What changed, and why it matters
This commit fixes a bug in a cryptocurrency wallet app where a warning about reaching the maximum number of subaddresses (separate receiving addresses) could appear at the wrong time or with wrong data. The changes remove a condition that only saved wallet state after transactions were loaded, and they stop assuming a default value of 1 when the saved subaddress index is missing. The security relevance is indirect: it mainly prevents user confusion and possible app misbehavior, not a direct theft or remote attack.
Treat as a routine bug fix. Review whether removing the txCount > 0 guard for store() could cause empty or partially loaded wallets to overwrite persisted state, and verify that the null default for unusedSubaddressIndex is handled safely elsewhere. No urgent security patch appears needed based on the diff alone.
Security signals we found
Behavior change in persistence logic: unconditional store() call may write state earlier or more often
Default-value removal for persisted subaddress index could change wallet address selection behavior
No cryptographic, authentication, or network-boundary changes visible
No input validation, injection, or secret-handling changes visible
Evidence from the diff
In lib/models/wallet_model.dart, the patch does two things. First, it removes the guard that called store() only when the wallet was connected, synced, and had at least one transaction; now store() is always awaited after stats are loaded. Second, it changes loadPersistedUnusedSubaddressIndex() so that missing SharedPreferences values return null instead of defaulting to 1 (for the index) and false (for the support flag). The commit title says this fixes a ‘max subaddresses warning bug,’ likely because stale or defaulted values were triggering an incorrect warning. There is no direct evidence in the diff of a vulnerability such as key leakage, remote code execution, or unauthorized spending.
Changed components
lib/models/wallet_model.dartWallet state persistence (store/load)Subaddress index management and related warning UIInspect captured patch +7 / −12
diff --git a/lib/models/wallet_model.dart b/lib/models/wallet_model.dart
index abe9767..dea5339 100644
--- a/lib/models/wallet_model.dart
+++ b/lib/models/wallet_model.dart
@@ -203,11 +203,7 @@ class WalletModel with ChangeNotifier {
log(LogLevel.error, 'Error loading all stats: $e');
}
- final txCount = _w2TxHistory!.count();
-
- if (_isConnected && _isSynced && txCount > 0) {
- await store();
- }
+ await store();
}
Future<void> load() async {
@@ -482,13 +478,12 @@ class WalletModel with ChangeNotifier {
}
Future<void> loadPersistedUnusedSubaddressIndex() async {
- _unusedSubaddressIndex =
- await SharedPreferencesService.get<int>(SharedPreferencesKeys.unusedSubaddressIndex) ?? 1;
- _unusedSubaddressIndexIsSupported =
- await SharedPreferencesService.get<bool>(
- SharedPreferencesKeys.unusedSubaddressIndexIsSupported,
- ) ??
- false;
+ _unusedSubaddressIndex = await SharedPreferencesService.get<int>(
+ SharedPreferencesKeys.unusedSubaddressIndex,
+ );
+ _unusedSubaddressIndexIsSupported = await SharedPreferencesService.get<bool>(
+ SharedPreferencesKeys.unusedSubaddressIndexIsSupported,
+ );
}
Future<bool> isSubaddressSupported(int subaddrIndex) async {
Why this scored 25/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.