SW
← All projectsSparrow

Sparrow Wallet

Desktop Bitcoin wallet focused on security, privacy, multisignature, and hardware signers.

BitcoinHardware integrationSoftware walletsNormal
Repository coverage

410 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

71security candidates271second-pass queue399AI analyses
88commits · 30 days
151commits · 60 days
249commits · 180 days
404commits · 365 days
Backfill bands
Aug 5 → Feb 6100 seen9 candidatesComplete
Feb 6 → Jun 6128 seen15 candidatesComplete
Jun 6 → Jul 67 seen1 candidatesComplete
Jul 6 → Aug 546 seen8 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

48/100 average clarity
0Strong · 80–100
35Adequate · 60–79
324Thin · 40–59
51Opaque · 0–39
2security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Craig Raw39667385647
doblon8313048
nzb-tuxxx212060
Michele Balistreri212048
nroktib111050
Liz Lightning202045
PeterXMR101045
Ian McKenzie101050
ottosch101050
craigraw101060
Analysis record

Published AI watches

Last scanned 50 minutes ago

Informational 17 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

remove the surplus signatures progress bar segments a finalized multisig transaction discards

This commit fixes a UI display bug in Sparrow Wallet's signature progress bar. When a multi-signature Bitcoin transaction becomes finalized, extra signatures beyond the required threshold are discarded. Previously, the progress bar did not…

UI state desynchronization after multisig finalizationProgress bar segment count mismatch with actual signature setNo change to cryptographic or transaction validation code
40f77206by Craig Raw+9−12 files
No security note in commit
Informational 15 AI analysisMessage 38 · Opaque
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

bump to v2.5.6

This commit is a routine version bump from 2.5.5 to 2.5.6. It only changes version strings in four files (build configuration, documentation, macOS app metadata, and a Java source constant). There are no code logic changes, no bug fixes, a…

f7f36d00by Craig Raw+4−44 files
No security note in commit
Informational 17 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

use a framerate-capped interpolated timeline for the server toggle and wallet tab loading pulse animations, and stop any running server toggle pulse before starting a new one

This commit tweaks two visual animations in the Sparrow Wallet desktop app: the server connection toggle pulse and the wallet loading pulse. It caps how often the screen is redrawn during the pulse and makes sure any already-running pulse …

Resource-consumption / performance hardening: capped animation framerate reduces CPU/GPU load from continuous 60 Hz redraws.State-management hardening: stopping an existing pulse before starting a new one prevents accumulation of running Timelines.No direct security flaw is present in the diff; signals are defensive-hardening in nature.
4da29f4eby Craig Raw+7−132 files
No security note in commit
Low 45 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

cut pasted amounts to the unit precision in the send tab and send to many, and stop the csv import skipping fractional sats and exponent amounts

This commit fixes how Sparrow Wallet handles pasted or imported Bitcoin amounts. Previously, very small or oddly formatted amounts (like scientific notation '1e-8' or fractional satoshis) could be misread or silently skipped during CSV imp…

Amount parsing inconsistency between UI paste and CSV importSilent swallowing of NumberFormatException could skip payment rowsUse of Double.parseDouble for monetary amounts
9e999d3fby Craig Raw+39−362 files
No security note in commit
Informational 15 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

add a system theme option that follows the os light or dark setting, and make it the default for new installs

This commit adds a new 'System' theme option to the Sparrow Wallet desktop app that automatically follows the operating system's light or dark mode setting, and makes it the default for new installations. It also updates various UI compone…

a573f22aby Craig Raw+90−3215 files
No security note in commit
Low 36 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

refuse bitbox02 keystore import and discovery for legacy p2sh and p2pkh wallets it cannot sign for, and hide those script types from the device import menus

This commit tightens how Sparrow Wallet handles BitBox02 hardware wallets when working with older Bitcoin address formats (legacy P2PKH and P2SH). Previously, the app could let a user import or discover a wallet that the BitBox02 cannot ac…

Prevents user from configuring a signing device for wallet types the device cannot sign forCould avoid funds becoming unspendable or requiring complex recovery if a user unknowingly imported an unsupported legacy script typeReplaces hard-coded device-specific logic with a generic capability model, reducing future similar issues
de169b18by Craig Raw+23−73 files
No security note in commit
Low 37 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

reject unknown command line options and values given to flags with an error and exit code instead of starting on the default network, and accept the --option=value form

