Repository navigation
Issue Reduction: Audit of All 80 Open Issues (Classification & Priority Table) #397
Description
Activity
Correction: Secret-deletion false-success bug — already addressed by PR #379
In my original audit I flagged the
return Trueinfinallyblocks atsdcard.py:165andflash.py:306as a "novel finding" and recorded it in a private security ledger.This was incorrect. Open PR #379 (opened 2026-08-12, "feat: secure file deletion + SD card format + delete_mnemonic error propagation fix") already identifies and fixes this exact bug. From the PR body:
Both
FlashKeyStore.delete_mnemonic()andSDKeyStore.delete_mnemonic()hadreturn Trueinside thefinallyblock, silently discarding theKeyStoreErrorraised when deletion failed. The UI showed "Your key is deleted." while the key file was still on disk. The success return is moved out offinally; both keystores now usesecure_delete_file()instead ofos.remove().The fix in #379 also goes beyond the minimal fix (moving
return Trueout offinally) by replacingos.remove()with a newsecure_delete_file()that overwrites the file with zeros before unlinking — addressing the forensic-recovery concern raised in #359 as well.#359 should reference #379 as the fix PR. My comment on #359 does reference #379 in the related-issues section, but I incorrectly classified the
return Truebug as a novel undisclosed finding. It is neither novel nor undisclosed — it's an open PR awaiting merge.Proposed Action Plan — Issue Triage & Reduction
This is a proposed phased plan to reduce the 80 open issues to a manageable set. Each phase is ordered by dependency and impact. Issue counts show the expected open-issue count after completing the phase.
Starting point: 80 open issues, 30 open PRs.
Phase 1: Merge pending security & hardening PRs (highest impact, already written)
These PRs are open, already reviewed to varying degrees, and address the most security-sensitive findings from the audit. They should be merged first.
PR Title Fixes issue Audit issue Notes #372 Reject dead-TRNG output in get_random_bytes#370 #370 (STILL RELEVANT, security) Maintainer-approved, 5 commits. Fixes silent-zero TRNG output. #380 Fix device wipe on final PIN attempt (fork #7) #229 (STILL RELEVANT, security) Fixes off-by-one: 10th entry wiped even if PIN was correct. Keeps pre-verify decrement for power-cut rewind protection. #388 Constant-time comparison for MAC/PIN checks (new) Security hardening Prevents timing side-channel on PIN/MAC checks. No behavior change. #379 Secure file deletion + SD format + delete_mnemonic error propagation fix #359 #359 (STILL RELEVANT, security) Fixes return Trueinfinallyfalse-success bug. Addssecure_delete_file()+ full-card SD format. Must merge before #378.#387 Fix change-output classification to require verified descriptor derivation (new) #326 (STILL RELEVANT, security) Requires on-device script re-derivation before accepting auto-change. Prevents host-supplied change metadata from hiding unverified outputs. #396 Fix incomplete secure wipe of QSPI flash (new) Related to #229 platform.wipe()only overwrote part of QSPI; rest could be forensically recovered.#381 Require on-device confirmation for host XPUB requests (new) Security hardening Prevents silent XPUB enumeration by compromised host. Fingerprint stays non-interactive. #382 Re-add mixed-inputs warning for multi-wallet transactions (new) Related to #63 Warning path was dead; restores multisig change-address attack warning. Dependency: #379 must merge before #378.
After Phase 1: 80 open issues (closes #359, #370, #326 directly; partially mitigates #229). ~22 issues meaningfully improved by merged code.
Phase 2: Close duplicates & not-recommended features (zero work, −12 issues)
No code changes needed. Close with a comment linking to the canonical issue or stating the rationale.
Duplicates to close (link to canonical):
Close Canonical Topic #256 → #234 Anti-klepto / RFC 6979 #328 → #229 Power-loss wipe #291 → #278 GPG key expired (both resolved) #298 → #293 Language selection (consolidate) #223 → #45 Recovery phrase UX (consolidate) Feature requests — no longer recommended (close with rationale):
Issue Title Reason #81 Import aezeed (LND) Niche format; BIP39 is standard #107 Yubikey support Conflicts with hardware signer model #138 TOTP app No reliable time source on device #139 DIY HSM Conflicts with verify-every-tx model #290 Payjoin V2 Transport belongs in host wallet #319 Add to WalletsRecovery.org External website, not firmware #375 Dice rolls as entropy Existing bit-editing UI (#109) already provides this After Phase 2: 68 open issues. (80 − 5 duplicates − 7 not-recommended)
Phase 3: Verify & close likely-fixed issues (−9 issues, some need HW check)
These issues were fixed by merged PRs. Some need hardware verification before closing.
