tentative fix for evm wallet creation issue after backup restore (#3316)
What changed, and why it matters
This commit is a bug-fix patch for Cake Wallet that addresses a problem where creating or restoring EVM (Ethereum-compatible) wallets would hang or fail after a backup restore. The changes add timeouts to WalletConnect initialization calls and move the WalletConnect setup off the main path so that if it fails, it does not block the wallet from being created or opened. There is no direct evidence in the commit of a security vulnerability being exploited; it appears to be a reliability fix that may reduce the risk of denial-of-service style hangs.
Treat as a reliability/stability fix rather than a security patch. Monitor for follow-up commits that make the fix non-tentative, and verify that the timeout durations (8s and 3s) do not cause legitimate slow connections to fail. No urgent security response is indicated by this diff alone.
Security signals we found
Timeout added to long-running async initialization to prevent indefinite hangs
Failure in WalletConnect setup is now caught and logged instead of crashing wallet load
Potential denial-of-service via unresponsive WalletConnect dependency is mitigated
No input validation, cryptographic, or access-control changes present
Evidence from the diff
The patch modifies two Dart files. In walletkit_service.dart, it wraps _walletKit.init() with an 8-second timeout and the accountsChanged emit with a 3-second timeout. In app_store.dart, it replaces the synchronous/awaited WalletConnect setup in walletLoad() with an unawaited call to a new helper _setupWalletConnect(), which catches and logs exceptions rather than propagating them. This prevents WalletConnect initialization failures or stalls from blocking wallet loading after backup restore. The commit title calls this a ‘tentative fix’ for an EVM wallet creation issue after backup restore.
Changed components
lib/src/screens/wallet_connect/services/walletkit_service.dartlib/store/app_store.dartWalletConnect/WalletKit integrationEVM wallet creation/restore flowInspect captured patch +20 / −5
diff --git a/lib/src/screens/wallet_connect/services/walletkit_service.dart b/lib/src/screens/wallet_connect/services/walletkit_service.dart
index 7d5a0ca6..a758b8b9 100644
--- a/lib/src/screens/wallet_connect/services/walletkit_service.dart
+++ b/lib/src/screens/wallet_connect/services/walletkit_service.dart
@@ -132,7 +132,10 @@ abstract class WalletKitServiceBase with Store {
debugPrint('Intializing walletKit');
if (!isInitialized) {
try {
- await _walletKit.init();
+ await _walletKit.init().timeout(
+ const Duration(seconds: 8),
+ onTimeout: () => throw TimeoutException('walletKit init timed out'),
+ );
debugPrint('Initialized');
isInitialized = true;
} catch (e) {
@@ -206,7 +209,7 @@ abstract class WalletKitServiceBase with Store {
name: 'accountsChanged',
data: [chain.publicKey],
),
- );
+ ).timeout(const Duration(seconds: 3));
}
} on ReownSignError catch (e) {
if (e.code == 6) {
diff --git a/lib/store/app_store.dart b/lib/store/app_store.dart
index dd41fe94..70ff844d 100644
--- a/lib/store/app_store.dart
+++ b/lib/store/app_store.dart
@@ -1,3 +1,5 @@
+import 'dart:async';
+
import 'package:cake_wallet/core/amount_parsing_proxy.dart';
import 'package:cake_wallet/di.dart';
import 'package:cake_wallet/entities/preferences_key.dart';
@@ -6,6 +8,7 @@ import 'package:cake_wallet/src/screens/wallet_connect/services/walletkit_servic
import 'package:cake_wallet/themes/core/theme_store.dart';
import 'package:cake_wallet/utils/exception_handler.dart';
import 'package:cw_core/transaction_info.dart';
+import 'package:cw_core/utils/print_verbose.dart';
import 'package:cw_core/wallet_type.dart';
import 'package:mobx/mobx.dart';
import 'package:cw_core/balance.dart';
@@ -63,13 +66,22 @@ abstract class AppStoreBase with Store {
this.wallet!.setExceptionHandler(ExceptionHandler.onError);
if (isWalletConnectCompatibleChain(wallet.type)) {
- await getIt.get<WalletKitService>().onDispose();
- getIt.get<WalletKitService>().create();
- await getIt.get<WalletKitService>().init();
+ unawaited(_setupWalletConnect());
}
await getIt.get<SharedPreferences>().setString(PreferencesKey.currentWalletName, wallet.name);
await getIt
.get<SharedPreferences>()
.setInt(PreferencesKey.currentWalletType, serializeToInt(wallet.type));
}
+
+ Future<void> _setupWalletConnect() async {
+ try {
+ final wcService = getIt.get<WalletKitService>();
+ await wcService.onDispose();
+ wcService.create();
+ await wcService.init();
+ } catch (e, s) {
+ printV('WalletConnect setup failed: $e\n$s');
+ }
+ }
}
Why this scored 23/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.