AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Informational 23 Monero

Make restore height optional, use polyseed restore date and add bip39 support

Public commit record

What the developer wrote

Authored by Keeqler

50/100 · Thin
Make restore height optional, use polyseed restore date and add bip39 support
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This commit changes how users restore a Monero wallet in the Skylight Wallet app. It makes the 'restore height' field optional, automatically fills it for newer Polyseed seeds, and adds support for restoring from BIP39-style mnemonic phrases (common 12/24-word seeds). The changes are mostly usability improvements, but they touch sensitive wallet-recovery code and introduce new dependencies for seed handling. There is no direct evidence in the commit of a security vulnerability, but the new BIP39 conversion logic and the changed restore flow deserve careful review because mistakes here could lead to users restoring the wrong wallet or leaking keys.

Recommended action

Treat this as a code-review priority area rather than an incident. Independently verify that the BIP39 derivation path and Ed25519 reduction in `lib/util/bip39.dart` match Monero's expected spend-key format and do not produce weak or colliding keys. Confirm that defaulting restore height to 0 cannot cause users to miss funds or accidentally expose transaction history. Review the new dependencies for supply-chain risk and ensure the `hashlib` override does not break other cryptographic assumptions. No patch or emergency response is indicated by the diff alone.

Security signals we found

01

New cryptographic key derivation code added (BIP39 -> BIP32 -> Monero spend key)

02

Restore height now optional and defaults to 0 when parsing fails

03

New third-party dependencies introduced for seed and key derivation

04

Polyseed birthday timestamp converted to restore height via a hard-coded month-to-height mapping

05

Sensitive wallet-recovery flow refactored with changed error handling

Risk score

Why this scored 23/100

Our methodology →
Potential impact 4/30
Exploitability 3/25
Stealth signal 2/15
Affected reach 5/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.