AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 29 Monero

Masternode collateral fee check and send cancel black screen

Public commit record

What the developer wrote

Authored by levoncrypto

73/100 · Adequate
Masternode collateral fee check and send cancel black screen

- Show exact fee amount when transparent balance equals exactly 1000
FIRO, preventing a silent consolidation that would result in a
sub-1000 UTXO unusable as collateral
- Move wasCancelled outside try{} so catch block can read it
- Skip building-dialog pop in catch when user already cancelled,
preventing a double-pop that caused a black screen
- Remove redundant Navigator.pop() from desktop_send onCancel callback
(BuildingTransactionDialog already pops itself)
- Show loading overlay via showLoading on desktop when send_view is
opened from a non-desktop flow (e.g. masternodes collateral prep)
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This commit fixes user-experience and minor reliability bugs in Stack Wallet's masternode collateral flow. It prevents users from accidentally creating a FIRO transaction that leaves them with less than the required 1000 FIRO collateral because of a hidden network fee. It also fixes a 'black screen' bug that could happen if a user cancels a send while the app is still building the transaction. A small Particl wallet change adds a flag but its security effect is unclear from the diff alone.

Recommended action

Review the `isParticl: true` change in particl_wallet.dart to confirm it does not alter signature hashing, prefix handling, or coin-selection in an unsafe way. Verify the fee-estimation fallback (`roughFeeEstimate`) is reasonable for all supported Particl/FIRO network conditions. Test the masternode collateral flow with exactly 1000 FIRO and with a user cancelling during transaction building on both desktop and mobile.

Security signals we found

01

UI logic change that prevents user from accidentally creating an unusable masternode collateral UTXO due to unaccounted network fees

02

State-scope fix: cancellation flag moved outside try{} so catch{} can read it

03

Double-pop / black-screen bug fixed by skipping Navigator.pop() when user already cancelled

04

Redundant Navigator.pop() removed from desktop send cancel callback

05

New boolean flag `isParticl: true` added to transaction input construction without visible validation or test changes

Risk score

Why this scored 29/100

Our methodology →
Potential impact 8/30
Exploitability 2/25
Stealth signal 3/15
Affected reach 5/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.