GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Online/Update

News linked to both this project and an event.

Electrum Releases 4.8.2 Security Update to Fix Lightning Wallet Backup Issue

Bitcoin wallet Electrum has released version 4.8.2, fixing multiple security issues, including an issue where some Lightning wallet backups were missing the keys required to recover on-chain funds after a remote force close, along with strengthened HTLC validation and Android QR scanner protection.

Electrum Releases Version 4.8.2, Fixing Critical Backup Issue for Lightning Wallets and Strengthening Security

Odaily Reports: Bitcoin News posted on X platform that Electrum has released version 4.8.2, introducing multiple security fixes and strengthening the security of its Bitcoin wallet codebase. The fixes are based on reports from researchers including Bitcoin Red Team, Calle, l0rinc, haoxucu, and m0wer. This version fixes a critical backup issue affecting certain Lightning wallets that use non-deterministic keys and anchor channels. Previously, affected wallets' channel backups and full wallet backups may have been missing the keys required to move funds on-chain after requesting a remote force close. Affected users will receive a warning when starting Electrum and should export new backups, as old backups cannot correctly recover funds in this scenario. This version also strengthens Lightning HTLC verification, rejects previously accepted malformed xpub/xprv keys, expands codebase security hardening, and prevents the Android QR code scanner from reading screenshots. This is Electrum's third security-focused release since July, following versions 4.8.0 and 4.8.1.

Sparrow Wallet Releases Version 2.5.4, AI-Assisted Code Review Fixes Multiple Security Vulnerabilities

According to Decrypt, privacy-focused Bitcoin wallet Sparrow Wallet released version 2.5.4 on August 28. Developer Craig Raw stated that the update was driven by an AI-assisted code review, with the majority of fixes originating from it. This review was prompted by the recent seed generation code vulnerability exploit affecting Coldcard, as well as the release of unrestricted AI models in China, which has significantly enhanced vulnerability scanning capabilities across large codebases. Key updates include: validating the authenticity of transactions returned by Electrum servers, enforcing stricter BitBox02 hardware wallet security requirements (firmware v9.4.0 or higher required), patching local DNS leaks, and masking sensitive credentials in debug logs. Raw noted that there are no indications of any exploits being leveraged, user funds remain secure, and he still advises all users to update at their earliest convenience.

Independent verification scope expanded, Sparrow Wallet releases v2.5.4 security update

Odaily News: Sparrow Wallet v2.5.4 has been released following an extensive AI-assisted review, featuring multiple security hardening updates aimed at reducing users' reliance on external servers such as Electrum.Additionally, this version strengthens Ledger, Keycard, Trezor, Payjoin, PSBT, and multi-signature handling, removes Bitcoin Core credentials and other sensitive information from debug logs, restricts permissions for existing wallet and backup directories to owner-only access, closes residual local DNS resolution leaks when using Tor, and reinforces validation for wallet import, signing, downloads, and server responses. The update expands Sparrow Wallet's scope of independent verification for transaction data, hardware devices, and other inputs, reducing dependence on data provided by external servers. (Bitcoin News)