AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 30 Bitcoin

bugfix: fwd slash in multisig name caused export to yikes. Replace fwd slash with dash in export filenames

Public commit record

What the developer wrote

Authored by scgbckbone

50/100 · Thin
bugfix: fwd slash in multisig name caused export to yikes. Replace fwd slash with dash in export filenames
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This update fixes a bug where giving a multisig wallet a name containing a forward slash (like '2/3 me/her/it') would crash the COLDCARD device when exporting wallet files to a microSD card. The slash is now replaced with a dash in the exported filename, preventing the crash. It is a reliability fix rather than a security vulnerability that could be exploited remotely.

Recommended action

Treat as a routine bugfix. No urgent security response is required. Users who create multisig wallets with '/' in the name should update to a firmware release containing this fix if they need to export wallet artifacts.

Security signals we found

01

Filename sanitization for filesystem-safe output

02

Crash (Yikes) triggered by user-controlled input in filename

03

Local-only trigger requiring physical device access and SD card export

04

No evidence of code execution, privilege escalation, or data leakage

Risk score

Why this scored 30/100

Our methodology →
Potential impact 6/30
Exploitability 4/25
Stealth signal 3/15
Affected reach 5/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.