Component: web-wallet/src/transfer.rs (~L1398, L1419)
Severity: Fragility (silent wrong-network acceptance if network config ever changes)
Summary
Transfer receive re-derives the funding address and builds Bip448TransferChainFacts with Network::Signet hardcoded:
let funding_address = Address::from_script(&funding_output.script_pubkey, Network::Signet)?;
...
Ok(Bip448TransferChainFacts {
expected_network: Network::Signet,
...
})
model.rs pins NETWORK = "signet", so this is consistent today — but the constant and these call sites can drift: change the deployment network and the receive path silently re-derives signet addresses (mutinynet HRPs happen to overlap signet, so a mismatch may not even error), or rejects valid transfers for no visible reason.
Suggested direction
Thread the configured network through instead of hardcoding; assert chain_url network (e.g., via genesis hash check at startup) against it.
Found during security review of feature/bip448-web-wallet-mutinynet @ 64d2423.
Component:
web-wallet/src/transfer.rs(~L1398, L1419)Severity: Fragility (silent wrong-network acceptance if network config ever changes)
Summary
Transfer receive re-derives the funding address and builds
Bip448TransferChainFactswithNetwork::Signethardcoded:model.rspinsNETWORK = "signet", so this is consistent today — but the constant and these call sites can drift: change the deployment network and the receive path silently re-derives signet addresses (mutinynet HRPs happen to overlap signet, so a mismatch may not even error), or rejects valid transfers for no visible reason.Suggested direction
Thread the configured network through instead of hardcoding; assert
chain_urlnetwork (e.g., via genesis hash check at startup) against it.Found during security review of
feature/bip448-web-wallet-mutinynet@ 64d2423.