Sparrow Wallet releases security update after AI-assisted code review

Sparrow Wallet releases security update after AI-assisted code review

Version 2.5.4 includes changes for hardware wallets, transaction verification, secret handling, and Tor privacy.

Sparrow Wallet released version 2.5.4 after an AI-assisted code review produced most of the update’s fixes, developer Craig Raw told Decrypt.

Raw said the review was prompted by the release of unrestricted Chinese AI models and new tools that can search large codebases for potential exploits. He did not identify which models were used.

Advertisement

The review followed a July attack involving a flaw in Coldcard’s seed-generation code that could allow an attacker to reconstruct private keys without accessing the physical device. Coldcard maker Coinkite said AI may have helped identify the flaw.

Sparrow’s changelog lists security changes that reduce reliance on outside services. The wallet now confirms that transactions returned by Electrum servers match the user’s request, checks cryptographic proofs that transactions were recorded in a Bitcoin block, and verifies the latest block before showing transactions as confirmed.

Version 2.5.4 also strengthens BitBox02 support by requiring firmware version 9.4.0 or later and anti-klepto protection. Other changes cover Ledger, Trezor, and Keycard devices, multisignature wallets, Payjoin, wallet imports, and partially signed Bitcoin transactions.

The update redacts Bitcoin Core credentials and other secrets from debug logs, restricts access to wallet and backup directories, and closes local DNS leaks when Tor is enabled.

Raw said the review found no issue likely to put users’ funds at risk and that he found no evidence of exploitation. He recommended installing the update, while advising users with air-gapped setups to read the changelog before deciding.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
Sparrow Wallet releases security update after AI-assisted code review
Sparrow Wallet releases security update after AI-assisted code review

Version 2.5.4 includes changes for hardware wallets, transaction verification, secret handling, and Tor privacy.

Share

Add us on Google

Sparrow Wallet released version 2.5.4 after an AI-assisted code review produced most of the update’s fixes, developer Craig Raw told Decrypt.

Raw said the review was prompted by the release of unrestricted Chinese AI models and new tools that can search large codebases for potential exploits. He did not identify which models were used.

Advertisement

The review followed a July attack involving a flaw in Coldcard’s seed-generation code that could allow an attacker to reconstruct private keys without accessing the physical device. Coldcard maker Coinkite said AI may have helped identify the flaw.

Sparrow’s changelog lists security changes that reduce reliance on outside services. The wallet now confirms that transactions returned by Electrum servers match the user’s request, checks cryptographic proofs that transactions were recorded in a Bitcoin block, and verifies the latest block before showing transactions as confirmed.

Version 2.5.4 also strengthens BitBox02 support by requiring firmware version 9.4.0 or later and anti-klepto protection. Other changes cover Ledger, Trezor, and Keycard devices, multisignature wallets, Payjoin, wallet imports, and partially signed Bitcoin transactions.

The update redacts Bitcoin Core credentials and other secrets from debug logs, restricts access to wallet and backup directories, and closes local DNS leaks when Tor is enabled.

Raw said the review found no issue likely to put users’ funds at risk and that he found no evidence of exploitation. He recommended installing the update, while advising users with air-gapped setups to read the changelog before deciding.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.