What changed, and why it matters
This commit only reorganizes release notes. It moves the changelog entries for firmware versions 5.6.2/1.5.2Q and 5.6.3/1.5.3Q into the historic changelog files and resets the 'next' changelog to placeholder 'tbd' entries. No source code, build scripts, or firmware logic were changed.
No security action needed; this is a documentation-only changelog reorganization.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The diff is limited to four markdown files under releases/. It archives already-published release notes into History-Mk.md and History-Q.md and updates ChangeLog.md/Next-ChangeLog.md to reflect the next unreleased version. There are no code, configuration, or cryptographic changes in this commit.
Changed components
releases/ChangeLog.mdreleases/History-Mk.mdreleases/History-Q.mdreleases/Next-ChangeLog.mdInspect captured patch +142 / −82
### releases/ChangeLog.md
@@ -19,72 +19,36 @@ This lists the changes in the most recent firmware, for each hardware platform.
# Shared Improvements - Both Mk and Q
-- New Feature: Added USB ncry v3 authenticated encryption for our USB communications
- protocol, now with direction-separated keys and replay protection.
-- Enhancement: Warn when a transaction's block-height `nLockTime` is more than
- ten years beyond the Bitcoin block height known to the firmware.
-- Enhancement: Retain up to 128 UTXO cache entries across restarts.
-- Enhancement: Add the ability to view the device-generated seed before adding user
- entropy, which was available in the previous dice-roll workflow but was inadvertently
- removed in 5.6.1/1.5.1Q. The new **View TRNG Words** menu item displays the full
- 256-bit seed from the STM32 TRNG, SE1, and SE2 as 24 BIP39 words, allowing independent
- verification of dice-roll or coin-flip mixing which follows.
-- Bugfix: Clear the Set Nickname checkmark when the nickname is removed, including
- empty nicknames saved by earlier firmware. Thanks to [@bonitoman](https://github.com/bonitoman).
-- Bugfix: Reject duplicate singleton keys in PSBT maps.
-- Bugfix: Add a block-height reset to Single-Signer Spending Policy's
- **Last Violation** screen after policy bypass, matching CCC.
-- Bugfix: Cancelled PSBTs no longer persist claimed input amounts to the UTXO
- cache; amounts are committed only after signing, for inputs actually signed.
-- Bugfix: Cache single-sig segwit change amounts at finalize, so understated
- input amounts are caught instead of silently trusted.
-- Bugfix: Reject foreign inputs from BIP-322 Proof of Reserves, including inputs
- disguised with forged key-path metadata or partial signatures.
-- Bugfix: Detect and abort transaction signing if a Virtual Disk firmware import
- overwrites the reviewed PSBT. Thanks to Huzaifa Jawaid.
-- Bugfix: Reject malformed PSBTs containing P2SH-P2WSH inputs with a missing or
- incorrect redeem script, preventing transactions with an unknown fee from
- proceeding to approval.
-- Bugfix: Abort a pending firmware upgrade if its staged image is overwritten before
- approval. Thanks to Huzaifa Jawaid.
-- Bugfix: Reject cyclic FAT chains in virtual-disk file imports instead of hanging.
-- Bugfix: Simulator crashed on Bless Firmware, due to a desynced LED pipe. Thanks to
- [@hitechhayekian](https://github.com/hitechhayekian).
-- Bugfix: With an empty master wallet and an active temporary seed, keep imports and
- backup restores temporary instead of treating them as master-seed changes.
-- Bugfix: Reject PSRAM virtual-disk files whose FAT metadata is inconsistent with the
- declared file size (oversized cluster chains, oversized fragment counts, spurious
- trailing fragments, final remainders exceeding the final fragment's capacity, or
- filesystems with more than one sector per cluster), fixing an integer underflow in
- `psram_copy_file`/`psram_mmap_file` that allowed out-of-bounds PSRAM writes, reads,
- and mappings from a compromised USB host.
-- Bugfix: Hide Change Main PIN while a temporary seed or BIP-39 passphrase wallet is active.
-- Bugfix: Reject PSBTv2 transactions with an out-of-range transaction version, matching
- the PSBTv0 parser. Previously a v2 PSBT with an invalid `nVersion` could be approved
- and signed, producing a transaction the network will not relay.
