Ignore connection error on seed restore
What changed, and why it matters
This commit changes how a cryptocurrency wallet app handles errors when restoring a wallet from a seed phrase. It now ignores certain 'connection' errors that occur before the wallet has actually connected to a server, and it also lowers the password-stretching strength (kdfRounds) to 1 during this restore step. The change appears aimed at letting users restore wallets even when the app cannot immediately reach its backend server, but it may also hide real errors and weakens the cryptographic protection of the wallet file during restore.
Review whether kdfRounds: 1 is intentional and safe for production wallet files; if not, restore the previous/default KDF rounds. Verify that 'Invalid argument' is truly a benign pre-connect error and cannot be triggered by malformed seed or wallet state. Add tests covering offline-restore and invalid-mnemonic cases to ensure real failures are not silently swallowed.
Security signals we found
kdfRounds reduced to 1 during wallet restore, weakening password-derived key protection
Error whitelist broadened from one string to two, potentially masking unexpected failures
Comment indicates restore triggers network rescan before connection, suggesting a workflow ordering issue
No explicit security framing or CVE reference in commit message
Evidence from the diff
The patch modifies lib/models/wallet_model.dart. It adds kdfRounds: 1 to a wallet restore/create call, which reduces the key-derivation cost for the wallet password. It then refactors error handling after mnemonic restore: instead of treating ‘No response from HTTP server’ as the only ignorable error, it now also ignores ‘Invalid argument’ errors, classifying both as pre-connect ‘connectionErrors’. Other errors still cause an exception. The commit message says this is needed because restore triggers a lightweight wallet server (LWS) rescan before connect.
Changed components
lib/models/wallet_model.dartWallet restore/seed-recovery flowKey derivation (KDF) configuration during restoreInspect captured patch +14 / −8
diff --git a/lib/models/wallet_model.dart b/lib/models/wallet_model.dart
index ada3d1b..9523f0f 100644
--- a/lib/models/wallet_model.dart
+++ b/lib/models/wallet_model.dart
@@ -1203,6 +1203,7 @@ class WalletModel with ChangeNotifier {
restoreHeight: restoreHeight,
password: password,
path: isDummy ? '' : walletPath,
+ kdfRounds: 1,
).address;
});
@@ -1327,15 +1328,20 @@ class WalletModel with ChangeNotifier {
);
}
- if ((wallet.errorString() != '' || wallet.status() != 0) &&
- !wallet.errorString().contains('No response from HTTP server')) {
- if (wallet.errorString().contains('word list failed verification') ||
- wallet.errorString().contains('Failed polyseed decode')) {
- throw Exception('Invalid mnemonic.');
- }
+ final errorString = wallet.errorString();
+
+ if (errorString.contains('word list failed verification') ||
+ errorString.contains('Failed polyseed decode')) {
+ throw Exception('Invalid mnemonic.');
+ }
+
+ // Restore fires an LWS rescan before connect; ignore its pre-connect error.
+ const connectionErrors = ['No response from HTTP server', 'Invalid argument'];
+ final isConnectionError = connectionErrors.any(errorString.contains);
- log(LogLevel.error, 'Error restoring from mnemonic: ${wallet.errorString()}');
- throw Exception('Error restoring from mnemonic: ${wallet.errorString()}');
+ if ((errorString != '' || wallet.status() != 0) && !isConnectionError) {
+ log(LogLevel.error, 'Error restoring from mnemonic: $errorString');
+ throw Exception('Error restoring from mnemonic: $errorString');
}
_w2Wallet = wallet;
Why this scored 35/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.