Skip to content
This repository has been archived by the owner on Feb 26, 2021. It is now read-only.

Light Wallet can generate an already generated address which causes funds to be stolen. #938

Closed
patchthecode opened this issue Jan 2, 2018 · 1 comment

Comments

@patchthecode
Copy link

Prerequisites

If you are not suggesting a feature, you must be able to check all of the following (place an x inside the brackets to check the box):

  • [ YES ] I confirm that this is an issue with the IOTA Wallet and not an exchange
  • [ YES ] I confirm that this is an issue with the wallet, not IRI
  • [ NO ] I confirm that this is not an issue related to stolen/lost funds

When snapshotting happens, it seems that the wallet will generate a previously generated address.
The has allows thousands of funds to be stolen from many users.
Can this be fixed urgently?

A user will not expect that the wallet itself will generate an already used address.

@rajivshah3
Copy link
Member

This cannot be fixed as the wallet does not remember how many addresses were generated before the snapshot. Other wallets however aim to implement that feature. Additionally, please do not report issues like this if you cannot check all of the boxes.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants