Skip to content

generation: Validate existing Bitcoin roots before sharing #125

Description

@BenWestgate

CreationCeremony.from_secret() accepts a Bitcoin MasterSeed without calling
the existing stdlib BIP32 root validator. It can emit recovery cards for a seed
whose BIP32 root is invalid. Kimi F7 / consolidated M8 reported this path as well
as the supplied-byte path; merged #16 fixes only the latter.

Reproduction on #53 (cde312b): construct a synthetic MasterSeed, force
codex32.generation._valid_root to return False, then call from_secret()
and next_share(). A share is returned and the validator is never called.
The forced validator models the extremely rare zero/out-of-range HMAC scalar;
this is a correctness failure, not evidence of a practical attack.

Reject before identifier randomness or any share output. Preserve valid Bitcoin
re-sharing, codex32 format parsing, and Core Lightning behavior. Refs #20, #16.

Activity

  1. added
    bugSomething isn't working
    gate: adversarial reviewResolve, merge, or explicitly defer before the next full adversarial review.
    area: bip93BIP93 encoding, checksum, parsing, and format rules.
    area: apiPublic and supported Python API boundaries.
    on Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: apiPublic and supported Python API boundaries.area: bip93BIP93 encoding, checksum, parsing, and format rules.bugSomething isn't workinggate: adversarial reviewResolve, merge, or explicitly defer before the next full adversarial review.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions