XMR
← All projectsMonero Project

Monero GUI

Official graphical Monero wallet and its release-build integration.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

138 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

12security candidates46second-pass queue58AI analyses
34commits · 30 days
43commits · 60 days
110commits · 180 days
138commits · 365 days
Backfill bands
Sep 27 → Mar 3127 seen0 candidatesComplete
Mar 31 → Jul 2961 seen8 candidatesComplete
Jul 29 → Aug 287 seen2 candidatesComplete
Aug 28 → Sep 2715 seen1 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

49/100 average clarity
6Strong · 80–100
14Adequate · 60–79
101Thin · 40–59
17Opaque · 0–39
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Thomas636178
selsta81628048
tobtoht2328052
Cole Munz111073
SChernykh10010028
jpk68902046
plowsof403051
наб100081
munzzyy100083
reservedbytes100050
Balló György100068
Analysis record

Published AI watches

Last scanned 35 minutes ago

Moderate 59 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4645

This change fixes a bug in the Monero wallet setup wizard. Previously, when restoring or creating a wallet from seed/keys, the wallet was first saved with a blank or temporary password before the user's chosen password was applied. If appl…

Wallet file created with empty/blank password before user password is appliedFailure to set user password does not prevent wallet file from being savedSensitive on-disk artifact (wallet file) may be protected by weaker credentials than intended
d7c2f13dby tobtoht+14−93 files
No security note in commit
Informational 17 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4687

This commit updates the Monero GUI wallet's message-signing screen so that when a user verifies a signature, the app now reports extra details: whether the signature is valid, which key type was used (spend key, view key, or unknown), and …

UI-only change to signature verification feedbackNo modification to cryptographic verification logicNew method exposes already-existing signature metadata (key type, version, old algorithm flag)
485a102cby tobtoht+50−133 files
No security note in commit
Low 35 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4709

This change adjusts how the Monero GUI wallet stores and passes login credentials for remote daemon connections. Previously, daemon username/password and 'trusted daemon' status were kept as persistent properties on the wallet object and r…

Credential scoping/lifetime reductionRemoval of persistent daemon login state from wallet objectDefense against cross-connection credential reuse
a5c305deby tobtoht+7−63 files
No security note in commit
Informational 19 AI analysisMessage 59 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4693

This commit fixes a display bug in the Monero GUI wallet's transaction history. Previously, when sorting transactions by block height, failed transactions were incorrectly treated like pending ones and shown at the top of the list. The fix…

UI display logic correction for transaction state classificationTightened conditional for treating transactions as pendingNo memory safety, cryptographic, or authorization changes observed
baef8be9by tobtoht+14−52 files
No security note in commit
Informational 15 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4692

This commit is a user-interface improvement for the Monero GUI wallet's transaction history screen. It changes how outgoing payments with multiple recipients are displayed, searched, and copied. There is no security vulnerability here; it …

0f8a1cf4by tobtoht+84−185 files
No security note in commit
Moderate 58 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4690

This update fixes a timing bug in the Monero wallet's send screen. If a user quickly changed or cancelled a payment while a transaction was still being prepared in the background, the wallet could accidentally show or use the wrong transac…

Race condition between asynchronous transaction creation and UI state changesUse-after-free / dangling pointer risk from stale PendingTransaction objectsPotential wrong-transaction confirmation or commit due to stale async result
c72adf62by tobtoht+57−243 files
No security note in commit
Informational 21 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4665

This commit adds a feature that lets users scan a QR code to restore a Monero wallet from its secret keys. The change itself is a feature addition, not a fix for a known vulnerability. There is one minor security-relevant detail: the QR co…

New QR URI parser handles secret keys (secret_view_key, secret_spend_key) and restore heightAddress validation is performed before accepting parsed restore URIScheme changed from monero_wallet: to monero-wallet:
68327c0aby tobtoht+52−13 files
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

p2pool v4.18.1

This commit simply updates the Monero GUI wallet's built-in downloader to fetch a newer version of the bundled P2Pool mining software (from v4.18 to v4.18.1) and updates the matching file hashes. There is no indication in the commit itself…

