AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
High 72 Bitcoin

sign_psbt: disallow taproot swaps

Public commit record

What the developer wrote

Authored by Jon Griffiths

35/100 · Opaque
sign_psbt: disallow taproot swaps
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
The short version

What changed, and why it matters

This commit blocks a specific kind of Bitcoin/Liquid transaction signing on the Blockstream Jade hardware wallet. It prevents 'swap' transactions from using 'taproot' inputs because the device's signature-calculation code does not yet safely handle that combination. Without the fix, a user might have been able to build a transaction that the wallet would sign incorrectly or in a way that could be exploited, potentially leading to loss or theft of funds in a swap.

Recommended action

Treat this as a security hardening patch and include it in the next firmware release. Review whether other unsupported signature-type/transaction-type combinations exist. If a CVE is desired, request one from a CNA, but the commit alone does not confirm an exploitable vulnerability.

Security signals we found

01

Unsupported cryptographic signing path disabled

02

Taproot/SegWit v1 signature hash incompatibility with swap transactions

03

Potential for incorrect or forgeable signatures if the combination were allowed

04

Hardware wallet boundary enforcement

Risk score

Why this scored 72/100

Our methodology →
Potential impact 22/30
Exploitability 18/25
Stealth signal 10/15
Affected reach 12/15
Confidence 7/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.