AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 49 Bitcoin

bip32: reject str path child index >= 2**31

Public commit record

What the developer wrote

Authored by MrKalipo

68/100 · Adequate
bip32: reject str path child index >= 2**31

convert_bip32_strpath_to_intpath only checked the *combined* value
(index | hardened flag) against UINT32_MAX. As the hardened flag is the
top bit, a literal index in [2**31, 2**32) passed the check and was
silently interpreted as hardened: "m/2147483648" parsed to the same path
as "m/0'", and for "m/2147483649'" the hardened marker was a no-op.

Reject any literal index >= 2**31 instead, and tell the user to use the
hardened suffix. This matches other implementations (rust-bitcoin,
bitcoinjs, BIP380 descriptor key paths) and makes the str->int->str
round trip unambiguous.

Co-authored-by: f321x <f@f321x.com>
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This commit fixes a bug in how Electrum parsed Bitcoin wallet derivation paths typed by users. A path like "m/2147483648" was silently treated the same as "m/0'" (a hardened key), and "m/2147483649'" lost its hardening marker. The patch now rejects any index of 2^31 or larger and tells the user to use the standard hardened suffix instead. This prevents confusion and makes path conversion unambiguous, but it is a correctness/hardening fix rather than a demonstrated remote exploit.

Recommended action

Treat as a low-severity hardening fix. Review any code that calls convert_bip32_strpath_to_intpath to ensure the new ValueError is handled gracefully in UI and command-line flows, and consider whether user-facing error messages need localization.

Security signals we found

01

Input validation gap in BIP32 path parser

02

Silent reinterpretation of user-supplied index as hardened bit

03

Ambiguous string-to-integer round-trip for derivation paths

04

Boundary-condition hardening for cryptographic key derivation input

Risk score

Why this scored 49/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 10/15
Affected reach 7/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.