AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 65 Cryptographic libraries

wallet2: store multisig nonce erasure before returning signed txset

Public commit record

What the developer wrote

Authored by selsta

50/100 · Thin
wallet2: store multisig nonce erasure before returning signed txset
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This patch changes how Monero's wallet handles multisig transactions. In a multisig wallet, several people must cooperate to sign a transaction. The patch makes sure that sensitive one-time secret values (called 'nonces') are wiped from the wallet's memory and saved to disk *before* the partially-signed transaction file is handed back to the user. Previously, the wallet could return the signed transaction file while still keeping those secret values in memory. If the wallet later crashed or was used again without saving, those secret values might be reused or leaked, which could weaken the security of the multisig scheme and, in the worst case, allow an attacker to recover private key material or forge signatures.

Recommended action

Treat this as a security fix and include it in the next release. Users who create or sign multisig transactions with affected versions should upgrade promptly. Wallet developers building on wallet2 should ensure they do not expose signed/partial multisig txsets before erasing and storing the corresponding m_multisig_k values. No immediate on-chain action is required.

Security signals we found

01

Multisig nonce (k-value) erasure moved to occur before txset is exposed to caller

02

New helper clear_multisig_k_and_store() ensures wallet cache is persisted after erasure

03

sign_multisig_tx now operates on a local copy and only commits output after secure cleanup

04

m_tx_keys/m_additional_tx_keys updates deferred until after nonce wipe and store()

05

memwipe used to clear sensitive rct::key material from m_multisig_k

06

Potential nonce-reuse / private-key-leak class issue in threshold multisig

Risk score

Why this scored 65/100

Our methodology →
Potential impact 22/30
Exploitability 14/25
Stealth signal 10/15
Affected reach 8/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.