What changed, and why it matters
This commit disables the Exolix cryptocurrency exchange provider in the Cake Wallet app. It adds a one-time settings migration that turns Exolix off for all users and bumps the migration version so the change runs on app startup. The commit message gives no reason, and there are no supplied references explaining whether this is a security fix, a business decision, or a response to an incident.
Treat this as a low-confidence signal requiring follow-up. Review the Exolix integration code for vulnerabilities, verify whether the provider was disabled due to a security incident, and confirm the migration correctly handles users who had manually enabled Exolix. If disabling is security-related, publish an advisory and consider removing or hardening the Exolix code path rather than only toggling availability.
Security signals we found
Provider deactivation without stated cause
Exchange/third-party service integration disabled via migration
No accompanying code removal or hardening of the Exolix integration
Evidence from the diff
The patch adds migration case 69 in default_settings_migration.dart, which calls _changeExchangeProviderAvailability with providerName: ‘Exolix’ and enabled: false. It also increments initialMigrationVersion from 68 to 69 in main.dart so existing installations execute the migration during initialization. The change is purely a configuration toggle; no code related to Exolix’s API integration, UI, or exchange logic is modified or removed.
Changed components
lib/entities/default_settings_migration.dartlib/main.dartExolix exchange provider availability settingInspect captured patch +8 / −1
diff --git a/lib/entities/default_settings_migration.dart b/lib/entities/default_settings_migration.dart
index ef8a213c..c4011172 100644
--- a/lib/entities/default_settings_migration.dart
+++ b/lib/entities/default_settings_migration.dart
@@ -628,6 +628,13 @@ Future<void> defaultSettingsMigration(
oldUri: ['nodes.hashvault.pro:18081'],
);
break;
+ case 69:
+ _changeExchangeProviderAvailability(
+ sharedPreferences,
+ providerName: "Exolix",
+ enabled: false,
+ );
+ break;
default:
break;
}
diff --git a/lib/main.dart b/lib/main.dart
index f292731f..923ace77 100644
--- a/lib/main.dart
+++ b/lib/main.dart
@@ -315,7 +315,7 @@ Future<void> initializeAppConfigs({bool loadWallet = true}) async {
payjoinSessionSource: payjoinSessionSource,
anonpayInvoiceInfo: anonpayInvoiceInfo,
havenSeedStore: havenSeedStore,
- initialMigrationVersion: 68,
+ initialMigrationVersion: 69,
);
}
Why this scored 32/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.