AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Informational 19 Cryptographic libraries

Merge pull request #11368

Public commit record

What the developer wrote

Authored by tobtoht

66/100 · Adequate
Merge pull request #11368

5626dfc wallet2: restore from a Polyseed with --generate-from-json (Thomas)
0214b32 simplewallet: keep the restore height from --generate-from-json (Thomas)

ACKs: jpk68, selsta
✓ Descriptive subject✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit fixes a wallet-creation bug: when restoring a Monero wallet from a special newer-style seed (called a Polyseed) using a JSON configuration file, the wallet software previously treated it like an older Electrum-style seed. This could cause the restore height to be set incorrectly and could apply an optional seed passphrase to the wrong key derivation path. The patch makes the JSON restore path recognize Polyseeds and handle their passphrase and birthday height correctly. It also preserves the restore height in the simplewallet command-line tool when no explicit restore height is provided.

Recommended action

Treat this as a bug-fix commit with low security impact. Users who restored Polyseed wallets via --generate-from-json before this patch should verify their wallet addresses and transaction history, and consider regenerating the wallet from the Polyseed on an updated client if a seed passphrase was used.

Security signals we found

01

Incorrect key derivation path for Polyseed when a seed passphrase is supplied via JSON

02

Restore height mishandling causing wallet to scan from wrong block height

03

Functional test added to assert correct Polyseed address, birthday, and encryption flag

Risk score

Why this scored 19/100

Our methodology →
Potential impact 2/30
Exploitability 1/25
Stealth signal 1/15
Affected reach 3/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.