AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 52 Monero

Enforce passphrase confirmation match on the restore and create wallet flows (#3474)

Public commit record

What the developer wrote

Authored by claude[bot]

81/100 · Strong
Enforce passphrase confirmation match on the restore and create wallet flows (#3474)

* fix: enforce passphrase confirmation in restore passphrase bottom sheet

The confirm-passphrase field in AddPassphraseBottomSheet already had a
validator comparing it to the first field, but the fields were not inside
a Form and nothing ever called validate(), so the validator never ran.
Tapping "Restore" restored the wallet with the first field's value even
when the confirmation did not match, defeating the typo check.

Wrap both fields in a Form and validate it before completing the restore,
matching the existing pattern in advanced_privacy_settings_page.dart.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019DtLNfYw1H81p7zZrkNDXM

* Validate passphrase confirmation when the passphrase field is empty

---------

Co-authored-by: Claude <noreply@anthropic.com>
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit fixes a bug in the wallet restore and creation screens where the 'confirm passphrase' field was not actually being checked. A user could type one passphrase and a different confirmation, yet still proceed. The wallet would then be created or restored using only the first passphrase, which could lock users out of their funds if they made a typo. The fix wraps the fields in a proper form and validates the confirmation before continuing.

Recommended action

Treat this as a security-relevant correctness fix and include it in the next release. No immediate incident response is required, but consider auditing other forms in the app for similar validators that are never invoked.

Security signals we found

01

Missing form validation bypassed confirmation-field check

02

User could restore/create wallet with mismatched passphrase confirmation

03

Risk of user locking themselves out of wallet due to undetected typo

04

Fix aligns restore flow with existing advanced privacy settings pattern

Risk score

Why this scored 52/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 10/15
Affected reach 10/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.