AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 48 Monero

Update RBF nsequence to 0xFFFFFFFD (#3077)

Public commit record

What the developer wrote

Authored by Armin Sabouri

76/100 · Adequate
Update RBF nsequence to 0xFFFFFFFD (#3077)

Technically `0x1` will signal opt-in RBF (since 0x1 ≤ 0xFFFFFFFD); however it also sets a relative timelock of 1 block. This seems like an unintended bug. It also fingerprints cake wallet since `0x1` is an abnormal value. This is especially harmful in collaborative settings e.g payjoin. Most wallets set `nsequence = 0xFFFFFFFD` to opt into RBF or just use full rbf which seems to be gaining more adoption.
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

Cake Wallet was setting a Bitcoin transaction value (called nSequence) to 1 when enabling Replace-By-Fee (RBF). The value 1 does technically opt into RBF, but it also tells the network the transaction cannot be mined until 1 block has passed, which is a relative timelock. This is likely unintended, makes Cake Wallet transactions stand out as unusual, and can cause problems in collaborative transactions like PayJoin. The fix changes the value to 0xFFFFFFFD, the standard value wallets use for RBF.

Recommended action

Review whether any in-flight or historical transactions used nSequence=0x1 and assess if the unintended 1-block relative timelock caused stuck transactions or fingerprinting exposure. Consider adding a test to assert nSequence values for RBF and non-RBF paths.

Security signals we found

01

Unintended relative timelock on RBF transactions

02

Wallet fingerprinting via non-standard nSequence value

03

Potential breakage or privacy degradation in collaborative transactions (e.g., PayJoin)

04

Fix aligns with standard wallet behavior

Risk score

Why this scored 48/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 10/15
Affected reach 7/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.