AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Informational 20 Monero

feat: add support for Zcash names resolution (#3237)

Public commit record

What the developer wrote

Authored by David Adegoke

100/100 · Strong
feat: add support for Zcash names resolution (#3237)

* feat: Add memo support for swap

* fix: Error on swap page select receiver bottomsheet when picking receiveing currency that's not a wallet type

* feat: exclude providers that do not support memo when receive currency needs it, also show passed memo in confirmation and trade history sheets

* fix: overflow for destination tag on swap confirmation

* feat: add support for Zcash names resolution

* fix conflict because github is shit

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
The short version

What changed, and why it matters

This commit adds a new feature that lets users type human-friendly Zcash names (like 'alice.zec' or 'bob.zcash') instead of long wallet addresses. The app looks up the real address from a remote service called zcashnames.com. The change also includes a few small swap-screen fixes and a safety catch around another name lookup. There is no clear security bug in the diff, but any name-to-address lookup adds a small risk that a malicious or compromised server could redirect payments.

Recommended action

Treat this as a routine feature addition with no immediate security patch needed. As a defense-in-depth step, the project should confirm that main.zcashnames.com is a trusted, documented Zcash Names resolver, consider pinning its certificate or supporting a user-configurable endpoint, and ensure the address-validation regex covers all supported Zcash address formats (including unified addresses if applicable).

Security signals we found

01

New network lookup of payment addresses from a single third-party endpoint (main.zcashnames.com)

02

Returned address is validated against a local Zcash address regex before use

03

Lookup is gated by a user preference that defaults to enabled

04

No certificate pinning or additional authentication for the lookup endpoint visible in the diff

05

Minor hardening: ThorChain name lookup now catches exceptions instead of crashing

Risk score

Why this scored 20/100

Our methodology →
Potential impact 2/30
Exploitability 3/25
Stealth signal 2/15
Affected reach 3/15
Confidence 7/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.