What changed, and why it matters
This patch adds a safety check in Monero's wallet code when it asks the connected node (daemon) for a block hash to repair an empty local record of past blocks. Previously, if the daemon returned malformed or invalid data, the wallet would silently treat the conversion as successful and use an uninitialized or corrupted hash. Now the wallet explicitly checks whether the conversion succeeded and throws an error if it did not. This is a defensive hardening fix that prevents the wallet from accepting an invalid block hash during a recovery operation.
Treat as a low-to-moderate hardening fix. Review whether other hex_to_pod() calls in wallet2.cpp and related modules similarly ignore return values, and apply consistent validation. No immediate incident response is indicated absent evidence of active exploitation.
Security signals we found
Unchecked return value from string-to-hash conversion
Potential use of invalid/uninitialized hash in blockchain refill
Daemon-supplied input not validated before use
Defensive hardening in wallet synchronization path
Evidence from the diff
In wallet2::trim_hashchain(), when the local hashchain is empty, the wallet fetches the block header for the current chain height from the daemon and converts the returned hex hash string to a crypto::hash via epee::string_tools::hex_to_pod(). The original code ignored the boolean return value of hex_to_pod(), which returns false on failure. The patch wraps the call in THROW_WALLET_EXCEPTION_IF() so that a failed conversion raises a wallet_internal_error with the message “Daemon returned an invalid block hash”. This prevents the subsequent m_blockchain.refill(hash) from being called with a potentially default-initialized or partially written hash.
Changed components
src/wallet/wallet2.cppwallet2::trim_hashchain()hashchain repair / refill logicInspect captured patch +2 / −1
### src/wallet/wallet2.cpp
@@ -6942,7 +6942,8 @@ void wallet2::trim_hashchain()
if (m_node_rpc_proxy.get_block_header_by_height(m_blockchain.size() - 1, block_header))
throw std::runtime_error("Failed to request block header by height");
crypto::hash hash;
- epee::string_tools::hex_to_pod(block_header.hash, hash);
+ THROW_WALLET_EXCEPTION_IF(!epee::string_tools::hex_to_pod(block_header.hash, hash),
+ error::wallet_internal_error, "Daemon returned an invalid block hash");
m_blockchain.refill(hash);
}
catch(...)Why this scored 42/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.