AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 59 Bitcoin

SSSP settings shared across temporary seeds

Public commit record

What the developer wrote

Authored by scgbckbone

25/100 · Opaque
SSSP settings shared across temporary seeds
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body! Contains work-in-progress language
The short version

What changed, and why it matters

This commit fixes a security bug in the COLDCARD firmware where the 'SSSP' (a spending-limit / hobbled mode feature) settings were being saved under the current temporary seed instead of the master seed. That meant switching to a different temporary seed could bypass or corrupt the spending policy. The patch forces SSSP settings to be read from and written to the master seed only, and hides the 'Destroy Seed' menu item when only a temporary seed is loaded.

Recommended action

Treat this as a security fix and include it in the next firmware release. Review any prior firmware versions where SSSP and temporary seeds coexist to determine if the bug is exploitable in released builds. No CVE or vendor advisory is referenced in the supplied materials.

Security signals we found

01

settings scoped to wrong seed context

02

temporary seed could alter or escape spending policy

03

master-only storage enforced for sensitive feature

04

UI menu item restricted to real secret present

05

new regression tests for cross-seed policy enforcement

Risk score

Why this scored 59/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.