Wipe address book and pending outgoing txs list when wallet is deleted
What changed, and why it matters
This commit fixes a cleanup bug: when a user deletes their wallet, the app now also removes the saved address book (contacts) and any pending outgoing transactions from phone storage. Before this fix, those details could remain on the device after the wallet was supposedly deleted, which is a privacy and data-retention issue rather than a direct money-stealing bug.
Treat as a low-to-moderate privacy fix. Users who previously deleted a wallet should be advised that contacts and pending-tx metadata may still exist in app storage and can be cleared by reinstalling the app or clearing app data. No immediate remote-exploitable vulnerability is indicated.
Security signals we found
Incomplete data deletion on wallet removal
Sensitive metadata retention (contacts / address book, pending transactions)
Privacy / data-sanitization fix
Evidence from the diff
The change adds two SharedPreferences removals inside the wallet deletion method in lib/models/wallet_model.dart. It now clears SharedPreferencesKeys.pendingOutgoingTxs and SharedPreferencesKeys.contacts in addition to the previously cleared wallet keys. This prevents stale wallet metadata from persisting locally after deleteWallet() is invoked.
Changed components
lib/models/wallet_model.dartSharedPreferences-backed local storage for contacts and pending outgoing transactionsInspect captured patch +4 / −0
diff --git a/lib/models/wallet_model.dart b/lib/models/wallet_model.dart
index 6c3ddaf..62fcb60 100644
--- a/lib/models/wallet_model.dart
+++ b/lib/models/wallet_model.dart
@@ -663,6 +663,10 @@ class WalletModel with ChangeNotifier {
SharedPreferencesKeys.walletRestoreHeight,
);
await SharedPreferencesService.remove(SharedPreferencesKeys.appLockEnabled);
+ await SharedPreferencesService.remove(
+ SharedPreferencesKeys.pendingOutgoingTxs,
+ );
+ await SharedPreferencesService.remove(SharedPreferencesKeys.contacts);
}
Future<bool> hasExistingWallet() async {
Why this scored 46/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.