Skip to content

Verify CLI recovery identity before wallet import #30

Description

@BenWestgate

ms32 wallet imports recovered descriptors before showing the recovered wallet identity.

A wrong but checksum-valid seed can therefore mutate the selected empty Bitcoin Core wallet before the operator can detect the mismatch.

Required behavior: derive and verify the independent wallet recovery commitment before any descriptor import. The BIP32 fingerprint may remain diagnostic, but must not authorize restore.

This applies to direct CLI restore and the recovery documentation.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    duplicateThis issue or pull request already existsgate: adversarial reviewResolve, merge, or explicitly defer before the next full adversarial review.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions