Sparrow Wallet's PayNym (BIP47 reusable payment code) contact handling. Previously, if a single contact in your PayNym following/followers list had a malformed payment code, the app either kept a broken contact w…

Null payment code previously stored in contact objectPotential NullPointerException or downstream dereference of null PaymentCode in contact lists/searchWhole PayNym response could fail on one malformed contact
94ebb849by Craig Raw+43−114 files
No security note in commit
Informational 19 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

skip the exchange currencies request in offline mode in the desktop and terminal general settings

This change stops Sparrow Wallet from trying to fetch live fiat-currency exchange rates when the user has explicitly chosen 'offline mode'. Instead of making a network request that is doomed to fail, it now reuses the currency already save…

Avoids unnecessary network egress in offline modeReduces error/warning noise for expected offline behavior
b91f7993by Craig Raw+15−12 files
No security note in commit
Low 37 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

skip addresses already given out under a label and widen the gap limit on an explicit advance in the terminal receive dialog

This commit fixes two related Bitcoin wallet behaviors in Sparrow. First, when you ask for a new receive address, the wallet now skips any address that already has a label, because a label means that address was already given to someone. P…

Address reuse prevention: labeled-but-empty addresses are now skipped consistently across desktop and terminal receive flowsGap-limit widening on explicit advance reduces risk of missing funds during wallet recovery/rescanLogic centralized in WalletForm to reduce UI-specific divergence
cae870ceby Craig Raw+85−164 files
No security note in commit
Low 44 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

cap bbqr display and pdf encodings at the 1295 parts the header can number, using larger parts for data that needs more rather than emitting a sequence that cannot be reassembled

This commit fixes a bug in Sparrow Wallet's BBQ QR code format. Previously, if a large transaction or data blob needed more than 1,295 QR-code-sized pieces, the app would generate pieces with impossible sequence numbers that could not be r…

Integer/sequence-number overflow-like limit violation in a data-encoding protocolPotential denial-of-service or data-integrity failure when exporting large transactions via QRRound-trip unit test added to prevent regression
4b5326d8by Craig Raw+27−12 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidateremove unused signature verification results in satochip and keycard signers, note where signatures are verifiedby Craig Raw · 866e9893 · Aug 4, 2026 · 2 filesMessage 65 · AdequateInformational 18Details
Commit message · Craig Raw

remove unused signature verification results in satochip and keycard signers, note where signatures are verified

65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
signing boundarydefensive validationsigning or wallet path
AI analysis · Informational 18/100

This commit removes leftover code that checked whether signatures from hardware card signers were valid, but then threw away the result. The signatures are still verified later by a different part of the wallet when the signed transaction is combined. The change is essentially a cleanup with no known security flaw, though it slightly reduces defense-in-depth by removing an early, unused sanity check.

Security candidateadd option to ignore dust on private key sweepby nroktib · cf797ea0 · Jul 29, 2026 · 1 fileMessage 50 · ThinInformational 19Details
Commit message · nroktib

add option to ignore dust on private key sweep

50/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
secret or key materialsigning or wallet path
AI analysis · Informational 19/100

This commit adds a user-facing checkbox labeled 'Ignore dust' to the private-key sweep feature in Sparrow Wallet. When enabled, very small ('dust') unspent outputs linked to the swept key are excluded from the transaction. This is a usability and privacy improvement, not a security fix, because dust outputs are often sent by third parties to track wallets or to make sweeps uneconomical due to fees. There is no evidence in the commit or supplied references that this addresses a vulnerability or was disclosed as a security issue.

Security candidateupdate external tor socks proxy control port authenticationby Craig Raw · b3d51bce · Jul 20, 2026 · 1 fileMessage 55 · ThinModerate 59Details
Commit message · Craig Raw

update external tor socks proxy control port authentication

55/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
access controlsigning or wallet path
AI analysis · Moderate 59/100

This commit hardens how Sparrow Wallet talks to an external Tor proxy's control port. Previously, when asking Tor for a new identity, the app used an older authentication method that could send the contents of a secret cookie file over the local connection. The update switches to Tor's 'SAFECOOKIE' challenge-response authentication, verifies the server before revealing anything, and refuses to open the control connection unless the target address is on the local computer (loopback). This reduces the risk that a malicious or misconfigured remote proxy could steal the Tor cookie or abuse the control port.

Security candidatecheck all open tabs when verifying a scanned or loaded transaction matches the originating psbtby Craig Raw · 078af174 · Jul 16, 2026 · 4 filesMessage 50 · ThinModerate 59Details
Commit message · Craig Raw

check all open tabs when verifying a scanned or loaded transaction matches the originating psbt

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundarysigning or wallet path
AI analysis · Moderate 59/100

This commit tightens how Sparrow Wallet checks that a scanned QR code or loaded file matches the transaction the user is currently working on. Previously, the app only compared the new transaction/PSBT against the single currently open tab. Now it checks all open transaction tabs. This reduces the chance that a user accidentally accepts a wrong or maliciously substituted transaction because they had the wrong tab active. It is a defensive hardening fix, not a clear-cut remote exploit.

Security candidateverify scanned or loaded transactions match the originating psbtby Craig Raw · 4b8a4594 · Jul 16, 2026 · 4 filesMessage 60 · AdequateModerate 59Details
Commit message · Craig Raw

verify scanned or loaded transactions match the originating psbt

60/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing boundarysigning or wallet path
AI analysis · Moderate 59/100

This commit adds a safety check in the Sparrow Wallet desktop app to make sure a transaction loaded from a file or scanned from a QR code actually matches the PSBT (a partially-signed Bitcoin transaction) that was already open. Before this change, the app would accept any transaction or PSBT from a file/scan and display it, which could mislead a user into thinking a different transaction was the one they intended to sign. The fix shows an error dialog when the loaded or scanned data does not match the original PSBT, and includes a special message for silent-payment transactions that cannot be verified from a final transaction alone.

Security candidatesha pin all github actions for package workflowby Craig Raw · 72c1d822 · Jul 13, 2026 · 1 fileMessage 45 · ThinLow 37Details
Commit message · Craig Raw

sha pin all github actions for package workflow

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
access controldocumentation-only discount
AI analysis · Low 37/100

This commit changes the project's automated build workflow to lock down the exact versions of external GitHub Actions it uses by specifying their cryptographic SHA fingerprints instead of version tags. This is a defensive hardening measure that reduces the risk of a supply-chain attack, where a malicious or compromised update to a third-party action could tamper with the wallet's build artifacts or signing certificates.

Security candidatecreate gradle dependency verification update workflowby nzb-tuxxx · c7798d92 · Jul 13, 2026 · 2 filesMessage 60 · AdequateInformational 12Details
Commit message · nzb-tuxxx

create gradle dependency verification update workflow

60/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
defensive validationboot or update pathdocumentation-only discount
AI analysis · Informational 12/100

This commit adds a GitHub Actions workflow that automatically updates the project's Gradle dependency verification files. These files are a security control that helps ensure downloaded build dependencies have not been tampered with. The change itself is a defensive automation improvement and does not introduce a vulnerability or malicious behavior.

Security candidatechange bip329 wallet labels export to only assert spendable false for frozen coins and omit otherwiseby Craig Raw · 37bab9f3 · Jul 2, 2026 · 1 fileMessage 62 · AdequateLow 28Details
Commit message · Craig Raw

change bip329 wallet labels export to only assert spendable false for frozen coins and omit otherwise

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Explains rationale or failure mode! No meaningful explanatory body
Why it was queued
secret or key materialsigning or wallet path
AI analysis · Low 28/100

This commit fixes how Sparrow Wallet exports coin labels in the BIP-329 format. Previously, the export incorrectly marked every unspent coin as 'spendable=true' in the exported file, even though the BIP-329 specification says the 'spendable' field should only be used to mark coins as frozen (not spendable). Other wallets importing this file could have treated frozen coins as spendable, or made incorrect assumptions about the user's coins. The fix now only writes 'spendable=false' for frozen coins and leaves the field out otherwise.

