AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
High 79 Monero

Add more guards to amounts being zero or infinity (#3612)

Public commit record

What the developer wrote

Authored by Omar Hatem

73/100 · Adequate
Add more guards to amounts being zero or infinity (#3612)

* Add more guards to amounts being zero or infinity

* Add more guards to amounts being zero or infinity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This update fixes a bug where entering special non-number values like 'Infinity' or 'NaN' as a crypto amount could slip past safety checks. Because the wallet treats an amount of zero as 'send everything' (sweep-all), a bad amount that collapsed to zero could unexpectedly drain the whole account. The patch adds stronger checks in the amount-parsing code and refuses to create transactions with zero or infinite amounts.

Recommended action

Treat this as a security fix and include it in the next release. Review other wallet modules (cw_wownero, cw_bitcoin, etc.) for similar amount parsing and sweep-all sentinel behavior. Ensure all user-facing amount inputs route through the hardened Money/parseFixed parsing path, and consider adding runtime assertions that transaction creation rejects zero/non-finite amounts.

Security signals we found

01

Non-finite double values (Infinity/NaN) accepted by double.tryParse bypass <= 0 amount guards

02

Collapsed non-finite amounts fall back to Money.zero, which stringifies to the sweep-all sentinel in Monero wallet2

03

New guards reject zero and non-finite amounts before transaction creation

04

Money/parseFixed layer now rejects non-finite inputs at the parsing stage

05

Fiat conversion helpers now check result.isFinite to avoid propagating Infinity/NaN

06

Send/swap confirmation sheets use sanitized/parsed Money objects instead of raw strings

07

Regression test added for non-finite amount spellings and sweep-all sentinel behavior

Risk score

Why this scored 79/100

Our methodology →
Potential impact 25/30
Exploitability 18/25
Stealth signal 12/15
Affected reach 12/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.