AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 63 Cryptographic libraries

wallet: fix inconsistent tx pubkey handling

Public commit record

What the developer wrote

Authored by selsta

45/100 · Thin
wallet: fix inconsistent tx pubkey handling
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This Monero commit fixes how the wallet handles transaction public keys and address public keys so that keys with small-order or non-standard curve points (called 'torsion' points) are normalized or rejected before being used. It also tightens validation of destination addresses and makes transaction-proof logic more consistent. In plain terms, the patch closes gaps where a malformed key could confuse the wallet about who paid whom or whether a payment proof is valid.

Recommended action

Treat this as a security-relevant hardening fix. Users and services should upgrade to a release containing this commit. Review whether any downstream wallets or hardware-wallet integrations rely on the old, more permissive key handling. No immediate emergency response is indicated by the diff alone, but the changes are consistent with preventing key-subgroup attacks.

Security signals we found

01

New torsion-clearing helper for public keys

02

Address validation now requires main-subgroup membership and rejects identity

03

Transaction construction rejects destinations with invalid address keys

04

Wallet proof generation/verification normalizes tx pub keys and iterates over multiple candidates

05

Trezor protocol clears torsion on tx pub keys sent to/received from hardware device

06

Payment ID decryption now normalizes tx pub key before use

Risk score

Why this scored 63/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 10/15
Affected reach 12/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.