AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 60 Bitcoin

Merge pull request #702 from Foundation-Devices/SFT-7378-passphrase-length-cap

Public commit record

What the developer wrote

Authored by mjg-foundation

73/100 · Adequate
Merge pull request #702 from Foundation-Devices/SFT-7378-passphrase-length-cap

SFT-7378: cap passphrase entry at what the KDF reads
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit fixes a design flaw in the Passport hardware wallet where users could enter a passphrase longer than the wallet's key-derivation function actually reads. Previously, extra characters were silently ignored, meaning two different long passphrases could unlock the same wallet. The fix caps passphrase entry at 256 characters and adds a test to ensure the cap matches what the cryptographic code reads. It is a correctness and interoperability fix rather than a remote hack, but it prevents users from accidentally creating wallets that cannot be reproduced on other BIP39 wallets.

Recommended action

Treat this as a security-hardening fix and ship it in the next firmware release. Notify users who may have created passphrases longer than 256 characters that only the first 256 characters were used, and advise them to migrate funds to a wallet derived from a passphrase within the supported length. No immediate remote exploitation is indicated.

Security signals we found

01

silent truncation of user-controlled secret input

02

BIP39 seed derivation mismatch with other wallets

03

UI input limit did not match cryptographic read limit

04

added regression test pinning MAX_PASSPHRASE_LENGTH to KDF behavior

Risk score

Why this scored 60/100

Our methodology →
Potential impact 18/30
Exploitability 10/25
Stealth signal 12/15
Affected reach 8/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.