What changed, and why it matters
This is a small code fix in Monero's wallet that keeps the recorded breakdown of received amounts consistent when a transaction output is 'burnt' (replaced or spent as part of a transaction the wallet is processing). The change adds a check that throws an internal wallet error if the expected amount cannot be found in the wallet's tracking list, and updates the tracked value to the remaining 'extra' amount. The commit message does not describe this as a security fix, and there is no direct evidence in the diff or supplied references that this is exploitable by an attacker.
Treat as a routine correctness/consistency fix unless a security advisory or additional context links it to a reproducible wallet bug. Reviewers may want to examine whether inconsistent accounting before this patch could lead to incorrect balance display, failed transaction construction, or other user-visible wallet errors, and whether the exception path is safely handled.
Security signals we found
Defensive consistency check added (THROW_WALLET_EXCEPTION_IF)
Fixes internal accounting of received output amounts
No explicit security claim in commit or supplied references
No input validation or remote-attack surface visible in diff
Evidence from the diff
In wallet2::process_new_transaction(), when the wallet encounters an output it already knows about (a ‘burnt’ transfer), it now locates that output’s amount in tx_amounts_individual_outs and replaces it with the computed extra_amount (amount - burnt). A THROW_WALLET_EXCEPTION_IF guard is added to fail if the amount is missing. This prevents the per-output amount accounting from becoming inconsistent during transaction processing. The patch is defensive and partial-looking (only one code path is updated), so its security relevance is unclear without broader context.
Changed components
src/wallet/wallet2.cppwallet2::process_new_transaction()received amount tracking / tx_amounts_individual_outsInspect captured patch +7 / −0
### src/wallet/wallet2.cpp
@@ -2759,6 +2759,13 @@ void wallet2::process_new_transaction(const crypto::hash &txid, const cryptonote
uint64_t amount = tx.vout[o].amount ? tx.vout[o].amount : tx_scan_info[o].amount;
uint64_t burnt = m_transfers[kit->second].amount();
uint64_t extra_amount = amount - burnt;
+
+ amounts_container& tx_amounts_this_out = tx_amounts_individual_outs[tx_scan_info[o].received->index];
+ auto amount_iterator = std::find(tx_amounts_this_out.begin(), tx_amounts_this_out.end(), amount);
+ THROW_WALLET_EXCEPTION_IF(amount_iterator == tx_amounts_this_out.end(),
+ error::wallet_internal_error, "Unexpected values of new and old outputs");
+ *amount_iterator = extra_amount;
+
if (!pool)
{
transfer_details &td = m_transfers[kit->second];Why this scored 38/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.