fix: remove _incoming and _outgoing tags from tx Ids, fixes blockchain links too. (#3323)
What changed, and why it matters
This commit fixes a display bug in Cake Wallet's Solana transaction history. Previously, the app added '_incoming' or '_outgoing' tags to the end of real Solana transaction IDs. This caused blockchain explorer links and copied transaction IDs to be invalid because those extra tags are not part of the real transaction hash. The fix strips those tags before showing or sharing the transaction ID. There is no direct evidence this was a security vulnerability, but it could confuse users or make it harder to verify payments on a blockchain explorer.
Treat as a routine bug fix. Verify that no other transaction info classes (e.g., for Monero, Bitcoin, Ethereum) use similar tagged IDs without a corresponding txHash override. Consider storing direction metadata in a separate field rather than mutating the transaction identifier.
Security signals we found
Transaction identifier tampering/pollution with non-hash suffixes
Blockchain explorer links rendered invalid by appended metadata
Potential user trust issue: inability to independently verify transactions
Evidence from the diff
In cw_solana/lib/solana_transaction_info.dart, an override for txHash is added that removes any trailing ‘_outgoing’ or ‘_incoming’ suffix from the stored id using a RegExp. The id field was apparently being mutated with direction tags elsewhere in the app, which polluted the transaction hash used for blockchain links and clipboard copies. The patch restores a clean transaction hash value without changing how the direction tag is stored or used internally.
Changed components
cw_solana/lib/solana_transaction_info.dartSolana transaction detail/link sharing UISolana transaction hash display/copy functionalityInspect captured patch +3 / −0
diff --git a/cw_solana/lib/solana_transaction_info.dart b/cw_solana/lib/solana_transaction_info.dart
index f51c55da..85c28ac0 100644
--- a/cw_solana/lib/solana_transaction_info.dart
+++ b/cw_solana/lib/solana_transaction_info.dart
@@ -28,6 +28,9 @@ class SolanaTransactionInfo extends TransactionInfo {
String? _fiatAmount;
+ @override
+ String get txHash => id.replaceFirst(RegExp(r'_(outgoing|incoming)$'), '');
+
@override
DateTime get date => blockTime;
Why this scored 19/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.