Component: web-wallet/src/client.rs (sync_funding_bindings)
Severity: Chain-state desync (corner case; needs deep reorg of a spend)
Summary
sync_funding_bindings moves each funding binding strictly forward: unspent → spent → confirmed. A spend that was recorded as confirmed and is later reorged out is never re-examined — the binding keeps observation_status = SpentConfirmed (and WithdrawalBroadcastStatus::Confirmed for linked withdrawals) even though the outpoint is unspent again on the new tip.
Consequences:
- A withdrawal marked
Confirmed that got reorged will never be retried (the attempt is terminal).
- A stale-state spend marked confirmed during a deep reorg permanently poisons the binding view — especially relevant given the always-open update gates (see locktime issue), where spends are the security signal.
Mutinynet's hashrate makes deep reorgs plausible enough to matter for a research deployment; on mainnet this would be mostly theoretical.
Suggested direction
For bindings in spent states, periodically re-check the spending tx's status (or the outpoint itself) and roll back to Unspent/SpentMempool when the chain says so; reopen the linked withdrawal attempt when its spend disappears.
Found during security review of feature/bip448-web-wallet-mutinynet @ 64d2423.
Component:
web-wallet/src/client.rs(sync_funding_bindings)Severity: Chain-state desync (corner case; needs deep reorg of a spend)
Summary
sync_funding_bindingsmoves each funding binding strictly forward: unspent → spent → confirmed. A spend that was recorded as confirmed and is later reorged out is never re-examined — the binding keepsobservation_status = SpentConfirmed(andWithdrawalBroadcastStatus::Confirmedfor linked withdrawals) even though the outpoint is unspent again on the new tip.Consequences:
Confirmedthat got reorged will never be retried (the attempt is terminal).Mutinynet's hashrate makes deep reorgs plausible enough to matter for a research deployment; on mainnet this would be mostly theoretical.
Suggested direction
For bindings in spent states, periodically re-check the spending tx's status (or the outpoint itself) and roll back to
Unspent/SpentMempoolwhen the chain says so; reopen the linked withdrawal attempt when its spend disappears.Found during security review of
feature/bip448-web-wallet-mutinynet@ 64d2423.