Skip to content

Issue Reduction: Audit of All 80 Open Issues (Classification & Priority Table) #397

Description

@schnuartz-ai

Issue Reduction: Audit of All Open Issues

Overview

As of 2026-08-30, this repository has 80 open issues. I performed a full engineering audit of every one, reading the current codebase (upstream HEAD 3f3c831, v1.10.3), git history, related PRs, and issue threads. A detailed evidence-based comment was posted on each issue with exact file:line references.

This issue serves as a reduction index: a single place to see the status of every open issue at a glance, grouped by classification and priority.


Summary Table

Classification Count Issues
Still Relevant — Bugs 22 #63, #82, #136, #229, #233, #234, #260, #271, #273, #277, #280, #281, #285, #286, #302, #316, #326, #355, #359, #370, #371, #393
Feature Request — Still Valuable 25 #122, #153, #184, #212, #223, #232, #235, #236, #237, #238, #266, #276, #282, #289, #293, #298, #303, #312, #324, #349, #353, #357, #364, #385, #394
Feature Request — No Longer Recommended 7 #81, #107, #138, #139, #290, #319, #375
Likely Fixed (verify & close) 10 #132, #189, #278, #283, #288, #291, #296, #300, #308, #320
Partially Fixed 10 #44, #45, #134, #141, #219, #221, #257, #279, #318, #322
Duplicate (close & link) 2 #256, #328
Uncertain / Hardware Verification Needed 4 #126, #162, #224, #274
Total 80

Priority Recommendations

Highest Priority — Security & Correctness Bugs

Issue Title Finding Key Location
#229 / #328 Power-loss during PIN verify wipes device Write-before-verify + wipe-on-decrypt-failure; no atomic write flash.py:117-118, flash.py:64-69
#370 TRNG timeout returns zeros silently rng_get() returns 0 on timeout; no sanity check in rng.py; PR #372 open/unmerged src/rng.py:23-33
#234 Anti-klepto nonce exfiltration not implemented RFC 6979 deterministic nonces present (good vs malicious host), but no host-commitment protocol (compromised firmware could bias nonce) ram.py:80-88, libsecp256k1.c:306,448
#302 SIGHASH_ALL appended to Schnorr signatures Falsy-0 fallthrough resolves Taproot sighash to SIGHASH.ALL instead of DEFAULT; embit guard never triggered manager.py:784, psbtview.py:652-653
#326 Taproot PSBT "Unknown wallet" warning + lost change verification Wallet match fails for taproot; signing succeeds via seed-root but change-address verification is skipped wallet.py:167, ram.py:77
#281 "Create Wallet" button creates single-sig from multisig xpub Security-downgrade footgun: button unconditional, only single-sig descriptors offered xpubs.py:314-320, xpubs/screens.py:52
#371 Build v1.10.3 not reproducible embed_git_info.py writes environment-dependent git metadata into frozen firmware tools/embed_git_info.py
#277 PSBT_TAP_KEY_SIG not supported Vendored embit pinned to 2023-12 commit; upstream fix exists but not vendored psbt.py:353, psbtview.py:654

High Priority — Functional Bugs

Issue Title Finding Key Location
#271 Cannot register Liana descriptor Miniscript.keys is O(n²) uncached, invoked 74× during parse → MemoryError embit/descriptor/miniscript.py:20-25
#260 Memory allocation with multiple wallets All wallets eagerly loaded into RAM at init; no lazy-loading manager.py:86, manager.py:503
#273 QR scanner error from Sparrow No UR:CRYPTO routing; unbounded payload_len can exhaust heap manager.py:160, ur.py:29
#393 Taproot offered for BIP-84 path m/84h path offers tr() descriptor under "Other" — wrong script type xpubs.py:337-348
#355 GM65 scanner reset breaks baud rate GM65 reset branch lacks baud handling that M3Y branch has qr.py:601-602 vs qr.py:586-599
#359 SD card data cannot be deleted No delete/secure-format on master; only open-file exists sd.py:16,71-100
#233 SD card ENODEV not handled No "format SD card" suggestion on read failure platform.py
#285 Seed-QR burns into OLED No anti-burn-in timeout; display.off() never called from app code qrcode.py:145-153, ram.py:396
#286 QR scanner overheats No auto-timeout; hardware timeout explicitly disabled qr.py:786,397,103-104
#136 Host command not recognized Intermittent parse failure; requires investigation manager.py
#82 Scanner doesn't start if PIN entered too fast Scanner init race with PIN entry specter.py
#63 Fee attack on segwit Partially mitigated; high-fee warning still missing (#324) transaction.py:76-88

Medium Priority — UX / Minor Bugs

Issue Title Finding Key Location
#280 Bit values in wrong order (ascending 1→1024) Never touched; fix must reverse labels AND toggle logic mnemonic.py:93-94,133-136
#316 P2TR question (answer: yes, with caveats) Dead experimental.taproot config written but never read specter.py:540
#322 Account indexing confusion Derivation paths not shown in default menu xpubs.py:76

Likely Fixed — Verify & Close

Issue Title Evidence Related PR
#283 Locktime/blockheight display nLockTime + nSequence added to confirmation screen #321 (3d1bb8e)
#288 False seed words from Compact SeedQR GM65 RAW mode detection + factory reset on boot #299 (031d285), #335 (97ab4d4)
#320 QR Code PSBT troubleshoot UART buffer 2048→4096 + EOL frame validation + M3Y support #335 (97ab4d4)
#300 Host error with Sparrow (M3Y) Full M3Y scanner support added #335 (97ab4d4)
#296 Build broken Ubuntu 24.04 -Wno-dangling-pointer added to CFLAGS #301 (a5c9926), #325 (a239557)
#308 docs.specter.solutions restored Live site verified 2026-08-30 cryptoadvance/docs
#278 / #291 GPG key expired Rotated to "Specter Signer 2026" key (k9ert) v1.10.3
#132 PIN font size PIN font enlarged; broader font setting = #236 —
#189 Simulator doesn't work Simulator runs on current build —

Duplicates — Close & Link

Issue Duplicate Of Reason
#256 #234 Same topic: RFC 6979 + anti-klepto; #234 is implementation ticket
#328 #229 Same root cause: power-loss wipe; flash write-before-verify

Feature Requests — Still Valuable

Grouped by theme:

Wallet & Address Management:

Issue Title Notes
#237 Store addresses for lookup Enables #303/#318; fixes brute-force slowness
#303 Verify address from QR Needs index-free routing; coordinate with #237
#318 USB address verification showaddr rejects tr; needs wallet-name+index command
#385 Create multisig descriptor Only single-sig offered; would fix #281 footgun
#282 Browse change addresses WalletScreen already supports branch=1; needs menu toggle
#364 Mark receive addresses as used Manual mark action; currently only auto-advanced by PSBT
#349 Recovery tool for unknown derivations Derivation-sweep tool; must not call set_mnemonic

Signing & PSBT:

Issue Title Notes
#234 Anti-klepto protocol See security section above
#289 Silent Payments support Primitives available; large new wallet type
#394 Mempool push QR Optional raw-tx QR alongside signed PSBT
#324 High fee warning Use existing meta["warnings"] path

Seed & Backup:

Issue Title Notes
#232 Password-encrypted seed export AEAD + password; companion to existing SD export
#353 SLIP-39 Shamir sharing embit has split/recover; needs new card applet
#212 SeedQR transcription mode Partially fixed; landscape mode still missing
#223 Recovery phrase UX Duplicate of #45; needs "Previous word" button
#238 Base43 encoding Scope to plaintext seed import; PSBT-over-base43 is legacy

Communication & Encoding:

Issue Title Notes
#357 BlueWallet export format Parse proprietary plain-text multisig setup file
#276 NFC support Upstream-blocked (needs specter-javacard applet)
#266 Encryption/decryption app All primitives present (ECDH+AEAD); companion to #184
#184 Message encryption Companion to #266

UI & Settings:

