…ex ETH
Two correctness bugs in the crypto address validators:
btc_address: the segwit branch is taken when the value starts with "bc"
or "tb", but the regexp only matched "bc" or "tc". Every valid testnet
bech32 address (tb1...) was therefore rejected. Correct the prefix to "tb".
eth_address: _validate_eth_checksum_address only checked the length of
the stripped address, not that its characters were hexadecimal. Inputs
made of non-hex, caseless characters (e.g. "0x" + "*" * 40) passed the
checksum loop vacuously and were accepted as valid. Require 40 hex
digits before running the checksum.
Existing fixtures are unchanged; added testnet bech32 addresses and a
non-hex input as regression tests.
This fixes two correctness bugs in the crypto_addresses validators. Both are covered by new regression tests, and the full test suite still passes.
1. btc_address rejects valid testnet segwit addresses
The segwit branch is selected when the value starts with bc or tb, but the regexp only matched bc or tc:
Because the gate accepts tb while the pattern expects tc, every valid testnet bech32 address is rejected:
tc is not a valid Bitcoin HRP and is unreachable through the value[:2] in ("bc", "tb") gate, so it is a typo for tb. Fix: (bc|tc) → (bc|tb). Mainnet bc1... is unaffected.
2. eth_address accepts non-hex "checksum" addresses
_validate_eth_checksum_address checked only the length of the stripped address, not that its characters were hexadecimal. The EIP-55 loop only constrains the case of letters, so caseless / non-hex characters pass it vacuously:
Fix: require the stripped address to be exactly 40 hex digits before running the checksum (this also subsumes the previous length check).
Tests
Both new cases fail on master and pass with this change. ruff reports no issues and the full suite (898 passed) is green.