Overview
- Sparrow Wallet has launched version 2.5.4 after an AI-assisted code analysis.
- Developer Craig Raw noted that the AI review was responsible for most of the update's fixes.
- No evidence of exploitation was found, but users are advised to update.
The privacy-centric Bitcoin wallet, Sparrow Wallet, has issued version 2.5.4 following a comprehensive AI-assisted code review that led to the majority of the fixes in this update, as stated by developer Craig Raw in an interview with Decrypt.
This review was primarily triggered by the emergence of unrestricted AI models from China, enhancing the ability to identify potential vulnerabilities within large codebases. Raw did not specify which AI models were utilized for the review of Sparrow Wallet.
Myriad: Speculations on OpenAI's GPT-6 release. Make your prediction here.This review followed a July incident where a vulnerability in Coldcard’s seed-generation code allowed unauthorized access to private keys without physical device access. Coinkite, the manufacturer of Coldcard, suggested that AI might have played a role in the attack.
“The Coldcard incident spurred significant activity within the Bitcoin community, largely due to the newfound ability to search extensive codebases for vulnerabilities,” Raw explained to Decrypt.
When asked about the specific fixes resulting from the AI review, Raw remarked, “Most of them—it constituted the majority of the adjustments in this release.”
Since its launch in 2020, Sparrow Wallet has included various privacy and security features, such as coin control to select specific Bitcoin funds for spending, Tor support to mask user IP addresses, and compatibility with hardware wallets for keeping private keys offline.
The official changelog for version 2.5.4 reveals numerous security enhancements aimed at minimizing reliance on external services. The wallet now ensures that transactions received from Electrum servers—which supply blockchain data—are indeed the ones requested. It also verifies cryptographic proofs that transactions have been recorded in a Bitcoin block and checks the latest block in the blockchain before confirming transactions.
In addition, version 2.5.4 bolsters the security of the BitBox02 hardware wallet, mandating firmware version 9.4.0 or higher and implementing anti-klepto measures to prevent compromised devices from leaking private-key information during transaction signing.
Further updates also modify how Sparrow interacts with Ledger, Trezor, and Keycard devices, as well as multisignature wallets, Payjoin, wallet imports, and partially signed Bitcoin transactions. The update enhances security by redacting Bitcoin Core credentials and other sensitive information from debug logs, limiting access to wallet and backup directories, and addressing local DNS leaks when using Tor.
Raw emphasized that the number of changes does not imply an immediate risk to users’ funds. “Nothing was discovered that would likely jeopardize funds,” he stated, noting that he personally reviewed each issue.
“Every concern raised was meticulously examined by myself and multiple independent AI assessments,” he added.
Myriad: What will be Bitcoin's next price movement? Make your prediction here.Raw reported no signs of exploitation or impact on Sparrow users, deeming such exploitation unlikely. However, he still recommends that users apply the update, acknowledging that those using air-gapped setups might hesitate to implement changes.
“I encourage everyone to update, although it’s understandable that some users running Sparrow on air-gapped systems may be reluctant to alter their configurations,” Raw said. “For these individuals, I suggest reviewing the changelog to make an informed decision.”
Sparrow Wallet's review is part of a larger initiative within the Bitcoin ecosystem to enhance security through AI, with developers leveraging this technology to scan wallets, payment protocols, and code libraries for vulnerabilities before attackers can exploit them.
