[
  {
    "label": "Radar App Store",
    "url": "https://apps.apple.com/ch/app/radar-chat-bitcoin/id6753939776?l=en-GB",
    "id": "source-2563cd7816",
    "verifiedAt": "2026-07-14",
    "type": "Web source",
    "public": true,
    "immutable": false,
    "host": "apps.apple.com",
    "findings": [
      {
        "title": "Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path",
        "slug": "across-primal-radar-wallet-of-satoshi-and-bringin-control-claims-were-not-matched-by-a-demonstrated-unilateral-exit-path"
      }
    ]
  },
  {
    "label": "Blink Weekly Brief",
    "url": "https://www.blink.sv/blog/weekly-brief-2026-28",
    "id": "source-d84482b62d",
    "verifiedAt": "2026-07-14",
    "type": "Blog or announcement",
    "public": true,
    "immutable": false,
    "host": "blink.sv",
    "findings": [
      {
        "title": "Blink’s Weekly Brief described seed-only recovery and an unswept amount as received",
        "slug": "blinks-weekly-brief-described-seed-only-recovery-and-an-unswept-amount-as-received"
      }
    ]
  },
  {
    "label": "Cake's Lightning article",
    "url": "https://blog.cakewallet.com/our-lightning-journey/",
    "id": "source-18aa58b58e",
    "verifiedAt": "2026-07-14",
    "type": "Web source",
    "public": true,
    "immutable": false,
    "host": "blog.cakewallet.com",
    "findings": [
      {
        "title": "Cake describes a one-transaction exit, but its reviewed shipped integration did not expose an exit flow",
        "slug": "cake-describes-a-one-transaction-exit-but-its-reviewed-shipped-integration-did-not-expose-an-exit-flow"
      }
    ]
  },
  {
    "label": "Bringin launch",
    "url": "https://bringin.app/blog/bitcoin-payments-app-in-europe",
    "id": "source-1b19988d50",
    "verifiedAt": "2026-07-14",
    "type": "Blog or announcement",
    "public": true,
    "immutable": false,
    "host": "bringin.app",
    "findings": [
      {
        "title": "No complete in-app operatorless exit was found in eight reviewed consumer-wallet products",
        "slug": "no-complete-in-app-operatorless-exit-was-found-in-eight-reviewed-consumer-wallet-products"
      },
      {
        "title": "Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path",
        "slug": "across-primal-radar-wallet-of-satoshi-and-bringin-control-claims-were-not-matched-by-a-demonstrated-unilateral-exit-path"
      }
    ]
  },
  {
    "label": "Global Accounts on Spark",
    "url": "https://docs.lightspark.com/global-accounts/index",
    "id": "source-eaaf6b593d",
    "verifiedAt": "2026-07-14",
    "type": "Official documentation",
    "public": true,
    "immutable": false,
    "host": "docs.lightspark.com",
    "findings": [
      {
        "title": "Grid’s common account model permits a Spark-backed wallet to carry a frozen status that blocks payments",
        "slug": "grids-common-account-model-permits-a-spark-backed-wallet-to-carry-a-frozen-status-that-blocks-payments"
      }
    ]
  },
  {
    "label": "current unilateral-exit manual",
    "url": "https://docs.spark.money/wallets/unilateral-exit",
    "id": "source-e9874abca5",
    "verifiedAt": "2026-07-14",
    "type": "Official documentation",
    "public": true,
    "immutable": false,
    "host": "docs.spark.money",
    "findings": [
      {
        "title": "Spark’s FAQ reduces exit to a pre-signed broadcast; its beta manual documents a multi-stage expert procedure",
        "slug": "sparks-faq-reduces-exit-to-a-pre-signed-broadcast-its-beta-manual-documents-a-multi-stage-expert-procedure"
      },
      {
        "title": "The documented independent exit cannot start from a Spark balance alone; it needs external on-chain fee funding",
        "slug": "the-documented-independent-exit-cannot-start-from-a-spark-balance-alone-it-needs-external-on-chain-fee-funding"
      }
    ]
  },
  {
    "label": "Spark addressing",
    "url": "https://docs.spark.money/wallets/addressing",
    "id": "source-55b7da5619",
    "verifiedAt": "2026-07-14",
    "type": "Official documentation",
    "public": true,
    "immutable": false,
    "host": "docs.spark.money",
    "findings": [
      {
        "title": "Sparkscan exposes the hidden Spark identity behind Lightning payments",
        "slug": "sparkscan-exposes-the-hidden-spark-identity-behind-lightning-payments"
      }
    ]
  },
  {
    "label": "Spark FAQ",
    "url": "https://docs.spark.money/learn/faq",
    "id": "source-56182f9cb1",
    "verifiedAt": "2026-07-14",
    "type": "Official documentation",
    "public": true,
    "immutable": false,
    "host": "docs.spark.money",
    "findings": [
      {
        "title": "Despite an announced Breez SSP, both reviewed SDKs still default only to Lightspark",
        "slug": "despite-an-announced-breez-ssp-both-reviewed-sdks-still-default-only-to-lightspark"
      },
      {
        "title": "Flashnet—one of three named Spark Operators—reserves compliance-based rejection and fund freezing in its service terms",
        "slug": "flashnet-one-of-three-named-spark-operators-reserves-compliance-based-rejection-and-fund-freezing-in-its-service-terms"
      },
      {
        "title": "Spark’s FAQ reduces exit to a pre-signed broadcast; its beta manual documents a multi-stage expert procedure",
        "slug": "sparks-faq-reduces-exit-to-a-pre-signed-broadcast-its-beta-manual-documents-a-multi-stage-expert-procedure"
      }
    ]
  },
  {
    "label": "Spark privacy mode",
    "url": "https://docs.spark.money/wallets/privacy",
    "id": "source-e825861365",
    "verifiedAt": "2026-07-14",
    "type": "Official documentation",
    "public": true,
    "immutable": false,
    "host": "docs.spark.money",
    "findings": [
      {
        "title": "Sparkscan exposes the hidden Spark identity behind Lightning payments",
        "slug": "sparkscan-exposes-the-hidden-spark-identity-behind-lightning-payments"
      },
      {
        "title": "Spark privacy does not cover a globally enumerable token ledger",
        "slug": "spark-privacy-does-not-cover-a-globally-enumerable-token-ledger"
      }
    ]
  },
  {
    "label": "Spark sovereignty page",
    "url": "https://docs.spark.money/learn/sovereignty",
    "id": "source-b2412dd493",
    "verifiedAt": "2026-07-14",
    "type": "Official documentation",
    "public": true,
    "immutable": false,
    "host": "docs.spark.money",
    "findings": [
      {
        "title": "Spark’s FAQ reduces exit to a pre-signed broadcast; its beta manual documents a multi-stage expert procedure",
        "slug": "sparks-faq-reduces-exit-to-a-pre-signed-broadcast-its-beta-manual-documents-a-multi-stage-expert-procedure"
      }
    ]
  },
  {
    "label": "Spark trust model",
    "url": "https://docs.spark.money/learn/trust-model",
    "id": "source-63b8094eb4",
    "verifiedAt": "2026-07-14",
    "type": "Official documentation",
    "public": true,
    "immutable": false,
    "host": "docs.spark.money",
    "findings": [
      {
        "title": "Spark's forward security rests on an act of key deletion users cannot verify",
        "slug": "sparks-forward-security-rests-on-an-act-of-key-deletion-users-cannot-verify"
      },
      {
        "title": "Retained Lightspark and Flashnet keys could sign a conflicting spend of a Lightspark-funded Lightning leaf",
        "slug": "retained-lightspark-and-flashnet-keys-could-sign-a-conflicting-spend-of-a-lightspark-funded-lightning-leaf"
      }
    ]
  },
  {
    "label": "Sparkscan transaction API",
    "url": "https://docs.sparkscan.io/api/tx",
    "id": "source-7c854330b8",
    "verifiedAt": "2026-07-14",
    "type": "Official documentation",
    "public": true,
    "immutable": false,
    "host": "docs.sparkscan.io",
    "findings": [
      {
        "title": "Sparkscan exposes the hidden Spark identity behind Lightning payments",
        "slug": "sparkscan-exposes-the-hidden-spark-identity-behind-lightning-payments"
      }
    ]
  },
  {
    "label": "Flashnet build relationship",
    "url": "https://www.flashnet.xyz/writing/seed-round-1",
    "id": "source-aea66db78d",
    "verifiedAt": "2026-07-14",
    "type": "Blog or announcement",
    "public": true,
    "immutable": false,
    "host": "flashnet.xyz",
    "findings": [
      {
        "title": "Retained Lightspark and Flashnet keys could sign a conflicting spend of a Lightspark-funded Lightning leaf",
        "slug": "retained-lightspark-and-flashnet-keys-could-sign-a-conflicting-spend-of-a-lightspark-funded-lightning-leaf"
      }
    ]
  },
  {
    "label": "Flashnet Terms, access restrictions",
    "url": "https://www.flashnet.xyz/terms-of-service",
    "id": "source-d3052d801d",
    "verifiedAt": "2026-07-14",
    "type": "Web source",
    "public": true,
    "immutable": false,
    "host": "flashnet.xyz",
    "findings": [
      {
        "title": "Flashnet—one of three named Spark Operators—reserves compliance-based rejection and fund freezing in its service terms",
        "slug": "flashnet-one-of-three-named-spark-operators-reserves-compliance-based-rejection-and-fund-freezing-in-its-service-terms"
      }
    ]
  },
  {
    "label": "4.1.8 APK",
    "url": "https://github.com/ClubOrangeBitcoin/ClubOrange-releases/releases/download/v4.1.8/ClubOrange.apk",
    "id": "source-33fb864ff7",
    "verifiedAt": "2026-07-14",
    "type": "Repository record",
    "public": true,
    "immutable": false,
    "host": "github.com",
    "findings": [
      {
        "title": "Club Orange bundled lower-level exit code without exposing an app-facing exit operation",
        "slug": "club-orange-bundled-lower-level-exit-code-without-exposing-an-app-facing-exit-operation"
      }
    ]
  },
  {
    "label": "all-Operator consensus selection",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/handler/transfer_handler_mimo.go#L369-L382",
    "id": "source-88a2b7963f",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Every Spark Operator receives transfer participants and records—not merely a signing share",
        "slug": "every-spark-operator-receives-transfer-participants-and-records-not-merely-a-signing-share"
      }
    ]
  },
  {
    "label": "all-Operator leaf synchronization",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/sdks/js/packages/spark-sdk/src/services/leaf-manager.ts#L292-L315",
    "id": "source-5845bf4977",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "A normal Spark wallet identifies itself separately to every Operator",
        "slug": "a-normal-spark-wallet-identifies-itself-separately-to-every-operator"
      }
    ]
  },
  {
    "label": "all-Operator outgoing Lightning request",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/protos/spark_internal.proto#L544-L568",
    "id": "source-fe5f91dc1c",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Every Spark Operator receives the full Lightning invoice—not merely one secret share",
        "slug": "every-spark-operator-receives-the-full-lightning-invoice-not-merely-one-secret-share"
      }
    ]
  },
  {
    "label": "all-Operator preimage-share fan-out",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/handler/lightning_handler.go#L152-L285",
    "id": "source-1a72044d81",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Every Spark Operator receives the full Lightning invoice—not merely one secret share",
