- disable Arbitrum - Minor fixes - Code cleanup
What changed, and why it matters
This commit mostly disables the Arbitrum cryptocurrency across build scripts and rewrites fee-estimation code. It also adds two small safety checks: one to prevent a crash when a Wownero wallet pointer is null, and another to wrap a Nano network call in a try/catch so an unexpected node response doesn't crash the app. There is no clear security vulnerability being fixed; it looks like routine cleanup and hardening.
Treat as a routine maintenance commit. Review the Arbitrum disablement for user-facing impact and verify the new null/exception guards cover all relevant call sites. No urgent security action is indicated from the diff alone.
Security signals we found
Null-pointer guard added in Wownero account list (wptr == null check)
Exception handling added around Nano receivable block processing
Arbitrum chain disabled in all platform build scripts
Fee-calculation code refactored from cascading if-statements to switch statement
Evidence from the diff
The diff removes –arbitrum from build configuration flags on Windows, Android, iOS, Linux, and macOS, and refactors lib/view_model/send/output.dart to use a switch statement for fee calculation. Two hardening changes are present: cw_wownero/lib/api/account_list.dart now returns early if wptr is null before dereferencing it, and cw_nano/lib/nano_client.dart wraps the receivable-block fetching and processing in a try/catch. The wallet_base and evm_chain_wallet signatures change updateEstimatedFeesParams to accept a nullable TransactionPriority. No explicit security bug, CVE, or researcher attribution is present in the commit or supplied references.
Changed components
cw_wownero/lib/api/account_list.dartcw_nano/lib/nano_client.dartlib/view_model/send/output.dartcw_core/lib/wallet_base.dartcw_evm/lib/evm_chain_wallet.dartcakewallet.batscripts/android/pubspec_gen.shscripts/ios/app_config.shscripts/linux/app_config.shscripts/macos/app_config.shInspect captured patch +106 / −107
diff --git a/cakewallet.bat b/cakewallet.bat
index d601741d..5870452b 100644
--- a/cakewallet.bat
+++ b/cakewallet.bat
@@ -1,5 +1,5 @@
@echo off
-set cw_win_app_config=--monero --bitcoin --ethereum --polygon --nano --bitcoinCash --solana --tron --dogecoin --base --arbitrum
+set cw_win_app_config=--monero --bitcoin --ethereum --polygon --nano --bitcoinCash --solana --tron --dogecoin --base
set cw_root=%cd%
set cw_archive_name=Cake Wallet.zip
set cw_archive_path=%cw_root%\%cw_archive_name%
diff --git a/cw_core/lib/wallet_base.dart b/cw_core/lib/wallet_base.dart
index 4aa0bd96..0a8a00bd 100644
--- a/cw_core/lib/wallet_base.dart
+++ b/cw_core/lib/wallet_base.dart
@@ -86,7 +86,7 @@ abstract class WalletBase<BalanceType extends Balance, HistoryType extends Trans
int calculateEstimatedFee(TransactionPriority priority, int? amount);
- Future<void> updateEstimatedFeesParams(TransactionPriority priority) async {}
+ Future<void> updateEstimatedFeesParams(TransactionPriority? priority) async {}
// void fetchTransactionsAsync(
// void Function(TransactionType transaction) onTransactionLoaded,
diff --git a/cw_evm/lib/evm_chain_wallet.dart b/cw_evm/lib/evm_chain_wallet.dart
index 75b08b0f..30ce827f 100644
--- a/cw_evm/lib/evm_chain_wallet.dart
+++ b/cw_evm/lib/evm_chain_wallet.dart
@@ -277,7 +277,7 @@ abstract class EVMChainWalletBase
int calculateEstimatedFee(TransactionPriority priority, int? amount) => 0;
@override
- Future<void> updateEstimatedFeesParams(TransactionPriority priority) async =>
+ Future<void> updateEstimatedFeesParams(TransactionPriority? priority) async =>
await _getEstimatedFees(priority);
