Privacy-focused Bitcoin wallet Sparrow Wallet released version 2.5.4 on Thursday after an AI-assisted code review that produced the bulk of the release’s fixes, according to developer Craig Raw.
Raw told Decrypt the review was prompted by the arrival of unrestricted Chinese AI models and the new ability to search large codebases for potential exploits. It also followed a July attack involving a flaw in Coldcard’s seed-generation code, which manufacturer Coinkite said may have been found with AI assistance.
No signs of exploitation were found, and Raw said he did not consider it likely that any issues were abused against Sparrow users. He nevertheless recommended installing the update, noting that even users with air-gapped setups should read the changelog to make an informed choice.
The update adds several security checks: it confirms that transactions returned by Electrum servers match requested data, verifies cryptographic proofs that transactions were recorded in a Bitcoin block, and confirms the latest chain block before showing transactions as confirmed. Version 2.5.4 also strengthens BitBox02 hardware wallet security by requiring firmware 9.4.0 or later and anti-klepto protection.
Other changes affect Ledger, Trezor and Keycard devices, multisignature wallets, Payjoin, wallet imports and partially signed Bitcoin transactions. The release redacts Bitcoin Core credentials and other secrets from debug logs, restricts access to wallet and backup directories, and closes local DNS leaks when using Tor.
Raw said every issue raised was carefully reviewed by himself and multiple independent AI passes, and that the update is part of a broader AI security push across the Bitcoin ecosystem.