-- Bugfix: Reject firmware images that extend past the world-checksum-covered flash region.
-- Security hardening: Remove the unused USB CDC/VCP serial interface from normal
- operation and keyboard emulation mode.
-- Bugfix: In Delta Mode, wipe the seed if anyone tries to view or activate a duress
- wallet's secret from the Trick PINs menu, instead of revealing it. Browsing the menu
- itself still works, so Delta Mode continues to look like normal operation.
-- Bugfix: Reject non-ASCII BIP-39 passphrases (USB, saved-passphrase recall, and
- note/password lanes) instead of silently deriving a wallet incompatible with
- BIP-39-normalizing software.
+- New Feature: Codex32 (BIP-93) secrets and Shamir secret sharing. Generate or import Codex32
+ wallets, split the active wallet into two to nine Shamir shares with **Shamir Split**, and
+ restore it with **Shamir Recover**. Word wallets split as `cw1`, raw master seeds as `ms1`,
+ and extended-key wallets as `cx1`. CW1 and CX1 are COLDCARD extensions that require
+ explicit support in recovery software.
+- Enhancement: Support per-input required height and time locktimes in PSBTv2 transactions.
+- Enhancement: Warn before installing firmware signed by an external contributor
+ or downgrading from the currently installed firmware. Thanks to Huzaifa Jawaid for suggestion.
+- Enhancement: Optionally show Seed Vault names for temporary seed fingerprints
+ at the top of the home menu.
+- Bugfix: Fix device crash when message-signing input is valid JSON but not an
+ object (NFC / QR / SD `.json` file). Thanks to [@Amiga500](https://github.com/Amiga500).
+- Bugfix: Harden PSBTv2 parsing by rejecting key data on singleton fields,
+ malformed global input/output count encodings, and files missing the required
+ global version.
+
# Mk Specific Changes
-## 5.6.2 - 2026-09-03
+## 5.6.3 - 2026-09-30
-- Bugfix: Require unrestricted HSM message-signing policy when signing BIP-322
- messages with WIF Store keys.
+- All of the above.
# Q Specific Changes
-## 1.5.2Q - 2026-09-03
+## 1.5.3Q - 2026-09-30
-- All of the above.
+- Bugfix: Prevent unintended master seed replacement when scanning seed words
+ or an extended private key from Ready To Sign or the Key Teleport retry screen.
### releases/History-Mk.md
@@ -1,5 +1,63 @@
*See ChangeLog.md for more recent changes, these are historic versions*
+## 5.6.2 - 2026-09-03
+
+- New Feature: Added USB ncry v3 authenticated encryption for our USB communications
+ protocol, now with direction-separated keys and replay protection.
+- Enhancement: Warn when a transaction's block-height `nLockTime` is more than
+ ten years beyond the Bitcoin block height known to the firmware.
+- Enhancement: Retain up to 128 UTXO cache entries across restarts.
+- Enhancement: Add the ability to view the device-generated seed before adding user
+ entropy, which was available in the previous dice-roll workflow but was inadvertently
+ removed in 5.6.1/1.5.1Q. The new **View TRNG Words** menu item displays the full
+ 256-bit seed from the STM32 TRNG, SE1, and SE2 as 24 BIP39 words, allowing independent
+ verification of dice-roll or coin-flip mixing which follows.
+- Bugfix: Clear the Set Nickname checkmark when the nickname is removed, including
+ empty nicknames saved by earlier firmware. Thanks to [@bonitoman](https://github.com/bonitoman).
+- Bugfix: Reject duplicate singleton keys in PSBT maps.
+- Bugfix: Add a block-height reset to Single-Signer Spending Policy's
+ **Last Violation** screen after policy bypass, matching CCC.
+- Bugfix: Cancelled PSBTs no longer persist claimed input amounts to the UTXO
+ cache; amounts are committed only after signing, for inputs actually signed.
+- Bugfix: Cache single-sig segwit change amounts at finalize, so understated
+ input amounts are caught instead of silently trusted.
+- Bugfix: Reject foreign inputs from BIP-322 Proof of Reserves, including inputs
+ disguised with forged key-path metadata or partial signatures.
+- Bugfix: Detect and abort transaction signing if a Virtual Disk firmware import
+ overwrites the reviewed PSBT. Thanks to Huzaifa Jawaid.