        "slug": "every-spark-operator-receives-the-full-lightning-invoice-not-merely-one-secret-share"
      }
    ]
  },
  {
    "label": "all-Operator transfer persistence",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/handler/send_transfer_flow_handler.go#L41-L88",
    "id": "source-7fe4e68ea1",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Every Spark Operator receives transfer participants and records—not merely a signing share",
        "slug": "every-spark-operator-receives-transfer-participants-and-records-not-merely-a-signing-share"
      }
    ]
  },
  {
    "label": "Android 0.7.13-pre6",
    "url": "https://github.com/BlitzWallet/BlitzWallet/releases/tag/Android-v0.7.13-pre6",
    "id": "source-ad1235bb80",
    "verifiedAt": "2026-07-14",
    "type": "Repository record",
    "public": true,
    "immutable": false,
    "host": "github.com",
    "findings": [
      {
        "title": "Blitz’s ‘no third parties’ recovery tool uses Spark’s cooperative-withdrawal path",
        "slug": "blitzs-no-third-parties-recovery-tool-uses-sparks-cooperative-withdrawal-path"
      }
    ]
  },
  {
    "label": "archive gossip fields",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/protos/gossip.proto#L181-L190",
    "id": "source-bac2a7e6dd",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Rotating a Spark deposit address leaves the Operator-side wallet cluster intact",
        "slug": "rotating-a-spark-deposit-address-leaves-the-operator-side-wallet-cluster-intact"
      }
    ]
  },
  {
    "label": "authz.go",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/spark/so/authz/authz.go#L36-L70",
    "id": "source-d04caa27e1",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark makes a targeted wallet freeze externally indistinguishable from an ordinary identity error",
        "slug": "spark-makes-a-targeted-wallet-freeze-externally-indistinguishable-from-an-ordinary-identity-error"
      }
    ]
  },
  {
    "label": "Blink case study",
    "url": "https://github.com/blinkbitcoin/spark-unilateral-exit/blob/d47fe9b209cf57ca26a6fd7a855ef47388384182/docs/mainnet-exit-case-study.md",
    "id": "source-f2874fcc61",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark’s FAQ reduces exit to a pre-signed broadcast; its beta manual documents a multi-stage expert procedure",
        "slug": "sparks-faq-reduces-exit-to-a-pre-signed-broadcast-its-beta-manual-documents-a-multi-stage-expert-procedure"
      },
      {
        "title": "One 100,000-sat wallet required 253 ordered packages; 252 failed when submitted together",
        "slug": "one-100-000-sat-wallet-required-253-ordered-packages-252-failed-when-submitted-together"
      },
      {
        "title": "At 1 sat/vB, 18 of 22 leaves cost more to exit than they held",
        "slug": "at-1-sat-vb-18-of-22-leaves-cost-more-to-exit-than-they-held"
      },
      {
        "title": "Blink’s first documented mainnet recovery bundle silently omitted required ancestry",
        "slug": "blinks-first-documented-mainnet-recovery-bundle-silently-omitted-required-ancestry"
      },
      {
        "title": "Cake describes a one-transaction exit, but its reviewed shipped integration did not expose an exit flow",
        "slug": "cake-describes-a-one-transaction-exit-but-its-reviewed-shipped-integration-did-not-expose-an-exit-flow"
      }
    ]
  },
  {
    "label": "Blink confirm-and-continue loop",
    "url": "https://github.com/blinkbitcoin/spark-unilateral-exit/blob/d47fe9b209cf57ca26a6fd7a855ef47388384182/docs/mainnet-exit-case-study.md#L132-L159",
    "id": "source-4eb0265bc8",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "A Spark unilateral exit is a staged recovery procedure, not a single emergency broadcast",
        "slug": "a-spark-unilateral-exit-is-a-staged-recovery-procedure-not-a-single-emergency-broadcast"
      }
    ]
  },
  {
    "label": "Blink consolidation takeaway",
    "url": "https://github.com/blinkbitcoin/spark-unilateral-exit/blob/d47fe9b209cf57ca26a6fd7a855ef47388384182/docs/mainnet-exit-case-study.md#L197-L215",
    "id": "source-90f14e5aee",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Wallet usage history—not just balance—determines Spark’s exit workload",
        "slug": "wallet-usage-history-not-just-balance-determines-sparks-exit-workload"
      }
    ]
  },
  {
    "label": "Blink economics takeaway",
    "url": "https://github.com/blinkbitcoin/spark-unilateral-exit/blob/d47fe9b209cf57ca26a6fd7a855ef47388384182/docs/mainnet-exit-case-study.md#L197-L208",
    "id": "source-0da7b54a8a",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Higher fee rates push more Spark leaves below the economic exit threshold",
        "slug": "higher-fee-rates-push-more-spark-leaves-below-the-economic-exit-threshold"
      }
    ]
  },
  {
    "label": "Blink exit accounting",
    "url": "https://github.com/blinkbitcoin/spark-unilateral-exit/blob/d47fe9b209cf57ca26a6fd7a855ef47388384182/docs/mainnet-exit-case-study.md#L99-L130",
    "id": "source-e67505f5bd",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "A Spark destination amount does not disclose the exit’s net economic recovery",
        "slug": "a-spark-destination-amount-does-not-disclose-the-exits-net-economic-recovery"
      },
      {
        "title": "Blink’s Weekly Brief described seed-only recovery and an unswept amount as received",
        "slug": "blinks-weekly-brief-described-seed-only-recovery-and-an-unswept-amount-as-received"
      }
    ]
  },
  {
    "label": "Blink fee-funding mechanics",
    "url": "https://github.com/blinkbitcoin/spark-unilateral-exit/blob/d47fe9b209cf57ca26a6fd7a855ef47388384182/docs/mainnet-exit-case-study.md#L40-L55",
    "id": "source-b688829de4",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "A Spark destination amount does not disclose the exit’s net economic recovery",
        "slug": "a-spark-destination-amount-does-not-disclose-the-exits-net-economic-recovery"
      }
    ]
  },
  {
    "label": "Blink fee-rate sensitivity",
    "url": "https://github.com/blinkbitcoin/spark-unilateral-exit/blob/d47fe9b209cf57ca26a6fd7a855ef47388384182/docs/mainnet-exit-case-study.md#L125-L130",
    "id": "source-1670ed4b03",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Higher fee rates push more Spark leaves below the economic exit threshold",
        "slug": "higher-fee-rates-push-more-spark-leaves-below-the-economic-exit-threshold"
      }
    ]
  },
  {
    "label": "Blink leaf economics",
    "url": "https://github.com/blinkbitcoin/spark-unilateral-exit/blob/d47fe9b209cf57ca26a6fd7a855ef47388384182/docs/mainnet-exit-case-study.md#L79-L98",
    "id": "source-300d848d16",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "A Spark destination amount does not disclose the exit’s net economic recovery",
        "slug": "a-spark-destination-amount-does-not-disclose-the-exits-net-economic-recovery"
      },
      {
        "title": "Higher fee rates push more Spark leaves below the economic exit threshold",
        "slug": "higher-fee-rates-push-more-spark-leaves-below-the-economic-exit-threshold"
      }
    ]
  },
  {
    "label": "Blink mobile",
    "url": "https://github.com/blinkbitcoin/blink-mobile/tree/3f3108998b1db6bf55823284e932ff6313eea496",
    "id": "source-8b4af7513d",
    "verifiedAt": "2026-07-14",
    "type": "Repository record",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "No complete in-app operatorless exit was found in eight reviewed consumer-wallet products",
        "slug": "no-complete-in-app-operatorless-exit-was-found-in-eight-reviewed-consumer-wallet-products"
      }
    ]
  },
  {
    "label": "Blink mobile integration plan",
    "url": "https://github.com/blinkbitcoin/spark-unilateral-exit/blob/d47fe9b209cf57ca26a6fd7a855ef47388384182/docs/mobile-integration-plan.md",
    "id": "source-845e009a6d",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark exit backups must track wallet mutations; a one-time seed backup cannot stay current",
        "slug": "spark-exit-backups-must-track-wallet-mutations-a-one-time-seed-backup-cannot-stay-current"
      },
      {
        "title": "The documented independent exit cannot start from a Spark balance alone; it needs external on-chain fee funding",
        "slug": "the-documented-independent-exit-cannot-start-from-a-spark-balance-alone-it-needs-external-on-chain-fee-funding"
      }
    ]
  },
  {
    "label": "Blink parallelism mechanics",
    "url": "https://github.com/blinkbitcoin/spark-unilateral-exit/blob/d47fe9b209cf57ca26a6fd7a855ef47388384182/docs/mainnet-exit-case-study.md#L161-L185",
    "id": "source-fd9413cd29",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "A Spark unilateral exit is a staged recovery procedure, not a single emergency broadcast",
        "slug": "a-spark-unilateral-exit-is-a-staged-recovery-procedure-not-a-single-emergency-broadcast"
      }
    ]
  },
  {
    "label": "Blink recovery-bundle requirement",
    "url": "https://github.com/blinkbitcoin/spark-unilateral-exit/blob/d47fe9b209cf57ca26a6fd7a855ef47388384182/docs/mainnet-exit-case-study.md#L19-L38",
    "id": "source-346505b7fa",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "A seed alone is not an operator-outage recovery backup for Spark",
        "slug": "a-seed-alone-is-not-an-operator-outage-recovery-backup-for-spark"
      },
      {
        "title": "Blink’s Weekly Brief described seed-only recovery and an unswept amount as received",
        "slug": "blinks-weekly-brief-described-seed-only-recovery-and-an-unswept-amount-as-received"
      }
    ]
  },
  {
    "label": "Blink seed-derived operations",
    "url": "https://github.com/blinkbitcoin/spark-unilateral-exit/blob/d47fe9b209cf57ca26a6fd7a855ef47388384182/docs/mainnet-exit-case-study.md#L209-L219",
    "id": "source-f7944a4853",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "A seed alone is not an operator-outage recovery backup for Spark",
        "slug": "a-seed-alone-is-not-an-operator-outage-recovery-backup-for-spark"
      }
    ]
  },
  {
    "label": "Blink timelock and sweep stages",
    "url": "https://github.com/blinkbitcoin/spark-unilateral-exit/blob/d47fe9b209cf57ca26a6fd7a855ef47388384182/docs/mainnet-exit-case-study.md#L187-L195",
    "id": "source-985e2feadd",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "A Spark unilateral exit is a staged recovery procedure, not a single emergency broadcast",
        "slug": "a-spark-unilateral-exit-is-a-staged-recovery-procedure-not-a-single-emergency-broadcast"
      },
      {
        "title": "Blink’s Weekly Brief described seed-only recovery and an unswept amount as received",
        "slug": "blinks-weekly-brief-described-seed-only-recovery-and-an-unswept-amount-as-received"
      }
    ]
  },
  {
    "label": "Blink TRUC sequencing",
    "url": "https://github.com/blinkbitcoin/spark-unilateral-exit/blob/d47fe9b209cf57ca26a6fd7a855ef47388384182/docs/mainnet-exit-case-study.md#L57-L77",
    "id": "source-d4f6cc1d37",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Wallet usage history—not just balance—determines Spark’s exit workload",
        "slug": "wallet-usage-history-not-just-balance-determines-sparks-exit-workload"
