AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 34 Monero

if input transactions are not all fetched correctly or had a failure,… (#3353)

Public commit record

What the developer wrote

Authored by Omar Hatem

81/100 · Strong
if input transactions are not all fetched correctly or had a failure,… (#3353)

* if input transactions are not all fetched correctly or had a failure, still parse the transaction correctly instead of skipping it

* handle nullable tx fee

* show warning for BTC txs with missing inputs

---------

Co-authored-by: Serhii <17529954+serhii-bor@users.noreply.github.com>
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit changes how Cake Wallet handles Bitcoin transactions when it cannot fetch all of their 'input' transaction data from the Electrum server. Previously, such transactions were skipped entirely and not shown in the wallet. Now they are still parsed and displayed, but with a warning ('Transaction has missing data') and a null fee. The change also makes the list of input transactions nullable and adds null checks in fee-calculation and replace-by-fee code paths, throwing errors if input data is missing there. This is primarily a robustness/usability fix, but it touches transaction parsing and fee logic, which are security-sensitive areas.

Recommended action

Review the null-handling paths to ensure no arithmetic or UI path can be tricked by a crafted transaction with missing inputs. Verify that the new hasMissingInputTx flag cannot be spoofed by a malicious Electrum server response. Consider adding tests for transactions with missing inputs and for the corrected getTransactionHex hash parameter.

Security signals we found

01

Transaction parsing now tolerates missing input data, which could affect balance/amount/fee calculations if bounds checks are insufficient.

02

New bounds check added: input.txIndex >= inputTransaction.outputs.length prevents an out-of-range access when an input transaction is present but malformed/short.

03

Fee is set to null when inputs are missing, preventing a potentially incorrect fee computed from partial input amounts.

04

Replace-by-fee and fee-calculation paths now throw on missing inputs rather than silently using null.

05

A real bug fix: input transaction hex fetch previously used the wrong txid (original hash instead of vin.txId), which could cause input lookup failures.

06

No explicit security disclosure, CVE, or researcher attribution in commit or supplied references.

Risk score

Why this scored 34/100

Our methodology →
Potential impact 8/30
Exploitability 4/25
Stealth signal 6/15
Affected reach 7/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.