The Bitcoin multisig wallet project Frostsnap has officially released version 0.4.0 of its software and firmware, addressing two critical security vulnerabilities discovered within its ecosystem. According to an announcement posted on social media platform X on August 27, 2026, the development team confirmed that there has been no evidence of user fund loss resulting from these flaws. The update serves as a proactive measure to secure the protocol against potential exploits and improve the overall stability of the hardware-software interface.
Technical Details of the Discovered Vulnerabilities
The version 0.4.0 patch specifically targets two distinct weaknesses in how the wallet handles transaction verification and key derivation. The first vulnerability involved malicious signature requests that could trick the system into marking outputs as belonging to the user's wallet without proper device-side verification. This flaw created a risk where malicious applications could redirect funds to unconfirmed addresses without the user's knowledge.
The second issue pertained to the management of payment change. In certain scenarios, change outputs could be assigned to "deep keychains" that fell outside the standard recovery scan range. While this did not result in a loss of Bitcoin, it led to incomplete wallet balance displays during backup restorations, causing potential confusion for users regarding their actual holdings.
New Security Features and Implementation
The Frostsnap team noted that the vulnerabilities were identified through a combination of user reports and internal audits. In addition to the security patches, the v0.4.0 update introduces several enhancements to the wallet's architecture:
- Firmware Downgrade Protection: Prevents attackers from reverting the device to older, vulnerable software versions.
- Enhanced Output Verification: Strict device-level checks to ensure all transaction outputs are legitimate.
- Refined Keychain Scanning: Improvements to the derivation path logic to ensure all funds are visible after a restoration.
- General Stability Fixes: Over a dozen minor bug fixes and performance optimizations.
Users are advised that maintaining updated firmware is a critical component of cold storage security, particularly for multisig configurations where coordination between multiple devices is required.
Conclusion
To ensure the continued safety of their digital assets, Frostsnap users are urged to download the latest application version from official channels and perform the mandatory firmware upgrade on their hardware devices. While the project reports no exploited funds to date, the transition to version 0.4.0 is essential for mitigating the risks associated with unauthorized signature requests and ensuring accurate balance reporting across the Bitcoin blockchain.
Frequently Asked Questions
Quick answers to the most common questions about this topic.