What changed, and why it matters
This is a tiny code change in a wallet app's data-handling routine. It makes a copy of a list of address records before looping through them to save them to the database. The change likely prevents a runtime error (modifying a collection while iterating over it) but does not, by itself, look like a security vulnerability. There is no description from the developer explaining why the fix was needed.
Treat as a routine stability fix unless additional context shows the concurrent modification was reachable through untrusted input or could corrupt stored wallet metadata. Code reviewers should confirm whether `addressInfos` can be mutated during this loop and whether any exception here could leave wallet state partially persisted.
Security signals we found
Collection-iteration safety fix (possible ConcurrentModificationError mitigation)
No commit message detail or security framing from the vendor
No references, CVE, or researcher attribution supplied
Evidence from the diff
In cw_core/lib/wallet_info.dart, the method that persists address info entries now calls .toList() on addressInfo.value before iterating. The original code iterated directly over the live collection. In Dart, iterating over a collection while it is concurrently modified can throw a ConcurrentModificationError. The patch avoids that by snapshotting the iterable. The diff is one line changed/one line added; no other context (callers, concurrency model, or reproduction steps) is provided.
Changed components
cw_core/lib/wallet_info.dartWalletInfo address-info persistence routineInspect captured patch +2 / −1
diff --git a/cw_core/lib/wallet_info.dart b/cw_core/lib/wallet_info.dart
index 90be1b32..3f2d9c05 100644
--- a/cw_core/lib/wallet_info.dart
+++ b/cw_core/lib/wallet_info.dart
@@ -452,7 +452,8 @@ class WalletInfo {
await WalletInfoAddressInfo.deleteByWalletInfoId(internalId);
final entries = addressInfos.entries.toList();
for (final addressInfo in entries) {
- for (final info in addressInfo.value) {
+ final infoList = addressInfo.value.toList();
+ for (final info in infoList) {
await WalletInfoAddressInfo.insert(
walletInfoId: internalId,
mapKey: addressInfo.key,
Why this scored 20/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.