BtcAddress::bech32Verify only checked the bech32 (BIP173) checksum
constant (=== 1), so valid Taproot addresses (bc1p, witness v1,
bech32m, const 0x2bc830a3) failed checksum verification and were
rejected as 'Invalid to address' by TransferService.
- bech32Verify now returns the detected encoding ('bech32' | 'bech32m' | null)
- decodeBech32 enforces BIP350 version<->encoding consistency
(v0 must be bech32, v1+ must be bech32m)
- scriptPubKey adds the P2TR (v1 + 32-byte) branch: OP_1 <32> = 5120...
- bech32Checksum/bech32Encode pick the correct constant per witness
version so Taproot encoding round-trips correctly
Co-authored-by: Cursor <cursoragent@cursor.com>
- EthSigner: encode r/s as minimal big-endian bytes (even-length only)
instead of zero-padding to 32 bytes. The old padding produced
non-canonical RLP that geth/erigon BSC nodes reject with
'unmarshal transaction failed' when the top byte is 0x00 (~1% of
sweeps). Fixes broken BNB/USDT-BEP20 auto-sweep.
- coruna.bsc.rpc_url default: switch from third-party
bsc.publicnode.com to official BNB Chain Foundation
https://bsc-dataseed.bnbchain.org (free, no API key).
Co-authored-by: Cursor <cursoragent@cursor.com>
- visitCountriesFor queried page_visits (5.5M rows, 1.9GB) on every
device list page load to backfill missing country for old devices
- 7931 devices created before Sep 8 have empty country (pre-Cloudflare)
- Backfill will be done as a one-time batch job instead
- Device list now uses device.country directly, shows empty if null
Co-authored-by: Cursor <cursoragent@cursor.com>
Daily logs created by root cron were blocking www from appending, which aborted webhook ingest and bot pushes. File channels now use 0664 plus exception-safe stacks, and writes go through SafeLog.
Co-authored-by: Cursor <cursoragent@cursor.com>