fix: temp input script index in particl buildTransaction
What changed, and why it matters
This commit fixes a small but meaningful bug in how Stack Wallet builds Particl cryptocurrency transactions. The code was accidentally reading the script signature from the first input for every input, instead of reading the correct one for each input. That could corrupt the transaction data the wallet stores or signs, potentially causing invalid transactions, failed sends, or in the worst case a security issue if the wrong data is signed. The fix changes one index from 'first input' to 'current input'.
Review the full buildTransaction flow to confirm InputV2 objects are only used internally and that no signed transaction or UTXO selection logic relies on the now-corrected scriptSig. Add regression tests covering multi-input Particl transactions and verify that pre-fix builds produced invalid transactions rather than silently valid but wrong ones. Consider auditing other wallet implementations for similar .first vs index i patterns.
Security signals we found
Wrong index used inside loop (first instead of i)
Transaction input scriptSig data mismatch
Potential for invalid or malleable transaction construction
No explicit security disclosure in commit message
Evidence from the diff
In lib/wallets/wallet/impl/particl_wallet.dart, inside a loop iterating over txb.inputs with index i, the code was using txb.inputs.first.script?.toHex when constructing each InputV2. The patch changes it to txb.inputs[i].script?.toHex. This is a classic off-by-one / wrong-index bug where loop-local data was being replaced by the first element. For transaction building, using the wrong scriptSig for an input means the resulting InputV2 objects do not match the actual UTXOs being spent. Depending on how those InputV2s are later used for signing, verification, or serialization, this could produce invalid transactions or, in a worst-case cryptographic scenario, sign unintended data.
Changed components
lib/wallets/wallet/impl/particl_wallet.dartParticlWallet.buildTransactionInputV2 construction for Particl transactionsInspect captured patch +1 / −1
diff --git a/lib/wallets/wallet/impl/particl_wallet.dart b/lib/wallets/wallet/impl/particl_wallet.dart
index d1ed90c..2d16f0b 100644
--- a/lib/wallets/wallet/impl/particl_wallet.dart
+++ b/lib/wallets/wallet/impl/particl_wallet.dart
@@ -451,7 +451,7 @@ class ParticlWallet<T extends ElectrumXCurrencyInterface>
tempInputs.add(
InputV2.isarCantDoRequiredInDefaultConstructor(
- scriptSigHex: txb.inputs.first.script?.toHex,
+ scriptSigHex: txb.inputs[i].script?.toHex,
scriptSigAsm: null,
sequence: 0xffffffff - 1,
outpoint: OutpointV2.isarCantDoRequiredInDefaultConstructor(
Why this scored 41/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.