AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 32 Bitcoin

clear the max selection and revalidate the amount when a payment uri sets the send amount

Public commit record

What the developer wrote

Authored by Craig Raw

50/100 · Thin
clear the max selection and revalidate the amount when a payment uri sets the send amount
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This commit fixes a UI bug in Sparrow Wallet's send screen. When a user clicked a Bitcoin payment link (a 'payment URI') that included a specific amount, the wallet could leave the 'send maximum' option turned on. That combination could lead to an incorrect or confusing transaction being prepared. The patch now clears the 'send maximum' setting and re-checks the amount whenever a payment URI supplies its own amount.

Recommended action

Review whether the same URI-driven amount update can affect other send controllers or coin-selection paths, and add regression tests for payment-URI handling when send-max is active. No urgent security deployment is indicated from the diff alone.

Security signals we found

01

Transaction amount/UI-state inconsistency in a Bitcoin wallet

02

Payment URI (BIP21) handling bypassing existing send-max reset logic

03

Potential for user-confirmed transaction with unintended total amount

Risk score

Why this scored 32/100

Our methodology →
Potential impact 8/30
Exploitability 4/25
Stealth signal 6/15
Affected reach 5/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.