AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 41 Monero

feat: restrict history api calls when toggle is off in privacy settings (#3615)

Public commit record

What the developer wrote

Authored by David Adegoke

93/100 · Strong
feat: restrict history api calls when toggle is off in privacy settings (#3615)

* feat: restrict history api calls when toggle is off in privacy settings

* refactor: remove unnecessary transaction timer cancellation
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit adds a privacy toggle that stops EVM and Tron wallets from calling third-party blockchain history APIs (like Etherscan, PolygonScan, TronGrid) when the user turns the feature off in privacy settings. It also fixes preference key names for Base and Arbitrum scan providers so the toggle actually controls the right service. Previously, even with the toggle off, the app may have kept querying these external providers, potentially leaking the user's wallet address and transaction history to them.

Recommended action

Treat as a privacy-hardening fix. Verify that the renamed preference keys match the values written by the settings view model and that migration/clearing of old keys is handled, otherwise users who previously toggled the setting may see reversed behavior. Review whether removing `_transactionsUpdateTimer?.cancel()` in the disabled branch is safe and does not cause stale periodic fetches.

Security signals we found

01

Privacy leak mitigation: prevents address/transaction history disclosure to third-party scan providers when user disables the option

02

Preference key mismatch fix: old keys `use_basescan`/`use_arbiscan` did not align with documented/expected keys, so toggles may have been ineffective

03

Fail-closed behavior: `checkIfScanProviderIsEnabled()` returns `false` on SharedPreferences read errors

04

No cryptographic or authentication changes

Risk score

Why this scored 41/100

Our methodology →
Potential impact 8/30
Exploitability 5/25
Stealth signal 7/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.