AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 59 Monero

fix: sanitize Electrum fee estimates (#3499)

Public commit record

What the developer wrote

Authored by Seth For Privacy

98/100 · Strong
fix: sanitize Electrum fee estimates (#3499)

* fix: sanitize Electrum fee estimates

* chore: drop test changes from this PR

Removes the test additions/modifications introduced by this branch so the
test design is left to the maintainers. Production code is unchanged.
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit hardens how Cake Wallet handles Bitcoin fee estimates from Electrum servers. Previously, a malicious or misbehaving Electrum server could return extreme or negative fee numbers, which could lead to users paying far too much, far too little, or creating invalid transactions. The patch now clamps fee rates between 0 and 2000 sat/vB, rejects all-zero fee lists, and refuses to build transactions when the computed fee is zero or negative. Most of the rest of the diff is just code formatting cleanup.

Recommended action

Treat this as a defensive hardening fix. Review whether the 2000 sat/vB cap is appropriate for all supported networks and fee markets, and consider adding unit tests for the sanitizer and `_isValidFeeRates()` behavior. The commit message notes tests were intentionally dropped from this PR.

Security signals we found

01

Untrusted Electrum server input is now bounded and validated before use in fee selection

02

Negative or zero fee rates are rejected, reducing risk of fee-underpayment or invalid transactions

03

Excessive fee rates are capped, limiting maximum overpayment from malicious server responses

04

Transaction creation now fails on non-positive fees rather than only on exactly-zero fees

Risk score

Why this scored 59/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.