AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 57 Cryptographic libraries

wallet2: fix edge case where tx's ki's remain marked unspent

Public commit record

What the developer wrote

Authored by j-berman

85/100 · Strong
wallet2: fix edge case where tx's ki's remain marked unspent

If a tx is marked as failed (because it never shows up in the
daemon's pool), its key images get reset back to unspent so they
can be used in future txs.

If the tx re-enters the daemon's pool (e.g. it's removed from the
pool and then relayed back), then the wallet incorrectly maintains
that the tx's key images are unspent.

This change ensures the wallet re-marks the tx's key images as
spent if the tx re-appears in the node's pool.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
The short version

What changed, and why it matters

This patch fixes a bookkeeping bug in the Monero wallet. When a transaction temporarily disappears from the network's pending pool and is later re-broadcast, the wallet could wrongly treat the coins it spends as still available. That could let the wallet try to spend the same coins twice, producing a conflict that prevents any of those follow-up transactions from confirming until the wallet state is manually repaired.

Recommended action

Apply the patch. Users running affected wallet versions should refresh/rescan if they observe failed or stuck transactions after a previously failed tx re-enters the mempool. Wallet RPC/services should monitor for duplicate key-image attempts and alert rather than blindly re-spend.

Security signals we found

01

Double-spend risk from inconsistent local key-image state

02

Transaction failure / denial of service for wallet-created transactions

03

State synchronization bug between wallet and daemon mempool

04

No cryptographic weakness or consensus bypass

Risk score

Why this scored 57/100

Our methodology →
Potential impact 18/30
Exploitability 10/25
Stealth signal 8/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.