Normalize tokens box in migration edgewise (#2904)
What changed, and why it matters
This commit adds a single extra step during a wallet migration path. When an older version of the app's token storage box is missing, the code now initializes the box and then immediately 'normalizes' its keys. The change is small and appears to be a data-consistency fix rather than a security patch, but the commit message gives no details about what problem it solves.
Treat as a routine maintenance/data-integrity change unless additional context (e.g., linked issue #2904, changelog, or security advisory) shows it fixes a concrete bug. Review the implementation of _normalizeEvmChainErc20TokensBoxKeys() to confirm it does not introduce race conditions or data loss during migration.
Security signals we found
Migration path modified
Data normalization added after box initialization
No explicit security context in commit message or diff
Evidence from the diff
In cw_evm/lib/evm_chain_wallet.dart, inside the migration logic for EVM-chain ERC-20 token boxes, the patch calls _normalizeEvmChainErc20TokensBoxKeys() immediately after _initEthereumErc20TokensBox() when the erc20TokensBox is absent and must be rebuilt from the global box. The helper’s implementation is not shown in the diff. The change is plausibly defensive: ensuring keys are normalized after a fresh box is created during migration. There is no direct evidence of a vulnerability being fixed.
Changed components
cw_evm/lib/evm_chain_wallet.dartEVM chain wallet migration logicERC-20 token box key normalizationInspect captured patch +1 / −0
diff --git a/cw_evm/lib/evm_chain_wallet.dart b/cw_evm/lib/evm_chain_wallet.dart
index ad81272f..1649e796 100644
--- a/cw_evm/lib/evm_chain_wallet.dart
+++ b/cw_evm/lib/evm_chain_wallet.dart
@@ -252,6 +252,7 @@ abstract class EVMChainWalletBase
} catch (_) {
// erc20TokensBox doesn't exist yet, run migration from global box
await _initEthereumErc20TokensBox();
+ await _normalizeEvmChainErc20TokensBoxKeys();
return;
}
}
Why this scored 21/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.