      }
    ]
  },
  {
    "label": "Blink wallet-tree mechanics",
    "url": "https://github.com/blinkbitcoin/spark-unilateral-exit/blob/d47fe9b209cf57ca26a6fd7a855ef47388384182/docs/mainnet-exit-case-study.md#L10-L17",
    "id": "source-087a914c79",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Wallet usage history—not just balance—determines Spark’s exit workload",
        "slug": "wallet-usage-history-not-just-balance-determines-sparks-exit-workload"
      }
    ]
  },
  {
    "label": "Blitz",
    "url": "https://github.com/BlitzWallet/BlitzWallet/tree/173298bae4cb650fde4681ee7398d2e651bfbdae",
    "id": "source-75c2bcb0fa",
    "verifiedAt": "2026-07-14",
    "type": "Repository record",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "No complete in-app operatorless exit was found in eight reviewed consumer-wallet products",
        "slug": "no-complete-in-app-operatorless-exit-was-found-in-eight-reviewed-consumer-wallet-products"
      }
    ]
  },
  {
    "label": "Blitz PR 999",
    "url": "https://github.com/BlitzWallet/BlitzWallet/pull/999",
    "id": "source-d4de1daf47",
    "verifiedAt": "2026-07-14",
    "type": "Repository record",
    "public": true,
    "immutable": false,
    "host": "github.com",
    "findings": [
      {
        "title": "Blitz’s ‘no third parties’ recovery tool uses Spark’s cooperative-withdrawal path",
        "slug": "blitzs-no-third-parties-recovery-tool-uses-sparks-cooperative-withdrawal-path"
      }
    ]
  },
  {
    "label": "Blitz recovery tool",
    "url": "https://github.com/BlitzWallet/spark-recover/tree/eddcd34735436a83b9060f4a2069e6a1a884097c",
    "id": "source-0714c4e186",
    "verifiedAt": "2026-07-14",
    "type": "Repository record",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Blitz’s ‘no third parties’ recovery tool uses Spark’s cooperative-withdrawal path",
        "slug": "blitzs-no-third-parties-recovery-tool-uses-sparks-cooperative-withdrawal-path"
      }
    ]
  },
  {
    "label": "BOLT 11 invoice fields",
    "url": "https://github.com/lightning/bolts/blob/94eb038c42e664dd7862faeec6508ccd25f63ff8/11-payment-encoding.md#L131-L160",
    "id": "source-7e09d01cfb",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Every Spark Operator receives the full Lightning invoice—not merely one secret share",
        "slug": "every-spark-operator-receives-the-full-lightning-invoice-not-merely-one-secret-share"
      }
    ]
  },
  {
    "label": "Breez cooperative-exit SSP flow",
    "url": "https://github.com/breez/spark-sdk/blob/bce792ec7c583f640cb554b97cca7b05d29b9047/crates/spark/src/services/coop_exit.rs#L146-L156",
    "id": "source-f78d1bcb5d",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "The referenced server logic for Spark’s default Lightspark SSP is not publicly accessible",
        "slug": "the-referenced-server-logic-for-sparks-default-lightspark-ssp-is-not-publicly-accessible"
      }
    ]
  },
  {
    "label": "Breez coordinator pool",
    "url": "https://github.com/breez/spark-sdk/blob/bce792ec7c583f640cb554b97cca7b05d29b9047/crates/spark/src/operator/pool.rs#L17-L61",
    "id": "source-7f2818a12d",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Both reviewed SDKs fix Lightspark SO0 as default coordinator without automatic failover",
        "slug": "both-reviewed-sdks-fix-lightspark-so0-as-default-coordinator-without-automatic-failover"
      }
    ]
  },
  {
    "label": "Breez fix PR 917",
    "url": "https://github.com/breez/spark-sdk/pull/917",
    "id": "source-f9624a7094",
    "verifiedAt": "2026-07-14",
    "type": "Repository record",
    "public": true,
    "immutable": false,
    "host": "github.com",
    "findings": [
      {
        "title": "Blink’s first documented mainnet recovery bundle silently omitted required ancestry",
        "slug": "blinks-first-documented-mainnet-recovery-bundle-silently-omitted-required-ancestry"
      }
    ]
  },
  {
    "label": "Breez Lightning SSP flow",
    "url": "https://github.com/breez/spark-sdk/blob/bce792ec7c583f640cb554b97cca7b05d29b9047/crates/spark/src/services/lightning.rs#L645-L671",
    "id": "source-28fad93757",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "The referenced server logic for Spark’s default Lightspark SSP is not publicly accessible",
        "slug": "the-referenced-server-logic-for-sparks-default-lightspark-ssp-is-not-publicly-accessible"
      }
    ]
  },
  {
    "label": "Breez releases",
    "url": "https://github.com/breez/spark-sdk/releases",
    "id": "source-caa2acfafe",
    "verifiedAt": "2026-07-14",
    "type": "Repository record",
    "public": true,
    "immutable": false,
    "host": "github.com",
    "findings": [
      {
        "title": "Breez 0.19.0 ships no public mobile exit API; its draft API still contacts an operator",
        "slug": "breez-0-19-0-ships-no-public-mobile-exit-api-its-draft-api-still-contacts-an-operator"
      }
    ]
  },
  {
    "label": "Breez SSP configuration",
    "url": "https://github.com/breez/spark-sdk/blob/bce792ec7c583f640cb554b97cca7b05d29b9047/crates/spark-wallet/src/config.rs#L51-L89",
    "id": "source-cb886ceb70",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "The referenced server logic for Spark’s default Lightspark SSP is not publicly accessible",
        "slug": "the-referenced-server-logic-for-sparks-default-lightspark-ssp-is-not-publicly-accessible"
      },
      {
        "title": "Despite an announced Breez SSP, both reviewed SDKs still default only to Lightspark",
        "slug": "despite-an-announced-breez-ssp-both-reviewed-sdks-still-default-only-to-lightspark"
      }
    ]
  },
  {
    "label": "Breez unilateral-exit source",
    "url": "https://github.com/breez/spark-sdk/blob/bce792ec7c583f640cb554b97cca7b05d29b9047/crates/spark/src/services/unilateral_exit.rs#L32-L36",
    "id": "source-179b8cd8ec",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Breez 0.19.0 can silently omit a required parent and produce an unbroadcastable exit package",
        "slug": "breez-0-19-0-can-silently-omit-a-required-parent-and-produce-an-unbroadcastable-exit-package"
      }
    ]
  },
  {
    "label": "Bringin public GitHub organization",
    "url": "https://github.com/bringinxyz",
    "id": "source-6072e04d5b",
    "verifiedAt": "2026-07-14",
    "type": "Repository record",
    "public": true,
    "immutable": false,
    "host": "github.com",
    "findings": [
      {
        "title": "Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path",
        "slug": "across-primal-radar-wallet-of-satoshi-and-bringin-control-claims-were-not-matched-by-a-demonstrated-unilateral-exit-path"
      }
    ]
  },
  {
    "label": "Cake",
    "url": "https://github.com/cake-tech/cake_wallet/tree/bff9b2fa9648b22c2fcc84062caba58861e9d24f",
    "id": "source-03ef7ff7cd",
    "verifiedAt": "2026-07-14",
    "type": "Repository record",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "No complete in-app operatorless exit was found in eight reviewed consumer-wallet products",
        "slug": "no-complete-in-app-operatorless-exit-was-found-in-eight-reviewed-consumer-wallet-products"
      },
      {
        "title": "Cake describes a one-transaction exit, but its reviewed shipped integration did not expose an exit flow",
        "slug": "cake-describes-a-one-transaction-exit-but-its-reviewed-shipped-integration-did-not-expose-an-exit-flow"
      }
    ]
  },
  {
    "label": "Cake Breez dependency",
    "url": "https://github.com/cake-tech/cake_wallet/blob/bff9b2fa9648b22c2fcc84062caba58861e9d24f/cw_bitcoin/pubspec.yaml#L72-L75",
    "id": "source-bcf6a760b9",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Cake describes a one-transaction exit, but its reviewed shipped integration did not expose an exit flow",
        "slug": "cake-describes-a-one-transaction-exit-but-its-reviewed-shipped-integration-did-not-expose-an-exit-flow"
      }
    ]
  },
  {
    "label": "client transfer-key tweak",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/sdks/js/packages/spark-sdk/src/signer/signer.ts#L395-L429",
    "id": "source-299eb4d5c2",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Retained Lightspark and Flashnet keys could sign a conflicting spend of a Lightspark-funded Lightning leaf",
        "slug": "retained-lightspark-and-flashnet-keys-could-sign-a-conflicting-spend-of-a-lightspark-funded-lightning-leaf"
      }
    ]
  },
  {
    "label": "client-IP extraction",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/middleware/headers.go#L14-L31",
    "id": "source-828ffbf245",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "A normal Spark wallet identifies itself separately to every Operator",
        "slug": "a-normal-spark-wallet-identifies-itself-separately-to-every-operator"
      }
    ]
  },
  {
    "label": "Club Orange releases",
    "url": "https://github.com/ClubOrangeBitcoin/ClubOrange-releases/releases/tag/v4.1.8",
    "id": "source-57090499c1",
    "verifiedAt": "2026-07-14",
    "type": "Repository record",
    "public": true,
    "immutable": false,
    "host": "github.com",
    "findings": [
      {
        "title": "No complete in-app operatorless exit was found in eight reviewed consumer-wallet products",
        "slug": "no-complete-in-app-operatorless-exit-was-found-in-eight-reviewed-consumer-wallet-products"
      },
      {
        "title": "Club Orange bundled lower-level exit code without exposing an app-facing exit operation",
        "slug": "club-orange-bundled-lower-level-exit-code-without-exposing-an-app-facing-exit-operation"
      }
    ]
  },
  {
    "label": "ComplianceProvider",
    "url": "https://github.com/lightsparkdev/js-sdk/blob/46c731cfaf9b1eeb9584d2176bc006076de3b2d1/packages/lightspark-sdk/src/objects/ComplianceProvider.ts#L3-L12",
    "id": "source-8c0d977466",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Lightspark Connect exposes Chainalysis-backed sanctions screening of Lightning nodes",
        "slug": "lightspark-connect-exposes-chainalysis-backed-sanctions-screening-of-lightning-nodes"
      }
    ]
  },
  {
    "label": "conditional Operator initialization",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/spark/bin/operator/main.go#L445-L456",
    "id": "source-5f11a48393",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "When enabled, Spark’s targeted wallet gate can be updated live, applied selectively, and reversed",
        "slug": "when-enabled-sparks-targeted-wallet-gate-can-be-updated-live-applied-selectively-and-reversed"
      }
    ]
  },
  {
    "label": "conditional request-logger activation",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/bin/operator/main.go#L733-L737",
    "id": "source-dd82f248c4",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "A normal Spark wallet identifies itself separately to every Operator",
        "slug": "a-normal-spark-wallet-identifies-itself-separately-to-every-operator"
      }
    ]
  },
  {
    "label": "cooperative exit gate",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/spark/so/handler/coop_exit_handler.go#L44-L67",
    "id": "source-c3aa6d8cd9",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark applies its wallet gate across exits, deposits, claims, and privileged-service paths",
