AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 26 Monero

fix: hide dust balance from "confirming" (#3456)

Public commit record

What the developer wrote

Authored by cyan

65/100 · Adequate
fix: hide dust balance from "confirming" (#3456)
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
The short version

What changed, and why it matters

This commit changes how Cake Wallet's Zcash wallet calculates and displays balances that are still 'confirming' or otherwise unavailable. It filters out tiny 'dust' notes from the unavailable balance, adjusts which note pools are considered spendable during the Zcash Ironwood network upgrade, and changes the bitmask used when building transactions. The main user-visible effect is that small unspendable notes no longer appear as 'confirming' balance, which could previously make users think they had funds that were not actually usable.

Recommended action

Review the new bitmask values (4/8) against the zkool library documentation to ensure they correctly map to Orchard/Ironwood and do not accidentally exclude legitimate spendable funds or include unintended pools. Verify that minSpendableNote and _ironwoodMigrateMinNote match the library's documented minimums. Consider adding unit tests for _sweepableTotal and _migratableOrchardTotal with dust, locked, and out-of-range note scenarios. No immediate security patch is indicated, but the change affects user trust in displayed balances.

Security signals we found

01

Balance display could previously overstate spendable/unconfirmed funds by including dust notes

02

Transaction source pool bitmask narrowed (7→4, 15→8), changing which note pools can fund payments

03

Auto-shield and migration now run before balance is recomputed, so displayed balance reflects post-migration state

04

New per-note minimum thresholds align auto-shield/migration guards with balance UI

Risk score

Why this scored 26/100

Our methodology →
Potential impact 4/30
Exploitability 2/25
Stealth signal 5/15
Affected reach 6/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.