What changed, and why it matters
This is a small defensive fix in Cake Wallet's Litecoin address handling. When the wallet tries to create a private 'change' address using the optional MimbleWimble (MWEB) feature, it now checks that an MWEB address actually exists before using it. Previously, if MWEB was enabled but no MWEB address had been generated, the code could try to use a non-existent address, likely causing a crash or returning an invalid change address. The change makes the wallet fall back to the normal change-address path instead.
Treat as a routine hardening fix. Review whether ensureMwebAddressUpToIndexExists() can silently fail or throw, and add tests covering the empty-mwebAddrs fallback path. No urgent security response is indicated by the diff alone.
Security signals we found
Defensive null/empty check added before list indexing
Fallback to standard change-address generation when optional MWEB address is unavailable
Potential crash/invalid-address scenario mitigated, but no explicit security claim by vendor
Evidence from the diff
In cw_bitcoin/lib/litecoin_wallet_addresses.dart, getChangeAddress() previously called ensureMwebAddressUpToIndexExists(1) and then unconditionally referenced mwebAddrs[0]. If ensureMwebAddressUpToIndexExists() failed to populate mwebAddrs (for example, due to a wallet state edge case or an exception swallowed elsewhere), the code would index into an empty list, producing a RangeError and likely crashing, or returning an uninitialized address record. The patch wraps the MWEB return path in if (mwebAddrs.isNotEmpty), so the wallet falls through to super.getChangeAddress() when no MWEB address is available. This is a hardening/fallback change rather than a clear-cut vulnerability fix, because the diff alone does not show an exploitable path to trigger the empty list condition.
Changed components
cw_bitcoin/lib/litecoin_wallet_addresses.dartLitecoin change address generationMWEB (MimbleWimble extension block) address handlingInspect captured patch +9 / −7
diff --git a/cw_bitcoin/lib/litecoin_wallet_addresses.dart b/cw_bitcoin/lib/litecoin_wallet_addresses.dart
index 1493fbfb..b0725f10 100644
--- a/cw_bitcoin/lib/litecoin_wallet_addresses.dart
+++ b/cw_bitcoin/lib/litecoin_wallet_addresses.dart
@@ -204,13 +204,15 @@ abstract class LitecoinWalletAddressesBase extends ElectrumWalletAddresses with
if (mwebEnabled) {
await ensureMwebAddressUpToIndexExists(1);
- updateChangeAddresses();
- return BitcoinAddressRecord(
- mwebAddrs[0],
- index: 0,
- type: SegwitAddresType.mweb,
- network: network,
- );
+ if (mwebAddrs.isNotEmpty) {
+ updateChangeAddresses();
+ return BitcoinAddressRecord(
+ mwebAddrs[0],
+ index: 0,
+ type: SegwitAddresType.mweb,
+ network: network,
+ );
+ }
}
return super.getChangeAddress();
Why this scored 32/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.