+- Bugfix: Reject malformed PSBTs containing P2SH-P2WSH inputs with a missing or
+ incorrect redeem script, preventing transactions with an unknown fee from
+ proceeding to approval.
+- Bugfix: Abort a pending firmware upgrade if its staged image is overwritten before
+ approval. Thanks to Huzaifa Jawaid.
+- Bugfix: Reject cyclic FAT chains in virtual-disk file imports instead of hanging.
+- Bugfix: Simulator crashed on Bless Firmware, due to a desynced LED pipe. Thanks to
+ [@hitechhayekian](https://github.com/hitechhayekian).
+- Bugfix: With an empty master wallet and an active temporary seed, keep imports and
+ backup restores temporary instead of treating them as master-seed changes.
+- Bugfix: Reject PSRAM virtual-disk files whose FAT metadata is inconsistent with the
+ declared file size (oversized cluster chains, oversized fragment counts, spurious
+ trailing fragments, final remainders exceeding the final fragment's capacity, or
+ filesystems with more than one sector per cluster), fixing an integer underflow in
+ `psram_copy_file`/`psram_mmap_file` that allowed out-of-bounds PSRAM writes, reads,
+ and mappings from a compromised USB host.
+- Bugfix: Hide Change Main PIN while a temporary seed or BIP-39 passphrase wallet is active.
+- Bugfix: Reject PSBTv2 transactions with an out-of-range transaction version, matching
+ the PSBTv0 parser. Previously a v2 PSBT with an invalid `nVersion` could be approved
+ and signed, producing a transaction the network will not relay.
+- Bugfix: Reject firmware images that extend past the world-checksum-covered flash region.
+- Security hardening: Remove the unused USB CDC/VCP serial interface from normal
+ operation and keyboard emulation mode.
+- Bugfix: In Delta Mode, wipe the seed if anyone tries to view or activate a duress
+ wallet's secret from the Trick PINs menu, instead of revealing it. Browsing the menu
+ itself still works, so Delta Mode continues to look like normal operation.
+- Bugfix: Reject non-ASCII BIP-39 passphrases (USB, saved-passphrase recall, and
+ note/password lanes) instead of silently deriving a wallet incompatible with
+ BIP-39-normalizing software.
+- Mk Bugfix: Require unrestricted HSM message-signing policy when signing BIP-322
+ messages with WIF Store keys.
+
+
## 5.6.1 - 2026-08-20
- Improvements to Entropy Generation:
### releases/History-Q.md
@@ -1,5 +1,62 @@
*See ChangeLog.md for more recent changes, these are historic versions*
+
+## 1.5.2Q - 2026-09-03
+
+- New Feature: Added USB ncry v3 authenticated encryption for our USB communications
+ protocol, now with direction-separated keys and replay protection.
+- Enhancement: Warn when a transaction's block-height `nLockTime` is more than
+ ten years beyond the Bitcoin block height known to the firmware.
+- Enhancement: Retain up to 128 UTXO cache entries across restarts.
+- Enhancement: Add the ability to view the device-generated seed before adding user
+ entropy, which was available in the previous dice-roll workflow but was inadvertently
+ removed in 5.6.1/1.5.1Q. The new **View TRNG Words** menu item displays the full
+ 256-bit seed from the STM32 TRNG, SE1, and SE2 as 24 BIP39 words, allowing independent
+ verification of dice-roll or coin-flip mixing which follows.
+- Bugfix: Clear the Set Nickname checkmark when the nickname is removed, including
+ empty nicknames saved by earlier firmware. Thanks to [@bonitoman](https://github.com/bonitoman).
+- Bugfix: Reject duplicate singleton keys in PSBT maps.
+- Bugfix: Add a block-height reset to Single-Signer Spending Policy's
+ **Last Violation** screen after policy bypass, matching CCC.
+- Bugfix: Cancelled PSBTs no longer persist claimed input amounts to the UTXO
+ cache; amounts are committed only after signing, for inputs actually signed.
+- Bugfix: Cache single-sig segwit change amounts at finalize, so understated
+ input amounts are caught instead of silently trusted.
+- Bugfix: Reject foreign inputs from BIP-322 Proof of Reserves, including inputs
+ disguised with forged key-path metadata or partial signatures.
