AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 52 Monero

fetch params from download.z.cash on demand to reduce app size (#2879)

Public commit record

What the developer wrote

Authored by cyan

58/100 · Thin
fetch params from download.z.cash on demand to reduce app size (#2879)

add restore height to seed screen
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
The short version

What changed, and why it matters

This commit changes the Cake Wallet app so that it no longer ships with two large Zcash cryptographic files inside the app bundle. Instead, the app downloads those files from download.z.cash the first time it needs them, and saves them to the app's cache folder. The same commit also adds the wallet's restore height to the seed/keys screen for Zcash wallets. The change is a size optimization, but it introduces a new network download of security-critical parameters and stores them on disk, which could matter if the download or storage is tampered with.

Recommended action

Treat this as a security-sensitive change that needs hardening before release. Add cryptographic verification of the downloaded parameter files against known trusted hashes or signatures before passing them to `WarpApi.initProver()`. Guard `loadProver()` against concurrent execution and redundant downloads. Consider shipping a small, signed manifest or using a verified, tamper-evident delivery channel. Review whether `ProxyWrapper` provides sufficient transport security and whether the cache directory is protected from modification by other apps on the device. The restore-height UI change should be reviewed for privacy impact but appears lower risk.

Security signals we found

01

Security-critical Zcash proving parameters are now downloaded from the public internet instead of shipped inside the signed app bundle

02

Downloaded parameters are written to the application cache directory and reused without integrity verification (no hash/signature check visible in the diff)

03

The download uses `ProxyWrapper().get()` with a clearnet URI; the diff does not show certificate pinning, signature verification, or fallback to a trusted source

04

A static `isProverLoaded` boolean is introduced but the diff shows no guard preventing concurrent or redundant downloads/initializations

05

The catch block treats any read failure (including permission or disk errors) as a signal to download from the network, which could enable downgrade or substitution if local files are corrupted or replaced

06

The commit also exposes `restoreHeight` in wallet keys/seed screen, which is a privacy-relevant metadata leak to the UI but not an exploit path by itself

Risk score

Why this scored 52/100

Our methodology →
Potential impact 12/30
Exploitability 14/25
Stealth signal 8/15
Affected reach 10/15
Confidence 5/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.