feat(mwc): set nodeApiSecret on default MWC node
What changed, and why it matters
This commit embeds a hardcoded secret string (nodeApiSecret) directly into the source code for the default Mimblewimblecoin (MWC) node configuration in a cryptocurrency wallet app. If this secret is meant to authenticate or protect access to the node, publishing it in public source code means anyone can read it. That could let an attacker interact with or abuse the default node in ways the developer did not intend. However, the commit itself does not explain what nodeApiSecret does, so we cannot be certain of the exact risk.
Treat the embedded value as potentially compromised. Replace the hardcoded nodeApiSecret with a user-specific or randomly generated secret, load it from secure device storage, or require the user to configure their own node credentials. Rotate the exposed secret on any infrastructure that accepted it, and audit whether the default MWC node has been accessed or abused using this credential.
Security signals we found
Hardcoded API secret/credential in source code
Default node configuration carries a static authentication value
Secret value is present in public repository and likely compiled binaries
No evidence of secret rotation, per-user derivation, or environment-based configuration
Evidence from the diff
The change adds a single line setting nodeApiSecret to the literal value ‘11ne3EAUtOXVKwhxm84U’ inside the default Mimblewimblecoin node definition in lib/wallets/crypto_currency/coins/mimblewimblecoin.dart. Hardcoding an API secret in source code is a security anti-pattern because the value becomes visible in the public repository and in compiled application binaries. Depending on how the MWC node software uses this secret, it could be used for administrative RPC authentication, node access control, or rate-limiting bypass. Without documentation or further context, the precise security impact is uncertain, but the pattern strongly signals a potential credential-exposure issue.
Changed components
lib/wallets/crypto_currency/coins/mimblewimblecoin.dartDefault Mimblewimblecoin (MWC) node configurationStack Wallet MWC wallet integrationInspect captured patch +1 / −0
diff --git a/lib/wallets/crypto_currency/coins/mimblewimblecoin.dart b/lib/wallets/crypto_currency/coins/mimblewimblecoin.dart
index c9d5787..2ed274b 100644
--- a/lib/wallets/crypto_currency/coins/mimblewimblecoin.dart
+++ b/lib/wallets/crypto_currency/coins/mimblewimblecoin.dart
@@ -101,6 +101,7 @@ class Mimblewimblecoin extends Bip39Currency {
torEnabled: true,
clearnetEnabled: true,
isPrimary: true,
+ nodeApiSecret: '11ne3EAUtOXVKwhxm84U',
);
default:
Why this scored 64/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.