Issue Title Notes
#236 Font size setting LVGL already compiles 12/16/22/28; discrete setting feasible
#293 / #298 Language selection No i18n infrastructure; needs t() + translation tables
#312 UI/menu restructure Prototyped in k9ert/specter-playground; needs implementation
#122 Import wallet from transaction Derive descriptor from signed tx
#153 Multisig message signing Needs cosigners app
#235 Fully stateless mode Large architectural work; no persistence mode
#45 Recovery screen improvements Autocomplete done; landscape/swipe not done

Feature Requests — No Longer Recommended

Issue Title Reason
#81 Import aezeed (LND) Niche format; BIP39 is standard
#107 Yubikey support Conflicts with hardware signer model
#138 TOTP app No reliable time source on device
#139 DIY HSM Conflicts with verify-every-tx model
#290 Payjoin V2 Transport belongs in host wallet, not hardware signer
#319 Add to WalletsRecovery.org External website task, not firmware code
#375 Dice rolls as entropy Existing bit-editing UI (#109) already provides user-controlled entropy

Cross-Issue Relationships

Relationship Issues Description
Power-loss wipe #229 ↔ #328 Same root cause; #328 is duplicate of #229
Anti-klepto #234 ↔ #256 Same topic; #256 is duplicate of #234
Scanner init race #82 ↔ #126 ↔ #134 Intermittent scanner startup issues
Recovery UX #45 ↔ #223 Duplicate; both request recovery screen improvements
SD card ENODEV #44 ↔ #233 SD card read failures
Encryption app #184 ↔ #266 Companions; both need ECDH+AEAD primitives
Password seed export #232 ↔ #226 Related seed export features
Address verification #237 ↔ #303 ↔ #318 Cache enables QR + USB verification
Multisig footgun #281 ↔ #385 Implementing #385 (multisig creation) fixes #281 footgun
Language/i18n #293 ↔ #298 Duplicates; consolidate into single issue
GPG key #278 ↔ #291 Duplicates; both resolved by key rotation in v1.10.3
Taproot signing #277 ↔ #302 ↔ #326 Related taproot PSBT handling bugs
GM65 scanner #288 ↔ #300 ↔ #320 ↔ #355 Related GM65/M3Y scanner fixes from #299/#335
Fee display #63 ↔ #324 Fee attack mitigation + high-fee warning
Font/UI #132 ↔ #236 ↔ #293 Related UI/font/language settings

Methodology

  • Audit snapshot: 2026-08-29, upstream HEAD 3f3c831 (v1.10.3)
  • Each issue was investigated against the current codebase with file:line citations
  • Git history checked for related commits and merged PRs
  • Related issues cross-referenced via GitHub search
  • Security findings assessed per-issue; novel undisclosed vulnerabilities reported privately
  • Classifications distinguish tested (reproduced/simulator-verified) vs inferred (code inspection) vs not-reproduced (hardware-only)

Notes

Activity

  1. schnuartz-ai commented on Aug 30, 2026

    @schnuartz-ai
    ContributorAuthor

    Correction: Secret-deletion false-success bug — already addressed by PR #379

    In my original audit I flagged the return True in finally blocks at sdcard.py:165 and flash.py:306 as a "novel finding" and recorded it in a private security ledger.

    This was incorrect. Open PR #379 (opened 2026-08-12, "feat: secure file deletion + SD card format + delete_mnemonic error propagation fix") already identifies and fixes this exact bug. From the PR body:

    Both FlashKeyStore.delete_mnemonic() and SDKeyStore.delete_mnemonic() had return True inside the finally block, silently discarding the KeyStoreError raised when deletion failed. The UI showed "Your key is deleted." while the key file was still on disk. The success return is moved out of finally; both keystores now use secure_delete_file() instead of os.remove().

    The fix in #379 also goes beyond the minimal fix (moving return True out of finally) by replacing os.remove() with a new secure_delete_file() that overwrites the file with zeros before unlinking — addressing the forensic-recovery concern raised in #359 as well.

