AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 37 Monero

CW-1290-Add-Duress-pin-feature (#2664)

Public commit record

What the developer wrote

Authored by Serhii

76/100 · Adequate
CW-1290-Add-Duress-pin-feature (#2664)

* add duress PIN feature

* add localization

* Update configure.dart

* Update configure.dart

* add duress PIN validation logic

* - fix error popup
- put behind a feature flag

---------

Co-authored-by: OmarHatem <omarh.ismail1@gmail.com>
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit adds a 'duress PIN' feature to Cake Wallet. It lets users set a second PIN that, if entered instead of the normal PIN, silently wipes all local wallet data, resets the app, and sends the user back to the welcome screen. The feature is meant to protect users who are forced to unlock their wallet under threat. The code includes checks to stop the duress PIN from being the same as the regular PIN, shows warnings before setup, and is hidden behind a feature flag that is currently turned on.

Recommended action

Treat this as a product-safety review, not an emergency vulnerability patch. Verify that the wipe routine cannot be triggered by an attacker who only knows the regular PIN, that the duress PIN cannot be brute-forced through the same rate-limiting path as the normal PIN, and that wiped data is unrecoverable on all supported platforms. Consider whether the feature flag should remain enabled by default given the irreversible data loss risk.

Security signals we found

01

New destructive authentication path: matching duress PIN triggers local data wipe

02

Secure storage, wallet directory, and SQLite wallet tables are all cleared

03

Duress PIN reuse with regular PIN is blocked at setup time

04

Feature is behind a compile-time flag that defaults to enabled

05

No vendor security advisory or CVE referenced in commit

Risk score

Why this scored 37/100

Our methodology →
Potential impact 8/30
Exploitability 6/25
Stealth signal 7/15
Affected reach 5/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.