AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 37 Monero

handle mweb 6 required min confirms

Public commit record

What the developer wrote

Authored by Julian

45/100 · Thin
handle mweb 6 required min confirms
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This commit fixes a wallet bug where Litecoin MWEB peg-out transactions could be spent before they were actually valid on the network. MWEB peg-outs require six confirmations to mature, but Stack Wallet was treating them like normal transactions that only need one confirmation. The patch detects these special outputs and enforces the six-block wait, preventing users from accidentally creating invalid or rejected transactions.

Recommended action

No immediate action needed beyond normal review and merge. Users should update to the fixed version to avoid attempting premature MWEB peg-out spends. Consider whether any existing UTXOs in user wallets were incorrectly marked spendable and might need rescanning or balance refresh after update.

Security signals we found

01

Fixes incorrect spendability check that allowed premature spending of MWEB peg-outs

02

Adds protocol-level maturity enforcement for Litecoin MWEB peg-out outputs

03

Includes regression tests for detection and confirmation logic

04

Prevents potential creation of invalid transactions that would be rejected by the network

Risk score

Why this scored 37/100

Our methodology →
Potential impact 8/30
Exploitability 6/25
Stealth signal 5/15
Affected reach 7/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.