SPARROW WALLET FIXES DOZENS OF SECURITY BUGS — DEVELOPER CREDITS UNRESTRICTED CHINESE AI MODELS FOR FINDING MOST OF THEM — “NOTHING WAS LIKELY TO PUT FUNDS AT RISK”
Sparrow Wallet, a privacy-focused Bitcoin wallet running since 2020, shipped version 2.5.4 Thursday. The changelog lists dozens of fixes: how it checks transaction proofs from Electrum servers, how it talks to Ledger, Trezor, BitBox02, and Keycard hardware devices, a debug log that stopped leaking credentials, a DNS leak that let Tor users’ traffic slip through. Here is the part worth sitting with. Developer Craig Raw did not find most of these bugs himself. He ran the code through newly available, unrestricted Chinese AI models, doing what he calls multiple independent passes, and says plainly: “Most of them — it was the bulk of the work in this release.” Raw also says nothing found was likely to put funds at risk, and updating is still recommended. That is the honest way to say it. This is not proof AI review replaces open source. It is proof open source made this possible at all — the code was sitting in public the whole time, waiting for anyone with the right tool to read it closely enough. A closed wallet does not get this kind of audit for free. Purity is not a security model. Architecture is, and so, increasingly, is whoever actually bothers to read the code.
Decrypt · Aug 27 2026 5:36 PM ET