AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 38 Monero

CW-1175-Implement-swaps.xyz-swap-provider (#2526)

Public commit record

What the developer wrote

Authored by Serhii

81/100 · Strong
CW-1175-Implement-swaps.xyz-swap-provider (#2526)

* Integrate SwapsXYZ

* Remove print

* enhance SwapsXyz EVM token swap handling

* Disable fixed rate support in SwapsXyz provider

* enable fixed rate swap

* fix timestamp parsing

* remove sender and recipient address from fetchRate

* Improve SwapsXYZ trade approval logic

* fix trade ID overflow

* add Base chain support for swaps xyz

* Update lib/view_model/exchange/exchange_trade_view_model.dart

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* add missing support for Base

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
The short version

What changed, and why it matters

This commit adds a new cryptocurrency swap provider called Swaps.XYZ to the Cake Wallet app. It also adds the ability to send pre-built EVM (Ethereum, Polygon, Base) transactions with custom data, and to approve ERC-20 token spending before those swaps. The changes are broad but appear to be a normal feature integration. There is no direct evidence in the commit of a security vulnerability, but the new code paths handle real money transactions and rely on an external API, which always carries some risk.

Recommended action

Treat this as a feature commit that expands the trusted-computing base. Reviewers should audit: (1) whether api-v2.swaps.xyz responses are validated before being turned into transactions; (2) whether routerData/to/value are authenticated or could be swapped by a malicious or compromised API; (3) whether the token approval spender matches the intended router and is not attacker-controlled; (4) whether the new BigInt/base-unit conversions handle edge cases and negative values safely; and (5) whether the new Hive fields in Trade are backward-compatible. No immediate patch is indicated by the diff alone, but a focused security review of the new provider and EVM raw-tx path is warranted before release.

Security signals we found

01

New third-party API integration (api-v2.swaps.xyz) with API key authentication

02

Raw EVM call-data transaction creation path added to Ethereum, Polygon, and Base wallets

03

ERC-20 token approval helper added with spender/amount derived from trade object

04

Trade object extended with new serialized fields for router data, value, chainId, and approval flags

05

CI workflows updated to inject a new secret (SWAPSXYZ_API_KEY) into generated secrets file

06

Transaction hash pre-computed from raw hex for Swaps.XYZ alt-vm registration

Risk score

Why this scored 38/100

Our methodology →
Potential impact 8/30
Exploitability 7/25
Stealth signal 6/15
Affected reach 9/15
Confidence 5/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.