What changed, and why it matters
This commit changes two places in a cryptocurrency wallet app where it connects to ElectrumX servers. Previously, one connection accepted unverified TLS/SSL certificates (acceptUnverified: true), which could let a malicious server impersonate a legitimate one. The patch disables that behavior (acceptUnverified: false) and also explicitly disables it in a connection-check helper. In plain terms, the wallet will now refuse to trust servers that cannot prove their identity with a valid certificate, reducing the risk of man-in-the-middle attacks.
Users should upgrade to a version containing this commit. Operators of self-hosted ElectrumX servers must ensure their servers present valid, trusted TLS certificates matching the configured hostname, or use non-SSL connections where appropriate. Review whether any other network clients in the codebase still use acceptUnverified: true.
Security signals we found
Disabling acceptance of unverified TLS certificates
ElectrumX server connection hardening
Man-in-the-middle risk reduction for wallet RPC traffic
Evidence from the diff
The patch sets acceptUnverified to false in lib/electrumx_rpc/electrumx_client.dart for ElectrumX JSON-RPC client initialization, replacing the previous acceptUnverified: true. It also adds acceptUnverified: false explicitly in lib/utilities/connection_check/electrum_connection_check.dart. acceptUnverified controls whether the TLS handshake accepts certificates that fail verification (e.g., self-signed, expired, wrong hostname). The change prevents the wallet from silently trusting arbitrary ElectrumX servers when using SSL/TLS, forcing proper certificate validation.
Changed components
lib/electrumx_rpc/electrumx_client.dartlib/utilities/connection_check/electrum_connection_check.dartInspect captured patch +2 / −1
diff --git a/lib/electrumx_rpc/electrumx_client.dart b/lib/electrumx_rpc/electrumx_client.dart
index e38e73a..b7c52b7 100644
--- a/lib/electrumx_rpc/electrumx_client.dart
+++ b/lib/electrumx_rpc/electrumx_client.dart
@@ -289,7 +289,7 @@ class ElectrumXClient {
port: usePort,
connectionTimeout: connectionTimeoutForSpecialCaseJsonRPCClients,
aliveTimerDuration: connectionTimeoutForSpecialCaseJsonRPCClients,
- acceptUnverified: true,
+ acceptUnverified: false,
useSSL: useUseSSL,
proxyInfo: proxyInfo,
);
diff --git a/lib/utilities/connection_check/electrum_connection_check.dart b/lib/utilities/connection_check/electrum_connection_check.dart
index 478d5e5..24bd871 100644
--- a/lib/utilities/connection_check/electrum_connection_check.dart
+++ b/lib/utilities/connection_check/electrum_connection_check.dart
@@ -49,6 +49,7 @@ Future<bool> checkElectrumServer({
port: port,
useSSL: useSSL && !host.endsWith('.onion'),
proxyInfo: proxyInfo,
+ acceptUnverified: false,
).timeout(
Duration(seconds: (proxyInfo == null ? 5 : 30)),
onTimeout: () => throw Exception(
Why this scored 66/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.