fix: witness field parsing in particl updateTransactions
What changed, and why it matters
This commit fixes how the Particl wallet reads transaction input data, specifically the 'witness' field, by switching to a dedicated parser instead of manually pulling fields. The change suggests the previous code may have misread or mishandled witness data, which could cause incorrect transaction details, failed transactions, or wallet display errors for Particl users. There is no claim in the commit that this is a security fix, and no independent security analysis is supplied.
Review the InputV2.fromElectrumxJson implementation to confirm it correctly handles all expected ElectrumX response shapes, including missing or malformed witness arrays. Test Particl wallet transaction parsing against real and edge-case transactions. Treat as a reliability/robustness fix unless further review shows a concrete security impact.
Security signals we found
Parsing fix for witness transaction field
Replacement of manual JSON field extraction with dedicated factory parser
Potential for incorrect input attribution or transaction handling if witness data was misread
Evidence from the diff
The patch replaces a manual construction of InputV2 using individual JSON fields (scriptSig, sequence, witness, innerRedeemscriptAsm, etc.) with a factory constructor InputV2.fromElectrumxJson that parses the ElectrumX JSON response directly. The commit title says this fixes ‘witness field parsing in particl updateTransactions’. The diff alone does not show what the parsing bug was, only that the old code cast map[‘witness’] as String? and map[‘innerRedeemscriptAsm’] as String? directly, while the new code delegates parsing to a presumably more robust method. Potential issues from incorrect witness parsing include wrong input attribution, incorrect balance calculations, or transaction construction failures, but the diff does not demonstrate an exploitable vulnerability.
Changed components
lib/wallets/wallet/impl/particl_wallet.dartParticlWallet transaction update logicInputV2 input parsingInspect captured patch +3 / −8
diff --git a/lib/wallets/wallet/impl/particl_wallet.dart b/lib/wallets/wallet/impl/particl_wallet.dart
index 6310bda..d1ed90c 100644
--- a/lib/wallets/wallet/impl/particl_wallet.dart
+++ b/lib/wallets/wallet/impl/particl_wallet.dart
@@ -239,17 +239,12 @@ class ParticlWallet<T extends ElectrumXCurrencyInterface>
addresses.addAll(prevOut.addresses);
}
- InputV2 input = InputV2.isarCantDoRequiredInDefaultConstructor(
- scriptSigHex: map["scriptSig"]?["hex"] as String?,
- scriptSigAsm: map["scriptSig"]?["asm"] as String?,
- sequence: map["sequence"] as int?,
+ InputV2 input = InputV2.fromElectrumxJson(
+ json: map,
outpoint: outpoint,
- valueStringSats: valueStringSats,
addresses: addresses,
- witness: map["witness"] as String?,
+ valueStringSats: valueStringSats,
coinbase: coinbase,
- innerRedeemScriptAsm: map["innerRedeemscriptAsm"] as String?,
- // Need addresses before we can know if the wallet owns this input.
walletOwns: false,
);
Why this scored 34/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.