        "slug": "spark-applies-its-wallet-gate-across-exits-deposits-claims-and-privileged-service-paths"
      }
    ]
  },
  {
    "label": "counterparty-privacy test",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/handler/transfer_handler_query_by_id_test.go#L20-L69",
    "id": "source-0ee25660e2",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "One public participant is enough to expose the full Spark transfer",
        "slug": "one-public-participant-is-enough-to-expose-the-full-spark-transfer"
      }
    ]
  },
  {
    "label": "current unilateral-exit service",
    "url": "https://github.com/breez/spark-sdk/blob/bce792ec7c583f640cb554b97cca7b05d29b9047/crates/spark/src/services/unilateral_exit.rs#L83-L195",
    "id": "source-3cc2feb29d",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Breez 0.19.0 ships no public mobile exit API; its draft API still contacts an operator",
        "slug": "breez-0-19-0-ships-no-public-mobile-exit-api-its-draft-api-still-contacts-an-operator"
      }
    ]
  },
  {
    "label": "default cooperative-exit flow",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/sdks/js/packages/spark-sdk/src/spark-wallet/spark-wallet.ts#L4929-L5100",
    "id": "source-2873acf3aa",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "The referenced server logic for Spark’s default Lightspark SSP is not publicly accessible",
        "slug": "the-referenced-server-logic-for-sparks-default-lightspark-ssp-is-not-publicly-accessible"
      }
    ]
  },
  {
    "label": "default Lightning SSP flow",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/sdks/js/packages/spark-sdk/src/spark-wallet/spark-wallet.ts#L4060-L4238",
    "id": "source-fab5596fde",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "The referenced server logic for Spark’s default Lightspark SSP is not publicly accessible",
        "slug": "the-referenced-server-logic-for-sparks-default-lightspark-ssp-is-not-publicly-accessible"
      }
    ]
  },
  {
    "label": "default mainnet SSP and coordinator",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/sdks/js/packages/spark-sdk/src/services/wallet-config.ts#L265-L397",
    "id": "source-ec3eddfbd9",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Lightspark's default SSP binds invoices and Bitcoin destinations to the Operator-layer wallet identity",
        "slug": "lightsparks-default-ssp-binds-invoices-and-bitcoin-destinations-to-the-operator-layer-wallet-identity"
      },
      {
        "title": "Spark's published 2-of-3 setting means one honest Operator cannot veto two retained shares",
        "slug": "sparks-published-2-of-3-setting-means-one-honest-operator-cannot-veto-two-retained-shares"
      },
      {
        "title": "Retained Lightspark and Flashnet keys could sign a conflicting spend of a Lightspark-funded Lightning leaf",
        "slug": "retained-lightspark-and-flashnet-keys-could-sign-a-conflicting-spend-of-a-lightspark-funded-lightning-leaf"
      }
    ]
  },
  {
    "label": "default topology and coordinator",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/sdks/js/packages/spark-sdk/src/services/wallet-config.ts#L184-L395",
    "id": "source-251c106c7d",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Both reviewed SDKs fix Lightspark SO0 as default coordinator without automatic failover",
        "slug": "both-reviewed-sdks-fix-lightspark-so0-as-default-coordinator-without-automatic-failover"
      }
    ]
  },
  {
    "label": "deposit-tree creation gate",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/spark/so/handler/deposit_handler.go#L892-L911",
    "id": "source-a1988d5929",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark applies its wallet gate across exits, deposits, claims, and privileged-service paths",
        "slug": "spark-applies-its-wallet-gate-across-exits-deposits-claims-and-privileged-service-paths"
      }
    ]
  },
  {
    "label": "DKG minimum signers",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/dkg/coordinator.go#L40-L52",
    "id": "source-0f8ac3c652",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark's published 2-of-3 setting means one honest Operator cannot veto two retained shares",
        "slug": "sparks-published-2-of-3-setting-means-one-honest-operator-cannot-veto-two-retained-shares"
      }
    ]
  },
  {
    "label": "documented SSP rejection point",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/.claude/flows/static_deposits.md#L25-L43",
    "id": "source-a25d85acb3",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "The referenced server logic for Spark’s default Lightspark SSP is not publicly accessible",
        "slug": "the-referenced-server-logic-for-sparks-default-lightspark-ssp-is-not-publicly-accessible"
      }
    ]
  },
  {
    "label": "empty-filter read-only client",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/sdks/js/packages/spark-sdk/src/spark-readonly-client/spark-readonly-client.ts#L753-L823",
    "id": "source-6f3ecba399",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark privacy does not cover a globally enumerable token ledger",
        "slug": "spark-privacy-does-not-cover-a-globally-enumerable-token-ledger"
      }
    ]
  },
  {
    "label": "ephemeral secret-storage design",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/entephemeral/README.md",
    "id": "source-012afa7925",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark's forward security rests on an act of key deletion users cannot verify",
        "slug": "sparks-forward-security-rests-on-an-act-of-key-deletion-users-cannot-verify"
      }
    ]
  },
  {
    "label": "fix PR 935",
    "url": "https://github.com/breez/spark-sdk/pull/935",
    "id": "source-ec07ac6207",
    "verifiedAt": "2026-07-14",
    "type": "Repository record",
    "public": true,
    "immutable": false,
    "host": "github.com",
    "findings": [
      {
        "title": "Breez 0.19.0 can silently omit a required parent and produce an unbroadcastable exit package",
        "slug": "breez-0-19-0-can-silently-omit-a-required-parent-and-produce-an-unbroadcastable-exit-package"
      }
    ]
  },
  {
    "label": "fixed SSP identity",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/sdks/js/packages/spark-sdk/src/services/wallet-config.ts#L11-L37",
    "id": "source-0bf860529d",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "One public participant is enough to expose the full Spark transfer",
        "slug": "one-public-participant-is-enough-to-expose-the-full-spark-transfer"
      },
      {
        "title": "Lightspark's default SSP binds invoices and Bitcoin destinations to the Operator-layer wallet identity",
        "slug": "lightsparks-default-ssp-binds-invoices-and-bitcoin-destinations-to-the-operator-layer-wallet-identity"
      },
      {
        "title": "Retained Lightspark and Flashnet keys could sign a conflicting spend of a Lightspark-funded Lightning leaf",
        "slug": "retained-lightspark-and-flashnet-keys-could-sign-a-conflicting-spend-of-a-lightspark-funded-lightning-leaf"
      }
    ]
  },
  {
    "label": "global token query path",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/handler/tokens/query_token_txs_handler.go#L454-L500",
    "id": "source-c45b4233c4",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark privacy does not cover a globally enumerable token ledger",
        "slug": "spark-privacy-does-not-cover-a-globally-enumerable-token-ledger"
      }
    ]
  },
  {
    "label": "Grid MSA section 2.1",
    "url": "https://github.com/lightsparkdev/grid-api/blob/f53bd763aea58a71f2522d29ee4fc591e433ad36/mintlify/legal/msa.mdx#L43-L45",
    "id": "source-ea7119d7ee",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Lightspark’s Grid contract expressly permits sanctions-based refusal, reversal, and freezing",
        "slug": "lightsparks-grid-contract-expressly-permits-sanctions-based-refusal-reversal-and-freezing"
      }
    ]
  },
  {
    "label": "Grid MSA section 2.5",
    "url": "https://github.com/lightsparkdev/grid-api/blob/f53bd763aea58a71f2522d29ee4fc591e433ad36/mintlify/legal/msa.mdx#L53-L61",
    "id": "source-c37082e184",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Grid’s contract puts compliance judgment, transaction execution, and suspension in Lightspark’s hands",
        "slug": "grids-contract-puts-compliance-judgment-transaction-execution-and-suspension-in-lightsparks-hands"
      }
    ]
  },
  {
    "label": "Grid Rewards Spark-wallet flow",
    "url": "https://github.com/lightsparkdev/grid-api/blob/f53bd763aea58a71f2522d29ee4fc591e433ad36/mintlify/rewards/quickstart.mdx#L186-L230",
    "id": "source-2f092920af",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Lightspark says Grid integrates sanctions checks into transactions and blocks illicit transfers by default",
        "slug": "lightspark-says-grid-integrates-sanctions-checks-into-transactions-and-blocks-illicit-transfers-by-default"
      }
    ]
  },
  {
    "label": "identity-bound request context",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/authn/interceptor.go#L85-L155",
    "id": "source-49e455643a",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "A normal Spark wallet identifies itself separately to every Operator",
        "slug": "a-normal-spark-wallet-identifies-itself-separately-to-every-operator"
      }
    ]
  },
  {
    "label": "identity-grouped static-address query",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/handler/tree_query_handler.go#L400-L441",
    "id": "source-aa8c2dcac0",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Rotating a Spark deposit address leaves the Operator-side wallet cluster intact",
        "slug": "rotating-a-spark-deposit-address-leaves-the-operator-side-wallet-cluster-intact"
      }
    ]
  },
  {
    "label": "immutable address-to-identity records",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/ent/schema/deposit_address.go#L28-L68",
    "id": "source-c5ba6f0ee5",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Rotating a Spark deposit address leaves the Operator-side wallet cluster intact",
        "slug": "rotating-a-spark-deposit-address-leaves-the-operator-side-wallet-cluster-intact"
      }
    ]
  },
  {
    "label": "indistinguishability test",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/spark/so/authz/killswitch_test.go#L16-L123",
    "id": "source-a3836e40b6",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark makes a targeted wallet freeze externally indistinguishable from an ordinary identity error",
        "slug": "spark-makes-a-targeted-wallet-freeze-externally-indistinguishable-from-an-ordinary-identity-error"
      }
    ]
  },
  {
    "label": "InternalAccount",
    "url": "https://github.com/lightsparkdev/grid-api/blob/f53bd763aea58a71f2522d29ee4fc591e433ad36/openapi/components/schemas/customers/InternalAccount.yaml#L1-L23",
    "id": "source-4fac637bd4",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Grid’s common account model permits a Spark-backed wallet to carry a frozen status that blocks payments",
        "slug": "grids-common-account-model-permits-a-spark-backed-wallet-to-carry-a-frozen-status-that-blocks-payments"
      }
    ]
  },
  {
    "label": "InternalAccountStatus",
