What changed, and why it matters
This commit updates Monero's built-in blockchain checkpoints to match the v0.18.5.3 release. Checkpoints are hard-coded reference points that help nodes quickly verify they are following the correct chain and resist certain attacks. The change only updates data values (block heights and hashes) and version references in documentation; it does not introduce new code logic or fix a known vulnerability.
Treat as a routine release-maintenance update. Users running Monero nodes should upgrade to v0.18.5.3 to stay synchronized with current checkpoints, but no urgent security action is indicated by this commit alone. Review the full v0.18.5.3 release notes for any separately disclosed security fixes.
Security signals we found
Hard-coded blockchain checkpoint data updated to a newer height/hash
Expected compiled-in block hashes digest changed
No new code paths, cryptographic changes, or bug fixes visible in the diff
Evidence from the diff
The merge commit updates the compiled-in checkpoints.dat binary, the checkpoint table in src/checkpoints/checkpoints.cpp (replacing height 3707000 with height 3774800 and its corresponding block hash and cumulative difficulty), and the expected hash of the compiled-in block hashes in src/cryptonote_core/blockchain.cpp. README.md references are bumped from v0.18.5.1 to v0.18.5.3. These are routine maintenance updates that accompany a point release.
Changed components
src/blocks/checkpoints.datsrc/checkpoints/checkpoints.cppsrc/cryptonote_core/blockchain.cppREADME.mdInspect captured patch +7 / −7
### README.md
@@ -121,8 +121,8 @@ Dates are provided in the format YYYY-MM-DD. The "Minimum" is the software versi
| 1978433 | 2019-11-30 | v12 | v0.15.0.0 | v0.16.0.0 | New PoW based on RandomX, only allow >= 2 outputs, change to the block median used to calculate penalty, v1 coinbases are forbidden, rct sigs in coinbase forbidden, 10 block lock time for incoming outputs
| 2210000 | 2020-10-17 | v13 | v0.17.0.0 | v0.17.3.2 | New CLSAG transaction format
| 2210720 | 2020-10-18 | v14 | v0.17.1.1 | v0.17.3.2 | forbid old MLSAG transaction format
-| 2688888 | 2022-08-13 | v15 | v0.18.0.0 | v0.18.5.1 | ringsize = 16, bulletproofs+, view tags, adjusted dynamic block weight algorithm
-| 2689608 | 2022-08-14 | v16 | v0.18.0.0 | v0.18.5.1 | forbid old v14 transaction format
+| 2688888 | 2022-08-13 | v15 | v0.18.0.0 | v0.18.5.3 | ringsize = 16, bulletproofs+, view tags, adjusted dynamic block weight algorithm
+| 2689608 | 2022-08-14 | v16 | v0.18.0.0 | v0.18.5.3 | forbid old v14 transaction format
| XXXXXXX | XXX-XX-XX | XXX | vX.XX.X.X | vX.XX.X.X | XXX |
X's indicate that these details have not been determined as of commit date.
@@ -284,7 +284,7 @@ Tested on a Raspberry Pi 5B with a clean installation of Raspberry Pi OS (64-bit
```bash
git clone --recursive https://github.com/monero-project/monero.git
cd monero
- git checkout v0.18.5.1
+ git checkout v0.18.5.3
```
* Build:
@@ -343,10 +343,10 @@ Binaries for Windows can be built on Windows using the MinGW toolchain within [M
cd monero
```
-* If you would like a specific [version/tag](https://github.com/monero-project/monero/tags), do a git checkout for that version. eg. 'v0.18.5.1'. If you don't care about the version and just want binaries from master, skip this step:
+* If you would like a specific [version/tag](https://github.com/monero-project/monero/tags), do a git checkout for that version. eg. 'v0.18.5.3'. If you don't care about the version and just want binaries from master, skip this step:
```bash
- git checkout v0.18.5.1
+ git checkout v0.18.5.3
```
* To build Monero, run:
### src/blocks/checkpoints.dat
[binary or diff unavailable]
### src/checkpoints/checkpoints.cpp
@@ -271,7 +271,7 @@ namespace cryptonote
ADD_CHECKPOINT2(3541000, "74c457bed9ceef40f31f43bb8fab804077519d45c910dcad2acf4dd8556195c7", "0x76ff158c682d218");
ADD_CHECKPOINT2(3576000, "5da4891bfd06be270193bd949f2a623a2b0cb0ebfaad21c70a6cb18e418e5b6a", "0x7cb2e203e867b57");
ADD_CHECKPOINT2(3661900, "ac392757a92123f68d63cd72f0d1410f63df1102a53b5d39fc4d53d0998b20a3", "0x8a38f2195826a97");
- ADD_CHECKPOINT2(3707000, "9c508fe29120b5cd204f9d150e68fd2e4015d8d859bc0431f7016c7aabc711c9", "0x91129586d4979a6");
+ ADD_CHECKPOINT2(3774800, "0f4c4c1ca33c35dc56cb764a94e96467df281299e9e5264a5d905309cb806488", "0x9bb1dcfc99f355c");
return true;
}
### src/cryptonote_core/blockchain.cpp
@@ -5476,7 +5476,7 @@ void Blockchain::cancel()
}
#if defined(PER_BLOCK_CHECKPOINT)
-static const char expected_block_hashes_hash[] = "2aea941d43024422a63f223c84b9d88d1f58d31e1f508c2d6d43cd637ba32d16";
+static const char expected_block_hashes_hash[] = "4871b67b077087affd07094be0f70bfd0d4e4105df126646e0a7524fe02b1d5d";
void Blockchain::load_compiled_in_block_hashes(const GetCheckpointsCallback& get_checkpoints)
{
if (get_checkpoints == nullptr || !m_fast_sync)Why this scored 22/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.