AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 34 Cryptographic libraries

Merge pull request #11373

Public commit record

What the developer wrote

Authored by tobtoht

58/100 · Thin
Merge pull request #11373

0a58a8e polyseed: do not strip unassigned code points when normalizing (Thomas)

ACKs: jpk68, rbrunner7, selsta
✓ Descriptive subject✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This change removes the 'strip unassigned code points' option from two Unicode text normalization functions used when handling Polyseed mnemonic seed phrases. Previously, characters that Unicode has not officially assigned any meaning to were silently removed during normalization. Now they are preserved. The practical effect is that a seed phrase containing such rare characters would normalize differently before and after this patch, which could in theory change the wallet key derived from the phrase. The commit message does not call this a security fix; it is described as a correctness fix for normalization.

Recommended action

Treat as a correctness-related change with possible wallet-recovery implications rather than an urgent vulnerability. Users who generated Polyseed wallets using mnemonic inputs containing unassigned Unicode characters should verify that their seed still derives the same wallet after this change. Wallet software should warn or reject mnemonics containing unusual/unassigned characters until compatibility is confirmed. Review whether any existing tests cover unassigned code points in Polyseed normalization and add regression tests if absent.

Security signals we found

01

Behavioral change in key-derivation input normalization

02

Removal of silent stripping of unassigned Unicode code points

03

Potential for same mnemonic input to produce different wallet keys before/after patch

04

No explicit security framing by vendor in commit or PR title

05

No input-sanitization or bounds-checking improvements added

Risk score

Why this scored 34/100

Our methodology →
Potential impact 8/30
Exploitability 6/25
Stealth signal 7/15
Affected reach 5/15
Confidence 5/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.