    "url": "https://github.com/lightsparkdev/grid-api/blob/f53bd763aea58a71f2522d29ee4fc591e433ad36/openapi/components/schemas/customers/InternalAccountStatus.yaml#L1-L25",
    "id": "source-b64f839f86",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Grid’s common account model permits a Spark-backed wallet to carry a frozen status that blocks payments",
        "slug": "grids-common-account-model-permits-a-spark-backed-wallet-to-carry-a-frozen-status-that-blocks-payments"
      }
    ]
  },
  {
    "label": "InternalAccountType",
    "url": "https://github.com/lightsparkdev/grid-api/blob/f53bd763aea58a71f2522d29ee4fc591e433ad36/openapi/components/schemas/customers/InternalAccountType.yaml#L1-L19",
    "id": "source-1b2b60f836",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Grid’s common account model permits a Spark-backed wallet to carry a frozen status that blocks payments",
        "slug": "grids-common-account-model-permits-a-spark-backed-wallet-to-carry-a-frozen-status-that-blocks-payments"
      }
    ]
  },
  {
    "label": "issue 374",
    "url": "https://github.com/breez/spark-sdk/issues/374",
    "id": "source-f178c2190e",
    "verifiedAt": "2026-07-14",
    "type": "Repository record",
    "public": true,
    "immutable": false,
    "host": "github.com",
    "findings": [
      {
        "title": "Breez 0.19.0 ships no public mobile exit API; its draft API still contacts an operator",
        "slug": "breez-0-19-0-ships-no-public-mobile-exit-api-its-draft-api-still-contacts-an-operator"
      },
      {
        "title": "Cake describes a one-transaction exit, but its reviewed shipped integration did not expose an exit flow",
        "slug": "cake-describes-a-one-transaction-exit-but-its-reviewed-shipped-integration-did-not-expose-an-exit-flow"
      }
    ]
  },
  {
    "label": "JavaScript coordinator lookup",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/sdks/js/packages/spark-sdk/src/services/config.ts#L207-L251",
    "id": "source-bbc83e04f3",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Both reviewed SDKs fix Lightspark SO0 as default coordinator without automatic failover",
        "slug": "both-reviewed-sdks-fix-lightspark-so0-as-default-coordinator-without-automatic-failover"
      }
    ]
  },
  {
    "label": "killswitch.go",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/spark/so/authz/killswitch.go#L16-L58",
    "id": "source-d20391edfa",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark makes a targeted wallet freeze externally indistinguishable from an ordinary identity error",
        "slug": "spark-makes-a-targeted-wallet-freeze-externally-indistinguishable-from-an-ordinary-identity-error"
      }
    ]
  },
  {
    "label": "knob definition",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/spark/so/knobs/knobs.go#L65-L70",
    "id": "source-30fe474ace",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark Operator code includes a wallet-identity kill switch for state-changing actions",
        "slug": "spark-operator-code-includes-a-wallet-identity-kill-switch-for-state-changing-actions"
      }
    ]
  },
  {
    "label": "leaf-renewal gate",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/spark/so/handler/renew_leaf_handler.go#L132-L149",
    "id": "source-34092e6953",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark applies its wallet gate across exits, deposits, claims, and privileged-service paths",
        "slug": "spark-applies-its-wallet-gate-across-exits-deposits-claims-and-privileged-service-paths"
      }
    ]
  },
  {
    "label": "legacy transfer fan-out",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/handler/transfer_handler_mimo.go#L407-L446",
    "id": "source-64583860e4",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Every Spark Operator receives transfer participants and records—not merely a signing share",
        "slug": "every-spark-operator-receives-transfer-participants-and-records-not-merely-a-signing-share"
      }
    ]
  },
  {
    "label": "Lightning transfer to fixed SSP",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/sdks/js/packages/spark-sdk/src/spark-wallet/spark-wallet.ts#L4173-L4215",
    "id": "source-1dd9103534",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "One public participant is enough to expose the full Spark transfer",
        "slug": "one-public-participant-is-enough-to-expose-the-full-spark-transfer"
      }
    ]
  },
  {
    "label": "Lightspark-only SSP interface",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/rpcpolicy/policy_lightspark.go#L1-L57",
    "id": "source-dd484c50cc",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark gives Lightspark's SSP explicit cross-wallet privacy-bypass paths",
        "slug": "spark-gives-lightsparks-ssp-explicit-cross-wallet-privacy-bypass-paths"
      }
    ]
  },
  {
    "label": "live ConfigMap watcher",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/spark/so/knobs/k8.go#L65-L88",
    "id": "source-362d5b4d9f",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "When enabled, Spark’s targeted wallet gate can be updated live, applied selectively, and reversed",
        "slug": "when-enabled-sparks-targeted-wallet-gate-can-be-updated-live-applied-selectively-and-reversed"
      }
    ]
  },
  {
    "label": "multi-participant privacy rule",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/handler/transfer_handler.go#L1933-L1968",
    "id": "source-d0ea1f9ed5",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "One public participant is enough to expose the full Spark transfer",
        "slug": "one-public-participant-is-enough-to-expose-the-full-spark-transfer"
      }
    ]
  },
  {
    "label": "normal leaf query",
    "url": "https://github.com/breez/spark-sdk/blob/bce792ec7c583f640cb554b97cca7b05d29b9047/crates/spark/src/tree/service.rs#L197-L211",
    "id": "source-bfb4f2bba6",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Breez’s default mobile persistence does not retain the tree needed for an outage exit",
        "slug": "breezs-default-mobile-persistence-does-not-retain-the-tree-needed-for-an-outage-exit"
      }
    ]
  },
  {
    "label": "old-version deletion logic",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/ent/signingkeyshare_extension.go#L205-L253",
    "id": "source-36997a93ba",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark's forward security rests on an act of key deletion users cannot verify",
        "slug": "sparks-forward-security-rests-on-an-act-of-key-deletion-users-cannot-verify"
      }
    ]
  },
  {
    "label": "one-plus-threshold signing construction",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/helper/signing_coordinator.go#L433-L480",
    "id": "source-c7f347b1ff",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark's published 2-of-3 setting means one honest Operator cannot veto two retained shares",
        "slug": "sparks-published-2-of-3-setting-means-one-honest-operator-cannot-veto-two-retained-shares"
      },
      {
        "title": "Retained Lightspark and Flashnet keys could sign a conflicting spend of a Lightspark-funded Lightning leaf",
        "slug": "retained-lightspark-and-flashnet-keys-could-sign-a-conflicting-spend-of-a-lightspark-funded-lightning-leaf"
      }
    ]
  },
  {
    "label": "Operator identity authentication",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/sdks/js/packages/spark-sdk/src/services/connection/connection.ts#L438-L490",
    "id": "source-99ed2d68bf",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Lightspark's default SSP binds invoices and Bitcoin destinations to the Operator-layer wallet identity",
        "slug": "lightsparks-default-ssp-binds-invoices-and-bitcoin-destinations-to-the-operator-layer-wallet-identity"
      }
    ]
  },
  {
    "label": "Operator share rotation",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/ent/signingkeyshare_extension.go#L847-L878",
    "id": "source-ae797f7959",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark's forward security rests on an act of key deletion users cannot verify",
        "slug": "sparks-forward-security-rests-on-an-act-of-key-deletion-users-cannot-verify"
      }
    ]
  },
  {
    "label": "ordinary deposit-address gate",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/spark/so/handler/deposit_handler.go#L135-L143",
    "id": "source-a95f5e0fb3",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark applies its wallet gate across exits, deposits, claims, and privileged-service paths",
        "slug": "spark-applies-its-wallet-gate-across-exits-deposits-claims-and-privileged-service-paths"
      }
    ]
  },
  {
    "label": "origin commit",
    "url": "https://github.com/buildonspark/spark/commit/08db5deea2d769b9f33c7f2aaf1cec67a183dd42",
    "id": "source-edb5fbf5eb",
    "verifiedAt": "2026-07-14",
    "type": "Code commit",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark Operator code includes a wallet-identity kill switch for state-changing actions",
        "slug": "spark-operator-code-includes-a-wallet-identity-kill-switch-for-state-changing-actions"
      }
    ]
  },
  {
    "label": "outgoing request fields",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/sdks/js/packages/spark-sdk/src/services/lightning.ts#L200-L278",
    "id": "source-c64760b959",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Every Spark Operator receives the full Lightning invoice—not merely one secret share",
        "slug": "every-spark-operator-receives-the-full-lightning-invoice-not-merely-one-secret-share"
      }
    ]
  },
  {
    "label": "participant-side transfer creation",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/handler/internal_transfer_handler.go#L567-L661",
    "id": "source-09dbd74f97",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Every Spark Operator receives transfer participants and records—not merely a signing share",
        "slug": "every-spark-operator-receives-transfer-participants-and-records-not-merely-a-signing-share"
      }
    ]
  },
  {
    "label": "per-Operator identity authentication",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/sdks/js/packages/spark-sdk/src/services/connection/connection.ts#L325-L490",
    "id": "source-7fc2cfcf3b",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "A normal Spark wallet identifies itself separately to every Operator",
        "slug": "a-normal-spark-wallet-identifies-itself-separately-to-every-operator"
      }
    ]
  },
  {
    "label": "preimage-share consensus handler",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/spark/so/handler/preimage_share_flow_handler.go#L170-L183",
    "id": "source-38e2915065",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark’s preimage-share consensus path enforces the wallet gate for SSP and LNURL callers",
        "slug": "sparks-preimage-share-consensus-path-enforces-the-wallet-gate-for-ssp-and-lnurl-callers"
      }
    ]
  },
  {
    "label": "Primal Android",
    "url": "https://github.com/PrimalHQ/primal-android-app/tree/c16997628c5111e56ac8b98b49d4297f5d52e480",
    "id": "source-cd1dc8f3a1",
    "verifiedAt": "2026-07-14",
