What changed, and why it matters
This commit fixes a small but meaningful mix-up in the mobile wallet's send screen. The code was reading the desktop fee-rate setting when preparing a Litecoin MWEB (privacy) transaction, instead of reading the mobile fee-rate setting. If the two settings differ, the user could end up paying an unexpected fee, or the transaction might not be built with the fee they actually selected on their phone. There is no direct evidence in the commit of funds being stolen or a remote attacker being able to exploit this.
Treat as a functional bug with possible fee/reliability side effects. Review whether the same provider mismatch exists in other mobile send paths or other MWEB-related flows. Add regression tests covering fee-rate selection for MWEB sends on mobile. No urgent security patch is indicated by the diff alone, but the fix should be included in the next release.
Security signals we found
State provider mismatch between desktop and mobile fee-rate settings
MWEB (privacy transaction) fee calculation affected
Single-line fix with no additional tests or validation
No explicit security framing by the vendor in commit title or message
Evidence from the diff
In lib/pages/send_view/send_view.dart, the MWEB transaction builder was referencing feeRateTypeDesktopStateProvider. The patch changes it to feeRateTypeMobileStateProvider. This is a state-provider mismatch on a mobile code path. The consequence is that the fee-rate type used for MWEB sends is taken from the wrong provider/state, potentially causing the transaction to use a fee setting the user did not choose in the mobile UI. The diff is one line and does not include tests, validation changes, or additional hardening.
Changed components
lib/pages/send_view/send_view.dartMWEB send flowFee-rate selection for mobileInspect captured patch +1 / −1
diff --git a/lib/pages/send_view/send_view.dart b/lib/pages/send_view/send_view.dart
index 18b8d5b..e763eb9 100644
--- a/lib/pages/send_view/send_view.dart
+++ b/lib/pages/send_view/send_view.dart
@@ -1080,7 +1080,7 @@ class _SendViewState extends ConsumerState<SendView> {
addressType: wallet.cryptoCurrency.getAddressType(_address!)!,
),
],
- feeRateType: ref.read(feeRateTypeDesktopStateProvider),
+ feeRateType: ref.read(feeRateTypeMobileStateProvider),
satsPerVByte: isCustomFee.value ? customFeeRate : null,
// these will need to be mweb utxos
Why this scored 26/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.