AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 41 Monero

fix: temp input script index in particl buildTransaction

Public commit record

What the developer wrote

Authored by sneurlax

42/100 · Thin
fix: temp input script index in particl buildTransaction
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body! Contains work-in-progress language
The short version

What changed, and why it matters

This commit fixes a small but meaningful bug in how Stack Wallet builds Particl cryptocurrency transactions. The code was accidentally reading the script signature from the first input for every input, instead of reading the correct one for each input. That could corrupt the transaction data the wallet stores or signs, potentially causing invalid transactions, failed sends, or in the worst case a security issue if the wrong data is signed. The fix changes one index from 'first input' to 'current input'.

Recommended action

Review the full buildTransaction flow to confirm InputV2 objects are only used internally and that no signed transaction or UTXO selection logic relies on the now-corrected scriptSig. Add regression tests covering multi-input Particl transactions and verify that pre-fix builds produced invalid transactions rather than silently valid but wrong ones. Consider auditing other wallet implementations for similar .first vs index i patterns.

Security signals we found

01

Wrong index used inside loop (first instead of i)

02

Transaction input scriptSig data mismatch

03

Potential for invalid or malleable transaction construction

04

No explicit security disclosure in commit message

Risk score

Why this scored 41/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 7/15
Affected reach 6/15
Confidence 5/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.