AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 27 Monero

fix(spl): handle Sol tokens the same way Eth tokens are

Public commit record

What the developer wrote

Authored by sneurlax

62/100 · Adequate
fix(spl): handle Sol tokens the same way Eth tokens are
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
The short version

What changed, and why it matters

This commit refactors how Solana (SPL) tokens are added and managed in Stack Wallet so they follow the same pattern already used for Ethereum tokens. It removes a large block of debug-only ownership-check code and replaces direct database updates with a new wallet method, `updateSolanaTokens`. It also makes sure the default Solana token list is seeded into the database if it is empty, mirroring existing Ethereum behavior. There is no direct evidence in the commit that this fixes an active security vulnerability, but it removes code that performed RPC calls and ownership checks from the UI layer, which reduces the attack surface and potential for mistakes.

Recommended action

Review the implementation of `wallet.updateSolanaTokens` to confirm it correctly validates and persists default and custom SPL token mint addresses, and that it does not reintroduce the removed ownership RPC calls in a less visible location. Verify that seeding `DefaultSplTokens.list` into the database does not overwrite user-defined custom tokens or allow injection of malicious default entries. Consider whether this change warrants a changelog note for users who previously saw ownership-check debug output.

Security signals we found

01

Removal of RPC client initialization and ownership-check calls from UI code

02

Consolidation of token-update logic behind a single wallet method

03

Alignment of Solana token seeding with existing Ethereum token seeding

04

No explicit security claim, CVE, or attribution in commit message or diff

Risk score

Why this scored 27/100

Our methodology →
Potential impact 5/30
Exploitability 3/25
Stealth signal 4/15
Affected reach 6/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.