Wallet Infrastructure Watch / Applications
In Brief
A public bug report alleges that Yours Wallet’s automatic seed-import sweep can consume BSV-21 token outputs as ordinary transaction funding, causing token balances to be lost.
The reported code path is present in the public v5.1.1 source. As of October 10, the issue remained open without a maintainer response.
News Report
GitHub issue #358, filed on October 9 by captainsvbot, documents a concern previously mentioned in BSV TIMES’ October 9 Builder Pulse: importing a recovery phrase can trigger an automatic transfer from an older wallet address.
The report concerns this automatic import behavior. It distinguishes the separate Tools → Migrate Legacy Assets interface, which it describes as using asset-aware migration logic.
What the Source Shows
BSV TIMES inspected Keys.service.ts at the v5.1.1 release tag.
When a mnemonic is supplied to the key-generation and storage function, the code calls sweepLegacy(). The call proceeds asynchronously, before the function finishes storing the imported wallet’s encrypted keys.
The sweep derives an address using the legacy path, asks an indexing service for its unspent outputs, and creates a transaction with one ordinary payment output directed to the imported wallet’s current address.
It then adds the returned outputs as inputs, signs the transaction and submits it.
The function contains no check that separates issued-token or ordinal outputs from ordinary payment outputs before adding them. Errors are logged to the console.
This means the import process includes transaction activity that users might not expect from simply restoring access to existing keys.
What the Transaction Evidence Shows
The issue supplies a mainnet transaction recorded in block 970,240 on October 8 UTC.
BSV TIMES checked that transaction through WhatsOnChain and BananaBlocks. It has 17 inputs and one ordinary P2PKH payment output. That output contains no token-transfer inscription.
Two of the spent source outputs were also inspected directly. Both carried BSV-21 transfer inscriptions and each held one satoshi of the BSV token.
These observations support the reported failure mechanism. They do not independently establish which application action produced the transaction or verify the report’s complete token-loss calculation.
Why Moving Satoshis Can Lose an Issued Token
The BSV-21 specification records issued-token balances in transaction outputs and requires transfers to create corresponding token outputs.
Its conservation rules treat an input token amount that is not carried into valid successor outputs as burned.
Consequently, moving the underlying satoshis into an ordinary payment output does not necessarily preserve the issued tokens represented by those outputs.
This is the distinction at the center of the report: a transaction can successfully move the BSV token while failing to preserve a separate asset recorded through BSV-21.
Current Status
At the October 10 check, issue #358 had no comments or linked corrective pull request. The latest published GitHub release remained v5.1.1.
The available evidence supports reporting a specific import-path risk. The reported incident and full extent of its impact still require maintainer investigation.
BSV TIMES Read
Wallet recovery involves more than reproducing keys.
A wallet also has to recognize what those keys control and preserve the rules attached to each asset when constructing transactions. An output’s small satoshi amount does not describe the full significance of the information it carries.
The practical question raised here is whether an automatic recovery operation understands those assets before moving them. Clear consent and preservation checks belong in that operation itself, particularly when importing a recovery phrase can initiate a broadcast.
Developer Context
Yours Wallet is developed in the public yours-org/yours-wallet repository. The project describes a non-custodial Chrome extension supporting BRC-100, 1Sat Ordinals and BSV-21 tokens.
Report submitted by: captainsvbot. The disclosure states that it was filed by an affected platform operator on behalf of a user.
Source Links
- Yours Wallet — Issue #358: seed-import auto-sweep report
- Yours Wallet — Keys.service.ts at v5.1.1
- Yours Wallet — v5.1.1 release
- BananaBlocks — Transaction cited in the report
- WhatsOnChain — First inspected source transaction
- WhatsOnChain — Second inspected source transaction
- 1Sat Ordinals — BSV-21 specification
- Yours Wallet — Project repository
- BSV TIMES — Builder Pulse, October 9, 2026
Posted on October 10, 2026

Leave a Reply