AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 34 Monero

memo/extraid swap support

Public commit record

What the developer wrote

Authored by Julian

35/100 · Opaque
memo/extraid swap support
✓ Descriptive subject! No meaningful explanatory body
The short version

What changed, and why it matters

This commit adds support for 'memos' or 'destination tags' when swapping cryptocurrencies through third-party exchange providers. Some coins (like XRP, XLM, ATOM, etc.) require these extra identifiers so the receiving platform knows which customer account should get the funds. Previously, the wallet always sent these fields as empty/null, which could cause swapped funds to be lost or misattributed when sent to an exchange or custodial address that requires a memo. The change also parses memos from scanned QR payment URIs and shows input fields only when the chosen currency commonly needs one.

Recommended action

Treat this as a functional correctness and potential funds-loss fix rather than an active exploit. Review that the hardcoded ExtraIdCurrencySupport ticker list matches each integrated exchange's actual memo requirements, ensure ChangeNow/Trocador API fields are named correctly, and verify that CypherGoat's rejection path cannot be bypassed by whitespace or null-vs-empty handling. Add integration tests for end-to-end trade creation with memos.

Security signals we found

01

Previously missing extra ID/memo data could be sent to exchange APIs, risking loss of swapped funds for tag-required currencies

02

New validation throws if memos are supplied to CypherGoat, which does not support them

03

Payment URI parsing now extracts memo/destination-tag aliases from QR codes and clipboard

04

UI conditionally shows memo fields only for currencies that commonly require them

Risk score

Why this scored 34/100

Our methodology →
Potential impact 5/30
Exploitability 5/25
Stealth signal 5/15
Affected reach 10/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.