Security candidateimprove verification of psbt sighash typesby Craig Raw · 61ed816c · May 31, 2026 · 2 filesMessage 55 · ThinModerate 60Details
Commit message · Craig Raw

improve verification of psbt sighash types

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing boundarydefensive validationsigning or wallet path
AI analysis · Moderate 60/100

This commit adds a safety check in Sparrow Wallet when opening a PSBT (a file format used to pass partially-signed Bitcoin transactions between wallets). Before this change, the wallet did not verify the signature-hash types declared inside the PSBT. A malicious or malformed PSBT could ask the wallet to sign in a way that unexpectedly alters what the signature covers, potentially leading to loss of funds. After the change, Sparrow warns the user and asks whether to continue.

Security candidateimprove url validation for auth47 and lnurl-authby Craig Raw · 464fade6 · May 30, 2026 · 5 filesMessage 50 · ThinModerate 63Details
Commit message · Craig Raw

improve url validation for auth47 and lnurl-auth

50/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
signing or wallet pathauthentication path
AI analysis · Moderate 63/100

This commit tightens the checks on web addresses used during two login-style features, Auth47 and LNURL-auth. Previously, a malicious or malformed callback address could use insecure schemes such as plain HTTP on the regular internet or non-web schemes like file:// or ftp://. The patch now requires callbacks to be HTTPS, a special 'srbn' scheme, or a Tor .onion address over HTTP, and adds tests to confirm the new behavior. This reduces the risk that an attacker could trick the wallet into sending authentication data to an unintended destination.

Security candidateadd custom context menu to signature text area in message sign dialogby Craig Raw · 287c943b · May 23, 2026 · 1 fileMessage 55 · ThinInformational 15Details
Commit message · Craig Raw

add custom context menu to signature text area in message sign dialog

55/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
signing boundarysigning or wallet path
AI analysis · Informational 15/100

This commit adds a standard right-click menu (copy, paste, clear) to the signature text box in Sparrow Wallet's message signing dialog. It is a routine user-interface convenience improvement with no security relevance visible in the code or commit message.

Security candidateimprove loaded psbt verificationby Craig Raw · cb92f765 · May 23, 2026 · 2 filesMessage 45 · ThinLow 40Details
Commit message · Craig Raw

improve loaded psbt verification

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing boundarydefensive validationsigning or wallet path
AI analysis · Low 40/100

This commit changes how Sparrow Wallet checks the silent payment addresses inside a loaded PSBT (a partially signed Bitcoin transaction). Previously, the wallet extracted and trusted the silent payment addresses directly from the PSBT file itself. Now it passes the PSBT to a wallet method that performs verification before returning the addresses. The change suggests the previous code may have accepted unverified or spoofed silent payment addresses from an external PSBT, which could lead to sending funds to an attacker's address, but the diff alone does not show what the new verification actually does or whether any bug was exploitable in practice.

Security candidateupdate bip322 implementation to match completed specby Craig Raw · bc7a0be8 · May 22, 2026 · 2 filesMessage 50 · ThinLow 33Details
Commit message · Craig Raw

update bip322 implementation to match completed spec

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
secret or key materialsigning or wallet path
AI analysis · Low 33/100

This commit adds a safety check when extracting a BIP-322 signature from a signed PSBT file. Before, Sparrow would blindly copy the signature into the dialog even if the message inside the PSBT did not match the message the user originally asked to sign. Now it warns the user and asks whether to continue, and if the user declines (or the extraction returns null), it no longer overwrites the signature field. This reduces the risk of a malicious or mismatched PSBT tricking a user into accepting a signature for a different message than intended.

Security candidatefinalize external inputs in cross-wallet psbts to avoid empty witnessesby Craig Raw · 79bbe7df · May 19, 2026 · 2 filesMessage 62 · AdequateModerate 55Details
Commit message · Craig Raw

finalize external inputs in cross-wallet psbts to avoid empty witnesses

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Explains rationale or failure mode! No meaningful explanatory body
Why it was queued
signing boundary
AI analysis · Moderate 55/100

This commit fixes a problem where Sparrow Wallet did not properly 'finalize' transaction inputs that belong to another wallet when creating or handling cross-wallet PSBTs (Partially Signed Bitcoin Transactions). Without finalization, those inputs could end up with empty witness data, which may cause a signed transaction to be rejected by the Bitcoin network or to behave unexpectedly. In practical terms, this could affect multi-party or multi-wallet transactions where one wallet provides inputs it does not fully control.

