simplewallet: show error for timed-out hardware wallets
What changed, and why it matters
This change improves the user experience when unlocking a Monero wallet that is paired with a hardware wallet (like Ledger or Trezor). Previously, if the hardware wallet timed out or disconnected during unlock, the software would silently loop back to the password prompt without explaining why. Now it prints a clear error message telling the user to check that the hardware wallet is connected and unlocked. This is a minor reliability/usability fix, not a fix for a serious security vulnerability.
No urgent action required. Treat as a routine quality-of-life improvement. If reviewing, verify that the new catch block does not leak sensitive information through e.what() and that the existing catch-all (...) behavior is intentional. Consider whether the generic catch-all should also log or report rather than silently swallow exceptions.
Security signals we found
Error-message improvement for hardware-wallet unlock failures
No change to authentication, authorization, or cryptographic logic
Pre-existing catch-all (...) still swallows unknown exceptions
Potential minor UX security benefit: users less likely to retry passwords blindly when HW wallet is the actual problem
Evidence from the diff
In simplewallet.cpp’s check_for_inactivity_lock(), a catch block for std::exception was added around the unlock loop. When unlocking throws (e.g., from a hardware wallet timeout/disconnect), it now writes a failure message via fail_msg_writer() and, if keys are stored on a device (key_on_device()), instructs the user to ensure the hardware wallet is connected and unlocked. The pre-existing catch-all (…) remains to handle any other exceptions silently. The patch only adds error reporting; it does not change authentication logic, cryptography, or access control.
Changed components
src/simplewallet/simplewallet.cppsimple_wallet::check_for_inactivity_lock()Hardware wallet unlock flowInspect captured patch +11 / −0
diff --git a/src/simplewallet/simplewallet.cpp b/src/simplewallet/simplewallet.cpp
index a78c233..ef604d9 100644
--- a/src/simplewallet/simplewallet.cpp
+++ b/src/simplewallet/simplewallet.cpp
@@ -6276,6 +6276,17 @@ void simple_wallet::check_for_inactivity_lock(bool user)
break;
}
}
+ catch (const std::exception &e)
+ {
+ // Report why unlocking failed, rather than just looping back to the password prompt
+ auto writer = fail_msg_writer();
+ if (show_wallet_name)
+ writer << tr("Failed to unlock wallet: ") << e.what();
+ else
+ writer << tr("Failed to unlock wallet.");
+ if (m_wallet->key_on_device())
+ writer << "\n" << tr("Please ensure the HW wallet is connected and unlocked.");
+ }
catch (...) { /* do nothing, just let the loop loop */ }
}
m_last_activity_time = time(NULL);
Why this scored 22/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.