    "type": "Repository record",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "No complete in-app operatorless exit was found in eight reviewed consumer-wallet products",
        "slug": "no-complete-in-app-operatorless-exit-was-found-in-eight-reviewed-consumer-wallet-products"
      },
      {
        "title": "Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path",
        "slug": "across-primal-radar-wallet-of-satoshi-and-bringin-control-claims-were-not-matched-by-a-demonstrated-unilateral-exit-path"
      }
    ]
  },
  {
    "label": "Primal Android control claim",
    "url": "https://github.com/PrimalHQ/primal-android-app/blob/c16997628c5111e56ac8b98b49d4297f5d52e480/app/src/main/res/values/strings.xml#L1380",
    "id": "source-80fd50e65b",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path",
        "slug": "across-primal-radar-wallet-of-satoshi-and-bringin-control-claims-were-not-matched-by-a-demonstrated-unilateral-exit-path"
      }
    ]
  },
  {
    "label": "Primal Android custody claims",
    "url": "https://github.com/PrimalHQ/primal-android-app/blob/c16997628c5111e56ac8b98b49d4297f5d52e480/app/src/main/res/values/strings.xml#L1574-L1588",
    "id": "source-46ea798506",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path",
        "slug": "across-primal-radar-wallet-of-satoshi-and-bringin-control-claims-were-not-matched-by-a-demonstrated-unilateral-exit-path"
      }
    ]
  },
  {
    "label": "Primal iOS",
    "url": "https://github.com/PrimalHQ/primal-ios-app/tree/91787a1209bd13f57afcb5fe100783102feae2fb",
    "id": "source-bbf4f4f230",
    "verifiedAt": "2026-07-14",
    "type": "Repository record",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "No complete in-app operatorless exit was found in eight reviewed consumer-wallet products",
        "slug": "no-complete-in-app-operatorless-exit-was-found-in-eight-reviewed-consumer-wallet-products"
      },
      {
        "title": "Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path",
        "slug": "across-primal-radar-wallet-of-satoshi-and-bringin-control-claims-were-not-matched-by-a-demonstrated-unilateral-exit-path"
      }
    ]
  },
  {
    "label": "Primal iOS backup claim",
    "url": "https://github.com/PrimalHQ/primal-ios-app/blob/91787a1209bd13f57afcb5fe100783102feae2fb/Primal/Scenes/Wallet/Backup/BackupWalletIntroController.swift#L35-L47",
    "id": "source-1776ca9a71",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path",
        "slug": "across-primal-radar-wallet-of-satoshi-and-bringin-control-claims-were-not-matched-by-a-demonstrated-unilateral-exit-path"
      }
    ]
  },
  {
    "label": "Primal iOS confirmation claim",
    "url": "https://github.com/PrimalHQ/primal-ios-app/blob/91787a1209bd13f57afcb5fe100783102feae2fb/Primal/Scenes/Wallet/Backup/BackupWalletConfirmController.swift#L20-L30",
    "id": "source-c2c81d46bf",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path",
        "slug": "across-primal-radar-wallet-of-satoshi-and-bringin-control-claims-were-not-matched-by-a-demonstrated-unilateral-exit-path"
      }
    ]
  },
  {
    "label": "privileged-broadcaster invariant",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/spark/so/handler/tokens/broadcast_permissions.go#L27-L43",
    "id": "source-ad1c5661b8",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark applies its wallet gate across exits, deposits, claims, and privileged-service paths",
        "slug": "spark-applies-its-wallet-gate-across-exits-deposits-claims-and-privileged-service-paths"
      }
    ]
  },
  {
    "label": "protobuf redaction list",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/common/logging/proto.go#L14-L18",
    "id": "source-9ceeb93504",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "A normal Spark wallet identifies itself separately to every Operator",
        "slug": "a-normal-spark-wallet-identifies-itself-separately-to-every-operator"
      }
    ]
  },
  {
    "label": "public read-only client and balance query",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/sdks/js/packages/spark-sdk/src/spark-readonly-client/spark-readonly-client.ts#L75-L270",
    "id": "source-b3a40353c5",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "A public-mode Spark identity exposes exact holdings and raw Bitcoin transaction material",
        "slug": "a-public-mode-spark-identity-exposes-exact-holdings-and-raw-bitcoin-transaction-material"
      }
    ]
  },
  {
    "label": "public SSP schema",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/schemas/ssp_rc_schema.graphql",
    "id": "source-7d948b1288",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "The referenced server logic for Spark’s default Lightspark SSP is not publicly accessible",
        "slug": "the-referenced-server-logic-for-sparks-default-lightspark-ssp-is-not-publicly-accessible"
      }
    ]
  },
  {
    "label": "public transfer fields",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/protos/spark.proto#L855-L900",
    "id": "source-c7cffda559",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "One public participant is enough to expose the full Spark transfer",
        "slug": "one-public-participant-is-enough-to-expose-the-full-spark-transfer"
      }
    ]
  },
  {
    "label": "pull request 795",
    "url": "https://github.com/breez/spark-sdk/pull/795",
    "id": "source-bc18e0dd62",
    "verifiedAt": "2026-07-14",
    "type": "Repository record",
    "public": true,
    "immutable": false,
    "host": "github.com",
    "findings": [
      {
        "title": "Breez 0.19.0 ships no public mobile exit API; its draft API still contacts an operator",
        "slug": "breez-0-19-0-ships-no-public-mobile-exit-api-its-draft-api-still-contacts-an-operator"
      }
    ]
  },
  {
    "label": "Radar Android",
    "url": "https://github.com/radar-labs/radar-android/tree/8ca3e2b147fa32648afb04f8a42c4dd4b7db9eda",
    "id": "source-fca02e3502",
    "verifiedAt": "2026-07-14",
    "type": "Repository record",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "No complete in-app operatorless exit was found in eight reviewed consumer-wallet products",
        "slug": "no-complete-in-app-operatorless-exit-was-found-in-eight-reviewed-consumer-wallet-products"
      },
      {
        "title": "Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path",
        "slug": "across-primal-radar-wallet-of-satoshi-and-bringin-control-claims-were-not-matched-by-a-demonstrated-unilateral-exit-path"
      }
    ]
  },
  {
    "label": "Radar Android Breez version",
    "url": "https://github.com/radar-labs/radar-android/blob/8ca3e2b147fa32648afb04f8a42c4dd4b7db9eda/gradle/libs.versions.toml#L191",
    "id": "source-fb31889a09",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path",
        "slug": "across-primal-radar-wallet-of-satoshi-and-bringin-control-claims-were-not-matched-by-a-demonstrated-unilateral-exit-path"
      }
    ]
  },
  {
    "label": "Radar control claim",
    "url": "https://github.com/radar-labs/Radar/blob/661a39cce1b9d270b6ae9d0914c15a836d103668/README.md#L5-L20",
    "id": "source-caac4b15c9",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path",
        "slug": "across-primal-radar-wallet-of-satoshi-and-bringin-control-claims-were-not-matched-by-a-demonstrated-unilateral-exit-path"
      }
    ]
  },
  {
    "label": "Radar iOS",
    "url": "https://github.com/radar-labs/Radar/tree/661a39cce1b9d270b6ae9d0914c15a836d103668",
    "id": "source-7a7287fdc3",
    "verifiedAt": "2026-07-14",
    "type": "Repository record",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "No complete in-app operatorless exit was found in eight reviewed consumer-wallet products",
        "slug": "no-complete-in-app-operatorless-exit-was-found-in-eight-reviewed-consumer-wallet-products"
      },
      {
        "title": "Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path",
        "slug": "across-primal-radar-wallet-of-satoshi-and-bringin-control-claims-were-not-matched-by-a-demonstrated-unilateral-exit-path"
      }
    ]
  },
  {
    "label": "Radar iOS Breez version",
    "url": "https://github.com/radar-labs/Radar/blob/661a39cce1b9d270b6ae9d0914c15a836d103668/ThirdParty/BreezSdkSpark.podspec.json#L1-L21",
    "id": "source-4dc7c56a5b",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path",
        "slug": "across-primal-radar-wallet-of-satoshi-and-bringin-control-claims-were-not-matched-by-a-demonstrated-unilateral-exit-path"
      }
    ]
  },
  {
    "label": "Radar recovery language",
    "url": "https://github.com/radar-labs/Radar/blob/661a39cce1b9d270b6ae9d0914c15a836d103668/Signal/translations/en.lproj/Localizable.strings#L8330-L8342",
    "id": "source-49769df467",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path",
        "slug": "across-primal-radar-wallet-of-satoshi-and-bringin-control-claims-were-not-matched-by-a-demonstrated-unilateral-exit-path"
      }
    ]
  },
  {
    "label": "receiver-side transfer comment and gate",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/spark/so/handler/transfer_handler.go#L5411-L5418",
    "id": "source-0d905f8be4",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark Operator code can stop a pending SSP-funded incoming transfer before wallet credit",
        "slug": "spark-operator-code-can-stop-a-pending-ssp-funded-incoming-transfer-before-wallet-credit"
      }
    ]
  },
  {
    "label": "reference SSP-funded Lightning receive",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/grpc_test/lightning_test.go#L118-L201",
    "id": "source-3cb19f803b",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Retained Lightspark and Flashnet keys could sign a conflicting spend of a Lightspark-funded Lightning leaf",
        "slug": "retained-lightspark-and-flashnet-keys-could-sign-a-conflicting-spend-of-a-lightspark-funded-lightning-leaf"
      }
    ]
  },
  {
    "label": "referenced non-public implementation",
    "url": "https://github.com/lightsparkdev/webdev/blob/150dd1ceecf85e122ec3ebd608d3c9f7c44f1969/sparkcore/sparkcore/spark/handlers/__tests__/test_transfer_v2.py#L35",
    "id": "source-f2455d7667",
    "verifiedAt": "2026-07-14",
    "type": "Referenced non-public implementation",
    "public": true,
    "immutable": true,
    "expectedUnavailable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "The referenced server logic for Spark’s default Lightspark SSP is not publicly accessible",
        "slug": "the-referenced-server-logic-for-sparks-default-lightspark-ssp-is-not-publicly-accessible"
      }
    ]
  },
  {
    "label": "request and client-metadata logger",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/common/logging/table.go#L143-L257",
    "id": "source-aba9f37ab0",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "A normal Spark wallet identifies itself separately to every Operator",
        "slug": "a-normal-spark-wallet-identifies-itself-separately-to-every-operator"
      }
    ]
  },
  {
    "label": "returned node fields",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/ent/treenode_extension.go#L17-L68",
    "id": "source-64a29de168",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "A public-mode Spark identity exposes exact holdings and raw Bitcoin transaction material",
