Update monero_wallet_service.dart (#2666)
What changed, and why it matters
This commit removes a single line that saved wallet metadata to persistent storage after creating a Monero wallet from a BIP39 seed phrase. The change could mean wallet details are not written to disk at this point, which might affect recovery, wallet listing, or data consistency. There is no clear evidence in the commit itself that this is a security fix, exploit, or intentional vulnerability patch.
Review the associated pull request #2666 and any related tests or issue reports to determine whether removing `walletInfo.save()` was intentional and safe. Verify that wallet metadata is persisted elsewhere or that this path is not used in production. If not, consider restoring the save call or ensuring equivalent persistence.
Security signals we found
Removal of persistence call for wallet metadata
Potential inconsistency between saved derivation info and unsaved wallet info
No explicit security context in commit title or message
Evidence from the diff
In cw_monero/lib/monero_wallet_service.dart, the call to walletInfo.save() was removed following derivationInfo.save() during wallet creation from a BIP39 mnemonic. The surrounding code still creates the wallet, derives the legacy mnemonic, and returns the wallet. Without the commit message or PR context, the motivation is unclear. Possible effects include: wallet metadata not persisted, subsequent operations relying on walletInfo having an ID or saved state failing, or duplicate-wallet checks being bypassed. The change is too small and context-free to classify confidently as a security issue.
Changed components
cw_monero/lib/monero_wallet_service.dartMonero wallet creation from BIP39 seed pathInspect captured patch +0 / −1
diff --git a/cw_monero/lib/monero_wallet_service.dart b/cw_monero/lib/monero_wallet_service.dart
index f3834192..d339d7ee 100644
--- a/cw_monero/lib/monero_wallet_service.dart
+++ b/cw_monero/lib/monero_wallet_service.dart
@@ -394,7 +394,6 @@ class MoneroWalletService extends WalletService<
derivationInfo.derivationType = DerivationType.bip39;
derivationInfo.derivationPath = "m/44'/128'/0'/0/0";
await derivationInfo.save();
- walletInfo.save();
final legacyMnemonic =
getLegacySeedFromBip39(mnemonic, passphrase: passphrase ?? "");
Why this scored 25/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.