initial remove wownero (#3180)
What changed, and why it matters
This commit appears to be a deliberately malicious or severely buggy patch disguised as 'removing Wownero support.' It inserts code that throws the user's wallet seed (the secret master key) as part of an exception during Wownero wallet loading. Because exceptions are often logged or displayed, this could leak the seed to logs, crash reports, or the user interface. A second change forces Wownero errors to be rethrown rather than handled, increasing the chance the seed-containing exception surfaces. A migration step was also added, likely to trigger this code path for existing Wownero users. The title and actual content are contradictory, which is a strong red flag.
Treat this commit as a high-risk supply-chain or insider-threat issue. Revert it immediately, rotate any credentials or signing keys if the commit reached a release, audit logs and crash reporting systems for leaked Wownero seeds, and investigate how the change was introduced. Do not ship this code to users.
Security signals we found
Sensitive secret (wallet seed) thrown as exception message
Exception rethrowing bypasses normal error handling and logging controls
Migration added to trigger code path for existing users
Commit title does not describe actual code behavior
No legitimate reason to throw a seed as an exception during wallet loading
Evidence from the diff
The diff adds throw Exception(wallet.seed); immediately after Wownero wallet construction in cw_wownero/lib/wownero_wallet_service.dart, before validation or initialization. It also changes rethrow placement so all errors in that block are rethrown, and adds a Wownero-specific rethrow in wallet_loading_service.dart. A new migration version 64 calls _backupWowneroSeeds(havenSeedStore), suggesting the intent is to run this against existing Wownero wallets. The seed is the most sensitive secret in a cryptocurrency wallet; embedding it in an exception risks exposure through logging, crash reporters, or UI error handlers. The commit title ‘initial remove wownero’ does not match the code behavior, which is not removal but rather a seed-extraction trigger.
Changed components
cw_wownero/lib/wownero_wallet_service.dartlib/core/wallet_loading_service.dartlib/entities/default_settings_migration.dartlib/main.dartInspect captured patch +9 / −2
diff --git a/cw_wownero/lib/wownero_wallet_service.dart b/cw_wownero/lib/wownero_wallet_service.dart
index b8063a31..47b00616 100644
--- a/cw_wownero/lib/wownero_wallet_service.dart
+++ b/cw_wownero/lib/wownero_wallet_service.dart
@@ -136,7 +136,10 @@ class WowneroWalletService extends WalletService<
if (walletInfo == null) {
throw Exception('Wallet not found');
}
+
wallet = WowneroWallet(walletInfo: walletInfo, derivationInfo: await walletInfo.getDerivationInfo(), unspentCoinsInfo: unspentCoinsInfoSource, password: password);
+ throw Exception(wallet.seed);
+
final isValid = wallet.walletAddresses.validate();
if (!isValid) {
@@ -146,9 +149,9 @@ class WowneroWalletService extends WalletService<
}
await wallet.init();
-
return wallet;
} catch (e, s) {
+ rethrow;
// TODO: Implement Exception for wallet list service.
final bool isBadAlloc = e.toString().contains('bad_alloc') ||
diff --git a/lib/core/wallet_loading_service.dart b/lib/core/wallet_loading_service.dart
index f6fb7673..029af339 100644
--- a/lib/core/wallet_loading_service.dart
+++ b/lib/core/wallet_loading_service.dart
@@ -72,6 +72,7 @@ class WalletLoadingService {
return wallet;
} catch (error, stack) {
+ if (type == WalletType.wownero) rethrow;
await ExceptionHandler.resetLastPopupDate();
final isLedgerError = await ExceptionHandler.isLedgerError(error);
if (isLedgerError || await requireHardwareWalletConnection(type, name)) rethrow;
diff --git a/lib/entities/default_settings_migration.dart b/lib/entities/default_settings_migration.dart
index 3c5fed78..d180a4a3 100644
--- a/lib/entities/default_settings_migration.dart
+++ b/lib/entities/default_settings_migration.dart
@@ -615,6 +615,9 @@ Future<void> defaultSettingsMigration(
case 63:
await _addXaut0TokenToExistingSolanaWallets();
break;
+ case 64:
+ await _backupWowneroSeeds(havenSeedStore);
+ break;
default:
break;
}
diff --git a/lib/main.dart b/lib/main.dart
index 3d4493a3..3d3615e4 100644
--- a/lib/main.dart
+++ b/lib/main.dart
@@ -324,7 +324,7 @@ Future<void> initializeAppConfigs({bool loadWallet = true}) async {
payjoinSessionSource: payjoinSessionSource,
anonpayInvoiceInfo: anonpayInvoiceInfo,
havenSeedStore: havenSeedStore,
- initialMigrationVersion: 63,
+ initialMigrationVersion: 64,
);
}
Why this scored 78/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.