fix: custom Bitcoin Ledger derivation paths and update ledger-bitcoin dependency (#2798)
What changed, and why it matters
This commit fixes how Cake Wallet handles custom Bitcoin account paths on Ledger hardware wallets. Previously, the app may have ignored a user's chosen derivation path when signing Bitcoin transactions with a Ledger, which could lead to signing from the wrong account or failing to find funds. The update also bumps the ledger-bitcoin plugin to a newer version. There is no direct evidence in the commit of a security vulnerability being exploited; it reads as a bug fix for correctness.
Review the diff between the old and new `ledger_bitcoin` git refs to confirm what changed in the dependency and whether it contains any security fixes. Verify that `setAccountDerivationPath` is called in all relevant Ledger signing flows and that the derivation path is validated before use. Consider whether the removed `derivationPath` parameter had any callers that need updating.
Security signals we found
Hardware wallet derivation path mismatch bug fixed
Third-party dependency updated to a newer git ref
Unused derivationPath parameter removed from signTransaction method signature
Evidence from the diff
The change adds a setter setAccountDerivationPath on BitcoinLedgerService that forwards the wallet’s derivationPath to the underlying BitcoinLedgerApp instance before signing. BitcoinWallet.signTransaction now checks if the hardware service is a BitcoinLedgerService and, if derivationInfo.derivationPath is non-null, calls that setter. The pubspec updates the git ref for ledger_bitcoin from dc42621f55702d0732681afc2f90bc0047f26633 to 75bba8632c529debf30ee2b1858530009fa6440b. The commit message frames this as fixing custom Bitcoin Ledger derivation paths and removing an unused derivationPath parameter in signTransaction.
Changed components
cw_bitcoin/lib/bitcoin_wallet.dartcw_bitcoin/lib/hardware/bitcoin_ledger_service.dartcw_bitcoin/pubspec.yamlLedger Bitcoin hardware wallet integrationInspect captured patch +11 / −3
diff --git a/cw_bitcoin/lib/bitcoin_wallet.dart b/cw_bitcoin/lib/bitcoin_wallet.dart
index b1feeb7a..49535742 100644
--- a/cw_bitcoin/lib/bitcoin_wallet.dart
+++ b/cw_bitcoin/lib/bitcoin_wallet.dart
@@ -13,6 +13,7 @@ import 'package:cw_bitcoin/electrum_derivations.dart';
import 'package:cw_bitcoin/electrum_wallet.dart';
import 'package:cw_bitcoin/electrum_wallet_snapshot.dart';
import 'package:cw_bitcoin/hardware/bitcoin_hardware_wallet_service.dart';
+import 'package:cw_bitcoin/hardware/bitcoin_ledger_service.dart';
import 'package:cw_bitcoin/payjoin/manager.dart';
import 'package:cw_bitcoin/payjoin/storage.dart';
import 'package:cw_bitcoin/pending_bitcoin_transaction.dart';
@@ -31,9 +32,7 @@ import 'package:cw_core/wallet_info.dart';
import 'package:cw_core/wallet_keys_file.dart';
import 'package:flutter/foundation.dart';
import 'package:hive/hive.dart';
-import 'package:ledger_bitcoin/ledger_bitcoin.dart';
import 'package:ledger_bitcoin/psbt.dart';
-import 'package:ledger_flutter_plus/ledger_flutter_plus.dart';
import 'package:mobx/mobx.dart';
import 'package:ur/cbor_lite.dart';
import 'package:ur/ur.dart';
@@ -356,6 +355,11 @@ abstract class BitcoinWalletBase extends ElectrumWallet with Store {
);
final psbtStr = base64Encode(psbt.serialize());
+ if (hardwareWalletService is BitcoinLedgerService && derivationInfo.derivationPath != null) {
+ (hardwareWalletService as BitcoinLedgerService)
+ .setAccountDerivationPath(derivationInfo.derivationPath!);
+ }
+
final rawHex = await hardwareWalletService!.signTransaction(transaction: psbtStr);
return BtcTransaction.fromRaw(BytesUtils.toHexString(rawHex));
}
diff --git a/cw_bitcoin/lib/hardware/bitcoin_ledger_service.dart b/cw_bitcoin/lib/hardware/bitcoin_ledger_service.dart
index 65ab7640..19c5bdc9 100644
--- a/cw_bitcoin/lib/hardware/bitcoin_ledger_service.dart
+++ b/cw_bitcoin/lib/hardware/bitcoin_ledger_service.dart
@@ -18,6 +18,10 @@ class BitcoinLedgerService extends HardwareWalletService with BitcoinHardwareWal
final LedgerConnection ledgerConnection;
final BitcoinLedgerApp bitcoinLedgerApp;
+ void setAccountDerivationPath(String derivationPath) {
+ bitcoinLedgerApp.derivationPath = derivationPath;
+ }
+
@override
Future<List<HardwareAccountData>> getAvailableAccounts({int index = 0, int limit = 5}) async {
final masterFp = await bitcoinLedgerApp.getMasterFingerprint();
diff --git a/cw_bitcoin/pubspec.yaml b/cw_bitcoin/pubspec.yaml
index 942a5069..3747e8db 100644
--- a/cw_bitcoin/pubspec.yaml
+++ b/cw_bitcoin/pubspec.yaml
@@ -49,7 +49,7 @@ dependencies:
git:
url: https://github.com/cake-tech/ledger-flutter-plus-plugins
path: packages/ledger-bitcoin
- ref: dc42621f55702d0732681afc2f90bc0047f26633
+ ref: 75bba8632c529debf30ee2b1858530009fa6440b
ledger_litecoin:
git:
url: https://github.com/cake-tech/ledger-flutter-plus-plugins
Why this scored 32/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.