AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 37 Monero

fix(epic): apply new flutter_libepiccash patterns to epic cash wallet impl

Public commit record

What the developer wrote

Authored by sneurlax

62/100 · Adequate
fix(epic): apply new flutter_libepiccash patterns to epic cash wallet impl
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
The short version

What changed, and why it matters

This commit updates how the Epic Cash wallet in Stack Wallet talks to its underlying Rust library (flutter_libepiccash). It moves some configuration data (epicboxConfig) into wallet load/create calls and removes it from individual transaction/address calls, matching a new library API. It also replaces a real address-validation check with a very simple length check, which could let users paste in malformed or wrong addresses. The change looks like a compatibility/refactoring patch rather than a deliberate security fix, but the weaker address check is a small security regression.

Recommended action

Review whether the simplified address validation is intentional and sufficient; consider re-adding a proper Epic Cash address format check (e.g., regex for epicbox addresses and slatepack/on-chain address validation). Verify that all callers of validateSendAddress handle the new Future<bool> return correctly and that moving epicboxConfig does not leak sensitive server configuration.

Security signals we found

01

Address validation weakened from library-backed check to length heuristic

02

Library API migration touches wallet initialization, transaction creation, and address derivation

03

New wallet handle persistence added after recovery flows

04

Async signature change for validateSendAddress may affect downstream callers

Risk score

Why this scored 37/100

Our methodology →
Potential impact 8/30
Exploitability 7/25
Stealth signal 6/15
Affected reach 8/15
Confidence 5/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.