Future<void> _getEstimatedFees(TransactionPriority? priority) async {
diff --git a/cw_nano/lib/nano_client.dart b/cw_nano/lib/nano_client.dart
index 812291f9..28546956 100644
--- a/cw_nano/lib/nano_client.dart
+++ b/cw_nano/lib/nano_client.dart
@@ -446,35 +446,34 @@ class NanoClient {
required String destinationAddress,
required String privateKey,
}) async {
- final receivableResponse = await ProxyWrapper().post(
- clearnetUri: _node!.uri,
- headers: getHeaders(_node!.uri.host),
- body: jsonEncode({
- "action": "receivable",
- "account": destinationAddress,
- "count": "-1",
- "source": true,
- }),
- );
- final receivableData = jsonDecode(receivableResponse.body) as Map<String, dynamic>;
- if (receivableData["blocks"] == "" || receivableData["blocks"] == null) {
- return 0;
- }
-
- dynamic blocks;
- if (receivableData["blocks"] is List<dynamic>) {
- var listBlocks = receivableData["blocks"] as List<dynamic>;
- if (listBlocks.isEmpty) {
+ try {
+ final receivableResponse = await ProxyWrapper().post(
+ clearnetUri: _node!.uri,
+ headers: getHeaders(_node!.uri.host),
+ body: jsonEncode({
+ "action": "receivable",
+ "account": destinationAddress,
+ "count": "-1",
+ "source": true,
+ }),
+ );
+ final receivableData = jsonDecode(receivableResponse.body) as Map<String, dynamic>;
+ if (receivableData["blocks"] == "" || receivableData["blocks"] == null) {
return 0;
}
- blocks = {for (var block in listBlocks) block['hash']: block};
- } else {
- blocks = receivableData["blocks"] as Map<String, dynamic>;
- }
- blocks = blocks as Map<String, dynamic>;
+ dynamic blocks;
+ if (receivableData["blocks"] is List<dynamic>) {
+ var listBlocks = receivableData["blocks"] as List<dynamic>;
+ if (listBlocks.isEmpty) {
+ return 0;
+ }
+ blocks = {for (var block in listBlocks) block['hash']: block};
+ } else {
+ blocks = receivableData["blocks"] as Map<String, dynamic>;
+ }
- try {
+ blocks = blocks as Map<String, dynamic>;
// confirm all receivable blocks:
for (final blockHash in blocks.keys) {
final block = blocks[blockHash];
diff --git a/cw_wownero/lib/api/account_list.dart b/cw_wownero/lib/api/account_list.dart
index 5bd18d51..5e9edb9f 100644
--- a/cw_wownero/lib/api/account_list.dart
+++ b/cw_wownero/lib/api/account_list.dart
@@ -19,6 +19,8 @@ wownero.SubaddressAccount? subaddressAccount;
bool isUpdating = false;
void refreshAccounts() {
+ if (wptr == null) return;
+
try {
isUpdating = true;
subaddressAccount = wownero.Wallet_subaddressAccount(wptr!);
@@ -31,6 +33,7 @@ void refreshAccounts() {
}
List<wownero.SubaddressAccountRow> getAllAccount() {
+ if (wptr == null) return [];
// final size = wownero.Wallet_numSubaddressAccounts(wptr!);
refreshAccounts();
int size = wownero.SubaddressAccount_getAll_size(subaddressAccount!);
diff --git a/lib/view_model/send/output.dart b/lib/view_model/send/output.dart
index 1caaf050..52b42bad 100644
--- a/lib/view_model/send/output.dart
+++ b/lib/view_model/send/output.dart
@@ -162,100 +162,96 @@ abstract class OutputBase with Store {
@action
Future<void> calculateEstimatedFee() async {
try {
- if (_wallet.type == WalletType.tron) {
- if (cryptoCurrencyHandler() == CryptoCurrency.trx) {
- final nativeEstimatedFee = tron!.getTronNativeEstimatedFee(_wallet) ?? '0';
- estimatedFee = double.parse(nativeEstimatedFee);
- } else {
- final trc20EstimatedFee = tron!.getTronTRC20EstimatedFee(_wallet) ?? '0';
- estimatedFee = double.parse(trc20EstimatedFee);
- }
- }
-
if (isEVMCompatibleChain(_wallet.type)) {
- if (_wallet.type == WalletType.arbitrum) {
- String? fee = cryptoCurrencyHandler() == CryptoCurrency.arbEth
- ? arbitrum!.getArbitrumNativeEstimatedFee(_wallet)
- : arbitrum!.getArbitrumERC20EstimatedFee(_wallet);
-
- estimatedFee = arbitrum!
