AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 42 Monero

Fix Spark mint fee subtraction edge case

Public commit record

What the developer wrote

Authored by Reuben Yap

45/100 · Thin
Fix Spark mint fee subtraction edge case
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This commit fixes how transaction fees are subtracted from Spark mint outputs. The old code could mis-handle cases where an output was too small to cover its share of the fee, potentially leaving leftover fees unassigned or removing outputs incorrectly. The new code walks through outputs one by one, recalculating each remaining output's fair share of the fee, and cleanly removes outputs that cannot cover their portion. It also adds a guard to drop the whole input set if every output gets removed because fees exceed the mint amount.

Recommended action

Review the new fee-subtraction loop against formal invariants (total fee deducted equals nFeeRet, no output goes negative, no infinite loop) and add unit tests covering edge cases such as: one output smaller than fee share, all outputs smaller than fee share, fee exactly equal to total mint value, and fee not evenly divisible by output count. Consider whether the removed-output value should be subtracted from remainingFee in full or only up to the fee share.

Security signals we found

01

Fee-allocation logic bug in privacy-focused Spark minting

02

Potential for transaction construction to produce invalid or uneconomical outputs

03

Edge case where outputs smaller than fee share are removed without redistributing fee

04

Added defensive check to discard a coin selection candidate when all outputs are consumed by fees

Risk score

Why this scored 42/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 6/15
Affected reach 7/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.