simplewallet: use the swept account for index=all in sweep_main
What changed, and why it matters
This is a one-line bug fix in Monero's command-line wallet. The 'sweep_account' command, when asked to sweep all subaddresses of a different account than the one currently selected, accidentally looked at the wrong account's list of subaddresses. This could cause some funds to be left behind or the command to wrongly report that the target account had no spendable balance. It does not let an attacker steal funds; it is a user-facing functional bug that could surprise a wallet user.
Treat as a routine bug fix rather than a security vulnerability. Users relying on sweep_account with index=all should upgrade to a version containing this commit to ensure all target subaddresses are swept correctly. No emergency response is warranted.
Security signals we found
Incorrect use of account context variable (m_current_subaddress_account vs parameter)
Functional bug in funds-sweeping logic
Potential denial of user intent: funds not moved as requested
No authentication bypass, memory corruption, or cryptographic weakness
Evidence from the diff
In simple_wallet::sweep_main(uint32_t account, …), the ‘index=all’ expansion loop iterated over m_wallet->get_num_subaddresses(m_current_subaddress_account) instead of the passed account parameter. Consequently, sweep_account (which passes a non-current account) built an incorrect subaddress index set. If the current account had fewer subaddresses than the target account, higher minor indices were omitted, potentially leaving outputs unswept and triggering a ‘No unlocked balance in the specified subaddress(es)’ error despite the target account having a balance. The RPC path already used the correct account index. The patch changes the loop to use the account parameter.
Changed components
src/simplewallet/simplewallet.cppsimple_wallet::sweep_mainCLI sweep_account commandInspect captured patch +1 / −1
diff --git a/src/simplewallet/simplewallet.cpp b/src/simplewallet/simplewallet.cpp
index 17a9f2b..0616f1f 100644
--- a/src/simplewallet/simplewallet.cpp
+++ b/src/simplewallet/simplewallet.cpp
@@ -6849,7 +6849,7 @@ bool simple_wallet::sweep_main(uint32_t account, uint64_t below, const std::vect
{
if (local_args[0] == "index=all")
{
- for (uint32_t i = 0; i < m_wallet->get_num_subaddresses(m_current_subaddress_account); ++i)
+ for (uint32_t i = 0; i < m_wallet->get_num_subaddresses(account); ++i)
subaddr_indices.insert(i);
}
else if (!parse_subaddress_indices(local_args[0], subaddr_indices))
Why this scored 32/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.