AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 47 Monero

- editable locale-aware text for mobile and desktop send flows - parse scanned payment amounts canonically, preserve values across locale changes, validate nonce text, and keep displayed fees separate from editable controller text

Public commit record

What the developer wrote

Authored by Julian

73/100 · Adequate
- editable locale-aware text for mobile and desktop send flows
- parse scanned payment amounts canonically, preserve values across locale changes, validate nonce text, and keep displayed fees separate from editable controller text
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This commit is a hardening and bug-fix patch for Stack Wallet's send screens. It changes how payment amounts are entered, parsed, and displayed so the wallet respects the user's locale (for example, comma vs. period as a decimal separator) without losing or misinterpreting values. It also stops using formatted fee strings for internal calculations, instead keeping fees as raw numeric Amount objects, and adds validation for Ethereum transaction nonces so only whole numbers are accepted. The changes reduce the chance that a user accidentally sends the wrong amount because the app misread a pasted QR-code amount or a locale-formatted number.

Recommended action

Review the new amount parsing helpers (Amount.tryParseCanonicalAmount, formatEditable, tryParseEditable, listenForAmountRelocalization) and the integer_input utility for correctness and edge cases. Test send flows with locales that use comma decimal separators, pasted BIP21/URI amounts with high precision, and Ethereum custom-fee/nonce inputs. Verify that cached fee Amount objects are not accidentally mutated and that preview/build transaction paths use the validated nonce and fee values consistently.

Security signals we found

01

Locale-aware amount parsing and formatting reduces decimal-separator confusion and amount-mismatch bugs

02

Canonical parsing of scanned QR payment amounts with overprecision truncation and null handling

03

Separation of internal fee Amount objects from displayed/formatted fee strings prevents parsing round-trips

04

Ethereum nonce input validated as non-negative integer before transaction preview

05

Custom EIP-1559 fee now required before preview button is enabled

Risk score

Why this scored 47/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 6/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.