8d95b8a4by SChernykh+12−121 file
No security note in commit
Low 34 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Wallet: keep daemon credentials scoped to each connection

This commit changes how the Monero GUI wallet stores and uses login credentials for remote nodes (servers that help the wallet talk to the Monero network). Previously, the wallet kept daemon username/password as persistent wallet-level set…

Credential scoping change: daemon username/password no longer stored as persistent wallet state for connection reuseRemoval of setDaemonLogin() call from QML remote-node selection pathDaemon credentials now captured per-init and passed directly to underlying wallet implementation
10b08b3bby selsta+7−63 files
No security note in commit
Informational 19 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

TransactionHistoryModel: only place pending tx first

This commit fixes a display bug in the Monero GUI wallet's transaction history list. Previously, failed transactions were being shown at the top of the list alongside pending transactions, because any transaction without a confirmed block …

UI presentation bug, not a memory-safety or cryptographic issueNo attacker-controlled input parsing changedNo privilege escalation, authentication, or authorization logic modified
27328f36by selsta+6−51 file
No security note in commit
Informational 15 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

History: improve display of transactions with multiple recipients

This commit is a user-interface improvement for the Monero GUI wallet's transaction history screen. It changes how outgoing payments to multiple recipients are displayed, searched, and copied. There is no security vulnerability here; it is…

a3dc3882by selsta+84−185 files
No security note in commit
Low 42 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Wallet: fix send confirmation stale transaction race

This patch fixes a race condition in the Monero GUI wallet's send screen. If a user quickly changed send details or canceled a transaction while an earlier transaction was still being prepared in the background, the wallet could mix up the…

Race condition between asynchronous transaction creation and UI state changesPotential use of stale PendingTransaction object after cancellation/replacementMemory leak via undisposed PendingTransaction objects on rejection paths
3f2d9794by selsta+57−243 files
No security note in commit
Informational 15 AI analysisMessage 35 · Opaque
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

workflows: fix Windows build

This is a routine GitHub Actions CI fix for the Windows build. It adds the 'rust:p' package to the list of MSYS2 packages installed during the build. There is no security-relevant change visible in the diff.

dc9f980bby selsta+1−11 file
No security note in commit
Moderate 59 AI analysisMessage 45 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

updater: use proxy for signed hash downloads

This change fixes a privacy leak in the Monero GUI wallet's update checker. Previously, when the wallet checked for updates and downloaded the signed list of official file hashes, it did not route that request through the user's configured…

Privacy leak: update metadata fetch bypassed user-configured proxyProxy setting now propagated to signed hash download pathPotential deanonymization of users who rely on proxy for network privacy
5e5ea68fby selsta+19−67 files
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

p2pool v4.18

This commit simply updates the Monero GUI's built-in downloader to fetch a newer version (4.18) of the bundled P2Pool mining software. It changes download URLs and the expected file hashes to match the new release. There is no indication o…

ddd080e3by SChernykh+12−121 file
No security note in commit
Moderate 58 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Transfer: disable offline signing for hardware wallets

This commit removes the 'Sign (offline)' button for hardware wallets in the Monero GUI wallet. The change prevents users from attempting an unsupported operation that could lead to failed or unsafe transactions when using a Ledger/Trezor-l…

UI control disabled for hardware-wallet-backed walletsReported by external party (zkao / zkSecurity)Prevents use of an operation likely unsupported by hardware wallet signing flow
66fab82cby selsta+1−11 file
No security note in commit
Informational 15 AI analysisMessage 45 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

wizard: simplify restore QR scanner layout

This commit is a straightforward user-interface cleanup in the Monero wallet restore wizard. It replaces a third radio-button option ('Restore from QR Code') with a dedicated QR scan button, simplifying the layout. There is no security-rel…

88324856by selsta+14−151 file
No security note in commit
Low 27 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

wizard: support key-based monero-wallet restore QR codes

This commit adds a feature to the Monero GUI wallet that lets users scan a QR code to restore a wallet from its secret keys. The change itself is a feature addition, not a direct security fix. However, it handles extremely sensitive data (…