        "slug": "a-public-mode-spark-identity-exposes-exact-holdings-and-raw-bitcoin-transaction-material"
      }
    ]
  },
  {
    "label": "screenNode",
    "url": "https://github.com/lightsparkdev/js-sdk/blob/46c731cfaf9b1eeb9584d2176bc006076de3b2d1/packages/lightspark-sdk/src/client.ts#L1395-L1425",
    "id": "source-f152b18d2c",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Lightspark Connect exposes Chainalysis-backed sanctions screening of Lightning nodes",
        "slug": "lightspark-connect-exposes-chainalysis-backed-sanctions-screening-of-lightning-nodes"
      }
    ]
  },
  {
    "label": "section 2.8(h)",
    "url": "https://github.com/lightsparkdev/grid-api/blob/f53bd763aea58a71f2522d29ee4fc591e433ad36/mintlify/legal/msa.mdx#L71-L81",
    "id": "source-bfa0fe6f0b",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Lightspark’s Grid contract expressly permits sanctions-based refusal, reversal, and freezing",
        "slug": "lightsparks-grid-contract-expressly-permits-sanctions-based-refusal-reversal-and-freezing"
      }
    ]
  },
  {
    "label": "server share update and invariant verifying key",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/helper/key_tweak_helper.go#L76-L121",
    "id": "source-124e40dde4",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Retained Lightspark and Flashnet keys could sign a conflicting spend of a Lightspark-funded Lightning leaf",
        "slug": "retained-lightspark-and-flashnet-keys-could-sign-a-conflicting-spend-of-a-lightspark-funded-lightning-leaf"
      }
    ]
  },
  {
    "label": "Spark CLI unilateralexit implementation",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/sdks/js/apps/spark-cli/src/cli.ts#L3525-L3895",
    "id": "source-f3d69c35d5",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark’s mainnet CLI generates packages but leaves signing, ordered broadcast, timelocks, and sweeping to the user",
        "slug": "sparks-mainnet-cli-generates-packages-but-leaves-signing-ordered-broadcast-timelocks-and-sweeping-to-the-user"
      }
    ]
  },
  {
    "label": "Spark package constructor",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/sdks/js/packages/spark-sdk/src/utils/unilateral-exit.ts",
    "id": "source-8b97312bb1",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "The documented independent exit cannot start from a Spark balance alone; it needs external on-chain fee funding",
        "slug": "the-documented-independent-exit-cannot-start-from-a-spark-balance-alone-it-needs-external-on-chain-fee-funding"
      }
    ]
  },
  {
    "label": "Spark renewal status",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/spark/so/handler/renew_leaf_handler.go#L390-L403",
    "id": "source-ef63979da2",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Breez 0.19.0 can silently omit a required parent and produce an unbroadcastable exit package",
        "slug": "breez-0-19-0-can-silently-omit-a-required-parent-and-produce-an-unbroadcastable-exit-package"
      }
    ]
  },
  {
    "label": "Spark SSP configuration",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/sdks/js/packages/spark-sdk/src/services/wallet-config.ts#L11-L38",
    "id": "source-4009f37def",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Despite an announced Breez SSP, both reviewed SDKs still default only to Lightspark",
        "slug": "despite-an-announced-breez-ssp-both-reviewed-sdks-still-default-only-to-lightspark"
      }
    ]
  },
  {
    "label": "Sparkcore SSP instructions",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/README.md#L254-L283",
    "id": "source-7c91c24385",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "The referenced server logic for Spark’s default Lightspark SSP is not publicly accessible",
        "slug": "the-referenced-server-logic-for-sparks-default-lightspark-ssp-is-not-publicly-accessible"
      }
    ]
  },
  {
    "label": "SQLite backend",
    "url": "https://github.com/breez/spark-sdk/blob/bce792ec7c583f640cb554b97cca7b05d29b9047/crates/breez-sdk/core/src/persist/backend/sqlite.rs#L29-L40",
    "id": "source-7ddb8a4a23",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Breez’s default mobile persistence does not retain the tree needed for an outage exit",
        "slug": "breezs-default-mobile-persistence-does-not-retain-the-tree-needed-for-an-outage-exit"
      }
    ]
  },
  {
    "label": "SSP cooperative-exit input",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/schemas/ssp_rc_schema.graphql#L990-L999",
    "id": "source-400cb225ab",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Lightspark's default SSP binds invoices and Bitcoin destinations to the Operator-layer wallet identity",
        "slug": "lightsparks-default-ssp-binds-invoices-and-bitcoin-destinations-to-the-operator-layer-wallet-identity"
      }
    ]
  },
  {
    "label": "SSP cooperative-exit record",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/schemas/ssp_rc_schema.graphql#L299-L335",
    "id": "source-1a5ba9efdf",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Lightspark's default SSP binds invoices and Bitcoin destinations to the Operator-layer wallet identity",
        "slug": "lightsparks-default-ssp-binds-invoices-and-bitcoin-destinations-to-the-operator-layer-wallet-identity"
      }
    ]
  },
  {
    "label": "SSP identity authentication",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/sdks/js/packages/spark-sdk/src/graphql/client.ts#L644-L720",
    "id": "source-f7ea55ee29",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Lightspark's default SSP binds invoices and Bitcoin destinations to the Operator-layer wallet identity",
        "slug": "lightsparks-default-ssp-binds-invoices-and-bitcoin-destinations-to-the-operator-layer-wallet-identity"
      }
    ]
  },
  {
    "label": "SSP Lightning-invoice record",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/schemas/ssp_rc_schema.graphql#L768-L803",
    "id": "source-3fc06670da",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Lightspark's default SSP binds invoices and Bitcoin destinations to the Operator-layer wallet identity",
        "slug": "lightsparks-default-ssp-binds-invoices-and-bitcoin-destinations-to-the-operator-layer-wallet-identity"
      }
    ]
  },
  {
    "label": "SSP node-query privacy bypass",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/handler/tree_query_handler.go#L37-L166",
    "id": "source-a4d3b5f183",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark gives Lightspark's SSP explicit cross-wallet privacy-bypass paths",
        "slug": "spark-gives-lightsparks-ssp-explicit-cross-wallet-privacy-bypass-paths"
      },
      {
        "title": "A public-mode Spark identity exposes exact holdings and raw Bitcoin transaction material",
        "slug": "a-public-mode-spark-identity-exposes-exact-holdings-and-raw-bitcoin-transaction-material"
      }
    ]
  },
  {
    "label": "SSP transfer privacy bypass",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/handler/transfer_handler.go#L2207-L2217",
    "id": "source-934a7f8213",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark gives Lightspark's SSP explicit cross-wallet privacy-bypass paths",
        "slug": "spark-gives-lightsparks-ssp-explicit-cross-wallet-privacy-bypass-paths"
      }
    ]
  },
  {
    "label": "SSP wallet identity and request history",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/schemas/ssp_rc_schema.graphql#L1190-L1206",
    "id": "source-4aae926ec2",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Lightspark's default SSP binds invoices and Bitcoin destinations to the Operator-layer wallet identity",
        "slug": "lightsparks-default-ssp-binds-invoices-and-bitcoin-destinations-to-the-operator-layer-wallet-identity"
      }
    ]
  },
  {
    "label": "static deposit-address gate",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/spark/so/handler/deposit_handler.go#L310-L333",
    "id": "source-9c6e2a7187",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark applies its wallet gate across exits, deposits, claims, and privileged-service paths",
        "slug": "spark-applies-its-wallet-gate-across-exits-deposits-claims-and-privileged-service-paths"
      }
    ]
  },
  {
    "label": "static-address bypass commit",
    "url": "https://github.com/buildonspark/spark/commit/4d8320507a0b99869ddfd62fa08f225962c2127c",
    "id": "source-32695dffcc",
    "verifiedAt": "2026-07-14",
    "type": "Code commit",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark gives Lightspark's SSP explicit cross-wallet privacy-bypass paths",
        "slug": "spark-gives-lightsparks-ssp-explicit-cross-wallet-privacy-bypass-paths"
      }
    ]
  },
  {
    "label": "static-address rotation and identity",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/handler/deposit_handler.go#L684-L830",
    "id": "source-cdb48ff208",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Rotating a Spark deposit address leaves the Operator-side wallet cluster intact",
        "slug": "rotating-a-spark-deposit-address-leaves-the-operator-side-wallet-cluster-intact"
      }
    ]
  },
  {
    "label": "static-address rotation gate",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/spark/so/handler/deposit_handler.go#L712-L732",
    "id": "source-8b4eac492d",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark applies its wallet gate across exits, deposits, claims, and privileged-service paths",
        "slug": "spark-applies-its-wallet-gate-across-exits-deposits-claims-and-privileged-service-paths"
      }
    ]
  },
  {
    "label": "stored invoice and wallet identity",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/ent/schema/preimage_share.go#L31-L59",
    "id": "source-645e870234",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Every Spark Operator receives the full Lightning invoice—not merely one secret share",
        "slug": "every-spark-operator-receives-the-full-lightning-invoice-not-merely-one-secret-share"
      }
    ]
  },
  {
    "label": "targeting and reversal test",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/spark/so/grpc_test/wallet_killswitch_test.go#L17-L83",
    "id": "source-44bfcee027",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "When enabled, Spark’s targeted wallet gate can be updated live, applied selectively, and reversed",
        "slug": "when-enabled-sparks-targeted-wallet-gate-can-be-updated-live-applied-selectively-and-reversed"
      }
    ]
  },
  {
    "label": "token output fields",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/protos/spark_token.proto#L70-L151",
    "id": "source-15f0892207",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark privacy does not cover a globally enumerable token ledger",
        "slug": "spark-privacy-does-not-cover-a-globally-enumerable-token-ledger"
      }
    ]
  },
  {
    "label": "transfer-claim gate",
    "url": "https://github.com/buildonspark/spark/blob/9c25e7fd0b0214d424a04cd6eecfa7d7f4e2584e/spark/so/handler/claim_transfer_flow_handler.go#L86-L98",
    "id": "source-e4c5b6a708",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark applies its wallet gate across exits, deposits, claims, and privileged-service paths",
