AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 44 Monero

fix(paynym): handle taproot inputs in notification tx parsing/building

Public commit record

What the developer wrote

Authored by sneurlax

62/100 · Adequate
fix(paynym): handle taproot inputs in notification tx parsing/building
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
The short version

What changed, and why it matters

This commit fixes how Stack Wallet handles Bitcoin PayNym notification transactions when the wallet has taproot-style coins. PayNym notification transactions need the sender's raw public key to set up a private payment channel. Taproot inputs hide that raw public key, so the previous code could crash or fail to parse/build notifications when taproot coins were selected. The fix avoids picking taproot coins for notification transactions and gracefully returns null instead of crashing when a taproot input is encountered during parsing.

Recommended action

Review whether returning null silently in notification parsing could cause higher-level code to ignore a valid but taproot-funded notification, and ensure users are warned if their wallet has only taproot UTXOs when creating a PayNym notification. Consider adding tests covering taproot-only and mixed UTXO scenarios.

Security signals we found

01

Null-dereference/crash avoided by removing non-null assertion on public key extraction

02

Cryptographic protocol limitation addressed: taproot inputs do not reveal raw public keys needed for BIP47 ECDH

03

UTXO selection changed to prefer non-taproot outputs for notification transactions

04

Graceful failure added when taproot inputs are used in notification parsing/building

Risk score

Why this scored 44/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 6/15
Affected reach 7/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.