set IME_FLAG_NO_PERSONALIZED_LEARNING for mnemonic words entry textfields
What changed, and why it matters
This commit adds a privacy flag to the text boxes where users type their wallet recovery phrase (mnemonic seed words). The flag tells the phone's keyboard not to learn or remember those words for personalized suggestions. Without it, sensitive seed words could be stored in the keyboard's user dictionary or cloud-backed learning models, increasing the risk that someone with access to the keyboard data could recover part of a wallet backup.
Review all other sensitive text inputs (passphrase, password, private key, address note fields) and apply `enableIMEPersonalizedLearning: false` where appropriate. Confirm the flag is honored on different Android keyboards and document any iOS/desktop limitations. Consider adding automated linting or widget tests to prevent regression.
Security signals we found
Privacy leak via keyboard personalized learning
Sensitive input (mnemonic seed words) exposed to IME/keyboard data
Android IME flag hardening
Partial patch limited to restore view
Evidence from the diff
The change sets enableIMEPersonalizedLearning: false on three TextFormField widgets in restore_wallet_view.dart that accept mnemonic seed words during wallet restore. On Android, this maps to IME_FLAG_NO_PERSONALIZED_LEARNING, instructing the input method editor not to add entered text to its personalized language model. The patch is partial: it only covers the restore view and does not address other sensitive text fields (e.g., password/passphrase fields) or verify behavior on iOS/desktop. It is a hardening/privacy fix rather than a cryptographic vulnerability fix.
Changed components
lib/pages/add_wallet_views/restore_wallet_view/restore_wallet_view.dartMnemonic seed word input fields during wallet restoreInspect captured patch +5 / −0
diff --git a/lib/pages/add_wallet_views/restore_wallet_view/restore_wallet_view.dart b/lib/pages/add_wallet_views/restore_wallet_view/restore_wallet_view.dart
index 5d101de..55016b7 100644
--- a/lib/pages/add_wallet_views/restore_wallet_view/restore_wallet_view.dart
+++ b/lib/pages/add_wallet_views/restore_wallet_view/restore_wallet_view.dart
@@ -861,6 +861,8 @@ class _RestoreWalletViewState extends ConsumerState<RestoreWalletView> {
child: Column(
children: [
TextFormField(
+ enableIMEPersonalizedLearning:
+ false,
obscureText: _hideSeedWords,
autocorrect: !isDesktop,
enableSuggestions: !isDesktop,
@@ -1007,6 +1009,8 @@ class _RestoreWalletViewState extends ConsumerState<RestoreWalletView> {
child: Column(
children: [
TextFormField(
+ enableIMEPersonalizedLearning:
+ false,
obscureText: _hideSeedWords,
autocorrect: !isDesktop,
enableSuggestions: !isDesktop,
@@ -1148,6 +1152,7 @@ class _RestoreWalletViewState extends ConsumerState<RestoreWalletView> {
vertical: 4,
),
child: TextFormField(
+ enableIMEPersonalizedLearning: false,
obscureText: _hideSeedWords,
autocorrect: !isDesktop,
enableSuggestions: !isDesktop,
Why this scored 52/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.