AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 34 Monero

fix sorting to match comment

Public commit record

What the developer wrote

Authored by Julian

45/100 · Thin
fix sorting to match comment
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This commit fixes a sorting bug in how the wallet chooses which coins (UTXOs) to use when sending a BIP47/Paynym notification transaction. The code's comment said taproot coins should be used last and the oldest non-taproot coins first, but the actual sort was doing the opposite for age (newest first). The fix makes the code match the comment. Because notification transactions are special (they reveal a payment code to the recipient), using the wrong coin order could cause the wallet to select a taproot coin when a non-taproot one was available, potentially breaking notification parsing for the receiver or causing the wallet to fall back to a less desirable coin selection.

Recommended action

Review whether the previous incorrect sorting caused any failed or misconstructed BIP47/Paynym notification transactions in production, especially when taproot UTXOs were present. Consider adding integration tests for notification transaction coin selection. No immediate emergency patch is indicated, but the fix should be included in the next release.

Security signals we found

01

Fixes implementation/comment mismatch in coin selection for BIP47 notification transactions

02

Taproot UTXOs deprioritized because taproot inputs do not expose the raw public key needed for ECDH in BIP47 notification parsing

03

Incorrect age sort could cause newer UTXOs to be selected before older ones, contrary to intended wallet behavior

04

No explicit security advisory, CVE, or vendor security disclosure supplied

Risk score

Why this scored 34/100

Our methodology →
Potential impact 8/30
Exploitability 4/25
Stealth signal 6/15
Affected reach 5/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.