AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 34 Monero

option to set restore/scan height for epiccash and a hacked in rescan

Public commit record

What the developer wrote

Authored by julian

50/100 · Thin
option to set restore/scan height for epiccash and a hacked in rescan
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This commit adds a user-facing option to set a restore/scan height and perform a rescan for the Epic Cash (Mimblewimble) wallet in Stack Wallet. The code itself is a feature addition, but it uses a risky workaround: during a rescan it temporarily deletes and recovers the wallet from the seed phrase, and it rewrites existing transaction IDs by appending a counter so they don't collide in the local database. There is no direct evidence in the commit that this is a security fix or that it fixes a known vulnerability; it appears to be a functional improvement with some fragile data-handling code.

Recommended action

Treat this as a feature commit rather than a security patch. Reviewers should audit the rescan path for race conditions, verify that deleteEpicWallet() truly only removes local wallet files and not seed backups, validate that the txid-mutation scheme cannot collide with real txids or corrupt transaction notes, and add tests for restore-height edge cases and duplicate detection. End users should ensure they have verified backups before using the new rescan feature.

Security signals we found

01

Temporary deletion and recovery of the Epic Cash wallet during rescan relies on secure storage of mnemonic and password

02

Transaction ID mutation with hardcoded delimiters may break uniqueness assumptions or downstream lookups

03

Fuzzy duplicate detection based on amount/fee/height/type/slateId could incorrectly merge or skip distinct transactions

04

No input validation or bounds checking on the user-supplied restore height beyond int.tryParse and >= 0

05

UI now exposes rescan/height editing for Epic Cash, increasing attack surface for social-engineering or accidental destructive actions

Risk score

Why this scored 34/100

Our methodology →
Potential impact 8/30
Exploitability 5/25
Stealth signal 6/15
Affected reach 7/15
Confidence 5/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.