AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 68 Bitcoin

check stored transaction block hashes against the header store when a wallet is first fetched

Public commit record

What the developer wrote

Authored by Craig Raw

50/100 · Thin
check stored transaction block hashes against the header store when a wallet is first fetched
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This commit fixes a gap in Sparrow Wallet's protection against Bitcoin blockchain reorganizations ('reorgs'). Previously, if a wallet was closed while a reorg happened, the wallet could reopen still believing an old, replaced block proved its transaction—because the server kept reporting the same block height. The change now compares stored transaction block hashes against the local header store when a wallet is first fetched, and re-proves any transaction whose recorded block no longer matches the chain. This prevents the wallet from displaying a transaction as confirmed when the proof is actually stale or invalid.

Recommended action

Users should upgrade to a Sparrow Wallet release containing this commit. Wallet operators relying on transaction verification should ensure the header store is kept in sync. Developers should review whether any other persisted proof metadata (e.g., labels, UTXO selection decisions) assumes block permanence.

Security signals we found

01

Fixes stale proof acceptance after blockchain reorganization

02

Adds verification of stored transaction block hashes against local header store

03

Forces re-proof when stored block hash differs from header store at same height

04

Prevents wallet from showing transactions as confirmed on orphaned blocks

05

Includes defensive tests covering positive, negative, and edge cases

Risk score

Why this scored 68/100

Our methodology →
Potential impact 22/30
Exploitability 12/25
Stealth signal 10/15
Affected reach 12/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.