AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 26 Bitcoin

SFT-8161: honour USE_BIP39_GENERATE

Public commit record

What the developer wrote

Authored by Jack

58/100 · Thin
SFT-8161: honour USE_BIP39_GENERATE

py.mk sets -DUSE_BIP39_GENERATE=0, but nothing in the tree read the flag,
so the binding was exposed regardless. Guard it on that flag, defaulting
to on where the flag is not defined so upstream builds of the vendored
tree are unchanged.

Nothing calls it, so the effect is to drop an unused name from
trezorcrypto.bip39. Everything else in that module stays.

Also record beside random32()/random_buffer() which consumers are on
them, so the next reader does not have to work it out.
✓ Descriptive subject✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This commit removes an unused function called `trezorcrypto.bip39.generate()` from the firmware's exposed programming interface. The function was supposed to be disabled by a build flag (`USE_BIP39_GENERATE=0`) but the flag was being ignored, so the function was still visible. Passport does not actually use this function to create wallet seeds—it creates seeds through a different path—so the change is mostly cleanup and defense in depth. A new test checks that the function stays removed and that the rest of the crypto API still works.

Recommended action

No immediate action required. Treat as a hardening/cleanup change. Reviewers may want to confirm that no other build flags in the vendored trezor-firmware tree are similarly ignored, and that the new regression test runs in CI.

Security signals we found

01

Build flag was not being honored, leaving an unused cryptographic API exposed

02

Change reduces firmware API surface by removing a seed-generation binding

03

Regression test added to prevent accidental re-exposure

04

Comments clarify randomness source separation between routine crypto and seed generation

Risk score

Why this scored 26/100

Our methodology →
Potential impact 5/30
Exploitability 2/25
Stealth signal 3/15
Affected reach 4/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.