Zcashd Security Announcement 2019-03-19

So the user’s experience of issuing a z_sendmany to forward on an attacker-modified note that the user had received would result in the user experiencing a z_getoperationresult of “failed” with error “logic error: witness of wrong element for joinsplit input”. But that’s only if the daemon decided to use that note. If it picked another one, the user might be none-the-wiser. Hence, better not to trust the balance on Sprout addresses until you’ve installed 2.0.4 [edit by @daira: and ran once with -rescan].

3 Likes