wallet2: clear m_additional_tx_keys during bg sync
What changed, and why it matters
This commit fixes a cleanup oversight in the Monero wallet. When the wallet clears private user data during background synchronization, it now also clears 'additional transaction keys' (m_additional_tx_keys). Previously, these extra keys were left behind while other similar secrets were wiped. This could mean sensitive cryptographic material persists longer than intended, potentially increasing exposure if an attacker later accesses wallet memory or state. The change is small and defensive, matching how related secrets are already handled.
Treat as a low-to-moderate defensive security fix. Include in routine release notes and backport to maintained branches. Users running background sync should update when a release containing this commit is available. No immediate emergency response is warranted because exploitation requires additional compromise (memory/state access) and the fix is straightforward.
Security signals we found
Incomplete sensitive-data cleanup / data lifetime issue
Missing clear of cryptographic key container during background sync
Consistency fix to match existing clearing of m_tx_keys and other user data
Evidence from the diff
In wallet2::clear_user_data(), the patch adds m_additional_tx_keys.clear() alongside existing clears for m_tx_keys, m_tx_notes, m_address_book, m_subaddress_labels, etc. m_additional_tx_keys stores additional transaction private keys used for things like multi-destination transactions and subaddresses. The omission meant that during background sync cleanup this container retained key material that should have been purged with other user-associated data. The fix aligns the lifecycle of additional tx keys with regular tx keys and other wallet metadata.
Changed components
src/wallet/wallet2.cppwallet2::clear_user_data()Background synchronization (bg sync) pathInspect captured patch +1 / −0
diff --git a/src/wallet/wallet2.cpp b/src/wallet/wallet2.cpp
index b89370f..be1305f 100644
--- a/src/wallet/wallet2.cpp
+++ b/src/wallet/wallet2.cpp
@@ -4538,6 +4538,7 @@ void wallet2::clear_user_data()
for (auto i = m_transfers.begin(); i != m_transfers.end(); ++i)
i->m_frozen = false;
m_tx_keys.clear();
+ m_additional_tx_keys.clear();
m_tx_notes.clear();
m_address_book.clear();
m_subaddress_labels.clear();
Why this scored 35/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.