prevent a locked wallet from signing a message, opening the dialog in verify only mode
What changed, and why it matters
This commit fixes a small UI bug in Sparrow Wallet. Previously, if you selected a locked (password-protected) wallet and tried to open the 'Sign/Verify Message' screen, the app would still open the signing screen as if it could sign. The fix checks whether the wallet is locked and, if so, opens the screen in verify-only mode instead. This prevents a user from being misled into thinking they can sign a message while the wallet is locked, and it avoids a confusing or potentially unsafe UI state.
No urgent action required beyond applying the patch. Users should upgrade to the version containing this commit. Developers may want to audit other wallet actions that should similarly be disabled when the wallet is locked.
Security signals we found
UI state guard tightened to prevent signing dialog on locked wallet
Verify-only fallback used when wallet is locked
No cryptographic or key-handling changes
Single-line conditional change in controller logic
Evidence from the diff
In AppController.signVerifyMessage(), the guard for creating a signing-capable MessageSignDialog was changed from selectedWalletForm != null to selectedWalletForm != null && !selectedWalletForm.isLocked(). When the selected wallet form is locked, execution falls through to the verify-only branch. This is a defensive correctness fix: a locked wallet cannot sign because private keys are unavailable, so presenting a signing dialog was inappropriate. The patch is minimal and partial in the sense that it only addresses the locked-wallet case; it does not indicate any deeper cryptographic flaw.
Changed components
src/main/java/com/sparrowwallet/sparrow/AppController.javaMessageSignDialogWalletForm.isLocked()Inspect captured patch +1 / −1
### src/main/java/com/sparrowwallet/sparrow/AppController.java
@@ -1505,7 +1505,7 @@ private void openSettings(SettingsGroup settingsGroup) {
public void signVerifyMessage(ActionEvent event) {
MessageSignDialog messageSignDialog = null;
WalletForm selectedWalletForm = getSelectedWalletForm();
- if(selectedWalletForm != null) {
+ if(selectedWalletForm != null && !selectedWalletForm.isLocked()) {
Wallet wallet = selectedWalletForm.getWallet();
if(wallet.getPolicyType() == PolicyType.SINGLE_HD || wallet.getPolicyType() == PolicyType.SINGLE_SP) {
//Can sign and verifyWhy this scored 52/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.