+- Bugfix: Detect and abort transaction signing if a Virtual Disk firmware import
+ overwrites the reviewed PSBT. Thanks to Huzaifa Jawaid.
+- Bugfix: Reject malformed PSBTs containing P2SH-P2WSH inputs with a missing or
+ incorrect redeem script, preventing transactions with an unknown fee from
+ proceeding to approval.
+- Bugfix: Abort a pending firmware upgrade if its staged image is overwritten before
+ approval. Thanks to Huzaifa Jawaid.
+- Bugfix: Reject cyclic FAT chains in virtual-disk file imports instead of hanging.
+- Bugfix: Simulator crashed on Bless Firmware, due to a desynced LED pipe. Thanks to
+ [@hitechhayekian](https://github.com/hitechhayekian).
+- Bugfix: With an empty master wallet and an active temporary seed, keep imports and
+ backup restores temporary instead of treating them as master-seed changes.
+- Bugfix: Reject PSRAM virtual-disk files whose FAT metadata is inconsistent with the
+ declared file size (oversized cluster chains, oversized fragment counts, spurious
+ trailing fragments, final remainders exceeding the final fragment's capacity, or
+ filesystems with more than one sector per cluster), fixing an integer underflow in
+ `psram_copy_file`/`psram_mmap_file` that allowed out-of-bounds PSRAM writes, reads,
+ and mappings from a compromised USB host.
+- Bugfix: Hide Change Main PIN while a temporary seed or BIP-39 passphrase wallet is active.
+- Bugfix: Reject PSBTv2 transactions with an out-of-range transaction version, matching
+ the PSBTv0 parser. Previously a v2 PSBT with an invalid `nVersion` could be approved
+ and signed, producing a transaction the network will not relay.
+- Bugfix: Reject firmware images that extend past the world-checksum-covered flash region.
+- Security hardening: Remove the unused USB CDC/VCP serial interface from normal
+ operation and keyboard emulation mode.
+- Bugfix: In Delta Mode, wipe the seed if anyone tries to view or activate a duress
+ wallet's secret from the Trick PINs menu, instead of revealing it. Browsing the menu
+ itself still works, so Delta Mode continues to look like normal operation.
+- Bugfix: Reject non-ASCII BIP-39 passphrases (USB, saved-passphrase recall, and
+ note/password lanes) instead of silently deriving a wallet incompatible with
+ BIP-39-normalizing software.
+
+
## 1.5.1Q - 2026-08-20
- Security Improvement: Require scrolling to reveal locally entered BIP-39 passphrases.
### releases/Next-ChangeLog.md
@@ -7,39 +7,20 @@ your addition and anything else already in this file.**
# Shared Improvements - Both Mk and Q
-- Enhancement: Warn before installing firmware signed by an external contributor
- or downgrading from the currently installed firmware. Thanks to Huzaifa Jawaid for his suggestion.
-
-- New Feature: Codex32 (BIP-93) secrets and Shamir secret sharing. Generate or import Codex32
- wallets, split the active wallet into two to nine Shamir shares with **Shamir Split**, and
- restore it with **Shamir Recover**. Word wallets split as `cw1`, raw master seeds as `ms1`,
- and extended-key wallets as `cx1`. CW1 and CX1 are COLDCARD extensions that require
- explicit support in recovery software.
-
-- Bugfix: Fix device crash when message-signing input is valid JSON but not an
- object (NFC / QR / SD `.json` file). Thanks to [@Amiga500](https://github.com/Amiga500).
-
-- Enhancement: Support per-input required height and time locktimes in PSBTv2 transactions.
-
-- Bugfix: Harden PSBTv2 parsing by rejecting key data on singleton fields,
- malformed global input/output count encodings, and files missing the required
- global version.
-
-- Enhancement: Optionally show Seed Vault names for temporary seed fingerprints
- at the top of the home menu.
+- tbd
# Mk Specific Changes
-## 5.6.3 - 2026-09-30
+## 5.6.? - 2026-10-??
+
+- tbd
-- All of the above.
# Q Specific Changes
-## 1.5.3Q - 2026-09-30
+## 1.5.?Q - 2026-10-??
-- Bugfix: Prevent unintended master seed replacement when scanning seed words
- or an extended private key from Ready To Sign or the Key Teleport retry screen.
+- tbd
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.