AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 35 Monero

feat(epic): add per-wallet listeners

Public commit record

What the developer wrote

Authored by sneurlax

57/100 · Thin
feat(epic): add per-wallet listeners
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
The short version

What changed, and why it matters

This commit changes how Stack Wallet manages background listeners for Epic Cash wallets. Previously, a single global listener was stopped and restarted during every wallet refresh, which could cause unnecessary reconnections and possibly interfere with other wallets' listeners in multi-wallet setups. The update makes listeners per-wallet, only stops the listener when there are actually new blocks to scan, and checks whether the listener is still alive before restarting it. The main security-relevant concern is that the old behavior may have left wallets briefly without a listener or restarted listeners unnecessarily, potentially causing missed transaction notifications or race conditions; the new behavior is a hardening improvement rather than an active vulnerability fix.

Recommended action

Treat as a defensive hardening/feature improvement. Review the corresponding `crypto_plugins/flutter_libepiccash` subproject commit to confirm the Rust-side listener map correctly isolates wallets and cleans up listeners on wallet exit. No immediate incident response is indicated, but users running multi-wallet Epic Cash setups should update to avoid missed notifications or listener races.

Security signals we found

01

Per-wallet listener isolation reduces cross-wallet interference

02

Avoids stopping/restarting listener when wallet is already at chain tip

03

Adds health check (`isEpicboxListenerRunning`) before restarting listener to avoid stale pointer issues

04

Removes unconditional global listener stop in `_startScans`

05

Subproject update to `crypto_plugins/flutter_libepiccash` likely implements Rust-side per-wallet listener state

Risk score

Why this scored 35/100

Our methodology →
Potential impact 8/30
Exploitability 5/25
Stealth signal 6/15
Affected reach 7/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.