AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 35 Cryptographic libraries

wallet: rescan_blockchain missing keep_key_images

Public commit record

What the developer wrote

Authored by Navid Rahimi

35/100 · Opaque
wallet: rescan_blockchain missing keep_key_images
✓ Descriptive subject! No meaningful explanatory body
The short version

What changed, and why it matters

This commit fixes a bug in Monero's wallet RPC server where the rescan_blockchain command was not passing through a new keep_key_images option. A hard rescan normally destroys key images (the proof that a coin has already been spent), so the patch also blocks the contradictory combination of a hard rescan while trying to preserve key images. The change is mostly a missing-parameter fix, but mishandling key images could in theory affect wallet balance accuracy or spendability.

Recommended action

Treat as a routine correctness fix. Review the underlying wallet2::rescan_blockchain implementation to confirm that keep_key_images behaves safely on soft rescans and that no other RPC wrappers omit the flag. No urgent security response is indicated from the diff alone.

Security signals we found

01

Missing parameter forwarding in RPC wrapper

02

New input validation guard for contradictory flags

03

Key-image handling change in wallet rescan logic

Risk score

Why this scored 35/100

Our methodology →
Potential impact 8/30
Exploitability 5/25
Stealth signal 6/15
Affected reach 7/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.