AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
High 76 Bitcoin

Merge pull request #640 from Foundation-Devices/SFT-4502-fix-p2wpkh-nested-in-p2sh-hash-change-validation

Public commit record

What the developer wrote

Authored by mjg-foundation

73/100 · Adequate
Merge pull request #640 from Foundation-Devices/SFT-4502-fix-p2wpkh-nested-in-p2sh-hash-change-validation

SFT-4502: fix p2wpkh nested in p2sh hash change validation
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This firmware update fixes a bug in how Passport hardware wallets decide whether a Bitcoin transaction's 'change' output really belongs to your wallet. Before the fix, a malicious or buggy companion app could trick the device into treating a payment to an attacker's address as mere change, or into hiding a change output that doesn't match your account type. The patch tightens the checks for nested SegWit (P2SH-wrapped P2WPKH), native SegWit, Taproot, and multisig change outputs, and makes sure outputs with unusual or incomplete derivation paths stay visible for user review instead of being silently accepted as change.

Recommended action

Treat this as a security-relevant firmware fix. Users should upgrade to a firmware release containing this commit, especially if they sign PSBTs produced by third-party wallet software. Wallet software vendors integrating with Passport should verify their PSBTs now include correct BIP32 derivation paths matching the output script type, and should test against the new regression suite.

Security signals we found

01

Fixes change-output validation bypass in P2SH-P2WPKH where only pubkey hash was checked, not the full redeem script

02

Adds address-format enforcement (BIP purpose vs output type) preventing cross-account-type change spoofing

03

Prevents too-short or unknown derivation paths from being silently classified as change

04

Routes BIP45/BIP48 script-wallet paths through multisig script validation instead of single-sig logic

05

Adds regression unit tests for fraudulent/mismatched change outputs

06

User-facing error messages now distinguish 'not ours', 'wrong account type', and 'multisig setup mismatch'

Risk score

Why this scored 76/100

Our methodology →
Potential impact 24/30
Exploitability 18/25
Stealth signal 12/15
Affected reach 10/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.