AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Informational 21 Monero

fix masternode list

Public commit record

What the developer wrote

Authored by levoncrypto

28/100 · Opaque
fix masternode list
✓ Subject identifies a change! No meaningful explanatory body
The short version

What changed, and why it matters

This commit changes how the Stack Wallet app finds a user's Firo masternodes. Previously, the wallet guessed masternode identities by scanning local transaction records and 1000-FIRO UTXOs, which could miss masternodes or include wrong transactions. The new code fetches full transaction details from the ElectrumX server and matches each ProRegTx transaction to its exact collateral transaction ID. There is no direct evidence in the commit that this fixes an exploitable security vulnerability; it appears to be a correctness/reliability fix for the masternode list display and management.

Recommended action

Treat this as a functional/reliability fix rather than a critical security patch. Reviewers should verify that getBatchTransactions() responses are validated correctly, that null/ malformed fields cannot crash the wallet, and that a malicious or compromised ElectrumX server cannot spoof masternode ownership by returning crafted proReg.collateralHash values. Consider adding tests for malformed server responses and confirming the fallback collateral-txid logic does not mislead the user.

Security signals we found

01

Change in masternode identity resolution logic

02

New network call to ElectrumX server for batch transaction data

03

Parsing of server-controlled fields (version, type, proReg.collateralHash) used to decide wallet state

04

Removal of local-only ProRegTx detection heuristic

05

Possible functional bug in old code: fallback could include non-ProRegTx txids that downstream code had to filter

Risk score

Why this scored 21/100

Our methodology →
Potential impact 4/30
Exploitability 2/25
Stealth signal 3/15
Affected reach 4/15
Confidence 5/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.