What changed, and why it matters
This commit contains three small fixes: a loop bug in Zcash address handling, a reclassification of a Ledger error message, and routine build number bumps. The Zcash fix changes two mistaken index references from 'i' to 'k' inside a loop, which likely caused the wrong wallet account to be checked for hidden/used transparent addresses. This could affect address rotation or privacy behavior for Zcash transparent addresses, but it is a correctness bug rather than an obvious exploit. The Ledger change moves 'transport error' from a list of known Ledger errors to a list of ignored/generic exception strings, which may reduce false crash reports but does not appear security-sensitive. The build number changes are administrative.
Review the Zcash transparent address rotation logic to confirm the corrected indices resolve the intended behavior and do not leave residual privacy or address-reuse issues. No immediate security patch appears required, but treat the Zcash fix as a privacy-relevant correctness fix.
Security signals we found
Loop-index misuse in address-rotation logic (correctness/privacy-relevant bug)
No explicit security claim in commit title or message
No CVE, advisory, or researcher attribution present
No cryptographic, authentication, or authorization changes
Evidence from the diff
In cw_zcash/lib/src/zcash_taddress_rotation.dart, a loop iterating over wallet indices ‘k’ incorrectly used ‘wis[i]’ (an outer loop index) when fetching hidden and used transparent addresses. The patch corrects these to ‘wis[k]’. This is a classic loop-index bug that could cause the rotation logic to inspect the wrong account’s addresses, potentially duplicating checks or missing addresses. In lib/utils/exception_handler.dart, the string ‘transport error’ is removed from isLedgerError’s known Ledger error list and added to the generic ignored exception list, changing how such errors are logged/filtered. scripts/android/app_env.sh and scripts/ios/app_env.sh only bump CAKEWALLET_BUILD_NUMBER.
Changed components
cw_zcash/lib/src/zcash_taddress_rotation.dartlib/utils/exception_handler.dartscripts/android/app_env.shscripts/ios/app_env.shInspect captured patch +5 / −5
diff --git a/cw_zcash/lib/src/zcash_taddress_rotation.dart b/cw_zcash/lib/src/zcash_taddress_rotation.dart
index 7a3f3ba8..7b17afd1 100644
--- a/cw_zcash/lib/src/zcash_taddress_rotation.dart
+++ b/cw_zcash/lib/src/zcash_taddress_rotation.dart
@@ -239,8 +239,8 @@ class ZcashTaddressRotation {
final List<String> hiddenAddresses_ = [];
for (int k = 0; k < wis.length; k++) {
- final addrs = await wis[i].getHiddenAddresses();
- final addr2 = await wis[i].getUsedAddresses();
+ final addrs = await wis[k].getHiddenAddresses();
+ final addr2 = await wis[k].getUsedAddresses();
hiddenAddresses_.addAll(addrs);
hiddenAddresses_.addAll(addr2);
}
diff --git a/lib/utils/exception_handler.dart b/lib/utils/exception_handler.dart
index 1b327466..f7f6de30 100644
--- a/lib/utils/exception_handler.dart
+++ b/lib/utils/exception_handler.dart
@@ -198,7 +198,6 @@ class ExceptionHandler {
'Exception: 6e00',
'Exception: 6985',
'Exception: 5515',
- 'transport error'
];
static bool isLedgerError(Object exception) =>
@@ -297,6 +296,7 @@ class ExceptionHandler {
"_QueuedFuture.execute (package:universal_ble/src/queue.dart:65)",
"reown_core/relay_client/websocket/websocket_handler.dart",
"Image upload failed due to loss of GPU access",
+ 'transport error',
];
static Future<void> _addDeviceInfo(File file) async {
diff --git a/scripts/android/app_env.sh b/scripts/android/app_env.sh
index 8383f705..f4e50e42 100644
--- a/scripts/android/app_env.sh
+++ b/scripts/android/app_env.sh
@@ -22,7 +22,7 @@ MONERO_COM_SCHEME="monero.com"
CAKEWALLET_NAME="Cake Wallet"
CAKEWALLET_VERSION="5.8.0"
-CAKEWALLET_BUILD_NUMBER=4299
+CAKEWALLET_BUILD_NUMBER=4301
CAKEWALLET_BUNDLE_ID="com.cakewallet.cake_wallet"
CAKEWALLET_PACKAGE="com.cakewallet.cake_wallet"
CAKEWALLET_SCHEME="cakewallet"
diff --git a/scripts/ios/app_env.sh b/scripts/ios/app_env.sh
index 05308d83..53a10bf2 100644
--- a/scripts/ios/app_env.sh
+++ b/scripts/ios/app_env.sh
@@ -18,7 +18,7 @@ MONERO_COM_BUNDLE_ID="com.cakewallet.monero"
CAKEWALLET_NAME="Cake Wallet"
CAKEWALLET_VERSION="5.8.0"
-CAKEWALLET_BUILD_NUMBER=366
+CAKEWALLET_BUILD_NUMBER=368
CAKEWALLET_BUNDLE_ID="com.fotolockr.cakewallet"
Why this scored 24/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.