AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 61 Bitcoin

Merge remote-tracking branch 'origin/dev-v2.4.0' into taproot-bip322-message-signing

Public commit record

What the developer wrote

Authored by Jack

75/100 · Adequate
Merge remote-tracking branch 'origin/dev-v2.4.0' into taproot-bip322-message-signing

# Conflicts:
# ports/stm32/boards/Passport/modules/tests/test_unit.py
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Mentions testing or verification
The short version

What changed, and why it matters

This merge commit pulls in several defensive fixes for the Passport hardware wallet. The most important changes reduce the maximum passphrase length from 1000 to 256 characters so passphrases are not silently truncated when deriving a wallet, prevent backup files from restoring sensitive identity values (like the wallet fingerprint and extended public key) that could otherwise be forged, and fix a typo in the error-code list that was accidentally joining two error names together. It also adds missing early returns in backup verification so the same result is not reported twice. These are hardening fixes rather than a single obvious exploit, but they close real security-relevant bugs.

Recommended action

Treat this merge as a security-hardening release. Review the new unit tests for completeness, ensure the UI enforces the 256-character passphrase cap consistently, and verify that backup files created before this change cannot still influence xfp/xpub/root_xfp during restore. Consider whether any other settings should be added to the non-restorable list.

Security signals we found

01

Passphrase length capped to match KDF input limit, preventing silent truncation of BIP39 passphrases

02

Backup restore now refuses to restore wallet identity metadata (xfp, xpub, root_xfp) from backup and re-derives it from the restored secret

03

Missing comma in error-code tuple fixed; the bug had caused two error names to merge into one and become unreachable

04

Missing early returns added in verify_backup_task so error paths do not also emit a success callback

05

New unit tests explicitly model attacker-supplied xfp/xpub in a backup and assert they are not persisted

Risk score

Why this scored 61/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 10/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.