Bitkey Fixes Vulnerability in Recovery Features, No User Funds at Risk
Bitkey, a self-custodial Bitcoin wallet built by Block (formerly Square), has patched a vulnerability in its recovery and inheritance contact setup flows. The issue was flagged by security researcher @1440000bytes on August 1, who reported that the bug required exceptional conditions to exploit.
The vulnerability existed within a specific window during the enrollment process for Bitkey's recovery and inheritance contact features. Engineering Lead Clay Garrett confirmed the bug, noting that even if someone had managed to exploit it, the wallet's defense-in-depth architecture would have prevented unauthorized access to funds.
Bitkey assured users that normal wallet operations could continue without concern, emphasizing the limited scope of the issue. The patch was submitted to both the Apple App Store and Google Play Store on August 1.
On August 2, Bitkey hosted a public technical discussion via an X Space, where the team walked through the details of the vulnerability, the fix, and the broader security architecture that kept funds safe. The company publicly thanked @1440000bytes for responsible disclosure.