What changed, and why it matters
This tiny change adjusts how the Monero wallet treats old-style unencrypted payment IDs when it cannot determine the block version of the transaction. Previously, if the block version was unknown (reported as 0), the wallet would still process the long payment ID. Now it ignores it, matching the intended privacy-preserving behavior for modern blocks. The risk is reduced privacy or accidental information leakage in edge cases, not theft of funds.
No urgent action required. Users and integrators should ensure they are running a version that includes this merge and should prefer short/integrated payment IDs or subaddresses for privacy. Review whether any services rely on long payment IDs in unversioned/legacy contexts.
Security signals we found
Privacy-hardening change: long payment IDs are unencrypted and can link transactions/addresses
Unknown block version now defaults to ignoring long PIDs rather than accepting them
Single-line logic fix with no input validation, crypto, or memory-safety changes
Evidence from the diff
In wallet2::process_new_transaction(), the condition for ignoring long (unencrypted) payment IDs changed from block_version >= IGNORE_LONG_PAYMENT_ID_FROM_BLOCK_VERSION to block_version == 0 || block_version >= IGNORE_LONG_PAYMENT_ID_FROM_BLOCK_VERSION. Block version 0 conventionally means ‘unknown’. The patch ensures that unknown block versions are treated the same as modern blocks and long PIDs are ignored, preventing a fallback to processing them.
Changed components
src/wallet/wallet2.cppwallet transaction processinglong payment ID handlingInspect captured patch +1 / −1
### src/wallet/wallet2.cpp
@@ -2621,7 +2621,7 @@ void wallet2::process_new_transaction(const crypto::hash &txid, const cryptonote
}
else if (get_payment_id_from_tx_extra_nonce(extra_nonce.nonce, payment_id))
{
- bool ignore = block_version >= IGNORE_LONG_PAYMENT_ID_FROM_BLOCK_VERSION;
+ bool ignore = block_version == 0 || block_version >= IGNORE_LONG_PAYMENT_ID_FROM_BLOCK_VERSION;
if (ignore)
{
LOG_PRINT_L2("Found unencrypted payment ID in tx " << txid << " (ignored)");Why this scored 45/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.