wallet_api: reject transaction file signing with hardware wallets
What changed, and why it matters
This change blocks a specific command—signing unsigned transaction files—from being used when a Monero wallet's private keys live on a hardware device (Ledger/Trezor). Before the patch, the software apparently allowed users to attempt this operation, which hardware wallets do not actually support. The patch now returns a clear error instead of proceeding. The risk is that a user or third-party tool could be misled into thinking a transaction was properly signed when it was not, potentially causing loss of funds or a failed/confused workflow. No exploit code is shown in the commit.
Treat as a low-to-moderate reliability/safety fix. If running a Monero wallet service or GUI that uses wallet_api with hardware wallets, apply the patch so users cannot attempt unsupported transaction-file signing. Review whether any other signing or export paths assume software keys when hardware wallets are in use. No emergency response is indicated by the diff alone.
Security signals we found
Missing authorization/unsupported operation now explicitly rejected
Hardware wallet key storage detected and blocked from incompatible signing path
User-facing error string added to prevent silent failure
No cryptographic fix or input validation change beyond the guard clause
Evidence from the diff
In src/wallet/api/unsigned_transaction.cpp, UnsignedTransactionImpl::sign() now checks m_wallet.m_wallet->key_on_device() and immediately fails with Status_Error and the message “Command not supported by hardware wallet”. This prevents the subsequent code path that loads and signs an unsigned transaction file from running when the wallet is backed by a hardware device. The patch is purely a guard clause; it does not implement hardware-wallet signing for transaction files. The commit message credits zkao using a tool by zkSecurity, but no advisory or CVE is supplied.
Changed components
src/wallet/api/unsigned_transaction.cppUnsignedTransactionImpl::sign()wallet_api hardware wallet integrationInspect captured patch +6 / −0
diff --git a/src/wallet/api/unsigned_transaction.cpp b/src/wallet/api/unsigned_transaction.cpp
index 1130159..6555f30 100644
--- a/src/wallet/api/unsigned_transaction.cpp
+++ b/src/wallet/api/unsigned_transaction.cpp
@@ -76,6 +76,12 @@ bool UnsignedTransactionImpl::sign(const std::string &signedFileName)
m_status = Status_Error;
return false;
}
+ if(m_wallet.m_wallet->key_on_device())
+ {
+ m_errorString = tr("Command not supported by hardware wallet");
+ m_status = Status_Error;
+ return false;
+ }
std::vector<tools::wallet2::pending_tx> ptx;
try
{
Why this scored 46/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.