What changed, and why it matters
This change alters how Monero creates a view-only wallet copy. Previously, the code exported outputs using a method that could strip some metadata. Now it copies the full internal transfer records directly, then wipes and clears the multi-signature key field to avoid leaking a signing secret. The intent appears to be a security fix: preserving more metadata in view-only wallets while scrubbing data that should not be exported. However, the patch is small and the commit message does not explicitly call it a security fix, so the classification is uncertain.
Treat as a potential security hardening fix. Review the previous export_outputs/import_outputs path to confirm what metadata was lost or leaked, verify that m_multisig_k is the only sensitive field not intended for view-only wallets, and ensure memwipe is applied to all copies of the data. Consider requesting an advisory or changelog entry from the Monero maintainers.
Security signals we found
Sensitive field sanitization before export (memwipe + clear of m_multisig_k)
Change in data export path for view-only wallet creation
Preservation of 'complete output metadata' implying previous path was incomplete
Multi-signature key material handled during wallet export
Evidence from the diff
The commit replaces a call to wallet2::export_outputs(true) followed by import_outputs(outputs) with a direct get_transfers(transfers) / import_outputs(tuple) path. It then memwipes and clears td.m_multisig_k for each transfer. m_multisig_k is part of the transfer_details structure and is relevant to multi-signature signing material. The change suggests the previous export path either lost output metadata or risked including multisig key material; the new path preserves complete metadata while explicitly sanitizing the multisig field. The commit is a merge of PR #11253 by selsta, ACKed by jpk68 and plowsof.
Changed components
src/wallet/api/wallet.cppWalletImpl::createWatchOnlyview-only wallet export/import flowmulti-signature key handlingInspect captured patch +9 / −3
### src/wallet/api/wallet.cpp
@@ -547,9 +547,15 @@ bool WalletImpl::createWatchOnly(const std::string &path, const std::string &pas
// Generate view only wallet
view_wallet->generate(path, password, address, viewkey);
- // Export/Import outputs
- auto outputs = m_wallet->export_outputs(true/*all*/);
- view_wallet->import_outputs(outputs);
+ // Preserve complete output metadata
+ tools::wallet2::transfer_container transfers;
+ m_wallet->get_transfers(transfers);
+ for (auto &td : transfers)
+ {
+ memwipe(td.m_multisig_k.data(), td.m_multisig_k.size() * sizeof(td.m_multisig_k[0]));
+ td.m_multisig_k.clear();
+ }
+ view_wallet->import_outputs(std::make_tuple(uint64_t{0}, uint64_t{transfers.size()}, transfers));
// Copy scanned blockchain
auto bc = m_wallet->export_blockchain();Why this scored 42/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.