AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 46 Monero

Cw 1117 prevent sending a transaction twice by mistake (#2567)

Public commit record

What the developer wrote

Authored by Serhii

81/100 · Strong
Cw 1117 prevent sending a transaction twice by mistake (#2567)

* Revert "Prevent double send actions in SendPage (#2542)"

This reverts commit dd4c941d2f356d7c4f2d39e9744ab43bbe1962c7.

* disable send buttons when ExecutedSuccessfully

* return value on bottom sheet pop [skip ci]
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This update fixes a user-interface bug where someone could accidentally trigger a cryptocurrency send twice in a row, for example by double-tapping a button. The app now disables the send button once a transaction has been successfully prepared, and it properly cancels the prepared transaction if the confirmation bottom sheet is closed without sliding to confirm. This reduces the chance of sending funds twice or leaving a half-prepared transaction open.

Recommended action

Treat as a functional reliability fix rather than a critical security vulnerability. Review whether any other send flows still rely on local flags or lack `ExecutedSuccessfullyState` disabling, and verify that `dismissTransaction()` correctly resets all relevant view-model state.

Security signals we found

01

UI-level double-submit prevention

02

State-driven button disabling after successful transaction preparation

03

Bottom-sheet dismissal now clears prepared transaction state

04

Reverts earlier client-side flag guard in favor of view-model state

Risk score

Why this scored 46/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 5/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.