AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 35 Monero

Add Robinhood Chain (#3398)

Public commit record

What the developer wrote

Authored by David Adegoke

76/100 · Adequate
Add Robinhood Chain (#3398)

* fix android CI

* feat: Add Robinhood Chain, all major flows done. minor issue now is our providers don't support it yet as its still pretty early, two weeks from launch

* feat: Add Robinhood Chain, all major flows done. minor issue now is our providers don't support it yet as its still pretty early, two weeks from launch

* Cleanup

* auto-reformat

* fix ui issue and contact listing for tokens

* fix: missing icons and crash for fee priority in settings

* chore: cleanup

* fixes from feedbacks

* fix: review issues and sync to latest dev
feat: switch history api to etherscan, add history toggle to privacy settings, exclude robETH from exchange pickers, skip tokens discovery for chains that moralis hasn't indexed, add tests

* fix: address Robinhood review comments

* fix: show Solana token icons in history

* fix: address review comments and default Robinhood to PublicNode

* fix: revert filter and refuse unmapped networks in provider

---------

Co-authored-by: Robert Malikowski <malikowskirobert@gmail.com>
✓ Descriptive subject✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction history, settings, and UI assets. There is no direct evidence in the commit of a security vulnerability, but the size and breadth of the change introduce ordinary implementation risks typical of adding a new EVM chain.

Recommended action

Treat this as a routine but sizable feature commit. Reviewers should focus on the RobinhoodClient transaction-signing path, the new Alchemy secret handling, the default node list trust assumptions, and the Moralis-disabled token-discovery fallback to ensure users cannot be tricked into accepting malicious token metadata. No immediate security action is indicated from the diff alone.

Security signals we found

01

New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)

02

New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)

03

New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows

04

Moralis token discovery explicitly disabled for Robinhood Chain (getMoralisChainName returns null for chain 4663)

05

Token metadata fallback now reads directly from RPC node when Moralis is unavailable

06

Large cross-cutting change touching 143 files with +1214/-159 lines

Risk score

Why this scored 35/100

Our methodology →
Potential impact 5/30
Exploitability 5/25
Stealth signal 5/15
Affected reach 10/15
Confidence 7/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.