This commit tightens how Sparrow Wallet handles command-line arguments. Previously, typos or unexpected values could silently be ignored, causing the wallet to start on the default Bitcoin network instead of the one the user intended. Now,…

Command-line argument parsing now rejects unknown options instead of silently ignoring themBoolean flags now reject `--flag=value` forms that would otherwise silently pass the value through as a file/URI argumentProgram now exits with non-zero status on argument errors, reducing risk of unintended default-network startup
46197586by Craig Raw+26−12 files
No security note in commit
Low 37 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

ignore amount digits beyond the selected unit precision in the send tab amount and fee fields and the send to many grid, instead of truncating them in the payment

This commit fixes a UI bug in the Sparrow Bitcoin wallet where typing or pasting too many decimal digits into amount or fee fields could be silently truncated, potentially causing a user to send a different amount than they saw on screen. …

Precision-loss / truncation bug in financial input fieldsUser-facing amount/fee mismatch between displayed value and parsed valueInput validation now tied to unit-specific precision (satoshis indivisible)
6cde97adby Craig Raw+48−315 files
No security note in commit
Low 41 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

derive public keys from the seed when importing a sparrow wallet file

This commit changes how Sparrow Wallet restores its own wallet files. Previously, when importing a Sparrow wallet file, the public keys (used to find transactions and addresses) might not be correctly rebuilt from the seed phrase. The fix …

Correctness fix for key material restoration during wallet importAdds test coverage for encrypted and unencrypted seed-based wallet importAdds test coverage for watch-only wallet import
1fb4e8bbby Craig Raw+149−23 files
No security note in commit
Informational 21 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

add file import of the xpub descriptor jade writes to usb storage

This commit adds the ability to import a Bitcoin wallet's extended public key (xpub) into Sparrow Wallet from a file written by a Blockstream Jade hardware wallet via USB storage. Previously, Jade only supported QR-code import. The change …

New file import path parses external descriptor data and converts it to a keystoreScript type mismatch is explicitly rejected with an IllegalArgumentExceptionSilent payments policy (SINGLE_SP) is explicitly rejected
c4b53879by Craig Raw+74−44 files
No security note in commit
Low 34 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

include the non-witness utxo in psbts for krux keystores, and in the qr display when the psbt has more than one input

This commit changes how Sparrow Wallet builds QR codes for partially-signed Bitcoin transactions (PSBTs). For certain hardware wallets (Krux), it now includes extra data (the full previous transaction, called 'non-witness utxo') in the QR …

Hardware wallet signing correctness: missing non-witness UTXO data can cause some signers to reject or mis-handle multi-input segwit PSBTsQR payload size increase: larger QR codes may be harder to scan reliably, potentially affecting usabilitySubproject update (drongo) likely contains related serialization logic changes
0e2c402fby Craig Raw+4−32 files
No security note in commit
Low 35 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

clear a scanned wallet when a file, text payload or unrecognised qr is imported in the same pane

This commit fixes a UI state bug in Sparrow Wallet's import pane. Previously, when a user scanned or imported a wallet and then imported a non-wallet file, text payload, or unrecognized QR code in the same pane, the previously loaded walle…

Stale UI state could mislead users about which wallet is loadedCross-import state retention in single import paneUser interface consistency fix with security-relevant consequences
d7ded1e7by Craig Raw+4−21 file
No security note in commit
Low 35 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

lock the cormorant store against client connection reads and serve history as a copy, and close the client socket however its handler exits

This commit fixes two reliability issues in Sparrow Wallet's built-in Electrum server (Cormorant). First, it makes sure the internal transaction store is locked while being read or updated, and returns a fresh copy of a wallet's history so…

Concurrency: shared mutable store accessed by client handler and polling threads now synchronizedData consistency: history returned as a defensive copy to avoid iterator seeing concurrent modificationsResource leak: client socket now closed in finally block regardless of exception path
6cc4d50aby Craig Raw+57−94 files
No security note in commit
Low 44 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

ensure cormorant responses and notifications are always serialized per client connection

This commit fixes a race condition in Sparrow Wallet's built-in Electrum server (Cormorant). Previously, a response to a wallet client and an asynchronous notification (like a new block or a balance update) could be written to the same net…

Race condition on shared socket output streamConcurrent writes from RPC response path and event-bus notification pathPotential interleaving/framing of JSON-RPC messages on same TCP connection
6d9d3014by Craig Raw+146−303 files
No security note in commit
Low 27 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

wake a silent payments history waiter when a failed widening restores a completed scan, rather than leaving it parked for the session

This commit fixes a bug in Sparrow Wallet's silent-payments scanning cache. If a background scan had already finished, then a later 'widening' request to extend the scan failed and rolled back, any history request that arrived during the f…

Concurrency / condition-variable waiter starvationSilent-payments history lookup hang / wallet UI unresponsivenessFailure-recovery path missing signal on rollback
7868a94dby Craig Raw+100−122 files
No security note in commit
Informational 18 AI analysisMessage 60 · Adequate
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

guard a short server.version response in the desktop and terminal connection tests

This commit fixes a minor crash bug in Sparrow Wallet's connection-test screens. Previously, if a Bitcoin Electrum server answered the version request with an unusually short response, the wallet would try to read list items that didn't ex…

Input validation hardening for external server responseIndexOutOfBoundsException prevented in UI feedback pathNo cryptographic, authentication, or transaction logic touched
66348fafby Craig Raw+4−42 files
No security note in commit
Low 37 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

omit a paynym contact whose payment code does not parse rather than keeping it with a null code or failing the whole paynym response

This commit fixes a bug in Sparrow Wallet's PayNym (BIP47 reusable payment code) contact handling. Previously, if a single contact in your PayNym following/followers list had a malformed payment code, the app either kept a broken contact w…

Null payment code previously stored in contact objectPotential NullPointerException or downstream dereference of null PaymentCode in contact lists/searchWhole PayNym response could fail on one malformed contact
94ebb849by Craig Raw+43−114 files
No security note in commit
Informational 19 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

skip the exchange currencies request in offline mode in the desktop and terminal general settings

This change stops Sparrow Wallet from trying to fetch live fiat-currency exchange rates when the user has explicitly chosen 'offline mode'. Instead of making a network request that is doomed to fail, it now reuses the currency already save…

Avoids unnecessary network egress in offline modeReduces error/warning noise for expected offline behavior
b91f7993by Craig Raw+15−12 files
No security note in commit
Low 37 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

skip addresses already given out under a label and widen the gap limit on an explicit advance in the terminal receive dialog

This commit fixes two related Bitcoin wallet behaviors in Sparrow. First, when you ask for a new receive address, the wallet now skips any address that already has a label, because a label means that address was already given to someone. P…

Address reuse prevention: labeled-but-empty addresses are now skipped consistently across desktop and terminal receive flowsGap-limit widening on explicit advance reduces risk of missing funds during wallet recovery/rescanLogic centralized in WalletForm to reduce UI-specific divergence
cae870ceby Craig Raw+85−164 files
No security note in commit
Low 44 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

cap bbqr display and pdf encodings at the 1295 parts the header can number, using larger parts for data that needs more rather than emitting a sequence that cannot be reassembled

This commit fixes a bug in Sparrow Wallet's BBQ QR code format. Previously, if a large transaction or data blob needed more than 1,295 QR-code-sized pieces, the app would generate pieces with impossible sequence numbers that could not be r…

Integer/sequence-number overflow-like limit violation in a data-encoding protocolPotential denial-of-service or data-integrity failure when exporting large transactions via QRRound-trip unit test added to prevent regression
4b5326d8by Craig Raw+27−12 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidateimprove reset instructions for trezor passphrase changeby Craig Raw · 67e15733 · Mar 9, 2026 · 1 fileMessage 50 · ThinInformational 15Details
Commit message · Craig Raw

improve reset instructions for trezor passphrase change

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
access controlsigning or wallet path
AI analysis · Informational 15/100

This commit only changes the wording of an on-screen instruction shown to users after they change the passphrase on a Trezor hardware wallet. It tells users to restart the device and adds guidance for battery-powered devices. There is no code behavior change and no security fix.

Security candidatefix psbtv2 and dst related transaction editor issues around tx version and locktimeby Craig Raw · 37665854 · Mar 6, 2026 · 3 filesMessage 50 · ThinLow 35Details
Commit message · Craig Raw

fix psbtv2 and dst related transaction editor issues around tx version and locktime

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundarysigning or wallet path
AI analysis · Low 35/100

This commit fixes UI bugs in Sparrow Wallet's transaction editor when working with PSBT v2 (a modern format for partially-signed Bitcoin transactions) and 'DST' (likely descriptor/transaction templates). Previously, when a user changed transaction version, locktime, or input sequence numbers in the editor, the underlying PSBT object was not updated to match. This could cause the displayed/edited transaction to disagree with the actual PSBT being signed or exported, potentially leading to unexpected transaction behavior or failed signing. The patch makes the editor keep the PSBT in sync and also disables locktime controls when the form is read-only.

