AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 35 Monero

zec ironwood (#3425)

Public commit record

What the developer wrote

Authored by cyan

59/100 · Thin
zec ironwood (#3425)

* initial

* wip

* ironwood detection, migration

* dev: zec address validation on rt

* fix: ironwood spend

* ironwood regressions

* fix: tx history

* bump: zkool2

* fix: tx amounts on pending
fix: ironwood pending balance
fix: orchard->ironwood migration
fix: orchard->any pre ironwood txs
fix: ironwood -> any txs
fix: WrongSpendAuthorizingKey
fix: tx history
fix: autoshield to ironwood
fix: zkool to latest version
break: my sleep schedule :sweating: :worksonmymachine:

* thx fable

* downgrade frb to 2.11.1

* fix: tx amounts in history

* Migating... / migration label for O->I txs
✓ Subject identifies a change✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit adds support for Zcash's Ironwood network upgrade to Cake Wallet. It changes how wallet balances, transactions, and addresses are handled when Ironwood activates, and it lets advanced users pick mainnet, testnet, or regtest for Zcash. The changes are mostly functional upgrades and bug fixes rather than a clear security patch, but they touch sensitive areas like balance calculation, transaction construction, and address validation. Because the commit is large and partially hardcodes dev-network settings (for example, a regtest node at 10.0.2.2), there is some risk of misconfiguration or incorrect balance reporting, though no direct exploit is visible in the diff.

Recommended action

Treat this as a significant feature upgrade, not a confirmed security fix. Review the hardcoded regtest endpoint and disabled address validation for dev networks to ensure they cannot be triggered in production builds. Audit the new balance and migration logic against zkool2's Rust behavior to confirm funds cannot be incorrectly classified or locked. Verify the zkool2 dependency bump does not introduce breaking or unsafe behavior. Run integration tests on mainnet, testnet, and regtest Zcash wallets for balance accuracy, send/receive, and migration display.

Security signals we found

01

Hardcoded regtest lightwalletd endpoint 10.0.2.2:9067 with no TLS (ZcashNetwork.defaultNodeUri/useSsl)

02

Address regex validation disabled for Zcash dev networks (AddressValidator returns null pattern)

03

Balance/availability logic changed based on ironwoodActive flag, with Orchard funds marked unavailable after Ironwood activation

04

New migration path invokes zkool_migrate.stepMigration() and adjusts transaction display/direction for migration transactions

05

Mempool tx removal and pending-outgoing amount tracking modified, affecting what transactions/balances are shown

06

Dependency zkool2 git ref bumped; full Rust-side behavior not visible in this diff

07

iOS deployment target raised and Google Sign-In dependencies removed (build/privacy surface change)

Risk score

Why this scored 35/100

Our methodology →
Potential impact 8/30
Exploitability 5/25
Stealth signal 6/15
Affected reach 7/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.