fix: Spark generate-next-address diversifier
What changed, and why it matters
This one-line change fixes how the wallet picks the next Spark privacy address. Previously it looked at the current regular receiving address to decide the next Spark address number (diversifier). Now it correctly looks at the current Spark receiving address. Using the wrong starting number could cause address reuse or generate addresses that collide with already-used ones, which weakens the privacy guarantees Spark is designed to provide.
Review whether any already-generated Spark addresses were derived from incorrect diversifier sequences and consider warning users who may have received funds on addresses that could overlap or be reused. Add regression tests that verify generateNextSparkAddress() consults the Spark-specific current address and that diversifier progression does not collide with the change-address boundary.
Security signals we found
Privacy address derivation index sourced from unrelated transparent address index
Potential Spark address reuse or collision with change boundary
Fix targets a privacy-critical code path (Spark / Lelantus Spark)
Evidence from the diff
In generateNextSparkAddress(), the code previously called getCurrentReceivingAddress() to obtain the current diversifier index. That method likely returns the wallet’s transparent/non-Spark receiving address, whose derivation index is unrelated to Spark diversifier allocation. The patch changes the call to getCurrentReceivingSparkAddress(), ensuring the next Spark diversifier is derived from the actual current Spark address. Address reuse or divergent index tracking could result in reduced anonymity set size, potential collisions with change addresses at libSpark.sparkChange, or users unknowingly reusing Spark addresses.
Changed components
lib/wallets/wallet/wallet_mixin_interfaces/spark_interface.dartSpark address generationgenerateNextSparkAddress()Inspect captured patch +1 / −1
diff --git a/lib/wallets/wallet/wallet_mixin_interfaces/spark_interface.dart b/lib/wallets/wallet/wallet_mixin_interfaces/spark_interface.dart
index 0dec8aa..80e19de 100644
--- a/lib/wallets/wallet/wallet_mixin_interfaces/spark_interface.dart
+++ b/lib/wallets/wallet/wallet_mixin_interfaces/spark_interface.dart
@@ -394,7 +394,7 @@ mixin SparkInterface<T extends ElectrumXCurrencyInterface>
Future<Address> generateNextSparkAddress({required bool saveToDB}) async {
final currentDiversifier =
- (await getCurrentReceivingAddress())?.derivationIndex;
+ (await getCurrentReceivingSparkAddress())?.derivationIndex;
// if current is null, start at index 1
int diversifier = (currentDiversifier ?? 0) + 1;
if (diversifier == libSpark.sparkChange) {
Why this scored 41/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.