AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 60 Bitcoin

Merge pull request #693 from Foundation-Devices/fix/hdnode-blank

Public commit record

What the developer wrote

Authored by mjg-foundation

73/100 · Adequate
Merge pull request #693 from Foundation-Devices/fix/hdnode-blank

SFT-981: expose HDNode.blank() again and call it where it was commented out
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit fixes a security hygiene issue in the Passport hardware wallet firmware. It restores an on-demand 'blank' method for wiping sensitive key data from BIP32 HDNode objects, and starts calling it in places where the code previously only had a TODO comment. It also ensures a 64-byte master seed buffer is wiped after use and that deserialized nodes are allocated with a finalizer so they get wiped when garbage collected. The practical risk is that private key material could remain in device memory longer than intended, but the commit is a defensive cleanup rather than a fix for an active exploit.

Recommended action

Treat as a security-hardening fix and include it in the next firmware release. Run the new hdnode_blank unit test and perform a memory-residue review (e.g., heap dump after key derivation/export flows) to confirm no additional sensitive buffers are left unwiped. Audit other TODOs and commented-out blank() calls across the codebase.

Security signals we found

01

Restores and uses explicit sensitive-data wiping (HDNode.blank())

02

Adds missing wipe of 64-byte BIP39 master seed in stash.decode()

03

Allocates deserialized HDNodes with a finalizer to ensure heap wipe on GC

04

Adds unit test coverage for blanking behavior

05

Previously commented-out TODOs indicate known incomplete cleanup

Risk score

Why this scored 60/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.