AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 49 Monero

feat: initial hive -> SQLite (#2502)

Public commit record

What the developer wrote

Authored by cyan

98/100 · Strong
feat: initial hive -> SQLite (#2502)

* feat: initial hive -> SQLite

Includes migration script and initial work done to
remove dependency on hive generators.

Also contains some refactoring to make sync code
async.

Features new dev screen that lists all SQLite tables

Aspects that need testing:
- backups (from this version, and from previous versions as well)
- wallet loading / wallet list
- almost everything else
- renaming
- deletion
- sorting in wallet list
- wallet groups
- wallet seed/keys
- wallet switching
- wallet creation / restore - all methods
- wallet address page
- hardware wallet connection (and prompts from mall screens)
- contacts
- advanced settings in wallet creation
- derivation paths
- some minor wownero fixes
- base, hardware wallets

* fix: build errors

* fix: Bad state: No element in backup restore

* address comments from review

* fix: HardwareWalletType
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This is a large internal refactor that replaces the Hive key-value database with SQLite for storing wallet metadata (names, addresses, derivation paths, etc.). It also migrates old Hive data to the new SQLite format. The change touches many wallet types and could affect wallet loading, backups, restores, renaming, deletion, and address book behavior. It is a feature/refactor commit, not a targeted security fix, but any bug in the migration or new SQL layer could lead to data loss or incorrect wallet selection.

Recommended action

Treat this as a high-risk refactor requiring thorough QA: verify one-way Hive-to-SQLite migration on iOS/Android/desktop, test backup/restore across old and new app versions, confirm wallet open/rename/delete/switching for each coin, and audit the new SQLite helpers for injection or race conditions in the full codebase. Do not deploy without regression testing, especially for users upgrading from older Hive-based versions.

Security signals we found

01

Large data-layer migration from Hive to SQLite with one-way migration logic

02

New SQL schema stores wallet metadata including derivation paths, addresses, hardware wallet type, and recovery flags

03

Multiple wallet services now throw generic Exception('Wallet not found') when SQLite lookup fails

04

Legacy Hive adapter retained to read old boxes and migrate them

05

Backup/restore code paths modified (backup_service.dart, backup_service_v3.dart, restore_from_backup_view_model.dart)

06

Address book and contact list storage moved to SQLite

07

No parameterized query issues visible in the supplied diff; queries use sqflite's where/whereArgs binding

08

Migration catches errors and continues, which could mask migration failures

Risk score

Why this scored 49/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 6/15
Affected reach 14/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.