        "slug": "spark-applies-its-wallet-gate-across-exits-deposits-claims-and-privileged-service-paths"
      }
    ]
  },
  {
    "label": "unauthenticated read policy",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/rpcpolicy/policy.go#L126-L170",
    "id": "source-f916faf243",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "A public-mode Spark identity exposes exact holdings and raw Bitcoin transaction material",
        "slug": "a-public-mode-spark-identity-exposes-exact-holdings-and-raw-bitcoin-transaction-material"
      }
    ]
  },
  {
    "label": "unauthenticated token policy",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/spark/so/rpcpolicy/policy.go#L225-L234",
    "id": "source-098a27f73d",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Spark privacy does not cover a globally enumerable token ledger",
        "slug": "spark-privacy-does-not-cover-a-globally-enumerable-token-ledger"
      }
    ]
  },
  {
    "label": "wallet constructs the SSP client",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/sdks/js/packages/spark-sdk/src/spark-wallet/spark-wallet.ts#L285-L305",
    "id": "source-a84d87cfa3",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Lightspark's default SSP binds invoices and Bitcoin destinations to the Operator-layer wallet identity",
        "slug": "lightsparks-default-ssp-binds-invoices-and-bitcoin-destinations-to-the-operator-layer-wallet-identity"
      }
    ]
  },
  {
    "label": "wallet initialization",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/sdks/js/packages/spark-sdk/src/spark-wallet/spark-wallet.ts#L465-L485",
    "id": "source-c4d3460bf3",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "A normal Spark wallet identifies itself separately to every Operator",
        "slug": "a-normal-spark-wallet-identifies-itself-separately-to-every-operator"
      }
    ]
  },
  {
    "label": "wallet preimage-share request",
    "url": "https://github.com/buildonspark/spark/blob/f1f968e68daa74d22e3398ce126302e35ac47f95/sdks/js/packages/spark-sdk/src/services/lightning.ts#L128-L179",
    "id": "source-51c3222639",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Every Spark Operator receives the full Lightning invoice—not merely one secret share",
        "slug": "every-spark-operator-receives-the-full-lightning-invoice-not-merely-one-secret-share"
      }
    ]
  },
  {
    "label": "WalletBuilder fallback",
    "url": "https://github.com/breez/spark-sdk/blob/bce792ec7c583f640cb554b97cca7b05d29b9047/crates/spark-wallet/src/wallet_builder.rs#L115-L127",
    "id": "source-2e849b3812",
    "verifiedAt": "2026-07-14",
    "type": "Pinned source code",
    "public": true,
    "immutable": true,
    "host": "github.com",
    "findings": [
      {
        "title": "Breez’s default mobile persistence does not retain the tree needed for an outage exit",
        "slug": "breezs-default-mobile-persistence-does-not-retain-the-tree-needed-for-an-outage-exit"
      }
    ]
  },
  {
    "label": "Breez SSP announcement",
    "url": "https://www.lightspark.com/news/spark/breez-spark-partnership",
    "id": "source-98c093e969",
    "verifiedAt": "2026-07-14",
    "type": "Blog or announcement",
    "public": true,
    "immutable": false,
    "host": "lightspark.com",
    "findings": [
      {
        "title": "Despite an announced Breez SSP, both reviewed SDKs still default only to Lightspark",
        "slug": "despite-an-announced-breez-ssp-both-reviewed-sdks-still-default-only-to-lightspark"
      }
    ]
  },
  {
    "label": "Lightspark on-demand platforms",
    "url": "https://www.lightspark.com/businesses/on-demand-platforms",
    "id": "source-985cd0bcc1",
    "verifiedAt": "2026-07-14",
    "type": "Web source",
    "public": true,
    "immutable": false,
    "host": "lightspark.com",
    "findings": [
      {
        "title": "Lightspark says it handles sanctions screening for account products built on Spark wallets",
        "slug": "lightspark-says-it-handles-sanctions-screening-for-account-products-built-on-spark-wallets"
      }
    ]
  },
  {
    "label": "Lightspark sanctions explainer",
    "url": "https://www.lightspark.com/glossary/sanctions-screening",
    "id": "source-ed5a10e1c1",
    "verifiedAt": "2026-07-14",
    "type": "Web source",
    "public": true,
    "immutable": false,
    "host": "lightspark.com",
    "findings": [
      {
        "title": "Lightspark says Grid integrates sanctions checks into transactions and blocks illicit transfers by default",
        "slug": "lightspark-says-grid-integrates-sanctions-checks-into-transactions-and-blocks-illicit-transfers-by-default"
      }
    ]
  },
  {
    "label": "Lightspark's open-source statement",
    "url": "https://www.lightspark.com/news/spark/introducing-spark",
    "id": "source-45abab1b69",
    "verifiedAt": "2026-07-14",
    "type": "Blog or announcement",
    "public": true,
    "immutable": false,
    "host": "lightspark.com",
    "findings": [
      {
        "title": "The referenced server logic for Spark’s default Lightspark SSP is not publicly accessible",
        "slug": "the-referenced-server-logic-for-sparks-default-lightspark-ssp-is-not-publicly-accessible"
      }
    ]
  },
  {
    "label": "Blink funding transaction",
    "url": "https://mempool.space/tx/3ab20a4c40d75f524b6c7b9e5837bc0bdef6aa350e79d932aa134134f0957262",
    "id": "source-72af077ba8",
    "verifiedAt": "2026-07-14",
    "type": "On-chain transaction",
    "public": true,
    "immutable": true,
    "host": "mempool.space",
    "findings": [
      {
        "title": "The documented independent exit cannot start from a Spark balance alone; it needs external on-chain fee funding",
        "slug": "the-documented-independent-exit-cannot-start-from-a-spark-balance-alone-it-needs-external-on-chain-fee-funding"
      }
    ]
  },
  {
    "label": "Wallet of Satoshi Play listing",
    "url": "https://play.google.com/store/apps/details?id=com.livingroomofsatoshi.wallet",
    "id": "source-423abd1dd0",
    "verifiedAt": "2026-07-14",
    "type": "Web source",
    "public": true,
    "immutable": false,
    "host": "play.google.com",
    "findings": [
      {
        "title": "Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path",
        "slug": "across-primal-radar-wallet-of-satoshi-and-bringin-control-claims-were-not-matched-by-a-demonstrated-unilateral-exit-path"
      }
    ]
  },
  {
    "label": "consumer-wallet exit audit manifest",
    "url": "data/consumer-wallet-exit-audit.json",
    "id": "source-baab8de22f",
    "verifiedAt": "2026-07-14",
    "type": "Reproducible audit manifest",
    "public": true,
    "immutable": true,
    "internal": true,
    "host": "Review of Spark's trust model",
    "findings": [
      {
        "title": "No complete in-app operatorless exit was found in eight reviewed consumer-wallet products",
        "slug": "no-complete-in-app-operatorless-exit-was-found-in-eight-reviewed-consumer-wallet-products"
      },
      {
        "title": "Club Orange bundled lower-level exit code without exposing an app-facing exit operation",
        "slug": "club-orange-bundled-lower-level-exit-code-without-exposing-an-app-facing-exit-operation"
      },
      {
        "title": "Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path",
        "slug": "across-primal-radar-wallet-of-satoshi-and-bringin-control-claims-were-not-matched-by-a-demonstrated-unilateral-exit-path"
      }
    ]
  },
  {
    "label": "sanitized mainnet observation",
    "url": "data/spark-mainnet-privacy-observation.json",
    "id": "source-16b8fc9bea",
    "verifiedAt": "2026-07-14",
    "type": "Reproducible audit manifest",
    "public": true,
    "immutable": true,
    "internal": true,
    "host": "Review of Spark's trust model",
    "findings": [
      {
        "title": "Sparkscan exposes the hidden Spark identity behind Lightning payments",
        "slug": "sparkscan-exposes-the-hidden-spark-identity-behind-lightning-payments"
      },
      {
        "title": "One public participant is enough to expose the full Spark transfer",
        "slug": "one-public-participant-is-enough-to-expose-the-full-spark-transfer"
      },
      {
        "title": "Spark privacy does not cover a globally enumerable token ledger",
        "slug": "spark-privacy-does-not-cover-a-globally-enumerable-token-ledger"
      }
    ]
  },
  {
    "label": "Spark statechain key-deletion analysis",
    "url": "https://www.spark.money/research/statechains-bitcoin-scaling-deep-dive",
    "id": "source-d1faa47e2c",
    "verifiedAt": "2026-07-14",
    "type": "Web source",
    "public": true,
    "immutable": false,
    "host": "spark.money",
    "findings": [
      {
        "title": "Spark's forward security rests on an act of key deletion users cannot verify",
        "slug": "sparks-forward-security-rests-on-an-act-of-key-deletion-users-cannot-verify"
      },
      {
        "title": "Spark's published 2-of-3 setting means one honest Operator cannot veto two retained shares",
        "slug": "sparks-published-2-of-3-setting-means-one-honest-operator-cannot-veto-two-retained-shares"
      }
    ]
  },
  {
    "label": "published Lightspark-Flashnet advisory role",
    "url": "https://static1.squarespace.com/static/532383d3e4b00a718e33e1da/t/68261be1070c3c5a48155e3b/1747327969367/CV_Catalini_May_2025.pdf",
    "id": "source-444822d77f",
    "verifiedAt": "2026-07-14",
    "type": "Web source",
    "public": true,
    "immutable": false,
    "host": "static1.squarespace.com",
    "findings": [
      {
        "title": "Retained Lightspark and Flashnet keys could sign a conflicting spend of a Lightspark-funded Lightning leaf",
        "slug": "retained-lightspark-and-flashnet-keys-could-sign-a-conflicting-spend-of-a-lightspark-funded-lightning-leaf"
      }
    ]
  },
  {
    "label": "Wallet of Satoshi disclosure",
    "url": "https://walletofsatoshi.com/disclosure",
    "id": "source-3bb9cc3854",
    "verifiedAt": "2026-07-14",
    "type": "Web source",
    "public": true,
    "immutable": false,
    "host": "walletofsatoshi.com",
    "findings": [
      {
        "title": "No complete in-app operatorless exit was found in eight reviewed consumer-wallet products",
        "slug": "no-complete-in-app-operatorless-exit-was-found-in-eight-reviewed-consumer-wallet-products"
      },
      {
        "title": "Across Primal, Radar, Wallet of Satoshi, and Bringin, control claims were not matched by a demonstrated unilateral-exit path",
        "slug": "across-primal-radar-wallet-of-satoshi-and-bringin-control-claims-were-not-matched-by-a-demonstrated-unilateral-exit-path"
      }
    ]
  },
  {
    "label": "archived official Lightspark Chainalysis guide",
    "url": "https://web.archive.org/web/20241224151636/https://docs.lightspark.com/lightspark-sdk/developer-guides/reconciliation-error-handling-testing",
    "id": "source-9d1a1c6341",
    "verifiedAt": "2026-07-14",
    "type": "Archived web source",
    "public": true,
    "immutable": true,
    "host": "web.archive.org",
    "findings": [
      {
        "title": "Lightspark Connect exposes Chainalysis-backed sanctions screening of Lightning nodes",
        "slug": "lightspark-connect-exposes-chainalysis-backed-sanctions-screening-of-lightning-nodes"
      }
    ]
  }
]