fix: address leaks (#3426)
What changed, and why it matters
This commit changes how Zcash wallet addresses are stored in the app's local wallet info. Instead of saving the full address map to persistent storage, it now saves an empty map, while still saving related metadata like address info, used addresses, and hidden addresses. The commit title says this fixes 'address leaks,' which suggests the previous behavior may have exposed or stored more address data than intended. However, the diff alone does not show what specific sensitive data was leaking, to whom, or under what conditions.
Review the pull request #3426 and any related issue or security discussion to confirm what data was leaking, from where, and to what destination. Verify that clearing the persisted address map does not break wallet recovery, address reuse detection, or backup/restore behavior. Consider whether the in-memory addressesMap still represents a leak surface in logs, backups, or IPC.
Security signals we found
Commit title explicitly claims 'fix: address leaks'
Persistent storage of address map is replaced with empty map
In-memory address map remains unchanged
No explicit CVE, advisory, or researcher attribution in commit or supplied references
Evidence from the diff
In cw_zcash/lib/src/zcash_wallet_addresses.dart, two lines are changed: (1) _initAddresses() now initializes addressesMap to {} instead of loading it from walletInfo.getAddresses(); (2) the address update method now calls walletInfo.setAddresses({}) instead of persisting addressesMap. The class still keeps addressesMap in memory and continues to persist addressInfos, usedAddresses, manualAddresses, and hiddenAddresses. The stated goal is to prevent ‘address leaks,’ but the patch does not remove the in-memory addressesMap or change how addresses are displayed, generated, or shared. It only stops writing the full map to the walletInfo storage layer.
Changed components
cw_zcash/lib/src/zcash_wallet_addresses.dartZcash wallet address persistence layerwalletInfo address storageInspect captured patch +2 / −2
diff --git a/cw_zcash/lib/src/zcash_wallet_addresses.dart b/cw_zcash/lib/src/zcash_wallet_addresses.dart
index 31bdbbf9..42bd3042 100644
--- a/cw_zcash/lib/src/zcash_wallet_addresses.dart
+++ b/cw_zcash/lib/src/zcash_wallet_addresses.dart
@@ -108,7 +108,7 @@ abstract class ZcashWalletAddressesBase extends WalletAddresses with Store {
Set<String> hiddenAddresses = {};
Future<void> _initAddresses() async {
- addressesMap = await walletInfo.getAddresses();
+ addressesMap = {};
addressInfos = await walletInfo.getAddressInfos();
usedAddresses = await walletInfo.getUsedAddresses();
manualAddresses = await walletInfo.getManualAddresses();
@@ -236,7 +236,7 @@ abstract class ZcashWalletAddressesBase extends WalletAddresses with Store {
if (!isPlaceholderAddress(address)) {
walletInfo.address = address;
}
- await walletInfo.setAddresses(addressesMap);
+ await walletInfo.setAddresses({});
await walletInfo.setAddressInfos(addressInfos);
await walletInfo.setUsedAddresses(usedAddresses.toList());
await walletInfo.setHiddenAddresses(hiddenAddresses.toList());
Why this scored 49/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.