AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 26 Monero

Cw 1624 trezor passphrase on trezor device instead of app (#3601)

Public commit record

What the developer wrote

Authored by Konstantin Ullrich

81/100 · Strong
Cw 1624 trezor passphrase on trezor device instead of app (#3601)

* feat: add support for Trezor device settings configuration and `AwaitingSettings` state in pairing flow

* fix ugly widgets

* trezor options ui

* feat: add support for Trezor on device passphrases

* chore: bump trezor_flutter deps

* fix: remove unused subtitle property in proceed_on_device_sheet [skip ci]

* chore: update trezor_flutter dependency to latest commit [skip ci]

* fix: set restore height and store wallet during initialization steps

---------

Co-authored-by: Robert Malikowski <malikowskirobert@gmail.com>
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit adds a new option for Trezor hardware wallet users to enter their passphrase directly on the Trezor device instead of typing it into the Cake Wallet app. It also updates the pairing flow to ask users about auto-connect and passphrase settings before finishing setup. The change is a feature improvement for hardware wallet usability and appears intended to reduce exposure of the passphrase to the app. There is no clear security vulnerability in the diff, but the commit is partial: it depends on an updated external Trezor library whose full behavior is not shown, and it removes some old passphrase-handling code while adding new session logic.

Recommended action

Review the updated trezor_flutter library at commit 02771769fc800c06e29ac9186e37e9c2aeb0b54c to confirm that on-device passphrase handling does not leak the passphrase to the host and that `createSession` securely manages sessions. Also verify that removing the old passphrase flow does not leave any cached passphrase values in app state or logs, and regression-test Trezor pairing for both on-device and in-app passphrase modes.

Security signals we found

01

Passphrase entry moved from app input field to on-device entry option

02

Old in-app passphrase session creation removed from wallet service and Trezor wrapper

03

New `TrezorPassphrase.onDevice()` and `TrezorPassphrase.value(...)` abstraction introduced via updated dependency

04

Dependency bump to unreleased git commit of trezor_flutter (no advisory or changelog supplied)

05

DateTime mutation bug fixed in `getMoneroHeigthByDate`

06

Restore height now stored after wallet restore from keys, seed, and hardware wallet

Risk score

Why this scored 26/100

Our methodology →
Potential impact 5/30
Exploitability 3/25
Stealth signal 4/15
Affected reach 5/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.