Skip to content

Bindings never re-evaluate recorded confirmed spends after reorgs #27

Description

@Rob1Ham

Component: web-wallet/src/client.rs (sync_funding_bindings)
Severity: Chain-state desync (corner case; needs deep reorg of a spend)

Summary

sync_funding_bindings moves each funding binding strictly forward: unspent → spent → confirmed. A spend that was recorded as confirmed and is later reorged out is never re-examined — the binding keeps observation_status = SpentConfirmed (and WithdrawalBroadcastStatus::Confirmed for linked withdrawals) even though the outpoint is unspent again on the new tip.

Consequences:

  • A withdrawal marked Confirmed that got reorged will never be retried (the attempt is terminal).
  • A stale-state spend marked confirmed during a deep reorg permanently poisons the binding view — especially relevant given the always-open update gates (see locktime issue), where spends are the security signal.

Mutinynet's hashrate makes deep reorgs plausible enough to matter for a research deployment; on mainnet this would be mostly theoretical.

Suggested direction

For bindings in spent states, periodically re-check the spending tx's status (or the outpoint itself) and roll back to Unspent/SpentMempool when the chain says so; reopen the linked withdrawal attempt when its spend disappears.

Found during security review of feature/bip448-web-wallet-mutinynet @ 64d2423.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions