AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 42 Monero

fix sol token sends with ATA

Public commit record

What the developer wrote

Authored by julian

45/100 · Thin
fix sol token sends with ATA
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This commit fixes how Stack Wallet sends Solana tokens. Previously, the app required the recipient to already have a token account (ATA) set up, and it could fail or send funds incorrectly if that account didn't exist. The update makes the wallet automatically create the recipient's token account during the transaction if needed, and it cleans up how token details are passed around. There is no clear security bug being patched, but the change touches code that handles real money transfers, so mistakes here could cause lost funds or failed transactions.

Recommended action

Treat as a functional bug fix rather than a security vulnerability. Reviewers should verify that the new ATA creation path correctly handles Token-2022 mints, that the fee estimate accounts for the extra create-account instruction, and that the null-safety assertions on pCurrentSolanaTokenWallet do not crash the UI in edge cases. No urgent security patch is indicated.

Security signals we found

01

Funds availability / transaction failure: prior code threw if recipient ATA did not exist, which could block legitimate sends but is not an exploit.

02

ATA derivation seed change: seeds now use pubkey bytes rather than a hardcoded 'account' string and base58 string conversions, fixing potential derivation mismatch.

03

Instruction reuse between prepareSend and confirmSend reduces risk of inconsistent transaction construction.

04

Removal of fallbacks to 'unknown' token metadata in UI reduces chance of user confusion, but introduces null-safety assertions (value!) that could crash if provider state is missing.

05

No explicit security disclosure, CVE, or researcher attribution in commit or references.

Risk score

Why this scored 42/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 6/15
Affected reach 7/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.