AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 35 Bitcoin

Restore why change candidacy ignores cosigners

Public commit record

What the developer wrote

Authored by kdmukai

98/100 · Strong
Restore why change candidacy ignores cosigners

Renaming _policy_shape_matches to _is_change_candidate dropped the
reason the candidacy test compares shape alone. Without it, adding the
cosigners to the comparison reads as a harmless tightening.

The old wording named a misannotated fingerprint as what breaks an
output's cosigner resolution. Since #1032, _get_cosigners matches each
key to a global xpub by derivation path alone and never reads the
fingerprint, so the restored note names a misannotated derivation path
instead.
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit only adds explanatory comments to a function that decides whether a Bitcoin transaction output should be treated as 'change' (money going back to the user's own wallet). The code itself is not changed. The new comments warn that comparing cosigner details at this early stage could let a malicious or malformed PSBT (transaction file) hide an output from normal change verification, because one bad derivation path could prevent cosigners from matching. The commit restores documentation that was accidentally lost during an earlier rename, so future developers do not mistakenly 'tighten' this check by adding cosigners here.

Recommended action

No immediate action is required for this commit because it changes only comments. However, reviewers should verify that the actual _is_change_candidate implementation still correctly ignores cosigners and that downstream cosigner validation is performed as described. Consider adding a regression test or code comment guard so the rationale is not lost again in future refactors.

Security signals we found

01

Comment-only change restoring a security rationale for ignoring cosigners in change candidacy

02

Describes a potential bypass where a malformed PSBT could cause an output to skip change-level scrutiny

03

References prior behavior change in PR #1032 regarding fingerprint vs derivation-path cosigner resolution

Risk score

Why this scored 35/100

Our methodology →
Potential impact 8/30
Exploitability 5/25
Stealth signal 7/15
Affected reach 6/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.