AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 25 Monero

Add QR restore

Public commit record

What the developer wrote

Authored by Justin Ehrenhofer

28/100 · Opaque
Add QR restore
✓ Subject identifies a change! No meaningful explanatory body
The short version

What changed, and why it matters

This commit removes a local QR-restore parser and switches the wallet to use a shared parser from another package. It also fixes two unrelated bugs in the send screen: one that could permanently block fee estimates after a single failure, and another that displayed tiny 'Max' balances in scientific notation, breaking sending. There is no obvious security vulnerability in the diff itself; the main concern is whether the new shared parser is as safe as the old one, which cannot be judged from this commit alone.

Recommended action

Review the implementation of parseRestoreQr in the wallet_domain package to confirm it preserves the same URI scheme allow-list, query decoding fallback, and seed/height validation as the removed local code. Also verify that the new package is pinned to a trusted version and that no additional schemes or relaxed parsing were introduced.

Security signals we found

01

Parser logic moved to an external package (wallet_domain) without showing the new implementation

02

Old parser used Uri.decodeQueryComponent with a fallback on failure; new parser behavior is not visible in this commit

03

No input validation or sanitization changes are visible in the consuming code

04

Two functional bug fixes in fee estimation and amount formatting

Risk score

Why this scored 25/100

Our methodology →
Potential impact 5/30
Exploitability 2/25
Stealth signal 2/15
Affected reach 5/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.