AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 59 Bitcoin

bip39: avoid unwiped mnemonic copies

Public commit record

What the developer wrote

Authored by Cedric Wiese

78/100 · Adequate
bip39: avoid unwiped mnemonic copies

to_string() can leave unwiped copies behind when its buffer grows.

Write the mnemonic into a preallocated zeroizing String, reusing
the capacity limit from last-word calculation. Add a maximum-length
test to check that the buffer does not grow.
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
The short version

What changed, and why it matters

This commit fixes a security hygiene issue in the BitBox02 hardware wallet's handling of BIP39 recovery phrases (mnemonics). When converting a mnemonic to text, the previous code could create temporary copies of the secret phrase in memory due to how Rust's string buffer grows. The new code pre-allocates a fixed-size, self-erasing buffer and writes the mnemonic directly into it, reducing the chance that leftover copies of the recovery words remain in device memory.

Recommended action

Treat this as a security-hardening fix for a potential information-disclosure weakness. Review whether any other secret-to-string conversions in the firmware use `to_string()` or similar growable buffers without pre-allocation, and apply the same zeroizing pre-allocation pattern. Verify that `Zeroizing` reliably wipes the underlying allocation on drop in the embedded target.

Security signals we found

01

Sensitive data (BIP39 mnemonic) may have been left in memory due to string reallocation/growth

02

Use of `zeroize::Zeroizing` to attempt secure erasure of secret material

03

Pre-allocation of fixed capacity to avoid heap reallocations during secret serialization

04

Commit title and message explicitly describe unwiped mnemonic copies as the problem

Risk score

Why this scored 59/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 10/15
Affected reach 8/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.