Fix BSC and ARB QR scan in pay-anything flow (#3075)
What changed, and why it matters
This commit fixes a bug in Cake Wallet's 'pay-anything' QR scanning flow so that BSC (Binance Smart Chain) and Arbitrum URIs are correctly recognized. Previously, scanning a QR code for these networks could fail to identify the right wallet/currency, leading to a broken or confusing payment experience. The change also adds 'bsc' as a recognized currency keyword and uses the network chain ID embedded in Ethereum-style URIs to pick the correct currency instead of relying only on the URI scheme.
Treat as a routine functional bug fix. Reviewers should verify that getCryptoCurrencyByChainId and getChainIdByCryptoCurrency are consistent and that no other EVM chain aliases are missing. No immediate security response is indicated by the diff.
Security signals we found
Functional bug fix in payment/address parsing
Adds missing currency alias 'bsc' -> BNB
ERC-681 chainId now drives currency selection for Ethereum URIs
No explicit security claims in commit message or diff
Evidence from the diff
The patch updates two files. In cw_core/lib/crypto_currency.dart, it adds ‘bsc’: bnb to the string-to-currency map so BSC URIs can resolve to BNB. In lib/core/universal_address_detector.dart, it imports cw_core/payment_uris.dart and changes currency detection for Ethereum-scheme URIs: if the scheme is ‘ethereum’, it parses the URI as an ERC-681 URI, extracts chainId, and maps that to a CryptoCurrency via getCryptoCurrencyByChainId; otherwise it falls back to scheme-based lookup and derives chainId from the currency. This makes BSC and Arbitrum QR codes work in the universal pay-anything flow.
Changed components
cw_core/lib/crypto_currency.dartlib/core/universal_address_detector.dartCake Wallet pay-anything QR scan flowBSC and Arbitrum payment URI handlingInspect captured patch +13 / −3
diff --git a/cw_core/lib/crypto_currency.dart b/cw_core/lib/crypto_currency.dart
index 879534d7..1371ed3e 100644
--- a/cw_core/lib/crypto_currency.dart
+++ b/cw_core/lib/crypto_currency.dart
@@ -303,6 +303,7 @@ class CryptoCurrency extends EnumerableItem<int> with Serializable<int> implemen
'lightning': btcln,
'base': baseEth,
'arbitrum': arbEth,
+ 'bsc': bnb,
};
static CryptoCurrency deserialize({required int raw}) {
diff --git a/lib/core/universal_address_detector.dart b/lib/core/universal_address_detector.dart
index 397ee73f..ab90c725 100644
--- a/lib/core/universal_address_detector.dart
+++ b/lib/core/universal_address_detector.dart
@@ -2,6 +2,7 @@ import 'package:cake_wallet/utils/payment_request.dart';
import 'package:cake_wallet/core/address_validator.dart';
import 'package:cw_core/crypto_currency.dart';
import 'package:cw_core/lnurl.dart';
+import 'package:cw_core/payment_uris.dart';
import 'package:cw_core/wallet_type.dart';
import 'package:cw_core/currency_for_wallet_type.dart';
@@ -72,10 +73,18 @@ class UniversalAddressDetector {
final paymentRequest = PaymentRequest.fromUri(uri);
- // Determine currency from scheme
- final currency = CryptoCurrency.fromString(uri.scheme.toLowerCase());
+ CryptoCurrency currency;
+ int? chainId;
+ if (uri.scheme.toLowerCase() == 'ethereum') {
+ final erc681 = ERC681URI.fromUri(uri);
+ chainId = erc681.chainId;
+ currency = getCryptoCurrencyByChainId(chainId);
+ } else {
+ currency = CryptoCurrency.fromString(uri.scheme.toLowerCase());
+ chainId = getChainIdByCryptoCurrency(currency);
+ }
+
final walletType = cryptoCurrencyOrTokenToWalletType(currency);
- final chainId = getChainIdByCryptoCurrency(currency);
return AddressDetectionResult(
address: paymentRequest.address,
Why this scored 23/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.