What changed, and why it matters
This commit adds signed release assertions for the BitBox02 firmware version 9.27.1. It contains only text files and detached signatures that record the expected SHA-256 hash of the official firmware binaries. There is no code change, no bug fix, and no security patch.
No action required. Treat as routine release metadata.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The merge commit adds four files under releases/firmware-v9.27.1/: two assertion text files (one for the Bitcoin-only edition, one for the multi-edition) and two detached signatures by ‘benma’. Each assertion binds the git tag firmware/v9.27.1 (commit 391864cd3f8676a3fd4e57593462921bc01d6064) to a published firmware binary hash. This is a normal release-artifact attestation step and does not modify firmware source or behavior.
Changed components
releases/firmware-v9.27.1/assertion-bitbox02-btconly-benma.sigreleases/firmware-v9.27.1/assertion-bitbox02-btconly.txtreleases/firmware-v9.27.1/assertion-bitbox02-multi-benma.sigreleases/firmware-v9.27.1/assertion-bitbox02-multi.txtInspect captured patch +16 / −0
### releases/firmware-v9.27.1/assertion-bitbox02-btconly-benma.sig
[binary or diff unavailable]
### releases/firmware-v9.27.1/assertion-bitbox02-btconly.txt
@@ -0,0 +1,8 @@
+By signing this file, the signer confirms that the BitBox02 Bitcoin-only firmware binary built from:
+
+git tag firmware/v9.27.1
+git commit hash 391864cd3f8676a3fd4e57593462921bc01d6064
+
+resulted, at the time of signing, in a firmware binary file with the following sha256sum:
+
+4fbf3da03f636004d4501bfe7e8043fc0af7c0740009471fca1760a36de24a92
### releases/firmware-v9.27.1/assertion-bitbox02-multi-benma.sig
[binary or diff unavailable]
### releases/firmware-v9.27.1/assertion-bitbox02-multi.txt
@@ -0,0 +1,8 @@
+By signing this file, the signer confirms that the BitBox02 Multi firmware binary built from:
+
+git tag firmware/v9.27.1
+git commit hash 391864cd3f8676a3fd4e57593462921bc01d6064
+
+resulted, at the time of signing, in a firmware binary file with the following sha256sum:
+
+cd8b8b6424dcea8ef19ec0e15ebe0c3bec2fc86c5a8e8c6b049ecf1f3a3c03c1Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.