What changed, and why it matters
This is a small bug-fix patch in Cake Wallet's buy/sell cryptocurrency screen. It rounds the calculated crypto amount to the correct number of decimal places before converting it into a Money object. Without the fix, certain exchange rates or fiat amounts could produce a value with too many decimal places, causing a 'decimals exception' (an app crash or error). The change is defensive and improves reliability, but it does not appear to be a security vulnerability on its own.
Treat as a routine reliability fix. Include in the next release. No urgent security response is indicated based on the commit alone. If the exception was reported as causing a crash, consider regression tests for quote calculations with high-precision rates.
Security signals we found
No security-relevant keywords in commit title or message
Change is a one-line precision/rounding fix in view-model code
No evidence of malicious intent or hidden behavior
No changes to cryptography, authentication, storage, or network trust
Exception path is user-visible (app error/crash), not a silent exploit
Evidence from the diff
In lib/view_model/buy/buy_sell_view_model.dart, amountForQuote() previously computed Money.parse(double.parse(fiatAmount) / quote.rate, cryptoCurrency). The Money.parse implementation likely validates that the parsed value does not exceed cryptoCurrency.decimals precision, throwing a decimals exception when it does. The patch rounds the division result via toStringAsFixed(cryptoCurrency.decimals) before parsing, ensuring the value conforms to the currency’s allowed precision. This is a correctness/reliability fix in UI/quote logic, not a cryptographic, authorization, or input-validation flaw.
Changed components
lib/view_model/buy/buy_sell_view_model.dartCake Wallet buy/sell quote amount calculationInspect captured patch +1 / −1
diff --git a/lib/view_model/buy/buy_sell_view_model.dart b/lib/view_model/buy/buy_sell_view_model.dart
index 4e6e2bf5..4228057c 100644
--- a/lib/view_model/buy/buy_sell_view_model.dart
+++ b/lib/view_model/buy/buy_sell_view_model.dart
@@ -175,7 +175,7 @@ abstract class BuySellViewModelBase extends WalletChangeListenerViewModel with S
}
Money amountForQuote(Quote quote) =>
- Money.parse(double.parse(fiatAmount) / quote.rate, cryptoCurrency);
+ Money.parse((double.parse(fiatAmount) / quote.rate).toStringAsFixed(cryptoCurrency.decimals), cryptoCurrency);
Money fiatAmountForQuote(Quote quote) {
return Money.parse(
Why this scored 23/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.