What changed, and why it matters
This change removes the 'strip unassigned code points' option from two Unicode text normalization functions used when handling Polyseed mnemonic seed phrases. Previously, characters that Unicode has not officially assigned any meaning to were silently removed during normalization. Now they are preserved. The practical effect is that a seed phrase containing such rare characters would normalize differently before and after this patch, which could in theory change the wallet key derived from the phrase. The commit message does not call this a security fix; it is described as a correctness fix for normalization.
Treat as a correctness-related change with possible wallet-recovery implications rather than an urgent vulnerability. Users who generated Polyseed wallets using mnemonic inputs containing unassigned Unicode characters should verify that their seed still derives the same wallet after this change. Wallet software should warn or reject mnemonics containing unusual/unassigned characters until compatibility is confirmed. Review whether any existing tests cover unassigned code points in Polyseed normalization and add regression tests if absent.
Security signals we found
Behavioral change in key-derivation input normalization
Removal of silent stripping of unassigned Unicode code points
Potential for same mnemonic input to produce different wallet keys before/after patch
No explicit security framing by vendor in commit or PR title
No input-sanitization or bounds-checking improvements added
Evidence from the diff
In src/mnemonics/polyseed/polyseed.cpp, the UTF8PROC_STRIPNA flag is removed from both utf8_nfc() and utf8_nfkd(). These wrappers call utf8_norm() (utf8proc) to normalize mnemonic/passphrase strings before they are hashed into a Polyseed wallet seed. UTF8PROC_STRIPNA causes unassigned Unicode code points (category Cn) to be stripped. Removing it means unassigned characters are kept and composed/decomposed instead of deleted. This makes normalization behavior stricter and more standards-compliant. The change is tiny (two flag removals) and does not add input validation, length checks, or error handling.
Changed components
src/mnemonics/polyseed/polyseed.cppPolyseed mnemonic seed normalization (NFC and NFKD)Wallet seed derivation path for Polyseed-based walletsInspect captured patch +2 / −2
### src/mnemonics/polyseed/polyseed.cpp
@@ -60,11 +60,11 @@ namespace polyseed {
}
static size_t utf8_nfc(const char* str, polyseed_str norm) {
- return utf8_norm(str, norm, (utf8proc_option_t)(UTF8PROC_NULLTERM | UTF8PROC_STABLE | UTF8PROC_COMPOSE | UTF8PROC_STRIPNA));
+ return utf8_norm(str, norm, (utf8proc_option_t)(UTF8PROC_NULLTERM | UTF8PROC_STABLE | UTF8PROC_COMPOSE));
}
static size_t utf8_nfkd(const char* str, polyseed_str norm) {
- return utf8_norm(str, norm, (utf8proc_option_t)(UTF8PROC_NULLTERM | UTF8PROC_STABLE | UTF8PROC_DECOMPOSE | UTF8PROC_COMPAT | UTF8PROC_STRIPNA));
+ return utf8_norm(str, norm, (utf8proc_option_t)(UTF8PROC_NULLTERM | UTF8PROC_STABLE | UTF8PROC_DECOMPOSE | UTF8PROC_COMPAT));
}
struct dependency {Why this scored 34/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.