AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 61 Monero

CW-1157-Use-correct-derivation-paths-for-other-address-types (#2825)

Public commit record

What the developer wrote

Authored by Serhii

81/100 · Strong
CW-1157-Use-correct-derivation-paths-for-other-address-types (#2825)

* feat: use bitcoin standard derivation paths per address type

* add support for Electrum derivation type in wallet

* fix merge conflict

* Use segwit HD for key export and simplify _hdFor

* skip derivation chooser for standard scan paths

* add legacy and P2SH derivation paths
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit changes how Cake Wallet derives Bitcoin-style addresses from a user's recovery seed. Previously, the app used a single derivation scheme for all address types. Now it uses the standard BIP44/49/84/86 paths per address type (legacy, SegWit, Taproot, etc.) while keeping an older 'legacy' path for compatibility with existing wallets. The change is a feature/fix for correctness and interoperability, not an obvious security vulnerability. However, any change to key derivation is sensitive because mistakes can make funds inaccessible or cause users to share/scan the wrong addresses.

Recommended action

Treat this as a high-risk correctness change rather than a malicious patch. Reviewers should verify that: (1) each address type maps to the correct BIP purpose and coin type; (2) legacy derivation fallback exactly matches the previous behavior for existing wallets; (3) signing and PSBT derivation paths use the same keys as address generation; (4) hardware wallet flows receive correct derivation paths; (5) the restore auto-skip cannot accidentally select a non-user path. Regression tests should cover seed-based address equality against known vectors and cross-check restored balances against previous app version.

Security signals we found

01

Change to BIP32/SLIP-10 key derivation paths for multiple UTXO coin wallets

02

New per-address-type HD key maps and legacy fallback key maps introduced

03

Address records now carry and persist an isLegacyDerivation flag

04

Signing, PSBT signing, key export, and message signing now select HD trees based on address record metadata

05

Address discovery and initial address generation logic changed to produce both legacy and standard derivation sets

06

Restore flow now auto-selects derivation when only standard scan paths have history

07

No explicit security advisory, CVE, or researcher attribution in commit or supplied references

Risk score

Why this scored 61/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 12/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.