Sparrow Wallet pushed out version 2.5.4 on Thursday after an AI-assisted code review turned up most of the changes in the release, developer Craig Raw told Decrypt. The update tightens a raft of privacy and security protections for the popular Bitcoin wallet — a direct response to recent industry concerns about automated code discovery tools and a high-profile hardware-wallet exploit. Why the review happened now Raw said the review was driven in part by the advent of unrestricted AI models that can quickly search large codebases for potential vulnerabilities. That capability, combined with a July incident involving a flaw in Coldcard’s seed-generation code — a bug that let an attacker reconstruct private keys without physical access to devices — made the Sparrow team accelerate a deeper audit. Coldcard maker Coinkite has suggested AI may have helped the attacker find that bug. Raw did not name the AI models used for Sparrow’s review. What Sparrow 2.5.4 changes Sparrow (launched in 2020) is a privacy-focused Bitcoin wallet with features like coin control, Tor support, hardware-wallet integrations and air-gapped signing. Its 2.5.4 release contains dozens of security and privacy hardenings. According to Sparrow’s changelog and Raw’s comments, highlights include: - Stronger Electrum-server handling: Sparrow now confirms that transactions returned by Electrum servers match the requests made, reducing the risk of a server feeding a wallet incorrect data. - Proof and block validation: The wallet checks cryptographic proofs that a transaction was recorded in a Bitcoin block and verifies the latest block before showing a transaction as confirmed. - BitBox02 protections: The update requires BitBox02 devices to run firmware 9.4.0 or newer and enforces anti-klepto protections, which prevent a compromised device from leaking key material during signing. - Hardware wallet and PSBT improvements: Various changes affect Ledger, Trezor and Keycard handling, multisignature wallets, Payjoin, wallet imports and the processing of partially signed Bitcoin transactions (PSBTs). - Privacy and operational hardening: The release redacts Bitcoin Core credentials and other secrets from debug logs, tightens file-system access to wallet and backup directories, and fixes local DNS leaks when Tor is in use. AI did most of the legwork — but humans verified Raw said “most” of the fixes came from the AI-assisted review and that he personally reviewed every issue raised. He also ran “multiple independent AI passes” and found no evidence that any of the flagged issues had been exploited in the wild or that Sparrow users were affected. “Nothing was found that was likely to put funds at risk,” he told Decrypt, though he still recommends users install the update. Practical guidance for users Raw acknowledged some users run Sparrow on strictly air-gapped systems and may be reluctant to update. He urged everyone to at least read the changelog to make an informed choice. For those using BitBox02 devices, ensure your hardware firmware is at or above 9.4.0 to benefit from the enforced protections. Bigger picture: AI meets Bitcoin security Sparrow’s proactive AI-assisted review is part of a broader push across the Bitcoin ecosystem to use automated tools to find and fix flaws before attackers do. The Coldcard incident showed how powerful code-searching capabilities can speed the discovery of vulnerabilities, and developers are increasingly turning the same techniques to defensive ends. Bottom line: Sparrow 2.5.4 is a security-focused patch driven by an AI-aided audit and manual verification. Users should review the changelog and update where feasible — especially if using affected hardware wallets. Read more AI-generated news on: undefined/news