Ported from Digibyte.X/dgb-wallet @ 989a2696.
BIP32 builds the master key as HMAC-SHA512("Bitcoin seed", seed). DigiByte's
official 2018-19 Android/iOS wallets were BreadWallet forks and used
"DigiByte seed" as the HMAC key instead, so the same twelve words produce a
completely different key tree — every address differs, and a standard scan
finds nothing at all. Anyone importing one of those seeds into Aegis got a
valid, empty address and a zero balance with no way to tell why. Same shape
as the Bitcoin.com coin-type-0 problem.
- rootFromSeed() in the vendored lib/dgb/core/hd.js takes an optional HMAC
key, matching upstream, and exports HMAC_BITCOIN_SEED /
HMAC_DIGIBYTE_SEED.
- lib/import-derive.js grows the same option, since that is what actually
derives the address on an import, and importWallet records the variant on
the spec so the entry says which tree its stored address came from.
- The path scanner added in 0.24.0 now covers DigiByte: all four purposes
under the standard key, plus m/0' and BIP44 under the legacy one. So the
answer to "which tree holds my coins" is a scan rather than a guess, and
the Use button carries the key along with the path.
Verified against an independent HMAC-SHA512 computation, and end to end: the
same mnemonic gives DG1Khh…N1i under the standard key and DMWQ1g…PHse under
the DigiByte key, both valid, with m/0' deriving DGAf4M…Wyn.
Also fixes a coupling this exposed: lib/import-derive.js derives taproot
addresses but never called initEccLib, relying on chain-btc.js (and formerly
lib/dgb/core/address.js, before it went lazy here) doing it at load time. It
now installs the schnorr backend itself, once, so its taproot output no
longer depends on an unrelated module's import order.
The gap-limit change in 0a5d7ade (scan gap 200/100 for DigiScope parity) is
upstream-only for now — Aegis's imported DGB adapter watches a single stored
address rather than scanning a gap.
32 lines
No EOL
1.6 KiB
JavaScript
32 lines
No EOL
1.6 KiB
JavaScript
import { bip32, hmac, sha512 } from '../deps.js';
|
|
import { digibyte, DGB_COIN_TYPE } from './network.js';
|
|
// BIP32 derives the master key as HMAC-SHA512(key, seed) with the key
|
|
// "Bitcoin seed". DigiByte's 2018-19 official mobile wallets (BreadWallet
|
|
// forks) used "DigiByte seed" instead, so the SAME 12 words give a
|
|
// completely different key tree — every address differs. A recovery that
|
|
// only tries the standard key never finds those coins.
|
|
// Ported from Digibyte.X/dgb-wallet @ 989a2696.
|
|
export const HMAC_BITCOIN_SEED = 'Bitcoin seed';
|
|
export const HMAC_DIGIBYTE_SEED = 'DigiByte seed';
|
|
export const PURPOSE_LABEL = {
|
|
44: 'BIP44 legacy P2PKH',
|
|
49: 'BIP49 P2SH-wrapped SegWit',
|
|
84: 'BIP84 native SegWit v0',
|
|
86: 'BIP86 Taproot (SegWit v1)',
|
|
};
|
|
export function rootFromSeed(seed, network = digibyte, hmacKey = HMAC_BITCOIN_SEED) {
|
|
if (hmacKey === HMAC_BITCOIN_SEED) return bip32().fromSeed(seed, network);
|
|
const I = hmac()(sha512(), new TextEncoder().encode(hmacKey), seed);
|
|
return bip32().fromPrivateKey(Buffer.from(I.slice(0, 32)), Buffer.from(I.slice(32)), network);
|
|
}
|
|
// Standard account-level derivation: m/purpose'/coin'/account'.
|
|
// account defaults to 0 (the first account).
|
|
export function accountNode(root, purpose, account = 0) {
|
|
return root.derivePath(`m/${purpose}'/${DGB_COIN_TYPE}'/${account}'`);
|
|
}
|
|
// Address-level derivation from an account node.
|
|
// change = 0 for external (receive) addresses, 1 for internal (change).
|
|
export function addressNode(account, change, index) {
|
|
return account.derive(change).derive(index);
|
|
}
|
|
//# sourceMappingURL=hd.js.map
|