Sparrow Wallet released version 2.5.4 on August 27 after subjecting its entire codebase to an AI-assisted security review that found no vulnerabilities threatening user funds. The update patches residual DNS leaks when routing connections through Tor, adds retry logic for policy registrations on hardware wallets Ledger, Trezor, BitBox02, and Keycard, and implements constant-time ECIES MAC comparisons to eliminate side-channel attacks during encrypted message verification. The fix also strips sensitive data, including Bitcoin Core RPC credentials, from debug logs and restricts directory permissions for wallet files to the file owner only. Sparrow further tightens its validation of responses from Electrum servers, reducing dependence on those external nodes behaving honestly.
Source: Read the original article