Security candidateadd bip322 message signing for silent payments walletsby Craig Raw · a2eb937f · May 18, 2026 · 4 filesMessage 50 · ThinInformational 19Details
Commit message · Craig Raw

add bip322 message signing for silent payments wallets

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
secret or key materialsigning boundarysigning or wallet path
AI analysis · Informational 19/100

This commit adds the ability for Sparrow Wallet users with 'silent payments' wallets to sign messages using the BIP322 standard. It is a feature addition that extends existing message-signing support to a new wallet type. There is no indication in the commit that it fixes a security bug or vulnerability.

Security candidatedefault sp wallet birthdate to creation time to avoid full rescansby Craig Raw · a035767e · May 14, 2026 · 4 filesMessage 62 · AdequateInformational 19Details
Commit message · Craig Raw

default sp wallet birthdate to creation time to avoid full rescans

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Explains rationale or failure mode! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 19/100

This commit changes Sparrow Wallet so that newly created or renamed single-signature (SINGLE_SP) wallets get a default 'birth date' set to the current time. The birth date tells the wallet how far back in the blockchain it needs to scan for transactions. Without it, the wallet would perform a full rescan of the entire blockchain, which is slow and resource-intensive. The change is a performance/usability improvement, not a security fix.

Security candidateimplement sp wallet loadingby Craig Raw · e64069f0 · May 4, 2026 · 22 filesMessage 35 · OpaqueInformational 23Details
Commit message · Craig Raw

implement sp wallet loading

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
signing or wallet pathboot or update path
AI analysis · Informational 23/100

This commit adds support for loading and refreshing 'silent payments' (a newer Bitcoin privacy feature) wallets in Sparrow. It introduces server subscription management, scan caching, and UI wiring. There is no direct evidence in the commit of a security vulnerability, but the new code handles private scan keys and network state, so correctness matters. The change is large and touches concurrency, making subtle bugs possible, but nothing in the diff clearly enables theft, remote code execution, or data leakage.

Security candidatesupport sp wallet import via all keystore importersby Craig Raw · 723b004e · Apr 27, 2026 · 13 filesMessage 50 · ThinInformational 19Details
Commit message · Craig Raw

support sp wallet import via all keystore importers

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 19/100

This commit adds the ability to import a new kind of Bitcoin wallet—called a 'silent payment' (SP) singlesig wallet—through the same screens and file formats that already supported ordinary HD singlesig wallets. It updates dropdown menus, import logic, and several hardware-wallet/file parsers so users can choose between HD and SP when importing. There is no direct evidence in the commit of a security vulnerability; it reads as a feature expansion with explicit guardrails (some importers reject SP if they cannot support it).

Security candidateadd policy type to all keystore import interfaces and factory methods for explicit keystore xpub or spscan field populationby Craig Raw · 0459f4ca · Apr 26, 2026 · 57 filesMessage 50 · ThinLow 33Details
Commit message · Craig Raw

add policy type to all keystore import interfaces and factory methods for explicit keystore xpub or spscan field population

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathseed or entropy pathsigning or wallet path
AI analysis · Low 33/100

This commit is a broad code change that threads a new 'policy type' value through many wallet import paths. The main practical effect visible in the diff is adding support for importing a new kind of Bitcoin wallet called 'silent payments' (policy type SINGLE_SP) from Coldcard hardware wallets. It also makes sure the correct extended public key or silent-payment scan key is set when a keystore is created, depending on the wallet type. There is no explicit mention of a security bug or fix in the commit message or code, but the change touches sensitive key-handling code and removes some workarounds that previously forced wallet-model labels.

Security candidateimprove sp related output descriptor and psbt behaviourby Craig Raw · c23dbeed · Apr 24, 2026 · 9 filesMessage 50 · ThinLow 26Details
Commit message · Craig Raw

improve sp related output descriptor and psbt behaviour

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundarysigning or wallet path
AI analysis · Low 26/100

This commit improves how Sparrow Wallet handles a newer Bitcoin address type called 'Silent Payments' (SP). It adds null-safety checks so the app doesn't crash when an extended public key is missing, supports exporting and importing labels tied to Silent Payment scan keys, and updates UI labels. Most changes are defensive or feature-related rather than fixes for active attacks.

Security candidateimplement silent payments change outputs and other sp related fixesby Craig Raw · c6700884 · Apr 23, 2026 · 8 filesMessage 50 · ThinLow 27Details
Commit message · Craig Raw

implement silent payments change outputs and other sp related fixes

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundarysigning or wallet path
AI analysis · Low 27/100

This commit adds support for silent payment change outputs in the Sparrow Wallet and fixes related silent payment issues. Silent payments are a newer Bitcoin privacy feature that lets someone receive payments without publicly revealing their receiving address on the blockchain. The changes touch how transactions are displayed, how change is created, and how the wallet interacts with Bitcoin Core. There is no clear security bug being fixed in the diff itself; it looks like a feature/enhancement commit with some defensive checks, such as blocking Bitcoin Core scanning for silent payment wallets because that is not yet supported.

Security candidateinitial policy type related changes from drongoby Craig Raw · 8780e515 · Apr 21, 2026 · 31 filesMessage 45 · ThinInformational 24Details
Commit message · Craig Raw

initial policy type related changes from drongo

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet pathauthentication path
AI analysis · Informational 24/100

This commit is a large but mechanical rename in the Sparrow Wallet codebase. It replaces the old policy type constants `PolicyType.SINGLE` and `PolicyType.MULTI` with more specific names `PolicyType.SINGLE_HD` and `PolicyType.MULTI_HD`, and adds handling for a new `PolicyType.SINGLE_SILENT_PAYMENTS`. It also updates method calls in the underlying `drongo` library to pass the policy type explicitly. There is no direct evidence in the diff of a security vulnerability being fixed; it reads like preparation for adding silent-payment wallet support. A few import cleanups and one new guard against exporting silent-payment wallets are included.

Security candidateadd bip32 derivation fallback when retreiving signing nodes for high-index inputsby Craig Raw · 32a35ed2 · Mar 11, 2026 · 1 fileMessage 50 · ThinLow 39Details
Commit message · Craig Raw

add bip32 derivation fallback when retreiving signing nodes for high-index inputs

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
secret or key materialsigning boundary
AI analysis · Low 39/100

This commit adds a fallback path for finding the correct private signing keys when a Bitcoin wallet handles unusual transaction inputs that use very high address indexes. Without the fallback, Sparrow might fail to locate the right key and therefore be unable to sign a valid transaction the user actually owns. The change is tiny (one line) and appears to be a bug fix rather than a clear security patch, but because it touches key derivation it could affect whether funds can be spent or whether the wallet behaves safely with non-standard inputs.

Security candidateavoid npe when the extracting signature from a bip322 psbtby Craig Raw · 21f9f9fe · Mar 10, 2026 · 1 fileMessage 55 · ThinLow 28Details
Commit message · Craig Raw

avoid npe when the extracting signature from a bip322 psbt

55/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
secret or key materialsigning boundary
AI analysis · Low 28/100

This commit fixes a null pointer exception (a common software crash) that could occur when Sparrow Wallet tried to extract a signature from a special type of Bitcoin proof-of-ownership transaction (BIP322 PSBT). Without seeing the actual code change, we can only say it appears to be a defensive bug fix that prevents a crash during signature handling. There is no evidence in the commit message that this was disclosed or treated as a security vulnerability by the project.

Security candidateuse psbtv0 for bip322 psbt qr and file exportsby Craig Raw · 6c6664f2 · Mar 10, 2026 · 1 fileMessage 45 · ThinLow 29Details
Commit message · Craig Raw

use psbtv0 for bip322 psbt qr and file exports

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
secret or key materialsigning boundarysigning or wallet path
AI analysis · Low 29/100

This commit changes how Sparrow Wallet exports BIP-322 message-signing PSBTs (Partially Signed Bitcoin Transactions) to QR codes and files. Instead of serializing the PSBT in whatever internal version it was created, it now explicitly requests a PSBT version 0 format for export. This is likely a compatibility fix to ensure other wallets and tools can read the exported PSBT correctly.