MEMPOL!TICS
← BACK TO THE BOARD
TechnologistFOUNDATION BLOG + THE WEEK’S LEDGER · FRI SEP 4 · 2:30 PM ET

THE WHOLE SELF-CUSTODY STACK PATCHED IN ONE WEEK — PASSPORT FIXES MULTISIG BUGS THAT COULD FAKE ‘CHANGE’ — FOURTH VENDOR IN FIVE DAYS, SAME LESSON: RUN CURRENT

Four vendors patched in five days. The machinery of disclose-fix-verify is working in public — and the operator’s share of the work is boring on purpose: update promptly, verify what you run.
Foundation shipped KeyOS 1.4.0 for Passport Prime today, and the bug-fix list deserves a slow read. A malicious multisig script could get itself labeled “Change” without the device checking your cosigners. A crafted transaction could disguise attacker-owned outputs by waving a genuine device key as a decoy. Repeated cosigner keys could quietly collapse a multisig threshold below the one you chose. All fixed, plus a third source of randomness mixed into seed creation, and the vendor’s own words: update promptly. Now zoom out, because this is the fourth self-custody security fix in five days. Trezor’s shipping vendor leaked ~80,000 customers’ names and home addresses. Core Lightning patched a bug that let a stranger crash your node with pings. Coldcard made its seed math independently checkable and repeated that pre-July seeds must be replaced. LND built rate limits against the same ping attack. The bear reading is that everything is broken. The Technologist’s reading is the opposite: this is what a security ecosystem looks like when it works — researchers disclose, vendors patch inside a week, and the fixes ship with their own proof. The one thing in this week’s pile that no firmware will ever patch is the leaked home address. Machines get fixed. Databases are forever.
KEY RECEIPTS KeyOS 1.4.0 (Foundation blog, Sept 4, the primary): fixes for change-output spoofing via unverified multisig scripts, decoy-key output disguise in crafted PSBTs, and repeated cosigner keys silently lowering a multisig threshold.
Also in 1.4.0: the ATECC608 secure element’s random-number generator now mixed into seed creation as a THIRD entropy source; PIN required before seed words display; option to harden against the multi-round fee attack.
Foundation: “We strongly recommend that all Passport Prime users update promptly.”
The week’s ledger: Trezor leak grows to ~80,000 buyers incl. home addresses (Sept 4) · Core Lightning ping-flood crash disclosed + fixed, Docker label trap (Optech #421) · LND 0.21.3 rate limits · Coldcard 5.6.2 verifiable seed mixing + standing 2021–July 2026 seed migration order.
The pattern: every failure this week was in software, vendors, or databases — not one compromised a key on a current, verified device.
Related: Trezor leak · Lightning ping bug · Coldcard’s checkable dice.
Machines get fixed. Databases are forever.
Run current. Tick tock. Next block.
READ THE COVERAGE →
Foundation blog (primary) · Fri Sep 4 2026