BC
← All projectsBitcoin Core

Hardware Wallet Interface

Python library and command-line interface for Bitcoin hardware-wallet communication.

BitcoinHardware integrationSoftware walletsNormal
Repository coverage

30 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

8security candidates3second-pass queue5AI analyses
23commits · 30 days
24commits · 60 days
27commits · 180 days
30commits · 365 days
Backfill bands
Aug 5 → Feb 63 seen1 candidatesComplete
Feb 6 → Jun 63 seen0 candidatesComplete
Jun 6 → Jul 61 seen0 candidatesComplete
Jul 6 → Aug 522 seen1 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

63/100 average clarity
7Strong · 80–100
7Adequate · 60–79
14Thin · 40–59
2Opaque · 0–39
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Sjors Provoost2065065
Ava Chow620066
Salvatore Ingala200057
andreasgriffin100018
Rohit Yadav100050
Analysis record

Published AI watches

Last scanned 6 minutes ago

Informational 15 AI analysisMessage 90 · Strong
BC Bitcoin CoreHardware Wallet Interface BitcoinHardware integrationSoftware wallets

test: make device signing cases more granular

This commit only changes test code. It makes the automated test suite more flexible by letting device simulators opt out of one specific test case involving unusual key derivation paths, while still running the rest of the tests. There is …

eab5bad3by Sjors Provoost+19−97 files
No security note in commit
Informational 15 AI analysisMessage 65 · Adequate
BC Bitcoin CoreHardware Wallet Interface BitcoinHardware integrationSoftware wallets

ledger: have sign_psbt return SignPsbtYieldedObject

This commit is a straightforward internal code refactor for Ledger hardware wallet support. It changes the data structure returned when signing a Bitcoin transaction from a simple tuple of raw bytes to a more descriptive object that can ca…

e86440aeby Sjors Provoost+73−274 files
No security note in commit
Low 40 AI analysisMessage 45 · Thin
BC Bitcoin CoreHardware Wallet Interface BitcoinHardware integrationSoftware wallets

ledger: handle script path signatures

This commit updates the Ledger hardware wallet driver in HWI so it can correctly store Taproot script-path signatures in a PSBT, not just key-path signatures. Previously, the code had a placeholder that always treated any Taproot signature…

Previously unimplemented TODO for script-path signaturesIncorrect PSBT field assignment for Taproot script-path spendsFunctional gap that could produce an invalid or incomplete PSBT
fc206450by Sjors Provoost+5−31 file
No security note in commit
Moderate 61 AI analysisMessage 88 · Strong
BC Bitcoin CoreHardware Wallet Interface BitcoinHardware integrationSoftware wallets

psbt: don't overwrite PSBTv2 tx version and fallback locktime

This commit fixes a bug in how the HWI library handles a newer Bitcoin transaction format called PSBTv2. Previously, when converting or setting up a PSBTv2 object, the code would accidentally overwrite the transaction's version number and …

Signature invalidation through mutation of transaction version/locktimeIncorrect null-check on PSBTv2 placeholder transaction objectPSBTv2 serialization round-trip failure for valid BIP 370 vectors
ca2caf04by Sjors Provoost+31−43 files
No security note in commit
Informational 21 AI analysisMessage 43 · Thin
BC Bitcoin CoreHardware Wallet Interface BitcoinHardware integrationSoftware wallets

psbt: add MuSig2 fields

This commit adds support for new MuSig2 fields in PSBT (Partially Signed Bitcoin Transaction) parsing and serialization. MuSig2 is a multi-signature protocol for Bitcoin. The change is a feature addition that parses and stores new PSBT fie…

New PSBT field parsing with explicit length validationDuplicate-key rejection for new fieldsNo cryptographic verification of MuSig2 nonces/signatures in this diff
351b3e4eby Sjors Provoost+120−32 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidateMerge bitcoin-core/HWI#819: Drop Python 3.9, use 3.10 for dist, bump Ledgerby Ava Chow · 2daa5916 · Aug 5, 2026 · 29 filesMessage 91 · StrongTriage 0Details
Commit message · Ava Chow

Merge bitcoin-core/HWI#819: Drop Python 3.9, use 3.10 for dist, bump Ledger

d27d196def0b24b9f0a1a1c15cad755907583221 test: disambiguate Ledger warning automation (Sjors Provoost)
0379e278589999c51d50a4e8714d8a66d22ec47c Drop Ledger deny rule from tests (Sjors Provoost)
1b0cbea5023fc712e764db488d8df6e0142860a6 Skip archiving hwi-qt on non-x86 platforms (Sjors Provoost)
d2a5874ac9cc36a1c5e058472d86df5e583046a8 test: reenable LedgerX tests (Sjors Provoost)
cd8a43174fc806d3c53f5dd9feeef5708339f1c4 test: increase stdin command timeout (Sjors Provoost)
976353eded87c8c37a56f67be3b2e3d65368b105 Bump Speculos and Ledger Bitcoin app (Sjors Provoost)
eab5bad366c580a386c765670f9ce8bd1ce76836 test: make device signing cases more granular (Sjors Provoost)
edfeace84c614d4a80143eb3412b9f20d204ecc5 Drop Python 3.9 support (Sjors Provoost)
45de0be7d14e4c5a754b76f8b0bd4f953b236251 build: deterministic builds use Python 3.10 (Sjors Provoost)
5c9d86d9364123f997b772326e7fa323752af5a5 build: use Podman friendly syntax (Sjors Provoost)
68c51cf90495821e34d3fd0907657c4baeea57ab build: add docker / container ignore files (Sjors Provoost)
8603233a6d399e2aa39bc412f9b5d217d41b0853 build: generate UI before building distributions (Sjors Provoost)

Pull request description:

This PR first switches the deterministic builds to Python 3.10. It then drops the end-of-life 3.9.

Then it bumps Speculos and Ledger and enables the tests that were previously disabled.

There's also a few minor cleanup commits, plus changes to make the Docker containers Podman friendly so I can easily run them locally.

ACKs for top commit:
achow101:
ACK d27d196def0b24b9f0a1a1c15cad755907583221

Tree-SHA512: d1b0605097e5dc4621c8ad9d16ba8a2f4f8c7b211ac7d8887d15fc74e97ab463d92cd2d0a34e97b454044409f6163fc4cba98d45888237f92c8008fb6e69188b

91/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
signing boundarymerge-commit duplicate discount
Lower-priorityDrop Ledger deny rule from testsby Sjors Provoost · 0379e278 · Aug 4, 2026 · 1 fileMessage 70 · AdequateTriage 0Details
Commit message · Sjors Provoost

Drop Ledger deny rule from tests

It's unused and occasionally trips up a test.

70/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Mentions testing or verification
Lower-prioritySkip archiving hwi-qt on non-x86 platformsby Sjors Provoost · 1b0cbea5 · Aug 4, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Sjors Provoost

Skip archiving hwi-qt on non-x86 platforms

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-prioritytest: reenable LedgerX testsby Sjors Provoost · d2a5874a · Aug 4, 2026 · 1 fileMessage 57 · ThinTriage 0Details
Commit message · Sjors Provoost

test: reenable LedgerX tests

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
Lower-prioritytest: increase stdin command timeoutby Sjors Provoost · cd8a4317 · Aug 4, 2026 · 1 fileMessage 90 · StrongTriage 0Details
Commit message · Sjors Provoost

test: increase stdin command timeout

Ledger app 2.5.0 can take over 60 seconds to sign the large
transaction fixture. Allow stdin commands up to 120 seconds.

90/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
Lower-priorityBump Speculos and Ledger Bitcoin appby Sjors Provoost · 976353ed · Aug 4, 2026 · 5 filesMessage 45 · ThinTriage 0Details
Commit message · Sjors Provoost

Bump Speculos and Ledger Bitcoin app

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Security candidatetest: make device signing cases more granularby Sjors Provoost · eab5bad3 · Aug 4, 2026 · 7 filesMessage 90 · StrongInformational 15Details
Commit message · Sjors Provoost

test: make device signing cases more granular

Most device simulators accept arbitrary keypool paths, so keep testing
that behavior by default.

Some devices enforce their own derivation path policies. Let those
emulators opt out of the arbitrary-path portion while still running the
remaining keypool checks.

90/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
signing boundary
AI analysis · Informational 15/100

This commit only changes test code. It makes the automated test suite more flexible by letting device simulators opt out of one specific test case involving unusual key derivation paths, while still running the rest of the tests. There is no change to the actual wallet software that users run, and no security fix or vulnerability is present in the diff.

AI review queuedDrop Python 3.9 supportby Sjors Provoost · edfeace8 · Aug 4, 2026 · 7 filesMessage 38 · OpaqueTriage 0Details
Commit message · Sjors Provoost

Drop Python 3.9 support

38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
Lower-prioritybuild: deterministic builds use Python 3.10by Sjors Provoost · 45de0be7 · Aug 4, 2026 · 8 filesMessage 57 · ThinTriage 0Details
Commit message · Sjors Provoost

build: deterministic builds use Python 3.10

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Lower-prioritybuild: generate UI before building distributionsby Sjors Provoost · 8603233a · Aug 4, 2026 · 4 filesMessage 57 · ThinTriage 0Details
Commit message · Sjors Provoost

build: generate UI before building distributions

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Lower-prioritybuild: use Podman friendly syntaxby Sjors Provoost · 5c9d86d9 · Aug 4, 2026 · 2 filesMessage 57 · ThinTriage 0Details
Commit message · Sjors Provoost

build: use Podman friendly syntax

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Lower-prioritybuild: add docker / container ignore filesby Sjors Provoost · 68c51cf9 · Aug 4, 2026 · 2 filesMessage 57 · ThinTriage 0Details
Commit message · Sjors Provoost

build: add docker / container ignore files

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
AI review queuedupgrade protobufby andreasgriffin · a7367506 · Aug 1, 2026 · 2 filesMessage 18 · OpaqueTriage 0Details
Commit message · andreasgriffin

upgrade protobuf

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
Lower-priorityudev: Remove group from rulesby Ava Chow · 46398257 · Jul 31, 2026 · 4 filesMessage 60 · AdequateTriage 0Details
Commit message · Ava Chow

udev: Remove group from rules

Since systemd 258, setting the group to a non-system group is no longer
supported.

60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Lower-priorityudev: Add uaccess tag to coldcard rulesby Ava Chow · cf66cb77 · Jul 31, 2026 · 1 fileMessage 60 · AdequateTriage 0Details
Commit message · Ava Chow

udev: Add uaccess tag to coldcard rules

Since systemd 258, uaccess is required for normal users to access
devices.

60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Lower-prioritytest: disambiguate Ledger warning automationby Sjors Provoost · d27d196d · Jul 31, 2026 · 1 fileMessage 90 · StrongTriage 0Details
Commit message · Sjors Provoost

test: disambiguate Ledger warning automation

Limit the warning rule to the centered title so it does not also click the repeated header on the details screen. This prevents the queued extra click from selecting Back to safety before Continue anyway is confirmed.

90/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
Security candidateledger: have sign_psbt return SignPsbtYieldedObjectby Sjors Provoost · e86440ae · Jul 31, 2026 · 4 filesMessage 65 · AdequateInformational 15Details
Commit message · Sjors Provoost

ledger: have sign_psbt return SignPsbtYieldedObject

Taken from LedgerHQ/app-bitcoin-new at 2.4.1

65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Why it was queued
signing boundary
AI analysis · Informational 15/100

This commit is a straightforward internal code refactor for Ledger hardware wallet support. It changes the data structure returned when signing a Bitcoin transaction from a simple tuple of raw bytes to a more descriptive object that can carry extra context for newer Taproot-style signatures. There is no indication this fixes a security bug or introduces a vulnerability; it is a compatibility and maintainability update taken from Ledger's own upstream code.

Security candidateledger: handle script path signaturesby Sjors Provoost · fc206450 · Jul 31, 2026 · 1 fileMessage 45 · ThinLow 40Details
Commit message · Sjors Provoost

ledger: handle script path signatures

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundary
AI analysis · Low 40/100

This commit updates the Ledger hardware wallet driver in HWI so it can correctly store Taproot script-path signatures in a PSBT, not just key-path signatures. Previously, the code had a placeholder that always treated any Taproot signature as a key-path signature. For users spending via a Taproot script path (for example, a multisig or timelock branch), the signature would have been placed in the wrong field, likely causing the PSBT to be invalid or incomplete. There is no direct evidence in the commit of an exploitable vulnerability; it appears to be a correctness/functional fix for an unimplemented feature.

Lower-prioritytest: only match Ledger "To" screen on the title rowby Sjors Provoost · d3e4ce7c · Jul 10, 2026 · 2 filesMessage 100 · StrongTriage 0Details
Commit message · Sjors Provoost

test: only match Ledger "To" screen on the title row

The Speculos automation file advances through screens by matching
text fragments. The rule for the "To" screen matched any fragment
starting with "To", including parts of the destination address
shown below that title.

This is what failed in CI run 28680592019 (job 85066632783). The
address mzmauywUy3WF1TX3YxzQMA5PR4zXqJVLTo was split on the device
screen into "mzmauywUy3WF1TX", "3YxzQMA5PR4zXqJVL" and "To". The
latter confused the automation rule for "To", which pressed an
extra right button:

automation: getting actions for "To" (57, 3)
automation: getting actions for "mzmauywUy3WF1TX" (9, 19)
automation: getting actions for "3YxzQMA5PR4zXqJVL" (8, 33)
automation: getting actions for "To" (57, 47)
seproxyhal: applying automation ['button', 2, True]
seproxyhal: applying automation ['button', 2, False]

From there every press landed one screen late; the approval hit
"Reject transaction" and the app returned 0x6985, so signtx
reported a canceled error. "T" and "o" are both valid base58
characters, and bitcoind generates fresh addresses on every run,
which makes this a rare and random failure. Bech32 addresses
cannot trigger it ("o" is not in the bech32 character set).

Limit the "To" rule to the title row (y=3), where address text
never appears. The rule file format does not allow comments, so a
warning about short words in automation rules goes in the README.

Co-authored-by: Claude (Fable 5) <noreply@anthropic.com>

100/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Names security-relevant behavior explicitly
Security candidatepsbt: don't overwrite PSBTv2 tx version and fallback locktimeby Sjors Provoost · ca2caf04 · Jul 10, 2026 · 3 filesMessage 88 · StrongModerate 61Details
Commit message · Sjors Provoost

psbt: don't overwrite PSBTv2 tx version and fallback locktime

self.tx is never None, for PSBTv2 it's an empty placeholder. Its
defaults would overwrite the deserialized tx version and fallback
locktime, invalidating any existing signature. Check the PSBT
version instead, here and in get_unsigned_tx().

Without this fix all BIP 370 valid test vectors, now added, fail
the serialization round-trip.

88/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Names security-relevant behavior explicitly
Why it was queued
signing boundaryfuzzing or regression evidencesigning or wallet path
AI analysis · Moderate 61/100

This commit fixes a bug in how the HWI library handles a newer Bitcoin transaction format called PSBTv2. Previously, when converting or setting up a PSBTv2 object, the code would accidentally overwrite the transaction's version number and locktime with default values. That could silently invalidate digital signatures that were already created for the transaction. The fix checks the PSBT version before touching those fields, and adds official BIP 370 test vectors to prevent the bug from returning.

Lower-priorityFix repo renamings for Ledger appsby Salvatore Ingala · f15d6d9a · Jul 10, 2026 · 3 filesMessage 68 · AdequateTriage 0Details
Commit message · Salvatore Ingala

Fix repo renamings for Ledger apps

The Ledger bitcoin app repos have moved:
- new: from LedgerHQ/app-bitcoin-new to LedgerHQ/app-bitcoin
- legacy: from LedgerHQ/app-bitcoin to LedgerHQ/app-bitcoin-legacy

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
documentation-only discount
Lower-priorityci: drop cirrus leftoversby Sjors Provoost · 9ded73e0 · Jul 10, 2026 · 5 filesMessage 47 · ThinTriage 0Details
Commit message · Sjors Provoost

ci: drop cirrus leftovers

47/100 · ThinMessage clarity
✓ Descriptive subject✓ Uses a recognizable type or scope! No meaningful explanatory body
Lower-priorityci: drop unused Python 3.7 Docker fileby Sjors Provoost · 7ac09cf8 · Jul 10, 2026 · 4 filesMessage 72 · AdequateTriage 0Details
Commit message · Sjors Provoost

ci: drop unused Python 3.7 Docker file

Also drops Python 3.6 dataclasses leftover.

72/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Security candidatetest: pin Trezor T Rust nightly to 2025-04-15by Sjors Provoost · eb36bd69 · Jul 3, 2026 · 1 fileMessage 90 · StrongTriage 18Details
Commit message · Sjors Provoost

test: pin Trezor T Rust nightly to 2025-04-15

The rolling nightly toolchain has drifted past what trezor-firmware
core/v2.9.6 supports: recent nightlies reject its
reexport_test_harness_main attribute with error E0658. Pin the nightly
to 2025-04-15, matching the firmware's own shell.nix.

Co-authored-by: Claude (Fable 5) <noreply@anthropic.com>

90/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
access control
Lower-priorityAdd model id for Ledger Nano Gen5by Salvatore Ingala · 6dbf8a42 · Apr 27, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Salvatore Ingala

Add model id for Ledger Nano Gen5

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body