AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 39 Monero

Merge branch 'staging' into dev/navidr/spark-name-verification

Public commit record

What the developer wrote

Authored by Julian

60/100 · Adequate
Merge branch 'staging' into dev/navidr/spark-name-verification
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
The short version

What changed, and why it matters

This commit merges several changes into a development branch. The most notable security-relevant change is a fix for how the Trocador exchange service routes traffic: it now automatically uses Tor (an anonymity network) when the user has Tor enabled, instead of callers hardcoding non-Tor connections. Previously, exchange calls always used the regular internet even if Tor was turned on, which could leak a user's IP address and trading activity to Trocador. The commit also updates the SOCKS5 proxy library and adds a test to verify that proxy requests correctly send hostnames (including .onion addresses) to the SOCKS server. Separately, it adds a small UI convenience: when paying a Spark private address, a payment message is auto-filled into the memo field, matching Firo-QT's behavior.

Recommended action

Review the new Tor routing logic to ensure `_useTor` cannot be bypassed and that `TorService.sharedInstance.getProxyInfo()` returns a valid proxy before use. Verify the new .onion authority belongs to Trocador and is not a typo or malicious substitution. Confirm the `socks5_proxy` 2.x upgrade does not break other SOCKS consumers in the app. For the Spark memo change, ensure `paymentData.message` is sanitized before being placed in the memo controller to avoid UI injection or unexpected length issues.

Security signals we found

01

Trocador exchange API previously forced clearnet (`isOnion: false`) at every call site, bypassing Tor even when enabled

02

New `_useTor` getter centralizes Tor routing decision based on app feature flag and user preference

03

Onion service address rotated to a new v3 .onion hostname

04

SOCKS5 proxy library upgraded from a dev pre-release to a stable release

05

New unit test confirms HTTP client sends hostname (including .onion) to SOCKS5 proxy rather than resolving locally

06

Spark memo auto-fill copies payment URI `message` field into memo for Spark addresses

Risk score

Why this scored 39/100

Our methodology →
Potential impact 8/30
Exploitability 7/25
Stealth signal 6/15
Affected reach 9/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.