fix: Add additional fees validation for native transaction (#2933)
What changed, and why it matters
This commit adds a safety check in Cake Wallet's Ethereum-compatible wallet to prevent users from creating native (non-token) transactions when the account does not have enough balance to cover both the amount being sent and the network transaction fee. Previously, the app only checked that the send amount itself was covered by the balance, which could allow a transaction to be created that would later fail or leave the account unexpectedly short. The fix throws a specific fee-related error when the combined amount plus estimated fees exceeds the available balance.
Treat as a low-to-moderate reliability/security fix. Review the full transaction creation flow to confirm no other balance/fee checks are missing, and verify that estimatedFeesForTransaction is computed consistently across all EVM chains and transaction types. Add regression tests for insufficient-balance scenarios including fees. No immediate incident response is indicated unless user reports of failed or stuck transactions surface.
Security signals we found
Insufficient funds validation gap in transaction creation
Native coin send could proceed without accounting for gas fees
New exception type introduced for fee-related failures
Partial patch: only adds one additional check; broader fee/estimation logic not reviewed
Evidence from the diff
In cw_evm/lib/evm_chain_wallet.dart, a new validation block was added inside the transaction creation flow. After the existing balance check (currencyBalance.balance < totalAmount), the patch now also checks: if the currency is not an ERC-20 token and totalAmount + estimatedFeesForTransaction > currencyBalance.balance, throw EVMChainTransactionFeesException.fromCurrency(currency.title). This closes a gap where native-coin sends could be approved despite insufficient funds for gas, while leaving ERC-20 fee logic (which is handled separately) unchanged.
Changed components
cw_evm/lib/evm_chain_wallet.dartEVMChainWalletBase transaction creationNative (non-ERC-20) EVM transfersInspect captured patch +4 / −0
diff --git a/cw_evm/lib/evm_chain_wallet.dart b/cw_evm/lib/evm_chain_wallet.dart
index ea1312e2..f60cd64e 100644
--- a/cw_evm/lib/evm_chain_wallet.dart
+++ b/cw_evm/lib/evm_chain_wallet.dart
@@ -1004,6 +1004,10 @@ abstract class EVMChainWalletBase
if (currencyBalance.balance < totalAmount) {
throw EVMChainTransactionCreationException(transactionCurrency);
}
+ if (transactionCurrency is! Erc20Token &&
+ totalAmount + estimatedFeesForTransaction > currencyBalance.balance) {
+ throw EVMChainTransactionFeesException.fromCurrency(currency.title);
+ }
}
if (transactionCurrency is Erc20Token &&
Why this scored 58/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.