What changed, and why it matters
This commit removes Zcash 'Warp' wallet-sync components from the macOS build of Cake Wallet, bumps the macOS app build numbers, slightly increases a startup delay, and changes one error case to return false instead of throwing an exception. There is no direct evidence in the commit that this fixes an active security vulnerability; it looks like a build cleanup and minor hardening change.
Treat as a routine build/maintenance commit. If the removed Warp components were used for Zcash shielded transactions on macOS, verify that no Zcash wallet functionality is broken and that users are informed if the feature is being deprecated. Review the hardware-wallet error-handling change to ensure returning false does not bypass intended security prompts.
Security signals we found
Removal of native framework (WarpApiFFI.xcframework) from macOS target
Removal of Flutter plugin dependencies cw_mweb and sp_scanner from macOS Podfile.lock
Behavior change: requireHardwareWalletConnection() now returns false instead of throwing Exception('Wallet not found')
Minor timing change: window-size platform channel delay increased from 100 ms to 200 ms
Evidence from the diff
The diff removes WarpApiFFI.xcframework and the cw_mweb/sp_scanner Flutter plugin references from the macOS Xcode project and Podfile.lock, indicating Zcash ‘warp’ sync support is being stripped from the macOS target. It also increases a platform-channel readiness delay from 100 ms to 200 ms in cw_core/lib/window_size.dart, and changes MoneroWalletService.requireHardwareWalletConnection() to return false instead of throwing when a wallet is not found. The commit message only says ‘remove warp from macos’. No CVE, advisory, or vendor security statement is supplied.
Changed components
macOS build targetcw_core/lib/window_size.dartcw_monero/lib/monero_wallet_service.dartmacos/Podfile.lockmacos/Runner.xcodeproj/project.pbxprojscripts/macos/app_env.shInspect captured patch +22 / −38
diff --git a/cw_core/lib/window_size.dart b/cw_core/lib/window_size.dart
index 4a084897..6b406e48 100644
--- a/cw_core/lib/window_size.dart
+++ b/cw_core/lib/window_size.dart
@@ -10,7 +10,7 @@ Future<void> setDefaultMinimumWindowSize() async {
try {
// A small delay to confirm that our native platform channels are ready
- await Future.delayed(const Duration(milliseconds: 100));
+ await Future.delayed(const Duration(milliseconds: 200));
final result = await _channel.invokeMethod(
'setMinWindowSize',
diff --git a/cw_monero/lib/monero_wallet_service.dart b/cw_monero/lib/monero_wallet_service.dart
index d339d7ee..83f8b467 100644
--- a/cw_monero/lib/monero_wallet_service.dart
+++ b/cw_monero/lib/monero_wallet_service.dart
@@ -564,7 +564,7 @@ class MoneroWalletService extends WalletService<
Future<bool> requireHardwareWalletConnection(String name) async {
final walletInfo = await WalletInfo.get(name, getType());
if (walletInfo == null) {
- throw Exception('Wallet not found');
+ return false;
}
return walletInfo.isHardwareWallet;
}
diff --git a/macos/Podfile.lock b/macos/Podfile.lock
index 3af0eb37..15bd774c 100644
--- a/macos/Podfile.lock
+++ b/macos/Podfile.lock
@@ -3,8 +3,6 @@ PODS:
- FlutterMacOS
- connectivity_plus (0.0.1):
- FlutterMacOS
- - cw_mweb (0.0.1):
- - FlutterMacOS
- device_info_plus (0.0.1):
- FlutterMacOS
- devicelocale (0.0.1):
@@ -37,8 +35,6 @@ PODS:
- shared_preferences_foundation (0.0.1):
- Flutter
- FlutterMacOS
- - sp_scanner (0.0.1):
- - FlutterMacOS
- sqflite_darwin (0.0.4):
- Flutter
- FlutterMacOS
@@ -80,7 +76,6 @@ PODS:
DEPENDENCIES:
- bitbox_flutter (from `Flutter/ephemeral/.symlinks/plugins/bitbox_flutter/macos`)
- connectivity_plus (from `Flutter/ephemeral/.symlinks/plugins/connectivity_plus/macos`)
- - cw_mweb (from `Flutter/ephemeral/.symlinks/plugins/cw_mweb/macos`)
- device_info_plus (from `Flutter/ephemeral/.symlinks/plugins/device_info_plus/macos`)
- devicelocale (from `Flutter/ephemeral/.symlinks/plugins/devicelocale/macos`)
- dnssec_proof (from `Flutter/ephemeral/.symlinks/plugins/dnssec_proof/macos`)
@@ -96,7 +91,6 @@ DEPENDENCIES:
- path_provider_foundation (from `Flutter/ephemeral/.symlinks/plugins/path_provider_foundation/darwin`)
- share_plus (from `Flutter/ephemeral/.symlinks/plugins/share_plus/macos`)
- shared_preferences_foundation (from `Flutter/ephemeral/.symlinks/plugins/shared_preferences_foundation/darwin`)
- - sp_scanner (from `Flutter/ephemeral/.symlinks/plugins/sp_scanner/macos`)
- sqflite_darwin (from `Flutter/ephemeral/.symlinks/plugins/sqflite_darwin/darwin`)
- sqlite3_flutter_libs (from `Flutter/ephemeral/.symlinks/plugins/sqlite3_flutter_libs/darwin`)
- torch_dart (from `Flutter/ephemeral/.symlinks/plugins/torch_dart/macos`)
@@ -114,8 +108,6 @@ EXTERNAL SOURCES:
:path: Flutter/ephemeral/.symlinks/plugins/bitbox_flutter/macos
connectivity_plus:
:path: Flutter/ephemeral/.symlinks/plugins/connectivity_plus/macos
- cw_mweb:
- :path: Flutter/ephemeral/.symlinks/plugins/cw_mweb/macos
device_info_plus:
:path: Flutter/ephemeral/.symlinks/plugins/device_info_plus/macos
devicelocale:
@@ -146,8 +138,6 @@ EXTERNAL SOURCES:
:path: Flutter/ephemeral/.symlinks/plugins/share_plus/macos
shared_preferences_foundation:
:path: Flutter/ephemeral/.symlinks/plugins/shared_preferences_foundation/darwin
- sp_scanner:
- :path: Flutter/ephemeral/.symlinks/plugins/sp_scanner/macos
sqflite_darwin:
:path: Flutter/ephemeral/.symlinks/plugins/sqflite_darwin/darwin
sqlite3_flutter_libs:
@@ -164,7 +154,6 @@ EXTERNAL SOURCES:
SPEC CHECKSUMS:
bitbox_flutter: 16088f5c7febacf894f4d07bbdfb441c9f0757fe
connectivity_plus: 0a976dfd033b59192912fa3c6c7b54aab5093802
- cw_mweb: 7440b12ead811dda972a9918442ea2a458e8742c
device_info_plus: 5401765fde0b8d062a2f8eb65510fb17e77cf07f
devicelocale: 9f0f36ac651cabae2c33f32dcff4f32b61c38225
dnssec_proof: d461cac7bd3301eb7447f87936745a0c1ae0a67e
@@ -181,7 +170,6 @@ SPEC CHECKSUMS:
path_provider_foundation: 2b6b4c569c0fb62ec74538f866245ac84301af46
share_plus: 1fa619de8392a4398bfaf176d441853922614e89
shared_preferences_foundation: fcdcbc04712aee1108ac7fda236f363274528f78
- sp_scanner: 269d96e0ec3173e69156be7239b95182be3b8303
sqflite_darwin: 5a7236e3b501866c1c9befc6771dfd73ffb8702d
sqlite3: 73513155ec6979715d3904ef53a8d68892d4032b
sqlite3_flutter_libs: 86f82662868ee26ff3451f73cac9c5fc2a1f57fa
diff --git a/macos/Runner.xcodeproj/project.pbxproj b/macos/Runner.xcodeproj/project.pbxproj
index e29989c8..0b71d21b 100644
--- a/macos/Runner.xcodeproj/project.pbxproj
+++ b/macos/Runner.xcodeproj/project.pbxproj
@@ -28,7 +28,6 @@
33CC11132044BFA00003C045 /* MainFlutterWindow.swift in Sources */ = {isa = PBXBuildFile; fileRef = 33CC11122044BFA00003C045 /* MainFlutterWindow.swift */; };
83FF6BF911B29965D3589BE7 /* Pods_Runner.framework in Frameworks */ = {isa = PBXBuildFile; fileRef = BD06F8F6E3797AC031038136 /* Pods_Runner.framework */; };
9F565D5929954F53009A75FB /* secRandom.swift in Sources */ = {isa = PBXBuildFile; fileRef = 9F565D5729954F53009A75FB /* secRandom.swift */; };
- CE46BF642F15C020000A6140 /* WarpApiFFI.xcframework in CopyFiles */ = {isa = PBXBuildFile; fileRef = CE46BF632F15C020000A6140 /* WarpApiFFI.xcframework */; settings = {ATTRIBUTES = (CodeSignOnCopy, RemoveHeadersOnCopy, ); }; };
CE75FC4A2C147EBA00CCC46E /* wownero_libwallet2_api_c.dylib in CopyFiles */ = {isa = PBXBuildFile; fileRef = CE75FC492C147EBA00CCC46E /* wownero_libwallet2_api_c.dylib */; settings = {ATTRIBUTES = (CodeSignOnCopy, ); }; };
CED5DBE42BE59BBF0065028F /* monero_libwallet2_api_c.dylib in CopyFiles */ = {isa = PBXBuildFile; fileRef = CED5DBE32BE59BBF0065028F /* monero_libwallet2_api_c.dylib */; settings = {ATTRIBUTES = (CodeSignOnCopy, ); }; };
/* End PBXBuildFile section */
@@ -60,7 +59,6 @@
dstPath = "";
dstSubfolderSpec = 10;
files = (
- CE46BF642F15C020000A6140 /* WarpApiFFI.xcframework in CopyFiles */,
CE75FC4A2C147EBA00CCC46E /* wownero_libwallet2_api_c.dylib in CopyFiles */,
CED5DBE42BE59BBF0065028F /* monero_libwallet2_api_c.dylib in CopyFiles */,
);
@@ -92,7 +90,6 @@
9F1E7BFB2BF2D27500C28C9A /* Runner.entitlements */ = {isa = PBXFileReference; lastKnownFileType = text.plist.entitlements; path = Runner.entitlements; sourceTree = "<group>"; };
9F565D5729954F53009A75FB /* secRandom.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; name = secRandom.swift; path = CakeWallet/secRandom.swift; sourceTree = "<group>"; };
BD06F8F6E3797AC031038136 /* Pods_Runner.framework */ = {isa = PBXFileReference; explicitFileType = wrapper.framework; includeInIndex = 0; path = Pods_Runner.framework; sourceTree = BUILT_PRODUCTS_DIR; };
- CE46BF632F15C020000A6140 /* WarpApiFFI.xcframework */ = {isa = PBXFileReference; lastKnownFileType = wrapper.xcframework; name = WarpApiFFI.xcframework; path = ../scripts/zcash_lib/WarpApiFFI.xcframework; sourceTree = "<group>"; };
CE75FC492C147EBA00CCC46E /* wownero_libwallet2_api_c.dylib */ = {isa = PBXFileReference; lastKnownFileType = "compiled.mach-o.dylib"; path = wownero_libwallet2_api_c.dylib; sourceTree = "<group>"; };
CED5DBE32BE59BBF0065028F /* monero_libwallet2_api_c.dylib */ = {isa = PBXFileReference; lastKnownFileType = "compiled.mach-o.dylib"; path = monero_libwallet2_api_c.dylib; sourceTree = "<group>"; };
/* End PBXFileReference section */
@@ -123,7 +120,6 @@
33CC10E42044A3C60003C045 = {
isa = PBXGroup;
children = (
- CE46BF632F15C020000A6140 /* WarpApiFFI.xcframework */,
CE75FC492C147EBA00CCC46E /* wownero_libwallet2_api_c.dylib */,
CED5DBE32BE59BBF0065028F /* monero_libwallet2_api_c.dylib */,
9F565D5729954F53009A75FB /* secRandom.swift */,
@@ -212,7 +208,7 @@
33CC110E2044A8840003C045 /* Bundle Framework */,
3399D490228B24CF009A79C7 /* ShellScript */,
CED5DBE02BE59B230065028F /* CopyFiles */,
- E61573101FD4A1463A0EF3D1 /* [CP] Embed Pods Frameworks */,
+ 3231D31843A573A7E0956F01 /* [CP] Embed Pods Frameworks */,
);
buildRules = (
);
@@ -281,6 +277,23 @@
/* End PBXResourcesBuildPhase section */
/* Begin PBXShellScriptBuildPhase section */
+ 3231D31843A573A7E0956F01 /* [CP] Embed Pods Frameworks */ = {
+ isa = PBXShellScriptBuildPhase;
+ buildActionMask = 2147483647;
+ files = (
+ );
+ inputFileListPaths = (
+ "${PODS_ROOT}/Target Support Files/Pods-Runner/Pods-Runner-frameworks-${CONFIGURATION}-input-files.xcfilelist",
+ );
+ name = "[CP] Embed Pods Frameworks";
+ outputFileListPaths = (
+ "${PODS_ROOT}/Target Support Files/Pods-Runner/Pods-Runner-frameworks-${CONFIGURATION}-output-files.xcfilelist",
+ );
+ runOnlyForDeploymentPostprocessing = 0;
+ shellPath = /bin/sh;
+ shellScript = "\"${PODS_ROOT}/Target Support Files/Pods-Runner/Pods-Runner-frameworks.sh\"\n";
+ showEnvVarsInLog = 0;
+ };
3399D490228B24CF009A79C7 /* ShellScript */ = {
isa = PBXShellScriptBuildPhase;
alwaysOutOfDate = 1;
@@ -341,23 +354,6 @@
shellScript = "diff \"${PODS_PODFILE_DIR_PATH}/Podfile.lock\" \"${PODS_ROOT}/Manifest.lock\" > /dev/null\nif [ $? != 0 ] ; then\n # print error to STDERR\n echo \"error: The sandbox is not in sync with the Podfile.lock. Run 'pod install' or update your CocoaPods installation.\" >&2\n exit 1\nfi\n# This output is used by Xcode 'outputs' to avoid re-running this script phase.\necho \"SUCCESS\" > \"${SCRIPT_OUTPUT_FILE_0}\"\n";
showEnvVarsInLog = 0;
};
- E61573101FD4A1463A0EF3D1 /* [CP] Embed Pods Frameworks */ = {
- isa = PBXShellScriptBuildPhase;
- buildActionMask = 2147483647;
- files = (
- );
- inputFileListPaths = (
- "${PODS_ROOT}/Target Support Files/Pods-Runner/Pods-Runner-frameworks-${CONFIGURATION}-input-files.xcfilelist",
- );
- name = "[CP] Embed Pods Frameworks";
- outputFileListPaths = (
- "${PODS_ROOT}/Target Support Files/Pods-Runner/Pods-Runner-frameworks-${CONFIGURATION}-output-files.xcfilelist",
- );
- runOnlyForDeploymentPostprocessing = 0;
- shellPath = /bin/sh;
- shellScript = "\"${PODS_ROOT}/Target Support Files/Pods-Runner/Pods-Runner-frameworks.sh\"\n";
- showEnvVarsInLog = 0;
- };
/* End PBXShellScriptBuildPhase section */
/* Begin PBXSourcesBuildPhase section */
diff --git a/scripts/macos/app_env.sh b/scripts/macos/app_env.sh
index 797b470a..0d47299d 100755
--- a/scripts/macos/app_env.sh
+++ b/scripts/macos/app_env.sh
@@ -17,12 +17,12 @@ fi
MONERO_COM_NAME="Monero.com"
MONERO_COM_VERSION="5.8.0"
-MONERO_COM_BUILD_NUMBER=75
+MONERO_COM_BUILD_NUMBER=76
MONERO_COM_BUNDLE_ID="com.cakewallet.monero"
CAKEWALLET_NAME="Cake Wallet"
CAKEWALLET_VERSION="5.8.0"
-CAKEWALLET_BUILD_NUMBER=143
+CAKEWALLET_BUILD_NUMBER=144
CAKEWALLET_BUNDLE_ID="com.fotolockr.cakewallet"
if ! [[ " ${TYPES[*]} " =~ " ${APP_MACOS_TYPE} " ]]; then
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.