Add support for Ledger Nano Gen 5 (#2609)
What changed, and why it matters
This commit adds support for a new Ledger hardware wallet model (Ledger Nano Gen 5) in the Cake Wallet app. It updates an internal device list, adds an icon, and switches the app to use a fork of the Ledger library maintained by Cake Wallet's own team. The code change also removes a redundant method argument when listening for device connection state changes. There is no direct evidence in the commit that this fixes a security vulnerability; it appears to be a routine feature addition and dependency maintenance change.
Review the differences between the old (`vespr-wallet/ledger-flutter-plus@60817d4b`) and new (`cake-tech/ledger-flutter-plus@5237e5b3`) dependency commits to confirm the fork does not introduce unexpected behavior or regressions. Verify the `deviceStateChanges` API change is compatible with the new fork. No immediate security patch action is indicated by this commit alone.
Security signals we found
Dependency source changed from third-party repository to vendor-owned fork
Dependency commit hash updated without disclosed vulnerability details
Hardware wallet integration code touched, but only device enumeration/display
Evidence from the diff
The diff adds ledgerNanoGen5 to the HardwareWalletDeviceType enum and maps the upstream LedgerDeviceType.nanoGen5 to it. It adds an SVG asset and a display case in the connect-device page. The pubspec_base.yaml dependency override for ledger_flutter_plus is moved from vespr-wallet/ledger-flutter-plus at commit 60817d4b to cake-tech/ledger-flutter-plus at commit 5237e5b3. In LedgerViewModel, deviceStateChanges(device.device.id) is replaced with the no-argument deviceStateChanges getter. No cryptographic, authorization, or input-validation logic is modified.
Changed components
Cake Wallet hardware wallet connection flowledger_flutter_plus dependency overrideLedger device enumeration and icon renderingInspect captured patch +11 / −3
diff --git a/assets/images/hardware_wallet/device_ledger_nano_gen_5.svg b/assets/images/hardware_wallet/device_ledger_nano_gen_5.svg
new file mode 100644
index 00000000..9d2fc8bb
--- /dev/null
+++ b/assets/images/hardware_wallet/device_ledger_nano_gen_5.svg
@@ -0,0 +1,3 @@
+<svg width="24" height="24" viewBox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
+<path d="M16.5 2C17.8807 2 19 3.11929 19 4.5V5C19.2761 5 19.5 5.22386 19.5 5.5V8C19.5 8.24171 19.3286 8.44371 19.1006 8.49023L19 8.5V19.5C19 20.8807 17.8807 22 16.5 22H7.5C6.11929 22 5 20.8807 5 19.5V4.5C5 3.11929 6.11929 2 7.5 2H16.5ZM14.5 19C13.9477 19 13.5 19.4477 13.5 20C13.5 20.5523 13.9477 21 14.5 21H16.5C17.0523 21 17.5 20.5523 17.5 20C17.5 19.4477 17.0523 19 16.5 19H14.5ZM7.5 3.5C6.94772 3.5 6.5 3.94772 6.5 4.5V16.5C6.5 17.0523 6.94772 17.5 7.5 17.5H16.5C17.0523 17.5 17.5 17.0523 17.5 16.5V4.5C17.5 3.94772 17.0523 3.5 16.5 3.5H7.5Z" fill="white"/>
+</svg>
diff --git a/lib/entities/hardware_wallet/hardware_wallet_device.dart b/lib/entities/hardware_wallet/hardware_wallet_device.dart
index 5bfbf96c..646f5a2c 100644
--- a/lib/entities/hardware_wallet/hardware_wallet_device.dart
+++ b/lib/entities/hardware_wallet/hardware_wallet_device.dart
@@ -46,6 +46,7 @@ enum HardwareWalletDeviceType {
ledgerNanoS,
ledgerNanoX,
ledgerNanoSPlus,
+ ledgerNanoGen5,
ledgerStax,
ledgerFlex,
BitBox02,
@@ -70,6 +71,8 @@ extension ToGenericHardwareWalletDeviceType on ledger.LedgerDeviceType {
return HardwareWalletDeviceType.ledgerNanoSPlus;
case ledger.LedgerDeviceType.nanoX:
return HardwareWalletDeviceType.ledgerNanoX;
+ case ledger.LedgerDeviceType.nanoGen5:
+ return HardwareWalletDeviceType.ledgerNanoGen5;
case ledger.LedgerDeviceType.stax:
return HardwareWalletDeviceType.ledgerStax;
case ledger.LedgerDeviceType.flex:
diff --git a/lib/src/screens/connect_device/connect_device_page.dart b/lib/src/screens/connect_device/connect_device_page.dart
index 7bde2743..00b5356b 100644
--- a/lib/src/screens/connect_device/connect_device_page.dart
+++ b/lib/src/screens/connect_device/connect_device_page.dart
@@ -165,6 +165,8 @@ class ConnectDevicePageBodyState extends State<ConnectDevicePageBody> {
switch (deviceType) {
case HardwareWalletDeviceType.ledgerNanoX:
return 'assets/images/hardware_wallet/ledger_nano_x.png';
+ case HardwareWalletDeviceType.ledgerNanoGen5:
+ return 'assets/images/hardware_wallet/device_ledger_nano_gen_5.svg';
case HardwareWalletDeviceType.ledgerStax:
return 'assets/images/hardware_wallet/ledger_stax.png';
case HardwareWalletDeviceType.ledgerFlex:
diff --git a/lib/view_model/hardware_wallet/ledger_view_model.dart b/lib/view_model/hardware_wallet/ledger_view_model.dart
index 2ac76446..628e0811 100644
--- a/lib/view_model/hardware_wallet/ledger_view_model.dart
+++ b/lib/view_model/hardware_wallet/ledger_view_model.dart
@@ -127,7 +127,7 @@ abstract class LedgerViewModelBase extends HardwareWalletViewModel with Store {
if (_connectionChangeSubscription == null) {
_connectionChangeSubscription = ledger
- .deviceStateChanges(device.device.id)
+ .deviceStateChanges
.listen(_connectionChangeListener);
}
diff --git a/pubspec_base.yaml b/pubspec_base.yaml
index d3083406..3360dec8 100644
--- a/pubspec_base.yaml
+++ b/pubspec_base.yaml
@@ -190,8 +190,8 @@ dependency_overrides:
ffi: 2.1.0
ledger_flutter_plus:
git:
- url: https://github.com/vespr-wallet/ledger-flutter-plus
- ref: 60817d4b20144f9da9029f5034790272795b9d38
+ url: https://github.com/cake-tech/ledger-flutter-plus
+ ref: 5237e5b3d5f07696eefd0aaee9c32478ed399d20
ledger_usb_plus:
git:
url: https://github.com/konstantinullrich/ledger-usb-plus
Why this scored 21/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.