Parsing of URI-encoded secret key material from QR codesManual URI/query-string parsing instead of using a hardened parserUse of decodeURIComponent on untrusted QR code data
a33f2421by selsta+52−13 files
No security note in commit
Informational 23 AI analysisMessage 68 · Adequate
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

wizard: fix restore from QR code

This commit fixes a broken feature in the Monero wallet's setup wizard that restores a wallet by scanning a QR code. The feature had been completely non-functional since a prior redesign because the code that processes the scanned QR code …

No security-relevant signals in the diff or commit messageFixes a broken user-facing feature (restore from QR code)Adds null-safety for extra_parameters to prevent crashes on bare-address QR codes
fbe4c084by Thomas+18−252 files
No security note in commit
Informational 15 AI analysisMessage 55 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

tests: add QML wallet wizard coverage

This commit adds automated user-interface tests for the Monero wallet setup wizard. It does not change how real users create or open wallets; it only adds test code and exposes a few internal UI control names so the tests can interact with…

0eef8dacby selsta+686−217 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queuedMerge pull request #4645by tobtoht · d7c2f13d · Oct 2, 2026 · 3 filesMessage 51 · ThinModerate 59Details
Commit message · tobtoht

Merge pull request #4645

dabf417 WizardController: abort saving the wallet if setPassword fails (plowsof)

ACKs: selsta

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Moderate 59/100

This change fixes a bug in the Monero wallet setup wizard. Previously, when restoring or creating a wallet from seed/keys, the wallet was first saved with a blank or temporary password before the user's chosen password was applied. If applying the real password failed, the wallet file could remain on disk with a weak or empty password. The patch makes the wallet creation functions accept the intended password directly, and aborts the save if the password cannot be set.

AI review queuedMerge pull request #4687by tobtoht · 485a102c · Oct 2, 2026 · 3 filesMessage 51 · ThinInformational 17Details
Commit message · tobtoht

Merge pull request #4687

523a905 Sign: show signed message key type (selsta)

ACKs: jpk68

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Informational 17/100

This commit updates the Monero GUI wallet's message-signing screen so that when a user verifies a signature, the app now reports extra details: whether the signature is valid, which key type was used (spend key, view key, or unknown), and whether it uses an older signing algorithm. It is a user-interface improvement to reduce confusion, not a fix for a vulnerability.

Lower-priorityMerge pull request #4724by tobtoht · 785d78f0 · Oct 2, 2026 · 4 filesMessage 51 · ThinTriage 0Details
Commit message · tobtoht

Merge pull request #4724

5decc23 build: prepare v0.18.5.3 (selsta)

ACKs: plowsof, tobtoht

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
merge-commit duplicate discount
Lower-prioritybuild: prepare v0.18.5.3by selsta · 5decc237 · Oct 2, 2026 · 4 filesMessage 50 · ThinTriage 0Details
Commit message · selsta

build: prepare v0.18.5.3

50/100 · ThinMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Lower-priorityMerge pull request #4721by tobtoht · 7a98f2e8 · Oct 2, 2026 · 1 fileMessage 51 · ThinTriage 0Details
Commit message · tobtoht

Merge pull request #4721

ba8ad72 History: derive default date range from transaction dates (selsta)

ACKs: jpk68, plowsof

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
merge-commit duplicate discount
Lower-priorityMerge pull request #4720by tobtoht · 4c16a4a3 · Oct 2, 2026 · 1 fileMessage 51 · ThinTriage 0Details
Commit message · tobtoht

Merge pull request #4720

551423e main: reset canceled transaction state before reusing dialog (selsta)

ACKs: jpk68, plowsof

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
merge-commit duplicate discount
Lower-prioritymain: reset canceled transaction state before reusing dialogby selsta · 551423e8 · Oct 2, 2026 · 1 fileMessage 50 · ThinTriage 0Details
Commit message · selsta

main: reset canceled transaction state before reusing dialog

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-priorityHistory: derive default date range from transaction datesby selsta · ba8ad728 · Oct 2, 2026 · 1 fileMessage 50 · ThinTriage 0Details
Commit message · selsta

