AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 28 Monero

feat: Add memo support for swap (#3229)

Public commit record

What the developer wrote

Authored by David Adegoke

93/100 · Strong
feat: Add memo support for swap (#3229)

* feat: Add memo support for swap

* fix: Error on swap page select receiver bottomsheet when picking receiveing currency that's not a wallet type

* feat: exclude providers that do not support memo when receive currency needs it, also show passed memo in confirmation and trade history sheets

* fix: overflow for destination tag on swap confirmation

* Update lib/view_model/exchange/exchange_view_model.dart [skip ci]

* Update lib/exchange/provider/trocador_exchange_provider.dart [skip ci]

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
The short version

What changed, and why it matters

This commit adds support for memos and destination tags when swapping to currencies that require them (like XRP, XLM, TON, EOS, HBAR). Previously, these currencies were excluded from swap receiving options. The change lets users enter a memo/destination tag, passes it to exchange providers that support it, filters out providers that don't support it, and stores it with the trade record. It also fixes a UI crash when selecting a receive currency that isn't a wallet type.

Recommended action

No immediate security action required; this is a feature addition. Reviewers should verify that memo/destination tag values are properly sanitized/escaped by each exchange provider's API client, confirm the SQLite migration handles existing Trade rows correctly, and ensure the provider capability flags accurately reflect each exchange's support to prevent failed or misdirected swaps.

Security signals we found

01

New user-supplied input field (memo/destination tag) flows to multiple third-party exchange APIs

02

Provider capability flag used to filter providers when memo-required currency selected

03

SQLite schema migration adds `toAddressExtraId` column to Trade table

04

Previously excluded receive currencies (XLM, XRP, BNB) re-enabled for swaps

05

UI crash fix in receive wallet selection wrapped in try/catch

06

Input length limits applied: 20 for destination tag, 256 for memo

Risk score

Why this scored 28/100

Our methodology →
Potential impact 5/30
Exploitability 2/25
Stealth signal 2/15
Affected reach 8/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.