AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 65 Cryptographic libraries

ringct: make h2d fallible

Public commit record

What the developer wrote

Authored by jeffro256

58/100 · Thin
ringct: make h2d fallible

One theoretically could have crafted a "long amount" (pre-v10) RingCT transaction
with non-0 padding bytes in the decoded amount which fails receiver scanning, but
passes third-party wallet proof checking.
✓ Descriptive subject✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This Monero patch fixes a RingCT amount-decoding function that previously ignored extra bytes beyond the first 8 in a 32-byte amount field. A pre-v10 'long amount' transaction could hide non-zero padding after the real amount. The receiver's wallet would fail to decode it, but a third-party wallet checking a proof might accept it, creating a mismatch between what the sender proves and what the recipient can actually spend. The change makes the decoder reject such malformed amounts.

Recommended action

Treat as a security fix. Review whether pre-v10 long-amount transaction validation on the network already rejects such padding, or whether a consensus/validation rule is also needed in addition to this wallet-level decoder change. Backport to maintained branches if applicable and consider a security advisory.

Security signals we found

01

Amount-decoding function silently ignored 24 bytes of input

02

Patch makes decoder reject non-zero high bytes

03

Commit message describes crafted transaction that can fool third-party proof verification

04

Receiver scanning failure vs. third-party proof success implies proof/verification inconsistency

05

Pre-v10 RingCT long-amount format is the affected transaction type

Risk score

Why this scored 65/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 13/15
Affected reach 10/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.