AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
High 72 Monero

CW-1615: Harden walletconnect auth (#3547)

Public commit record

What the developer wrote

Authored by David Adegoke

81/100 · Strong
CW-1615: Harden walletconnect auth (#3547)

* fix android CI

* fix: harden walletconnect auth so a connected session won't transfer on dApp when wallet is switched within the app

* refactor: improve session mgmt and better error handling, also added a loader to the listing page

* feat: switch to newer id for solana dapps connections and fix requests not triggering
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
The short version

What changed, and why it matters

This update fixes a security weakness in Cake Wallet's WalletConnect feature. Previously, if a user switched to a different wallet inside the app while still connected to a decentralized app (dApp), the dApp could keep sending signing or transaction requests that might be handled by the wrong wallet. The patch now checks that each incoming request truly belongs to the currently active wallet, rejects mismatched requests with a clear message, and refreshes or clears WalletConnect sessions when wallets are switched. It also updates Solana connection identifiers and improves loading/error feedback.

Recommended action

Review the authorization logic for completeness, especially edge cases where multiple accounts or chains are authorized in one session, and ensure the `_pendingRequest` matcher correctly handles concurrent requests with the same topic and method. Consider adding automated tests for wallet-switch scenarios and unauthorized request rejection.

Security signals we found

01

Authorization check added before signing/transaction approval

02

Session ownership verified against current wallet public key

03

Request address matched to wallet address before approval

04

Unauthorized WalletConnect requests rejected with 4100 error

05

WalletConnect state reset and sessions reloaded on wallet switch

06

Relay client disconnected on WalletConnect dispose

07

Topic/method-scoped pending request lookup replaces global last-request lookup

08

Solana chain ID updated and legacy ID retained for compatibility

Risk score

Why this scored 72/100

Our methodology →
Potential impact 22/30
Exploitability 16/25
Stealth signal 10/15
Affected reach 12/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.