fix zcash not getting passed the group seed
What changed, and why it matters
This commit fixes a bug where new Zcash wallets in Cake Wallet were created without receiving the user's recovery phrase (mnemonic seed). Instead of using the intended seed, the wallet likely fell back to generating or using a different seed internally. This could mean a user who wrote down their recovery phrase would later be unable to restore their Zcash wallet with that phrase, potentially locking them out of funds. It is a reliability/functional bug with possible loss-of-access consequences, not an obvious remote attack vector.
Verify that Zcash wallet restore from the displayed mnemonic now works end-to-end, audit other wallet-type branches for similar missing seed parameters, and consider prompting affected users who created Zcash wallets in the affected window to verify their backups restore correctly.
Security signals we found
seed/mnemonic handling inconsistency
wallet creation credential parameter omission
potential loss of funds due to restore failure
single-line fix in wallet creation flow
Evidence from the diff
In lib/view_model/wallet_new_vm.dart, the Zcash branch of the wallet creation switch was missing the mnemonic parameter when calling createZcashNewWalletCredentials. The patch adds mnemonic: newWalletArguments!.mnemonic so the wallet is derived from the group seed shown to the user. Without this, the created wallet’s seed may not match the displayed mnemonic, breaking backup/restore consistency for Zcash wallets.
Changed components
lib/view_model/wallet_new_vm.dartZcash wallet creation flowmnemonic/seed derivation for new Zcash walletsInspect captured patch +1 / −0
diff --git a/lib/view_model/wallet_new_vm.dart b/lib/view_model/wallet_new_vm.dart
index 8e077214..d1c6f2ce 100644
--- a/lib/view_model/wallet_new_vm.dart
+++ b/lib/view_model/wallet_new_vm.dart
@@ -143,6 +143,7 @@ abstract class WalletNewVMBase extends WalletCreationVM with Store {
return zcash!.createZcashNewWalletCredentials(
name: name,
password: walletPassword,
+ mnemonic: newWalletArguments!.mnemonic,
passphrase: passphrase,
);
case WalletType.decred:
Why this scored 44/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.