update destination address for spark name registration fees
What changed, and why it matters
This commit changes the destination address used when paying fees to register a Spark name in the Stack Wallet app. It switches from a 'development fund' address to a 'community fund' address, and updates the underlying library version. There is no direct evidence in the commit that this fixes a security vulnerability; it appears to be a routine destination-address update, though a typo in one generated constant name (kStage3DCommunityFundAddressTestNet) is introduced.
Verify that the new community fund addresses in the updated flutter_libsparkmobile ref are the intended, legitimate destinations and that the old development fund addresses are no longer valid or desired. Also fix the typo kStage3DCommunityFundAddressTestNet in the template. Treat as a configuration/operational change unless independent evidence shows the old address was compromised or malicious.
Security signals we found
Change of fund destination address for on-chain fees
Dependency version bump to a different git ref of flutter_libsparkmobile
No explicit security framing, CVE, or vulnerability description in commit message or diff
Evidence from the diff
The patch updates the Firo Spark name registration fee destination in spark_interface.dart from libSpark.stage3DevelopmentFundAddressMainNet/TestNet to libSpark.stage3CommunityFundAddressMainNet/TestNet. It renames the corresponding abstract getters in lib_spark_interface.dart and the template implementation in FIRO_lib_spark_interface_impl.template.dart, and bumps the flutter_libsparkmobile git dependency from ref 83928dbeb5f… to 4bd84c88e1b2.... The actual address values live in the external library, so the diff does not show whether the old or new addresses are correct. A typo is introduced in the template: kStage3DCommunityFundAddressTestNet (extra ‘D’).
Changed components
lib/wallets/wallet/wallet_mixin_interfaces/spark_interface.dartlib/wl_gen/interfaces/lib_spark_interface.darttool/wl_templates/FIRO_lib_spark_interface_impl.template.dartpubspec.lockscripts/app_config/templates/pubspec.template.yamlFiro Spark name registration fee routingInspect captured patch +11 / −11
diff --git a/lib/wallets/wallet/wallet_mixin_interfaces/spark_interface.dart b/lib/wallets/wallet/wallet_mixin_interfaces/spark_interface.dart
index 2aa846e..7ac1fc2 100644
--- a/lib/wallets/wallet/wallet_mixin_interfaces/spark_interface.dart
+++ b/lib/wallets/wallet/wallet_mixin_interfaces/spark_interface.dart
@@ -2239,11 +2239,11 @@ mixin SparkInterface<T extends ElectrumXCurrencyInterface>
final String destinationAddress;
switch (cryptoCurrency.network) {
case CryptoCurrencyNetwork.main:
- destinationAddress = libSpark.stage3DevelopmentFundAddressMainNet;
+ destinationAddress = libSpark.stage3CommunityFundAddressMainNet;
break;
case CryptoCurrencyNetwork.test:
- destinationAddress = libSpark.stage3DevelopmentFundAddressTestNet;
+ destinationAddress = libSpark.stage3CommunityFundAddressTestNet;
break;
default:
diff --git a/lib/wl_gen/interfaces/lib_spark_interface.dart b/lib/wl_gen/interfaces/lib_spark_interface.dart
index 6f0df29..92404f5 100644
--- a/lib/wl_gen/interfaces/lib_spark_interface.dart
+++ b/lib/wl_gen/interfaces/lib_spark_interface.dart
@@ -14,8 +14,8 @@ abstract class LibSparkInterface {
int get maxNameLength;
int get maxAdditionalInfoLengthBytes;
String get nameRegexString;
- String get stage3DevelopmentFundAddressMainNet;
- String get stage3DevelopmentFundAddressTestNet;
+ String get stage3CommunityFundAddressMainNet;
+ String get stage3CommunityFundAddressTestNet;
List<int> get standardSparkNamesFee;
void initSparkLogging(Level level);
diff --git a/pubspec.lock b/pubspec.lock
index 23e1eb6..b985461 100644
--- a/pubspec.lock
+++ b/pubspec.lock
@@ -1020,8 +1020,8 @@ packages:
dependency: "direct main"
description:
path: "."
- ref: "83928dbeb5f150be57e03b7e9f6d720ef7f7cf7b"
- resolved-ref: "83928dbeb5f150be57e03b7e9f6d720ef7f7cf7b"
+ ref: "4bd84c88e1b2a817a2604ec53030634cc3304bc7"
+ resolved-ref: "4bd84c88e1b2a817a2604ec53030634cc3304bc7"
url: "https://github.com/cypherstack/flutter_libsparkmobile.git"
source: git
version: "0.1.0"
diff --git a/scripts/app_config/templates/pubspec.template.yaml b/scripts/app_config/templates/pubspec.template.yaml
index 9ca348b..0723e2d 100644
--- a/scripts/app_config/templates/pubspec.template.yaml
+++ b/scripts/app_config/templates/pubspec.template.yaml
@@ -40,7 +40,7 @@ dependencies:
# flutter_libsparkmobile:
# git:
# url: https://github.com/cypherstack/flutter_libsparkmobile.git
-# ref: 83928dbeb5f150be57e03b7e9f6d720ef7f7cf7b
+# ref: 4bd84c88e1b2a817a2604ec53030634cc3304bc7
# %%END_ENABLE_FIRO%%
# %%ENABLE_EPIC%%
diff --git a/tool/wl_templates/FIRO_lib_spark_interface_impl.template.dart b/tool/wl_templates/FIRO_lib_spark_interface_impl.template.dart
index f4120a8..f2998be 100644
--- a/tool/wl_templates/FIRO_lib_spark_interface_impl.template.dart
+++ b/tool/wl_templates/FIRO_lib_spark_interface_impl.template.dart
@@ -48,12 +48,12 @@ class _LibSparkInterfaceImpl extends LibSparkInterface {
String get nameRegexString => kNameRegexString;
@override
- String get stage3DevelopmentFundAddressMainNet =>
- kStage3DevelopmentFundAddressMainNet;
+ String get stage3CommunityFundAddressMainNet =>
+ kStage3CommunityFundAddressMainNet;
@override
- String get stage3DevelopmentFundAddressTestNet =>
- kStage3DevelopmentFundAddressTestNet;
+ String get stage3CommunityFundAddressTestNet =>
+ kStage3DCommunityFundAddressTestNet;
@override
List<int> get standardSparkNamesFee =>
Why this scored 18/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.