History: derive default date range from transaction dates

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-priorityMerge pull request #4719by tobtoht · 5bd59432 · Oct 2, 2026 · 1 fileMessage 51 · ThinTriage 0Details
Commit message · tobtoht

Merge pull request #4719

05b076f main: display reserve proof amounts in XMR (selsta)

ACKs: jpk68, SNeedlewoods

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
merge-commit duplicate discount
Lower-priorityMerge pull request #4717by tobtoht · 2018adc4 · Oct 2, 2026 · 1 fileMessage 51 · ThinTriage 0Details
Commit message · tobtoht

Merge pull request #4717

d243cef docker: remove obsolete Android SDK tools package (selsta)

ACKs: jpk68

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
merge-commit duplicate discount
Lower-priorityMerge pull request #4714by tobtoht · 9bb84ce5 · Oct 2, 2026 · 3 filesMessage 51 · ThinTriage 0Details
Commit message · tobtoht

Merge pull request #4714

faa631f main: add more fiat currency options, rework api logic (jpk68)

ACKs: SChernykh*, selsta, plowsof

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
merge-commit duplicate discount
Lower-prioritymain: display reserve proof amounts in XMRby selsta · 05b076f7 · Oct 1, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · selsta

main: display reserve proof amounts in XMR

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-prioritydocker: remove obsolete Android SDK tools packageby selsta · d243cefc · Sep 23, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · selsta

docker: remove obsolete Android SDK tools package

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-priorityMerge pull request #4715by tobtoht · 01d6640a · Sep 23, 2026 · 1 fileMessage 51 · ThinTriage 0Details
Commit message · tobtoht

Merge pull request #4715

8d95b8a p2pool v4.18.1 (SChernykh)

ACKs: jpk68, selsta

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
merge-commit duplicate discount
Lower-priorityMerge pull request #4711by tobtoht · 6bd307b1 · Sep 23, 2026 · 2 filesMessage 51 · ThinTriage 0Details
Commit message · tobtoht

Merge pull request #4711

d6f381a openpgp: reject unsupported hash algorithms (selsta)

ACKs: jpk68, PyXMR2025

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
merge-commit duplicate discount
Lower-priorityMerge pull request #4710by tobtoht · 221b4435 · Sep 23, 2026 · 1 fileMessage 51 · ThinTriage 0Details
Commit message · tobtoht

Merge pull request #4710

7ac859d main: fix localhost proxy bypass (selsta)

ACKs: jpk68, PyXMR2025

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
merge-commit duplicate discount
Security candidateMerge pull request #4709by tobtoht · a5c305de · Sep 23, 2026 · 3 filesMessage 51 · ThinLow 35Details
Commit message · tobtoht

Merge pull request #4709

10b08b3 Wallet: keep daemon credentials scoped to each connection (selsta)

ACKs: jpk68, plowsof, PyXMR2025

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
credential or privilege statesigning or wallet pathmerge-commit duplicate discount
AI analysis · Low 35/100

This change adjusts how the Monero GUI wallet stores and passes login credentials for remote daemon connections. Previously, daemon username/password and 'trusted daemon' status were kept as persistent properties on the wallet object and reused across connections. The patch scopes those credentials to each individual connection instead, passing them as parameters when initializing a connection rather than storing them on the wallet. This reduces the risk that credentials or trust settings from one remote node could accidentally be reused for a different node later.

