Add onionbalance Tor frontends to default node lists (#3431)
What changed, and why it matters
This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and makes Bitcoin fee estimates use a Tor address when Tor mode is on. The changes are infrastructure/configuration updates rather than code fixes for a vulnerability. There is no direct evidence in the commit that this is a security patch, but routing traffic through Tor can improve user privacy.
Treat as a routine infrastructure/privacy improvement. Review that the new .onion URIs match published Cake Wallet infrastructure, verify ProxyWrapper correctly enforces Tor routing when an onionUri is supplied, and confirm no clearnet fallback leaks occur when Tor is enabled. No urgent security action is indicated by the diff alone.
Security signals we found
Adds Tor/onion routing for Bitcoin fee estimates
Replaces single Tor nodes with load-balanced onionbalance frontends
Marks Cake Wallet Tor nodes as official in default node lists
No vulnerability fix, authentication change, or exploit mitigation visible in diff
Evidence from the diff
The diff modifies five files: four YAML server lists and one Dart wallet file. In the YAML files, old single-instance .onion addresses for Monero and Zcash are swapped for onionbalance-managed .onion frontends, and new official .onion Electrum servers are added for Bitcoin and Litecoin. In cw_bitcoin/lib/electrum_wallet.dart, the mempool fee fetcher now passes an onionUri to ProxyWrapper.get() so that, when Tor is enabled, the request can be routed to cakememcninjdqbaub3tp2iswuigxqtdoevnpgzkolmy4gvhrrsub3yd.onion instead of the clearnet mempool.cakewallet.com endpoint. No cryptographic, authentication, or input-validation logic is changed.
Changed components
assets/bitcoin_electrum_server_list.ymlassets/litecoin_electrum_server_list.ymlassets/node_list.ymlassets/zcash_node_list.ymlcw_bitcoin/lib/electrum_wallet.dartInspect captured patch +21 / −9
### assets/bitcoin_electrum_server_list.yml
@@ -9,6 +9,11 @@
uri: electrs.cakewallet.com:50001
isOfficial: true
label: "Cake Wallet Electrs"
+-
+ uri: cakebtc5pihzt3byjclxfumiwvtxj72auarshrsvmaatmwmr7dj6zyid.onion:50001
+ useSSL: false
+ isOfficial: true
+ label: "Cake Wallet (Tor)"
-
uri: fulcrum.sethforprivacy.com:50002
useSSL: true
### assets/litecoin_electrum_server_list.yml
@@ -5,6 +5,11 @@
isOfficial: true
isEnabledForAutoSwitching: true
label: "Cake Wallet"
+-
+ uri: cakeltcnzbdxhk3dhlzxjnnylxbfhhbx2njegaluyh35t7dca35vcnqd.onion:50001
+ useSSL: false
+ isOfficial: true
+ label: "Cake Wallet (Tor)"
-
uri: litecoin.stackwallet.com:20063
useSSL: true
### assets/node_list.yml
@@ -7,8 +7,9 @@
useSSL: true
isEnabledForAutoSwitching: true
-
- label: "Cake Wallet (Onion)"
- uri: cakexmrl7bonq7ovjka5kuwuyd3f7qnkz6z6s6dmsy3uckwra7bvggyd.onion:18081
+ label: "Cake Wallet (Tor)"
+ uri: cakexmrkbd7ptshw7vfzhzqgg77xgeavdrxm6zbu57lppfkj3fczbrqd.onion:18081
+ isOfficial: true
-
label: "Seth For Privacy"
uri: node.sethforprivacy.com:443
### assets/zcash_node_list.yml
@@ -11,10 +11,7 @@
isEnabledForAutoSwitching: true
label: "Zec.rocks"
-
- uri: 2c4whzg26j6hgjh22rxynj3oig4gm22ga7x74weclujywxye23v3u5id.onion:9067
+ uri: cakezecgh6enylxz3yya52pu4rq3bojy7zfhvnegqkq4qbbpzderjiqd.onion:9067
useSSL: false
- label: "Cake Wallet (Tor)"
--
- uri: bvp2l442g5ogma7rywzahm7eqyhpp3g26n3gvvxeioqn5csio2ir6myd.onion:9067
- useSSL: false
- label: "Cake Wallet (Tor #2)"
\ No newline at end of file
+ isOfficial: true
+ label: "Cake Wallet (Tor)"
\ No newline at end of file
### cw_bitcoin/lib/electrum_wallet.dart
@@ -794,7 +794,11 @@ abstract class ElectrumWalletBase
if (await checkIfMempoolAPIIsEnabled() && type == WalletType.bitcoin) {
try {
final response = await ProxyWrapper()
- .get(clearnetUri: Uri.parse("https://mempool.cakewallet.com/api/v1/fees/recommended"))
+ .get(
+ clearnetUri: Uri.parse("https://mempool.cakewallet.com/api/v1/fees/recommended"),
+ onionUri: Uri.parse(
+ "http://cakememcninjdqbaub3tp2iswuigxqtdoevnpgzkolmy4gvhrrsub3yd.onion/api/v1/fees/recommended"),
+ )
.timeout(Duration(seconds: 15));
final result = json.decode(response.body) as Map<String, dynamic>;Why this scored 21/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.