Security candidatesupport qr and file methods for signing messages via psbt when bip322 is selectedby Craig Raw · 537c2ffe · Mar 5, 2026 · 2 filesMessage 50 · ThinInformational 22Details
Commit message · Craig Raw

support qr and file methods for signing messages via psbt when bip322 is selected

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
secret or key materialsigning boundarysigning or wallet path
AI analysis · Informational 22/100

This commit adds new ways to sign Bitcoin messages using the BIP-322 standard through QR codes and PSBT files in Sparrow Wallet. It changes how the wallet decides which signing formats are allowed and removes a fallback that previously forced older P2PKH-style signing for wallets that couldn't sign BIP-322. The main concern is that the new logic may let users select a signing format their hardware wallet or keystore doesn't actually support, or may mishandle PSBT files imported back from an external signer. There is no direct evidence in the commit of a vulnerability being fixed or introduced, but the change touches security-sensitive signing code.

Security candidateadd keepkey passphrase supportby Craig Raw · e13fe897 · Feb 12, 2026 · 1 fileMessage 35 · OpaqueInformational 2Details
Commit message · Craig Raw

add keepkey passphrase support

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
access control
AI analysis · Informational 2/100

This commit appears to add support for using a passphrase with KeepKey hardware wallets in Sparrow Wallet. A passphrase is an extra word added to a wallet seed for additional security. No actual code diff was provided, so we cannot assess whether the change was implemented safely or unsafely. Based only on the title and one-line description, there is no visible security issue.

Security candidateremove extension-less file associations which are no longer supported by jpackageby Craig Raw · a120d08e · Feb 6, 2026 · 4 filesMessage 50 · ThinInformational 17Details
Commit message · Craig Raw

remove extension-less file associations which are no longer supported by jpackage

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 17/100

This commit removes Sparrow Wallet's installer associations for handling 'bitcoin:', 'lightning:', and 'auth47:' web-style links. The change was made because the packaging tool (jpackage) no longer supports these extension-less file associations. This is a compatibility/build cleanup, not a security fix. A side effect is that after installing future Sparrow versions, clicking these link types in a browser may no longer automatically open Sparrow, depending on the platform and how the installer is configured.

Security candidatefix trezor change detection on signingby Craig Raw · 49d807f3 · Jan 22, 2026 · 1 fileMessage 45 · ThinModerate 53Details
Commit message · Craig Raw

fix trezor change detection on signing

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundary
AI analysis · Moderate 53/100

This commit claims to fix how Sparrow Wallet detects 'change' outputs when signing transactions with a Trezor hardware wallet. Change outputs are coins sent back to the user's own wallet during a payment. If detection fails, the wallet or device might mislabel or mishandle those coins, which could confuse the user or in some designs affect how funds are verified. The actual code change is only one line in one file, but the diff was not provided, so we cannot verify what exactly was changed.

Security candidatefix handling of non-standard key derivations when writing output descriptorsby Craig Raw · ab99f1d3 · Jan 15, 2026 · 2 filesMessage 50 · ThinLow 32Details
Commit message · Craig Raw

fix handling of non-standard key derivations when writing output descriptors

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
secret or key materialsigning or wallet path
AI analysis · Low 32/100

This commit fixes how Sparrow Wallet writes output descriptors when a wallet uses a non-standard key derivation path. Previously, the code stripped the leading 'm/' from the derivation path in a simplistic way, which could produce incorrect descriptors for unusual paths. The fix now uses a dedicated parser/formatter (KeyDerivation.parsePath/writePath) to handle the path correctly. This is primarily a correctness/reliability fix, but incorrect descriptors could in theory lead to users backing up or sharing wrong wallet configuration data.

Security candidateadd support for keycard via smart card interfaceby Michele Balistreri · 0c679627 · Jan 13, 2026 · 18 filesMessage 45 · ThinLow 25Details
Commit message · Michele Balistreri

add support for keycard via smart card interface

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Low 25/100

This commit adds a brand-new feature to Sparrow Wallet: support for Keycard hardware wallets via a smart card interface. It introduces many new Java files that handle low-level smart card communication, secure channel encryption, PIN handling, key derivation, and signing. The change is a large feature addition (+3,250 lines) rather than a small bug fix. There is no direct evidence in the commit message or diff that this fixes a known security vulnerability, and no external references were provided. Some implementation details—such as hardcoded pairing passwords, a TODO comment about device certificate verification, and a fallback to a default derivation path—could become security concerns if misused, but they are not proven vulnerabilities on their own.

