Skip to content

passkey-kit v0.17.0

Choose a tag to compare

@kalepail kalepail released this 01 Sep 21:19
· 43 commits to main since this release
v0.17.0
143838a

Security release

This release closes accepted-code wallet redirection during passkey wallet discovery.

The smart wallet now verifies a GENESIS WebAuthn proof inside __constructor.
The add_secp256r1 function requires a separate ADD proof.
Each proof binds the network, wallet address, purpose, and complete signer value.

The SDK now verifies the wallet creation transaction before connection.
It also verifies current code, signer state, the stored proof, and fresh passkey possession.
The SDK rejects incomplete, stale, ambiguous, and derivation-only discovery.

This design keeps direct CreateContractV2 and __constructor.
It does not use a factory contract.

Compatibility

This alpha release has no migration path for pre-0.17.0 wallets.
Fresh-device discovery fails closed until the indexer serves the schema-2 candidate response.

Packages

  • passkey-kit@0.17.0
  • passkey-kit-sdk@0.9.0
  • sac-sdk@0.4.4

Smart-wallet WASM

The attached smart_wallet.wasm has this SHA-256 hash:

97ce047884106b1c6c3bb40b8973cc48db1c4dad95c9e20462bf2c701daa764e

The same bytes exist on Stellar testnet and mainnet.
See docs/deployments-2026-09-01.md for the upload transactions.

Validation

  • 272 TypeScript tests pass.
  • 136 smart-wallet tests pass.
  • Two real-WASM constructor tests pass.
  • Rust formatting and clippy pass.
  • GitHub CI, CodeQL, and Socket checks pass.