What changed, and why it matters
This commit simplifies how the wallet decides whether a Solana token uses the older SPL token standard or the newer Token-2022 standard. It replaces a precise check of the exact program address with a looser check: anything whose owner address starts with 'Token' is treated as Token-2022. It also removes an unused helper function for finding token metadata addresses and strips out some debug print statements. The change is described by the developer as a 'cleanup' with a low-priority TODO to improve the detection later.
Treat this as a minor maintainability change rather than a security fix. Review whether the relaxed 'startsWith Token' heuristic could misclassify future or custom Solana token programs, which might affect fee logic, UI labels, or transaction construction. Revisit the TODO to implement proper program metadata parsing when feasible. No urgent patching is indicated by the diff alone.
Security signals we found
Loosened program ownership heuristic: any owner address beginning with 'Token' is classified as Token-2022
Removed debug logging of detected token program variants
Removed unused metadata PDA derivation helper
Developer TODO acknowledges current detection is rough and should be improved
Evidence from the diff
In lib/services/solana/solana_token_api.dart, _detectTokenProgramVersion was refactored. The previous code returned ‘spl’ only for the exact Tokenkeg… program ID, returned ‘token2022’ for any other owner starting with ‘Token’, and logged the variant. The new code keeps the exact SPL match but collapses the Token-2022 branch into a simpler startsWith(‘Token’) check and removes the logging. It also deletes the unused _deriveMetadataPda helper and its extensive comments. The commit message calls this a ‘cleanup’ and adds a TODO noting the check is ‘rough’ and should eventually be fixed via program metadata parsing.
Changed components
lib/services/solana/solana_token_api.dartSolana token program version detectionSolana token metadata handling (removed helper)Inspect captured patch +8 / −45
diff --git a/lib/services/solana/solana_token_api.dart b/lib/services/solana/solana_token_api.dart
index 336562c..3798e45 100644
--- a/lib/services/solana/solana_token_api.dart
+++ b/lib/services/solana/solana_token_api.dart
@@ -408,58 +408,21 @@ class SolanaTokenAPI {
final owner = response.value!.owner;
- // Check which program owns this mint.
- // SPL Token: TokenkegQfeZyiNwAJsyFbPVwwQQfg5bgUiqhStM5QA
- // Token-2022: TokenzQdBNbLvnVCrqtsvQQrXTVkDkAydS7d5xgqfnb
+ // Rough check which program owns this mint.
+ //
+ // For now all we need to know ius if it's SPL or newer.
+ // TODO [prio=low]: Fix via program metadata parsing or similar.
if (owner == 'TokenkegQfeZyiNwAJsyFbPVwwQQfg5bgUiqhStM5QA') {
return 'spl';
+ } else {
+ if (owner.startsWith('Token')) {
+ return 'token2022';
+ }
}
- if (owner.startsWith('Token') && owner != 'TokenkegQfeZyiNwAJsyFbPVwwQQfg5bgUiqhStM5QA') {
- print('[SOLANA_TOKEN_API] Detected Token-2022 variant: $owner');
- return 'token2022';
- }
-
- return null;
- } catch (e) {
- print('[SOLANA_TOKEN_API] Error detecting token program: $e');
- return null;
- }
- }
-
- /// Derive the metadata PDA for a given mint address.
- ///
- /// This is a temporary implementation that queries known metadata endpoints.
- /// In production, this should use solana package's findProgramAddress utilities.
- ///
- /// Returns: metadata PDA address or null if derivation fails
- Future<String?> _deriveMetadataPda(String mintAddress) async {
- try {
- // Validate the mint address first
- if (!isValidSolanaMintAddress(mintAddress)) {
- return null;
- }
-
- // TODO: Implement proper PDA derivation using solana package's findProgramAddress
- // This is a placeholder that would need to be updated when solana package
- // exposes the necessary utilities
- //
- // For now, we return null to trigger fallback behavior
- // In a real implementation, you would derive the PDA like:
- // final seeds = [
- // 'metadata'.codeUnits,
- // metadataProgram.toBytes(),
- // mint.toBytes(),
- // ];
- // final (pda, _) = Ed25519HDPublicKey.findProgramAddress(
- // seeds,
- // metadataProgram,
- // );
- // return pda.toBase58();
return null;
} catch (e) {
return null;
}
}
-
}
Why this scored 26/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.