AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 34 Monero

Normalize erc20 token addresses and fix duplicate tokens (#2884)

Public commit record

What the developer wrote

Authored by David Adegoke

58/100 · Thin
Normalize erc20 token addresses and fix duplicate tokens (#2884)
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
The short version

What changed, and why it matters

This commit fixes a bookkeeping problem in Cake Wallet's handling of Ethereum-compatible tokens. Because Ethereum addresses are case-insensitive but the app was storing them with mixed-case keys, the same token could appear twice or get out of sync. The patch adds a one-time cleanup that converts all stored token addresses to lowercase and merges duplicates. It also updates the built-in token lists to use lowercase addresses. This is a data-consistency bug fix rather than an active remote hack, but if left unfixed it could have led to wrong balances, missing tokens, or in a worst-case scenario sending funds to or trusting the wrong contract address.

Recommended action

Treat as a defensive data-integrity fix. Review whether any other code paths still use mixed-case addresses as lookup keys (transaction history, balance fetchers, swap providers, address-book entries) and normalize them consistently. Add checksum (EIP-55) validation when users import custom tokens so maliciously cased addresses cannot be used to spoof legitimate tokens. Verify the migration handles concurrent wallet opens safely and that the `isPotentialScam` OR-merge does not accidentally preserve a scam flag on a legitimate token entry.

Security signals we found

01

Data normalization of case-sensitive keys for case-insensitive identifiers

02

Duplicate-token merge logic that ORs `enabled` and `isPotentialScam` flags

03

One-time migration guarded by a SharedPreferences flag

04

Hardcoded token contract addresses changed to lowercase across five chain registries

05

No input validation or checksum verification added for user-added tokens

Risk score

Why this scored 34/100

Our methodology →
Potential impact 8/30
Exploitability 4/25
Stealth signal 6/15
Affected reach 7/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.