AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 31 Monero

fix masternode utxo freeze handling

Public commit record

What the developer wrote

Authored by Julian

45/100 · Thin
fix masternode utxo freeze handling
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This commit fixes how Stack Wallet handles Firo masternode collateral UTXOs. Previously, the wallet could auto-freeze a UTXO, the user could deliberately unfreeze it, and then a later sync would re-freeze it automatically. The patch prevents that automatic re-freezing once a user has unfrozen a UTXO, while still allowing a first-time auto-freeze when masternode collateral is newly detected. It also improves the labels shown to users when collateral is detected with certainty versus only suspected. The pubspec.lock changes update unrelated dependencies and are not directly security-relevant.

Recommended action

Review the freeze/unfreeze UI code to confirm it never clears blockedReason, since the new userUnfroze heuristic depends on that invariant. Consider adding a dedicated userUnfroze boolean field instead of inferring intent from leftover metadata. Verify that the Firo masternode detection RPC failure path still blocks the UTXO as intended. The dependency updates in pubspec.lock should be reviewed separately for supply-chain relevance, but they are outside the scope of this fix.

Security signals we found

01

Auto-freeze logic could previously override an explicit user unfreeze, risking denial-of-spend or unexpected locked funds.

02

Masternode collateral UTXOs, if spent, invalidate the masternode; the patch improves labeling and preserves user intent.

03

The userUnfroze heuristic depends on the invariant that unfreezing only flips isBlocked and does not clear blockedReason; if that invariant is violated elsewhere, the protection collapses.

04

No input validation, cryptographic, or network-layer changes are present in the diff.

Risk score

Why this scored 31/100

Our methodology →
Potential impact 8/30
Exploitability 4/25
Stealth signal 3/15
Affected reach 5/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.