What changed, and why it matters
This commit is a minor cleanup: it swaps two ordinary print statements for Flutter's debugPrint (which only shows in debug builds), removes a leftover debug print of a transaction map, and stops sending an API key in requests to the CypherGoat exchange service. The API-key removal is the only change with any security angle, but the diff does not show what the key was, how it was stored, or whether it was sensitive. There is no evidence of an active vulnerability being fixed.
No urgent action is required from this commit alone. If the removed kCypherGoatApiKey was a real, hardcoded secret, rotate it and verify it is not present in repository history or other branches. Review whether the API key is still needed elsewhere and consider moving any required secrets to secure storage rather than source code.
Security signals we found
Removal of API key parameter from outbound exchange request
Replacement of print with debugPrint to avoid release-mode logging
Removal of debug print of parsed transaction map
Evidence from the diff
The patch makes three small changes in a Dart/Flutter wallet app: (1) in main.dart, MWEBD log lines now use debugPrint instead of print so they are suppressed in release builds; (2) in cyphergoat_api.dart, the code no longer adds kCypherGoatApiKey to /estimate query parameters; (3) in cg_transaction.dart, a debug print(map) is removed from the fromMap factory. The API-key change could be a hardcoded-key cleanup, but the diff does not reveal the key’s nature, origin, or exposure path, so it cannot be classified as a confirmed credential leak fix.
Changed components
lib/main.dartlib/services/exchange/cyphergoat/cyphergoat_api.dartlib/services/exchange/cyphergoat/response_objects/cg_transaction.dartInspect captured patch +2 / −7
diff --git a/lib/main.dart b/lib/main.dart
index 3b4083c..89d7dec 100644
--- a/lib/main.dart
+++ b/lib/main.dart
@@ -260,7 +260,7 @@ void main(List<String> args) async {
.logsStream(CryptoCurrencyNetwork.main)
.then(
(stream) =>
- stream.listen((line) => print("[MWEBD: MAINNET]: $line")),
+ stream.listen((line) => debugPrint("[MWEBD: MAINNET]: $line")),
),
);
unawaited(
@@ -268,7 +268,7 @@ void main(List<String> args) async {
.logsStream(CryptoCurrencyNetwork.test)
.then(
(stream) =>
- stream.listen((line) => print("[MWEBD: TESTNET]: $line")),
+ stream.listen((line) => debugPrint("[MWEBD: TESTNET]: $line")),
),
);
}
diff --git a/lib/services/exchange/cyphergoat/cyphergoat_api.dart b/lib/services/exchange/cyphergoat/cyphergoat_api.dart
index 5f11225..63760f5 100644
--- a/lib/services/exchange/cyphergoat/cyphergoat_api.dart
+++ b/lib/services/exchange/cyphergoat/cyphergoat_api.dart
@@ -84,10 +84,6 @@ abstract class CypherGoatAPI {
"best": "false",
};
- if (kCypherGoatApiKey.isNotEmpty) {
- params["api_key"] = kCypherGoatApiKey;
- }
-
final uri = _buildUri(path: "/estimate", params: params);
try {
diff --git a/lib/services/exchange/cyphergoat/response_objects/cg_transaction.dart b/lib/services/exchange/cyphergoat/response_objects/cg_transaction.dart
index b46802f..2ca4bde 100644
--- a/lib/services/exchange/cyphergoat/response_objects/cg_transaction.dart
+++ b/lib/services/exchange/cyphergoat/response_objects/cg_transaction.dart
@@ -62,7 +62,6 @@ class CgTransaction {
}
factory CgTransaction.fromMap(Map<String, dynamic> map) {
- print(map);
return CgTransaction(
coin1: requireCgString(map, "Coin1"),
coin2: requireCgString(map, "Coin2"),
Why this scored 18/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.