- .formatterArbitrumAmountToDouble(amount: BigInt.from(double.parse(fee ?? '0.0')));
- return;
- }
-
await _wallet.updateEstimatedFeesParams(_settingsStore.priority[_wallet.type]!);
+ }
- double calculatedFee = 0.0;
+ int? fee = _wallet.calculateEstimatedFee(
+ _settingsStore.priority[_wallet.type]!,
+ formattedCryptoAmount,
+ );
- if (_wallet.type == WalletType.ethereum) {
+ switch (_wallet.type) {
+ case WalletType.monero:
+ estimatedFee = monero!.formatterMoneroAmountToDouble(amount: fee);
+ break;
+ case WalletType.bitcoin:
+ if (_settingsStore.priority[_wallet.type] ==
+ bitcoin!.getBitcoinTransactionPriorityCustom()) {
+ fee = bitcoin!.getEstimatedFeeWithFeeRate(
+ _wallet, _settingsStore.customBitcoinFeeRate, formattedCryptoAmount);
+ }
+
+ estimatedFee = bitcoin!.formatterBitcoinAmountToDouble(amount: fee);
+ break;
+ case WalletType.litecoin:
+ case WalletType.bitcoinCash:
+ case WalletType.dogecoin:
+ estimatedFee = bitcoin!.formatterBitcoinAmountToDouble(amount: fee);
+ break;
+ case WalletType.solana:
+ estimatedFee = solana!.getEstimateFees(_wallet) ?? 0.0;
+ break;
+ case WalletType.wownero:
+ estimatedFee = wownero!.formatterWowneroAmountToDouble(amount: fee);
+ break;
+ case WalletType.zano:
+ estimatedFee = zano!.formatterIntAmountToDouble(
+ amount: fee, currency: cryptoCurrencyHandler(), forFee: true);
+ break;
+ case WalletType.decred:
+ estimatedFee = decred!.formatterDecredAmountToDouble(amount: fee);
+ break;
+ case WalletType.tron:
+ if (cryptoCurrencyHandler() == CryptoCurrency.trx) {
+ final nativeEstimatedFee = tron!.getTronNativeEstimatedFee(_wallet) ?? '0';
+ estimatedFee = double.parse(nativeEstimatedFee);
+ } else {
+ final trc20EstimatedFee = tron!.getTronTRC20EstimatedFee(_wallet) ?? '0';
+ estimatedFee = double.parse(trc20EstimatedFee);
+ }
+ break;
+
+ /// EVMs
+ case WalletType.ethereum:
String? fee = cryptoCurrencyHandler() == CryptoCurrency.eth
? ethereum!.getEthereumNativeEstimatedFee(_wallet)
: ethereum!.getEthereumERC20EstimatedFee(_wallet);
- calculatedFee = ethereum!
+ estimatedFee = ethereum!
.formatterEthereumAmountToDouble(amount: BigInt.from(double.parse(fee ?? '0.0')));
- }
-
- if (_wallet.type == WalletType.polygon) {
+ break;
+ case WalletType.polygon:
String? fee = cryptoCurrencyHandler() == CryptoCurrency.maticpoly
? polygon!.getPolygonNativeEstimatedFee(_wallet)
: polygon!.getPolygonERC20EstimatedFee(_wallet);
- calculatedFee = polygon!
+ estimatedFee = polygon!
.formatterPolygonAmountToDouble(amount: BigInt.from(double.parse(fee ?? '0.0')));
- }
-
- if (_wallet.type == WalletType.base) {
+ break;
+ case WalletType.base:
String? fee = cryptoCurrencyHandler() == CryptoCurrency.baseEth
? base!.getBaseNativeEstimatedFee(_wallet)
: base!.getBaseERC20EstimatedFee(_wallet);
- calculatedFee =
+ estimatedFee =
base!.formatterBaseAmountToDouble(amount: BigInt.from(double.parse(fee ?? '0.0')));
- }
-
- estimatedFee = calculatedFee;
- }
-
- if (_wallet.type == WalletType.solana) {
- estimatedFee = solana!.getEstimateFees(_wallet) ?? 0.0;
- }
-
- int? fee = _wallet.calculateEstimatedFee(
- _settingsStore.priority[_wallet.type]!,
- formattedCryptoAmount,
- );
-
- if (_wallet.type == WalletType.bitcoin) {
- if (_settingsStore.priority[_wallet.type] ==
- bitcoin!.getBitcoinTransactionPriorityCustom()) {
- fee = bitcoin!.getEstimatedFeeWithFeeRate(
- _wallet, _settingsStore.customBitcoinFeeRate, formattedCryptoAmount);
- }
-
- estimatedFee = bitcoin!.formatterBitcoinAmountToDouble(amount: fee);
- }
-
- if (_wallet.type == WalletType.litecoin ||
- _wallet.type == WalletType.bitcoinCash ||
- _wallet.type == WalletType.dogecoin) {
- estimatedFee = bitcoin!.formatterBitcoinAmountToDouble(amount: fee);
- }
-
- if (_wallet.type == WalletType.monero) {
- estimatedFee = monero!.formatterMoneroAmountToDouble(amount: fee);
- }
-
- if (_wallet.type == WalletType.wownero) {
- estimatedFee = wownero!.formatterWowneroAmountToDouble(amount: fee);
- }
-
- if (_wallet.type == WalletType.zano) {
- estimatedFee = zano!.formatterIntAmountToDouble(
- amount: fee, currency: cryptoCurrencyHandler(), forFee: true);
- }
+ break;
+ case WalletType.arbitrum:
+ String? fee = cryptoCurrencyHandler() == CryptoCurrency.arbEth
+ ? arbitrum!.getArbitrumNativeEstimatedFee(_wallet)
+ : arbitrum!.getArbitrumERC20EstimatedFee(_wallet);
- if (_wallet.type == WalletType.decred) {
- estimatedFee = decred!.formatterDecredAmountToDouble(amount: fee);
+ estimatedFee = arbitrum!
