AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 34 Monero

CW-1273: Implement USDT0 Bridge (#2855)

Public commit record

What the developer wrote

Authored by David Adegoke

76/100 · Adequate
CW-1273: Implement USDT0 Bridge (#2855)

* feat: Implement USDT0 Bridging using OFT Standard by Layer Zero. POC available in apps menu.

* feat: Implement USDT0 Bridging using OFT Standard by Layer Zero. POC available in apps menu.

* feat: Implement USDT0 Bridging using OFT Standard by Layer Zero. POC available in apps menu.

* Add transaction history and status polling for USDT0 bridging

* Add Transaction history and status polling for USDT0 Bridging

* USDT0 Bridging Implementation

* Update Arbitrum USDT token symbol

* fix: Merge conflicts

* fix: Merge conflicts

* chore: Rever formatting

* feat: Implement new flow

* feat: Implement new ui flow

* Add currency to configure

* feat: new ui flow

* Update USDT0 implementation
- Switch to sqlite for storage instead of hive
- Switch bridge history and details to modals
- Switch bridge transfer details page to new tx details ui

* refactor: rearrange modal action buttons

* enhance usdt0 bridge flows

* Update lib/entities/wallet_manager.dart [skip ci]

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit adds a new feature to Cake Wallet that lets users move USDT (a popular stablecoin) between Ethereum, Polygon, and Arbitrum using a cross-chain bridge powered by LayerZero. It introduces new screens, a service that talks to the bridge contracts, a database table to store bridge history, and status polling so users can see whether their transfer is in progress or completed. The change is a feature implementation, not a documented security fix, but it touches sensitive areas such as transaction construction, token approvals, and external API calls.

Recommended action

Treat this as a high-touch feature addition requiring security review. Verify the hardcoded USDT0/LayerZero contract addresses and endpoint IDs against official documentation. Review the unlimited ERC-20 approval path on Ethereum for necessity and consider whether a user-controlled or per-transfer allowance is safer. Audit how recipient addresses and amounts are validated before being encoded into OFT send() calldata, ensure the LayerZero scan service response parsing is robust against malicious API responses, and confirm the new BridgeTransfer SQLite table does not leak sensitive data in backups or logs. Test the changed transaction-deduplication logic for regressions.

Security signals we found

01

New feature adds cross-chain token bridge with hardcoded contract addresses and endpoint IDs

02

Ethereum path requests unlimited ERC-20 approval (maxUint) to a hardcoded OFT adapter address

03

New external network dependency: LayerZero scan API (https://scan.layerzero-api.com/v1)

04

New SQLite table BridgeTransfer stores wallet_id, chain IDs, token contract, amount, recipient address, source tx hash, status, and error/status messages

05

OFT contract wrapper encodes payable send() calls and passes user-supplied recipient address as bytes32

06

Transaction deduplication logic changed to prefer outgoing transactions that include an EVM token contract address

07

No explicit security claims, CVE references, or researcher attribution in commit message or diff

Risk score

Why this scored 34/100

Our methodology →
Potential impact 8/30
Exploitability 6/25
Stealth signal 4/15
Affected reach 7/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.