allow owner address to equal voting address
What changed, and why it matters
This small change relaxes a wallet rule for the Firo cryptocurrency. Previously, when setting up a masternode-like service, the wallet required the 'owner address' to be different from the 'voting address'. Now it allows them to be the same. The change itself does not look like a typical security bug; it is more likely a feature or bug-fix for valid user setups. However, because it removes a deliberate separation between two addresses, it could slightly weaken privacy or governance separation in some configurations. There is no evidence in the commit of a vulnerability, exploit, or security disclosure.
Treat as a low-signal product change unless additional context shows the prior restriction was security-critical. Review Firo masternode documentation to confirm whether owner/voting address separation is a protocol requirement or merely a best practice. If it is required, this change could violate protocol rules and should be reverted or gated by user confirmation. Otherwise, no immediate security action is needed.
Security signals we found
Removal of address distinctness check between owner and voting addresses
Change affects Firo masternode address derivation logic
No input validation, cryptographic, or memory-safety changes present
No mention of security, CVE, vulnerability, or researcher attribution in commit
Evidence from the diff
In lib/wallets/wallet/impl/firo_wallet.dart, the isUsableOwner predicate is changed so that address.value != votingAddress is no longer enforced. The error message is updated accordingly. This permits the owner address and voting address to be identical when deriving a Firo masternode owner address. The diff is a relaxation of an existing constraint, not an injection of unsafe code. Without additional context, this appears to be a product/logic change rather than a security patch. It may reduce the intended separation of roles (owner vs. voting) for Firo masternodes, but no exploit path is visible from the diff alone.
Changed components
lib/wallets/wallet/impl/firo_wallet.dartFiro masternode owner address derivationInspect captured patch +3 / −4
### lib/wallets/wallet/impl/firo_wallet.dart
@@ -1023,8 +1023,7 @@ class FiroWallet<T extends ElectrumXCurrencyInterface> extends Bip39HDWallet<T>
bool isUsableOwner(Address? address) =>
address != null &&
address.value != collateralAddress &&
- address.value != payoutAddress &&
- address.value != votingAddress;
+ address.value != payoutAddress;
Address? ownerAddress = await getCurrentReceivingAddress();
const maxOwnerAttempts = 32;
@@ -1034,8 +1033,8 @@ class FiroWallet<T extends ElectrumXCurrencyInterface> extends Bip39HDWallet<T>
}
if (ownerAddress == null || !isUsableOwner(ownerAddress)) {
throw Exception(
- "Could not derive owner address distinct from collateral, payout "
- "and voting addresses.",
+ "Could not derive owner address distinct from collateral and payout "
+ "addresses.",
);
}
Why this scored 24/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.