What changed, and why it matters
This commit fixes a crash when restoring a cryptocurrency wallet from a QR code. The old code tried to convert an 'xpub' value even when it didn't exist, which would cause an error. The fix only runs the conversion if the value is actually present. There is no direct evidence this is a security vulnerability, but a crash during wallet restore could disrupt user access to funds.
Treat as a routine bug fix. Review whether the crash could be triggered by malformed QR input and consider input validation tests for restore payloads. No urgent security response is indicated based on the available evidence.
Security signals we found
Null-pointer / null-argument runtime crash in wallet restore path
Wallet restoration failure could lead to temporary denial of access to funds
No explicit security claim or advisory from vendor
No evidence of malicious exploitation in the diff
Evidence from the diff
In lib/view_model/restore/restore_wallet.dart, the RestoredWallet.fromJSON factory previously called convertAnyToXpub(json[‘xpub’] as String) unconditionally. If the JSON lacked an ‘xpub’ key, this would pass null to a function expecting a non-null String, causing a runtime TypeError/crash. The patch wraps the call in a null check: if (json[‘xpub’] != null) { json[‘xpub’] = convertAnyToXpub(…); }. This is a robustness fix for wallet restoration flows, particularly from QR codes where the payload may not contain an xpub.
Changed components
lib/view_model/restore/restore_wallet.dartRestoredWallet.fromJSON factoryQR code wallet restore flowInspect captured patch +3 / −1
diff --git a/lib/view_model/restore/restore_wallet.dart b/lib/view_model/restore/restore_wallet.dart
index bd70fce3..bfa83725 100644
--- a/lib/view_model/restore/restore_wallet.dart
+++ b/lib/view_model/restore/restore_wallet.dart
@@ -58,7 +58,9 @@ class RestoredWallet {
if (json['zpub'] != null) {
json['xpub'] = convertZpubToXpub(json['zpub'] as String);
}
- json['xpub'] = convertAnyToXpub(json['xpub'] as String);
+ if (json['xpub'] != null) {
+ json['xpub'] = convertAnyToXpub(json['xpub'] as String);
+ }
json['view_key'] ??= json['xpub'];
final height = json['height'] as String?;
return RestoredWallet(
Why this scored 24/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.