fix address on monero tx info (#3192)
What changed, and why it matters
This commit fixes a UI bug in how Cake Wallet displays the recipient address for Monero transactions. Previously, the app always tried to look up a Monero subaddress for every transaction, even for outgoing payments, which could show the wrong address or no address. Now it only does that lookup for incoming transactions and falls back to the transaction's own 'to' field otherwise. There is no direct evidence this is a security vulnerability or that it could be exploited to steal funds.
Treat as a routine bug fix. No immediate security action required. If auditing, verify that getTransactionAddress is only called with valid indices and that transactionInfo.to is appropriate for outgoing Monero transactions.
Security signals we found
UI display logic change only
No cryptographic, networking, or permission changes
No input validation or sanitization changes
No memory safety or native code changes
No authentication/authorization changes
Evidence from the diff
The change is in transaction_details_view_model.dart. The recipient-address valueGetter now distinguishes Monero incoming vs outgoing transactions. For incoming Monero transactions it still calls monero!.getTransactionAddress using accountIndex/addressIndex from additionalInfo. For outgoing or non-Monero transactions it uses the transactionInfo.to field (or wallet-specific helpers for Bitcoin/TRON). It also only sets isRecipientAddressShown to true when a non-empty address was actually resolved. This prevents incorrect subaddress lookups on outgoing Monero transactions and avoids showing an empty address row.
Changed components
lib/view_model/transaction_details_view_model.dartMonero transaction details screenInspect captured patch +16 / −8
diff --git a/lib/view_model/transaction_details_view_model.dart b/lib/view_model/transaction_details_view_model.dart
index cc289733..492c561a 100644
--- a/lib/view_model/transaction_details_view_model.dart
+++ b/lib/view_model/transaction_details_view_model.dart
@@ -98,22 +98,30 @@ class TxDetailRowDefinition {
keyString: "standard_list_item_transaction_details_recipient_address_key",
title: S.current.transaction_details_recipient_address,
valueGetter: (vm) {
- vm.isRecipientAddressShown = true;
+ String? ret = null;
+
switch (vm.wallet.type) {
case WalletType.monero:
- return monero!.getTransactionAddress(
- vm.wallet,
- vm.transactionInfo.additionalInfo['accountIndex'] as int,
- vm.transactionInfo.additionalInfo['addressIndex'] as int);
+ if (vm.transactionInfo.direction == TransactionDirection.incoming) {
+ ret = monero!.getTransactionAddress(
+ vm.wallet,
+ vm.transactionInfo.additionalInfo['accountIndex'] as int,
+ vm.transactionInfo.additionalInfo['addressIndex'] as int);
+ }
case WalletType.bitcoin:
- return (bitcoin!.getTransactionAddresses(vm.wallet, vm.transactionInfo) ?? [])
+ ret = (bitcoin!.getTransactionAddresses(vm.wallet, vm.transactionInfo) ?? [])
.firstOrNull ??
"";
case WalletType.tron:
- return tron!.getTronBase58Address(vm.transactionInfo.to!, vm.wallet);
+ ret = tron!.getTronBase58Address(vm.transactionInfo.to!, vm.wallet);
default:
- return vm.transactionInfo.to!;
+ break;
+ }
+ if(ret == null) {
+ ret = vm.transactionInfo.to ?? "";
}
+ vm.isRecipientAddressShown = ret.isNotEmpty;
+ return ret;
},
applicable: (vm) =>
vm.showRecipientAddress &&
Why this scored 19/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.