AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 59 Monero

fix: solana wallet bugs and security issues (#3484)

Public commit record

What the developer wrote

Authored by David Adegoke

100/100 · Strong
fix: solana wallet bugs and security issues (#3484)

* fix android CI

* fix: duplicate outgoing tx for jup swaps and stuck pending state

* fix solana security risk by handling duplicate token symbols in wallet transactions

* feat: implement additional cost handling for pending transactions in Solana wallet.

* fix: Items on security audit list for solana wallet

* refactor: streamline fee payer index handling and improve error logging

* fix: verifySignature for solana and handle wrong mint on default token

* fix: token decimals defaulting to zero and breaking amount parsing in solana

* fix: use token mask in tx history

* refactor: apply lint to modified code

* fix: merge conflicts

* fix: use Money and mint decimals when parsing sol swaps

* test: add unit tests for SPL token amount handling and parsing

* test: add more tests

* fix: update decimal handling for fetched token and remove unused fields
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
The short version

What changed, and why it matters

This commit fixes several Solana wallet bugs and security issues in Cake Wallet. The main security-relevant changes are: (1) preventing users from accidentally sending the wrong token when two tokens share the same symbol, by matching on the unique mint address instead of the symbol; (2) using the correct token decimals from the blockchain rather than defaulting to zero, so amounts are parsed and displayed accurately; (3) adding a warning and proper accounting for the extra SOL cost when a recipient's token account must be created; and (4) improving signature verification and transaction-history parsing. The commit title and message explicitly call these 'security issues' and mention an audit list.

Recommended action

Review the Solana send/swap flow to confirm the duplicate-symbol disambiguation and additional-cost UI behave correctly in production. Consider whether the new AmbiguousTokenSymbolException needs handling in any other call sites. Verify that the on-chain decimal fallback does not introduce RPC latency or failure modes for tokens with missing metadata.

Security signals we found

01

Commit title/message explicitly labels changes as 'security issues' and 'security audit list'

02

Disambiguation of duplicate token symbols by mint address prevents wrong-token sends

03

Use of on-chain mint decimals prevents amount miscalculation/parsing errors

04

Additional cost handling for recipient token account creation prevents hidden rent shortfalls

05

verifyMessage rewritten to derive public key from expected address and verify base58 signature

06

Token-2022 program support added to transaction parsing

07

Transaction history JSON parsing now catches per-entry errors instead of failing wholesale

Risk score

Why this scored 59/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.