Security candidateadd any missing key path information to psbts once signing wallet is chosenby Craig Raw · 34900d29 · Jan 3, 2026 · 2 filesMessage 50 · ThinLow 29Details
Commit message · Craig Raw

add any missing key path information to psbts once signing wallet is chosen

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundarysigning or wallet path
AI analysis · Low 29/100

This commit changes Sparrow Wallet so that, when a user chooses a wallet to sign a Bitcoin transaction (PSBT), the app automatically fills in any missing key-path details needed for signing. The change is small and appears to be a usability/fix improvement rather than a clear security patch. There is no vendor statement or external reference saying this fixes a vulnerability, so we cannot confidently label it as a security fix.

Security candidateimprove thp pairing flow, and add passphrase session supportby Craig Raw · 59d85cdd · Dec 18, 2025 · 2 filesMessage 50 · ThinInformational 18Details
Commit message · Craig Raw

improve thp pairing flow, and add passphrase session support

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
access controlsigning or wallet path
AI analysis · Informational 18/100

This commit improves the user interface for pairing a Trezor hardware wallet with Sparrow Wallet. It adds a numeric-only input filter for the pairing code, makes the text larger, and shows the device name in pairing messages. There is no clear security vulnerability in the changes.

Security candidateminor ui changes to master private key importby Craig Raw · f900f6dc · Dec 4, 2025 · 2 filesMessage 50 · ThinInformational 15Details
Commit message · Craig Raw

minor ui changes to master private key import

50/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
secret or key materialcryptography-sensitive pathsigning or wallet path
AI analysis · Informational 15/100

This commit makes two small user-interface tweaks to the screen where a user imports a master private key: it changes a title to say 'Enter master private key', makes the Import button the default button that activates when the user presses Enter, and adds a period to a description sentence. There is no security-relevant code change.

Security candidateupdate drongo for bip32 testsby Craig Raw · ac044c6f · Nov 24, 2025 · 1 fileMessage 55 · ThinInformational 4Details
Commit message · Craig Raw

update drongo for bip32 tests

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
secret or key material
AI analysis · Informational 4/100

This commit updates a dependency or submodule named 'drongo' specifically for BIP32 (a Bitcoin wallet key-derivation standard) tests. The change is a single-line version bump in a test-related component. There is no diff available and no security-relevant description in the commit message.

Security candidateimprove psbt/tx matching and ensure incoming psbt signatures are always verifiedby Craig Raw · d2d45e54 · Nov 24, 2025 · 5 filesMessage 50 · ThinModerate 58Details
Commit message · Craig Raw

improve psbt/tx matching and ensure incoming psbt signatures are always verified

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundarysigning or wallet path
AI analysis · Moderate 58/100

This commit changes how Sparrow Wallet matches incoming PSBTs (Partially Signed Bitcoin Transactions) against already-open transaction tabs, and adds verification of signatures before combining them. Previously, the app matched transactions by exact byte-for-byte equality and then merged PSBTs without checking that signatures in the incoming PSBT were valid. Now it matches by transaction ID and witness data, warns when two transactions share the same ID but have different witnesses, verifies signatures before merging, and warns users about silent-payments transactions whose recipient addresses cannot be verified. The change reduces the risk that a malicious or malformed PSBT could silently overwrite or merge with an existing transaction.

Security candidatehandle errors if silent payments psbt validation failsby Craig Raw · c16997ea · Nov 19, 2025 · 4 filesMessage 50 · ThinLow 43Details
Commit message · Craig Raw

handle errors if silent payments psbt validation fails

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundarysigning or wallet path
AI analysis · Low 43/100

This commit adds error handling for a new type of PSBT (Partially Signed Bitcoin Transaction) validation failure related to silent payments. Previously, if silent payment proof validation failed during transaction extraction, broadcasting, saving, sweeping private keys, or payjoin, the application would likely crash or propagate an unhandled exception. Now it shows an error dialog instead. The commit also makes some related payjoin logic more robust, such as computing the additional fee contribution before serialization and fixing a change-output value comparison bug.

