src: update checkpoints to match v0.18.5.1
What changed, and why it matters
This commit updates Monero's built-in blockchain checkpoints to match the v0.18.5.1 release. Checkpoints are hard-coded reference points that help nodes quickly verify they are following the correct chain and protect against certain history-rewriting attacks. The README version references are also updated from v0.18.4.1 to v0.18.5.1. There is no code-level vulnerability being patched here; it is a routine network-consistency maintenance update.
Treat as a normal release-maintenance commit. Users and operators should upgrade to v0.18.5.1 to stay in sync with the latest checkpoints and network consensus, but no urgent security response is indicated by this commit alone.
Security signals we found
Hard-coded blockchain checkpoint added at height 3707000
Compiled-in expected block hashes hash updated
Binary checkpoints.dat refreshed
No vulnerability description, CVE reference, or bug fix present in commit message or diff
Evidence from the diff
The change adds a new checkpoint at height 3707000 in src/checkpoints/checkpoints.cpp, refreshes the binary checkpoints.dat blob, and updates the expected hash of the compiled-in block hashes in src/cryptonote_core/blockchain.cpp. README.md hard-fork table rows for v15/v16 now list v0.18.5.1 as the recommended version and build examples use v0.18.5.1 instead of v0.18.4.1. These are standard release-synchronization artifacts, not a security fix.
Changed components
src/checkpoints/checkpoints.cppsrc/blocks/checkpoints.datsrc/cryptonote_core/blockchain.cppREADME.mdInspect captured patch +7 / −6
diff --git a/README.md b/README.md
index 2a52e8c..9aeec92 100644
--- a/README.md
+++ b/README.md
@@ -137,8 +137,8 @@ Dates are provided in the format YYYY-MM-DD. The "Minimum" is the software versi
| 1978433 | 2019-11-30 | v12 | v0.15.0.0 | v0.16.0.0 | New PoW based on RandomX, only allow >= 2 outputs, change to the block median used to calculate penalty, v1 coinbases are forbidden, rct sigs in coinbase forbidden, 10 block lock time for incoming outputs
| 2210000 | 2020-10-17 | v13 | v0.17.0.0 | v0.17.3.2 | New CLSAG transaction format
| 2210720 | 2020-10-18 | v14 | v0.17.1.1 | v0.17.3.2 | forbid old MLSAG transaction format
-| 2688888 | 2022-08-13 | v15 | v0.18.0.0 | v0.18.5.0 | ringsize = 16, bulletproofs+, view tags, adjusted dynamic block weight algorithm
-| 2689608 | 2022-08-14 | v16 | v0.18.0.0 | v0.18.5.0 | forbid old v14 transaction format
+| 2688888 | 2022-08-13 | v15 | v0.18.0.0 | v0.18.5.1 | ringsize = 16, bulletproofs+, view tags, adjusted dynamic block weight algorithm
+| 2689608 | 2022-08-14 | v16 | v0.18.0.0 | v0.18.5.1 | forbid old v14 transaction format
| XXXXXXX | XXX-XX-XX | XXX | vX.XX.X.X | vX.XX.X.X | XXX |
X's indicate that these details have not been determined as of commit date.
@@ -319,7 +319,7 @@ Tested on a Raspberry Pi 5B with a clean installation of Raspberry Pi OS (64-bit
```bash
git clone --recursive https://github.com/monero-project/monero.git
cd monero
- git checkout v0.18.4.1
+ git checkout v0.18.5.1
```
* Build:
@@ -382,10 +382,10 @@ application.
cd monero
```
-* If you would like a specific [version/tag](https://github.com/monero-project/monero/tags), do a git checkout for that version. eg. 'v0.18.4.1'. If you don't care about the version and just want binaries from master, skip this step:
+* If you would like a specific [version/tag](https://github.com/monero-project/monero/tags), do a git checkout for that version. eg. 'v0.18.5.1'. If you don't care about the version and just want binaries from master, skip this step:
```bash
- git checkout v0.18.4.1
+ git checkout v0.18.5.1
```
* To build Monero, run:
diff --git a/src/blocks/checkpoints.dat b/src/blocks/checkpoints.dat
index 5b8f04c..0fa7ac0 100644
Binary files a/src/blocks/checkpoints.dat and b/src/blocks/checkpoints.dat differ
diff --git a/src/checkpoints/checkpoints.cpp b/src/checkpoints/checkpoints.cpp
index 2d12180..542fe0b 100644
--- a/src/checkpoints/checkpoints.cpp
+++ b/src/checkpoints/checkpoints.cpp
@@ -271,6 +271,7 @@ namespace cryptonote
ADD_CHECKPOINT2(3541000, "74c457bed9ceef40f31f43bb8fab804077519d45c910dcad2acf4dd8556195c7", "0x76ff158c682d218");
ADD_CHECKPOINT2(3576000, "5da4891bfd06be270193bd949f2a623a2b0cb0ebfaad21c70a6cb18e418e5b6a", "0x7cb2e203e867b57");
ADD_CHECKPOINT2(3661900, "ac392757a92123f68d63cd72f0d1410f63df1102a53b5d39fc4d53d0998b20a3", "0x8a38f2195826a97");
+ ADD_CHECKPOINT2(3707000, "9c508fe29120b5cd204f9d150e68fd2e4015d8d859bc0431f7016c7aabc711c9", "0x91129586d4979a6");
return true;
}
diff --git a/src/cryptonote_core/blockchain.cpp b/src/cryptonote_core/blockchain.cpp
index f2e8e23..42be61e 100644
--- a/src/cryptonote_core/blockchain.cpp
+++ b/src/cryptonote_core/blockchain.cpp
@@ -5446,7 +5446,7 @@ void Blockchain::cancel()
}
#if defined(PER_BLOCK_CHECKPOINT)
-static const char expected_block_hashes_hash[] = "3aed3b6b896e8c1f97802b65f84966526d1ac8d75f417e5ce666f31a5928ac3f";
+static const char expected_block_hashes_hash[] = "2aea941d43024422a63f223c84b9d88d1f58d31e1f508c2d6d43cd637ba32d16";
void Blockchain::load_compiled_in_block_hashes(const GetCheckpointsCallback& get_checkpoints)
{
if (get_checkpoints == nullptr || !m_fast_sync)
Why this scored 22/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.