    #359 should reference #379 as the fix PR. My comment on #359 does reference #379 in the related-issues section, but I incorrectly classified the return True bug as a novel undisclosed finding. It is neither novel nor undisclosed — it's an open PR awaiting merge.

  2. schnuartz-ai commented on Aug 30, 2026

    @schnuartz-ai
    ContributorAuthor

    Proposed Action Plan — Issue Triage & Reduction

    This is a proposed phased plan to reduce the 80 open issues to a manageable set. Each phase is ordered by dependency and impact. Issue counts show the expected open-issue count after completing the phase.

    Starting point: 80 open issues, 30 open PRs.


    Phase 1: Merge pending security & hardening PRs (highest impact, already written)

    These PRs are open, already reviewed to varying degrees, and address the most security-sensitive findings from the audit. They should be merged first.

    PR Title Fixes issue Audit issue Notes
    #372 Reject dead-TRNG output in get_random_bytes #370 #370 (STILL RELEVANT, security) Maintainer-approved, 5 commits. Fixes silent-zero TRNG output.
    #380 Fix device wipe on final PIN attempt (fork #7) #229 (STILL RELEVANT, security) Fixes off-by-one: 10th entry wiped even if PIN was correct. Keeps pre-verify decrement for power-cut rewind protection.
    #388 Constant-time comparison for MAC/PIN checks (new) Security hardening Prevents timing side-channel on PIN/MAC checks. No behavior change.
    #379 Secure file deletion + SD format + delete_mnemonic error propagation fix #359 #359 (STILL RELEVANT, security) Fixes return True in finally false-success bug. Adds secure_delete_file() + full-card SD format. Must merge before #378.
    #387 Fix change-output classification to require verified descriptor derivation (new) #326 (STILL RELEVANT, security) Requires on-device script re-derivation before accepting auto-change. Prevents host-supplied change metadata from hiding unverified outputs.
    #396 Fix incomplete secure wipe of QSPI flash (new) Related to #229 platform.wipe() only overwrote part of QSPI; rest could be forensically recovered.
    #381 Require on-device confirmation for host XPUB requests (new) Security hardening Prevents silent XPUB enumeration by compromised host. Fingerprint stays non-interactive.
    #382 Re-add mixed-inputs warning for multi-wallet transactions (new) Related to #63 Warning path was dead; restores multisig change-address attack warning.

    Dependency: #379 must merge before #378.

    After Phase 1: 80 open issues (closes #359, #370, #326 directly; partially mitigates #229). ~22 issues meaningfully improved by merged code.


    Phase 2: Close duplicates & not-recommended features (zero work, −12 issues)

    No code changes needed. Close with a comment linking to the canonical issue or stating the rationale.

    Duplicates to close (link to canonical):

    Close Canonical Topic
    #256 → #234 Anti-klepto / RFC 6979
    #328 → #229 Power-loss wipe
    #291 → #278 GPG key expired (both resolved)
    #298 → #293 Language selection (consolidate)
    #223 → #45 Recovery phrase UX (consolidate)

    Feature requests — no longer recommended (close with rationale):

    Issue Title Reason
    #81 Import aezeed (LND) Niche format; BIP39 is standard
    #107 Yubikey support Conflicts with hardware signer model
    #138 TOTP app No reliable time source on device
    #139 DIY HSM Conflicts with verify-every-tx model
    #290 Payjoin V2 Transport belongs in host wallet
    #319 Add to WalletsRecovery.org External website, not firmware
    #375 Dice rolls as entropy Existing bit-editing UI (#109) already provides this

    After Phase 2: 68 open issues. (80 − 5 duplicates − 7 not-recommended)


    Phase 3: Verify & close likely-fixed issues (−9 issues, some need HW check)

    These issues were fixed by merged PRs. Some need hardware verification before closing.

