AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 59 Bitcoin

update release notes

Public commit record

What the developer wrote

Authored by Peter D. Gray

28/100 · Opaque
update release notes
✓ Subject identifies a change! No meaningful explanatory body
The short version

What changed, and why it matters

This commit is a documentation-only update to Coldcard firmware release notes. It moves many bug-fix and feature descriptions from an unpublished 'Next-ChangeLog.md' into the published 'ChangeLog.md' and renames/reorganizes history files. The actual code changes were made in earlier commits that are not shown here. The notes describe several security-relevant fixes, most notably a fix for 'legacy input amount spoofing' in PSBT signing, plus many crash and usability fixes. Because we only see the changelog edits, we cannot directly verify the code fixes or tell how complete they are.

Recommended action

Treat this commit as a release-note bookkeeping change. Review the actual code commits that implemented the listed bug fixes (especially the PSBT witness-utxo spoofing fix, HSM/NFC activation ordering, and HSM/CCC policy import limit) to confirm they are complete and correct before relying on the security claims. Users should install the released firmware once it is published and verify the changelog claims against the signed release artifacts.

Security signals we found

01

Changelog claims fix for legacy input amount spoofing via PSBT witness-utxo handling

02

Changelog claims disabling Virtual Disk and NFC before HSM activation

03

Changelog claims stricter address ownership validation

04

Changelog claims robust handling of malformed NDEF records

05

Changelog claims ignoring 'bkpw' field if added to backup

06

Changelog claims HSM/CCC policy import limit bug fixed

07

Changelog claims malformed JSON/QR message signing rejected safely

08

No source-code diff is present to independently verify any fix

Risk score

Why this scored 59/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 12/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.