AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 35 Monero

fix: ordinals by looking up tx info directly

Public commit record

What the developer wrote

Authored by sneurlax

80/100 · Strong
fix: ordinals by looking up tx info directly

TODO: remove (comment?) dead code
litescribe_api.dart, litescribe_response.dart, address_inscription_response.dart are now orphaned
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This commit changes how the Stack Wallet app detects Litecoin Ordinals (a type of digital collectible). Instead of asking a third-party service (litescribe.io) which inscriptions belong to a wallet address, the app now asks its own ord-litecoin.stackwallet.com server directly about each transaction output. The change removes a heuristic that blocked small outputs as 'possible ordinals' only when an address-level check passed, and instead checks each output directly. There is no clear security bug being fixed, but the commit does switch data sources and removes some protective logic around small-value outputs.

Recommended action

Treat this as a routine refactor with supply-chain/trust implications. Review whether the new ord-litecoin.stackwallet.com endpoint is authenticated or pinned, validate that server-returned inscription IDs and content URLs cannot inject malicious data into the wallet's UTXO blocking or UI layers, and complete the TODO to remove or clearly deprecate the orphaned litescribe files. No immediate security patch appears required from the diff alone.

Security signals we found

01

Removed third-party API dependency (litescribe.io) for inscription data

02

Added direct queries to vendor-controlled ord-litecoin.stackwallet.com server

03

UTXO blocking now uses per-output inscription lookup instead of address-level lookup

04

Small-value UTXO heuristic (<=10000 sats) retained as fallback 'possible ordinal' block

05

No visible certificate pinning or response authentication in new HTTP client usage

06

JSON fields cast with as String? / as int? with default fallbacks; missing validation of server-provided txid/address/content

07

Dead-code TODO left in commit message for litescribe-related files

Risk score

Why this scored 35/100

Our methodology →
Potential impact 8/30
Exploitability 5/25
Stealth signal 6/15
Affected reach 7/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.