+ .formatterArbitrumAmountToDouble(amount: BigInt.from(double.parse(fee ?? '0.0')));
+ break;
+ /// end EVMs
+
+ case WalletType.haven:
+ case WalletType.nano:
+ case WalletType.banano:
+ case WalletType.none:
+ // will not reach here as it doesn't have priority and this function is triggered only when priority changes
+ break;
}
} catch (e) {
printV(e.toString());
@@ -288,6 +284,7 @@ abstract class OutputBase with Store {
final SettingsStore _settingsStore;
final FiatConversionStore _fiatConversationStore;
final NumberFormat _cryptoNumberFormat;
+
@action
void setSendAll(String fullBalance) {
cryptoFullBalance = fullBalance;
diff --git a/scripts/android/pubspec_gen.sh b/scripts/android/pubspec_gen.sh
index 1d4dcadc..71aa1e1e 100755
--- a/scripts/android/pubspec_gen.sh
+++ b/scripts/android/pubspec_gen.sh
@@ -10,7 +10,7 @@ case $APP_ANDROID_TYPE in
CONFIG_ARGS="--monero"
;;
$CAKEWALLET)
- CONFIG_ARGS="--monero --bitcoin --ethereum --polygon --nano --bitcoinCash --solana --tron --wownero --zano --decred --dogecoin --base --arbitrum"
+ CONFIG_ARGS="--monero --bitcoin --ethereum --polygon --nano --bitcoinCash --solana --tron --wownero --zano --decred --dogecoin --base" # --arbitrum
;;
esac
diff --git a/scripts/ios/app_config.sh b/scripts/ios/app_config.sh
index 9a8ee840..d22b5ab3 100755
--- a/scripts/ios/app_config.sh
+++ b/scripts/ios/app_config.sh
@@ -31,7 +31,7 @@ case $APP_IOS_TYPE in
;;
$CAKEWALLET)
- CONFIG_ARGS="--monero --bitcoin --ethereum --polygon --nano --bitcoinCash --solana --tron --wownero --zano --decred --dogecoin --base --arbitrum"
+ CONFIG_ARGS="--monero --bitcoin --ethereum --polygon --nano --bitcoinCash --solana --tron --wownero --zano --decred --dogecoin --base" # --arbitrum
;;
esac
diff --git a/scripts/linux/app_config.sh b/scripts/linux/app_config.sh
index 78f01fa8..8663b1cd 100755
--- a/scripts/linux/app_config.sh
+++ b/scripts/linux/app_config.sh
@@ -13,7 +13,7 @@ CONFIG_ARGS=""
case $APP_LINUX_TYPE in
$CAKEWALLET)
- CONFIG_ARGS="--monero --bitcoin --ethereum --polygon --nano --bitcoinCash --solana --tron --wownero --dogecoin --base --arbitrum --excludeFlutterSecureStorage";;
+ CONFIG_ARGS="--monero --bitcoin --ethereum --polygon --nano --bitcoinCash --solana --tron --wownero --dogecoin --base --excludeFlutterSecureStorage";; # --arbitrum
esac
cp -rf pubspec_description.yaml pubspec.yaml
diff --git a/scripts/macos/app_config.sh b/scripts/macos/app_config.sh
index 589b5ec1..9d6b9454 100755
--- a/scripts/macos/app_config.sh
+++ b/scripts/macos/app_config.sh
@@ -36,7 +36,7 @@ case $APP_MACOS_TYPE in
$MONERO_COM)
CONFIG_ARGS="--monero";;
$CAKEWALLET)
- CONFIG_ARGS="--monero --bitcoin --ethereum --polygon --nano --bitcoinCash --solana --tron --wownero --dogecoin --base --arbitrum";;
+ CONFIG_ARGS="--monero --bitcoin --ethereum --polygon --nano --bitcoinCash --solana --tron --wownero --dogecoin --base";; # --arbitrum
esac
cp -rf pubspec_description.yaml pubspec.yaml
Why this scored 23/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.