Security candidateminor updates to handle psbtv2 as the default internal representationby Craig Raw · 21543de0 · Nov 19, 2025 · 4 filesMessage 50 · ThinLow 27Details
Commit message · Craig Raw

minor updates to handle psbtv2 as the default internal representation

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundarysigning or wallet path
AI analysis · Low 27/100

This commit changes Sparrow Wallet to use PSBT version 2 as its default internal format instead of converting PSBTv2 files down to PSBTv0. It also adjusts how transactions are compared (by transaction ID instead of object equality) and changes how a PayJoin PSBT is prepared before being exported. These are internal refactoring changes; there is no direct evidence in the commit that they fix a security vulnerability.

Security candidateuse sparrowwallet action for macos codesigningby Craig Raw · a0f7e2e6 · Nov 10, 2025 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · Craig Raw

use sparrowwallet action for macos codesigning

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundarydocumentation-only discount
AI analysis · Informational 15/100

This commit updates the project's automated build workflow to use a custom Sparrow Wallet action for signing and notarizing macOS releases. It is a routine CI/CD configuration change and does not contain any apparent security vulnerability.

Security candidateshow signing keystores in transaction blockchain form for spends from multisig walletsby Craig Raw · 2f62a9e9 · Nov 4, 2025 · 3 filesMessage 50 · ThinInformational 18Details
Commit message · Craig Raw

show signing keystores in transaction blockchain form for spends from multisig wallets

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundarysigning or wallet path
AI analysis · Informational 18/100

This commit adds a small UI label that shows which signing keystores have already signed a multisig transaction when viewing it in the transaction details form. It is a user-interface improvement, not a security fix or vulnerability.

Security candidateuse language-independent sid for windows users group permissionby doblon8 · 31909b7a · Oct 21, 2025 · 1 fileMessage 50 · ThinInformational 18Details
Commit message · doblon8

use language-independent sid for windows users group permission

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
credential or privilege state
AI analysis · Informational 18/100

This commit fixes a Windows build script bug. Previously, the build process granted file permissions to a group literally named 'Users', which fails on non-English Windows versions where that group has a translated name. The change uses the universal numeric identifier (SID) for the Users group instead, so the build works on all language versions of Windows. It is a reliability/localization fix, not a security vulnerability fix.

Security candidaterestore pre gradle 9 archive task behaviour for file permissionsby Craig Raw · e2fa3df0 · Oct 3, 2025 · 1 fileMessage 50 · ThinLow 27Details
Commit message · Craig Raw

restore pre gradle 9 archive task behaviour for file permissions

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
credential or privilege state
AI analysis · Low 27/100

This commit changes how the wallet's build packaging handles file metadata. It removes settings that make archive files (like ZIPs) bit-for-bit identical every time they are built, and instead restores an older Gradle behavior that preserves file permissions (such as whether a file is executable). This is likely a build-fix rather than a direct security patch, but it could affect whether downloaded archives have correct executable bits, which matters for usability and trust in reproducible builds.

Security candidateimprove implementation of adding dns payment information from psbtby Craig Raw · cca9ab10 · Oct 2, 2025 · 1 fileMessage 50 · ThinLow 28Details
Commit message · Craig Raw

improve implementation of adding dns payment information from psbt

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundarysigning or wallet path
AI analysis · Low 28/100

This commit refines how Sparrow Wallet stores DNS payment details extracted from a Bitcoin PSBT (a transaction template). The old code tried to cache DNS payment info for both regular addresses and silent payment addresses in one combined flow, using helper methods like hasAddress() and hasSilentPaymentAddress(). The new code separates the two cases and, importantly, validates that the DNS payment record actually matches the address/silent payment address before caching it. This looks like a hardening change: it reduces the chance that a malicious or malformed PSBT could trick the wallet into caching a DNS payment entry for an unrelated address.

Security candidatefix non bip32 child derivation testby Craig Raw · 4ec36037 · Aug 7, 2025 · 1 fileMessage 55 · ThinInformational 3Details
Commit message · Craig Raw

fix non bip32 child derivation test

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
secret or key material
AI analysis · Informational 3/100

This appears to be a one-line change to a test file named 'drongo' with the description 'fix non bip32 child derivation test'. There is no actual diff content available, and no security-related context is provided. Based solely on the title and stats, this looks like a routine correction to a unit test for Bitcoin BIP32 hierarchical deterministic wallet key derivation logic. Nothing in the supplied materials indicates a security vulnerability, exploit, or user-facing bug.