Lower-priorityMerge pull request #4707by tobtoht · f24187c2 · Sep 23, 2026 · 1 fileMessage 51 · ThinTriage 0Details
Commit message · tobtoht

Merge pull request #4707

fb49a8b main: enforce SOCKS5 for GUI proxy connections (selsta)

ACKs: jpk68, plowsof, PyXMR2025

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
merge-commit duplicate discount
Lower-priorityMerge pull request #4699by tobtoht · df29db71 · Sep 23, 2026 · 1 fileMessage 51 · ThinTriage 0Details
Commit message · tobtoht

Merge pull request #4699

6bf2165 DatePicker: improve contrast for the current day (selsta)

ACKs: jpk68

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
merge-commit duplicate discount
Lower-priorityMerge pull request #4698by tobtoht · 864a1617 · Sep 23, 2026 · 1 fileMessage 51 · ThinTriage 0Details
Commit message · tobtoht

Merge pull request #4698

9f03cc4 DatePicker: close calendar popup with esc (selsta)

ACKs: jpk68

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
merge-commit duplicate discount
Lower-priorityMerge pull request #4697by tobtoht · 14c26c4d · Sep 23, 2026 · 4 filesMessage 61 · AdequateTriage 0Details
Commit message · tobtoht

Merge pull request #4697

6a773e0 tests: make QML test harness opt-in (selsta)

ACKs: jpk68, plowsof

61/100 · AdequateMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
merge-commit duplicate discount
AI review queuedMerge pull request #4693by tobtoht · baef8be9 · Sep 23, 2026 · 2 filesMessage 59 · ThinInformational 19Details
Commit message · tobtoht

Merge pull request #4693

c6647c9 History: fix sorting of multiple pending transactions (selsta)
27328f3 TransactionHistoryModel: only place pending tx first (selsta)

ACKs: plowsof, jpk68

59/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit fixes a display bug in the Monero GUI wallet's transaction history. Previously, when sorting transactions by block height, failed transactions were incorrectly treated like pending ones and shown at the top of the list. The fix ensures only genuinely pending (unconfirmed) transactions float to the top, while failed transactions are sorted by their actual block height like normal. There is no direct evidence this is a security vulnerability—it's primarily a user-experience and accuracy fix.

AI review queuedMerge pull request #4692by tobtoht · 0f8a1cf4 · Sep 23, 2026 · 5 filesMessage 51 · ThinInformational 15Details
Commit message · tobtoht

Merge pull request #4692

a3dc388 History: improve display of transactions with multiple recipients (selsta)

ACKs: plowsof, jpk68

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a user-interface improvement for the Monero GUI wallet's transaction history screen. It changes how outgoing payments with multiple recipients are displayed, searched, and copied. There is no security vulnerability here; it is a routine feature enhancement.

AI review queuedMerge pull request #4690by tobtoht · c72adf62 · Sep 23, 2026 · 3 filesMessage 51 · ThinModerate 58Details
Commit message · tobtoht

Merge pull request #4690

3f2d979 Wallet: fix send confirmation stale transaction race (selsta)

ACKs: plowsof, jpk68

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Moderate 58/100

This update fixes a timing bug in the Monero wallet's send screen. If a user quickly changed or cancelled a payment while a transaction was still being prepared in the background, the wallet could accidentally show or use the wrong transaction details. The fix adds request IDs so the app can tell old, stale transactions apart from the current one and safely discard them. It also cleans up transaction objects when the user rejects a payment, preventing possible crashes or memory waste.

AI review queuedMerge pull request #4665by tobtoht · 68327c0a · Sep 23, 2026 · 3 filesMessage 51 · ThinInformational 21Details
Commit message · tobtoht

Merge pull request #4665

a33f242 wizard: support key-based monero-wallet restore QR codes (selsta)

ACKs: jpk68

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Informational 21/100

This commit adds a feature that lets users scan a QR code to restore a Monero wallet from its secret keys. The change itself is a feature addition, not a fix for a known vulnerability. There is one minor security-relevant detail: the QR code URI scheme was changed from 'monero_wallet:' to 'monero-wallet:' and a new parser was added. The code validates the wallet address before accepting the QR data, which is good. However, the new parser does not validate the secret view/spend keys or restore height values, so a malformed QR code could at worst cause the restore wizard to receive invalid key strings. There is no evidence in the commit of a disclosed security bug, an exploit, or an attacker-controlled code path.