    Can close now (code-verified):

    Issue Fixed by Evidence
    #132 PIN font enlarged Specific ask met; broader font setting tracked in #236
    #189 Simulator runs Verified on current build
    #278 GPG key rotated "Specter Signer 2026" key (k9ert), SECURITY.md:32-35
    #283 PR #321 (3d1bb8e) nLockTime + nSequence in confirmation screen
    #296 PR #301 (a5c9926), #325 (a239557) -Wno-dangling-pointer in CFLAGS
    #308 docs site live Verified 2026-08-30

    Need hardware verification before closing:

    Issue Fixed by What to verify
    #288 PR #299 (031d285), #335 (97ab4d4) GM65 RAW mode with affected SW versions (137, 134)
    #300 PR #335 (97ab4d4) M3Y-W scanner + Sparrow animated UR:CRYPTO-PSBT
    #320 PR #335 (97ab4d4) Large single PSBT QR via M3Y-W

    After Phase 3: 59 open issues. (68 − 6 code-verified − 3 HW-verify-then-close)


    Phase 4: Merge feature PRs that close open issues

    These open PRs directly implement requested features:

    PR Title Closes issue Status
    #392 Warn on disproportionately high transaction fees #324 Open. Implements high-fee warning via existing meta["warnings"] path.
    #369 Touch-friendly SeedQR transcription viewer #212 (partially) Open. Implements zone-based transcription viewer.
    #376 Update embit to v0.8.2 #277 (partially) Open. Includes PSBT_IN_TAP_KEY_SIG support + miniscript fixes. Fixes #277 directly.
    #378 BitBox02 backup import/export + secure delete (feature) Open. Depends on #379 merging first.
    #358 MicroPython v1.25 + LVGL v9.3 migration #274 (partially) Open. Large migration; may fix simulator segfault.

    After Phase 4: 56 open issues. (59 − #324 − partial closes on #212, #277)


    Phase 5: Quick-fix PRs (low-risk, high-value, no open PR exists)

    These are small, well-scoped fixes I identified during the audit. No open PR addresses them. I can contribute these from the fork.

    Issue Title Fix scope Key location
    #302 SIGHASH_ALL appended to Schnorr signatures One-line: pass 0 (DEFAULT) through instead of falsy-0 fallthrough to SIGHASH.ALL manager.py:784
    #393 Taproot offered for BIP-84 path Filter taproot from descriptors dict for non-86h paths xpubs.py:337-348
    #355 GM65 reset breaks baud rate Mirror M3Y baud-handling pattern in GM65 reset branch qr.py:601-602
    #280 Bit values in ascending order Reverse keyboard labels AND toggle index logic mnemonic.py:93-94,133-136
    #316 Dead experimental.taproot config Remove dead config write (written at specter.py:540, never read) specter.py:540

    After Phase 5: 51 open issues. (56 − 5 fixed)


    Phase 6: Security-critical bugs needing new PRs (no open PR)

    These need new PRs. They are security-sensitive and should be prioritized after Phase 1's merges.

    Issue Title Fix direction Complexity
    #229 Power-loss during PIN verify wipes device Two-slot atomic write with monotonic anti-rollback counter; wipe only when BOTH slots invalid; change wipe-on-corrupt policy in load_state High — flash write architecture
    #371 Build v1.10.3 not reproducible Make embed_git_info.py deterministic: strip clone URL/branch, use full commit hash Medium — build tooling
    #234 Anti-klepto nonce exfiltration Host-commitment protocol: thread host_commitment/nonce_data through embit → secp256k1_ecdsa_sign (binding already accepts data ptr). New QR round in src/hosts/. High — architecture, UX

    Note: #380 (Phase 1) fixes the off-by-one wipe-on-correct-PIN symptom of #229, but the deeper power-loss-corruption-during-write problem remains open until atomic write is implemented.

