fix: always update key images (#3310)
What changed, and why it matters
This commit changes a Monero wallet so it always refreshes its list of spendable coins before creating a transaction, instead of skipping the refresh when the list looked non-empty. The developer says this fixes a bug where a placeholder key image (a long string of zeros) would appear and cause transaction creation to fail. The commit also updates a dependency version for an unrelated build fix.
Treat as a routine bug-fix commit unless further review shows the zero key-image condition could be induced by an attacker or lead to loss of funds. Verify the new monero_c commit hash matches an official release and review its changelog for any security-relevant changes.
Security signals we found
Transaction creation failure triggered by stale/zero key images
Removal of a conditional that could use cached/out-of-date unspent coin data
Dependency bump to a newer monero_c commit without disclosed security content
Evidence from the diff
In cw_monero/lib/monero_wallet.dart, the code previously called updateUnspent() only when unspentCoins was empty. The patch removes that guard and always awaits updateUnspent() before building a transaction. The commit message links this to preventing the all-zero key image 0100…00 from appearing and throwing during tx creation. The second file updates the pinned monero_c commit hash in scripts/prepare_moneroc.sh to 5952bef2ec01b0b7e57c11613cbdc081dcd727c5, described as fixing an Ubuntu 26.04 arm64 build issue.
Changed components
cw_monero/lib/monero_wallet.dartscripts/prepare_moneroc.shInspect captured patch +2 / −4
diff --git a/cw_monero/lib/monero_wallet.dart b/cw_monero/lib/monero_wallet.dart
index 30c5507..95e02f9 100644
--- a/cw_monero/lib/monero_wallet.dart
+++ b/cw_monero/lib/monero_wallet.dart
@@ -435,9 +435,7 @@ abstract class MoneroWalletBase extends WalletBase<MoneroBalance,
throw MoneroTransactionCreationException('The wallet is not synced.');
}
- if (unspentCoins.isEmpty) {
- await updateUnspent();
- }
+ await updateUnspent();
for (final utx in unspentCoins) {
if (utx.isSending) {
diff --git a/scripts/prepare_moneroc.sh b/scripts/prepare_moneroc.sh
index d8caf00..8d0d6e5 100755
--- a/scripts/prepare_moneroc.sh
+++ b/scripts/prepare_moneroc.sh
@@ -16,7 +16,7 @@ fi
# NOTE: Make sure to update monero_c prebuilds link in workflow files
# https://github.com/MrCyjaneK/monero_c/releases/download/v0.18.4.6-RC2/release-bundle.zip
git fetch -a
-git checkout 0b324fe33ff5709feb69e2892767c1be9349957d
+git checkout 5952bef2ec01b0b7e57c11613cbdc081dcd727c5
git reset --hard
git submodule update --init --force --recursive
Why this scored 41/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.