AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Informational 20 Cryptographic libraries

wallet: support offset in key image export and import

Public commit record

What the developer wrote

Authored by woodser

73/100 · Adequate
wallet: support offset in key image export and import

Adds MoneroKeyImageExportResult with the offset returned by the wallet
and an offset parameter on importKeyImages(), in rpc and jni bindings.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This commit updates the Java Monero wallet library so that exporting and importing signed key images now also carries an 'offset' value. The offset tells the wallet where the exported key images start among all the wallet's outputs. This is a feature/API alignment change rather than a clear security fix. There is no evidence in the commit message or diff that the author describes it as fixing a vulnerability, and no independent security references are provided.

Recommended action

Treat this as a routine API/feature update. If using the new importKeyImages(List, long) overload, ensure the offset is validated and matches the wallet's actual output list to avoid incorrect spent-status reporting. Review the underlying monero-cpp/native implementation for how it handles out-of-range offsets, since this wrapper does not add validation.

Security signals we found

01

API surface change for key image import/export

02

New offset parameter passed to native wallet import_key_images

03

No explicit security claim in commit message or diff

04

No input validation added for offset or key image fields

05

No bounds/overflow checks visible in the diff

Risk score

Why this scored 20/100

Our methodology →
Potential impact 2/30
Exploitability 2/25
Stealth signal 1/15
Affected reach 3/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.