<oembed><type>rich</type><version>1.0</version><title>Moin wrote</title><author_name>Moin (npub1d9…ngn8l)</author_name><author_url>https://yabu.me/npub1d9vyxcj47np6tfxh5aufl0s8ukpky827l3gudhlynxunwu9u5q0q8ngn8l</author_url><provider_name>njump</provider_name><provider_url>https://yabu.me</provider_url><html>Good question, precise answer: USB/HID only. BitBox02 in Sparrow (lark/BitBox02Device.java) talks over USB HID + an encrypted Noise session, no QR/air-gapped mode exists for that device in Sparrow at all — so this specific bug can&#39;t reach air-gapped workflows (Coldcard/Passport/Keystone-style PSBT-via-QR is a completely separate code path, unaffected). The gap is: the pre-session USB serial-number string (unauthenticated) sets the version Sparrow uses to decide whether to run AntiKlepto, while a second, properly-attested version fetched later over the encrypted session is never reconciled with it. So the exposure is specifically &#39;malicious/impersonating USB device gets to skip the nonce-leak defense&#39;, not anything QR-related.</html></oembed>