AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 35 Monero

feat: Integrate Jupiter DEX (#2761)

Public commit record

What the developer wrote

Authored by David Adegoke

88/100 · Strong
feat: Integrate Jupiter DEX (#2761)

* feat: Integrate Jupiter DEX

* feat: Enable internal swaps

* feat: implement Jupiter swap execution api and enhance trade handling

- Added executeSwap method to handle signed swap transactions via the execute endpoint.
- Updated signAndPrepareJupiterSwapTransaction to include request ID and handle swap execution response.
- Modified trade details to use txId instead of id for Jupiter trades.
- Enhanced error handling for swap execution with user-friendly messages.
- Updated sendviewmodel to manage trade state updates after transaction commitment.

* fix: null error after successfully swapping

* fix: Finallyyy fixed the annoying tx history issue for solana dex swaps

* fix: update inputAddress to use toAddress in JupiterExchangeProvider

* feat: enhance transaction handling and token balance updates

- Cut down tx fetch/update time for transactions update after swapping
- Added TransactionFetchResult class to hold parsed transactions and token mints.
- Added pollForTransaction method to handle transaction polling with exponential backoff.
- Conditionally hide the external send button based on provider type.

* feat: add fees to trade object and handle null case

* feat: add Jupiter referral fee and account configuration

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit adds a new Jupiter DEX (decentralized exchange) integration to Cake Wallet, allowing users to swap Solana-based tokens directly inside the app. It also changes how Solana transactions are parsed and how balances are updated after swaps. The changes are mostly feature additions and UI tweaks, not a security patch. There are some code-quality concerns—such as trusting external API responses, deriving counterparty addresses from the first account in an instruction, and adding referral fee configuration—but no direct evidence in the diff of an exploitable vulnerability.

Recommended action

Treat this as a feature commit, not a security fix. Reviewers should audit JupiterExchangeProvider for MITM/API spoofing resilience, verify that the Solana swap parser's synthetic transactions cannot misattribute senders/recipients, confirm referral fee values are validated against a known allowlist, and ensure that exposing previously-private wallet methods does not introduce unintended call sites. Consider adding independent on-chain confirmation before marking Jupiter trades as completed.

Security signals we found

01

New third-party API integration (Jupiter /ultra/v1/order and /execute) over HTTPS via ProxyWrapper

02

Signed transactions are sent to Jupiter's execute endpoint; server response status/signature is trusted for UI state updates

03

Solana swap parsing derives 'to'/'from' addresses from instructions[0].accounts[0] when the real counterparty may be a program or intermediate account

04

Referral fee configuration is read from secrets and passed to Jupiter order params with only a 0-10000 bps range check

05

Private Solana wallet methods (updateTokenBalance, addTransactionsToTransactionHistory, updateSPLTokenTransactions) are now public, increasing internal API surface

06

Transaction parsing now returns lists and uses maxSupportedTransactionVersion: 1 with skipVerification: true

07

Error handling maps Jupiter error codes to user-facing strings but does not appear to validate on-chain outcomes independently

Risk score

Why this scored 35/100

Our methodology →
Potential impact 8/30
Exploitability 7/25
Stealth signal 5/15
Affected reach 6/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.