AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 69 Cryptographic libraries

Merge pull request #11333

Public commit record

What the developer wrote

Authored by tobtoht

66/100 · Adequate
Merge pull request #11333

b19cf44 wallet: fix inconsistent tx pubkey handling (selsta)
3becac8 crypto: move torsion clearing into crypto (selsta)

ACKs: j-berman, PyXMR2025
✓ Descriptive subject✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This Monero update hardens how public keys and transaction pubkeys are handled. It moves a low-level 'torsion clearing' routine into the core crypto library, adds checks that wallet/destination addresses are valid points on the main subgroup of the curve, and normalizes transaction public keys before they are used for payment-ID decryption, transaction proofs, and hardware-wallet communication. The changes reduce the risk that malformed or small-subgroup public keys could be used to confuse wallet logic, leak information, or cause inconsistent behavior. The commit message frames it as a fix for 'inconsistent tx pubkey handling' and a crypto cleanup, not as an active-exploit patch.

Recommended action

Treat as a security-hardening fix and include in the next release. Users running nodes/wallets from source should update to a build containing this commit. Review whether any downstream tools or RPC consumers parse transaction pubkeys independently and may need similar normalization. No immediate emergency response is indicated by the commit materials alone, but the changes address real cryptographic hygiene issues.

Security signals we found

01

Adds main-subgroup membership validation for public address keys (spend/view)

02

Normalizes transaction public keys before use in payment-ID decryption and tx proofs

03

Moves torsion-clearing primitive into core crypto layer to ensure consistent behavior

04

Fixes index bounds check when serializing additional tx pubkeys to Trezor

05

Replaces ad-hoc subgroup checks with centralized check_address() helper

06

Changes wallet logic to rely on recorded tx pubkey index rather than scanning all pubkeys

Risk score

Why this scored 69/100

Our methodology →
Potential impact 22/30
Exploitability 14/25
Stealth signal 10/15
Affected reach 12/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.