Skip to content

Single-Esplora trust for all chain facts (tip, MTP, UTXOs, outspends, broadcast) #23

Description

@Rob1Ham

Component: web-wallet/src/client.rs, web-wallet/src/transfer.rs
Severity: Design risk (chain-state desync; affects every security-relevant chain decision)

Summary

The wallet derives all chain facts from one configured Esplora endpoint (deployment.chain_url):

  • tip height (blocks/tip/height)
  • median time past (block/{tip}.mediantime) — used for recovery finality
  • funding/binding UTXOs and outspends — deposit completion, duplicate detection, spend tracking
  • package broadcast (txs/package) and confirmation counting (CONFIRMATION_TARGET = 2)

A malicious, compromised, or merely divergent endpoint can:

  1. Hide a stale-update spend — the wallet never learns its funding was spent (compounds with the missing watcher).
  2. Lie about confirmations — a deposit or incoming transfer is accepted at 2 confirmations purely on the endpoint's word.
  3. Censor package submission — silently drop the CPFP recovery package during the exact window it matters.
  4. Reorg handling is forward-only: bindings record spends but never re-evaluate a previously-recorded confirmed spend that got reorged out.

Suggested direction

Cross-check security-critical facts against a second independent source (another Esplora, the Mercury server's view, or compact block filters), at least for spend detection and confirmation thresholds.

Found during security review of feature/bip448-web-wallet-mutinynet @ 64d2423.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions