AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 27 Monero

Migrate EVM/Sol/TRX tokens to SQL (#3450)

Public commit record

What the developer wrote

Authored by David Adegoke

76/100 · Adequate
Migrate EVM/Sol/TRX tokens to SQL (#3450)

* fix android CI

* feat: Migrate EVM, Sol and Tron tokens to SQL

* handle rename edgecase

* refactor: enhance token migration logic and improve database handling
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit replaces the way Cake Wallet stores EVM, Solana, and Tron token lists: it moves them from Hive (a local key-value store) into SQLite (a local SQL database). It also adds migration code that copies existing token data from the old Hive boxes into the new SQLite tables when the app starts or restores a backup. The change is a large data-layer refactor, not a clear security fix or vulnerability. There are some migration edge cases (duplicate wallet names, interrupted migrations, case-insensitive EVM contract addresses) that are explicitly handled and tested.

Recommended action

Treat as a regular data-layer refactor. Review the migration order and exception handling in production, ensure backups are taken before the schema upgrade, and verify that ConflictAlgorithm.replace does not unintentionally clobber user-disabled scam tokens during future default-token updates. No immediate security patch is indicated by the diff alone.

Security signals we found

01

Large data migration touching token metadata and enabled toggles

02

Use of ConflictAlgorithm.replace for token upserts could overwrite user-modified fields if default token metadata changes later

03

Migration swallows exceptions and continues, which may hide corruption but avoids startup crashes

04

EVM contract addresses are normalized to lowercase; Solana/TRX mint/contract addresses preserve casing

05

Rename logic deletes rows under the target walletName before updating, which could destroy unrelated token data if a wallet is renamed to an existing name

06

No parameterized query issues visible; sqflite helpers are used consistently

Risk score

Why this scored 27/100

Our methodology →
Potential impact 5/30
Exploitability 4/25
Stealth signal 3/15
Affected reach 6/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.