fix(spl): delegate chain refresh to parent wallet
What changed, and why it matters
A one-line change in the Solana token wallet code now asks the main Solana wallet to refresh the blockchain height instead of doing nothing. Previously, the token wallet's chain-height update was left as an unfinished 'to-do' task, which could have caused stale or missing chain-height information for token accounts. There is no direct evidence this was a security vulnerability, but relying on a placeholder no-op for chain-height updates is a reliability weakness.
Review whether stale chain height in SolanaTokenWallet could affect transaction construction, fee estimation, or confirmation logic elsewhere in the wallet. Consider adding tests that verify the token wallet's chain height matches the parent wallet after refresh. No urgent patch is required beyond this commit.
Security signals we found
Placeholder TODO no-op replaced with delegated parent call
Potential stale chain height in token sub-wallet before fix
No explicit security claim in commit message or diff
Evidence from the diff
In lib/wallets/wallet/impl/sub_wallets/solana_token_wallet.dart, the SolanaTokenWallet.updateChainHeight() override was changed from a no-op TODO comment to await parentSolanaWallet.updateChainHeight(). This delegates chain-height refresh to the parent Solana wallet. The diff alone does not show any exploit path, but it removes a sub-wallet state where chain height could remain stale or inconsistent with the parent wallet.
Changed components
SolanaTokenWallet.updateChainHeight()Solana token sub-wallet chain height synchronizationInspect captured patch +1 / −1
diff --git a/lib/wallets/wallet/impl/sub_wallets/solana_token_wallet.dart b/lib/wallets/wallet/impl/sub_wallets/solana_token_wallet.dart
index 3a35a49..8ae30e3 100644
--- a/lib/wallets/wallet/impl/sub_wallets/solana_token_wallet.dart
+++ b/lib/wallets/wallet/impl/sub_wallets/solana_token_wallet.dart
@@ -666,7 +666,7 @@ class SolanaTokenWallet extends Wallet {
@override
Future<void> updateChainHeight() async {
- // TODO: Get latest Solana block height.
+ await parentSolanaWallet.updateChainHeight();
}
@override
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.