Disable ETA by default, use electrs node as a fallback not hardcoded
What changed, and why it matters
This commit makes two user-facing changes in the Cake Wallet app: it turns off a default 'estimated time remaining' display for wallet syncing, and it stops silently forcing a hardcoded Cake-run Bitcoin server when scanning certain private transactions. Instead, the app will use the server the user already picked, only falling back to the hardcoded one if none was chosen. The commit also slightly increases a network keep-alive timer. There is no direct evidence in the commit that this fixes an active security vulnerability, but it reduces privacy and trust risks by giving users more control over which server handles their transaction data.
Treat as a routine privacy-hardening/default-tuning change rather than an urgent security patch. Review whether the hardcoded fallback node (electrs.cakewallet.com:50001) is still appropriate and disclosed to users, and confirm the ETA display change is intentional for all wallet types. No immediate user action is required.
Security signals we found
Reduced reliance on a hardcoded third-party Electrum server for silent-payment scanning
User-selected node now preferred over vendor-operated fallback node
Default setting changed to hide ETA (estimated time to sync)
Minor network keep-alive timer adjustment (4s -> 5s)
Evidence from the diff
The diff touches four files. (1) cw_bitcoin/lib/electrum.dart bumps aliveTimerDuration from 4 to 5 seconds. (2) cw_bitcoin/lib/electrum_wallet.dart changes silent-payment scanning so the Electrum node URI is taken from scanData.node?.uri instead of always defaulting to tcp://electrs.cakewallet.com:50001; the hardcoded node becomes a fallback. (3) lib/entities/default_settings_migration.dart adds migration version 56, which writes SyncStatusDisplayMode.blocksRemaining to shared preferences, effectively disabling ETA display by default. (4) lib/main.dart bumps initialMigrationVersion from 55 to 56. No cryptographic, authentication, or input-validation changes are present. The commit message frames the change as a default-setting and fallback-behavior adjustment, not as a security fix.
Changed components
cw_bitcoin/lib/electrum.dartcw_bitcoin/lib/electrum_wallet.dartlib/entities/default_settings_migration.dartlib/main.dartInspect captured patch +9 / −5
diff --git a/cw_bitcoin/lib/electrum.dart b/cw_bitcoin/lib/electrum.dart
index b6469acc..e7993d4c 100644
--- a/cw_bitcoin/lib/electrum.dart
+++ b/cw_bitcoin/lib/electrum.dart
@@ -40,7 +40,7 @@ class ElectrumClient {
unterminatedString = '';
static const connectionTimeout = Duration(seconds: 5);
- static const aliveTimerDuration = Duration(seconds: 4);
+ static const aliveTimerDuration = Duration(seconds: 5);
bool get isConnected => socket != null && socket?.isClosed == false;
ProxySocket? socket;
diff --git a/cw_bitcoin/lib/electrum_wallet.dart b/cw_bitcoin/lib/electrum_wallet.dart
index 4bcee04d..972cfe5e 100644
--- a/cw_bitcoin/lib/electrum_wallet.dart
+++ b/cw_bitcoin/lib/electrum_wallet.dart
@@ -3013,7 +3013,7 @@ Future<void> _handleScanSilentPayments(ScanData scanData) async {
final hasForcedRescanHeights = !shouldUpdateSyncStatus;
CakeTor.instance = await CakeTorInstance.getInstance();
- var node = Uri.parse("tcp://electrs.cakewallet.com:50001");
+ var node = scanData.node?.uri ?? Uri.parse("tcp://electrs.cakewallet.com:50001");
void log(String message, LogLevel level) {
printV("[Scanning] $message", file: scanData.debugLogPath, level: level);
diff --git a/lib/entities/default_settings_migration.dart b/lib/entities/default_settings_migration.dart
index c176ebe5..a71604e6 100644
--- a/lib/entities/default_settings_migration.dart
+++ b/lib/entities/default_settings_migration.dart
@@ -5,8 +5,8 @@ import 'package:cake_wallet/core/secure_storage.dart';
import 'package:cake_wallet/entities/exchange_api_mode.dart';
import 'package:cake_wallet/entities/fiat_api_mode.dart';
import 'package:cake_wallet/entities/haven_seed_store.dart';
+import 'package:cake_wallet/entities/sync_status_display_mode.dart';
import 'package:cake_wallet/wownero/wownero.dart';
-import 'package:cw_core/cake_hive.dart';
import 'package:cw_core/pathForWallet.dart';
import 'package:cake_wallet/entities/secret_store_key.dart';
import 'package:cw_core/root_dir.dart';
@@ -23,7 +23,6 @@ import 'package:cake_wallet/monero/monero.dart';
import 'package:cake_wallet/entities/contact.dart';
import 'package:cake_wallet/entities/fs_migration.dart';
import 'package:cw_core/wallet_info.dart';
-import 'package:cw_core/wallet_info_legacy.dart' as wiLegacy;
import 'package:cake_wallet/exchange/trade.dart';
import 'package:encrypt/encrypt.dart' as encrypt;
import 'package:collection/collection.dart';
@@ -568,6 +567,11 @@ Future<void> defaultSettingsMigration(
type: WalletType.zcash,
currentNodePreferenceKey: PreferencesKey.currentZcashNodeIdKey,
);
+ break;
+ case 56:
+ await sharedPreferences.setString(
+ PreferencesKey.syncStatusDisplayMode, SyncStatusDisplayMode.blocksRemaining.name);
+ break;
default:
break;
}
diff --git a/lib/main.dart b/lib/main.dart
index 21e1d4c1..9d8a416e 100644
--- a/lib/main.dart
+++ b/lib/main.dart
@@ -313,7 +313,7 @@ Future<void> initializeAppConfigs({bool loadWallet = true}) async {
payjoinSessionSource: payjoinSessionSource,
anonpayInvoiceInfo: anonpayInvoiceInfo,
havenSeedStore: havenSeedStore,
- initialMigrationVersion: 55,
+ initialMigrationVersion: 56,
);
}
Why this scored 24/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.