Can close now (code-verified):
Issue Fixed by Evidence #132 PIN font enlarged Specific ask met; broader font setting tracked in #236 #189 Simulator runs Verified on current build #278 GPG key rotated "Specter Signer 2026" key (k9ert), SECURITY.md:32-35#283 PR #321 ( 3d1bb8e)nLockTime + nSequence in confirmation screen #296 PR #301 ( a5c9926), #325 (a239557)-Wno-dangling-pointerin CFLAGS#308 docs site live Verified 2026-08-30 Need hardware verification before closing:
Issue Fixed by What to verify #288 PR #299 ( 031d285), #335 (97ab4d4)GM65 RAW mode with affected SW versions (137, 134) #300 PR #335 ( 97ab4d4)M3Y-W scanner + Sparrow animated UR:CRYPTO-PSBT #320 PR #335 ( 97ab4d4)Large single PSBT QR via M3Y-W After Phase 3: 59 open issues. (68 − 6 code-verified − 3 HW-verify-then-close)
Phase 4: Merge feature PRs that close open issues
These open PRs directly implement requested features:
PR Title Closes issue Status #392 Warn on disproportionately high transaction fees #324 Open. Implements high-fee warning via existing meta["warnings"]path.#369 Touch-friendly SeedQR transcription viewer #212 (partially) Open. Implements zone-based transcription viewer. #376 Update embit to v0.8.2 #277 (partially) Open. Includes PSBT_IN_TAP_KEY_SIGsupport + miniscript fixes. Fixes #277 directly.#378 BitBox02 backup import/export + secure delete (feature) Open. Depends on #379 merging first. #358 MicroPython v1.25 + LVGL v9.3 migration #274 (partially) Open. Large migration; may fix simulator segfault. After Phase 4: 56 open issues. (59 − #324 − partial closes on #212, #277)
Phase 5: Quick-fix PRs (low-risk, high-value, no open PR exists)
These are small, well-scoped fixes I identified during the audit. No open PR addresses them. I can contribute these from the fork.
Issue Title Fix scope Key location #302 SIGHASH_ALL appended to Schnorr signatures One-line: pass 0(DEFAULT) through instead of falsy-0 fallthrough to SIGHASH.ALLmanager.py:784#393 Taproot offered for BIP-84 path Filter taprootfrom descriptors dict for non-86h pathsxpubs.py:337-348#355 GM65 reset breaks baud rate Mirror M3Y baud-handling pattern in GM65 reset branch qr.py:601-602#280 Bit values in ascending order Reverse keyboard labels AND toggle index logic mnemonic.py:93-94,133-136#316 Dead experimental.taprootconfigRemove dead config write (written at specter.py:540, never read)specter.py:540After Phase 5: 51 open issues. (56 − 5 fixed)
Phase 6: Security-critical bugs needing new PRs (no open PR)
These need new PRs. They are security-sensitive and should be prioritized after Phase 1's merges.
Issue Title Fix direction Complexity #229 Power-loss during PIN verify wipes device Two-slot atomic write with monotonic anti-rollback counter; wipe only when BOTH slots invalid; change wipe-on-corrupt policy in load_stateHigh — flash write architecture #371 Build v1.10.3 not reproducible Make embed_git_info.pydeterministic: strip clone URL/branch, use full commit hashMedium — build tooling #234 Anti-klepto nonce exfiltration Host-commitment protocol: thread host_commitment/nonce_datathrough embit →secp256k1_ecdsa_sign(binding already acceptsdataptr). New QR round insrc/hosts/.High — architecture, UX Note: #380 (Phase 1) fixes the off-by-one wipe-on-correct-PIN symptom of #229, but the deeper power-loss-corruption-during-write problem remains open until atomic write is implemented.
