AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 26 Monero

feat: Enhance Solana wallet with token program ID support (#2814)

Public commit record

What the developer wrote

Authored by David Adegoke

93/100 · Strong
feat: Enhance Solana wallet with token program ID support (#2814)

- Handle custom token program IDs, supporting both standard SPL Token and Token-2022.
- Fetch the appropriate token program ID based on mint address.
- Updated associated token account creation logic to use the detected token program ID, ensuring compatibility with different token standards.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit updates Cake Wallet's Solana support so it can work with both the older standard SPL token program and the newer Token-2022 program. It fetches the correct token program from the blockchain for each token and uses that program when finding or creating associated token accounts and when building transfer instructions. The change is a feature enhancement, not a stated security fix. There is a small risk that if the code picks the wrong program ID or an attacker-controlled RPC returns bad data, transactions could fail or funds could be sent to incompatible accounts, but the diff itself does not show an obvious vulnerability.

Recommended action

Review the manual _createTransferCheckedInstruction implementation for exact byte-layout correctness and compare it with the Solana Program Library reference. Ensure the RPC response for mint account owner is validated and that only well-known token program IDs (Tokenkeg... and TokenzQd... ) are accepted, to reduce risk from a malicious or compromised RPC. Add tests covering Token-2022 mints, standard SPL mints, and fallback paths. Consider whether the removed cw_evm import change should be in a separate commit.

Security signals we found

01

Manual instruction encoding for SPL Token transferChecked replaces library helper

02

Token program ID is now fetched from RPC mint account owner and used for ATA derivation and transfer instructions

03

Sender ATA ownership is verified on-chain before transfer

04

Recipient ATA is created using the same token program ID as the sender

05

Default fallback to standard SPL Token program ID when RPC lookup fails

06

No input validation or whitelist of allowed token program IDs

07

No explicit security relevance disclosed by vendor

Risk score

Why this scored 26/100

Our methodology →
Potential impact 5/30
Exploitability 4/25
Stealth signal 3/15
Affected reach 6/15
Confidence 5/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.