Skip to content

BitWindow wallet & cheque API (4 of 4): 2 fixes from a security review - #2150

Open
giaki3003 wants to merge 2 commits into
LayerTwo-Labs:masterfrom
giaki3003:fix/w5-area-bwsrv-wallet-r3
Open

giaki3003 wants to merge 2 commits into
LayerTwo-Labs:masterfrom
giaki3003:fix/w5-area-bwsrv-wallet-r3

Conversation

@giaki3003

Copy link
Copy Markdown
Contributor

A set of 2 independent fixes to the BitWindow wallet & cheque API, stacked on one branch so they can be reviewed together and cherry-picked individually. Based on current master; the branch builds and its tests pass at the tip (2 files changed, 76 insertions(+), 1 deletion(-)).

Fixes (oldest first)

  • 9d112d266 Confirmation: BitWindow ListSidechainDeposits returns deposit history while locked
  • c747e41f4 BitWindow GetStats leaks per-wallet aggregate analytics while wallet is locked

Each commit is self-contained — git cherry-pick <sha> works for any of them. Happy to split, reorder, or drop any. Finding reports for individual fixes available on request.

giaki3003 and others added 2 commits August 30, 2026 22:46
…history while locked

Bug: w5-20260627-2044-openclaw-confirm-kimiclaw- (primary)
Finding: findings/20260627-2044-openclaw-confirm-kimiclaw-drivechain-frontends-bitwindow-listsidechaindeposits-locked-leak.md
Severity: R3-T4

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
(cherry picked from commit fa9eb23)
…wallet is locked

Bug: w5-20260628-0642-kimiclaw-confirm-glmclaw-d (primary)
Finding: findings/20260628-0642-kimiclaw-confirm-glmclaw-drivechain-frontends-bitwindow-getstats-locked-aggregate-leak.md
Severity: R3-T4

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
(cherry picked from commit fc0592f)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant