AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 35 Monero

Remove replaced electrum transactions (#2738)

Public commit record

What the developer wrote

Authored by malik1004x

68/100 · Adequate
Remove replaced electrum transactions (#2738)

* fix: remove replaced btc transactions

* fix: remove replaced btc transactions

* remove debug print
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit changes how Cake Wallet's Bitcoin wallet handles transaction history from Electrum servers. When refreshing balances, it now deletes any stored Bitcoin transactions that send to the wallet's address but are no longer returned by the Electrum server. The stated goal is to remove transactions that were replaced or invalidated, such as RBF (Replace-By-Fee) replacements. This is a data-cleanup fix, but it could affect what transactions the user sees and what the wallet believes is spendable.

Recommended action

Review whether relying solely on Electrum server history to delete local transactions is safe. Consider adding checks for transaction age, confirmation depth, or local user intent before deletion. Ensure the change does not hide legitimate unconfirmed transactions when Electrum servers are slow, pruned, or malicious. Test RBF and reorg scenarios. If this addresses a reported bug, document the issue and any coordinated disclosure.

Security signals we found

01

Transaction history desynchronization between local wallet state and Electrum server

02

Potential removal of valid but unconfirmed transactions if server omits them

03

RBF/replacement transaction handling gap

04

Server-trusting logic: local state is altered based solely on Electrum server response

05

No explicit safeguards against malicious or faulty Electrum server omitting transactions

Risk score

Why this scored 35/100

Our methodology →
Potential impact 8/30
Exploitability 5/25
Stealth signal 6/15
Affected reach 7/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.