After Phase 6: 48 open issues. (51 − 3 fixed)
Phase 7: Functional bugs needing new PRs (no open PR)
Issue Title Fix direction Complexity #271 Liana miniscript MemoryError Cache Miniscript.keysproperty; lazy/streaming parseMedium #260 Multiple wallets RAM exhaustion Lazy-load wallets on demand; unload when not active Medium #273 QR scanner Sparrow error Add UR:CRYPTOrouting inparse_stream; boundpayload_lenin UR decoderMedium #285 Seed-QR OLED burn-in Idle timeout to dismiss/rotate static QRs; call display.off()after timeoutLow #286 QR scanner overheats Auto-timeout in scan loop; enable hardware timeout Low #281 Multisig→single-sig footgun Hide "Create Wallet" button for multisig xpubs, OR implement #385 Low (hide) / High (implement) After Phase 7: 42 open issues. (48 − 6 fixed)
Phase 8: Remaining partially-fixed & uncertain issues
These need investigation or hardware verification before deciding next steps:
Issue Classification What's needed #44 Partially fixed 1 remaining TODO item #45 Partially fixed Consolidate with #223 (Phase 2); track remaining UX features #134 Partially fixed Remaining scanner settings #141 Mostly fixed Residual xPub/SD issue #219 Partially fixed / HW M-chips compile needs hardware verify #221 Partially fixed Export-only /0/*bug remains#257 Partially fixed Address verification still open (depends on #237) #279 Partially fixed SD-disable path 1 not enforced #318 Partially fixed showaddr rejects tr; needs extension#322 Partially fixed Display-only improvement optional #126 Uncertain Intermittent scanner init; needs reproduction #162 Uncertain / HW Show mnemonic with encrypted smartcard #224 Uncertain / HW Battery status calibration #274 Uncertain Simulator segfault; may be fixed by #358 MicroPython upgrade After Phase 8: 28 open issues (42 − 14 resolved/investigated)
Phase 9: Feature requests still valuable (maintainer prioritization)
The remaining ~28 issues are feature requests that need maintainer decisions on prioritization. Grouped by theme:
Address verification cluster (high user demand):
- Optionally store addresses for lookup #237 (address cache) → enables [Feature Request]: Verify adress from QR #303 (QR verify) + [USB] Add a command in order to let software walet trigger an adress verification #318 (USB verify) + helps Unable to use it with Nunchuk wallet as coordinator #257
Multisig (safety-critical):
- Feature Request: Create Multisig Descriptor from Specter DIY #385 (create multisig descriptor) → fixes '+Create Wallet' Button creates pitfall (Multisig) #281 footgun
Signing & PSBT:
- [Feature Request]: Silent Payments support #289 (silent payments), Feature request: Optional Mempool Push QR for broadcasting finalized transactions #394 (mempool push QR)
Seed & backup:
- Password encrypted seed export to SD card #232 (encrypted seed export), Feature request: 2 of 3 Shamir Secret Sharing (SLIP-039) Keycard backup #353 (SLIP-39), Add transcription mode to SeedQR #212 (SeedQR transcription, partially in PR Add touch-friendly SeedQR transcription viewer #369)
Communication:
- Blue Wallet Export Coordination Setup via QR-Code is not supportet yet #357 (BlueWallet format), [Feature request] Add NFC #276 (NFC, upstream-blocked), Implement basic encryption/decryption app #266/Add message encryption/decryption #184 (encryption app)
UI & settings:
- Add a setting to customize fonts size #236 (font size), Implement language selection in the settings #293 (language selection), Proposal for more user centric UI/menu structure #312 (menu restructure)
Architecture (large):
- Add fully stateless mode #235 (stateless mode)
Other:
- Allow import of the wallet from the transaction #122, Multisig message signing #153, Add support for base43 encoding #238, Browse change addresses in Wallet App #282, Feature Request: Recovery tool for unknown derivation paths #349, Add Ability to Mark Receive Addresses as Used Directly on Specter DIY #364
