AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 59 Bitcoin

Narrow bare p2sh candidacy to what the rebuild cannot decide

Public commit record

What the developer wrote

Authored by kdmukai

83/100 · Strong
Narrow bare p2sh candidacy to what the rebuild cannot decide

The nested single sig outlier in change candidacy also required the
output's one derivation path entry to claim this seed's fingerprint.
That kept an output paying our key under another seed's key and
fingerprint out of the rebuild, so it was shown as a spend to the
user's own address, while the same output with its redeem script
present is refused as a contradiction. The rebuild derives our key at
the entry's path whatever fingerprint it lists, so the outlier drops
the condition and _is_change_candidate drops the verified derivation
paths it read for it.

The outlier also required exactly one derivation path entry. It only
kept out bare p2sh outputs annotated with several keys while omitting
their scripts, which no surveyed coordinator emits, and the single sig
surplus check now refuses those.

The m-of-n exclusion becomes a check that the output omits its redeem
script. For an output parsed as plain p2sh the two admit the same
outputs, since a supplied multisig redeem script is the only source of
an m-of-n there, and the new check states what the outlier is for.

New tests refuse an output that pays this seed but lists another key,
and pin each of the three remaining conditions: a payment to another
wallet of this seed, annotated with our key, stays a spend.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
The short version

What changed, and why it matters

This commit fixes a logic flaw in how SeedSigner decides whether a Bitcoin transaction output is 'change' going back to the user's own wallet, versus a payment to someone else. Previously, a specially crafted PSBT could make an output that actually pays to the user's own key appear as a spend to an external address, or could make a contradictory ownership claim slip through. The patch narrows the special-case rule and adds tests to catch these scenarios.

Recommended action

Review and merge the patch, then verify that the new unit tests cover the three stated conditions and that no other change-detection shortcuts rely on fingerprint rather than verified key material.

Security signals we found

01

PSBT output ownership misclassification

02

Fingerprint vs key derivation mismatch in change detection

03

Contradiction between supplied derivation path and redeem script omission

04

Defensive hardening of change-output heuristics

Risk score

Why this scored 59/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 10/15
Affected reach 8/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.