Sparrow Wallet releases security update after AI-assisted code review
Version 2.5.4 includes changes for hardware wallets, transaction verification, secret handling, and Tor privacy.
Sparrow Wallet released version 2.5.4 after an AI-assisted code review produced most of the update’s fixes, developer Craig Raw told Decrypt.
Raw said the review was prompted by the release of unrestricted Chinese AI models and new tools that can search large codebases for potential exploits. He did not identify which models were used.
The review followed a July attack involving a flaw in Coldcard’s seed-generation code that could allow an attacker to reconstruct private keys without accessing the physical device. Coldcard maker Coinkite said AI may have helped identify the flaw.
Sparrow’s changelog lists security changes that reduce reliance on outside services. The wallet now confirms that transactions returned by Electrum servers match the user’s request, checks cryptographic proofs that transactions were recorded in a Bitcoin block, and verifies the latest block before showing transactions as confirmed.
AI, tech, and the markets they move—in one daily briefing.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
Version 2.5.4 also strengthens BitBox02 support by requiring firmware version 9.4.0 or later and anti-klepto protection. Other changes cover Ledger, Trezor, and Keycard devices, multisignature wallets, Payjoin, wallet imports, and partially signed Bitcoin transactions.
The update redacts Bitcoin Core credentials and other secrets from debug logs, restricts access to wallet and backup directories, and closes local DNS leaks when Tor is enabled.
Raw said the review found no issue likely to put users’ funds at risk and that he found no evidence of exploitation. He recommended installing the update, while advising users with air-gapped setups to read the changelog before deciding.