AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 44 Monero

feat: zkool2 (#3165)

Public commit record

What the developer wrote

Authored by cyan

71/100 · Adequate
feat: zkool2 (#3165)

* feat: zkool2

* feat: rescan on zkool
fix: sending to extracted addresses
fix: labeling shielding txs
fix: autoshield endless loop
fix: autoshield t addr not firing
fix: autoshield destinations
chore: remove old routes for rescan with zkool
other minor fixes/cleanups

* fix: zcash hardfork

* fix: update sync progress more reliably

* fix: pending transaction loading
fix: autoshield txs
fix: taddress
fix: fee estimation
fix: tx send errors

* chore: bump zkool2 to latest version
fix: reduce amount of taddrs generated
fix: derivation path for internal wallets
fix: display address in correct hidden/usable spots
fix: get wallet db height before it syncs for the first time
fix: taddr rotation with passphrase
fix: sync progress ui refresh
fix: taddress generation not getting capped
fix: hidden addresses not being hidden
fix: pending transactions not being shown
fix: t address cache misses
fix: t address rotation not getting refreshed
fix: t address high index not being used

* fix: refresh t addresses

* fix: patch rust side to make t addr rotation work

* fix: ui issue in recipient address
fix: zcash multiaddress send to show in the ui
fix: potential race condition

* minor fixes

* format

* fix: flashing on receive screen

* remove unused 'autoShield'

* review
✓ Subject identifies a change✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This is a large feature commit that replaces Cake Wallet's older Zcash wallet backend (warp_api) with a new library called zkool2. It touches address generation, transaction creation, balance scanning, transparent-address rotation, auto-shielding, and migration of old wallets. The commit message lists many bug fixes, but the code change is broad and partially complete (for example, the rescan method is mostly commented out). There is no direct evidence in the commit of a deliberate security vulnerability, but the size and incomplete state create a higher-than-normal risk of bugs that could lose funds, leak privacy, or produce incorrect balances.

Recommended action

Treat this as a high-risk refactor requiring focused review and QA before release. Specifically: verify zkool2 dependency version and supply-chain integrity; audit the new transaction commit/broadcast error path; complete and review the commented-out rescan logic; test transparent-address rotation, auto-shielding, and migration on mainnet-like data; and run integration tests for send/receive/rescan across wallet types. No immediate CVE or advisory action is warranted from the diff alone.

Security signals we found

01

Large backend replacement for a cryptocurrency wallet (high blast radius)

02

Transaction broadcast failure detection relies on txId length check (64 hex chars) rather than explicit success signal

03

Auto-shielding and t-address rotation logic rewritten with new concurrency and rate-limiting assumptions

04

Rescan implementation is partially stubbed/commented out

05

New dependency on external zkool2 Rust library whose code is not shown in the diff

06

Migration code reads old SQLite seed material and restores wallets with derived birth heights

07

Mempool parsing added with account-Id matching on notes/amounts

Risk score

Why this scored 44/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 6/15
Affected reach 10/15
Confidence 5/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.