AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 59 Cryptographic libraries

wallet: derive encrypted payment ID dummy/real status from tx.extra, not cd.dests

Public commit record

What the developer wrote

Authored by waris )

50/100 · Thin
wallet: derive encrypted payment ID dummy/real status from tx.extra, not cd.dests
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This Monero wallet patch changes how the wallet decides whether an encrypted payment ID is real or a dummy placeholder. Previously, the wallet relied on destination address data (cd.dests), which could be manipulated by a malicious signer or loaded transaction to make a real payment ID look fake, or a fake one look real. The patch now derives that status directly from the transaction's extra field, where the payment ID is actually stored, and adds a consistency check. This is a security fix for a potential information leak or user deception during multi-step transaction signing.

Recommended action

Treat as a security fix. Review related code paths for other instances where destination metadata rather than tx.extra is used for payment ID decisions, and verify the consistency check cannot be bypassed. No explicit CVE or advisory is present in the provided materials, so monitor Monero Project channels for disclosure.

Security signals we found

01

Trust boundary crossed: loaded unsigned transaction / destination metadata used for security-relevant decision

02

Inconsistent data sources for payment ID status (tx.extra vs cd.dests)

03

Added runtime consistency assertion (CHECK_AND_ASSERT_MES) between derived dummy status and actual encrypted payment ID value

04

Removed reliance on entry.original address string comparison for integrated address display

05

Potential for user deception: real encrypted payment ID could be hidden or dummy could be presented as real

Risk score

Why this scored 59/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 10/15
Affected reach 10/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.