Enable SSL for some nodes [skip ci]
What changed, and why it matters
This commit turns on HTTPS/SSL encryption for several built-in Ethereum and Polygon server connections in the Cake Wallet app. Without SSL, data sent between the wallet and those servers could be read or tampered with by attackers on the same network. The change is a security improvement, not a vulnerability introduction, but it fixes a real exposure for users who relied on these default nodes.
Verify that the wallet client actually honors `useSSL: true` and rejects plaintext fallback for these nodes. Apply the same SSL flag to any remaining default nodes, and consider pinning or validating certificates for high-risk RPC providers.
Security signals we found
Transport-layer encryption enabled for default RPC endpoints
Plaintext HTTP default node connections reduced
Network-level eavesdropping / MITM exposure mitigated
Partial patch: remaining nodes still lack explicit useSSL flag
Evidence from the diff
The patch adds useSSL: true to six default RPC node entries across assets/ethereum_server_list.yml and assets/polygon_node_list.yml. Previously these nodes likely connected over plaintext HTTP, exposing JSON-RPC traffic to passive sniffing and active MITM. Enabling SSL forces TLS-protected connections, improving confidentiality and integrity of transaction and balance queries. The change is additive and partial: not every node in the lists is updated, and the actual client-side enforcement of useSSL is not visible in this diff.
Changed components
assets/ethereum_server_list.ymlassets/polygon_node_list.ymlDefault Ethereum RPC node selectionDefault Polygon RPC node selectionInspect captured patch +6 / −0
diff --git a/assets/ethereum_server_list.yml b/assets/ethereum_server_list.yml
index 2eae58bc..0ba098fc 100644
--- a/assets/ethereum_server_list.yml
+++ b/assets/ethereum_server_list.yml
@@ -5,12 +5,16 @@
isEnabledForAutoSwitching: true
-
uri: eth.llamarpc.com
+ useSSL: true
-
uri: rpc.flashbots.net
+ useSSL: true
-
uri: eth-mainnet.public.blastapi.io
+ useSSL: true
-
uri: eth.nownodes.io
+ useSSL: true
isEnabledForAutoSwitching: true
-
uri: ethereum.publicnode.com
\ No newline at end of file
diff --git a/assets/polygon_node_list.yml b/assets/polygon_node_list.yml
index 74dc23ef..822a8b4f 100644
--- a/assets/polygon_node_list.yml
+++ b/assets/polygon_node_list.yml
@@ -7,6 +7,8 @@
isEnabledForAutoSwitching: true
-
uri: polygon.llamarpc.com
+ useSSL: true
-
uri: matic.nownodes.io
+ useSSL: true
isEnabledForAutoSwitching: true
\ No newline at end of file
Why this scored 42/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.