AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 52 Cryptographic libraries

wallet: respect --no-dns for OpenAlias

Public commit record

What the developer wrote

Authored by Samy

45/100 · Thin
wallet: respect --no-dns for OpenAlias
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This commit fixes a privacy and security bug where Monero wallets ignored the user's --no-dns setting and still performed DNS lookups for OpenAlias addresses (human-readable names like donate.getmonero.org). Now, when DNS is disabled or the wallet is offline, the wallet will not make those DNS queries. This prevents accidental network leaks and reduces the chance that a malicious or monitored DNS server could manipulate address resolution.

Recommended action

Users who rely on --no-dns or offline mode for privacy should upgrade to a release containing this commit. Operators of wallet RPC services should review whether they expose OpenAlias resolution and ensure the no-dns/offline setting is respected.

Security signals we found

01

Fixes a configuration-bypass bug where --no-dns did not prevent OpenAlias DNS lookups

02

Prevents unintended outbound DNS queries that could leak user intent or metadata

03

Reduces attack surface for DNS-based address spoofing when the user explicitly disabled DNS

04

Adds unit test coverage for the disabled/offline DNS path

Risk score

Why this scored 52/100

Our methodology →
Potential impact 12/30
Exploitability 10/25
Stealth signal 8/15
Affected reach 10/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.