AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 60 Monero

- Treat maxFeePerGas as the total protocol cap for presets and custom fees. Validate it against base and priority fees, and use the same cap and gas limit for transaction construction and maximum-fee estimates.

Public commit record

What the developer wrote

Authored by Julian

65/100 · Adequate
- Treat maxFeePerGas as the total protocol cap for presets and custom fees. Validate it against base and priority fees, and use the same cap and gas limit for transaction construction and maximum-fee estimates.

- Localize custom fee input and reject malformed gas limits.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
The short version

What changed, and why it matters

This commit fixes how Stack Wallet handles Ethereum transaction fees. Previously, the app appears to have treated 'max base fee' and 'priority fee' as separate fields, which could let users set a priority fee higher than the total fee cap or set a total cap too low to cover the network's base fee. The patch makes the 'max fee per gas' the hard total cap, validates that the priority fee fits inside it, and uses the same cap and gas limit both when building the transaction and when showing the maximum possible fee. It also improves input validation so malformed gas limits are rejected and fee numbers are properly localized for different languages.

Recommended action

Review and merge after confirming tests pass. The change is defensive and improves fee safety, but verify that preset fee estimates still display intuitively to users and that the new maxFeePerGas label is understood as a total cap. Consider adding a changelog note because the UI terminology changed.

Security signals we found

01

Fee-cap validation added: maxPriorityFeePerGas must not exceed maxFeePerGas

02

Total cap semantics corrected: maxFeePerGas is now base + priority inclusive cap

03

Transaction construction and fee estimate now use consistent gasLimit and maxFeePerGas

04

Malformed gas-limit input is rejected instead of silently coerced

05

Custom fee form emits null state when inputs are invalid, preventing downstream use of bad values

Risk score

Why this scored 60/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.