AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 57 Cryptographic libraries

wallet2: check reserve proof additional key index

Public commit record

What the developer wrote

Authored by selsta

60/100 · Adequate
wallet2: check reserve proof additional key index

Reported by xmrack and the MAGIC Monero Fund.
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
The short version

What changed, and why it matters

This patch tightens a safety check in Monero's wallet when creating a 'reserve proof' (a cryptographic receipt proving funds exist). Previously the wallet only checked whether any extra public keys existed at all; now it checks whether the specific key needed for the output actually exists. Without this check, the wallet could read past the end of an empty list and crash or behave unpredictably, but the change is small and the error path already threw an exception.

Recommended action

Apply the patch. It is a minimal, defensive fix. Users relying on reserve proofs should upgrade, though no active remote exploit path is evident from the diff alone.

Security signals we found

01

Bounds-check hardening on array index before use

02

Out-of-bounds read risk in reserve-proof generation

03

Potential use of invalid tx pub key pointer

04

Reported by external party (xmrack / MAGIC Monero Fund)

Risk score

Why this scored 57/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.