Dependency Map
Phase 1: Merge security PRs #379 ──must merge before──→ #378 #372 fixes #370 #380 partially fixes #229 #387 fixes #326 #396 supplements #229 fix #388, #381, #382 = hardening Phase 2: Close duplicates & not-recommended (no deps) Phase 3: Verify & close likely-fixed (no deps) Phase 4: Merge feature PRs #379 (Phase 1) ──must merge before──→ #378 #376 (embit update) → fixes #277 (PSBT_IN_TAP_KEY_SIG), may help #271 (miniscript fixes) Phase 5: Quick-fix PRs (independent, can parallelize) #302, #393, #355, #280, #316 Phase 6: Security new PRs (depend on Phase 1 merges landing first) #229 atomic write (builds on #380, #396) #371 reproducible build #234 anti-klepto (large, standalone) Phase 7: Functional bug PRs (independent) #271, #260, #273, #285, #286, #281 Phase 8: Investigate partial/uncertain #274 may be fixed by #358 (Phase 4) #257, #318 depend on #237 (Phase 9) #281 depends on #385 (Phase 9) OR Phase 7 quick-hide
Expected Outcome
Phase Issues closed Open after Start — 80 1: Merge security PRs 3 (#359, #370, #326) 77 2: Close dup & not-recommended 12 65 3: Verify & close likely-fixed 9 56 4: Merge feature PRs 1-3 ~54 5: Quick-fix PRs 5 ~49 6: Security new PRs 3 ~46 7: Functional bug PRs 6 ~40 8: Investigate partial/uncertain ~14 ~26 9: Feature prioritization remaining ~26 feature requests From 80 open issues to ~26 feature requests — a 67% reduction — with the remaining set being deliberate product decisions rather than bugs or stale tickets.
What I can contribute
I can prepare quick-fix PRs from the fork for Phase 5 issues (#302, #393, #355, #280, #316) — these are all small, well-scoped, and have no competing open PR. Let me know if you'd like me to proceed with those.
Issue Reduction: Audit of All Open Issues
Overview
As of 2026-08-30, this repository has 80 open issues. I performed a full engineering audit of every one, reading the current codebase (upstream HEAD
3f3c831, v1.10.3), git history, related PRs, and issue threads. A detailed evidence-based comment was posted on each issue with exactfile:linereferences.This issue serves as a reduction index: a single place to see the status of every open issue at a glance, grouped by classification and priority.
Summary Table
Priority Recommendations
Highest Priority — Security & Correctness Bugs
flash.py:117-118,flash.py:64-69rng_get()returns 0 on timeout; no sanity check inrng.py; PR #372 open/unmergedsrc/rng.py:23-33ram.py:80-88,libsecp256k1.c:306,448manager.py:784,psbtview.py:652-653wallet.py:167,ram.py:77xpubs.py:314-320,xpubs/screens.py:52embed_git_info.pywrites environment-dependent git metadata into frozen firmwaretools/embed_git_info.pypsbt.py:353,psbtview.py:654High Priority — Functional Bugs
Miniscript.keysis O(n²) uncached, invoked 74× during parse → MemoryErrorembit/descriptor/miniscript.py:20-25manager.py:86,manager.py:503UR:CRYPTOrouting; unboundedpayload_lencan exhaust heapmanager.py:160,ur.py:29tr()descriptor under "Other" — wrong script typexpubs.py:337-348qr.py:601-602vsqr.py:586-599sd.py:16,71-100platform.pydisplay.off()never called from app codeqrcode.py:145-153,ram.py:396qr.py:786,397,103-104manager.pyspecter.pytransaction.py:76-88Medium Priority — UX / Minor Bugs
mnemonic.py:93-94,133-136experimental.taprootconfig written but never readspecter.py:540xpubs.py:76Likely Fixed — Verify & Close
3d1bb8e)031d285), #335 (97ab4d4)97ab4d4)97ab4d4)-Wno-dangling-pointeradded to CFLAGSa5c9926), #325 (a239557)Duplicates — Close & Link
Feature Requests — Still Valuable
Grouped by theme:
Wallet & Address Management:
tr; needs wallet-name+index commandset_mnemonicSigning & PSBT:
meta["warnings"]pathSeed & Backup:
Communication & Encoding:
UI & Settings:
t()+ translation tablesFeature Requests — No Longer Recommended
Cross-Issue Relationships
Methodology
3f3c831(v1.10.3)file:linecitationsNotes