    After Phase 6: 48 open issues. (51 − 3 fixed)


    Phase 7: Functional bugs needing new PRs (no open PR)

    Issue Title Fix direction Complexity
    #271 Liana miniscript MemoryError Cache Miniscript.keys property; lazy/streaming parse Medium
    #260 Multiple wallets RAM exhaustion Lazy-load wallets on demand; unload when not active Medium
    #273 QR scanner Sparrow error Add UR:CRYPTO routing in parse_stream; bound payload_len in UR decoder Medium
    #285 Seed-QR OLED burn-in Idle timeout to dismiss/rotate static QRs; call display.off() after timeout Low
    #286 QR scanner overheats Auto-timeout in scan loop; enable hardware timeout Low
    #281 Multisig→single-sig footgun Hide "Create Wallet" button for multisig xpubs, OR implement #385 Low (hide) / High (implement)

    After Phase 7: 42 open issues. (48 − 6 fixed)


    Phase 8: Remaining partially-fixed & uncertain issues

    These need investigation or hardware verification before deciding next steps:

    Issue Classification What's needed
    #44 Partially fixed 1 remaining TODO item
    #45 Partially fixed Consolidate with #223 (Phase 2); track remaining UX features
    #134 Partially fixed Remaining scanner settings
    #141 Mostly fixed Residual xPub/SD issue
    #219 Partially fixed / HW M-chips compile needs hardware verify
    #221 Partially fixed Export-only /0/* bug remains
    #257 Partially fixed Address verification still open (depends on #237)
    #279 Partially fixed SD-disable path 1 not enforced
    #318 Partially fixed showaddr rejects tr; needs extension
    #322 Partially fixed Display-only improvement optional
    #126 Uncertain Intermittent scanner init; needs reproduction
    #162 Uncertain / HW Show mnemonic with encrypted smartcard
    #224 Uncertain / HW Battery status calibration
    #274 Uncertain Simulator segfault; may be fixed by #358 MicroPython upgrade

    After Phase 8: 28 open issues (42 − 14 resolved/investigated)


    Phase 9: Feature requests still valuable (maintainer prioritization)

    The remaining ~28 issues are feature requests that need maintainer decisions on prioritization. Grouped by theme:

    Address verification cluster (high user demand):

    Multisig (safety-critical):

    Signing & PSBT:

    Seed & backup:

    Communication:

    UI & settings:

    Architecture (large):

    Other:


    Dependency Map

    Phase 1: Merge security PRs
      #379 ──must merge before──→ #378
      #372 fixes #370
      #380 partially fixes #229
      #387 fixes #326
      #396 supplements #229 fix
      #388, #381, #382 = hardening
    
    Phase 2: Close duplicates & not-recommended (no deps)
    
    Phase 3: Verify & close likely-fixed (no deps)
    
    Phase 4: Merge feature PRs
      #379 (Phase 1) ──must merge before──→ #378
      #376 (embit update) → fixes #277 (PSBT_IN_TAP_KEY_SIG), may help #271 (miniscript fixes)
    
    Phase 5: Quick-fix PRs (independent, can parallelize)
      #302, #393, #355, #280, #316
    
    Phase 6: Security new PRs (depend on Phase 1 merges landing first)
      #229 atomic write (builds on #380, #396)
      #371 reproducible build
      #234 anti-klepto (large, standalone)
    
    Phase 7: Functional bug PRs (independent)
      #271, #260, #273, #285, #286, #281
    
    Phase 8: Investigate partial/uncertain
      #274 may be fixed by #358 (Phase 4)
      #257, #318 depend on #237 (Phase 9)
      #281 depends on #385 (Phase 9) OR Phase 7 quick-hide
    

    Expected Outcome

    Phase Issues closed Open after
    Start — 80
    1: Merge security PRs 3 (#359, #370, #326) 77
    2: Close dup & not-recommended 12 65
    3: Verify & close likely-fixed 9 56
    4: Merge feature PRs 1-3 ~54
    5: Quick-fix PRs 5 ~49
    6: Security new PRs 3 ~46
    7: Functional bug PRs 6 ~40
    8: Investigate partial/uncertain ~14 ~26
    9: Feature prioritization remaining ~26 feature requests

    From 80 open issues to ~26 feature requests — a 67% reduction — with the remaining set being deliberate product decisions rather than bugs or stale tickets.


    What I can contribute

    I can prepare quick-fix PRs from the fork for Phase 5 issues (#302, #393, #355, #280, #316) — these are all small, well-scoped, and have no competing open PR. Let me know if you'd like me to proceed with those.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions