AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 58 Monero

Cw 1294 fix xo swaps bug (#2645)

Public commit record

What the developer wrote

Authored by Serhii

76/100 · Adequate
Cw 1294 fix xo swaps bug (#2645)

* Improve currency parsing with tag support

* changenow currency parsing fix

* exolix currency parsing fix

* letsExchange currency parsing fix

* stealth currency parsing fix

* trocador currency parsing fix

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit fixes how the Cake Wallet app figures out which cryptocurrency a user is sending or receiving during swaps. Before the fix, the app could confuse coins that share the same name but live on different blockchains (for example, USD Coin on Ethereum versus USD Coin on Polygon). That confusion could lead to the app picking the wrong wallet balance, building an incorrect transaction, or showing the user the wrong asset. The fix adds 'tag' support so the app can tell these similar coins apart, and it also improves error handling when a coin isn't enabled in the wallet.

Recommended action

Treat this as a functional bug fix with possible security side effects. Review whether any prior swap could have been constructed with mismatched currency tags, and consider adding automated tests that exercise multi-network tickers (e.g., USDC on ETH vs POL) across all exchange providers. Verify that the new orElse exceptions are surfaced to users clearly and do not crash silently.

Security signals we found

01

Currency confusion / wrong-asset selection when same ticker exists on multiple networks

02

Balance lookup by title only could select wrong token balance

03

Missing orElse on firstWhere could throw NoSuchMethodError / StateError instead of actionable message

04

Exchange trade metadata (userCurrencyFromRaw / userCurrencyToRaw) now includes network tag

05

XOSwap special-cases BASE and USDT default tags

Risk score

Why this scored 58/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 7/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.