Skip to content

Honor bip122 signMessage protocol - #6222

Merged
j0ntz merged 2 commits into
developfrom
jon/wc-btc-bip322-signing
Oct 2, 2026
Merged

j0ntz merged 2 commits into
developfrom
jon/wc-btc-bip322-signing

Conversation

@j0ntz

@j0ntz j0ntz commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Description

WalletConnect bip122 signMessage requests carry a protocol of ecdsa (the default) or bip322. WcSignMessageModal always signed with BIP-137, so a dapp asking for BIP-322 got the same 65-byte BIP-137 signature it got for ecdsa.

The request's protocol now reaches the modal. bip322 signs with the UTXO plugin's new bip322 signatureFormat, and ecdsa keeps BIP-137. An unknown protocol fails the cleaner and rejects the request. The optional address param is checked against the session address the same way as account.

A separate commit swaps the deprecated asLegacyTokenId in the WalletConnect payload cleaner for asOptional(asEdgeTokenId, null), which maps a missing tokenId to null the same way.

The bip322 path needs edge-currency-plugins with EdgeApp/edge-currency-plugins#461. The current published plugin does not know the bip322 format, and this branch does not bump the plugin version.

Tested on the iOS simulator with the plugin change linked in: a WalletConnect test dapp paired through an edge://wc deep link and requested both protocols from a native SegWit wallet.

  • bip322: a 107-byte witness that an independent BIP-322 verifier (hand-built BIP-143 sighash, secp256k1 verify) accepts for the wallet's bc1q address and rejects for a tampered message.
  • ecdsa: a 65-byte BIP-137 signature that verifies with bitcoinjs-message.

Asana: WalletConnect Bitcoin proof of ownership

CHANGELOG

Does this branch warrant an entry to the CHANGELOG?

  • Yes
  • No

Dependencies

EdgeApp/edge-currency-plugins#461

Requirements

If you have made any visual changes to the GUI. Make sure you have:

  • Tested on iOS device
  • Tested on Android device
  • Tested on small-screen device (iPod Touch)
  • Tested on large-screen device (tablet)

Note

Medium Risk
Changes WalletConnect Bitcoin proof-of-signing behavior and depends on an unreleased UTXO plugin for the new bip322 format; invalid protocols are rejected at parse time.

Overview
WalletConnect bip122 signMessage calls can ask for ecdsa (BIP-137) or bip322. The app previously always signed with BIP-137, so dapps requesting BIP-322 still got a recoverable ECDSA-style signature.

The service now parses optional protocol, address, and account from the request, rejects requests that name an unservable address/account, and passes protocol into WcSignMessageModal, which maps bip322 → signatureFormat: 'bip322' and ecdsa → 'bip137' before hex-encoding the result for the spec.

Separately, the WalletConnect payload amount cleaner replaces deprecated asLegacyTokenId with asOptional(asEdgeTokenId, null) so native transfers without a tokenId field parse as null.

Note: BIP-322 signing requires a matching edge-currency-plugins release; this repo does not bump that dependency in this PR.

Reviewed by Cursor Bugbot for commit c2f88fa. Bugbot is set up for automated code reviews on this repo. Configure here.

Test evidence

c2f88fa
Honor bip122 signMessage protocol
2026-09-25

1. wc connect

2. bip322 modal

3. ecdsa modal

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

Claude Code Review is paused for this repository. To reconnect it, an admin of this repository's GitHub organization (or the account owner, for personal repositories) who can also manage your Claude organization's Code Review settings needs to re-link GitHub in Code Review settings. This is a one-time step.

Tip: disable this comment in your organization's Code Review settings.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@peachbits peachbits left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The protocol plumbing and the account/address checks look right. This needs to land together with the edge-currency-plugins bump that includes EdgeApp/edge-currency-plugins#461. The published plugin cleans an unknown signatureFormat to electrum, so until the bump a bip322 request would silently get an Electrum signature.

@j0ntz

j0ntz commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Agreed on the ordering: this lands only together with the edge-currency-plugins bump that includes #461. Until that version is published the plugin cleans the unknown signatureFormat to electrum, so this PR stays unmerged.

j0ntz added 2 commits October 2, 2026 16:24
asLegacyTokenId is deprecated outside notification-server payloads.
asOptional(asEdgeTokenId, null) keeps the same undefined-to-null mapping
for payload parsers that omit tokenId on the native asset.
WalletConnect bip122 signMessage requests carry a protocol of ecdsa (the
default) or bip322, but the modal always signed with BIP-137. A dapp
asking for BIP-322 got a 65-byte BIP-137 signature back, the same bytes
it got for ecdsa.

The request's protocol now reaches WcSignMessageModal: bip322 signs with
the UTXO plugin's bip322 signatureFormat, and ecdsa keeps BIP-137. An
unknown protocol fails the cleaner and rejects the request. The optional
address param is checked against the session address the same way as
account.
@j0ntz
j0ntz force-pushed the jon/wc-btc-bip322-signing branch from c2f88fa to 27d5b5f Compare October 2, 2026 23:26
@j0ntz
j0ntz enabled auto-merge October 2, 2026 23:27
@j0ntz
j0ntz merged commit 1e4e6f6 into develop Oct 2, 2026
6 checks passed
@j0ntz
j0ntz deleted the jon/wc-btc-bip322-signing branch October 2, 2026 23:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants