Switch default Tezos node to tezos.stackwallet.com which doesn't support /header/shell, so getChainHeight calls /header instead, which also contains level.
What changed, and why it matters
This commit changes the default Tezos blockchain server used by Stack Wallet from a public Tezos node to Stack Wallet's own node, and adjusts the API endpoint used to check the latest block height. There is no direct evidence in the commit of a security vulnerability, but running wallet traffic through a single party-controlled node and changing the data source for chain state can carry trust and reliability risks.
Treat as a routine infrastructure/default-node update. Users who distrust the vendor node should verify they can configure a custom Tezos RPC node. Reviewers may want to confirm tezos.stackwallet.com is operated securely and that /header responses are validated before use, but no immediate security patch is indicated by the diff.
Security signals we found
Default node changed to vendor-operated infrastructure (tezos.stackwallet.com)
Chain-height data source changed from /header/shell to /header
No authentication, encryption, or input-validation changes present
No mention of vulnerability, CVE, bug bounty, or researcher attribution
Evidence from the diff
The patch switches the default Tezos node host from https://mainnet.api.tez.ie to https://tezos.stackwallet.com and changes getChainHeight from querying /chains/main/blocks/head/header/shell to /chains/main/blocks/head/header. The commit message states the new node does not support the /header/shell endpoint and that /header also contains the needed level field. This is a functional compatibility change, not a cryptographic or access-control fix.
Changed components
lib/wallets/api/tezos/tezos_rpc_api.dartlib/wallets/crypto_currency/coins/tezos.dartInspect captured patch +2 / −3
diff --git a/lib/wallets/api/tezos/tezos_rpc_api.dart b/lib/wallets/api/tezos/tezos_rpc_api.dart
index 721d8b0..0449de8 100644
--- a/lib/wallets/api/tezos/tezos_rpc_api.dart
+++ b/lib/wallets/api/tezos/tezos_rpc_api.dart
@@ -46,7 +46,7 @@ abstract final class TezosRpcAPI {
}) async {
try {
final api =
- "${nodeInfo.host}:${nodeInfo.port}/chains/main/blocks/head/header/shell";
+ "${nodeInfo.host}:${nodeInfo.port}/chains/main/blocks/head/header";
final response = await _client.get(
url: Uri.parse(api),
diff --git a/lib/wallets/crypto_currency/coins/tezos.dart b/lib/wallets/crypto_currency/coins/tezos.dart
index 179ae2c..0da163b 100644
--- a/lib/wallets/crypto_currency/coins/tezos.dart
+++ b/lib/wallets/crypto_currency/coins/tezos.dart
@@ -107,8 +107,7 @@ class Tezos extends Bip39Currency {
switch (network) {
case CryptoCurrencyNetwork.main:
return NodeModel(
- // TODO: ?Change this to stack wallet one?
- host: "https://mainnet.api.tez.ie",
+ host: "https://tezos.stackwallet.com",
port: 443,
name: DefaultNodes.defaultName,
id: DefaultNodes.buildId(this),
Why this scored 19/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.