What changed, and why it matters
This commit fixes how Stack Wallet builds Solana token transfer addresses. It corrects two mistakes: a truncated Solana program ID string, and a change from encoding address seeds as plain text to encoding them properly as base58-decoded bytes. The old code likely produced wrong associated-token-account addresses, which could cause token sends to fail or, in the worst case, send funds to an address the user did not intend.
Review the full Solana token send path to confirm no other truncated program IDs or incorrect seed encodings remain. Add unit tests that verify ATA derivation against known-good Solana addresses for representative token programs and owners. Because the commit is marked WIP, avoid treating it as a complete fix until follow-up commits land.
Security signals we found
Incorrect program ID constant (truncated base58 string)
Incorrect seed encoding for Solana Program Derived Address (PDA) derivation
Potential loss of funds or failed transactions due to wrong associated token account address
Fix is marked WIP (work in progress), indicating patch may be incomplete
Evidence from the diff
The patch updates lib/wallets/wallet/impl/sub_wallets/solana_token_wallet.dart. It replaces a shortened associated-token-program ID (‘ATokenGPvbdGVqstVQmcLsNZAqeEjlCoquUSjfJ5c’) with the canonical 32-byte base58 ID (‘ATokenGPvbdGVxr1b2hvZbsiqW5xWH25efTNsLJA8knL’). It also changes the seeds passed to Ed25519HDPublicKey.findProgramAddress from UTF-8 code units of base58 strings to the correct base58-decoded byte arrays via new extension methods (toUint8ListFromUtf8 and toUint8ListFromBase58Encoded). The prior code would have derived an incorrect associated token account (ATA) address, breaking token sends or potentially deriving an ATA not controlled by the intended owner.
Changed components
lib/wallets/wallet/impl/sub_wallets/solana_token_wallet.dartSolana SPL token send/transfer flowAssociated Token Account (ATA) derivationInspect captured patch +6 / −5
diff --git a/lib/wallets/wallet/impl/sub_wallets/solana_token_wallet.dart b/lib/wallets/wallet/impl/sub_wallets/solana_token_wallet.dart
index bf0e4b1..65fbe32 100644
--- a/lib/wallets/wallet/impl/sub_wallets/solana_token_wallet.dart
+++ b/lib/wallets/wallet/impl/sub_wallets/solana_token_wallet.dart
@@ -21,6 +21,7 @@ import '../../../../models/isar/models/isar_models.dart';
import '../../../../models/paymint/fee_object_model.dart';
import '../../../../services/solana/solana_token_api.dart';
import '../../../../utilities/amount/amount.dart';
+import '../../../../utilities/extensions/extensions.dart';
import '../../../../utilities/logger.dart';
import '../../../models/tx_data.dart';
import '../../wallet.dart';
@@ -866,16 +867,16 @@ class SolanaTokenWallet extends Wallet {
final tokenProgramPubkey = Ed25519HDPublicKey.fromBase58(tokenProgramId);
const associatedTokenProgramId =
- 'ATokenGPvbdGVqstVQmcLsNZAqeEjlCoquUSjfJ5c';
+ 'ATokenGPvbdGVxr1b2hvZbsiqW5xWH25efTNsLJA8knL';
final associatedTokenProgramPubkey = Ed25519HDPublicKey.fromBase58(
associatedTokenProgramId,
);
final seeds = [
- 'account'.codeUnits,
- ownerPubkey.toBase58().codeUnits,
- tokenProgramPubkey.toBase58().codeUnits,
- mintPubkey.toBase58().codeUnits,
+ 'account'.toUint8ListFromUtf8,
+ ownerPubkey.toBase58().toUint8ListFromBase58Encoded,
+ tokenProgramPubkey.toBase58().toUint8ListFromBase58Encoded,
+ mintPubkey.toBase58().toUint8ListFromBase58Encoded,
];
final ataAddress = await Ed25519HDPublicKey.findProgramAddress(
Why this scored 32/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.