AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 59 Monero

wizard: create wallets in memory

Public commit record

What the developer wrote

Authored by selsta

45/100 · Thin
wizard: create wallets in memory
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This change alters the Monero GUI wallet setup wizard so that newly created or recovered wallets are kept only in memory, rather than being written to a temporary file on disk during the setup process. The old approach created temporary wallet files on the computer's storage and then deleted them after the user finished the wizard. The patch removes the code that created and cleaned up those temporary files. This is a defensive improvement: it reduces the chance that an unfinished or temporary wallet file containing sensitive data is left behind on disk, exposed to other users, recovered by forensic tools, or leaked through backups, swap files, or file indexing. The change also adds a small UI guard so the wizard cannot be interacted with while a hardware-device wallet is being created asynchronously.

Recommended action

Treat this as a security-hardening improvement rather than an active vulnerability. Reviewers should verify that the underlying Monero wallet library correctly handles empty path strings for in-memory wallets across all supported platforms, that no temporary files are still created by lower-level code, and that the new `closeWizardWallet()` cleanup path is invoked reliably when the wizard is cancelled or restarted. Users should upgrade to a build containing this commit to reduce disk-side exposure of wallet secrets during creation/recovery.

Security signals we found

01

Eliminates temporary wallet files that could persist or leak sensitive key material before final wallet storage

02

Reduces attack surface from temporary file handling, file-permission issues, and incomplete cleanup

03

Adds UI state guard (`deviceWalletCreationInProgress`) to prevent user interaction during asynchronous hardware wallet creation

04

Destructor logic updated to avoid storing or logging paths for in-memory wallets

05

No explicit security advisory, CVE, or researcher attribution present in commit or supplied references

Risk score

Why this scored 59/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.