AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 62 Monero

fix: validate EVM restore mnemonic checksum (#3498)

Public commit record

What the developer wrote

Authored by Seth For Privacy

100/100 · Strong
fix: validate EVM restore mnemonic checksum (#3498)

* fix: validate EVM restore mnemonics

* chore: drop test changes from this PR

Removes the test additions/modifications introduced by this branch so the
test design is left to the maintainers. Production code is unchanged.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit adds a missing safety check when users restore an Ethereum-compatible (EVM) wallet from a seed phrase. Before the fix, the app accepted any 12 or 24 words that looked like a mnemonic, even if the words were wrong or the checksum was invalid. That could let a user create a wallet from a typo-ridden seed and later be unable to access their funds. The fix validates the seed phrase's checksum before restoring, and shows a clear error if it is invalid.

Recommended action

Verify that the bip39.validateMnemonic() call covers all supported EVM wallet types and languages, and that the error messages are surfaced correctly to users. Consider adding unit tests for invalid checksums, wrong word counts, and non-BIP39 words. Review whether non-EVM restore paths (e.g., Monero, Bitcoin) need similar checksum validation.

Security signals we found

01

Missing input validation on mnemonic seed phrases

02

BIP-39 checksum validation added to restore path

03

New exception type for invalid EVM mnemonic format

04

QR-code restore path now validates EVM mnemonics

05

Potential for user funds lockout due to undetected seed typos

Risk score

Why this scored 62/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 12/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.