handle lightning balance fetch failures (#3382)
What changed, and why it matters
This commit wraps a lightning balance lookup in a try/catch so that if the lookup fails, the app logs an error instead of crashing or throwing an unhandled exception. It is a defensive reliability fix; there is no direct evidence it fixes an exploitable security vulnerability.
Treat as a routine stability/reliability improvement. Review whether silent swallowing of balance-fetch failures could mask sync or accounting issues, and consider surfacing a user-visible warning when lightning balance is stale or unavailable.
Security signals we found
Unhandled exception path removed from balance refresh
Defensive error handling added around external/lightning balance fetch
No evidence of memory corruption, injection, or cryptographic weakness
Evidence from the diff
In cw_bitcoin/lib/bitcoin_wallet.dart, the call to lightningWallet!.getBalance() is now wrapped in a try/catch. Previously, a failure from getBalance() would propagate as an unhandled exception, likely causing UI refresh or wallet balance computation to fail. The patch catches any exception, prints it, and leaves the existing balance.confirmed-based return path intact. No input validation, authentication, or cryptographic changes are present.
Changed components
cw_bitcoin/lib/bitcoin_wallet.dartBitcoinWalletBase balance refresh logicLightning wallet balance integrationInspect captured patch +4 / −0
diff --git a/cw_bitcoin/lib/bitcoin_wallet.dart b/cw_bitcoin/lib/bitcoin_wallet.dart
index 51f48571..a0d88ce9 100644
--- a/cw_bitcoin/lib/bitcoin_wallet.dart
+++ b/cw_bitcoin/lib/bitcoin_wallet.dart
@@ -345,12 +345,16 @@ abstract class BitcoinWalletBase extends ElectrumWallet with Store {
return balance;
}
+ try {
final lBalance = await lightningWallet!.getBalance();
this.balance[CryptoCurrency.btcln] = ElectrumBalance(
confirmed: lBalance,
unconfirmed: Money.zero(CryptoCurrency.btcln),
frozen: Money.zero(CryptoCurrency.btcln));
+ } catch (e) {
+ printV("Error fetching lightning balance: $e");
+ }
return ElectrumBalance(
confirmed: balance.confirmed,
Why this scored 20/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.