Show fiat amount for tokens on swipe confirmation sheet (#2670)
What changed, and why it matters
This commit fixes a UI bug where the estimated fiat (e.g., USD) value of token payments was not shown on the 'swipe to confirm' send screen. It adds a helper to match currencies by both name and network tag, then uses that match to look up the correct exchange price. There is no direct evidence this is a security vulnerability; it appears to be a user-experience fix that could indirectly prevent user confusion or transaction mistakes.
Treat as a routine bug fix. Reviewers may optionally verify that titleAndTagEqual handles null tags consistently and that firstWhere throwing does not produce a poor user experience, but no security-specific action is required based on the supplied materials.
Security signals we found
UI-only fix with no change to transaction construction, signing, or validation
New helper only compares title and tag fields; no external input is parsed or executed
Lookup failure still falls through to existing catch block, preserving prior behavior
No references to secrets, keys, seed phrases, or network calls in the diff
Evidence from the diff
The change introduces CryptoCurrency.titleAndTagEqual() in cw_core and uses it in SendViewModelBase to resolve a price from _fiatConversationStore.prices when the simple selectedCryptoCurrency key lookup fails. The prior code used a direct map index on selectedCryptoCurrency, which apparently missed tokens that share a title but differ by tag (e.g., ERC-20 vs BEP-20 versions of a token). The new code iterates keys and matches on title+tag. If no match is found, firstWhere will throw, which is caught by the existing catch-all. This is a UI/data-resolution fix with no cryptographic, authentication, or authorization changes visible in the diff.
Changed components
cw_core/lib/crypto_currency.dartlib/view_model/send/send_view_model.dartCake Wallet send confirmation sheet UIInspect captured patch +6 / −1
diff --git a/cw_core/lib/crypto_currency.dart b/cw_core/lib/crypto_currency.dart
index 952d7c08..b35531b7 100644
--- a/cw_core/lib/crypto_currency.dart
+++ b/cw_core/lib/crypto_currency.dart
@@ -393,4 +393,8 @@ class CryptoCurrency extends EnumerableItem<int> with Serializable<int> implemen
@override
String toString() => title;
+
+ bool titleAndTagEqual(CryptoCurrency other) {
+ return title == other.title && tag == other.tag;
+ }
}
diff --git a/lib/view_model/send/send_view_model.dart b/lib/view_model/send/send_view_model.dart
index 1b446e02..24f71cac 100644
--- a/lib/view_model/send/send_view_model.dart
+++ b/lib/view_model/send/send_view_model.dart
@@ -191,7 +191,8 @@ abstract class SendViewModelBase extends WalletChangeListenerViewModel with Stor
try {
final fiat = calculateFiatAmount(
- price: _fiatConversationStore.prices[selectedCryptoCurrency]!,
+ price: _fiatConversationStore.prices[_fiatConversationStore.prices.keys
+ .firstWhere((k) => k.titleAndTagEqual(selectedCryptoCurrency))],
cryptoAmount: pendingTransaction!.amountFormatted);
return fiat;
} catch (_) {
Why this scored 17/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.