Bitcoin's private wallet Sparrow Wallet has published version 2.5.4. The developer Craig Raw indicated to Decrypt that most of the repairs in this update came from an AI support code review, which focused on quelling potential gaps and reducing wallet trust in external services.

Post-Coldcard inspection speeds up.

Raw indicates that one of the background to this round is the Coldcard seed generation code gap event in July. This loophole has given the attackers the opportunity to rebuild their private key without contact with physical equipment. Coldcard manufacturer Coinkite previously stated that the attackers might have discovered this defect through AI.

He also mentioned that another reason for the review was that a new generation of AI tools was already able to search for potential use points in large code repositories. Raw did not disclose which models were specifically used by Sparrow, but indicated that most of the repairs in the release were from the review round.

Transaction validation is the focus of the update

According to official updates, version 2.5.4 includes a number of security checks related to the confirmation of transactions, mainly to reduce the single point of trust in the wallet for external block chain data services.

  • Check that the Eectrum server returned a transaction that was consistent with the request
  • The authentication transaction has been encrypted into bitcoin blocks
  • Show the latest block on the chain before the transaction is confirmed

Synchronize hardware wallets with Tor protection

The new version also reinforces the security requirements of BitBox02. Sparrow now requires that the device be solid at least 9.4.0 and uses the anti-klepto protection to prevent the device from leaking private key information during the signature process.

In addition to BitBox02, the updates cover the functions of Legger, Trezor, Keycard, multiple wallets, Payjoin, wallet import and partial signature of bitcoin transactions. At the same time, Sparrow has desensitized the Bitcoin Core vouchers and other sensitive information in the debugging log and restricted access to wallets and backup directories, adding local DNS leaks to Tor.

According to Raw, the review did not identify problems that would put user funds at immediate risk and there was no evidence that they had been used. However, he suggested that users should install the update. More broadly, AI is being used by more bitcoin developers to scan potential loopholes in wallets, payment protocols and code libraries.