simplewallet: prompt for restore height when using generate-from-device
What changed, and why it matters
This change adjusts the Monero command-line wallet's setup flow when creating a wallet from a hardware device. Previously, if the user answered anything other than 'yes' to a confirmation prompt, wallet creation was aborted. Now, if the user answers 'no', wallet creation continues but the wallet is told not to start scanning the blockchain from a specific estimated height. This could cause the wallet to scan from the beginning of the chain, which may be slower and could potentially reveal more information about the user's transaction history than intended. It is a usability and privacy-related change rather than a direct exploit.
Review the default refresh_from_block_height behavior when explicit_refresh_from_block_height is false, especially in the generate-from-device path. Ensure that declining the restore-height prompt does not cause the wallet to scan from genesis or expose more transaction history than users expect. Consider adding clearer user-facing messaging when 'no' is selected.
Security signals we found
Behavioral change in user confirmation handling
Restore height no longer forced on non-yes responses
Potential privacy impact from default scan behavior when explicit height is unset
No input validation or bounds checking changes
Evidence from the diff
In simplewallet.cpp, the init() path for generate-from-device previously aborted on any non-‘yes’ response to the ‘Is this okay?’ prompt. The patch splits the logic: EOF still aborts, ‘yes’ continues with the existing behavior of setting refresh_from_block_height to estimate_blockchain_height()-1 and marking it explicit, and ‘no’ now continues while calling explicit_refresh_from_block_height(false). This means a non-affirmative user response no longer aborts account creation, but instead leaves the wallet without an explicit restore height. Depending on downstream defaults, this could result in scanning from genesis or from the wallet’s default creation height, affecting privacy and performance.
Changed components
src/simplewallet/simplewallet.cppgenerate-from-device wallet initialization flowrestore height / refresh_from_block_height handlingInspect captured patch +11 / −5
diff --git a/src/simplewallet/simplewallet.cpp b/src/simplewallet/simplewallet.cpp
index 69c66d0..5bad767 100644
--- a/src/simplewallet/simplewallet.cpp
+++ b/src/simplewallet/simplewallet.cpp
@@ -4297,12 +4297,18 @@ bool simple_wallet::init(const boost::program_options::variables_map& vm)
wrt << tr("Use --restore-height or --restore-date if you want to restore an already setup account from a specific height.");
}
std::string confirm = input_line(tr("Is this okay?"), true);
- if (std::cin.eof() || !command_line::is_yes(confirm))
- CHECK_AND_ASSERT_MES(false, false, tr("account creation aborted"));
+ if (std::cin.eof()) CHECK_AND_ASSERT_MES(false, false, tr("account creation aborted"));
- m_wallet->set_refresh_from_block_height(m_wallet->estimate_blockchain_height() > 0 ? m_wallet->estimate_blockchain_height() - 1 : 0);
- m_wallet->explicit_refresh_from_block_height(true);
- m_restore_height = m_wallet->get_refresh_from_block_height();
+ if (command_line::is_yes(confirm))
+ {
+ m_wallet->set_refresh_from_block_height(m_wallet->estimate_blockchain_height() > 0 ? m_wallet->estimate_blockchain_height() - 1 : 0);
+ m_wallet->explicit_refresh_from_block_height(true);
+ m_restore_height = m_wallet->get_refresh_from_block_height();
+ }
+ else
+ {
+ m_wallet->explicit_refresh_from_block_height(false);
+ }
}
}
else
Why this scored 25/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.