AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 40 Monero

fix: checkBlockUTXO only checking the specific UTXO output

Public commit record

What the developer wrote

Authored by sneurlax

62/100 · Adequate
fix: checkBlockUTXO only checking the specific UTXO output
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
The short version

What changed, and why it matters

This commit fixes a bug in how Stack Wallet checks whether a Particl coin can be spent. Previously, the wallet looked at every output in the entire transaction to decide if a single coin (UTXO) was blocked. If any unrelated output in the same transaction was a blind/confidential/data/staking output, the wallet would wrongly mark the user's spendable coin as blocked too. Now it only checks the specific output that actually belongs to the coin in question. This is a correctness fix that could prevent coins from being incorrectly frozen or hidden from the user, but it does not appear to be a direct theft or remote-code-execution vulnerability.

Recommended action

Review whether the missing-output case (orElse returning null) is handled safely downstream, and consider adding a bounds/validation check for vout. Otherwise, this is a straightforward correctness fix that should be merged and tested against real Particl transactions containing mixed output types.

Security signals we found

01

Incorrect blocking logic could cause denial-of-spend for legitimate UTXOs

02

Previously scanned all transaction outputs instead of the UTXO-specific output

03

No input validation or bounds check added for vout against outputs length

04

No explicit security framing in commit message or diff comments

Risk score

Why this scored 40/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 6/15
Affected reach 5/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.