AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 27 Monero

feat: bip39 decred (#3348)

Public commit record

What the developer wrote

Authored by cyan

55/100 · Thin
feat: bip39 decred (#3348)
✓ Descriptive subject✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
The short version

What changed, and why it matters

This commit adds BIP39 seed phrase support for Decred wallets in Cake Wallet. It changes how Decred wallets are created, restored, and saved, including storing an encrypted backup of the seed/passphrase and switching the underlying Decred library call used to build transactions. There is no explicit security bug in the diff, but the change touches sensitive wallet-key handling and transaction creation code, so it warrants careful review.

Recommended action

Review the new key-file backup implementation for Decred to ensure encryption and storage follow the same hardened path as other BIP39 wallets. Verify that the `createTransaction` FFI change in libdcrwallet still produces signed transactions correctly and does not introduce unsigned-tx exposure. Confirm the bumped libwallet version does not contain unrelated security changes. No immediate patch is indicated by the diff alone.

Security signals we found

01

New encrypted key backup path introduced for Decred (WalletKeysData/saveKeysFile)

02

Transaction construction FFI call renamed and request payload changed (createSignedTransaction -> createTransaction + sign: true)

03

Passphrase now accepted and persisted for Decred wallets

04

Mnemonic validation added but only checks word count for native 15-word Decred seeds, not checksum

05

Wallet rename now also renames .keys/.keys.backup files, reducing risk of orphaned key material

Risk score

Why this scored 27/100

Our methodology →
Potential impact 5/30
Exploitability 5/25
Stealth signal 3/15
Affected reach 5/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.