wallet: send amounts to wallet rpc as json numbers for v0.18.5.3
What changed, and why it matters
This commit changes how the Java wallet library sends monetary amounts to the Monero wallet RPC server. Previously, amounts were converted to strings before being sent; now they are sent as JSON numbers. This is a compatibility fix for Monero daemon version 0.18.5.3, which expects numeric values rather than strings. There is no direct evidence in the commit that this is a security vulnerability, but sending the wrong data type could cause transaction creation or proof generation to fail or behave unexpectedly.
Treat this as a compatibility/maintenance patch. Users relying on monero-wallet-rpc v0.18.5.3 should upgrade to this commit to avoid RPC failures. Review whether the RPC library's JSON serializer correctly handles BigInteger as a number without precision loss. No immediate security response is indicated by the available evidence.
Security signals we found
Data type mismatch between client and RPC server could lead to failed or misinterpreted transactions
Amount handling changes in transaction creation and reserve proof generation paths
No input validation or bounds checks added in the patch
No explicit security context provided by the vendor in commit message
Evidence from the diff
The patch modifies MoneroWalletRpc.java to pass BigInteger amount values directly into RPC parameter maps instead of calling .toString() first. Affected methods include createTxs(), getReserveProofAccount(), and getPaymentUri(). The change aligns the Java client with the RPC API expectations of monero-wallet-rpc v0.18.5.3, where amount fields are numeric. The commit message frames this as a version-specific compatibility update, not a security fix.
Changed components
src/main/java/monero/wallet/MoneroWalletRpc.javacreateTxs()getReserveProofAccount()getPaymentUri()Inspect captured patch +3 / −3
### src/main/java/monero/wallet/MoneroWalletRpc.java
@@ -1231,7 +1231,7 @@ public List<MoneroTxWallet> createTxs(MoneroTxConfig config) {
GenUtils.assertNotNull("Destination amount is not defined", destination.getAmount());
Map<String, Object> destinationMap = new HashMap<String, Object>();
destinationMap.put("address", destination.getAddress());
- destinationMap.put("amount", destination.getAmount().toString());
+ destinationMap.put("amount", destination.getAmount());
destinationMaps.add(destinationMap);
}
if (config.getSubtractFeeFrom() != null) params.put("subtract_fee_from_outputs", config.getSubtractFeeFrom());
@@ -1626,7 +1626,7 @@ public String getReserveProofWallet(String message) {
public String getReserveProofAccount(int accountIdx, BigInteger amount, String message) {
Map<String, Object> params = new HashMap<String, Object>();
params.put("account_index", accountIdx);
- params.put("amount", amount.toString());
+ params.put("amount", amount);
params.put("message", message);
Map<String, Object> resp = rpc.sendJsonRequest("get_reserve_proof", params);
Map<String, Object> result = (Map<String, Object>) resp.get("result");
@@ -1775,7 +1775,7 @@ public String getPaymentUri(MoneroTxConfig config) {
GenUtils.assertNotNull("Must provide send request to create a payment URI", config);
Map<String, Object> params = new HashMap<String, Object>();
params.put("address", config.getDestinations().get(0).getAddress());
- params.put("amount", config.getDestinations().get(0).getAmount() != null ? config.getDestinations().get(0).getAmount().toString() : null);
+ params.put("amount", config.getDestinations().get(0).getAmount());
params.put("payment_id", config.getPaymentId());
params.put("recipient_name", config.getRecipientName());
params.put("tx_description", config.getNote());Why this scored 24/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.