Sparrow Wallet v2.5.4 adds security checks after AI-assisted review

Sparrow Wallet released version 2.5.4 after an AI-assisted review of its codebase found no issues that could put user funds at risk. Developer Craig Raw said the review was prompted by the arrival of unrestricted Chinese AI models and improved tools for searching large codebases for potential exploits, following a July attack involving a Coldcard seed-generation flaw. He said most of the release’s fixes came from the AI-assisted review, that he personally checked each issue, and that he found no evidence the issues had been exploited or that users had been affected, while still recommending the update. The maintenance release addresses residual DNS leaks when connections are routed through Tor, strengthens BitBox02 handling with firmware 9.4.0 or later and anti-klepto protection, and improves Ledger, Trezor, Keycard, multisignature, Payjoin, wallet-import and PSBT support. It also redacts Bitcoin Core credentials and other secrets from debug logs, restricts wallet and backup directory access, and tightens Electrum-server transaction checks, cryptographic proofs and latest-block verification before showing confirmations. Launched in 2020, Sparrow is aimed at advanced Bitcoin users seeking coin control, Tor privacy, hardware and air-gapped signing, and reduced trust in outside services.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.