fix: prevent off by one error in ensureMwebAddressUpToIndexExists (#3131)
What changed, and why it matters
This commit fixes an off-by-one error in a Litecoin wallet feature that ensures enough MWEB (privacy) addresses exist up to a requested index. The fix adds 1 to the requested index before generating addresses. Without the fix, the wallet might create one fewer MWEB address than needed, which could cause address lookup or balance detection issues for privacy transactions. There is no direct evidence in the commit of a security vulnerability or exploit.
Review the full implementation of ensureMwebAddressUpToIndexExists and the MWEB address cache to confirm the off-by-one fix is complete and that no derived gap-limit or address-indexing issues remain. Consider adding unit tests covering edge indices 0, 1, and N for MWEB address generation.
Security signals we found
Off-by-one error in address derivation/indexing
MWEB (Mimblewimble Extension Blocks) privacy address handling
Potential address gap or missing address causing balance/UTXO visibility issues
Evidence from the diff
In cw_bitcoin/lib/litecoin_wallet_addresses.dart, ensureMwebAddressUpToIndexExists now takes _index and immediately computes index = _index + 1. This corrects an off-by-one where the loop likely generated addresses from 0 to index-1 instead of 0 to index. The change is minimal (+2/-1) and only affects desktop platforms indirectly (the method returns early on Linux/macOS/Windows). The actual address generation logic is not shown in the diff, so the full scope of the bug is inferred.
Changed components
cw_bitcoin/lib/litecoin_wallet_addresses.dartLitecoin MWEB address generationensureMwebAddressUpToIndexExists methodInspect captured patch +2 / −1
diff --git a/cw_bitcoin/lib/litecoin_wallet_addresses.dart b/cw_bitcoin/lib/litecoin_wallet_addresses.dart
index 147281a7..737bd41f 100644
--- a/cw_bitcoin/lib/litecoin_wallet_addresses.dart
+++ b/cw_bitcoin/lib/litecoin_wallet_addresses.dart
@@ -73,7 +73,8 @@ abstract class LitecoinWalletAddressesBase extends ElectrumWalletAddresses with
return List.from(super.allAddresses)..addAll(mwebAddresses);
}
- Future<void> ensureMwebAddressUpToIndexExists(int index) async {
+ Future<void> ensureMwebAddressUpToIndexExists(int _index) async {
+ final index = _index + 1;
if (Platform.isLinux || Platform.isMacOS || Platform.isWindows) {
return null;
}
Why this scored 30/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.