AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 46 Cryptographic libraries

wallet2: reject duplicate outputs in reserve proofs

Public commit record

What the developer wrote

Authored by selsta

50/100 · Thin
wallet2: reject duplicate outputs in reserve proofs
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This change adds a safety check in Monero's wallet code when verifying a 'reserve proof'—a cryptographic receipt that proves someone owns enough funds. Before this fix, a maliciously crafted proof could include the same output or key image more than once. The patch now rejects such duplicate entries. This likely prevents a proof from being counted multiple times or from confusing the verification logic, which could otherwise make someone appear richer than they really are.

Recommended action

Treat as a low-to-moderate security hardening fix. Review whether reserve proof generation (get_reserve_proof) can emit duplicates and whether other proof-verification paths need equivalent deduplication. Backport to maintained release branches. No immediate emergency response is indicated, but a security advisory or release note mentioning the hardening would be appropriate.

Security signals we found

01

Input validation hardening: duplicate entries in parsed proof data are now rejected

02

Potential proof-of-funds inflation: duplicate outputs/key images could previously be counted multiple times or bypass uniqueness assumptions in downstream verification

03

No explicit CVE, advisory, or security disclosure referenced in commit metadata

04

Patch is partial/one-sided: it adds a guard but does not show whether other proof types or callers had similar issues

Risk score

Why this scored 46/100

Our methodology →
Potential impact 12/30
Exploitability 10/25
Stealth signal 8/15
Affected reach 7/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.