What changed, and why it matters
This commit swaps the source of the Mimblewimblecoin (MWC) library used inside Stack Wallet. It replaces a direct import of an external Flutter package called flutter_libmwc with a project-specific wrapper interface named libmwc_interface. The actual address-validation logic still calls the same validateSendAddress function, just through the new wrapper. There is no obvious security bug being fixed here; it looks like a routine code reorganization to make the wallet use an internal abstraction layer instead of a third-party package directly.
No immediate security action is required. Treat this as a normal dependency/refactoring commit. If the new libmwc_interface wrapper changes how the underlying native library is loaded or initialized, review that wrapper separately to ensure it preserves the same validation behavior and does not introduce new trust assumptions.
Security signals we found
Third-party dependency replaced by internal wrapper (abstraction change, not a vulnerability fix)
Address validation logic unchanged at the call site
No input sanitization, cryptographic, or permission changes visible
Evidence from the diff
The diff in lib/wallets/crypto_currency/coins/mimblewimblecoin.dart removes the import of package:flutter_libmwc/lib.dart and adds an import of a local wrapper ../../../wl_gen/interfaces/libmwc_interface.dart. The validateAddress override is updated from mimblewimblecoin.Libmwc.validateSendAddress(…) to libMwc.validateSendAddress(…). A minor formatting change is also made to the defaultDerivePathType getter. No functional change to address validation semantics is visible in the diff.
Changed components
lib/wallets/crypto_currency/coins/mimblewimblecoin.dartMimblewimblecoin (MWC) wallet integrationAddress validation path for MWCInspect captured patch +5 / −7
diff --git a/lib/wallets/crypto_currency/coins/mimblewimblecoin.dart b/lib/wallets/crypto_currency/coins/mimblewimblecoin.dart
index 6d670d5..c9d5787 100644
--- a/lib/wallets/crypto_currency/coins/mimblewimblecoin.dart
+++ b/lib/wallets/crypto_currency/coins/mimblewimblecoin.dart
@@ -1,10 +1,9 @@
-import 'package:flutter_libmwc/lib.dart' as mimblewimblecoin;
-
import '../../../models/isar/models/blockchain_data/address.dart';
import '../../../models/node_model.dart';
import '../../../utilities/default_nodes.dart';
import '../../../utilities/enums/derive_path_type_enum.dart';
import '../../../utilities/enums/mwc_transaction_method.dart';
+import '../../../wl_gen/interfaces/libmwc_interface.dart';
import '../crypto_currency.dart';
import '../intermediate/bip39_currency.dart';
@@ -54,7 +53,7 @@ class Mimblewimblecoin extends Bip39Currency {
@override
bool validateAddress(String address) {
// Use libmwc for address validation.
- return mimblewimblecoin.Libmwc.validateSendAddress(address: address);
+ return libMwc.validateSendAddress(address: address);
}
/// Check if data is a slatepack.
@@ -134,10 +133,9 @@ class Mimblewimblecoin extends Bip39Currency {
int get targetBlockTimeSeconds => 60;
@override
- DerivePathType get defaultDerivePathType =>
- throw UnsupportedError(
- "$runtimeType does not use bitcoin style derivation paths",
- );
+ DerivePathType get defaultDerivePathType => throw UnsupportedError(
+ "$runtimeType does not use bitcoin style derivation paths",
+ );
@override
Uri defaultBlockExplorer(String txid) {
Why this scored 16/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.