What changed, and why it matters
This commit fixes a likely data-labeling bug in the Epic Cash wallet code. The previous code assigned the sender's address to a transaction output (money received) and the recipient's address to a transaction input (money spent). The swap corrects this so outputs are labeled with the recipient's address and inputs with the sender's address. This is primarily a correctness/display issue rather than a direct theft vulnerability, but it could mislead users or downstream features about where funds came from or went.
Verify that addressFrom and addressTo are correctly populated upstream and that this swap does not break other wallet features such as transaction history, address book matching, or coin selection. Consider adding unit tests for input/output address assignment in Epic Cash transactions.
Security signals we found
Data-labeling/correctness bug in transaction metadata
Potential user confusion or incorrect downstream decisions based on swapped addresses
No direct cryptographic or authorization flaw visible in diff
Evidence from the diff
In lib/wallets/wallet/impl/epiccash_wallet.dart, the OutputV2.addresses list was populated with addressFrom and the InputV2.addresses list was populated with addressTo. The patch swaps them: OutputV2 now uses addressTo and InputV2 now uses addressFrom. This aligns with the conventional UTXO model where an output’s address is the destination (to) and an input’s address is the source (from). The change is small and localized, but the previous assignment was semantically inverted.
Changed components
lib/wallets/wallet/impl/epiccash_wallet.dartEpic Cash wallet transaction output/input constructionInspect captured patch +2 / −2
diff --git a/lib/wallets/wallet/impl/epiccash_wallet.dart b/lib/wallets/wallet/impl/epiccash_wallet.dart
index 042138e..3746a48 100644
--- a/lib/wallets/wallet/impl/epiccash_wallet.dart
+++ b/lib/wallets/wallet/impl/epiccash_wallet.dart
@@ -1409,7 +1409,7 @@ class EpiccashWallet extends Bip39Wallet {
OutputV2 output = OutputV2.isarCantDoRequiredInDefaultConstructor(
scriptPubKeyHex: "00",
valueStringSats: credit.toString(),
- addresses: [if (addressFrom != null) addressFrom],
+ addresses: [if (addressTo != null) addressTo],
walletOwns: true,
);
final InputV2 input = InputV2.isarCantDoRequiredInDefaultConstructor(
@@ -1417,7 +1417,7 @@ class EpiccashWallet extends Bip39Wallet {
scriptSigAsm: null,
sequence: null,
outpoint: null,
- addresses: [if (addressTo != null) addressTo],
+ addresses: [if (addressFrom != null) addressFrom],
valueStringSats: debit.toString(),
witness: null,
innerRedeemScriptAsm: null,
Why this scored 29/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.