What changed, and why it matters
This commit fixes a display/calculation bug when buying or selling Nano cryptocurrency through Cake Wallet. Nano supports very small decimal amounts (up to 30 places). The app was trying to format the calculated crypto amount using all of those decimals, which caused an error because the formatting function only supports up to 20 decimal places. The fix caps the decimals at 20. This is primarily a reliability/usability bug, not a direct security vulnerability, though it could cause failed transactions or user confusion in the buy/sell flow.
Treat as a routine bug fix. Verify that capping Nano decimals at 20 does not introduce rounding discrepancies with payment provider APIs or wallet balance displays. Consider adding a unit test for amountForQuote with Nano and other high-decimal assets. No urgent security response is indicated by the diff alone.
Security signals we found
UI/ViewModel crash in buy/sell flow
Defensive bounds clamp on formatting precision
No input sanitization changes observed
No cryptographic, authentication, or authorization changes
Evidence from the diff
In lib/view_model/buy/buy_sell_view_model.dart, amountForQuote() previously called toStringAsFixed(cryptoCurrency.decimals). For Nano, decimals is 30, but Dart’s toStringAsFixed() only accepts 0-20, throwing an ArgumentError or RangeError at runtime. The patch clamps decimals to min(20, cryptoCurrency.decimals), preventing the crash. The downstream Money.safeParse then receives a string with at most 20 fractional digits. There is no evidence in the diff of input validation, arithmetic precision, or injection issues; the change is a defensive bounds clamp.
Changed components
lib/view_model/buy/buy_sell_view_model.dartBuy/Sell quote amount calculationNano (XNO) buy/sell flowInspect captured patch +1 / −1
diff --git a/lib/view_model/buy/buy_sell_view_model.dart b/lib/view_model/buy/buy_sell_view_model.dart
index fa257a41..e9f7a342 100644
--- a/lib/view_model/buy/buy_sell_view_model.dart
+++ b/lib/view_model/buy/buy_sell_view_model.dart
@@ -172,7 +172,7 @@ abstract class BuySellViewModelBase extends WalletChangeListenerViewModel with S
}
Money amountForQuote(Quote quote) => Money.safeParse(
- (double.parse(fiatAmount) / quote.rate).toStringAsFixed(cryptoCurrency.decimals),
+ (double.parse(fiatAmount) / quote.rate).toStringAsFixed(min(20, cryptoCurrency.decimals)),
cryptoCurrency);
Money? fiatAmountForQuote(Quote quote) {
Why this scored 20/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.