AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 30 Monero

Set anti-fee-sniping locktime (exact-tip) on bitcoin sends (#3385)

Public commit record

What the developer wrote

Authored by Cindy

81/100 · Strong
Set anti-fee-sniping locktime (exact-tip) on bitcoin sends (#3385)

* Set anti-fee-sniping locktime on bitcoin sends

Current tip (exact-tip) via shared helper, wired into normal sends (path A) and payjoin/PSBT (path B). 0 when unsynced. Converges with the exact-tip cluster (payjoin-cli, ldk-node, Bull Bitcoin) and skips the ~10% backdate.

* Update cw_bitcoin/lib/locktime.dart

Co-authored-by: Konstantin Ullrich <konstantinullrich12@gmail.com>

* Update cw_bitcoin/lib/locktime.dart

Co-authored-by: Konstantin Ullrich <konstantinullrich12@gmail.com>

* Update cw_bitcoin/lib/locktime.dart [skip ci]

---------

Co-authored-by: Konstantin Ullrich <konstantinullrich12@gmail.com>
Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit changes how Cake Wallet sets the 'locktime' field on outgoing Bitcoin transactions. Previously, Cake Wallet apparently left this value at zero, which made its transactions stand out and easier to track. Now it sets the locktime to the current blockchain height when the wallet is synced, matching common behavior used by other Bitcoin wallets. This is a privacy improvement, not a fix for a vulnerability that lets someone steal funds directly.

Recommended action

Treat as a privacy-hardening improvement rather than an urgent security patch. Review whether the exact-tip approach is acceptable for the wallet's threat model, since it slightly differs from Bitcoin Core's randomized backdating. Ensure the getCurrentChainTip() source is trustworthy and that unsynced fallback to zero does not itself become a fingerprint.

Security signals we found

01

Privacy/fingerprinting reduction: removes unique nLockTime=0 wallet fingerprint

02

Anti-fee-sniping: aligns locktime with current chain tip

03

Defensive fallback: returns locktime 0 when not synced or tip unknown to avoid stale heights

04

No direct funds-loss vulnerability present in diff

Risk score

Why this scored 30/100

Our methodology →
Potential impact 5/30
Exploitability 3/25
Stealth signal 6/15
Affected reach 5/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.