What changed, and why it matters
This commit changes which version of the 'Spark Mobile' cryptographic library Stack Wallet uses. It switches from the official Firo project repository to a fork maintained by Cypher Stack (the same company that makes Stack Wallet) and updates the pinned commit hash. The change itself does not show any vulnerability in the code, but it is a supply-chain-style update: the wallet now depends on a different copy of a library that handles sensitive private-key and transaction operations for the Firo cryptocurrency. Without knowing what changed between the two commit hashes, we cannot say whether this makes users safer or less safe.
Treat this as a supply-chain change that needs verification. Review the diff between the old and new flutter_libsparkmobile commits (53db5a06... and 783bd00f...) to confirm it contains only intended fixes and no malicious or weakened cryptography. Verify the Cypher Stack fork is an authorized/official mirror and that the new ref is signed or tagged. If this is a security update, request the project to publish a changelog or advisory explaining the change.
Security signals we found
Dependency source changed from upstream vendor (firoorg) to project maintainer's fork (cypherstack)
Pinned cryptographic library ref updated without disclosed rationale
Library is in the trusted computing base for Firo private keys and Spark transactions
No CVE, advisory, or security explanation present in commit or supplied references
Evidence from the diff
The diff updates the git dependency pin for flutter_libsparkmobile in both pubspec.lock and the pubspec.template.yaml. The repository URL changes from https://github.com/firoorg/flutter_libsparkmobile.git to https://github.com/cypherstack/flutter_libsparkmobile.git, and the pinned ref changes from 53db5a06a7b7f3df68fe6263f1453f77513bec06 to 783bd00f0114b007f7ef97017cd10ad263ed452c. flutter_libsparkmobile is a Dart/Flutter wrapper around libsparkmobile, which implements the Spark privacy protocol for Firo (formerly Zcoin). This library is in the trusted computing base for Firo keys, addresses, and transaction creation/signing. The commit message only says ‘Update Spark Mobile wrapper pin’ and provides no rationale, changelog, or security justification.
Changed components
Firo/Spark wallet functionalityflutter_libsparkmobile dependencypubspec.lockscripts/app_config/templates/pubspec.template.yamlInspect captured patch +5 / −5
diff --git a/pubspec.lock b/pubspec.lock
index 7518575..115772a 100644
--- a/pubspec.lock
+++ b/pubspec.lock
@@ -1028,9 +1028,9 @@ packages:
dependency: "direct main"
description:
path: "."
- ref: "53db5a06a7b7f3df68fe6263f1453f77513bec06"
- resolved-ref: "53db5a06a7b7f3df68fe6263f1453f77513bec06"
- url: "https://github.com/firoorg/flutter_libsparkmobile.git"
+ ref: "783bd00f0114b007f7ef97017cd10ad263ed452c"
+ resolved-ref: "783bd00f0114b007f7ef97017cd10ad263ed452c"
+ url: "https://github.com/cypherstack/flutter_libsparkmobile.git"
source: git
version: "0.1.0"
flutter_lints:
diff --git a/scripts/app_config/templates/pubspec.template.yaml b/scripts/app_config/templates/pubspec.template.yaml
index ead1294..7aba945 100644
--- a/scripts/app_config/templates/pubspec.template.yaml
+++ b/scripts/app_config/templates/pubspec.template.yaml
@@ -43,8 +43,8 @@ dependencies:
# %%ENABLE_FIRO%%
# flutter_libsparkmobile:
# git:
-# url: https://github.com/firoorg/flutter_libsparkmobile.git
-# ref: 53db5a06a7b7f3df68fe6263f1453f77513bec06
+# url: https://github.com/cypherstack/flutter_libsparkmobile.git
+# ref: 783bd00f0114b007f7ef97017cd10ad263ed452c
# %%END_ENABLE_FIRO%%
# %%ENABLE_EPIC%%
Why this scored 32/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.